<?xml version="1.0" encoding="ISO-8859-1"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Spyware and Malware Removal Guides</title>

	<link>http://www.bleepingcomputer.com/malware-removal/</link>
	<description>The latest information about current malware and spyware threats to your computer.  Use these guides and tutorials to remove or uninstall various malware and infections from your comptuer. All removal instructions are free to use and do not cost any money to remove any of the malware listed in these guides.</description>
	<pubDate>Sat, 05 Jul 2008 07:33:33 EDT</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>

 <item>
	<title>How to remove Wista Antivirus (Removal Guide)</title>
	<link>http://www.bleepingcomputer.com/malware-removal/wista-antivirus-removal</link>
	<pubDate>Fri, 04 Jul 2008 23:34:23 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware]]></category>

	<category><![CDATA[Wista Antivirus]]></category>

	<guid>http://www.bleepingcomputer.com/malware-removal/wista-antivirus-removal</guid>
	<description><![CDATA[Wista Antivirus is a rogue anti-spyware program that deliberately 
  displays false information to scare you into purchasing their software. When 
  Wista Antivirus is installed on your computer, it will automatically ... [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">

 <h1>How to remove Wista Antivirus (Removal Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/malware-removal/forums/index.php?showuser=3">Grinler</a> on Fri, 04 Jul 2008 23:34:23 EDT &middot; Views: 21</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/wista-antivirus-removal', 'How to remove Wista Antivirus (Removal Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle"></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/wista-antivirus-removal', 'How to remove Wista Antivirus (Removal Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle"></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p> <strong>Wista Antivirus</strong> is a rogue anti-spyware program that deliberately 
  displays false information to scare you into purchasing their software. When 
  Wista Antivirus is installed on your computer, it will automatically scan for 
  malware and display a variety of infections on your computer that cannot be 
  removed unless you first purchase the software. These infections, though, are 
  all fake and are only being shown in order to scare you into thinking you are 
  infected. </p>
<p>
  
</p>
<p>This guide will walk you through removing the Wista Antivirus program and any 
  associated malware for free. </p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/malware-removal/rogue-programs">Information on Rogue Programs</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Add/Remove Programs control panel entry:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/11139/Wista-Antivirus.html">Wista Antivirus</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [wistaantivirus] C:\Program Files\WistaAntivirus\wistaantivirus.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>07/04/08 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Wista Antivirus using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>Download_mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Wista Antivirus</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>WistaAntivirus</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. <br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/results-page.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>WistaAntivirus</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Wista Antivirus Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Start Menu\Programs\WistaAntivirus<br />
c:\Documents and Settings\All Users\Start Menu\Programs\WistaAntivirus\Uninstall wistaantivirus.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\WistaAntivirus\wistaantivirus on the Web.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\WistaAntivirus\WistaAntivirus.lnk<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WistaAntivirus.lnk<br />
%UserProfile%\Desktop\WistaAntivirus.lnk<br />
c:\Program Files\WistaAntivirus<br />
c:\Program Files\WistaAntivirus\alarm.wav<br />
c:\Program Files\WistaAntivirus\click.wav<br />
c:\Program Files\WistaAntivirus\config.cfg<br />
c:\Program Files\WistaAntivirus\dbinfo<br />
c:\Program Files\WistaAntivirus\success.wav<br />
c:\Program Files\WistaAntivirus\unins000.dat<br />
c:\Program Files\WistaAntivirus\unins000.exe<br />
c:\Program Files\WistaAntivirus\wistaantivirus.exe<br />
c:\Program Files\WistaAntivirus\wistaantivirus.url<br />
c:\Program Files\WistaAntivirus\dll<br />
c:\Program Files\WistaAntivirus\dll\antirootkit.sys<br />
c:\Program Files\WistaAntivirus\dll\def1.base<br />
c:\Program Files\WistaAntivirus\dll\def2.base<br />
c:\Program Files\WistaAntivirus\dll\def3.base<br />
c:\Program Files\WistaAntivirus\dll\immunization.pl<br />
c:\Program Files\WistaAntivirus\dll\license<br />
c:\Program Files\WistaAntivirus\dll\loader.sys<br />
c:\Program Files\WistaAntivirus\dll\privacy.dat<br />
c:\Program Files\WistaAntivirus\dll\realscanner.dll<br />
c:\Program Files\WistaAntivirus\dll\sig1.base<br />
c:\Program Files\WistaAntivirus\dll\sig2.base<br />
c:\Program Files\WistaAntivirus\dll\sigrules.rul
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Wista Antivirus Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\wistaantivirus<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wista Antivirus_is1<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "wistaantivirus"
     </blockquote>
  <p>&nbsp;</p>

</div>
]]></content:encoded>
 </item>

 <item>
	<title>How to uninstall WinAntispyware2008 (Removal Guide)</title>
	<link>http://www.bleepingcomputer.com/malware-removal/uninstall-winantispyware2008</link>
	<pubDate>Sun, 29 Jun 2008 18:52:15 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware]]></category>

	<category><![CDATA[WinAntispyware2008]]></category>

	<guid>http://www.bleepingcomputer.com/malware-removal/uninstall-winantispyware2008</guid>
	<description><![CDATA[WinAntispyware2008 is a rogue anti-spyware program that deliberately 
  displays false information to scare you into purchasing their software. WinAntispyware2008 
  is advertised through web sites pretending to scan your computer for infections. 
  When these fake scans are done, it will state your computer is infected and 
  that you should install WinAntiSpyware2008 in order to ... [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">

 <h1>How to uninstall WinAntispyware2008 (Removal Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/malware-removal/forums/index.php?showuser=3">Grinler</a> on Sun, 29 Jun 2008 18:52:15 EDT &middot; Views: 436</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/uninstall-winantispyware2008', 'How to uninstall WinAntispyware2008 (Removal Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle"></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/uninstall-winantispyware2008', 'How to uninstall WinAntispyware2008 (Removal Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle"></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p> <strong>WinAntispyware2008</strong> is a rogue anti-spyware program that deliberately 
  displays false information to scare you into purchasing their software. WinAntispyware2008 
  is advertised through web sites pretending to scan your computer for infections. 
  When these fake scans are done, it will state your computer is infected and 
  that you should install WinAntiSpyware2008 in order to remove these infections. 
  If you decide to install WinAntiSpyware, the program will automatically start 
  and scan your computer stating that it has found infections that can only be 
  removed if you first purchase the software.</p>
<p>What it does not tell you is that the files it finds are ones that are actually 
  planted on your computer by WinAntispyware2008. When WinAntispyware2008 is installed, 
  it will also copy a variety of harmless files that are dummy infections on to 
  your computer so that WinAntiSpyware 2008 can find them later when it is scanning 
  your computer. These files are:</p>
<blockquote>
  <p><strong>c:\WINDOWS\byfupo.dl<br>
    c:\WINDOWS\jezuro.ban<br>
    c:\WINDOWS\okulyretaq.dl<br>
    c:\WINDOWS\ymanev._sy<br>
    c:\WINDOWS\yqumo.db<br>
    c:\WINDOWS\system32\fuduco.com<br>
    c:\WINDOWS\system32\juporel.vbs<br>
    c:\WINDOWS\system32\retyn.lib<br>
    c:\WINDOWS\system32\roforawav.bin<br>
    c:\WINDOWS\system32\upoceso.ban</strong></p>
</blockquote>
<p>It is important to stress that these files are all harmless and are only there 
  to scare you into thinking you have an actual infection.</p>
<p>
  
</p>
<p>This guide will walk you through removing the WinAntispyware 2008 program and 
  its associated malware for free. </p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/malware-removal/rogue-programs">Information on Rogue Programs</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Add/Remove Programs control panel entry:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/11134/WinAntispyware2008.html">WinAntispyware2008</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [WinAntispyware2008] "C:\Program Files\WinAntispyware2008\WinAntispyware2008.exe" /hide
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/28/08 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for WinAntispyware2008 using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>Download_mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>WinAntispyware2008</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>WinAntispyware 2008</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. <br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/w/winantispyware2008/mbam-winantispyware2008.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>WinAntispyware 2008</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated WinAntispyware2008 Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Application Data\agekav.pif<br />
c:\Documents and Settings\All Users\Application Data\dali.reg<br />
c:\Documents and Settings\All Users\Application Data\myxum.dat<br />
c:\Documents and Settings\All Users\Application Data\rozusug.vbs<br />
c:\Documents and Settings\All Users\Application Data\utimipylof.ban<br />
c:\Documents and Settings\All Users\Documents\ecofubyg.exe<br />
c:\Documents and Settings\All Users\Documents\gilixowa.reg<br />
%UserProfile%\Application Data\ewapili.com<br />
%UserProfile%\Application Data\uwudoj.reg<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAntispyware2008.lnk<br />
%UserProfile%\Cookies\iduf.reg<br />
%UserProfile%\Cookies\jelepyl.inf<br />
%UserProfile%\Cookies\nivo._sy<br />
%UserProfile%\Cookies\umumula._dl<br />
%UserProfile%\Cookies\xagoloq._dl<br />
%UserProfile%\Desktop\WinAntispyware2008.lnk<br />
%UserProfile%\Local Settings\Application Data\adylewu.dl<br />
%UserProfile%\Local Settings\Application Data\ezeh.pif<br />
%UserProfile%\Local Settings\Application Data\usow.db<br />
%UserProfile%\Local Settings\Application Data\ysuzis.bat<br />
%UserProfile%\Start Menu\Programs\WinAntispyware2008<br />
%UserProfile%\Start Menu\Programs\WinAntispyware2008\Uninstall.lnk<br />
%UserProfile%\Start Menu\Programs\WinAntispyware2008\WinAntispyware2008.lnk<br />
c:\Program Files\Common Files\amufy.db<br />
c:\Program Files\Common Files\egogoko.sys<br />
c:\Program Files\WinAntispyware2008<br />
c:\Program Files\WinAntispyware2008\htmlayout.dll<br />
c:\Program Files\WinAntispyware2008\pthreadVC2.dll<br />
c:\Program Files\WinAntispyware2008\Uninstall.exe<br />
c:\Program Files\WinAntispyware2008\WinAntispyware2008.cfg<br />
c:\Program Files\WinAntispyware2008\WinAntispyware2008.dll<br />
c:\Program Files\WinAntispyware2008\WinAntispyware2008.exe<br />
c:\Program Files\WinAntispyware2008\data<br />
c:\Program Files\WinAntispyware2008\data\daily.cvd<br />
c:\Program Files\WinAntispyware2008\Microsoft.VC80.CRT<br />
c:\Program Files\WinAntispyware2008\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest<br />
c:\Program Files\WinAntispyware2008\Microsoft.VC80.CRT\msvcm80.dll<br />
c:\Program Files\WinAntispyware2008\Microsoft.VC80.CRT\msvcp80.dll<br />
c:\Program Files\WinAntispyware2008\Microsoft.VC80.CRT\msvcr80.dll<br />
c:\WINDOWS\byfupo.dl<br />
c:\WINDOWS\jezuro.ban<br />
c:\WINDOWS\okulyretaq.dl<br />
c:\WINDOWS\ymanev._sy<br />
c:\WINDOWS\yqumo.db<br />
c:\WINDOWS\system32\fuduco.com<br />
c:\WINDOWS\system32\juporel.vbs<br />
c:\WINDOWS\system32\retyn.lib<br />
c:\WINDOWS\system32\roforawav.bin<br />
c:\WINDOWS\system32\upoceso.ban
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated WinAntispyware2008 Windows Registry Information:</span></p>
     <blockquote>
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinAntispyware2008<br />
HKEY_LOCAL_MACHINE\SOFTWARE\WinAntispyware2008<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WinAntispyware2008"
     </blockquote>
  <p>&nbsp;</p>

