Archive for the 'Rogue Antispyware/Antivirus' Category

What is Antivir.exe, How to remove Antivir.exe

Friday, November 27th, 2009

Antivir.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: Antivir
Filename: Antivir.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | AV

Command: C:\Program Files\AV\Antivir.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [AV] C:\Program Files\AV\Antivir.exe

DDS Line:

uRun: [AV] C:\Program Files\AV\Antivir.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“AV”=C:\Program Files\AV\Antivir.exe

Description: core part of Antivir. Antivir is a rogue antispyware program.

How to remove: use these Antivir removal instructions.

What is REAnti.exe, How to remove REAnti.exe

Thursday, November 26th, 2009

REAnti.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: REAnti
Filename: REAnti.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | REAnti.exe

Command: C:\Program Files\REAnti Software\REAnti\REAnti.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [REAnti.exe] C:\Program Files\REAnti Software\REAnti\REAnti.exe

DDS Line:

uRun: [REAnti.exe] C:\Program Files\REAnti Software\REAnti\REAnti.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“REAnti.exe”=C:\Program Files\REAnti Software\REAnti\REAnti.exe [2009-11-27 1638400]

Description: core component of REAnti. REAnti is a rogue antispyware program

How to remove: use these REAnti removal instructions.

What is KeepCop.exe, How to remove KeepCop.exe

Tuesday, November 24th, 2009

KeepCop.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: KeepCop
Filename: KeepCop.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | KeepCop

Command: C:\Program Files\KeepCop Software\KeepCop\KeepCop.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [KeepCop] C:\Program Files\KeepCop Software\KeepCop\KeepCop.exe -min

DDS Line:

uRun: [KeepCop] C:\Program Files\KeepCop Software\KeepCop\KeepCop.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“KeepCop”=C:\Program Files\KeepCop Software\KeepCop\KeepCop.exe

Description: core component of KeepCop. KeepCop is a rogue antispyware program.

How to remove: use these KeepCop removal instructions.

What is alpha.exe, How to remove alpha.exe

Monday, November 23rd, 2009

alpha.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: alpha
Filename: alpha.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | AAntivirus

Command: C:\Program Files\AAntivirus\alpha.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [AAntivirus] C:\Program Files\AAntivirus\alpha.exe

DDS Line:

uRun: [AAntivirus] C:\Program Files\AAntivirus\alpha.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“AAntivirus”=C:\Program Files\AAntivirus\alpha.exe

Description: core component of Alpha Antivirus. Alpha Antivirus is a rogue antispyware program.

How to remove: use these Alpha Antivirus removal instructions.

What is ExplorerImages.dll, How to remove ExplorerImages.dll

Monday, November 23rd, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: ExplorerImages
Filename: ExplorerImages.dll
Registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}

Command: C:\WINDOWS\system32\ExplorerImages.dll
CLSID: {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
Startup Type: BHO
HijackThis Category: O2
HijackThis Line:

O2 – BHO: &Advanced Explorer Editor – {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} – C:\WINDOWS\system32\ExplorerImages.dll

DDS Line:

BHO: &Advanced Explorer Editor – {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} – C:\WINDOWS\system32\ExplorerImages.dll

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}

Description: component of Alpha Antivirus that hijacks InternetExplorer. Alpha Antivirus is a rogue antispyware program.

How to remove: use these Alpha Antivirus removal instructions.

What is vec.exe, How to remove vec.exe

Monday, November 23rd, 2009

vec.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: vec
Filename: vec.exe
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | mxcll

Command: C:\Documents and Settings\All Users\Application Data\eca\vec.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [mxcll] C:\Documents and Settings\All Users\Application Data\eca\vec.exe

DDS Line:

mRun: [mxcll] C:\Documents and Settings\All Users\Application Data\eca\vec.exe

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“mxcll”=C:\Documents and Settings\All Users\Application Data\eca\vec.exe

Description: core component of Eco AntiVirus 2010. Eco AntiVirus 2010 is a rogue antispyware program.

How to remove: use these Eco AntiVirus 2010 removal instructions.

What is AVR.exe, How to remove AVR.exe

Friday, November 20th, 2009

AVR.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: AVR
Filename: AVR.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Advanced Virus Remover

Command: C:\Program Files\AdvancedVirusRemover\AVR.exe
CLSID: clsid
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [Advanced Virus Remover] C:\Program Files\AdvancedVirusRemover\AVR.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Advanced Virus Remover”=C:\Program Files\AdvancedVirusRemover\AVR.exe

Description: core part of Advanced Virus Remover. Advanced Virus Remover is a rogue anti-spyware program.

How to remove: use these Advanced Virus Remover removal instructions.

What is esysprotector2009.microsoft.com, How to remove esysprotector2009.microsoft.com

Thursday, November 19th, 2009

esysprotector2009.microsoft.com is a malicious website

remove The site was created to spread Antivirus System Pro. If your browser is redirected to esysprotector2009.microsoft.com, then you should immediately check your PC using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

IP Address: 91.212.127.227
Site addess: esysprotector2009.microsoft.com
HijackThis Category: O1
HijackThis Line:

O1 – Hosts: 91.212.127.227 esysprotector2009.microsoft.com

Description: esysprotector2009.microsoft.com is not related with Microsoft company and can only be seen on infected computers. The site used to promote the rogue antispyware program called Antivirus System Pro.

How to remove: use these Antivirus System Pro removal instructions in order to remove this infection.

What is AntiVirus Plus.1.dll, How to remove AntiVirus Plus.1.dll

Thursday, November 19th, 2009

AntiVirus Plus.1.dll is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: AntiVirus Plus.1
Filename: AntiVirus Plus.1.dll
Registry key:

Command: %UserProfile%\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll
CLSID: {C2B5AAB8-2183-4be7-81A6-F11493C45872}
Startup Type:
HijackThis Category:
HijackThis Line:

O2 – BHO: Antivirus Plus BHO – {C2B5AAB8-2183-4be7-81A6-F11493C45872} – C:\Documents and Settings\comp\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll
O4 – HKLM\..\Run: [AntiVirus Plus] “C:\WINDOWS\system32\rundll32.exe” “C:\Documents and Settings\comp\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll”, start 1
O4 – HKCU\..\Run: [AntiVirus Plus] “C:\WINDOWS\system32\rundll32.exe” “C:\Documents and Settings\comp\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll”, start 1

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2B5AAB8-2183-4be7-81A6-F11493C45872}]
Antivirus Plus BHO – C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll [2009-11-19 2453504]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“AntiVirus Plus”=C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll [2009-11-19 2453504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“AntiVirus Plus”=C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll [2009-11-19 2453504]

Description: component of AntiVirus Plus. AntiVirus Plus is a rogue antispyware program.

How to remove: use these AntiVirus Plus removal instructions.

What is SecureKeeper.exe, How to remove SecureKeeper.exe

Wednesday, November 18th, 2009

SecureKeeper.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: SecureKeeper
Filename: SecureKeeper.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecureKeeper

Command: C:\Program Files\SecureKeeper Software\SecureKeeper\SecureKeeper.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [SecureKeeper] C:\Program Files\SecureKeeper Software\SecureKeeper\SecureKeeper.exe -min

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“SecureKeeper”=C:\Program Files\SecureKeeper Software\SecureKeeper\SecureKeeper.exe -min

Description: core part of SecureKeeper. SecureKeeper is a rogue antispyware program.

How to remove: use these SecureKeeper removal instructions.