System Security 4.52
System Security 4.52 Description
System Security 4.52 is a new rogue anti-spyware application emanating from the same family as System Security, System Security 2009 and System Security 4.51. Usually System Security 4.52 is downloaded onto a computer once a fake video codec is installed manually by an unknowing user. Once active, System Security 4.52 kills all .exe processes, leaving the system without fully operational and functional processes. Along with fake scan reports that display fictitious and sometimes grossly exaggerated infection results, the user is prompted to purchase and download the fake spyware remover System Security 4.52 in order to combat these threats.
Type: Rogue AntiSpyware Programs
Automatic Detection of System Security 4.52
System Security 4.52 has typically the following processes in memory:
- 549344438.exe
- 1003720520.exe
- TubePlayer.ver.6.exe
- mupd1_2_1165664.exe
- ldycgadzmr.dll
- 19329203.exe
- 281681216.exe
- bnmio.exe
- iii[1].exe
- ParisHilton[1].exe
- card[1].exe
- AdwarePro_Setup[1].exe
- 1[1].exe
- Omahonafazeq.dll
- adv111[1].exe
- ieupdates.exe
- loader[1].exe
- i386si.sys
- uxeqipuzimocin.dll
- winlogin.exe
- imod3.dll
- swapdm.dll
- 431192516.exe
- 931330021.exe
- 432632312.exe
- 438978017.exe
- 2030350728.exe
- 1431998300.exe
- 1767930182.exe
- 1550536869.exe
- 2029503323.exe
- 375534146.exe
- 370382475.exe
- 25238076.exe
- 1690486455.exe
- 1255330437.exe
- 01560265.exe
- 500153984.exe
- 13496218.exe
- 06837430.exe
- 90188702.exe
- 13059684.exe
- 17236094.exe
- 14865934.exe
- 16846714.exe
- 18058594.exe
- 99363896.exe
- 10639534.exe
- 19916874.exe
- 14147964.exe
- 14945624.exe
- 16723754.exe
- 90249366.exe
- 936453029.exe
- 1714292029.exe
- AdobeFlash[1].exe
- torbjne.exe
- iemodule.dll
- iehelper.exe
- install[1].exe
- ~tmpa.exe
- vamsoft.exe
- winafoe.exe
- TckBX673.exe
- AdwarePro.exe
- StartApp.exe
- usp10.dll
- gr[2].exe
- SetupAntivirusXP[1].exe
- Test.exe
- Hyves_Browser_Instalation.exe
- 1462403437.exe
- oqarib.dll
- vvunbwrhxa.exe
- svchost.exe
- 800990911.exe
- 240844061.exe
- 3DF7076F.exe
- 1591300478.exe
- 1977868703.exe
- 564DB681.exe
- 1940874419.exe
- 695276073.exe
- 498278020.exe
- 1743310514.exe
- 202150970.exe
- 801085450.exe
- 1354455340.exe
- 2113272685.exe
- 554845319.exe
- 00607031.exe
- 52796787.exe
- 14610250.exe
- 03380828.exe
- 93069676.exe
- 97246086.exe
- 94875926.exe
- 99388276.exe
- 18563124.exe
- 91457186.exe
- 90649526.exe
- 93789346.exe
- 94157956.exe
- 94955616.exe
- 96733746.exe
- 19815934.exe
- SystemSecurity.exe
- 788573529.exe
- adobe_flash[1].exe
- cogad.exe
- winscenter.exe
- iehelpers[1].exe
- ayscjcts.exe
- setupapi.dll
- bd3q0qix.exe
- load[1].exe
- winkfmc.exe
- ert51791.exe
- SSEngine.dll
- ntos.exe
- new23[1].exe
- new26[1].exe
- 28823330.exe
- Hyves_Browser.exe
- 9179499.exe
- cvucujahoza.dll
- AntivirusXP.exe
- 372561511.exe
- 1610380076.exe
- 172939276.exe
- 973260134.exe
- 613622941.exe
- 1986350760.exe
- install[2].exe
- 1947101902.exe
- 650526885.exe
- 1327825314.exe
- 14894324.exe
- 1573468717.exe
- 2084498445.exe
- 380679599.exe
- 1725032906.exe
- 1126514300.exe
- 02686578.exe
- 96484328.exe
- 03326093.exe
- 29192498.exe
- 00184705.exe
- 11120624.exe
- 699415262.exe
- 19378284.exe
- 96856706.exe
- 11447194.exe
- 19353904.exe
- 13779354.exe
- 99926866.exe
- 17722954.exe
- 16692344.exe
- 99825926.exe
- 10239374.exe
System Security 4.52 creates the following registry entries:
- Microsoft\Windows\CurrentVersion\Run\kxva
- Adware Pro
- AntivirusXP
- MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AntivirusXP.exe
- Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\System Security
- Microsoft\Windows\CurrentVersion\Uninstall\SystemSecurity2009
- HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\cogad
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 11120624
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 699415262
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 19378284
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 96856706
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 11447194
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 19353904
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 13779354
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 99926866
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 17722954
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 16723754
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 19815934
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 90249366
- Microsoft\Windows\CurrentVersion\Run\281681216
- Microsoft\Windows\CurrentVersion\Run\AdwareProMFCT
- Microsoft\Windows\CurrentVersion\Run\Mmexofumutokara
- Microsoft\Windows\CurrentVersion\Uninstall\Hyves Browser
- Microsoft\Windows\CurrentVersion\Run\973260134
- Microsoft\Windows\CurrentVersion\Run\370382475
- Microsoft\Windows\CurrentVersion\Run\00206953
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 13059684
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 17236094
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 14865934
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 16846714
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 18058594
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 99363896
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 10639534
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 19916874
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 94157956
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 94955616
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 16692344
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 10239374
- Microsoft\Windows\CurrentVersion\Run\SystemSecurity
- Microsoft\Windows\CurrentVersion\Uninstall\AdwarePro
- Microsoft\Windows\CurrentVersion\App Paths\AdwarePro.exe
- Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AntivirusXP
- Microsoft\Windows\CurrentVersion\Run\359F5809-00B8-4455-A73A-9EA62A51101B
- Microsoft\Windows\CurrentVersion\Run\1690486455
- Microsoft\Windows\CurrentVersion\Run\02215359
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 93069676
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 97246086
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 94875926
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 99388276
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 18563124
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 91457186
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 90649526
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 93789346
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 14147964
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 14945624
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 96733746
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 99825926
Important Article Disclaimer


English 

System Security 4.52 