</div>
]]></content:encoded>
 </item>

 <item>
	<title>PestSweeper Removal Guide (Uninstall Instructions)</title>
	<link>http://www.bleepingcomputer.com/malware-removal/pestsweeper-removal</link>
	<pubDate>Sun, 29 Jun 2008 18:29:21 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware]]></category>

	<category><![CDATA[PestSweeper]]></category>

	<guid>http://www.bleepingcomputer.com/malware-removal/pestsweeper-removal</guid>
	<description><![CDATA[Pestsweeper is a rogue anti-spyware program from the same 
  family as SpywareScanner 
  2008. PestSweeper is advertised through the use of misleading advertisements 
  found on web sites that masquerade as anti-malware scanners running on your 
  computer. After the advertisement ... [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">

 <h1>PestSweeper Removal Guide (Uninstall Instructions)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/malware-removal/forums/index.php?showuser=3">Grinler</a> on Sun, 29 Jun 2008 18:29:21 EDT &middot; Views: 133</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/pestsweeper-removal', 'PestSweeper Removal Guide (Uninstall Instructions)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle"></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/pestsweeper-removal', 'PestSweeper Removal Guide (Uninstall Instructions)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle"></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p> <strong>Pestsweeper</strong> is a rogue anti-spyware program from the same 
  family as <a href="http://www.bleepingcomputer.com/malware-removal/spywarescanner-2008-removal">SpywareScanner 
  2008</a>. PestSweeper is advertised through the use of misleading advertisements 
  found on web sites that masquerade as anti-malware scanners running on your 
  computer. After the advertisement finishes, it will imply that you are infected 
  with a variety of infections and that you should download PestSweeper in order 
  to remove these infections. If you decide to download and install PestSweeper, it will automatically scan your computer and display a list of infections 
  that are supposedly on your computer. In reality, though, these are fake infections 
  and are only being displayed to scare you into purchasing the software.</p>
<p>
  
</p>
<p>This guide will walk you through removing the PestSweeper program and 
  its associated malware for free. </p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/malware-removal/rogue-programs">Information on Rogue Programs</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Add/Remove Programs control panel entry:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/11133/PestSweeper-1.0.html">PestSweeper 1.0</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [pestsweeper] C:\Program Files\PestSweeper\pestsweeper.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/29/08 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for PestSweeper using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>Download_mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>PestSweeper</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>PestSweeper</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. <br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/p/pestsweeper/mbam-pestsweeper.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>PestSweeper</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated PestSweeper Files:</span></p>
     <blockquote>
        c:\WINDOWS\system\cmsd.exe<br />
c:\WINDOWS\system\MsWin000.exe<br />
c:\winxplogon.sys<br />
c:\Program Files\PestSweeper<br />
c:\Program Files\PestSweeper\alarm.wav<br />
c:\Program Files\PestSweeper\click.wav<br />
c:\Program Files\PestSweeper\config.cfg<br />
c:\Program Files\PestSweeper\dbinfo<br />
c:\Program Files\PestSweeper\pestsweeper.exe<br />
c:\Program Files\PestSweeper\pestsweeper.url<br />
c:\Program Files\PestSweeper\success.wav<br />
c:\Program Files\PestSweeper\unins000.dat<br />
c:\Program Files\PestSweeper\unins000.exe<br />
c:\Program Files\PestSweeper\dll<br />
c:\Program Files\PestSweeper\dll\def2.base<br />
c:\Program Files\PestSweeper\dll\defbase0.db<br />
c:\Program Files\PestSweeper\dll\defbase1.db<br />
c:\Program Files\PestSweeper\dll\defbase2.db<br />
c:\Program Files\PestSweeper\dll\defbase3.db<br />
c:\Program Files\PestSweeper\dll\defbase4.db<br />
c:\Program Files\PestSweeper\dll\defbase5.db<br />
c:\Program Files\PestSweeper\dll\defbase6.db<br />
c:\Program Files\PestSweeper\dll\defbase7.db<br />
c:\Program Files\PestSweeper\dll\defbase8.db<br />
c:\Program Files\PestSweeper\dll\immunization.pl<br />
c:\Program Files\PestSweeper\dll\license<br />
c:\Program Files\PestSweeper\dll\sig2.base<br />
c:\Program Files\PestSweeper\dll\sigrules.rul<br />
c:\Program Files\PestSweeper\dll\update.scr<br />
%UserProfile%\Desktop\pestsweeper.lnk<br />
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\sav.exe<br />
%UserProfile%\Local Settings\Apps<br />
%UserProfile%\Local Settings\Apps\2.0<br />
%UserProfile%\Local Settings\Apps\2.0\srw94.exe<br />
%UserProfile%\Local Settings\Temp\sav.exe<br />
c:\Documents and Settings\All Users\Start Menu\Programs\PestSweeper<br />
c:\Documents and Settings\All Users\Start Menu\Programs\PestSweeper\pestsweeper on the Web.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\PestSweeper\pestsweeper.lnk<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\pestsweeper.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated PestSweeper Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\pestsweeper<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PestSweeper_is1<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "pestsweeper"
     </blockquote>
  <p>&nbsp;</p>

</div>
]]></content:encoded>
 </item>

 <item>
	<title>How to remove SpywareScanner 2008 (Removal Instructions)</title>
	<link>http://www.bleepingcomputer.com/malware-removal/spywarescanner-2008-removal</link>
	<pubDate>Sun, 29 Jun 2008 17:00:32 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware]]></category>

