Archive for the 'O4' Category
Friday, October 9th, 2009
Antivirus.exe is a harmful program.
Name: Antivirus
Filename: Antivirus.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Antivirus.exe
Command: C:\Program Files\Antivirus\Antivirus.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [Antivirus.exe] C:\Program Files\Antivirus\Antivirus.exe
DDS Line:
uRun: [Antivirus.exe] C:\Program Files\Antivirus\Antivirus.exe
Combofix/RSIT Line:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Antivirus.exe”=C:\Program Files\Antivirus\Antivirus.exe
Description: core part of Antivirus. Antivirus is a rogue antispyware program.
How to remove: use Antivirus removal instructions.
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Wednesday, October 7th, 2009
SafeFighter.exe is a harmful program.
Name: SafeFighter
Filename: SafeFighter.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SafeFighter
Command: command
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SafeFighter] C:\Program Files\SafeFighter Software\SafeFighter\SafeFighter.exe -min
RSIT Line:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“SafeFighter”=C:\Program Files\SafeFighter Software\SafeFighter\SafeFighter.exe [2009-10-08 831488]
Description: part of SafeFighter. SafeFighter is a scareware that utilizes false scan results and fake security alerts as method to scare you into buying the software.
How to remove: use these SafeFighter removal instructions.
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Monday, October 5th, 2009
TrustCop.exe is a harmful program.
Name: TrustCop
Filename: TrustCop.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | TrustCop
Command: C:\Program Files\TrustCop Software\TrustCop\TrustCop.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [TrustCop] C:\Program Files\TrustCop Software\TrustCop\TrustCop.exe -min
Combofix/RSIT Line:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“TrustCop”=C:\Program Files\TrustCop Software\TrustCop\TrustCop.exe [2009-10-06 786432]
Description: main file of TrustCop. TrustCop is a fake antispyware program.
Removal instructions: How to Remove TrustCop (Uninstall instructions).
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Friday, October 2nd, 2009
SecureWarrior.exe is a harmful program.
Name: SecureWarrior
Filename: SecureWarrior.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecureWarrior
Command: C:\Program Files\SecureWarrior Software\SecureWarrior\SecureWarrior.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SecureWarrior] C:\Program Files\SecureWarrior Software\SecureWarrior\SecureWarrior.exe -min
Combofix/RSIT Line:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“SecureWarrior”=C:\Program Files\SecureWarrior Software\SecureWarrior\SecureWarrior.exe [2009-10-02 830976]
Description: main component of SecureWarrior rogue antispyware software
How to remove: use these SecureWarrior removal instructins
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Wednesday, September 30th, 2009
This is a harmful program.
Name: SecureFighter
Filename: SecureFighter.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecureFighter
Command: C:\Program Files\SecureFighter Software\SecureFighter\SecureFighter.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SecureFighter] C:\Program Files\SecureFighter Software\SecureFighter\SecureFighter.exe -min
Description: component of SecureFighter rogue antispyware program
How to remove: use these SecureFighter removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Tuesday, September 29th, 2009
This is a harmful program.
Name: ld14
Filename: ld14.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysldtray
Command: C:\Windows\ld14.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sysldtray] C:\Windows\ld14.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysldtray”=C:\Windows\ld14.exe [2009-09-23 61440]
Description: component of worm koobface, that takes over computers by spreading through the social networks
How to remove: use Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Tuesday, September 29th, 2009
This is a harmful program.
Name: pp12
Filename: pp12.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | pp
Command: C:\Windows\pp12.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [pp] C:\Windows\pp12.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“pp”=C:\Windows\pp12.exe [2009-09-23 49152]
Description: component of worm koobface
How to remove: use Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Tuesday, September 29th, 2009
This is a harmful program.
Name: freddy66
Filename: freddy66.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysfbtray
Command: c:\windows\freddy66.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sysfbtray] c:\windows\freddy66.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysfbtray”=c:\windows\freddy66.exe [2009-09-25 77824]
Description: part of worm Koobface that takes over computers by spreading through the social networks
How to remove: use Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Tuesday, September 29th, 2009
SecureVeteran.exe is a harmful program.
Name: SecureVeteran
Filename: SecureVeteran.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecureVeteran
Command: C:\Program Files\SecureVeteran Software\SecureVeteran\SecureVeteran.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SecuritySoldier] C:\Program Files\SecureVeteran Software\SecureVeteran\SecureVeteran.exe -min
Description: main file of SecureVeteran rogue antispyware program
How to remove: use these SecureVeteran removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Monday, September 28th, 2009
NetFilter.exe is a harmful program.
Name: NetFilter
Filename: NetFilter.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | MSDRV
Command: C:\WINDOWS\system32\NetFilter.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [MSDRV] NetFilter.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“MSDRV”=C:\WINDOWS\system32\NetFilter.exe [2009-09-23 122880]
Description: trojan that installed by Alpha Antivirus rogue antispyware program
How to remove: use these Alpha Antivirus removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run, Trojan | No Comments »