Archive for the 'Rogue Antispyware/Antivirus' Category

Antivirus Live – [random]sysguard.exe – How to remove

Monday, December 7th, 2009

[random]sysguard.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: [random]sysguard
Filename: [random]sysguard.exe
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | [random]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | [random]

Command: %UserProfile%\Local Settings\Application Data\[random]\[random]sysguard.exe
Startup Type: HKLM->Run, HKCU->Run
HijackThis Category:
HijackThis Line:

O4 – HKLM\..\Run: [random] C:\Documents and Settings\user\Local Settings\Application Data\[random]\[random]sysguard.exe
O4 – HKCU\..\Run: [random] C:\Documents and Settings\user\Local Settings\Application Data\[random]\[random]sysguard.exe

DDS Line:

mRun: [random] C:\Documents and Settings\user\Local Settings\Application Data\[random]\[random]sysguard.exe
uRun: [random] C:\Documents and Settings\user\Local Settings\Application Data\[random]\[random]sysguard.exe

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“[random]”=C:\Documents and Settings\user\Local Settings\Application Data\[random]\[random]sysguard.exe
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“[random]”=C:\Documents and Settings\user\Local Settings\Application Data\[random]\[random]sysguard.exe

Description: core part of Antivirus Live. Antivirus Live is a rogue antispyware program.

How to remove: use these Antivirus Live removal instructions.

What is Winsecure2010.microsoft.com, How to remove Winsecure2010.microsoft.com

Monday, December 7th, 2009

Winsecure2010.microsoft.com is a malicious website

remove The site was created to spread Antivirus System Pro. If your browser is redirected to Winsecure2010.microsoft.com, then you should immediately check your PC using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Site addess: Winsecure2010.microsoft.com
Description: Winsecure2010.microsoft.com is not related with Microsoft company and can only be seen on infected computers. The site used to promote the rogue antispyware program called Antivirus System Pro.

How to remove: use these Antivirus System Pro removal instructions in order to remove this infection.

What is AntiKeep.exe, How to remove AntiKeep.exe

Thursday, December 3rd, 2009

AntiKeep.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: AntiKeep
Filename: AntiKeep.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | AntiKeep.exe

Command: C:\Program Files\AntiKeep Software\AntiKeep\AntiKeep.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [AntiKeep.exe] C:\Program Files\AntiKeep Software\AntiKeep\AntiKeep.exe

DDS Line:

uRun: [AntiKeep.exe] C:\Program Files\AntiKeep Software\AntiKeep\AntiKeep.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“AntiKeep.exe”=C:\Program Files\AntiKeep Software\AntiKeep\AntiKeep.exe [2009-12-03 1638400]

Description: core component of AntiKeep. AntiKeep is a rogue antispyware program.

How to remove: use these AntiKeep removal instructions.

What is win32extension.dll, How to remove win32extension.dll

Tuesday, December 1st, 2009

win32extension.dll is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: win32extension
Filename: win32extension.dll
Registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}

Command: C:\WINDOWS\system32\win32extension.dll
CLSID: {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
Startup Type: BHO
HijackThis Category: O2
HijackThis Line:

O2 – BHO: &Security Update – {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} – C:\WINDOWS\system32\win32extension.dll

DDS Line:

BHO: &Security Update: {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} – C:\WINDOWS\system32\win32extension.dll

RSIT Line:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}]
&Security Update – C:\WINDOWS\system32\win32extension.dll [2009-12-01 665088]

Description: component of Personal Security. Personal Security is a rogue antispyware program.

How to remove: use these Personal Security removal instructions.

What is psecurity.exe, How to remove psecurity.exe

Tuesday, December 1st, 2009

psecurity.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: psecurity
Filename: psecurity.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | PSecurity

Command: C:\Program Files\PSecurity\psecurity.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [PSecurity] C:\Program Files\PSecurity\psecurity.exe

DDS Line:

uRun: [PSecurity] C:\Program Files\PSecurity\psecurity.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“PSecurity”=C:\Program Files\PSecurity\psecurity.exe [2009-12-01 1268224]

Description: core component of Personal Security. Personal Security is a rogue antispyware program.

How to remove: use these Personal Security removal instructions.

What is winhelper86.dll, How to remove winhelper86.dll

Tuesday, December 1st, 2009

winhelper86.dll is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: winhelper86
Filename: winhelper86.dll
Command: C:\WINDOWS\system32\winhelper86.dll
Startup Type: LSP
HijackThis Category: O10
HijackThis Line:

O10 – Unknown file in Winsock LSP: c:\windows\system32\winhelper86.dll

MalwareBytes Anti-malware Log Line:

C:\WINDOWS\system32\winhelper86.dll (Trojan.Fakeinit)

Combofix:

LSP: c:\windows\system32\winhelper86.dll

Description: trojan that installed with Advanced Virus Remover

How to remove: use LSP Fix or these Advanced Virus Remover removal instructions.

What is Winwarepro2010.microsoft.com, How to remove Winwarepro2010.microsoft.com

Tuesday, December 1st, 2009

Winwarepro2010.microsoft.com is a malicious website

remove The site was created to spread Antivirus System Pro. If your browser is redirected to Winwarepro2010.microsoft.com, then you should immediately check your PC using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Site addess: Winwarepro2010.microsoft.com
Description: Winwarepro2010.microsoft.com is not related with Microsoft company and can only be seen on infected computers. The site used to promote the rogue antispyware program called Antivirus System Pro.

How to remove: use these Antivirus System Pro removal instructions in order to remove this infection.

What is AntiAdd.exe, How to remove AntiAdd.exe

Tuesday, December 1st, 2009

AntiAdd.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: AntiAdd
Filename: AntiAdd.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | AntiAdd.exe

Command: C:\Program Files\AntiAdd Software\AntiAdd\AntiAdd.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [AntiAdd.exe] C:\Program Files\AntiAdd Software\AntiAdd\AntiAdd.exe

DDS Line:

uRun: [AntiAdd.exe] C:\Program Files\AntiAdd Software\AntiAdd\AntiAdd.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“AntiAdd.exe”=C:\Program Files\AntiAdd Software\AntiAdd\AntiAdd.exe [2009-12-01 1638400]

Description: core component of AntiAdd. AntiAdd is a rogue antispyware program.

How to remove: use these AntiAdd removal instructions.

What is sysguard2010.microsoft.com, How to remove sysguard2010.microsoft.com

Saturday, November 28th, 2009

sysguard2010.microsoft.com is a malicious website

remove The site was created to spread Antivirus System Pro. If your browser is redirected to sysguard2010.microsoft.com, then you should immediately check your PC using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Site addess: sysguard2010.microsoft.com
Description: sysguard2010.microsoft.com is not related with Microsoft company and can only be seen on infected computers. The site used to promote the rogue antispyware program called Antivirus System Pro.

How to remove: use these Antivirus System Pro removal instructions in order to remove this infection.

What is RESpyWare.exe, How to remove RESpyWare.exe

Friday, November 27th, 2009

RESpyWare.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: RESpyWare
Filename: RESpyWare.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | RESpyWare.exe

Command: C:\Program Files\RESpyWare Software\RESpyWare\RESpyWare.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [RESpyWare.exe] C:\Program Files\RESpyWare Software\RESpyWare\RESpyWare.exe

DDS Line:

uRun: [RESpyWare.exe] C:\Program Files\RESpyWare Software\RESpyWare\RESpyWare.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“RESpyWare.exe”=C:\Program Files\RESpyWare Software\RESpyWare\RESpyWare.exe [2009-11-28 1637888]

Description: core component of RESpyWare. RESpyWare is a rogue antispyware program.

How to remove: use these RESpyWare removal instructions.