	<category><![CDATA[SpywareScanner 2008]]></category>

	<guid>http://www.bleepingcomputer.com/malware-removal/spywarescanner-2008-removal</guid>
	<description><![CDATA[SpywareScanner 2008 is a rogue anti-spyware program from 
  the same family as PestSweeper. 
  SpywareScanner 2008 is advertised through the use of deceptive advertising on 
  web sites where they pretend they are scanning your computer and finding infections 
  on it. In reality, though, these are just ... [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">

 <h1>How to remove SpywareScanner 2008 (Removal Instructions)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/malware-removal/forums/index.php?showuser=3">Grinler</a> on Sun, 29 Jun 2008 17:00:32 EDT &middot; Views: 169</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/spywarescanner-2008-removal', 'How to remove SpywareScanner 2008 (Removal Instructions)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle"></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/spywarescanner-2008-removal', 'How to remove SpywareScanner 2008 (Removal Instructions)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle"></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p> <strong>SpywareScanner 2008</strong> is a rogue anti-spyware program from 
  the same family as <a href="http://www.bleepingcomputer.com/malware-removal/pestsweeper-removal">PestSweeper</a>. 
  SpywareScanner 2008 is advertised through the use of deceptive advertising on 
  web sites where they pretend they are scanning your computer and finding infections 
  on it. In reality, though, these are just ads and the web site has no idea what 
  is on your computer. If you decide to install SpywareScanner 2008 it will automatically 
  scan your computer and display a list of infections that are supposedly on your 
  computer. In reality, though, these are fake infections and are only being displayed 
  to scare you into purchasing the software.</p>
<p>
  
</p>
<p>This guide will walk you through removing the SpywareScanner2008 program and 
  its associated malware for free. </p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/malware-removal/rogue-programs">Information on Rogue Programs</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Add/Remove Programs control panel entry:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/11132/SpywareScanner-2008.html">SpywareScanner 2008</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [spywarescanner] C:\Program Files\SpywareScanner\spywarescanner.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/29/08 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for SpywareScanner 2008 using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>Download_mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>SpywareScanner 2008</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>SpywareScanner2008</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. <br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/s/spywarescanner-2008/mbam-spyware-scanner-2008.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>SpywareScanner2008</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated SpywareScanner 2008 Files:</span></p>
     <blockquote>
        %UserProfile%\Desktop\spywarescanner.lnk<br />
c:\Program Files\SpywareScanner<br />
c:\Program Files\SpywareScanner\alarm.wav<br />
c:\Program Files\SpywareScanner\click.wav<br />
c:\Program Files\SpywareScanner\config.cfg<br />
c:\Program Files\SpywareScanner\dbinfo<br />
c:\Program Files\SpywareScanner\spywarescanner.exe<br />
c:\Program Files\SpywareScanner\spywarescanner.url<br />
c:\Program Files\SpywareScanner\success.wav<br />
c:\Program Files\SpywareScanner\unins000.dat<br />
c:\Program Files\SpywareScanner\unins000.exe<br />
c:\Program Files\SpywareScanner\dll<br />
c:\Program Files\SpywareScanner\dll\def2.base<br />
c:\Program Files\SpywareScanner\dll\defbase0.db<br />
c:\Program Files\SpywareScanner\dll\defbase1.db<br />
c:\Program Files\SpywareScanner\dll\defbase2.db<br />
c:\Program Files\SpywareScanner\dll\defbase3.db<br />
c:\Program Files\SpywareScanner\dll\defbase4.db<br />
c:\Program Files\SpywareScanner\dll\defbase5.db<br />
c:\Program Files\SpywareScanner\dll\defbase6.db<br />
c:\Program Files\SpywareScanner\dll\defbase7.db<br />
c:\Program Files\SpywareScanner\dll\defbase8.db<br />
c:\Program Files\SpywareScanner\dll\immunization.pl<br />
c:\Program Files\SpywareScanner\dll\license<br />
c:\Program Files\SpywareScanner\dll\sig2.base<br />
c:\Program Files\SpywareScanner\dll\sigrules.rul<br />
c:\Program Files\SpywareScanner\dll\update.scr<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SpywareScanner<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SpywareScanner\spywarescanner on the Web.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SpywareScanner\spywarescanner.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SpywareScanner\Uninstall spywarescanner.lnk<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\spywarescanner.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated SpywareScanner 2008 Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\spywarescanner<br />
HKEY_CURRENT_USER\Software\SpywareScanner2008<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareScanner 2008_is1<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "spywarescanner"
     </blockquote>
  <p>&nbsp;</p>

</div>
]]></content:encoded>
 </item>

 <item>
	<title>How to remove Antivirus 2009 (Uninstall Instructions)</title>
	<link>http://www.bleepingcomputer.com/malware-removal/uninstall-antivirus-2009</link>
	<pubDate>Sat, 28 Jun 2008 15:59:23 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware]]></category>

	<category><![CDATA[Antivirus 2009]]></category>

	<guid>http://www.bleepingcomputer.com/malware-removal/uninstall-antivirus-2009</guid>
	<description><![CDATA[Antivirus 2009 is a new rogue anti-spyware program from the 
  same family as Antivirus 
  2008 and Doctor 
  Antivirus . Antivirus 2009 is installed and advertised through the use of 
  misleading web sites that attempt to make you think your computer is infected 
  with a variety of malware. Once installed [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">

 <h1>How to remove Antivirus 2009 (Uninstall Instructions)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/malware-removal/forums/index.php?showuser=3">Grinler</a> on Sat, 28 Jun 2008 15:59:23 EDT &middot; Views: 2921</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/uninstall-antivirus-2009', 'How to remove Antivirus 2009 (Uninstall Instructions)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle"></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/uninstall-antivirus-2009', 'How to remove Antivirus 2009 (Uninstall Instructions)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle"></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p> <strong>Antivirus 2009</strong> is a new rogue anti-spyware program from the 
  same family as <a href="http://www.bleepingcomputer.com/malware-removal/antivirus-2008">Antivirus 
  2008</a> and <a href="http://www.bleepingcomputer.com/malware-removal/remove-doctor-antivirus-2008">Doctor 
  Antivirus </a>. Antivirus 2009 is installed and advertised through the use of 
  misleading web sites that attempt to make you think your computer is infected 
  with a variety of malware. Once installed, Antivirus 2009 will scan your computer 
  and list a variety of fake infections that can't be removed unless you first 
  purchase the software. These infections are fake, though, and only being shown 
  to scare you into purchasing the software.</p>
<p>When Antivirus 2009 is installed, a Internet Explorer browser helper object 
  is also installed that displays fake messages when using Internet Explorer. 
  These messages range from a line at the top of the browser stating an infection 
  was found to adding a box to the Google homepage stating Google detected that 
  your computer was infected. These tactics are just two more methods where Antivirus 
  2009 uses false information to scare you into purchasing their software. A more 
  detailed writeup on how the Google home page is hijacked can be found <a href="http://www.bleepingcomputer.com/forums/topic154973.html">here</a>.</p>
<p>
  
</p>
  
<p>This guide will walk you through removing the Antivirus 2009 program and 
  its associated malware for free. </p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/malware-removal/rogue-programs">Information on Rogue Programs</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	Note: Some of these entries are random named.<br />
<br />
O2 - BHO: &Research - {037C7B8A-151A-49E6-BAED-CC05FCB50328} - C:\WINDOWS\system32\winsrc.dll<br />
O4 - HKCU\..\Run: [75319611769193918898704537500611] C:\Program Files\Antivirus 2009\av2009.exe<br />
O4 - HKCU\..\Run: [ieupdate] "C:\WINDOWS\system32\ieupdates.exe"
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/28/08 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Antivirus 2009 using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>Download_mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Antivirus 2009</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>Antivirus 2009</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. <br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/results-page.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Antivirus 2009</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Antivirus 2009 Files:</span></p>
     <blockquote>
        Note: Some of these entries are random named.<br />
<br />
%UserProfile%\Desktop\Antivirus 2009.lnk<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk<br />
%UserProfile%\Local Settings\Temporary Internet Files\Content.IE5\S96PZM7V\winsrc[1].dll<br />
%UserProfile%\Start Menu\Antivirus 2009<br />
%UserProfile%\Start Menu\Antivirus 2009\Antivirus 2009.lnk<br />
%UserProfile%\Start Menu\Antivirus 2009\Uninstall Antivirus 2009.lnk<br />
c:\Program Files\Antivirus 2009<br />
c:\Program Files\Antivirus 2009\av2009.exe<br />
c:\WINDOWS\system32\ieupdates.exe<br />
c:\WINDOWS\system32\scui.cpl<br />
c:\WINDOWS\system32\winsrc.dll
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Antivirus 2009 Windows Registry Information:</span></p>
     <blockquote>
        Note: Some of these entries are random named.<br />
<br />
HKEY_CURRENT_USER\Software\75319611769193918898704537500611<br />
HKEY_CLASSES_ROOT\CLSID\{037C7B8A-151A-49E6-BAED-CC05FCB50328}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{037C7B8A-151A-49E6-BAED-CC05FCB50328}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "75319611769193918898704537500611"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "ieupdate"
     </blockquote>
  <p>&nbsp;</p>

</div>
]]></content:encoded>
 </item>

 <item>
	<title>How to remove Doctor Antivirus 2008</title>
	<link>http://www.bleepingcomputer.com/malware-removal/remove-doctor-antivirus-2008</link>
	<pubDate>Sat, 28 Jun 2008 15:43:12 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware]]></category>

	<category><![CDATA[Doctor Antivirus 2008]]></category>

	<guid>http://www.bleepingcomputer.com/malware-removal/remove-doctor-antivirus-2008</guid>
	<description><![CDATA[Doctor Antivirus 2008 is a new rogue anti-spyware program 
  from the same family as Antivirus 
  2008 and Antivirus 
  2009. When installed, Doctor Antivirus will scan your computer and list 
  a variety of infections found on your computer. In order to remove any of these 
  infections, though, you must first purchase the software. The problem is that 
  all of the infections Doctor Antivirus states ... [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">

 <h1>How to remove Doctor Antivirus 2008</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/malware-removal/forums/index.php?showuser=3">Grinler</a> on Sat, 28 Jun 2008 15:43:12 EDT &middot; Views: 461</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/remove-doctor-antivirus-2008', 'How to remove Doctor Antivirus 2008');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle"></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/remove-doctor-antivirus-2008', 'How to remove Doctor Antivirus 2008');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle"></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p> <strong>Doctor Antivirus 2008</strong> is a new rogue anti-spyware program 
  from the same family as <a href="http://www.bleepingcomputer.com/malware-removal/antivirus-2008">Antivirus 
  2008</a> and <a href="http://www.bleepingcomputer.com/malware-removal/remove-antivirus-2009">Antivirus 
  2009</a>. When installed, Doctor Antivirus will scan your computer and list 
  a variety of infections found on your computer. In order to remove any of these 
  infections, though, you must first purchase the software. The problem is that 
  all of the infections Doctor Antivirus states are on your computer, are actually 
  harmless or do not even exist. The only reason why they are being displayed 
  is to scare you into purchasing the program.</p>
<p>
  
</p>
  
<p>This guide will walk you through removing the Doctor Antivirus 2008 program and 
  its associated malware for free. </p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/malware-removal/rogue-programs">Information on Rogue Programs</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [Doctor Antivirus 2008] C:\Documents and Settings\BC\Desktop\antvr.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/28/08 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Doctor Antivirus 2008 using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>Download_mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Doctor Antivirus 2008</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>Doctor Antivirus 2008</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. <br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/results-page.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Doctor Antivirus 2008</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Doctor Antivirus 2008 Files:</span></p>
     <blockquote>
        %UserProfile%\Desktop\antvr.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Doctor Antivirus 2008 Windows Registry Information:</span></p>
     <blockquote>
        HKEY_LOCAL_MACHINE\SOFTWARE\Doctor2008<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Doctor Antivirus 2008"
     </blockquote>
  <p>&nbsp;</p>

