Jun 06
The Emsisoft malware research team has discoverd a new outbreak of the SysAntivirus adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.SysAntivirus.
SysAntivirus is a rogue security program, this is a new variant of XJR Antivirus, AKM Antivirus 2010 Pro and RTS Antivirus 2010. The maker of this rogue give it name as Sysinternals Antivirus. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.
Create new files:
- %ProgramFiles%\wp3.dat
- %ProgramFiles%\wp4.dat
- %ProgramFiles%\wpp.exe
- %ProgramFiles%\adc_w32.dll
- %ProgramFiles%\alggui.exe
- %ProgramFiles%\nuar.old
- %ProgramFiles%\skynet.dat
- %ProgramFiles%\svchost.exe
- %ProgramFiles%\Sysinternals Antivirus\Sysinternals Antivirus.exe
- %UserProfile%\Desktop\Sysinternals Antivirus.lnk
- %UserProfile%\Start Menu\Programs\Sysinternals Antivirus\Sysinternals Antivirus.lnk
- C:\Sysinternals Antivirus\Sysinternals Antivirus.lnk
Create new registry entries:
- HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}
- HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}\InprocServer32
- HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd
- HKEY_CURRENT_USER\software\Sysinternals Antivirus
- HKEY_CURRENT_USER\software\Sysinternals Antivirus\wpp
- HKEY_CURRENT_USER\software\Sysinternals Antivirus\wpp\Registration
- HKEY_CURRENT_USER\software\Sysinternals Antivirus\wpp\setdata
- HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus
- HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus\Sysinternals Antivirus
- HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus\Sysinternals Antivirus\Registration
- HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus\Sysinternals Antivirus\setdata
Screenshots:

How to remove the infection of SysAntivirus (Adware.Win32.SysAntivirus)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.
Tags: Rogue, SysAntivirus
Posted in Malware Alerts, Removal Help | Comments Off
May 28
The Emsisoft malware research team has discoverd a new outbreak of the Win Antispyware Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WinAntispywareCenter.
Win Antispyware Center is a rogue security program. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.
Create new files:
- %ProgramFiles%\WinAntispywareCenter\av.exe
- %UserProfile%\Local Settings\Temp\10.tmp
Create or modify registry entries:
- HKEY_LOCAL_MACHINE\software\Classes\secfile
- HKEY_LOCAL_MACHINE\software\Classes\secfile\DefaultIcon
- HKEY_LOCAL_MACHINE\software\Classes\secfile\shell
- HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\open
- HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\open\command
- HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\runas
- HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\runas\command
- HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\start
- HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\start\command
- HKEY_CURRENT_USER\software\Win Antispyware Center
- HKEY_LOCAL_MACHINE\software\Classes\.exe\shell\open\command
(Default) = “C:\Program Files\WinAntispywareCenter\av.exe” /START “%1″ %*
IsolatedCommand = “%1″ %*
- HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\open\command
(Default) = “C:\Program Files\WinAntispywareCenter\av.exe” /START “%1″ %*
IsolatedCommand = “%1″ %*
- HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run
Win Antispyware Center = C:\Program Files\WinAntispywareCenter\av.exe
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run
Win Antispyware Center = C:\Program Files\WinAntispywareCenter\av.exe
Screenshots:



How to remove the infection of Win Antispyware Center (Adware.Win32.WinAntispywareCenter)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.
Tags: Rogue, WinAntispywareCenter
Posted in Malware Alerts, Removal Help | Comments Off
May 26
The Emsisoft malware research team has discoverd a new outbreak of the XJR Antivirus adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.XJRAntivirus.
XJR Antivirus is a rogue security program, this is a new variant of AKM Antivirus 2010 Pro and RTS Antivirus 2010. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.
Create new files:
- %ProgramFiles%\wp4.dat
- %ProgramFiles%\adc_w32.dll
- %ProgramFiles%\alggui.exe
- %ProgramFiles%\skynet.dat
- %ProgramFiles%\svchost.exe
- %ProgramFiles%\wp3.dat
- %ProgramFiles%\XJR Antivirus\XJR Antivirus.exe
- %UserProfile%\Desktop\XJR Antivirus.lnk
- %UserProfile%\Start Menu\Programs\XJR Antivirus\XJR Antivirus.lnk
Create new registry entries:
- HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}
- HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}\InprocServer32
- HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd
- HKEY_CURRENT_USER\software\XJR Antivirus
- HKEY_CURRENT_USER\software\XJR Antivirus\wpp
- HKEY_CURRENT_USER\software\XJR Antivirus\wpp\Registration
- HKEY_CURRENT_USER\software\XJR Antivirus\wpp\setdata
- HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus
- HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus\Registration
- HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus\setdata
Modify registry entry:
- HKEY_LOCAL_MACHINE\software\Classes\exefile\shell\open\command
Old: = “%1″ %*
New: = C:\Program Files\alggui.exe “%1″ %*
Screenshots:

How to remove the infection of XJR Antivirus (Adware.Win32.XJRAntivirus)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.
Tags: Rogue, XJRAntivirus
Posted in Malware Alerts, Removal Help | Comments Off
May 20
The Emsisoft malware research team has discoverd a new outbreak of the ByteDefender adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.ByteDefender.
ByteDefender is a rogue security program. This is a new variant from Winiguard/Winisoft family. The author of ByteDefender also made SystemIron, SecurePcAv, SafePcAv, GuardWWW, MyPcSecure, PcSecureNet, PcsSecure, APcSafe, APcSecure, ProtectSoldier, ProtectDefender, ArmorDefender, DefendAPc, SysDefenders, InSysSecure, SysProtector, APcDefender, PcProtectar, PcsProtector,… etc. To further convince victim, SystemIron will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.
Create new files:
- %ProgramFiles%\ByteDefender Software\ByteDefender\ByteDefender.exe
- %ProgramFiles%\ByteDefender Software\ByteDefender\Uninstall.exe
- %ProgramFiles%\ByteDefender Software\ByteDefender\always_delete.xml
- %ProgramFiles%\ByteDefender Software\ByteDefender\always_skip.xml
- %ProgramFiles%\ByteDefender Software\ByteDefender\quarantine\quarantine.xml
- %AllUsersProfile%\Start Menu\Programs\ByteDefender.lnk
- %UserProfile%\Desktop\ByteDefender.lnk
Create new registry entries:
- HKEY_LOCAL_MACHINE\software\ByteDefender
- HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\ByteDefender
- HKEY_CURRENT_USER\software\ByteDefender
- HKEY_CURRENT_USER\software\ByteDefender\agents
- HKEY_CURRENT_USER\software\ByteDefender\general
- HKEY_CURRENT_USER\software\ByteDefender\realtime
- HKEY_CURRENT_USER\software\ByteDefender\scanner
- HKEY_CURRENT_USER\software\ByteDefender\tasks
- HKEY_CURRENT_USER\software\ByteDefender\tasks\0
- HKEY_CURRENT_USER\software\ByteDefender\tasks\1
- HKEY_CURRENT_USER\software\ByteDefender\updates
- HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, “ByteDefender”
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, “ByteDefender”
Screenshots:








How to remove the infection of ByteDefender (Adware.Win32.ByteDefender)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.
Tags: ByteDefender, Rogue
Posted in Malware Alerts, Removal Help | Comments Off