Archive for December, 2009

What is ProtectPcs.exe, How to remove ProtectPcs.exe

Sunday, December 20th, 2009

ProtectPcs.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: ProtectPcs
Filename: ProtectPcs.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | ProtectPcs.exe

Command: C:\Program Files\ProtectPcs Software\ProtectPcs\ProtectPcs.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [ProtectPcs.exe] C:\Program Files\ProtectPcs Software\ProtectPcs\ProtectPcs.exe

DDS Line:

uRun: [ProtectPcs.exe] C:\Program Files\ProtectPcs Software\ProtectPcs\ProtectPcs.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“ProtectPcs.exe”=C:\Program Files\ProtectPcs Software\ProtectPcs\ProtectPcs.exe [2009-12-21 1638912]

Description: core component of ProtectPcs. ProtectPcs is a rogue antispyware program.

How to remove: use these ProtectPcs removal instructions.

What is mdefense.exe, How to remove mdefense.exe

Sunday, December 20th, 2009

mdefense.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: mdefense
Filename: mdefense.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Malware Defense

Command: C:\Program Files\Malware Defense\mdefense.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [Malware Defense] “C:\Program Files\Malware Defense\mdefense.exe” -noscan

DDS Line:

uRun: [Malware Defense] C:\Program Files\Malware Defense\mdefense.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Malware Defense”=C:\Program Files\Malware Defense\mdefense.exe [2009-12-20 1756088]

Description: core component of Malware Defense. Malware Defense is a rogue antispyware program.

How to remove: use these Malware Defense removal instructions.

What is clspackxq.exe, How to remove clspackxq.exe

Saturday, December 19th, 2009

clspackxq.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: clspackxq
Filename: clspackxq.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | clspackxq.exe

Command: %Temp%\clspackxq.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [clspackxq.exe] c:\docume~1\user\locals~1\temp\clspackxq.exe

DDS Line:

uRun: [clspackxq.exe] c:\docume~1\user\locals~1\temp\clspackxq.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“clspackxq.exe”=c:\docume~1\user\locals~1\temp\clspackxq.exe

Description: trojan FakeAlert

How to remove: use HijackThis + Malwarebytes` Anti-malware

What is SysDefence.exe, How to remove SysDefence.exe

Thursday, December 17th, 2009

SysDefence.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: SysDefence
Filename: SysDefence.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SysDefence.exe

Command: C:\Program Files\SysDefence Software\SysDefence\SysDefence.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [SysDefence.exe] C:\Program Files\SysDefence Software\SysDefence\SysDefence.exe

DDS Line:

uRun: [SysDefence.exe] C:\Program Files\SysDefence Software\SysDefence\SysDefence.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“SysDefence.exe”=C:\Program Files\SysDefence Software\SysDefence\SysDefence.exe [2009-12-17 1638912]

Description: core component of SysDefence. SysDefence is positioned as an anti-spyware software, but in reality it is a malicious program, which must be removed immediately after getting on the computer!

How to remove: use these SysDefence removal instructions.

What is TheDefend.exe, How to remove TheDefend.exe

Wednesday, December 16th, 2009

TheDefend.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: TheDefend
Filename: TheDefend.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | TheDefend.exe

Command: C:\Program Files\TheDefend Software\TheDefend\TheDefend.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [TheDefend.exe] C:\Program Files\TheDefend Software\TheDefend\TheDefend.exe

DDS Line:

uRun: [TheDefend.exe] C:\Program Files\TheDefend Software\TheDefend\TheDefend.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“TheDefend.exe”=C:\Program Files\TheDefend Software\TheDefend\TheDefend.exe [2009-12-17 1638912]

Description: core component of TheDefend. TheDefend is positioned as a program to remove malware, but in reality it is a malicious program, which must be removed immediately after getting on the computer!

How to remove: use these TheDefend removal instructions.

What is winsecurepro2010.microsoft.com, How to remove winsecurepro2010.microsoft.com

Wednesday, December 16th, 2009

winsecurepro2010.microsoft.com is a malicious website

remove The site was created to spread Antivirus Live. If your browser is redirected to winsecurepro2010.microsoft.com, then you should immediately check your PC using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Site addess: winsecurepro2010.microsoft.com
Description: winsecurepro2010.microsoft.com is not related with Microsoft company and can only be seen on infected computers. The site used to promote the rogue antispyware program called Antivirus Live.

How to remove: use these Antivirus Live removal instructions in order to remove this infection.

What is GuardPcs.exe, How to remove GuardPcs.exe

Tuesday, December 15th, 2009

GuardPcs.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: GuardPcs
Filename: GuardPcs.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | GuardPcs.exe

Command: C:\Program Files\GuardPcs Software\GuardPcs\GuardPcs.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [GuardPcs.exe] C:\Program Files\GuardPcs Software\GuardPcs\GuardPcs.exe

DDS Line:

uRun: [GuardPcs.exe] C:\Program Files\GuardPcs Software\GuardPcs\GuardPcs.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“GuardPcs.exe”=C:\Program Files\GuardPcs Software\GuardPcs\GuardPcs.exe [2009-12-15 1638912]

Description: core component of GuardPcs. GuardPcs is a rogue antispyware program.

How to remove: use these GuardPcs removal instructions.

What is Freddy77.exe, How to remove Freddy77.exe

Monday, December 14th, 2009

Freddy77.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: Freddy77
Filename: Freddy77.exe
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysfbtray

Command: C:\windows\freddy77.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [sysfbtray] C:\windows\freddy77.exe

DDS Line:

mRun: [sysfbtray] C:\windows\freddy77.exe

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysfbtray”=C:\windows\freddy77.exe

Description: part of Koobface worm

How to remove: use these Koobface removal instructions.

What is winsts.sys, How to remove winsts.sys

Sunday, December 13th, 2009

winsts.sys is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: winsts
Filename: winsts.sys
Registry key:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winsts

Command: c:\windows\system32\winsts.sys
Startup Type: Service
HijackThis Category: O23
HijackThis Line:

O23 – Service: winsts (winsts) – – C:\WINDOWS\system32\winsts.sys

DDS/Combofix/RSIT Line:

S3 winsts;winsts;c:\windows\system32\winsts.sys

Description: trojan

How to remove: use HijackThis + Kaspersky virus removal tool or ask for help in the Spyware removal forum.
How to remove: link

What is ansid.exe, How to remove ansid.exe

Sunday, December 13th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: ansid
Filename: ansid.exe
Registry key:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mnmsrvcRDSessMgr

Command: c:\windows\SYSTEM32\ansid.exe
Startup Type: Service
HijackThis Category:
HijackThis Line:

O23 – Service: NetMeeting Remote Desktop Sharing mnmsrvcRDSessMgr (mnmsrvcRDSessMgr) – – C:\WINDOWS\system32\ansid.exe srv

DDS/Combofix/RSIT Line:

R2 mnmsrvcRDSessMgr;NetMeeting Remote Desktop Sharing mnmsrvcRDSessMgr;c:\windows\SYSTEM32\ansid.exe srv

Description: virus also known as W32.Virut.CF [Symantec], Virus.Win32.Virut.ce [Kaspersky Lab], W32/Virut.n.gen [McAfee], W32/Scribble-B [Sophos], Virus:Win32/Virut.BM [Microsoft]

How to remove: use Kaspersky virus removal tool