</div>
]]></content:encoded>
 </item>

 <item>
	<title>How to uninstall WinX Security Center (Removal Guide)</title>
	<link>http://www.bleepingcomputer.com/malware-removal/uninstall-winx-security-center </link>
	<pubDate>Wed, 25 Jun 2008 17:11:12 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware]]></category>

	<category><![CDATA[WinX Security Center]]></category>

	<guid>http://www.bleepingcomputer.com/malware-removal/uninstall-winx-security-center </guid>
	<description><![CDATA[WinX Security Center is a new rogue anti-spyware program 
  that is advertised through misleading web sites and popups. When visiting certain 
  web sites, you may be presented with a popup stating that your computer is infected 
  and that you should download and install WinX Security Center in order to clean 
  your computer. If you decide to install the software, Winx Security Center will 
  automatically start and scan your [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">

 <h1>How to uninstall WinX Security Center (Removal Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/malware-removal/forums/index.php?showuser=3">Grinler</a> on Wed, 25 Jun 2008 17:11:12 EDT &middot; Views: 241</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/uninstall-winx-security-center ', 'How to uninstall WinX Security Center (Removal Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle"></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/uninstall-winx-security-center ', 'How to uninstall WinX Security Center (Removal Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle"></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p> <strong>WinX Security Center</strong> is a new rogue anti-spyware program 
  that is advertised through misleading web sites and popups. When visiting certain 
  web sites, you may be presented with a popup stating that your computer is infected 
  and that you should download and install WinX Security Center in order to clean 
  your computer. If you decide to install the software, Winx Security Center will 
  automatically start and scan your computer. When the scan has been completed, 
  you will be shown a list of security risks on your computer that can only be 
  removed if you first purchase the software. What it does not tell you, though, 
  is that all of these supposed security risks are in fact legitimate programs 
  being flagged as infections in order to scare you into purchasing the software.</p>
<p>
  
</p>
  
<p>This guide will walk you through removing the WinX Security Center program and 
  its associated malware for free. </p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/malware-removal/rogue-programs">Information on Rogue Programs</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O2 - BHO: (no name) - {F3642B57-3EA8-4EEA-A643-9DE138381A57} - C:\Program Files\WinX Security Center\redir.dll<br />
O4 - HKCU\..\Run: [WinX Security Center] C:\Program Files\WinX Security Center\WinX Security Center.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/25/08 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for WinX Security Center using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>Download_mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>WinX Security Center</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>WinX Security Center</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. <br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/w/winx-security-center/mbam-winx-security-center.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>WinX Security Center</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated WinX Security Center Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Start Menu\Programs\WinX Security Center<br />
c:\Documents and Settings\All Users\Start Menu\Programs\WinX Security Center\Purchase License.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\WinX Security Center\Start WinX Security Center.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\WinX Security Center\Support Page.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\WinX Security Center\WinX Security Center Uninstall.lnk<br />
c:\Documents and Settings\forensics\Application Data\WinX Security Center<br />
c:\Documents and Settings\forensics\Application Data\WinX Security Center\base.dat<br />
c:\Documents and Settings\forensics\Application Data\WinX Security Center\base2.dat<br />
c:\Documents and Settings\forensics\Application Data\WinX Security Center\Desc.dat<br />
c:\Documents and Settings\forensics\Application Data\WinX Security Center\spline.dat<br />
c:\Documents and Settings\forensics\Application Data\WinX Security Center\WinX Security Center.ini<br />
c:\Documents and Settings\forensics\Desktop\WinX Security Center.lnk<br />
c:\Program Files\WinX Security Center<br />
c:\Program Files\WinX Security Center\Buy.url<br />
c:\Program Files\WinX Security Center\Help.url<br />
c:\Program Files\WinX Security Center\HowToBuy.txt<br />
c:\Program Files\WinX Security Center\License.txt<br />
c:\Program Files\WinX Security Center\redir.dll<br />
c:\Program Files\WinX Security Center\Restart.exe<br />
c:\Program Files\WinX Security Center\Uninstall.exe<br />
c:\Program Files\WinX Security Center\WinX Security Center.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated WinX Security Center Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CLASSES_ROOT\CLSID\{F3642B57-3EA8-4EEA-A643-9DE138381A57}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3642B57-3EA8-4EEA-A643-9DE138381A57}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WinX Security Center"
     </blockquote>
  <p>&nbsp;</p>

</div>
]]></content:encoded>
 </item>

 <item>
	<title>How to remove Antivirus XP 2008 (Uninstall Instructions)</title>
	<link>http://www.bleepingcomputer.com/malware-removal/remove-antivirus-xp-2008</link>
	<pubDate>Wed, 25 Jun 2008 15:45:58 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware]]></category>

	<category><![CDATA[Antivirus XP 2008]]></category>

	<guid>http://www.bleepingcomputer.com/malware-removal/remove-antivirus-xp-2008</guid>
	<description><![CDATA[Antivirus XP 2008 is a new rogue anti-spyware program that 
  is advertised through Trojans and other malware. It is advertised in the form 
  of fake security alerts and warnings on web sites that state you are infected 
  with malware or are being attacked in some manner. When you click on these ads, 
  it will automatically download the ... [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">

