<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; FakeAntivirus</title>
	<atom:link href="http://www.anti-malware-blog.com/tag/fakeantivirus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Fake Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/08/fake-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/08/fake-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 18:04:51 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[FakeAntivirus]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=636</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Fake Antivirus  adware. a-squared Anti-Malware detects this malware as Adware.Win32.FakeAntivirus. &#8220;Antivirus&#8221;, is name of this rogue application, it come from hxxp://just-protect-pc.info. This rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak    of the Fake Antivirus  adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared    Anti-Malware</a> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FakeAntivirus" target="_blank">Adware.Win32.FakeAntivirus</a>.</p>
<p>&#8220;Antivirus&#8221;, is name of this rogue application, it come from hxxp://just-protect-pc.info. This rogue  application  tries to trick you by displaying  false positive/misleading  scan results  report, which says that your  computer is infected with  viruses or  trojan, but you will not be able  to delete them before you  purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Antivirus\AvBho.dll</li>
<li>%ProgramFiles%\Antivirus\Uninstall.exe</li>
<li>%ProgramFiles%\Antivirus\wscsvc32.exe</li>
<li>%ProgramFiles%\Antivirus\Antivirus.exe</li>
<li>%AllUsersProfile%\Desktop\Antivirus.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Antivirus\Antivirus.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Antivirus\Uninstall.lnk</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk</li>
<li>%UserProfile%\Local Settings\Temp\winupd64x.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Antivirus</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AvBho.AvBhoApp</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AvBho.AvBhoApp\CLSID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AvBho.AvBhoApp\CurVer</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AvBho.AvBhoApp.1</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AvBho.AvBhoApp.1\CLSID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}\Programmable</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}\TypeLib</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{9d541c6a-573b-4888-b35e-6816e68c3620}\VersionIndependentProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\TypeLib</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\TypeLib</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}\1.0</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}\1.0\0</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}\1.0\0\win32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}\1.0\FLAGS</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Typelib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}\1.0\HELPDIR</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9d541c6a-573b-4888-b35e-6816e68c3620}</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Antivirus</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Antivirus.exe&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;wscsvc32.exe&#8221;</li>
</ul>
<p><strong>Modify hosts file:</strong></p>
<ul>
<li>174.142.113.204           just-protect-pc.info</li>
<li>70.38.11.165             review.2009softwarereviews.com</li>
<li>70.38.11.165             a1.review.zdnet.com</li>
<li>70.38.11.165             d1.reviews.cnet.com</li>
<li>70.38.11.165             reviews.toptenreviews.com</li>
<li>70.38.11.165             reviews.download.com</li>
<li>70.38.11.165             reviews.pcadvisor.co.uk</li>
<li>70.38.11.165             reviews.pcmag.com</li>
<li>70.38.11.165             reviews.pcpro.co.uk</li>
<li>70.38.11.165             reviews.reevoo.com</li>
<li>70.38.11.165             reviews.riverstreams.co.uk</li>
<li>70.38.11.165             reviews.techradar.com</li>
<li>70.38.11.165             av2010pro.com</li>
<li>70.38.11.165             review.deutsch.eazel.com</li>
<li>70.38.11.165             reviews.download.softwareload.de</li>
<li>70.38.11.165             r1.downloads.phpnuke.org</li>
<li>70.38.11.165             www.anti.actebis.com</li>
<li>70.38.11.165             www.antivirus-review.channelpartner.de</li>
<li>70.38.11.165             www.reviews.chip.de</li>
<li>70.38.11.165             www.dah5.ppks.net</li>
<li>70.38.11.165             www.test-reviews.softguide.de</li>
<li>70.38.11.165             www.review.virenschutz.ch</li>
<li>70.38.11.165             www.reviews.wave-computer.de</li>
<li>70.38.11.165             www.about.zdnet.de</li>
<li>70.38.11.165             www.soft-review.zdnet1.de</li>
<li>70.38.11.165             reviews.livix.blogspot.com</li>
<li>70.38.11.165             www.review-antivirus.alegsa.com.ar</li>
<li>70.38.11.165             www.ra1.analisis-antivirus.com</li>
<li>70.38.11.165             www.review.antivirusgratis.com.ar</li>
<li>70.38.11.165             www.soft-review.directoriowarez.com</li>
<li>70.38.11.165             www.arbest.grupogeek.com</li>
<li>70.38.11.165             www.best-reviews.pcasalvo.com</li>
<li>70.38.11.165             www.testing-av.pcdecasa.net</li>
<li>70.38.11.165             www.rz-x.wei.cl</li>
<li>70.38.11.165             www.review.yoreparo.com</li>
<li>70.38.11.165             reviews.coprocessing.be</li>
<li>70.38.11.165             lab.descary.com</li>
<li>70.38.11.165             review.fr.brothersoft.com</li>
<li>70.38.11.165             www.antilab-review.01net.com</li>
<li>70.38.11.165             www.review-lab.blogeek.ch</li>
<li>70.38.11.165             www.gr1.clubic.com</li>
<li>70.38.11.165             www.laboratory.commentcamarche.net</li>
<li>70.38.11.165             www.review.generation-nt.com</li>
<li>70.38.11.165             www.top-rev.host.fr</li>
<li>70.38.11.165             www.expert.infos-du-net.com</li>
<li>70.38.11.165             www.review.numerama.com</li>
<li>70.38.11.165             www.lab1-r.starzik.com</li>
<li>70.38.11.165             review-tests.italian.ircfast.com</li>
<li>70.38.11.165             www.labs.b2b24.ilsole24ore.com</li>
<li>70.38.11.165             www.ref1.blogslab.net</li>
<li>70.38.11.165             www.review.dvdprice.it</li>
<li>70.38.11.165             www.reviews.ebizitalia.it</li>
<li>70.38.11.165             www.review-software.hwgadget.com</li>
<li>70.38.11.165             www.exp-test.hwupgrade.it</li>
<li>70.38.11.165             www.full-reiew.lolasoft.it</li>
<li>70.38.11.165             www.dkl23.mondotechblog.com</li>
<li>70.38.11.165             www.antiviruses.sicurezzainrete.com</li>
<li>70.38.11.165             www.top.tomshw.it</li>
<li>70.38.11.165             avangate.com</li>
<li>70.38.11.165             regnow.com</li>
<li>70.38.11.165             shareit.com</li>
<li>70.38.11.165             eSellerate.net</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_1.png"><img class="alignnone size-medium wp-image-637" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_1-400x248.png" alt="" width="400" height="248" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_2.png"><img class="alignnone size-medium wp-image-638" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_2-400x67.png" alt="" width="400" height="67" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_3.png"><img class="alignnone size-medium wp-image-639" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_3-400x313.png" alt="" width="400" height="313" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_4.png"><img class="alignnone size-medium wp-image-640" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_4-400x301.png" alt="" width="400" height="301" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_5.png"><img class="alignnone size-medium wp-image-641" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_5-400x294.png" alt="" width="400" height="294" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_6.png"><img class="alignnone size-medium wp-image-642" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_6-400x400.png" alt="" width="400" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_7.png"><img class="alignnone size-medium wp-image-643" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_7-399x297.png" alt="" width="399" height="297" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_8.png"><img class="alignnone size-medium wp-image-644" title="Adware.Win32.FakeAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.FakeAntivirus_8-400x289.png" alt="" width="400" height="289" /></a></p>
<p><strong>How to remove the infection of Fake Antivirus </strong><strong>(Adware.Win32.FakeAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared      Anti-Malware</a>. Run a full scan on all drives and move all detected      items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/09/01/advanced-security-tool-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Advanced Security Tool 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">AKM Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/" rel="bookmark" class="crp_title">XJR Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">SysAntivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/31/desktop-defender-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Desktop Defender 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/08/fake-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

