<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; WinAntispywareCenter</title>
	<atom:link href="http://www.anti-malware-blog.com/tag/winantispywarecenter/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Win Antispyware Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/28/win-antispyware-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/28/win-antispyware-center-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 28 May 2010 06:07:59 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[WinAntispywareCenter]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=923</guid>
		<description><![CDATA[The Emsisoft malware research team has discoverd a new outbreak of the Win Antispyware Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WinAntispywareCenter. Win Antispyware Center is a rogue security program. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak               of the<strong> Win Antispyware Center </strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinAntispywareCenter" target="_blank"><strong>Adware.Win32.</strong><strong>WinAntispywareCenter</strong></a>.</p>
<p><strong>Win Antispyware Center </strong>is a rogue security program. A  rogue      application         tries to  trick you  by displaying   false         positive/misleading   scan        results  report, which   says that  your         computer is  infected   with       viruses or   trojan, but  you     will not be     able   to  delete  them  before you        purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\WinAntispywareCenter\av.exe</li>
<li>%UserProfile%\Local Settings\Temp\10.tmp</li>
</ul>
<p><strong>Create or modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\DefaultIcon</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\open</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\open\command</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\runas</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\runas\command</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\start</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\start\command</li>
<li>HKEY_CURRENT_USER\software\Win Antispyware Center</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\.exe\shell\open\command<br />
(Default) = &#8220;C:\Program Files\WinAntispywareCenter\av.exe&#8221; /START &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\secfile\shell\open\command<br />
(Default) = &#8220;C:\Program Files\WinAntispywareCenter\av.exe&#8221; /START &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
Win Antispyware Center = C:\Program Files\WinAntispywareCenter\av.exe</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run<br />
Win Antispyware Center = C:\Program Files\WinAntispywareCenter\av.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_1.png"><img class="alignnone size-medium wp-image-924" title="Adware.Win32.WinAntispywareCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_1-400x285.png" alt="" width="400" height="285" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_2.png"><img class="alignnone size-medium wp-image-925" title="Adware.Win32.WinAntispywareCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_2-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_3.png"><img class="alignnone size-medium wp-image-926" title="Adware.Win32.WinAntispywareCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.WinAntispywareCenter_3-400x301.png" alt="" width="400" height="301" /></a></p>
<p><strong>How to remove the infection of Win Antispyware Center </strong><strong>(Adware.Win32.</strong><strong>WinAntispywareCenter</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong>. Run a full scan on all  drives      and      move     all detected          items to the  quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/" rel="bookmark" class="crp_title">XP Antivirus 2012 (MultiFakeAV) Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/23/win-7-antispyware-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Win 7 Antispyware 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/" rel="bookmark" class="crp_title">XJR Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/23/your-pc-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Your PC Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/08/11/wireshark-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Wireshark Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/28/win-antispyware-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

