Subscribe: Subscribe to Malware Help. Org Full Post Feed Subscribe to Malware Help. Org Summary Feed

Custom Search
Search more than 150 trusted Websites for related information.

Safety Anti-Spyware Analysis and Removal

December 17, 2009 by Shanmuga  
Filed under Featured, Rogue Security Software, spyware removal

Once installed this rogue anti-spyware software starts with Windows, runs constantly in the background and uses scare messages about non-existent malicious files to convince the user to pay for activation.

A rogue security software such as Safety Anti-Spyware belongs to a family of software products that call themselves as antivirus, antispyware or registry cleaners and often use deceptive or high pressure sales tactics and deliberate false positives to convince users into buying a license/subscription. They are often repackaged and renamed. They do not actually remove malware instead many of them add more malware of their own.

This scareware is known by the following aliases:

Trojan.Win32.Inject, Win-Trojan/Fakealert, Trojan.Win32.Inject.alyb, Trojan:Win32/FakeRean and RogueAntiSpyware.SafetyAntiSpyware.

Typical Safety Anti-Spyware Scare Messages

safety antispyware scare messages Safety Anti Spyware Analysis and Removal

safety-antispyware-scare-messages

Security Warning! Malicious programs that may steal your private information and prevent your system from working properly are detected on your computer. Click here clean your PC immediately.

The installer file is named SafetyAntiSpyware.exe, about 1188352 bytes in size and is currently being detected by 27/40 (67.5%) of the anti-virus engines available at VirusTotal.

Safety Anti-Spyware Associated Files and Folders

  • C:\Program Files\Safety Anti-Spyware 3\Safety Anti-Spyware 3.exe
  • C:\Documents and Settings\malwarehelp.org\Desktop\SafetyAntiSpyware.exe
  • C:\Documents and Settings\malwarehelp.org\Start Menu\Safety Anti-Spyware 3\Safety Anti-Spyware 3.lnk
  • C:\Documents and Settings\malwarehelp.org\Application Data\Microsoft\Internet Explorer\Quick Launch\Safety Anti-Spyware 3.lnk
  • C:\Documents and Settings\malwarehelp.org\Desktop\Safety Anti-Spyware 3.lnk
  • C:\WINDOWS\Prefetch\SAFETY ANTI-SPYWARE 3.EXE-08556251.pf
  • C:\Documents and Settings\malwarehelp.org\Start Menu\Safety Anti-Spyware 3
  • C:\Program Files\Safety Anti-Spyware 3

Some of the file names may be randomly generated.

Safety Anti-Spyware Associated Registry Values and Keys

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\safety anti-spyware 3
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Safety Anti-Spyware 3

Safety Anti-Spyware Associated Domains

This scareware was observed accessing the following domains during installation and operation:

  • http://updateantiviruscenter com
  • http://safetyantispywareshop com

Note: Visiting the domains mentioned above may harm your computer system.

Safety Anti-Spyware Removal (How to remove Safety Anti-Spyware)

The free versions of MalwareBytes’s Anti-Malware and SuperAntiSpyware appear to remove Safety Anti-Spyware Scareware.

  1. Use an alternate browser like Firefox or Chrome to download and Install either MalwareBytes’s Anti-Malware or SuperAntiSpyware from the links above.
  2. Also download CCleaner.
  3. Boot in to Windows Safe mode.
  4. Click to scan with your chosen software. Check mark all instances of the rogue security software and delete them.
  5. Turn System Restore off and on
  6. Install, scan and clean the temporary files with CCleaner.

You should now be clean of this rogue.

Safety Anti-Spyware Scareware — Screenshots

Safety Anti-Spyware Scareware — Video

Note: The Safety Anti-Spyware installation and removal was tested on a fully patched Windows XP SP3 running updated versions of Internet Explorer and Firefox. The content provided in this article is not warranted or guaranteed by Malware Help. Org. The content provided is intended for entertainment and/or educational purposes. I am not liable for any negative consequences that may result from implementing any information covered in this article. The above information is correct at the time of my testing, it might change with time and or under different testing conditions.

  • StumbleUpon
  • Digg
  • del.icio.us
  • Facebook
  • MySpace
  • Google Bookmarks
  • Live
If you enjoyed this post, make sure you subscribe to my RSS feed!

Post to Twitter

Limited Period Offers

Save 10% on Kaspersky AntiVirus 2010 - Coupon Code: KAV10
10% off Spyware Doctor - Coupon Code: pctools10
Get McAfee Total Protection for only $49.99 after $30 off!
Save 25% on a 2 year subscription of avast! 5 Pro Antivirus
Save 50% on ZoneAlarm Internet Security Suite 2010 ...More Offers

You may also like to read

Comments

Everyone has an Opinion...why don't you share yours and oh, if you want a pic to show with your comment, go get a gravatar! or you can even subscribe to our comments feed.

    Note:
  • All fields except the comments field are optional.
  • Real names aren't required, but please give us something to call you. Conversations among several people called "Anonymous" get too confusing.
  • All comments are pre-moderated, and will not appear on this site until approved by the site owner.





Tags

More News, Articles from elsewhere