Archive for February, 2010

What is Antispyware.exe, How to remove Antispyware.exe

Saturday, February 20th, 2010

Antispyware.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: Antispyware.exe
Filename: Antispyware.exe
Registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Userinit

Command: C:\Program Files\Def Group\PC Defender\Antispyware.exe
Startup Type: Winlogon\UserInit
HijackThis Category: F2
HijackThis Line:

F2 – REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,”C:\Program Files\Def Group\PC Defender\Antispyware.exe”

Description: core component of PC Defender. PC Defender is a rogue antispyware program.

How to remove: use these PC Defender removal instructions.

What is Antimalware Doctor.exe, How to remove Antimalware Doctor.exe

Saturday, February 20th, 2010

Antimalware Doctor.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: Antimalware Doctor
Filename: Antimalware Doctor.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Antimalware Doctor.exe

Command: C:\Windows\System32\Antimalware Doctor.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [Antimalware Doctor.exe] C:\Windows\System32\Antimalware Doctor.exe

DDS Line:

uRun: [Antimalware Doctor.exe] C:\Windows\System32\Antimalware Doctor.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Antimalware Doctor.exe”=C:\Windows\System32\Antimalware Doctor.exe

Description: core component of Antimalware Doctor. Antimalware Doctor is a rogue antispyware program.

How to remove: use these Antimalware Doctor removal instructions.

What is eventcreatexp.exe, How to remove eventcreatexp.exe

Friday, February 19th, 2010

eventcreatexp.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: eventcreatexp
Filename: eventcreatexp.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | eventcreatexp.exe

Command: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\eventcreatexp.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [eventcreatexp.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\eventcreatexp.exe

DDS Line:

uRun: [eventcreatexp.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\eventcreatexp.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“eventcreatexp.exe”=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\eventcreatexp.exe

Description: trojan FakeAlert that installed with Paladin Antivirus. Paladin Antivirus is a rogue antispyware program.

How to remove: use these Paladin Antivirus removal instructions.

What is SysShield.exe, How to remove SysShield.exe

Tuesday, February 16th, 2010

SysShield.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: SysShield
Filename: SysShield.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Windows applications server

Command: C:\Program Files\Personal Anti Malware\SysShield.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [Windows applications server] C:\Program Files\Personal Anti Malware\SysShield.exe

DDS Line:

uRun: [Windows applications server] C:\Program Files\Personal Anti Malware\SysShield.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Windows applications server”=C:\Program Files\Personal Anti Malware\SysShield.exe

Description: trojan FakeAlert, component of Personal Anti Malware. Personal Anti Malware is a rogue antispyware program.

How to remove: use these Personal Anti Malware removal inbstructions.

What is PAM.exe, How to remove PAM.exe

Tuesday, February 16th, 2010

PAM.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: PAM
Filename: PAM.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Personal Anti Malware

Command: C:\Program Files\Personal Anti Malware\PAM.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [Personal Anti Malware] C:\Program Files\Personal Anti Malware\PAM.exe

DDS Line:

uRun: [Personal Anti Malware] C:\Program Files\Personal Anti Malware\PAM.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Personal Anti Malware”=C:\Program Files\Personal Anti Malware\PAM.exe

Description: core component of Personal Anti Malware. Personal Anti Malware is a rogue antispyware program.

How to remove: use these Personal Anti Malware removal instructions.

What is SE2010.exe, How to remove SE2010.exe

Monday, February 15th, 2010

SE2010.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: SE2010
Filename: SE2010.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Security essentials 2010

Command: C:\Program Files\Securityessentials2010\SE2010.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [Security essentials 2010] C:\Program Files\Securityessentials2010\SE2010.exe

DDS Line:

uRun: [Security essentials 2010] C:\Program Files\Securityessentials2010\SE2010.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Security essentials 2010″=C:\Program Files\Securityessentials2010\SE2010.exe

Description: core component of Security Essentials 2010. Security Essentials 2010 is a rogue antispyware program.

How to remove: use these Security Essentials 2010 removal instructions.

What is ccmain.exe, How to remove ccmain.exe

Saturday, February 13th, 2010

ccmain.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: ccmain
Filename: ccmain.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell

Command: %UserProfile%\Application Data\Control-Center\ccagent.exe
Startup Type: Winlogon\Shell
HijackThis Category: F2
HijackThis Line:

F2 – REG:system.ini: %UserProfile%\Application Data\Control-Center\ccagent.exe

Description: core component of Control Center. Control Center isa fake Windows optimization program.

How to remove: use these Control Center removal instructions.

My Security Wall – MS176.exe

Friday, February 12th, 2010

MS176.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: MS176
Filename: MS176.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | My Security Wall

Command: C:\Documents and Settings\All Users\Application Data\15a2f\MS176.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [My Security Wall] “C:\Documents and Settings\All Users\Application Data\15a2f\MS176.exe” /s /d

DDS Line:

uRun: [My Security Wall] C:\Documents and Settings\All Users\Application Data\15a2f\MS176.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“My Security Wall”=C:\Documents and Settings\All Users\Application Data\15a2f\MS176.exe

Description: core component of My Security Wall. My Security Wall is a rogue antispyware program.

How to remove: use these My Security Wall removal instructions.

What is taskmandb.exe, How to remove taskmandb.exe

Friday, February 12th, 2010

taskmandb.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: taskmandb
Filename: taskmandb.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | taskmandb.exe

Command: %UserProfile%\LOCALS~1\Temp\taskmandb.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [taskmandb.exe] C:\DOCUME~1\comp\LOCALS~1\Temp\taskmandb.exe

DDS Line:

uRun: [taskmandb.exe] C:\DOCUME~1\comp\LOCALS~1\Temp\taskmandb.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“taskmandb.exe”=C:\DOCUME~1\comp\LOCALS~1\Temp\taskmandb.exe

Description: trojan FakeAlert

How to remove: use HijackThis + Malwarebytes` Anti-malware

What is freddy101.exe, How to remove freddy101.exe

Friday, February 12th, 2010

freddy101.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: freddy101
Filename: freddy101.exe
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysfbtray

Command: C:\windows\freddy101.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [sysfbtray] C:\windows\freddy101.exe

DDS Line:

mRun: [sysfbtray] C:\windows\freddy101.exe

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysfbtray”=C:\windows\freddy101.exe

Description: component of Koobface worm.

How to remove: use these Koobface removal instructions.