 <h1>How to remove Antivirus XP 2008 (Uninstall Instructions)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/malware-removal/forums/index.php?showuser=3">Grinler</a> on Wed, 25 Jun 2008 15:45:58 EDT &middot; Views: 9300</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/remove-antivirus-xp-2008', 'How to remove Antivirus XP 2008 (Uninstall Instructions)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle"></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/remove-antivirus-xp-2008', 'How to remove Antivirus XP 2008 (Uninstall Instructions)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle"></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p> <strong>Antivirus XP 2008</strong> is a new rogue anti-spyware program that 
  is advertised through Trojans and other malware. It is advertised in the form 
  of fake security alerts and warnings on web sites that state you are infected 
  with malware or are being attacked in some manner. When you click on these ads, 
  it will automatically download the installer for Antivirus XP 2008 and install 
  it on your machine. In some cases, this program is installed without any intervention 
  at all from you.</p>
<p>Once installed, Antivirus XP 2008 will scan your computer and display a variety 
  of security risks found on your computer that can only be removed if you purchase 
  a license of the software. These risks, though, are all fake and are only being 
  displayed to scare you into thinking you are infected and thus purchase their 
  software. Another tactic that Antivirus XP 2008, and the accompanied malware, 
  uses is to change your desktop background to be a message stating you are infected, 
  popups and fake alerts stating your computer is being attacked, and a fake Internet 
  Explorer page that states Google has found your computer to be infected. All 
  of these are further scare tactics and should be ignored. These methods are 
  all illustrated in the images below.</p>
<p>
  
</p>
  
<p>This guide will walk you through removing the Antivirus XP 2008 program and 
  its associated malware for free. </p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/malware-removal/rogue-programs">Information on Rogue Programs</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Add/Remove Programs control panel entry:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/11067/AntivirXP08.html">AntivirXP08</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [antivirus-2008pro.exe] C:\Program Files\Antivirus 2008 PRO\antivirus-2008pro.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/25/08 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Antivirus XP 2008 using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>Download_mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Antivirus XP 2008</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>AntivirusXP2008</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. <br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/a/antivirus-xp-2008/mbam-antivirus-xp-2008.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>AntivirusXP2008</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Antivirus XP 2008 Files:</span></p>
     <blockquote>
        Note, Some of these files and folders may be random:<br />
<br />
C:\WINDOWS\qegbdmwf.dll<br />
C:\WINDOWS\pntqkflv.dll<br />
c:\Program Files\rhcnkrj0etfg<br />
c:\Program Files\rhcnkrj0etfg\database.dat<br />
c:\Program Files\rhcnkrj0etfg\license.txt<br />
c:\Program Files\rhcnkrj0etfg\MFC71.dll<br />
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL<br />
c:\Program Files\rhcnkrj0etfg\msvcp71.dll<br />
c:\Program Files\rhcnkrj0etfg\msvcr71.dll<br />
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe<br />
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local<br />
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfgSkin.dll<br />
c:\Program Files\rhcnkrj0etfg\Uninstall.exe<br />
c:\WINDOWS\system32\pphcjkrj0etfg.exe<br />
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk<br />
%UserProfile%\Application Data\rhcnkrj0etfg<br />
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine<br />
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun<br />
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\HKCU<br />
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\HKCU\RunOnce<br />
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\HKLM<br />
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\HKLM\RunOnce<br />
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\StartMenuAllUsers<br />
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\StartMenuCurrentUser<br />
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\BrowserObjects<br />
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Packages
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Antivirus XP 2008 Windows Registry Information:</span></p>
     <blockquote>
        Note, Some of these Registry keys and values may be random:<br />
<br />
HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhcnkrj0etfg<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion "rhcnkrj0etfg"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform "AntivirXP08"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SMrhcnkrj0etfg"
     </blockquote>
  <p>&nbsp;</p>

</div>
]]></content:encoded>
 </item>

 <item>
	<title>How to remove Advanced Antivirus (Removal Instructions)</title>
	<link>http://www.bleepingcomputer.com/malware-removal/remove-advanced-antivirus</link>
	<pubDate>Thu, 19 Jun 2008 14:30:21 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware]]></category>

	<category><![CDATA[Advanced Antivirus]]></category>

	<guid>http://www.bleepingcomputer.com/malware-removal/remove-advanced-antivirus</guid>
	<description><![CDATA[Advanced Antivirus is a rogue anti-spyware program from the 
  same family as Ultimate 
  Antivirus 2008, Vista 
  Antivirus 2008, and Windows 
  Antivirus 2008. Once installed, Advanced Antivirus will perform a scan and 
  display a list of security risks found on your computer. These infections which 
  are all fake and false positives, though, cannot be removed unless you first 
  purchase a license of the software. They show these ... [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">

 <h1>How to remove Advanced Antivirus (Removal Instructions)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/malware-removal/forums/index.php?showuser=3">Grinler</a> on Thu, 19 Jun 2008 14:30:21 EDT &middot; Views: 1133</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/remove-advanced-antivirus', 'How to remove Advanced Antivirus (Removal Instructions)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle"></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/remove-advanced-antivirus', 'How to remove Advanced Antivirus (Removal Instructions)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle"></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p> <strong>Advanced Antivirus</strong> is a rogue anti-spyware program from the 
  same family as <a href="http://www.bleepingcomputer.com/malware-removal/ultimate-antivirus-2008">Ultimate 
  Antivirus 2008</a>, <a href="http://www.bleepingcomputer.com/malware-removal/remove-vista-antivirus-2008">Vista 
  Antivirus 2008</a>, and <a href="http://www.bleepingcomputer.com/malware-removal/remove-windows-antivirus-2008">Windows 
  Antivirus 2008</a>. Once installed, Advanced Antivirus will perform a scan and 
  display a list of security risks found on your computer. These infections which 
  are all fake and false positives, though, cannot be removed unless you first 
  purchase a license of the software. They show these infections to scare you 
  into thinking you are infected and hope that you will then buy their software. 
  Another tactic they also perform is to show fake warnings that your computer 
  is being attacked and that you should purchase Advanced Antivirus in order to 
  protect yourself. This is just another scare tactic and should be ignored.</p>
<p>
  
</p>
  
<p>This guide will walk you through removing the AdvancedAntivirus program and 
  any related malware.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/malware-removal/rogue-programs">Information on Rogue Programs</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [Antivirus] C:\Program Files\AAV\aav.exe<br />
O4 - HKCU\..\Run: [Antivirus] C:\Program Files\AAV\aav.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/19/08 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Advanced Antivirus using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>Download_mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Advanced Antivirus</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>AdvancedAntivirus</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. <br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/results-page.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>AdvancedAntivirus</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Advanced Antivirus Files:</span></p>
     <blockquote>
        c:\Program Files\AAV<br />
c:\Program Files\AAV\aav.cpl<br />
c:\Program Files\AAV\aav.exe<br />
c:\Program Files\AAV\aav0.dat<br />
c:\Program Files\AAV\aav1.dat<br />
c:\WINDOWS\system32\aav.cpl<br />
c:\Documents and Settings\Bleeping\Desktop\Advanced Antivirus.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Advanced Antivirus Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CLASSES_ROOT\.key<br />
HKEY_CURRENT_USER\Software\AAV<br />
HKEY_CURRENT_USER\Software\AntiVirus<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Antivirus"
     </blockquote>
  <p>&nbsp;</p>

</div>
]]></content:encoded>
 </item>

 <item>
	<title>How to remove WinSpywareProtect (Removal Instructions)</title>
	<link>http://www.bleepingcomputer.com/malware-removal/remove-winspywareprotect</link>
	<pubDate>Tue, 17 Jun 2008 16:27:32 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware]]></category>

	<category><![CDATA[WinSpywareProtect]]></category>

	<guid>http://www.bleepingcomputer.com/malware-removal/remove-winspywareprotect</guid>
	<description><![CDATA[WinSpywareProtect is a rogue anti-spyware program, that once 
  installed, will automatically scan your computer and list a variety of fake 
  results and false positives that cannot be removed unless you first purchase 
  the software. The tactic of showing supposed infections and requiring you to 
  purchase the software in order to remove them is simply a scare tactic and should 
  be ignored. Instead use a legitimate program, like ... [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">

 <h1>How to remove WinSpywareProtect (Removal Instructions)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/malware-removal/forums/index.php?showuser=3">Grinler</a> on Tue, 17 Jun 2008 16:27:32 EDT &middot; Views: 2400</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/remove-winspywareprotect', 'How to remove WinSpywareProtect (Removal Instructions)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle"></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/malware-removal/http://www.bleepingcomputer.com/malware-removal/remove-winspywareprotect', 'How to remove WinSpywareProtect (Removal Instructions)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle"></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p> <strong>WinSpywareProtect</strong> is a rogue anti-spyware program, that once 
  installed, will automatically scan your computer and list a variety of fake 
  results and false positives that cannot be removed unless you first purchase 
  the software. The tactic of showing supposed infections and requiring you to 
  purchase the software in order to remove them is simply a scare tactic and should 
  be ignored. Instead use a legitimate program, like the one below, to clean your 
  computer of this software and any related malware that may have been installed 
  with it. While WinSpywareProtect is running, you may also see fake Windows Security 
  Center alerts and warnings stating that your computer has an active infection 
  or that you are being attacked. These too can be ignored as they are just another 
  scare tactic.</p>
<p>&nbsp;</p>
<p>
  
</p>
  
<p>This guide will walk you through removing the WinSpywareProtect program and 
  any related malware.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/malware-removal/rogue-programs">Information on Rogue Programs</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Add/Remove Programs control panel entry:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/10865/LabelCommand.html">LabelCommand</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O2 - BHO: LabelCommand module - {18CB1A7B-94CD-4582-8022-ADA16851E44B} - C:\Program Files\LabelCommand\LabelCommand.dll<br />
O4 - HKCU\..\Run: [C:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\winspywareprotect.exe] "C:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\winspywareprotect.exe" /autorun
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/17/08 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for WinSpywareProtect using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>Download_mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>WinSpywareProtect</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>WinSpywareProtect</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. <br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/w/winspywareprotect/mbam-winspywareprotect.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>WinSpywareProtect</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated WinSpywareProtect Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Application Data\ADSL Software Limited<br />
c:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect<br />
c:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\winspywareprotect.exe<br />
c:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\BASE<br />
c:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\DELETED<br />
c:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\LOG<br />
c:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\LOG\20080617111154889.log<br />
c:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\SAVED<br />
%UserProfile%\Local Settings\Temp\_addon.exe<br />
%UserProfile%\Local Settings\Temp\temp.dll<br />
c:\Program Files\LabelCommand<br />
c:\Program Files\LabelCommand\LabelCommand.dll<br />
c:\Program Files\LabelCommand\uninstall.dat<br />
c:\Program Files\LabelCommand\Uninstall.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated WinSpywareProtect Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\ADSL Software Limited<br />
HKEY_CURRENT_USER\Software\LabelCommand<br />
HKEY_CLASSES_ROOT\CLSID\{18CB1A7B-94CD-4582-8022-ADA16851E44B}<br />
HKEY_CLASSES_ROOT\TypeLib\{8B8DF25F-2C47-4473-8E1C-7F54AC7EF481}\<br />
HKEY_CLASSES_ROOT\LabelCommand.LabelCommand<br />
HKEY_CLASSES_ROOT\LabelCommand.LabelCommand.1<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18CB1A7B-94CD-4582-8022-ADA16851E44B}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7C4BCD17-BDBA-4078-9D8C-8CA8B7EABE77}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "C:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\winspywareprotect.exe"
     </blockquote>
  <p>&nbsp;</p>

</div>
]]></content:encoded>
 </item>

</channel>
</rss>