My Shield Security

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: September 12, 2011
Last Seen: January 7, 2021
OS(es) Affected: Windows

My Shield Security is a fake anti-virus application from the VirusDoctor family with the aim to steal your money and hold your computer hostage. Like other rogue anti-virus applications, My Shield Security is distributed, promoted and installed through the use of Trojans. My Shield Security is scamware since it is designed to fool computer users into thinking the program is a legitimate anti-virus program. My Shield Security pretends to scan the PC for viruses and displays virus warning messages that may appear serious but are only web pages with false virus detections.

My Shield Security is a complete scam and is a variant of other fake security tools such as Best Antivirus, Windows Trojans Sleuth.

Trojans can keep My Shield Security on a computer longer than a computer user would want to. To keep My Shield Security on an infected computer, a trojan can change system settings, inject malicious files to the Windows Registry, and disable key tools (i.e. Task Manager) on a computer. Do not download or install My Shield Security. To remove My Shield Security, you should rely on a capable and legitimate anti-malware program.

File System Details

My Shield Security may create the following file(s):
# File Name Detections
1. %Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe

Registry Details

My Shield Security may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = '127.0.0.1:?'
HKEY_CURRENT_USER\Software\[RANDOM CHARACTERS]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"

Messages

The following messages associated with My Shield Security were found:

"[Random program .exe file]" is infected with "Virus.DOS.PM.733".
Do you want to register your copy and remove all threats now?
Access violation at address 1322AA8F in module ms305c_231.exe read of address 00000000
My Shield Security Firewall Alert
My Shield Security has prevented a program from accessing the internet
My Shield Security Warning
My Shield Security has detected malware in your system.
It is highly recommended that your register My Shield Security and remove the threats immediately.
My Shield Security Warning
Your system is still infected with malicious software. Activate antivirus protection to avoid privacy violation and theft of your credit card information.
Click here to activate protection.

Trending

Most Viewed

Loading...