New Rogue : AntiVirus360

December 11th, 2008

AntiVirus360 is a new rogue. We have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and adult/keygen sites.

AntiVirus360
Rogue - ExtraAntiVir Main Screen

Click here to download SUPERAntiSpyware to Remove AntiVirus360

Threat Update : Zlog/FakeAlert/SmitFraud

December 10th, 2008

Shared Task Scheduler Registry Entry
{50E9D039-FB50-4020-A841-1D226AE52B22}

Associated File Item(s)
C:\WINDOWS\SYSTEM32\PGFSHVP.DLL (name varies)

MD5 Hash
01D2E1CF268FB814D34B6E879B3CEA12

Click here to download SUPERAntiSpyware and remove this threat

Threat Update : FakeAlert/Zlob

December 7th, 2008

Shared Task Scheduler Registry Entry
{341BD909-3367-4307-B37D-FB1CC56387AD}

Associated File Item(s)
C:\WINDOWS\SYSTEM32\ELMNPLW.DLL (name varies)

MD5 Hash
C45B48A6779CBB73490F566B8A78A321

Click here to download SUPERAntiSpyware and remove this threat

Threat Update : FakeAlert/Zlob/SmitFraud

December 2nd, 2008

Shared Task Scheduler Registry Entry
{51E7273D-911A-445A-BF46-BD4B86B0E87B}

Associated File Item(s)
C:\WINDOWS\SYSTEM32\PBHHA.DLL (name varies)

MD5 Hash
4D49D9DEFF51E66C84030B9CFCE6E35A

Click here to download SUPERAntiSpyware and remove this threat

New Rogue : ExtraAntiVir

November 27th, 2008

ExtraAntiVir is a new rogue. We have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and adult/keygen sites.

ExtraAntiVir Application
Rogue - ExtraAntiVir Main Screen

Associated File Items
%PROGRAMFILES%\Extra Antivir
%PROGRAMFILES%\Extra Antivir\ExtraAntiVir.exe
%PROGRAMFILES%\Extra Antivir\Buy.url
%PROGRAMFILES%\Extra Antivir\Help.url
%PROGRAMFILES%\Extra Antivir\HowToBuy.txt
%PROGRAMFILES%\Extra Antivir\ID.dat
%PROGRAMFILES%\Extra Antivir\License.txt
%PROGRAMFILES%\Extra Antivir\Uninstall.exe

Click here to download SUPERAntiSpyware to Remove ExtraAntiVir

Rogue : AntiSpywareGuard

November 25th, 2008

AntiSpywareGuard updated rogue. We have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and adult/keygen sites.

AntiSpywareGuard Application
Rogue - AntiSpywareGuard Main Screen

Associated File Items
%PROGRAMFILES%\AntiSpywareGuard
%PROGRAMFILES%\AntiSpywareGuard\asg.exe
%PROGRAMFILES%\AntiSpywareGuard\asg.ini
%PROGRAMFILES%\AntiSpywareGuard\BL.dat
%PROGRAMFILES%\AntiSpywareGuard\PP.exe
%PROGRAMFILES%\AntiSpywareGuard\WL.dat

Click here to download SUPERAntiSpyware to Remove AntiSpywareGuard

Rogue Update : MicroAntiVirus2009

November 25th, 2008

MicroAntiVirus rogue update. We have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and adult/keygen sites.

MicroAntiVirus Web
Rogue - MicroAntiVirus

Associated File Items
%PROGRAMFILES%\MicroAV
%PROGRAMFILES%\MicroAV\MicroAV.cpl
%PROGRAMFILES%\MicroAV\MicroAV.exe
%PROGRAMFILES%\MicroAV\MicroAV.ooo
%PROGRAMFILES%\MicroAV\MicroAV0.dat
%PROGRAMFILES%\MicroAV\MicroAV1.dat

Click here to download SUPERAntiSpyware to Remove MicroAntiVirus

Threat Update : FakeAlert/SmitFraud/ZLob and VirusTrigger

November 24th, 2008

FakeAlert/SmitFraud/ZLob Registry Items
{854B8525-C907-4258-BC2E-7B118037419C}
{DFB3C1DC-1212-4235-88FD-98539540F423}

