January 23rd, 2010 O4, Rogue Antispyware/Antivirus, Run
securitycenter.exe is a harmful program.
Name: securitycenter
Filename: securitycenter.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | SecurityCenter
Command: C:\Program Files\Desktop Security 2010\securitycenter.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [SecurityCenter] C:\Program Files\Desktop Security 2010\securitycenter.exe
DDS Line:
mRun: [SecurityCenter] C:\Program Files\Desktop Security 2010\securitycenter.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“SecurityCenter”=C:\Program Files\Desktop Security 2010\securitycenter.exe
Description: component of Desktop Security 2010. Desktop Security 2010 is a rogue antispyware program.
How to remove: use these Desktop Security 2010 removal instructions.
January 23rd, 2010 O4, Rogue Antispyware/Antivirus, Run
Desktop Security 2010.exe is a harmful program.
Name: Desktop Security 2010
Filename: Desktop Security 2010.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Desktop Security 2010
Command: C:\Program Files\Desktop Security 2010\Desktop Security 2010.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [Desktop Security 2010] C:\Program Files\Desktop Security 2010\Desktop Security 2010.exe
DDS Line:
mRun: [Desktop Security 2010] C:\Program Files\Desktop Security 2010\Desktop Security 2010.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“Desktop Security 2010″=C:\Program Files\Desktop Security 2010\Desktop Security 2010.exe
Description: core component of Desktop Security 2010. Desktop Security 2010 is a rogue antispyware program.
How to remove: use these Desktop Security 2010 removal instructions.
January 22nd, 2010 O4, Rogue Antispyware/Antivirus, Run
ProtectSoldier.exe is a harmful program.
Name: ProtectSoldier
Filename: ProtectSoldier.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | ProtectSoldier
Command: C:\Program Files\ProtectSoldier Software\ProtectSoldier\ProtectSoldier.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [ProtectSoldier] C:\Program Files\ProtectSoldier Software\ProtectSoldier\ProtectSoldier.exe
DDS Line:
mRun: [ProtectSoldier] C:\Program Files\ProtectSoldier Software\ProtectSoldier\ProtectSoldier.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“ProtectSoldier”=C:\Program Files\ProtectSoldier Software\ProtectSoldier\ProtectSoldier.exe
Description: core part of ProtectSoldier. ProtectSoldier is a rogue antispyware program.
How to remove: use these ProtectSoldier removal instructions.
January 22nd, 2010 O4, Rogue Antispyware/Antivirus, Run
APcSecure.exe is a harmful program.
Name: APcSecure
Filename: APcSecure.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | APcSecure
Command: C:\Program Files\APcSecure Software\APcSecure\APcSecure.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [APcSecure] C:\Program Files\APcSecure Software\APcSecure\APcSecure.exe
DDS Line:
mRun: [APcSecure] C:\Program Files\APcSecure Software\APcSecure\APcSecure.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“APcSecure”=C:\Program Files\APcSecure Software\APcSecure\APcSecure.exe
Description: core component of APcSecure. APcSecure is a rogue antispyware program that spreads through the use of trojans that come from fake online scanners and once installed, it detects false infections.
How to remove: use these APcSecure removal instructions.
January 21st, 2010 autorun.inf, Trojan
9fo3ar0j.exe is a harmful program.
Name: 9fo3ar0j
Filename: 9fo3ar0j.exe
Command: c:\9fo3ar0j.exe
Startup Type: autorun.inf
Description: autorun.inf trojan also known as Mal/Generic-A [Sophos], PWS.Win32 [Ikarus], packed with ASPack [Kaspersky Lab]. The trojan is installed with herss.exe trojan.
How to remove: use these autorun.inf trojans removal instructions + run Kaspersky virus removal tool
January 21st, 2010 O4, Startup folder, Trojan
wwwpos32.exe is a harmful program.
Name: wwwpos32
Filename: wwwpos32.exe
Command: c:\documents and settings\user\start menu\programs\startup\wwwpos32.exe
Startup Type: Startup folder
HijackThis Category: O4
HijackThis Line:
O4 – Startup: wwwpos32.exe
DDS Line:
StartupFolder: c:\documents and settings\user\start menu\programs\startup\wwwpos32.exe
Combofix/RSIT Line:
C:\Documents and Settings\user\Start Menu\Programs\Startup
wwwpos32.exe [2008-4-14 40448]
Description: trojan
How to remove: use HijackThis + Kaspersky virus removal tool
January 21st, 2010 O4, Rogue Antispyware/Antivirus, Run
ProtectDefender.exe is a harmful program.
Name: ProtectDefender
Filename: ProtectDefender.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | ProtectDefender
Command: C:\Program Files\ProtectDefender Software\ProtectDefender\ProtectDefender.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [ProtectDefender] C:\Program Files\ProtectDefender Software\ProtectDefender\ProtectDefender.exe
DDS Line:
mRun: [ProtectDefender] C:\Program Files\ProtectDefender Software\ProtectDefender\ProtectDefender.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“ProtectDefender”=C:\Program Files\ProtectDefender Software\ProtectDefender\ProtectDefender.exe
Description: core part of ProtectDefender. ProtectDefender is a rogue antispyware program.
How to remove: use these ProtectDefender removal instructions.
January 20th, 2010 O4, Rogue Antispyware/Antivirus, Run
cliconfg64.exe is a harmful program.
Name: cliconfg64
Filename: cliconfg64.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | cliconfg64.exe
Command: %UserProfile%\temp\cliconfg64.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [cliconfg64.exe] C:\DOCUME~1\user\LOCALS~1\Temp\cliconfg64.exe
DDS Line:
uRun: [cliconfg64.exe] c:\dokume~1\user\lokale~1\temp\cliconfg64.exe
Combofix/RSIT Line:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“cliconfg64.exe”=c:\dokume~1\user\lokale~1\temp\cliconfg64.exe
Description: component of trojan FakeAlert.
How to remove: use HijackThis + Malwarebytes` Anti-malware
January 19th, 2010 O4, Rogue Antispyware/Antivirus, Run
ArmorDefender.exe is a harmful program.
Name: ArmorDefender
Filename: ArmorDefender.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | ArmorDefender
Command: C:\Program Files\ArmorDefender Software\ArmorDefender\ArmorDefender.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [ArmorDefender] C:\Program Files\ArmorDefender Software\ArmorDefender\ArmorDefender.exe
DDS Line:
mRun: [ArmorDefender] C:\Program Files\ArmorDefender Software\ArmorDefender\ArmorDefender.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“ArmorDefender”=C:\Program Files\ArmorDefender Software\ArmorDefender\ArmorDefender.exe
Description: core part of ArmorDefender. ArmorDefender is a rogue antispyware program.
How to remove: use these ArmorDefender removal instructions.
January 17th, 2010 O4, Rogue Antispyware/Antivirus, Startup folder
WinSecurity360.exe is a harmful program.
Name: WinSecurity360
Filename: WinSecurity360.exe
Command: C:\Program Files\WinSecurity360\WinSecurity360.exe
Startup Type: StartupFolder
HijackThis Category: O4
HijackThis Line:
O4 – Startup: Win Security 360.lnk = C:\Program Files\WinSecurity360\WinSecurity360.exe
DDS Line:
StartupFolder: Win Security 360.lnk
Combofix/RSIT Line:
C:\Documents and Settings\user\Start Menu\Programs\Startup
Win Security 360.lnk
Description: core part of Win Security 360. Win Security 360 is a rogue antispyware program.
How to remove: use these Win Security 360 removal instructions.