November 17th, 2009 O4, Rogue Antispyware/Antivirus, Run
personalprotector.exe is a harmful program.
Name: personalprotector
Filename: personalprotector.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | personalprotector
Command: C:\Program Files\Personal Protector\personalprotector.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [personalprotector] C:\Program Files\Personal Protector\personalprotector.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“personalprotector”=C:\Program Files\Personal Protector\personalprotector.exe [2009-11-17 1012736]
Description: core part of Personal Protector. Personal Protector is a rogue antispyware program.
How to remove: use these Personal Protector removal instructions.
November 16th, 2009 Rogue Antispyware/Antivirus, Winlogon\Shell
cc.exe is a harmful program.
Name: cc
Filename: cc.exe
Registry key:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell
Command: %UserProfile%\Application Data\CC\cc.exe
Startup Type: Winlogon\Shell
MalwareBytes Anti-malware shows this infection:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (C:\Documents and Settings\user\Application Data\CC\cc.exe) Good: (Explorer.exe)
Description: part of Control Center. Control Center is a fake Windows optimization application.
How to remove: use these Control Center removal instructions.
November 16th, 2009 O4, Rogue Antispyware/Antivirus, Run
LinkSafeness.exe is a harmful program.
Name: LinkSafeness
Filename: LinkSafeness.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | LinkSafeness
Command: C:\Program Files\LinkSafeness Software\LinkSafeness\LinkSafeness.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [LinkSafeness] C:\Program Files\LinkSafeness Software\LinkSafeness\LinkSafeness.exe -min
Combofix/RSIT Line:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“LinkSafeness”=C:\Program Files\LinkSafeness Software\LinkSafeness\LinkSafeness.exe [2009-11-17 1634304]
Description: core file of LinkSafeness. LinkSafeness is a fake security program also known as rogue antispyware.
How to remove: use these LinkSafeness removal instructions.
November 16th, 2009 Rogue Antispyware/Antivirus
iewarningsite.com is a malicious website
|
The site was created to spread Alpha Antivirus. If your browser is redirected to iewarningsite.com, then you should immediately check your PC using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. |
IP Address: 94.102.58.252
Site addess: iewarningsite.com
Description: The site used to promote the rogue antispyware program called Alpha Antivirus.
How to remove: use these Alpha Antivirus removal instructions in order to remove this infection.
November 13th, 2009 Driver, Trojan
tdidis32.sys is a harmful program.
Name: tdidis32
Filename: tdidis32.sys
Command: C:\WINDOWS\system32\tdidis32.sys
Startup Type: driver
Combofix/RSIT Line:
S1 tdidis32.sys;tdidis32.sys; \??\C:\WINDOWS\system32\tdidis32.sys []
Description: trojan agent also known as Rootkit.Win32.Pakes
How to remove: use SUPERAntiSpyware
November 13th, 2009 O1, Rogue Antispyware/Antivirus
awareremover2009.microsoft.com is a malicious website
|
The site was created to spread Antivirus System Pro. If your browser is redirected to awareremover2009.microsoft.com, then you should immediately check your PC using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. |
IP Address: 91.212.127.227
Site addess: awareremover2009.microsoft.com
HijackThis Category: O1
HijackThis Line:
O1 – Hosts: 91.212.127.227 awareremover2009.microsoft.com
Description: awareremover2009.microsoft.com is not related with Microsoft company and can only be seen on infected computers. The site used to promote the rogue antispyware program called Antivirus System Pro.
How to remove: use these Antivirus System Pro removal instructions in order to remove this infection.
November 11th, 2009 O4, Rogue Antispyware/Antivirus, Run
AntiAID.exe is a harmful program.
Name: AntiAID
Filename: AntiAID.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | AntiAID
Command: C:\Program Files\AntiAID Software\AntiAID\AntiAID.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [AntiAID] C:\Program Files\AntiAID Software\AntiAID\AntiAID.exe -min
Combofix/RSIT Line:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“AntiAID”=C:\Program Files\AntiAID Software\AntiAID\AntiAID.exe [2009-11-12 1634304]
Description: core part of AntiAID. AntiAID is a rogue antispyware program from WiniGuard scareware family.
How to remove: use these AntiAID removal instructions.
November 11th, 2009 O1, Rogue Antispyware/Antivirus
Osawarepro2009.microsoft.com is a malicious website
|
The site was created to spread Antivirus System Pro. If your browser is redirected to Osawarepro2009.microsoft.com, then you should immediately check your PC using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. |
IP Address: 91.212.127.227
Site addess: Osawarepro2009.microsoft.com
HijackThis Category:
HijackThis Line:
O1 – Hosts: 91.212.127.227 osawarepro2009.microsoft.com
Description: Osawarepro2009.microsoft.com is not related with Microsoft company and can only be seen on infected computers. The site used to promote the rogue antispyware program called Antivirus System Pro.
How to remove: use these Antivirus System Pro removal instructions in order to remove this infection.
November 11th, 2009 O4, Run, Worm
mstre22.exe is a harmful program.
Name: mstre22
Filename: mstre22.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | SySmstray
Command: C:\Windows\mstre22.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [SySmstray] C:\Windows\mstre22.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“SySmstray”=C:\Windows\mstre22.exe
Description: part of Koobface worm
How to remove: use HijackThis + Malwarebytes` Anti-malware
November 10th, 2009 O4, Rogue Antispyware/Antivirus, Run
SystemWarrior.exe is a harmful program.
Name: SystemWarrior
Filename: SystemWarrior.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | SystemWarrior
Command: C:\Program Files\SystemWarrior Software\SystemWarrior\SystemWarrior.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [SystemWarrior] “C:\Program Files\SystemWarrior Software\SystemWarrior\SystemWarrior.exe” -min
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“SystemWarrior”=C:\Program Files\SystemWarrior Software\SystemWarrior\SystemWarrior.exe [2009-11-11 742400]
Description: core part of SystemWarrior. SystemWarrior is a rogue antispyware program.
How to remove: use these SystemWarrior removal instructions.