TheSpyBot – Rogue Anti-Malware

by malwarekilla on June 26, 2008

I came across TheSpyBot while working in Webster, MO. It was pretty obvious to me that this was Rogue Anti-Malware, however my client had it confused with Spybot Search and Destroy…no doubt this is what the malware author’s intensions were.

TheSpyBot loads at startup and starts doing its fake scan. After only a few seconds it’s prompting us to purchase the program…not! TheSpyBot is fake anti-malware and should never be purchased. If this was loaded on your computer without your knowledge then you have a virtumonde infection that needs to be treated.

My client opted to remove his AVG install and go with Spyware Doctor with Antivirus. Spyware Doctor with Antivirus removed the malware, and then I used ComboFix to remove some security settings that had been set by the malware (like disabled desktop and task manager).

062608 1605 thespybotro1 TheSpyBot – Rogue Anti Malware

{ 1 comment… read it below or add one }

sekhar July 1, 2008 at 7:30 am

thanks for the TheSpyBot – Rogue Anti-Malware softwares this help full for me i think thanks alot

Leave a Comment

Previous post:

Next post: