SpywareScrapper

Description: Rogue Security Program
Risk Level: High
Date of First Occurence: Thursday, April 17, 2008
Software Developer: (unknown)
Brief Info: Rogue/Suspect Anti-Spyware Product "Rogue/Suspect" means that these products are of unknown, questionable, or dubious value as anti-spyware protection.
Removal: This threat can be removed using "Spyware Terminator"

ELIMINAR SPYWARE »

Geographical Distribution of Threat "SpywareScrapper"

Threat Info

View All

Detected Items

  1. Detected Files: %APPDATA%\AntiSpywareDAT\Quarantine\atipdsxx.dll MD5: 1EEA62448BE29842D0692F0B666FC471 Size:172032 %APPDATA%\AntiSpywareDAT\Quarantine\rv40.dll MD5: E40244E3799D63F174FF734EA1DB0927 Size:49221 %APPDATA%\AntiSpywareDAT\Quarantine\powerreg scheduler.exe MD5: 748492545412B161E3B1FD4D1B40F620 Size:256000 %APPDATA%\AntiSpywareDAT\purasi.exe MD5: 742130EEF3FBD7E72A91DDA2516F01FD Size:16141 %APPDATA%\AntiSpywareDAT\Quarantine\pxwma.dll MD5: 767D178CD944F5E24F3C681B8BFEA1F8 Size:158456 MD5: DC30A4C7C983A1BB957C5ED7C51A8298 Size:151552 MD5: D75C161CE390F59F1B2A983B36359FFC Size:151552 MD5: BEA8ECE1982C072C37A48B85402D06E9 Size:158456 MD5: 9AFDBDAB0ADBC7CF10062C4968DBD941 Size:151552 MD5: D15C5B06E22629C02453B40FA75BE5FD Size:157352 MD5: 451B6F2420544191E8D72AAD602C4360 Size:86016 MD5: 746C97E5CCED7B2F24CF1158F8D26D10 Size:158456 MD5: EC9816DFE28C6C3623EAF0721FF0CD55 Size:151552 MD5: FA69021E7B3875790D0CA8E02328A2C2 Size:158456 %APPDATA%\AntiSpywareDAT\Quarantine\mwssrcas.dll MD5: 33122F5B04C8291F3138BEA26CDAB224 Size:57344 %APPDATA%\AntiSpywareDAT\Quarantine\mwsoestb.dll MD5: 75BF15A65055C062337213D476659866 Size:40960 %APPDATA%\AntiSpywareDAT\Quarantine\mwsbar.dll MD5: E75F15F3DB5D4D933FC8A0C72C6441CE Size:381012 %APPDATA%\AntiSpywareDAT\Quarantine\m3skplay.exe MD5: 2FDB1A37D942F5E3A9E9F0F9263374AD Size:24576 %APPDATA%\AntiSpywareDAT\Quarantine\m3skin.dll MD5: 2969949C709460C00AD82F3DE04069A7 Size:118784 %APPDATA%\AntiSpywareDAT\Quarantine\m3outlcn.dll MD5: D3DC055A901B6EF0BB4D01FDB142CAC8 Size:57344 %APPDATA%\AntiSpywareDAT\Quarantine\m3idle.dll MD5: E96DB55DF87CFB08293E2DD1CCB5DCEB Size:28672 %APPDATA%\AntiSpywareDAT\Quarantine\f3wphook.dll MD5: CEE57E05ECCF470E751689DED838B7D2 Size:20480 %APPDATA%\AntiSpywareDAT\Quarantine\f3shllvw.dll MD5: 5719E6DC6E3F1379D4B0C15B1E3FB9E4 Size:143360 %APPDATA%\AntiSpywareDAT\Quarantine\f3scrctr.dll MD5: 633686C1F4C5E7DA080F2314880E2040 Size:290816 %APPDATA%\AntiSpywareDAT\Quarantine\f3reprox.dll MD5: B1F265F5AC5CF5ED551DB01C37D72355 Size:94208 %APPDATA%\AntiSpywareDAT\Quarantine\f3popswt.dll MD5: 9DCEB3E2AA7AA6FBB895467DA7C321AF Size:118784 %APPDATA%\AntiSpywareDAT\Quarantine\f3httpct.dll MD5: 03E5F2E8EA3812E438D6BC34BE6CE726 Size:73728 %APPDATA%\AntiSpywareDAT\Quarantine\f3htmlmu.dll MD5: 17C7770230C6C75054B2A9210755584E Size:143421 %APPDATA%\AntiSpywareDAT\Quarantine\f3histsw.dll MD5: E12730ADB54FC2D75C5138C1165072B6 Size:249856 %APPDATA%\AntiSpywareDAT\Quarantine\f3cjpeg.dll MD5: 1D943CB3CBDD92161AE32532FB88265D Size:139264 %APPDATA%\AntiSpywareDAT\Quarantine\webp2pinstaller.dll MD5: 8494BA3CD9AE4E1737E3A73E706ECE19 Size:88576 %APPDATA%\AntiSpywareDAT\Quarantine\wapchk.dll MD5: 47549B4C79191AE0C5E805396F16A647 Size:48128 %APPDATA%\AntiSpywareDAT\Quarantine\p2psetup.exe MD5: 3E1D143C28BB5119CA6B72468E65A152 Size:468152 %APPDATA%\AntiSpywareDAT\Quarantine\mpegdll.dll MD5: 85B656445A8FD24DD9D78DEAA490691F Size:150016 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\.NetworkShare\LimeWireWin4.16.2.exe MD5: D025FE6058822B118E1BA0786AB0B673 Size:4494664 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\uninstall.exe MD5: 29D44FEE33CB211EDC622B8CDFC4F019 Size:122933 MD5: 209ADC2923AAF00833F205ED771DFB9E Size:125685 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\SystemUtilities.dll MD5: 000A0B5A47970D3D89BCA788FC3026D4 Size:81920 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\LimeWire.exe MD5: 690C56AC5FFC7C26F98A658F7FBEA9A1 Size:147456 MD5: 365418B2FEFCA481C6CE388DA076EAC2 Size:147456 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\lib\SystemUtilitiesA.dll MD5: 101CF5C28A5F1206F1A92D6A560E3F87 Size:86016 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\lib\SystemUtilities.dll MD5: 51B5AE29E0DAC0306C385D5DBECE8527 Size:90112 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\.NetworkShare\LimeWireWin4.14.10.exe MD5: 36D61784B4E84830618C8865D9D986BF Size:3380048 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\.NetworkShare\LimeWireWin4.12.6.exe MD5: DBF7CBD4B625F38AEEA268D75C0B32BC Size:3064200 %APPDATA%\AntiSpywareDAT\Quarantine\webstats.exe MD5: 3114E2732C4315B27F4BD31355DE547F Size:294912 %APPDATA%\AntiSpywareDAT\Quarantine\runmsc.dll MD5: B938EDABE9EFC9B024E79697E6C01FEA Size:57344 %APPDATA%\AntiSpywareDAT\Quarantine\wtcpl.cpl MD5: DEFA9C7459ED6094E7B45C0612EF3AA2 Size:45056 %APPDATA%\AntiSpywareDAT\Quarantine\liveupdate.exe MD5: 388826610867FCCAAFE17E4492E61AD2 Size:417792 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\.NetworkShare\LimeWireWin4.14.12.exe MD5: 955310C31C2B64108482109B74090825 Size:3381280 %APPDATA%\AntiSpywareDAT\Quarantine\ares.exe MD5: 60CE0FAA932A0F4A4ADF815474EB6008 Size:947200 %APPDATA%\AntiSpywareDAT\Quarantine\autorungui.dll MD5: D81CA58E34FF573BA4862377E10C2556 Size:434176 %APPDATA%\AntiSpywareDAT\Quarantine\autorun.exe MD5: A0FD24D4CB82B8AD4714AC650793341E Size:729088
  2. Detected Files with variable Filenames: MD5: B411CE46DAEE8FFE1ADF145F3CD7FC48 Size: 45056 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\tray.dll %APPDATA%\AntiSpywareDAT\Quarantine\limewire\lib\tray.dll MD5: A1E460904C64A49CD4D30274C717C646 Size: 110592 %APPDATA%\AntiSpywareDAT\Quarantine\limewire\jdic.dll %APPDATA%\AntiSpywareDAT\Quarantine\limewire\lib\jdic.dll

