Home Malware Programs Rogue Anti-Spyware Programs AntiMalware GO

AntiMalware GO

Posted: February 25, 2011

Threat Metric

Threat Level: 10/10
Infected PCs: 59
First Seen: February 28, 2011
Last Seen: August 17, 2022
OS(es) Affected: Windows

ScreenshotAntiMalware GO is a dangerous new clone of old confirmed rogue anti-virus programs. Like all rogue products, AntiMalware GO will try to look like a friendly and useful anti-malware program, but AntiMalware GO actually gives you fake error messages and scans without substance behind them. AntiMalware GO will also change your registry to allow AntiMalware GO to take over your computer during startup, and may hijack your browser through proxy server abuse. As a dangerous product used to steal money from the unwary, AntiMalware GO should be defended against preemptively as well as harshly rebuked off your hard drive when required.

New Name, Same Old Scam

AntiMalware GO is a clone of the well-known AntiVira Av and Antivirus .NET rogue products. Because of this AntiMalware GO relies more on lack of recognition than ingenuity in tactics to fool computer users. Its appearance is a friendly one, but AntiMalware GO's scan results and alerts are all falsified, serving no purpose other than to prod you into spending money on registering AntiMalware GO. A registered version of AntiMalware GO will still cause your computer to behave poorly and will present a security risk as long as AntiMalware GO is around, which makes deleting AntiMalware GO the only practical choice.

One noticeable potential sign of AntiMalware GO's activity is if you notice pop-up alerts announcing infections your other security software hasn't noticed. This is especially visible in the case of Banker.Fox.A, which is an imaginary malware name solely used by AntiVira Av clones and other rogue programs.

Clones of AntiVira Av such as AntiMalware GO have been known to cause worse problems as well. AntiMalware GO may prevent you from accessing websites, or hijack your browser periodically to redirect you towards malicious sites. Never give any credibility to a 'security software' website that your browser was forced to direct itself to; such websites are invariably run by criminals interested only in stealing money and confidential information.

Clobbering AntiMalware GO Rogue Program Before AntiMalware GO Clobbers Your System

AntiMalware GO and other rogue anti-virus applications will reduce your security settings in other ways, and may disable genuine anti-malware programs and Windows-centric processes like your Task Manager. The longer you go without deleting AntiMalware GO, the worse risk your system is forced to suffer. Programs are often terminated with more false alerts like this one:

Security Alert
Virus Alert!
Application can't be started! The file notepad.exe is damaged. Do you want to activate your anti-virus software now?

To remove AntiMalware GO and everything that came with AntiMalware GO, you'll usually be required to reboot into Safe Mode. By preventing AntiMalware GO's process from running, you can re-enable access to your old security programs and take appropriate action.

ScreenshotScreenshot

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\buyxgnvvj\hoqlhywhmof.exe File name: hoqlhywhmof.exe
Size: 336.38 KB (336384 bytes)
MD5: 8b1d33bb89ad929b8214d84d324b3f0b
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\buyxgnvvj
Group: Malware file
Last Updated: August 17, 2022

Additional Information

The following URL's were detected:
Acantispy.com
The following messages's were detected:
# Message
1Antivirus software alert
Infiltration alert
Your computer is being attacked by an Internet virus. It could be password-stealing attack, a trojan-dropper or similar.
2Internet Explorer Warning - visiting this web site may harm your computer!
Most likely causes:
- The website contains exploits that can launch a malicious code on your computer
- Suspicious network activity detected
- There might be an active spyware running on your computer

2 Comments

  • Pist Off says:

    This darn malware is horrible. Terrible, Im gonna try this, Thanks spwareremove, hopefully this will work and i will post another comment on here letting users know if its an easy process, if i gave up or if this post is pointless. Thanks again! PO

  • Misra says:

    I followed ur steps and it work for like 3 soecnd. Then everything just closed. Then I try to re-open it and it doesn't let me open the . I try renaming it and it still doesn't work. Can you help me?

Loading...