Virus Trigger Registry Item
{3A267370-076E-4AF4-B986-77626B8E89DF}

Associated File Item(s)
C:\WINDOWS\SYSTEM32\UMHZWL.DLL (name varies)
C:\WINDOWS\SYSTEM32\EEBJP.DLL (name varies)
C:\PROGRAM FILES\AVIRTRSOFTWARE\AVIRTRWARNING.DLL

MD5 Hash
A0C02530EC6C7701C9872D0E1EAC8495
EF418C2FA21F6A795B8F1FD6721874FB
F5AD9FF34E66CC133053729DD88F75FB

Click here to download SUPERAntiSpyware and remove these threats

New Rogue : SpywareRemover2009

November 23rd, 2008

SpywareRemover2009 is yet another rogue - we have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and adult/keygen sites.

SpywareRemover2009 Application
Rogue - SpywareRemover2009 Main Screen

Associated File Items
%PROGRAMFILES%\SpywareRemover2009
%PROGRAMFILES%\SpywareRemover2009\cn.exe [MD5:8CD76F9EA4E7A8E8BD95D8F4E7568BF6]
%PROGRAMFILES%\SpywareRemover2009\cn.xml [MD5:CD781F6EDAEE7362C303B801A15FA76C]
%PROGRAMFILES%\SpywareRemover2009\database
%PROGRAMFILES%\SpywareRemover2009\database\AutoProcess.dat [MD5:7DEA362B3FAC8E00956A4952A3D4F474]
%PROGRAMFILES%\SpywareRemover2009\database\enemies.dat [MD5:1F668F488E9034D6B3D0F59D742BB283]
%PROGRAMFILES%\SpywareRemover2009\database\monstate.dat [MD5:1E53F880D256AE64575D6E2ABF035C32]
%PROGRAMFILES%\SpywareRemover2009\database\quarantine.dat
%PROGRAMFILES%\SpywareRemover2009\database\quarantine.dat\#post_quarantine
%PROGRAMFILES%\SpywareRemover2009\database\Summary.dat
%PROGRAMFILES%\SpywareRemover2009\database\vbpv.dat [MD5:0369EEF45ECC69BDD9BDC5DE4FBA5F22]
%PROGRAMFILES%\SpywareRemover2009\InstUp.exe [MD5:5D6C54F0E2414E2EA5B8FD43C6C25AFF]
%PROGRAMFILES%\SpywareRemover2009\license.rtf [MD5:143188FDE601860E34E51A5998240523]
%PROGRAMFILES%\SpywareRemover2009\mfc80.dll [MD5:1B7524806D0270B81360C63A2FA047CB]
%PROGRAMFILES%\SpywareRemover2009\Microsoft.VC80.CRT.manifest [MD5:541423A06EFDCD4E4554C719061F82CF]
%PROGRAMFILES%\SpywareRemover2009\Microsoft.VC80.MFC.manifest [MD5:97B859F11538BBE20F17DFB9C0979A1C]
%PROGRAMFILES%\SpywareRemover2009\msvcm80.dll [MD5:CAE6861B19A2A7E5D42FEFC4DFDF5CCF]
%PROGRAMFILES%\SpywareRemover2009\msvcp80.dll [MD5:4C8A880EABC0B4D462CC4B2472116EA1]
%PROGRAMFILES%\SpywareRemover2009\msvcr80.dll [MD5:E4FECE18310E23B1D8FEE993E35E7A6F]
%PROGRAMFILES%\SpywareRemover2009\PaymentPage.exe [MD5:F89E95B92E9812A6F782E5FF872E8C54]
%PROGRAMFILES%\SpywareRemover2009\pv.dat [MD5:E60821D5D30481FC5B15A611905E7CD9]
%PROGRAMFILES%\SpywareRemover2009\Quarantine
%PROGRAMFILES%\SpywareRemover2009\quaratine.dat
%PROGRAMFILES%\SpywareRemover2009\readme.rtf [MD5:BABAC5871CB31E1BC076B8EBABC4BC85]
%PROGRAMFILES%\SpywareRemover2009\settings.ini [MD5:63A1C1F9ED8472F8C560E935B49799D8]
%PROGRAMFILES%\SpywareRemover2009\SR.exe [MD5:CD675DB34D3BBE6BACB1CF8A0A09F110]
%PROGRAMFILES%\SpywareRemover2009\SR.xml [MD5:C96D0BA4EF785932F3B62AC1FFB40D22]
%PROGRAMFILES%\SpywareRemover2009\unins000.dat [MD5:99E53AF36095EA493A51EB8D4C149071]
%PROGRAMFILES%\SpywareRemover2009\unins000.exe [MD5:21187F13B67CADF5BD798DA9036D1615]
%PROGRAMFILES%\SpywareRemover2009\updateapp.dat [MD5:9C02B78854878E5D3BA5318C24320947]
%PROGRAMFILES%\SpywareRemover2009\updatedb.dat [MD5:0E8F782C54CC96E082FEE2E2461049EF]
%PROGRAMFILES%\SpywareRemover2009\Updater.dll [MD5:54227C0E12394F192752B8F6E7C82B7C]
%PROGRAMFILES%\SpywareRemover2009\UserAgent.dll [MD5:E5DA1EDF503C7F1ABBD118D086E773E1]

Click here to download SUPERAntiSpyware to Remove SpywareRemover2009

Rogue : XPProtectionCenter

November 23rd, 2008

XPProtectionCenter is yet another updated rogue - we have updated our definitions to detect and remove all traces of this rogue. Being distributed through the spam and keygen sites.

XPProtectionCenter Application
Rogue - XPProtectionCenter Main Screen

Associated File Items
%PROGRAMFILES%\XPProtectionCenter
%PROGRAMFILES%\XPProtectionCenter\AVEngn.dll [MD5:64036EF18561D9159A19C1C420E6118F]
%PROGRAMFILES%\XPProtectionCenter\data
%PROGRAMFILES%\XPProtectionCenter\data\daily.cvd [MD5:3ABFB6068A87262CE66A65E4E234A630]
%PROGRAMFILES%\XPProtectionCenter\htmlayout.dll [MD5:C6A107A2675C865A359525AF502A6F23]
%PROGRAMFILES%\XPProtectionCenter\Microsoft.VC80.CRT
%PROGRAMFILES%\XPProtectionCenter\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest [MD5:9EDF5EB3D091D4823C96A00B6B45DF45]
%PROGRAMFILES%\XPProtectionCenter\Microsoft.VC80.CRT\msvcm80.dll [MD5:CDCC63E967D64ECE3729246720AF4FCC]
%PROGRAMFILES%\XPProtectionCenter\Microsoft.VC80.CRT\msvcp80.dll [MD5:2BC650257FB0867ABD54FD460EC2BAFC]
%PROGRAMFILES%\XPProtectionCenter\Microsoft.VC80.CRT\msvcr80.dll [MD5:16D7DDF3B659F7CF1CB9F4DCFF4219F0]
%PROGRAMFILES%\XPProtectionCenter\pthreadVC2.dll [MD5:0AB7D0E87F3843F8104B3670F5A9AF62]
%PROGRAMFILES%\XPProtectionCenter\Uninstall.exe [MD5:CAB283AAB0DF5D0B102A41A5C42317D5]
%PROGRAMFILES%\XPProtectionCenter\wscui.cpl [MD5:EF483AAA03356A9DBB30564977EDC17B]
%PROGRAMFILES%\XPProtectionCenter\XPProtectionCenter.cfg [MD5:DD2E9F1ED79F6AF18689376F48FB97D4]
%PROGRAMFILES%\XPProtectionCenter\XPProtectionCenter.exe [MD5:158810C8C6BF05BB74C2A5A4F22F1756]

Click here to download SUPERAntiSpyware to Remove XPProtectionCenter