Archive for the 'Rogue Antispyware/Antivirus' Category
Wednesday, October 7th, 2009
tsc.exe is a harmful program.
Name: tsc
Filename: tsc.exe
Command: C:\program Files\CS\tsc.exe
Description: part of Cyber Security. Cyber Security is fake security program (scareware).
Removal instructions: How to remove Cyber Security (Uninstall instructions)
Posted in Rogue Antispyware/Antivirus | No Comments »
Monday, October 5th, 2009
TrustCop.exe is a harmful program.
Name: TrustCop
Filename: TrustCop.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | TrustCop
Command: C:\Program Files\TrustCop Software\TrustCop\TrustCop.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [TrustCop] C:\Program Files\TrustCop Software\TrustCop\TrustCop.exe -min
Combofix/RSIT Line:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“TrustCop”=C:\Program Files\TrustCop Software\TrustCop\TrustCop.exe [2009-10-06 786432]
Description: main file of TrustCop. TrustCop is a fake antispyware program.
Removal instructions: How to Remove TrustCop (Uninstall instructions).
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Friday, October 2nd, 2009
SecureWarrior.exe is a harmful program.
Name: SecureWarrior
Filename: SecureWarrior.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecureWarrior
Command: C:\Program Files\SecureWarrior Software\SecureWarrior\SecureWarrior.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SecureWarrior] C:\Program Files\SecureWarrior Software\SecureWarrior\SecureWarrior.exe -min
Combofix/RSIT Line:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“SecureWarrior”=C:\Program Files\SecureWarrior Software\SecureWarrior\SecureWarrior.exe [2009-10-02 830976]
Description: main component of SecureWarrior rogue antispyware software
How to remove: use these SecureWarrior removal instructins
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Wednesday, September 30th, 2009
This is a harmful program.
Name: SecureFighter
Filename: SecureFighter.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecureFighter
Command: C:\Program Files\SecureFighter Software\SecureFighter\SecureFighter.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SecureFighter] C:\Program Files\SecureFighter Software\SecureFighter\SecureFighter.exe -min
Description: component of SecureFighter rogue antispyware program
How to remove: use these SecureFighter removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Tuesday, September 29th, 2009
SecureVeteran.exe is a harmful program.
Name: SecureVeteran
Filename: SecureVeteran.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecureVeteran
Command: C:\Program Files\SecureVeteran Software\SecureVeteran\SecureVeteran.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SecuritySoldier] C:\Program Files\SecureVeteran Software\SecureVeteran\SecureVeteran.exe -min
Description: main file of SecureVeteran rogue antispyware program
How to remove: use these SecureVeteran removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Tuesday, September 29th, 2009
iehelpmod.dll is a harmful program.
Name: iehelpmod
Filename: iehelpmod.dll
Registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
Command: C:\WINDOWS\system32\iehelpmod.dll
CLSID: {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
Startup Type: BHO
HijackThis Category: O2
HijackThis Line:
O2 – BHO: &IE Help – {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} – C:\WINDOWS\system32\iehelpmod.dll
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}]
&IE Help – C:\WINDOWS\system32\iehelpmod.dll [2009-09-29 336896]
Description: trojan fakeAlert that installed by Total Security rogue antispyware program
How to remove: use these Total Security removal instructions
Posted in BHO, O2, Rogue Antispyware/Antivirus, Trojan | No Comments »
Monday, September 28th, 2009
NDISRD.sys is a harmful program.
Name: NDISRD
Filename: NDISRD.sys
Registry key:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NDISRD
Command: C:\WINDOWS\system32\drivers\NDISRD.sys
Startup Type: Driver
Combofix/RSIT Line:
S1 NDISRD;NDISRD; C:\WINDOWS\system32\drivers\NDISRD.sys [2009-06-22 24576
Description: trojan also known as TrojanDownloader, it installed with Alpha Antivirus rogue antispyware program
How to remove: use these Alpha Antivirus removal instructions
Posted in Driver, Rogue Antispyware/Antivirus, Trojan | No Comments »
Monday, September 28th, 2009
msnaoladdon.dll is a harmful program.
Name: msnaoladdon
Filename: msnaoladdon.dll
Registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A77D3539-581D-450C-9E44-A84C415A6172}
Command: C:\WINDOWS\system32\msnaoladdon.dll
CLSID: {A77D3539-581D-450C-9E44-A84C415A6172}
Startup Type: BHO
HijackThis Category: O2
HijackThis Line:
O2 – BHO: (no name) – {A77D3539-581D-450C-9E44-A84C415A6172} – C:\WINDOWS\system32\msnaoladdon.dll
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A77D3539-581D-450C-9E44-A84C415A6172}]
C:\WINDOWS\system32\msnaoladdon.dll [2009-09-26 403968]
Description: trojan that installed by Alpha Antivirus (fake antivirus application)
How to remove: use these Alpha Antivirus removal instructions
Posted in BHO, O2, Rogue Antispyware/Antivirus, Trojan | No Comments »
Monday, September 28th, 2009
NetFilter.exe is a harmful program.
Name: NetFilter
Filename: NetFilter.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | MSDRV
Command: C:\WINDOWS\system32\NetFilter.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [MSDRV] NetFilter.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“MSDRV”=C:\WINDOWS\system32\NetFilter.exe [2009-09-23 122880]
Description: trojan that installed by Alpha Antivirus rogue antispyware program
How to remove: use these Alpha Antivirus removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run, Trojan | No Comments »
Monday, September 28th, 2009
AlphaAV.exe is a harmful program.
Name: AlphaAV
Filename: AlphaAV.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | AlphaAV
Command: C:\Program Files\AlphaAV\AlphaAV.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [AlphaAV] C:\Program Files\AlphaAV\AlphaAV.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“AlphaAV”=C:\Program Files\AlphaAV\AlphaAV.exe [2009-09-26 1581056]
Description: main file of Alpha Antivirus rogue antispyware program
How to remove: use these Alpha Antivirus removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »