<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; SystemIron</title>
	<atom:link href="http://www.anti-malware-blog.com/tag/systemiron/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>SystemIron Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 23:35:28 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SystemIron]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=769</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the SystemIron adware. a-squared Anti-Malware detects this malware as Adware.Win32.SystemIron. SystemIron is a rogue security program. This is a new variant from Winiguard/Winisoft family. The author of SystemIron also made SecurePcAv, SafePcAv, GuardWWW, MyPcSecure, PcSecureNet, PcsSecure, APcSafe, APcSecure, ProtectSoldier, ProtectDefender, ArmorDefender, DefendAPc, SysDefenders, [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has discoverd a new outbreak          of the <strong>SystemIron</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared          Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemIron" target="_blank">Adware.Win32.SystemIron</a></strong>.</p>
<p><strong>SystemIron</strong> is a rogue     security      program. This is a new variant from Winiguard/Winisoft    family.  The      author of SystemIron also made <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurePcAv" target="_blank">SecurePcAv</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SafePcAv" target="_blank">SafePcAv</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardWWW" target="_blank">GuardWWW</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyPcSecure" target="_blank">MyPcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcSecureNet" target="_blank">PcSecureNet</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsSecure" target="_blank">PcsSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSafe" target="_blank">APcSafe</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcSecure" target="_blank">APcSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectSoldier" target="_blank">ProtectSoldier</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectDefender" target="_blank">ProtectDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ArmorDefender" target="_blank">ArmorDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefendAPc" target="_blank">DefendAPc</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysDefenders" target="_blank">SysDefenders</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InSysSecure" target="_blank">InSysSecure</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysProtector" target="_blank">SysProtector</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.APcDefender" target="_blank">APcDefender</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcProtectar" target="_blank">PcProtectar</a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PcsProtector" target="_blank">PcsProtector</a>,… etc. To further convince victim, SystemIron will also create numerous junk files with random names on         your  computer that will be detected as malware when the program    scans      your  computer, but will not allow you to remove them until    you    purchase    it.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\SystemIron Software\SystemIron\data.bin</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\license.txt</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\main_config.xml</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\SystemIron.exe</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\SystemIronSvc.exe</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\uninstall.exe</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\always_delete.xml</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\always_skip.xml</li>
<li>%ProgramFiles%\SystemIron Software\SystemIron\quarantine\quarantine.xml</li>
<li>%AllUsersProfile%\Desktop\SystemIron.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SystemIron\2 Homepage.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SystemIron\3 Uninstall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\SystemIron\1 SystemIron.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SystemIron</li>
<li>HKEY_LOCAL_MACHINE\software\SystemIron</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AntispySvc</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SystemIronSvc</li>
<li>HKEY_CURRENT_USER\software\SystemIron</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;SystemIron&#8221;</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;SystemIron&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_1.png"><img class="alignnone size-medium wp-image-770" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_1-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_2.png"><img class="alignnone size-medium wp-image-771" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_2-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_3.png"><img class="alignnone size-medium wp-image-772" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_3-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_4.png"><img class="alignnone size-medium wp-image-773" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_4-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_5.png"><img class="alignnone size-medium wp-image-774" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_5-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_6.png"><img class="alignnone size-medium wp-image-775" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_6-400x312.png" alt="" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_7.png"><img class="alignnone size-medium wp-image-776" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_7-400x233.png" alt="" width="400" height="233" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_8.png"><img class="alignnone size-medium wp-image-777" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_8-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_9.png"><img class="alignnone size-medium wp-image-778" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_9-400x273.png" alt="" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_10.png"><img class="alignnone size-medium wp-image-779" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_10-400x295.png" alt="" width="400" height="295" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_11.png"><img class="alignnone size-medium wp-image-780" title="Adware.Win32.SystemIron" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/03/Adware.Win32.SystemIron_11-400x273.png" alt="" width="400" height="273" /></a></p>
<p><strong>How to remove the infection of </strong><strong>SystemIron</strong><strong> </strong><strong>(Adware.Win32.SystemIron</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared      Anti-Malware</a>. Run a full scan on all drives and move all detected      items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/05/20/bytedefender-adware-removal-instructions/" rel="bookmark" class="crp_title">ByteDefender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/securepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SecurePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/safepcav-adware-removal-instructions/" rel="bookmark" class="crp_title">SafePcAv Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/03/guardwww-adware-removal-instructions/" rel="bookmark" class="crp_title">GuardWWW Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/mypcsecure-adware-removal-instructions/" rel="bookmark" class="crp_title">MyPcSecure Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/03/13/systemiron-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

