<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; XJRAntivirus</title>
	<atom:link href="http://www.anti-malware-blog.com/tag/xjrantivirus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>XJR Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/</link>
		<comments>http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/#comments</comments>
		<pubDate>Wed, 26 May 2010 06:56:56 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[XJRAntivirus]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=919</guid>
		<description><![CDATA[The Emsisoft malware research team has discoverd a new outbreak of the XJR Antivirus adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.XJRAntivirus. XJR Antivirus is a rogue security program, this is a new variant of AKM Antivirus 2010 Pro and RTS Antivirus 2010. A rogue application tries to trick you by displaying false positive/misleading scan [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak              of the<strong> XJR Antivirus </strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                        Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.XJRAntivirus" target="_blank"><strong>Adware.Win32.XJRAntivirus</strong></a>.</p>
<p><strong>XJR Antivirus </strong>is a rogue security program, this is a new variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AKMAntivirus2010Pro" target="_blank"><strong>AKM Antivirus 2010 Pro</strong></a> and <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RTSAntivirus2010" target="_blank">RTS Antivirus 2010</a></strong>. A  rogue     application         tries to  trick you  by displaying   false        positive/misleading   scan        results  report, which   says that your         computer is  infected   with       viruses or   trojan, but you     will not be     able   to  delete  them  before you       purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\wp4.dat</li>
<li>%ProgramFiles%\adc_w32.dll</li>
<li>%ProgramFiles%\alggui.exe</li>
<li>%ProgramFiles%\skynet.dat</li>
<li>%ProgramFiles%\svchost.exe</li>
<li>%ProgramFiles%\wp3.dat</li>
<li>%ProgramFiles%\XJR Antivirus\XJR Antivirus.exe</li>
<li>%UserProfile%\Desktop\XJR Antivirus.lnk</li>
<li>%UserProfile%\Start Menu\Programs\XJR Antivirus\XJR Antivirus.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\wpp</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\wpp\Registration</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\wpp\setdata</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus\Registration</li>
<li>HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus\setdata</li>
</ul>
<p><strong>Modify registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\exefile\shell\open\command<br />
Old: = &#8220;%1&#8243; %*<br />
New:  = C:\Program Files\alggui.exe &#8220;%1&#8243; %*</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.XJRAntivirus_1.png"><img class="alignnone size-medium wp-image-920" title="Adware.Win32.XJRAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/05/Adware.Win32.XJRAntivirus_1-400x301.png" alt="" width="400" height="301" /></a></p>
<p><strong>How to remove the infection of XJR Antivirus </strong><strong>(Adware.Win32.XJRAntivirus</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                        Anti-Malware</a></strong>. Run a full scan on all drives      and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">SysAntivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/08/11/wireshark-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Wireshark Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/akm-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">AKM Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/09/30/anvi-adware-removal-instructions/" rel="bookmark" class="crp_title">AnVi Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/05/26/xjr-antivirus-adware-removal-instructions-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

