Archive for the 'Run' Category
Tuesday, September 29th, 2009
This is a harmful program.
Name: pp12
Filename: pp12.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | pp
Command: C:\Windows\pp12.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [pp] C:\Windows\pp12.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“pp”=C:\Windows\pp12.exe [2009-09-23 49152]
Description: component of worm koobface
How to remove: use Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Tuesday, September 29th, 2009
This is a harmful program.
Name: freddy66
Filename: freddy66.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysfbtray
Command: c:\windows\freddy66.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sysfbtray] c:\windows\freddy66.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sysfbtray”=c:\windows\freddy66.exe [2009-09-25 77824]
Description: part of worm Koobface that takes over computers by spreading through the social networks
How to remove: use Malwarebytes` Anti-malware
Posted in O4, Run, Worm | No Comments »
Tuesday, September 29th, 2009
SecureVeteran.exe is a harmful program.
Name: SecureVeteran
Filename: SecureVeteran.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecureVeteran
Command: C:\Program Files\SecureVeteran Software\SecureVeteran\SecureVeteran.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SecuritySoldier] C:\Program Files\SecureVeteran Software\SecureVeteran\SecureVeteran.exe -min
Description: main file of SecureVeteran rogue antispyware program
How to remove: use these SecureVeteran removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Monday, September 28th, 2009
NetFilter.exe is a harmful program.
Name: NetFilter
Filename: NetFilter.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | MSDRV
Command: C:\WINDOWS\system32\NetFilter.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [MSDRV] NetFilter.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“MSDRV”=C:\WINDOWS\system32\NetFilter.exe [2009-09-23 122880]
Description: trojan that installed by Alpha Antivirus rogue antispyware program
How to remove: use these Alpha Antivirus removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run, Trojan | No Comments »
Monday, September 28th, 2009
AlphaAV.exe is a harmful program.
Name: AlphaAV
Filename: AlphaAV.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | AlphaAV
Command: C:\Program Files\AlphaAV\AlphaAV.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [AlphaAV] C:\Program Files\AlphaAV\AlphaAV.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“AlphaAV”=C:\Program Files\AlphaAV\AlphaAV.exe [2009-09-26 1581056]
Description: main file of Alpha Antivirus rogue antispyware program
How to remove: use these Alpha Antivirus removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Saturday, September 26th, 2009
This is a harmful program.
Name: SecuritySoldier
Filename: SecuritySoldier.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecuritySoldier
Command: C:\Program Files\SecuritySoldier Software\SecuritySoldier\SecuritySoldier.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SecuritySoldier] C:\Program Files\SecuritySoldier Software\SecuritySoldier\SecuritySoldier.exe -min
Description: main component of SecuritySoldier rogue antispyware program
How to remove: use these SecuritySoldier removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Thursday, September 24th, 2009
SecurityFighter.exe is a harmful program.
Name: SecurityFighter
Filename: SecurityFighter.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecurityFighter
Command: C:\Program Files\SecurityFighter Software\SecurityFighter\SecurityFighter.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SecurityFighter] C:\Program Files\SecurityFighter Software\SecurityFighter\SecurityFighter.exe -min
Description: main file of SecurityFighter fake antispyware program
How to remove: use these SecurityFighter removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Tuesday, September 22nd, 2009
This is a harmful program.
Name: wsn
Filename: wsn.bat
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | RANDOM NUMBERS
Command: C:\ProgramData\gra\wsn.bat
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [RANDOM NUMBERS] C:\ProgramData\gwr\wsn.bat
O4 – HKCU\..\Run: [RANDOM NUMBERS] C:\ProgramData\gra\wsn.bat
Description: component of Green AV rogue antivirus/antispyware program
How to remove: use these Green AV removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Monday, September 21st, 2009
This is a harmful program.
Name: SaveArmor
Filename: SaveArmor.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SaveArmor
Command: C:\Program Files\SaveArmor Software\SaveArmor\SaveArmor.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SaveArmor] C:\Program Files\SaveArmor Software\SaveArmor\SaveArmor.exe -min
Description: main component of SaveArmor rogue antispyware program
How to remove: use these SaveArmor removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »
Monday, September 21st, 2009
This is a harmful program.
Name: SaveDefender
Filename: SaveDefender.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SaveDefender
Command: C:\Program Files\SaveDefender Software\SaveDefender\SaveDefender.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [SaveDefender] C:\Program Files\SaveDefender Software\SaveDefender\SaveDefender.exe -min
Description: main file of SaveDefender rogue antispyware program
How to remove: use these SaveDefender removal instructions
Posted in O4, Rogue Antispyware/Antivirus, Run | No Comments »