July 23rd, 2009 BHO, O2, Trojan
This is a harmful program.
Name: kj32
Filename: kj32.dll
Registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6458C00E-EF7F-4f06-9E06-49EA923386FD}
Command: C:\WINDOWS\System32\kj32.dll
CLSID: {6458C00E-EF7F-4f06-9E06-49EA923386FD}
Startup Type: BHO
HijackThis Category: O2
HijackThis Line:
O2 – BHO: pl – {6458C00E-EF7F-4f06-9E06-49EA923386FD} – C:\WINDOWS\System32\kj32.dll
Description: trojan bho
How to remove: use HijackThis + use Malwarebytes` Anti-malware
July 23rd, 2009 O4, Run, Trojan
This is a harmful program.
Name: _ex-68
Filename: _ex-68.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | PromoReg
Command: C:\WINDOWS\Temp\_ex-68.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [PromoReg] C:\WINDOWS\Temp\_ex-68.exe
Description: unknown trojan component, that installed with rogue antispyware programs
How to remove: use HijackThis + use Malwarebytes Antimalware
July 23rd, 2009 O4, Policies\Explorer\Run, Worm
This is a harmful program.
Name: csrcs
Filename: csrcs.exe
Command: C:\WINDOWS\system32\csrcs.exe
Startup Type: Policies->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe
Description: worm [W32/Spybot]
How to remove: use HijackThis + use Malwarebytes Antimalware
July 23rd, 2009 O4, Startup folder, Trojan
This is a harmful program.
Name: rncsys32
Filename: rncsys32.exe
Startup Type: Startup folder
HijackThis Category: O4
HijackThis Line:
O4 – Startup: rncsys32.exe
Description: trojan [Downloader-BRM]. Read more here.
How to remove: use HijackThis
July 23rd, 2009 O4, Startup folder, Trojan
This is a harmful program.
Name: Cleanup
Filename: Cleanup.exe
Startup Type: Startup folder
HijackThis Category: O4
HijackThis Line:
O4 – Global Startup: Cleanup.exe
Description: trojan component [Trojan.Win32.Zapchast]
How to remove: use HijackThis + use Malwarebytes Antimalware
July 19th, 2009 O4, Rogue Antispyware/Antivirus, Run
This is a harmful program.
Name: HomeAntivirus2010
Filename: HomeAntivirus2010.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Home Antivirus 2010
Command: C:\Program Files\HomeAntivirus2010\HomeAntivirus2010.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [Home Antivirus 2010] “C:\Program Files\HomeAntivirus2010\HomeAntivirus2010.exe” /hide
Description: main file of Home Antivirus 2010 (rogue antispyware program)
How to remove: use these Home Antivirus 2010 removal instructions.
July 16th, 2009 O4, Rogue Antispyware/Antivirus, Run
This is a harmful program.
Name: MalwareRemoval
Filename: MalwareRemoval.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | MalwareRemoval
Command: C:\Program Files\MalwareRemoval\MalwareRemoval.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [MalwareRemoval] C:\Program Files\MalwareRemoval\MalwareRemoval.exe
Description: main file of Fake Microsoft Windows Malicious Software Removal Tool
How to remove: use Malwarebytes Antimalware
July 16th, 2009 O4, Rogue Antispyware/Antivirus, Run
This is a harmful program.
Name: AntiVirus_Pro
Filename: AntiVirus_Pro.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | AntiVirus_ProNET
Command: C:\Program Files\AntiVirus_Pro\AntiVirus_Pro.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [AntiVirus_ProNET] C:\Program Files\AntiVirus_Pro\AntiVirus_Pro.exe
Description: main file of AntiVirusPro (fake antivirus software)
How to remove: use these AntiVirusPro removal instructions.
July 12th, 2009 O4, Rogue Antispyware/Antivirus, Run
This is a harmful program.
Name: PC_Security2009
Filename: PC_Security2009.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | PC Security 2009
Command: C:\Program Files\PC_Security2009\PC_Security2009.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [PC Security 2009] “C:\Program Files\PC_Security2009\PC_Security2009.exe” /hide
Description: main file of PC Security 2009 (rogue antispyware program)
How to remove: use these PC Security 2009 removal instructions.
July 10th, 2009 O23, Rogue Antispyware/Antivirus, Service
This is a harmful program.
Name: WiniFighterSvc
Filename: WiniFighterSvc.exe
Registry key:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winifightersvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\winifightersvc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winifightersvc
Command: C:\Program Files\WiniFighter Software\WiniFighter\WiniFighterSvc.exe
Startup Type: Service
HijackThis Category: O23
HijackThis Line:
O23 – Service: WiniFighter Security Service (WiniFighterSvc) – Unknown owner – C:\Program Files\WiniFighter Software\WiniFighter\WiniFighterSvc.exe
How to remove: use these WiniFighter removal instructions.