Archive for the 'Rogue Antispyware/Antivirus' Category

wingenocx.dll is trojan BHO

Monday, June 15th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: wingenocx
Filename: wingenocx.dll
Registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}

Command: C:\WINDOWS\system32\wingenocx.dll
CLSID: {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
Startup Type: BHO
HijackThis Category: O2
HijackThis Line:

O2 – BHO: BhoApp – {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} – C:\WINDOWS\system32\wingenocx.dll

Description: trojan BHO that installed with Protection System (rogue antispyware software)

How to remove: use Malwarebytes Antimalware

96857956.exe is component of System Security

Friday, June 12th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: 96857956
Filename: 96857956.exe
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | 16847964

Command: C:\Documents and Settings\All Users\Application Data\16847964\16847964.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [16847964] C:\Documents and Settings\All Users\Application Data\16847964\16847964.exe

Description: component of System Security (rogue antispyware program)
Note: System Security uses random names for hide itself.

How to remove: use these System Security removal instructions.

WindOptimizer.exe is a main file of Wind Optimizer

Wednesday, June 10th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: WindOptimizer
Filename: WindOptimizer.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Wind Optimizer

Command: C:\Program Files\Wind Optimizer\WindOptimizer.exe
Startup Type: HKCU
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [Wind Optimizer] “C:\Program Files\Wind Optimizer\WindOptimizer.exe” /s

Description: main file of Wind Optimizer (rogue antispyware)

How to remove: use Malwarebytes Antimalware

xpdeluxe.exe is main file of XP Deluxe Protector

Thursday, June 4th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: xpdeluxe
Filename: xpdeluxe.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | xpprotect

Command: %UserProfile%\XP Deluxe Protector\xpdeluxe.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [xpprotect] C:\Documents and Settings\lab\XP Deluxe Protector\xpdeluxe.exe

Description: main file of XP Deluxe Protector (rogue antispyware program)

How to remove: use these XP Deluxe Protector removal instructions

WinBlueSoft.exe – WinBlueSoft rogue antispyware

Wednesday, June 3rd, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: WinBlueSoft
Filename: WinBlueSoft.exe
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | WinBlueSoft

Command: C:\Program Files\WinBlueSoft Software\WinBlueSoft\WinBlueSoft.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [WinBlueSoft] C:\Program Files\WinBlueSoft Software\WinBlueSoft\WinBlueSoft.exe -min

Description: WinBlueSoft.exe is a main component of WinBlueSoft rogue antispyware program

How to remove: use these WinBlueSoft removal instructions

windef – windef.exe – WinDefender2009

Tuesday, June 2nd, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: windef
Filename: windef.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | WinDefender2009

Command: c:\Program Files\WinDefender\windef.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [WinDefender2009] c:\Program Files\WinDefender\windef.exe

Description: windef.exe is a main file of WinDefender2009 (rogue antispyware program)

How to remove: use Malwarebytes Antimalware

FastAV – FastAV.exe – Fast Antivirus 2009

Sunday, May 24th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: FastAV
Filename: FastAV.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Fast Antivirus 2009

Command: C:\Documents and Settings\All Users\Application Data\d0aef09\FastAV.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [Fast Antivirus 2009] “C:\Documents and Settings\All Users\Application Data\d0aef09\FastAV.exe” /s /d

Description: main file of Fast Antivirus 2009 (rogue antipyware program)

How to remove: use the instructions How to remove Fast Antivirus 2009

AV.EXE is main file of Secure Antivirus Pro

Monday, May 18th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: AV
Filename: AV.EXE
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Secure AntiVirus Pro

Command: C:\WINDOWS\AV.EXE
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [Secure AntiVirus Pro] C:\WINDOWS\AV.EXE

Description: main file of Secure Antivirus Pro (rogue antispyware program)

How to remove: use the Secure Antivirus Pro removal instructions

MCatcher.exe is main file of Malware Catcher 2009

Friday, May 8th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: MCatcher
Filename: MCatcher.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Malware Catcher 2009

Command: C:\Documents and Settings\All Users\Application Data\f5bc4e8\MCatcher.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [Malware Catcher 2009] “C:\Documents and Settings\All Users\Application Data\f5bc4e8\MCatcher.exe” /s /d

Description: main file of Malware Catcher 2009 (rogue antispyware program)

How to remove: use Malwarebytes Antimalware

pav.exe is main file of Personal Antivirus

Thursday, May 7th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: pav
Filename: pav.exe
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | PAV

Command: c:\program files\pav\pav.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [PAV] c:\program files\pav\pav.exe

Description: main file of Personal Antivirus (rogue antispyware program)

How to remove: use these instructions How to remove Personal Antivirus