<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; CleanUPAntivirus</title>
	<atom:link href="http://www.anti-malware-blog.com/tag/cleanupantivirus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>CleanUP Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 18:58:35 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[CleanUPAntivirus]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=782</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the CleanUP Antivirus adware. a-squared Anti-Malware detects this malware as Adware.Win32.CleanUPAntivirus. CleanUP Antivirus is a rogue security software that show false warning messages and show misleading scan results. It will start automatically when your computer starts. The installer will also create numerous harmless [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak            of the <strong>CleanUP Antivirus</strong> adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared            Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CleanUPAntivirus" target="_blank">Adware.Win32.CleanUPAntivirus</a>.</p>
<p><strong>CleanUP Antivirus</strong> is a rogue security software that show false  warning  messages and show misleading scan results. It will start  automatically when your computer starts. The  installer will also create  numerous harmless files on your computer,  usually at Recent folder,  that are used to impersonate malware files.  Once the program is running  it will scan your computer and then display  these files as infections,  but will not allow you to remove them until  you purchase the program.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\58969\CUf4c.exe</li>
<li>%AllUsersProfile%\Application Data\58969\CUA.ico</li>
<li>%AllUsersProfile%\Application Data\CUQKWA\CUZNJUENEA.cfg</li>
<li>%UserProfile%\Application Data\CleanUp Antivirus\Instructions.ini</li>
<li>%UserProfile%\Application Data\CleanUp Antivirus\cookies.sqlite</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\CleanUp Antivirus.lnk</li>
<li>%UserProfile%\Desktop\CleanUp Antivirus.lnk</li>
<li>%UserProfile%\Start Menu\CleanUp Antivirus.lnk</li>
<li>%UserProfile%\Start Menu\Programs\CleanUp Antivirus.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;CleanUp Antivirus</li>
</ul>
<p><strong>Modify hosts file:</strong></p>
<ul>
<li>127.0.0.1       localhost</li>
<li>74.125.45.100 4-open-davinci.com</li>
<li>74.125.45.100 securitysoftwarepayments.com</li>
<li>74.125.45.100 privatesecuredpayments.com</li>
<li>74.125.45.100 secure.privatesecuredpayments.com</li>
<li>74.125.45.100 getantivirusplusnow.com</li>
<li>74.125.45.100 secure-plus-payments.com</li>
<li>74.125.45.100 www.getantivirusplusnow.com</li>
<li>74.125.45.100 www.secure-plus-payments.com</li>
<li>74.125.45.100 www.getavplusnow.com</li>
<li>74.125.45.100 safebrowsing-cache.google.com</li>
<li>74.125.45.100 urs.microsoft.com</li>
<li>74.125.45.100 www.securesoftwarebill.com</li>
<li>74.125.45.100 secure.paysecuresystem.com</li>
<li>74.125.45.100 paysoftbillsolution.com</li>
<li>74.125.45.100 protected.maxisoftwaremart.com</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.CleanUPAntivirus_1.png"><img class="alignnone size-medium wp-image-783" title="Adware.Win32.CleanUPAntivirus_1" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.CleanUPAntivirus_1-400x290.png" alt="" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.CleanUPAntivirus_2.png"><img class="alignnone size-medium wp-image-784" title="Adware.Win32.CleanUPAntivirus_2" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.CleanUPAntivirus_2-400x290.png" alt="" width="400" height="290" /></a></p>
<p><strong>How to remove the infection of CleanUP Antivirus</strong><strong> </strong><strong>(Adware.Win32.CleanUPAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared           Anti-Malware</a>. Run a full scan on all drives and move all detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Security Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

