Subscribe to Malware Help RSS Feed RSS Feed - Subscribe to Malware Help. Org on Twitter Follow on Twitter - Malware Help YouTube Channel YouTube Channel - Subscribe to Malware Help by Email Subscribe by Email

Antispyware Pro XP Analysis and Removal

by Shanmuga| Tweet This | Google +1 | Facebook | Stumble It | Reddit | Digg | del.icio.us

Antispyware Pro XP or Anti spyware Pro XP is one of the many variants belonging to the family of rogue security software. The following is an account of my experience with this rogue.

antispyware pro xp019a Antispyware Pro XP Analysis and Removal

What is a rogue security software, rogue anti-spyware, rogue anti-virus or rogue anti-malware software?

A family of software products that call themselves as antivirus, antispyware or registry cleaners and often use deceptive or high pressure sales tactics and deliberate false positives to convince users into buying a license/subscription. They are often repackaged and renamed. They do not actually remove malware instead many of them add more malware of their own.

Note: Visiting any of the malware hosting domains mentioned below may be injurious to the health of your computer system.

Analysis of Antispyware Pro XP Installation

This rogue mimics a online spyware scan at scan.antispyware-free-scanner.com (IP 78.26.179.230 based in Ukraine), once the fake scan is run it displays fraudulent false positives and persuades the users’ to download an installer setup_1_1_.exe of size 90.50 KB VirusTotal info: File setup_1_1_.exe received on 09.23.2008 10:02:01 (CET) Result: 7/36 (19.44%) from files.as-pro-xp-download.com (IP 78.157.142.79 based in Latvia).

Then the following Internet Connections were established:

  • 85.92.157.141/mxlivemedia/get_file.php
  • int.azsxdcqwe.com/stat.php?func=install&pid=1&ip=127.0.0.1&landing=1&subid=0&progid=MXwwfDAwMDZGRDM4
  • 85.92.157.141/mxlivemedia/multi/11.exe
  • a1.mxlivemedia.com/bc/123kah.php

An adware mxlivemedia browser enhancer ( which may serve advertisements even while you are not surfing the Internet ) is downloaded and installed as identified by the following HijackThis entries:

  • O2 – BHO: mxlivemedia browser enhancer – {70501665-0202-d505-1a1a-e0112ba2560f} – C:WINDOWSsystem32fcwsqamokaehjnw.dll
  • O4 – HKLM..Run: [wtuehxugvpph] C:WINDOWSSystem32Rundll32.exe “C:WINDOWSsystem32fcwsqamokaehjnw.dll” EntryPoint

The payment processor for this rogue security software is secure.paymentbit.net (IP 216.195.56.148 )notorious for peddling rogue security software. This domain is registered to Markus Lulmann via SRSPlus Private Registration.

Antispyware Pro XP – Associated Files and Folders

  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XP
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPBASE
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPDELETED
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPLOG
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPSAVED
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPasproxp.exe
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPLOG20080923130552480.log
  • C:WINDOWSSYSTEM32FCWSQAMOKAEHJNW.DLL

Antispyware Pro XP – Associated Registry keys and values

  • HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRuns9201
  • HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwtuehxugvpph
  • HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{70501665-0202-d505-1a1a-e0112ba2560f}
  • HKCRCLSID{70501665-0202-D505-1A1A-E0112BA2560F}
  • HKCRCLSID{70501665-0202-D505-1A1A-E0112BA2560F}InProcServer32
  • HKCRCLSID{70501665-0202-D505-1A1A-E0112BA2560F}InProcServer32#ThreadingModel
  • HKUS-1-5-21-746137067-776561741-1417001333-1003SoftwareSoftware LicensorsAntispyware PRO XP

Note: File names may be randomly generated.

Antispyware Pro XP – Associated Domains

  • antispyware-pro-xp.com
  • scan.proxp.com
  • scan.antispyware-free-scanner.com
  • files.as-pro-xp-download.com
  • 85.92.157.141
  • int.azsxdcqwe.com
  • sales.buy-antispyware-pro-xp.com
  • int.mjnhbgvf.com
  • secure.paymentbit.net

Antispyware Pro XP – Removal

I ran the scans with 5 of the most widely used FREE anti spyware software…after updating them with the latest definitions…the results speak for themselves.

Spybot – Search & Destroy

antispyware pro xp029 Antispyware Pro XP Analysis and Removal

Poor performance, found only the tracking cookies…not the rogue Antispyware Pro XP or the adware mxlivemedia browser enhancer.

Ad-Aware 2008

antispyware pro xp027 Antispyware Pro XP Analysis and Removal

A smart scan with Ad-Aware 2008 turned up the rogue and tracking cookies but not the adware.

a-squared Free 3.5

antispyware pro xp038 Antispyware Pro XP Analysis and Removal

A smart scan with a-squared Free 3.5 turned up only the registry entries, tracking cookies but not the actual malware .dll or .exe files.

SuperAntiSpyware Free Edition

antispyware pro xp031 Antispyware Pro XP Analysis and Removal

A quick scan with SuperAntiSpyware Free Edition did a great job rooting out the evil .dll, .exe, registry traces, the adware and the tracking cookies. It required a reboot to complete the cleaning process, but it failed to delete the rogue softwares’ program files folder and files and clean the autostart registry entry HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwtuehxugvpph leading to the following prompt on reboot:

antispyware pro xp040 Antispyware Pro XP Analysis and Removal

Malwarebytes’ Anti-Malware

A quick scan with Malwarebytes’ Anti-Malware was thorough in cleaning the malware files, registry traces and the tracking cookies with out a reboot.

antispyware pro xp030 Antispyware Pro XP Analysis and Removal

I recommend using Malwarebytes’ Anti-Malware Free version for cleaning Antispyware Pro XP.

I further used CCleaner to clear the temporary and cache files of Windows and my browsers and I also disabled the system restore to wipe out the remnants of rogueware from the restore files and re-enabled it back.

If you still have popups or other symptoms after running the automated malware scans, please post your problem at one of the Recommended Online Forums for Malware Help.

Antispyware Pro XP – Rogue Gallery

Antispyware Pro XP – Video

Note: The content provided in this article is not warranted or guaranteed by Malware Help. Org. The content provided is intended for entertainment and/or educational purposes. I am not liable for any negative consequences that may result from implementing any information covered in this article. The above information is correct at the time of my testing, it might change with time and or different testing conditions.

You may also like to read



{ 0 comments… add one now }

Leave a Comment

{ 1 trackback }

Previous post:

Next post: