Wireshark Antivirus, a fake security application rogue of the FakeScanti family first seen in August of 2010, used scare tactics showing windows and other applications as being infected to scare the user into buying the rogue.
File and Locations:
%Program_Files%\Wireshark Antivirus\Wireshark Antivirus.exe
%Program_Files%\adc_w32.dll
%Program_Files%\alggui.exe
%Program_Files%\nuar.old
%Program_Files%\skynet.dat
%Program_Files%\svchost.exe
%Program_Files%\wp3.dat
%Program_Files%\wp4.dat
Sites associated:
belewr2ret.com
bondbm3x.com
caronlinetu.com
core3019.aquashoolonline.com
core3019.bigbooklibrary.com
core3019.boxingshool.com
core3019.greenteeforyou.com
fastanduop.com
jn3019.payonshoolonline.com
letsworkfromanywhere.com
max3wrxstia.com
mohotwrxst.info
new3stford.com
orderfrombook.com
programmingshool.com
protectyourpc-10.com
protectyourpc-11.com
velewr1rst.com
waponlineorder.com
xerexx5rs.com
The rogue could be removed using manually removal methods, however, the WireShark Antivirus rogue is difficult as it will try and re-infect the computer, so we recommend using our Antivirus removal tool, VIPRE Antivirus. You can download a free trial to remove the WireShark Antivirus rogue from your PC for no cost by clicking on the link below:
http://www.vipreantivirus.com/Antivirus-Trial/VIPRE-Antivirus/
If you are unable to download and install our malware removal tool because this has infected your computer and is not allowing you to install the program, you can use our VIPRE Rescue Disc here: