Home Malware Programs Trojans Win32/privacyremover.m64

Win32/privacyremover.m64

Posted: August 18, 2008

Win32/privacyremover.m64 is a Trojan name that is displayed in the fake Warning messages that report a spyware infection only to trick you into purchasing a rogue anti-spyware application, which at the moment is XP-Guard.

If "Win32/privacyremover.m64" fake alert message appears on your computer, you may be infected with a trojan called Zlob. Zlob infects your computer with the help of fake codecs that pretend to be free video codecs, often found on porno websites. If you download free video codecs from questionable websites, it is highly probable that they will be infected with dangerous Trojan programs. Once the Trojan program is installed, you will be bombarded with "Win32/privacyremover.m64" fake alert messages that may look as this one:

"WARNING! Spyware detected on your computer! Install an antivirus or spyware remover to clean your computer.
Warning! Win32/Adware.Virtumonde
Warning! Win32/privacyremover.M64."

Once you click on this fake alert message, you will be directed to XP-Guard's website, or another rogue website, where you are persuaded to buy the commercial version of the rogue anti-spyware program. We recommend the immediate removal of Win32/privacyremover.m64, XP-Guard and Zlob from your PC.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Desktop\XP-Guard.lnk
    2 %UserProfile%\Start Menu\Programs\XPGuard\XP-Guard Web Site.lnk
    3 %UserProfile%\Start Menu\Programs\XPGuard\XP-Guard.lnk
    4 c:\Program Files\XPGuard\install.log
    5 c:\Program Files\XPGuard\unwise.exe
    6 c:\Program Files\XPGuard\XP-Guard Web Site.url
    7 c:\Program Files\XPGuard\XP-Guard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "XPGuard"HKEY_CURRENT_USER\Software\XPGuardHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}XP-Guard

4 Comments

  • Bryan says:

    I can;t find anything it will not let me search it. I can not download anything it blocks all downloads and program installs

  • Nashey says:

    Some time ago I ended up with a virus (XP AntiVirus 2008) which this site helped me to .. more or less, get rid of. (Thanks mainly to TOMT).

    Just 2 days ago I downloaded something from an email, (stupid but it looked familiar enough to fool me) and when I opened it, my background image was replaced with something that read:

    WARNING!
    Spyware Detected on your computer.
    Install an antivirus or spyware remover to clean your computer

    Warning! Win32/Adware.Virtumonde
    Detected on your computer

    Warning! Win32/privacyremover.m64
    Detected on your computer

    As i did months ago when I got the XP AntiVirus, Virus.. I typed in one of those two virus/spyware names into Yahoo search and was brought to this site.
    Today I downloaded and installed the SpyHunter3 Scanner to which there is a link on page for Adware.Virtuemonde. It found 530 infections with the first scan, so to get rid of them I bought 30.00 subscription. When I removed all it would (all but Zango which I think is mostly off my computer anyways) I restarted the computer. I had replaed the WARNING! Background with my own picture again, hoping it would remain, but the Warning has returned.

    How can I make it stop doing that when no more SpyWare/AdWare is being found..

    Is the Scanner linked on this page a different scanner or the same thing as what I got from the other (Win32/Adware.Virtumonde) page??

    Someone please help me, if you can. I'm confused and not the best at this antivirus ... stuff.

    Thanks.
    Nashey

  • chasm says:

    I cannot understand the mentality of someone who deliberatly sends emails tthat have "viruses/trojans" ect, to others, unknown to them. Can some one please explain why - is it a commercial idea by companies selling programmes to destroy these malicious viruses, or what? Why cannot we find out who sent them and return the favour?

  • charlie says:

    our computer has been infected and the warning message comes up straight way then it the computer restarts straight away what should we do?

Loading...