New Rogue : System Tuner

July 11th, 2009

System Tuner is a new/updated rogue claiming to “tune” your system. We have updated our definitions to detect and remove all traces of this rogue.

System Tuner Application
Rogue - System Tuner Main Screen

Files/Folders Created
%CSIDL_PROGRAMS%\SYSTEMTUNER
%PROGRAMFILES%\SYSTEMTUNER

Registry Items Created/Added
HKLM\SOFTWARE\SystemTuner
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemTuner

Click here to download SUPERAntiSpyware to Remove System Tuner

New Rogue : WiniFighter

July 9th, 2009

WiniFighter is a new/updated rogue from the WinBlueSoft series. We have updated our definitions to detect and remove all traces of this rogue.

WiniFighter Application
Rogue - WiniFighter Main Screen

Files/Folders Created
%CSIDL_COMMON_PROGRAMS%\WINIFIGHTER
%CSIDL_COMMON_PROGRAMS%\WINIFIGHTER\1 WINIFIGHTER.LNK
%CSIDL_COMMON_PROGRAMS%\WINIFIGHTER\2 HOMEPAGE.LNK
%CSIDL_COMMON_PROGRAMS%\WINIFIGHTER\3 UNINSTALL.LNK
%PROGRAMFILES%\WINIFIGHTER SOFTWARE
%PROGRAMFILES%\WINIFIGHTER SOFTWARE\WINIFIGHTER
%PROGRAMFILES%\WINIFIGHTER SOFTWARE\WINIFIGHTER\DATA.BIN
%PROGRAMFILES%\WINIFIGHTER SOFTWARE\WINIFIGHTER\LICENSE.TXT
%PROGRAMFILES%\WINIFIGHTER SOFTWARE\WINIFIGHTER\UNINSTALL.EXE
%PROGRAMFILES%\WINIFIGHTER SOFTWARE\WINIFIGHTER\WINIFIGHTER.EXE
%PROGRAMFILES%\WINIFIGHTER SOFTWARE\WINIFIGHTER\WINIFIGHTERSVC.EXE

Registry Items Created/Added
HKCU\Software\WiniFighter
HKCU\Software\WiniFighter#CurrentVersion =
HKCU\Software\WiniFighter#AgentsSettings
HKCU\Software\Microsoft\Windows\CurrentVersion\Run#WiniFighter = C:\Program Files\WiniFighter Software\WiniFighter\WiniFighter.exe -min

Click here to download SUPERAntiSpyware to Remove WiniFighter

New Rogue : Spyware XP Guard

July 8th, 2009

Spyware XP Guard is a new/updated rogue. Part of the WinDefender family. We have updated our definitions to detect and remove all traces of this rogue.

Spyware XP Guard Application
Rogue - Spyware XP Guard Main Screen

Click here to download SUPERAntiSpyware to Remove Spyware XP Guard

New Rogue : Smart Defender Pro

July 7th, 2009

Smart Defender Pro is a new/updated rogue. We have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and adult/keygen sites.

Smart Defender Pro Application
Rogue - Smart Defender Pro Main Screen

Files/Folders Created
%CSIDL_COMMON_DESKTOPDIRECTORY%\SMART DEFENDER PRO.LNK
%CSIDL_APPDATA%\SMART DEFENDER PRO
%CSIDL_COMMON_PROGRAMS%\SMART DEFENDER PRO
%CSIDL_COMMON_PROGRAMS%\SMART DEFENDER PRO\SMART DEFENDER PRO.LNK

Registry Items Created/Added
HKCU\Software\Smart Defender PRO
HKCU\Software\Smart Defender PRO#Smart Defender PRO = D41D8CD98F00B204E9800998ECF8427E
HKCU\Software\Smart Defender PRO#LastUpdate = 2009-06-30
HKCU\Software\Smart Defender PRO#ZF = XOge3/+m0ghHNi2HpBX3b2fhucJAeDTUvPHfYWg5HOGaKMyJFJSWqeIHYlB0aXWRnnrHLw==
HKCU\Software\Smart Defender PRO#SS = 321
HKCU\Software\Smart Defender PRO\threats

Click here to download SUPERAntiSpyware to Remove Smart Defender Pro

New Rogue : UnVirex

June 2nd, 2009

UnVirex is a new/updated rogue. We have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and adult/keygen sites.

UnVirex Application
Rogue - UnVirex Main Screen

Files/Folders Created
%CSIDL_COMMON_PROGRAMS%\UNVIREX.LNK
%CSIDL_COMMON_PROGRAMS%\UNVIREX
%CSIDL_COMMON_PROGRAMS%\UNVIREX\HOW TO REGISTER UNVIREX.LNK
%CSIDL_COMMON_PROGRAMS%\UNVIREX\REGISTER UNVIREX.LNK
%CSIDL_COMMON_PROGRAMS%\UNVIREX\UNVIREX.LNK
%PROGRAMFILES%\UNVIREX
%PROGRAMFILES%\UNVIREX\DAILY.CVD
%PROGRAMFILES%\UNVIREX\DRVFLTIP.SYS
%PROGRAMFILES%\UNVIREX\HJENGINE.DLL
%PROGRAMFILES%\UNVIREX\IEADDON.DLL
%PROGRAMFILES%\UNVIREX\MAIN.CVD
%PROGRAMFILES%\UNVIREX\MFC71.DLL
%PROGRAMFILES%\UNVIREX\MFC71ENU.DLL
%PROGRAMFILES%\UNVIREX\MSVCP71.DLL
%PROGRAMFILES%\UNVIREX\MSVCR71.DLL
%PROGRAMFILES%\UNVIREX\PTHREADVC2.DLL
%PROGRAMFILES%\UNVIREX\SHELLEXT.DLL
%PROGRAMFILES%\UNVIREX\SIGLSP.DLL
%PROGRAMFILES%\UNVIREX\UNINSTALL.EXE
%PROGRAMFILES%\UNVIREX\UNVIREX.EXE

Registry Items Created/Added
HKLM\SOFTWARE\UnVirex#ADVid =
HKLM\SOFTWARE\UnVirex# = C:\Program Files\UnVirex
HKLM\SOFTWARE\UnVirex#InstallDir = C:\Program Files\UnVirex
HKLM\SOFTWARE\UnVirex#SoftID = UnVirex
HKLM\SOFTWARE\UnVirex#ScanSystemOnStartup
HKLM\SOFTWARE\UnVirex#AutomaticallyUpdates
HKLM\SOFTWARE\UnVirex#MinimizeOnStart
HKLM\SOFTWARE\UnVirex#BackgroundScan
HKLM\SOFTWARE\UnVirex#BackgroundScanTimeout
HKLM\SOFTWARE\UnVirex#LastTimeStamp

Click here to download SUPERAntiSpyware to Remove UnVirex

SUPERSampleSubmit - Submit Samples

May 28th, 2009

We have just released a utility called “SUPERSampleSubmit” to make it easier for users to submit samples for review and analysis.

The link to the utility is :
http://www.superantispyware.com/downloads/SUPERSampleSubmit.exe

Please ONLY submit files you believe are “harmful” and they will be analyzed by our labs on a priority basis.

Threat Research Center

May 21st, 2009

We are always asked “Does SUPERAntiSpyware detect <THREATNAME>?” or “I have <FILENAME> running on my computer, what is it?” - we decided to post our live threats stream on our Threat Research Center here:

Threat Research Center
http://www.superantispyware.com/threatresearchcenter.html

The files are updated several times a day and are from real infected systems. If you have an infection that can’t be removed by SUPERAntiSpyware or another product, please do not hesitate to contact us via our forums (link below) or submit a support request!

SUPERAntiSpyware Forums
http://forums.superantispyware.com

We also have our File Research Center here:
http://www.fileresearchcenter.com

New Rogue : Renus 2008

March 18th, 2009

Renus 2008 is a new/updated rogue. We have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and adult/keygen sites.

Renus 2008 Application
Rogue - Renus 2008 Main Screen

Click here to download SUPERAntiSpyware to Remove Renus 2008

New Rogue : AntiSpyware Pro 2009

March 6th, 2009

AntiSpyware Pro 2009 is a new/updated rogue. We have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and adult/keygen sites.

AntiSpyware Pro 2009 Application
Rogue - AntiSpyware Pro 2009 Main Screen

Folders Created by AntiSpyware Pro 2009
%PROGRAMFILES%\AntiSpyware Pro
%CSIDL_APPDATA%\AntiSpyware Pro

Registry Items Created by AntiSpyware Pro 2009
HKCR\CLSID\{66B643BE-5E94-4569-B93E-CE2636848AC8}
HKCR\CLSID\{6D1CD63B-2FD7-48AA-ADA9-C847829A22AD}
HKCR\CLSID\{BFD7B5CD-F8CB-4E26-A406-CC5B655F4815}
HKCR\TypeLib\{7FA7E4D2-5EA2-4B67-8A04-661663F3DBE9}
HKCR\Interface\{DBFB5DCA-362F-4B62-AF35-476F95927C84}
HKCR\Interface\{EC4C2EAC-A823-42D4-9675-3D286A281BF5}
HKCU\Software\AntiSpyware Pro
HKLM\Software\AntiSpyware Pro
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiSpyware Pro

Click here to download SUPERAntiSpyware to Remove AntiSpyware Pro 2009

New Rogue : Malware Doctor/MalwareDoc

February 25th, 2009

Malware Doctor/MalwareDoc is a new/updated rogue. We have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and adult/keygen sites.

Malware Doctor Application
Rogue - Malware Doctor Main Screen

Click here to download SUPERAntiSpyware to Remove Malware Doctor