Detecting items list:

  1. Files by Name %APPDATA%\AntiSpywareDAT\BlockedCookies.dat %APPDATA%\AntiSpywareDAT\date.dat %APPDATA%\AntiSpywareDAT\DirectoryDefinition.dat %APPDATA%\AntiSpywareDAT\ENoSignature.dat %APPDATA%\AntiSpywareDAT\ExeDefinition.dat %APPDATA%\AntiSpywareDAT\FileDefinition.dat %APPDATA%\AntiSpywareDAT\Quarantine\Quarantined files will be placed here.txt %DESKTOP%\Spyware Scrapper Demo.lnk %START_PROGRAMS%\SpywareScrapper.com Software\Spyware Scrapper Demo\Readme-Help.lnk %START_PROGRAMS%\SpywareScrapper.com Software\Spyware Scrapper Demo.lnk %START_PROGRAMS%\SpywareScrapper.com Software\Spyware Scrapper Demo\SpywareScrapper.com.url %programfiles%\Spyware Scrapper Demo\help.chm %programfiles%\Spyware Scrapper Demo\Localization.xml %programfiles%\Spyware Scrapper Demo\riched32.dll %programfiles%\Spyware Scrapper Demo\scan.txt %programfiles%\Spyware Scrapper Demo\SpywareScrapper.com.url %programfiles%\Spyware Scrapper Demo\SpywareScrapperDemo.exe
  2. Files by Directories %APPDATA%\AntiSpywareDAT %START_PROGRAMS%\SpywareScrapper.com Software\Spyware Scrapper Demo %programfiles%\Spyware Scrapper Demo
  3. Registry Keys HKCU\Software\VB and VBA Program Settings\Spyware Scrapper HKLM\software\SpywareScrapper.com HKLM\software\Microsoft\Windows\CurrentVersion\Installer\Folders\%SystemDiskRoot%\Program Files\Spyware Scrapper Demo HKLM\software\Microsoft\Windows\CurrentVersion\Uninstall\{2004E9C1-92E4-47A9-B4CC-2253AE8E437C}

« Go to Software Database