Subscribe to Malware Help RSS Feed RSS Feed - Subscribe to Malware Help. Org on Twitter Follow on Twitter - Malware Help YouTube Channel YouTube Channel - Subscribe to Malware Help by Email Subscribe by Email

Antispyware Pro XP Analysis and Removal

by Shanmuga| Tweet This | Google +1 | Facebook | Stumble It | Reddit | Digg |

Antispyware Pro XP or Anti spyware Pro XP is one of the many variants belonging to the family of rogue security software. The following is an account of my experience with this rogue.

Antispyware Pro XP

What is a rogue security software, rogue anti-spyware, rogue anti-virus or rogue anti-malware software?

A family of software products that call themselves as antivirus, antispyware or registry cleaners and often use deceptive or high pressure sales tactics and deliberate false positives to convince users into buying a license/subscription. They are often repackaged and renamed. They do not actually remove malware instead many of them add more malware of their own.

Note: Visiting any of the malware hosting domains mentioned below may be injurious to the health of your computer system.

Analysis of Antispyware Pro XP Installation

This rogue mimics a online spyware scan at (IP based in Ukraine), once the fake scan is run it displays fraudulent false positives and persuades the users’ to download an installer setup_1_1_.exe of size 90.50 KB VirusTotal info: File setup_1_1_.exe received on 09.23.2008 10:02:01 (CET) Result: 7/36 (19.44%) from (IP based in Latvia).

Then the following Internet Connections were established:


An adware mxlivemedia browser enhancer ( which may serve advertisements even while you are not surfing the Internet ) is downloaded and installed as identified by the following HijackThis entries:

  • O2 – BHO: mxlivemedia browser enhancer – {70501665-0202-d505-1a1a-e0112ba2560f} – C:WINDOWSsystem32fcwsqamokaehjnw.dll
  • O4 – HKLM..Run: [wtuehxugvpph] C:WINDOWSSystem32Rundll32.exe “C:WINDOWSsystem32fcwsqamokaehjnw.dll” EntryPoint

The payment processor for this rogue security software is (IP )notorious for peddling rogue security software. This domain is registered to Markus Lulmann via SRSPlus Private Registration.

Antispyware Pro XP – Associated Files and Folders

  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XP
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPBASE
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPDELETED
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPLOG
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPSAVED
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPasproxp.exe
  • C:Documents and SettingsAll UsersApplication DataSoftware LicensorsAntispyware PRO XPLOG20080923130552480.log

Antispyware Pro XP – Associated Registry keys and values

  • HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRuns9201
  • HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwtuehxugvpph
  • HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{70501665-0202-d505-1a1a-e0112ba2560f}
  • HKCRCLSID{70501665-0202-D505-1A1A-E0112BA2560F}
  • HKCRCLSID{70501665-0202-D505-1A1A-E0112BA2560F}InProcServer32
  • HKCRCLSID{70501665-0202-D505-1A1A-E0112BA2560F}InProcServer32#ThreadingModel
  • HKUS-1-5-21-746137067-776561741-1417001333-1003SoftwareSoftware LicensorsAntispyware PRO XP

Note: File names may be randomly generated.

Antispyware Pro XP – Associated Domains


Antispyware Pro XP – Removal

I ran the scans with 5 of the most widely used FREE anti spyware software…after updating them with the latest definitions…the results speak for themselves.

Spybot – Search & Destroy

Spybot - Search & Destroy

Poor performance, found only the tracking cookies…not the rogue Antispyware Pro XP or the adware mxlivemedia browser enhancer.

Ad-Aware 2008

Ad-aware 2008

A smart scan with Ad-Aware 2008 turned up the rogue and tracking cookies but not the adware.

a-squared Free 3.5

a squared free

A smart scan with a-squared Free 3.5 turned up only the registry entries, tracking cookies but not the actual malware .dll or .exe files.

SuperAntiSpyware Free Edition

superantispyware free edition

A quick scan with SuperAntiSpyware Free Edition did a great job rooting out the evil .dll, .exe, registry traces, the adware and the tracking cookies. It required a reboot to complete the cleaning process, but it failed to delete the rogue softwares’ program files folder and files and clean the autostart registry entry HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwtuehxugvpph leading to the following prompt on reboot:


Malwarebytes’ Anti-Malware

A quick scan with Malwarebytes’ Anti-Malware was thorough in cleaning the malware files, registry traces and the tracking cookies with out a reboot.

malwarebytes antimalware

I recommend using Malwarebytes’ Anti-Malware Free version for cleaning Antispyware Pro XP.

I further used CCleaner to clear the temporary and cache files of Windows and my browsers and I also disabled the system restore to wipe out the remnants of rogueware from the restore files and re-enabled it back.

If you still have popups or other symptoms after running the automated malware scans, please post your problem at one of the Recommended Online Forums for Malware Help.

Antispyware Pro XP – Rogue Gallery

Antispyware Pro XP – Video

Note: The content provided in this article is not warranted or guaranteed by Malware Help. Org. The content provided is intended for entertainment and/or educational purposes. I am not liable for any negative consequences that may result from implementing any information covered in this article. The above information is correct at the time of my testing, it might change with time and or different testing conditions.

{ 0 comments… add one now }

Leave a Comment

{ 1 trackback }

Previous post:

Next post: