Archive for the 'Rogue Antispyware/Antivirus' Category
Saturday, September 5th, 2009
This is a harmful program.
Name: QuickHealCleaner
Filename: QuickHealCleaner.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | QuickHealCleaner
Command: C:\Program Files\QuickHealCleaner Software\QuickHealCleaner\QuickHealCleaner.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [QuickHealCleaner] C:\Program Files\QuickHealCleaner Software\QuickHealCleaner\QuickHealCleaner.exe -min
Description: main file of QuickHealCleaner. QuickHealCleaner is a rogue antispyware program that designed to scam people.
How to remove: use these QuickHealCleaner.exe removal instructions.
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Wednesday, September 2nd, 2009
This is a harmful program.
Name: SystemCopSvc
Filename: SystemCopSvc.exe
Registry key:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SystemCopSvc
Command: C:\Program Files\SystemCop Software\SystemCop\SystemCopSvc.exe
Startup Type: Service
HijackThis Category: O23
HijackThis Line:
O23 – Service: SystemCop Security Service (SystemCopSvc) – Unknown owner – C:\Program Files\SystemCop Software\SystemCop\SystemCopSvc.exe
Description: component of SystemCop (rogue antispyware program)
How to remove: use these SystemCop removal instructions.
Posted in O23, Rogue Antispyware/Antivirus, Service | No Comments »
Wednesday, September 2nd, 2009
This is a harmful program.
Name: SystemCop
Filename: SystemCop.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SystemCop
Command: C:\Program Files\SystemCop Software\SystemCop\SystemCop.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SystemCop] C:\Program Files\SystemCop Software\SystemCop\SystemCop.exe -min
Description: main file of SystemCop (rogue antispyware program)
How to remove: use these SystemCop removal instructions.
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Monday, August 31st, 2009
This is a harmful program.
Name: svchasts
Filename: svchasts.exe
Registry key:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\antippro2009_100
Command: C:\WINDOWS\svchasts.exe
Startup Type: Service
HijackThis Category: O23
HijackThis Line:
O23 – Service: AntipPro2009_100 (AntipyProex) – Unknown owner – C:\WINDOWS\svchasts.exe
Combofix/RSIT Line:
R2 AntipPro2009_100;AntipyProex; C:\WINDOWS\svchasts.exe [2009-08-31 163840]
Description: component of Windows Police Pro (rogue antispyware program)
How to remove: use these Windows Police Pro removal instructions.
Posted in O23, Rogue Antispyware/Antivirus, Service | No Comments »
Monday, August 31st, 2009
This is a harmful program.
Name: desote
Filename: desote.exe
Registry key:
HKEY_CLASSES_ROOT\exefile\shell\open\command
Command: c:\windows\system32\desote.exe
Startup Type: File associations
.exe – open – C:\WINDOWS\system32\desote.exe “%1″ %*
Description: component of Windows Police Pro (rogue antispyware program) that blocks ability to run any programs.
How to remove: use these Windows Police Pro removal instructions.
Posted in File associations, Rogue Antispyware/Antivirus | No Comments »
Saturday, August 29th, 2009
This is a harmful program.
Name: SM205
Filename: SM205.exe (Smart Virus Eliminator uses random file name to hide itself)
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Smart Virus Eliminator
Command: C:\Documents and Settings\All Users\Application Data\7d189\SM205.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [Smart Virus Eliminator] “C:\Documents and Settings\All Users\Application Data\7d189\SM205.exe” /s /d
Description: main file of Smart Virus Eliminator
How to remove: use these Smart Virus Eliminator removal instructions.
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Friday, August 28th, 2009
This is a harmful program.
Name: WIa9ca
Filename: WIa9ca.exe (uses random filenames to hide itself)
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Windows Protection Suite
Command: C:\Documents and Settings\All Users\Application Data\a91c29\WIa9ca.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [Windows Protection Suite] “C:\Documents and Settings\All Users\Application Data\a91c29\WIa9ca.exe” /s /d
Description: main file of Windows Protection Suite (rogue antispyware software)
How to remove: use these Windows Protection Suite removal instructions.
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Friday, August 28th, 2009
This is a harmful program.
Name: BlockDefenseSvc
Filename: BlockDefenseSvc.exe
Registry key:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\blockdefensesvc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\blockdefensesvc
Command: C:\Program Files\BlockDefense Software\BlockDefense\BlockDefenseSvc.exe
Startup Type: Service
HijackThis Category: O23
HijackThis Line:
O23 – Service: BlockDefense Security Service (BlockDefenseSvc) – Unknown owner – C:\Program Files\BlockDefense Software\BlockDefense\BlockDefenseSvc.exe
Description: component of BlockDefense (rogue antispyware program)
How to remove: use these BlockDefense removal instructions.
Posted in O23, Rogue Antispyware/Antivirus, Service | No Comments »
Friday, August 28th, 2009
This is a harmful program.
Name: BlockDefense
Filename: BlockDefense.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | BlockDefense
Command: C:\Program Files\BlockDefense Software\BlockDefense\BlockDefense.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [BlockDefense] C:\Program Files\BlockDefense Software\BlockDefense\BlockDefense.exe -min
Description: main file of BlockDefense (rogue antispyware program)
How to remove: use these BlockDefense removal instructions.
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Thursday, August 27th, 2009
This is a harmful program.
Name: SaveDefenseSvc
Filename: SaveDefenseSvc.exe
Registry key:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SaveDefenseSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SaveDefenseSvc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SaveDefenseSvc
Command: C:\Program Files\SaveDefense Software\SaveDefense\SaveDefenseSvc.exe
Startup Type: Service
HijackThis Category: O23
HijackThis Line:
O23 – Service: SaveDefense Security Service (SaveDefenseSvc) – Unknown owner – C:\Program Files\SaveDefense Software\SaveDefense\SaveDefenseSvc.exe
Description: component of SaveDefense (rogue antispyware program)
How to remove: use these SaveDefense removal instructions.
Posted in O23, Rogue Antispyware/Antivirus, Service | No Comments »