Thursday, April 9, 2009

Virus Sweeper

Virus Sweeper is a new rogue. It belongs to the same family as Ultra Antivir 2009, Virusdoctor, VirusMelt, VirusAlarm. The GUI is always the same, only the title name is changing. Note that 2 GUIs exist, one with a Vista skin, the other with a XP skin.

As for the previous rogues of this family, the software is hosted on google code.

Virus Sweeper comes from fake online scanners. Nonexistent files are detected on a clean system, installation of the software is proposed to users for a free scan.
Virus Sweeper drops many files on the system with different filenames taken from a dictionary. These files are not Win32 executables and are detected as infections.

BleepingComputer Removal Guide.
Malwarebytes VirusSweeper Blog Post.