WI345d
WI345d Description
WI345d is a fake security threat appearing on counterfeit warning notifications, all designed and launched by the rogue anti-spyware program known as Windows Security Suite. These WI345d pop-up windows read as follows:
“Windows Security Alert!
To help protect your computer, Windows Firewall has blocked some features of this progrma. Do you want to keep blocking this program? Name: WI345d; Publisher: Unknown… Windows Firewall has blocked this program from accepting connections from the Internet or a network. If you recognize the program or trust the publisher, you can unblock it. When should I unblock a program?”
This WI345d is a fake and should not be taken lightly. Following the prompts will only cause the user to purchase and download the fake spyware remover Windows Security Suite. Instead, remove both the rogue spyware remover and WI345d from the computer as soon as they are detected.
Type: Fake Warning Messages
How Can You Detect WI345d?
WI345d has typically the following processes in memory:
- %UserProfile%\Recent\energy.dll
- %UserProfile%\Recent\PE.dll
- c:\Documents and Settings\All Users\Application Data\345d567\sqlite3.dll
- c:\Documents and Settings\All Users\Application Data\345d567\WI345d.exe
- %UserProfile%\Recent\std.exe
- %UserProfile%\Recent\tempdoc.dll
- %UserProfile%\Recent\SM.dll
- c:\Documents and Settings\All Users\Application Data\345d567\mozcrt19.dll
- %UserProfile%\Recent\grid.sys
- %UserProfile%\Recent\snl2w.exe
- %UserProfile%\Recent\kernel32.dll
- %UserProfile%\Recent\runddl.dll
- %UserProfile%\Recent\grid.dll
- %UserProfile%\Recent\dudl.sys
- %UserProfile%\Recent\CLSV.exe
WI345d creates the following registry entries:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Windows Security Suite”
- HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
- HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “698909210803″
Important Article Disclaimer

English 
Deutsch
Español
Français
Portuguese
WI345d 










