WI345d

By Sumo3000 in Fake Error Messages

WI345d is a fake security threat appearing on counterfeit warning notifications, all designed and launched by the rogue anti-spyware program known as Windows Security Suite. These WI345d pop-up windows read as follows:

"Windows Security Alert!
To help protect your computer, Windows Firewall has blocked some features of this progrma. Do you want to keep blocking this program? Name: WI345d; Publisher: Unknown... Windows Firewall has blocked this program from accepting connections from the Internet or a network. If you recognize the program or trust the publisher, you can unblock it. When should I unblock a program?"

This WI345d is a fake and should not be taken lightly. Following the prompts will only cause the user to purchase and download the fake spyware remover Windows Security Suite. Instead, remove both the rogue spyware remover and WI345d from the computer as soon as they are detected.

File System Details

WI345d may create the following file(s):
# File Name Detections
1. %UserProfile%\Recent\energy.dll
2. %UserProfile%\Recent\PE.dll
3. C:\Documents and Settings\\Application Data\345d567\sqlite3.dll
4. C:\Documents and Settings\\Application Data\345d567\WI345d.exe
5. %UserProfile%\Recent\std.exe
6. %UserProfile%\Recent\tempdoc.dll
7. %UserProfile%\Recent\SM.dll
8. C:\Documents and Settings\\Application Data\345d567\mozcrt19.dll
9. %UserProfile%\Recent\grid.sys
10. %UserProfile%\Recent\snl2w.exe
11. %UserProfile%\Recent\kernel32.dll
12. %UserProfile%\Recent\runddl.dll
13. %UserProfile%\Recent\grid.dll
14. %UserProfile%\Recent\dudl.sys
15. %UserProfile%\Recent\CLSV.exe
16. C:\Documents and Settings\\Application Data\345d567\WINSSSys
17. %UserProfile%\Application Data\Windows Security Suite\Instructions.ini
18. C:\Documents and Settings\\Application Data\WINSSSys\winss.cfg
19. C:\Documents and Settings\\Application Data\345d567\26.mof
20. %UserProfile%\Recent\ANTIGEN.drv
21. %UserProfile%\Application Data\Windows Security Suite\cookies.sqlite
22. c:\ADWARE_LOG
23. C:\Documents and Settings\\Application Data\345d567
24. C:\Documents and Settings\\Application Data\345d567\WINSSSys\vd952342.bd
25. c:\Program Files\Mozilla Firefox\searchplugins\search.xml
26. C:\Documents and Settings\\Application Data\345d567\working.log
27. %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Security Suite.lnk
28. %UserProfile%\Start Menu\Windows Security Suite.lnk
29. %UserProfile%\Application Data\Windows Security Suite
30. C:\Documents and Settings\\Application Data\WINSSSys
31. %UserProfile%\Desktop\Windows Security Suite.lnk
32. %UserProfile%\Start Menu\Programs\Windows Security Suite.lnk
33. C:\Documents and Settings\\Application Data\345d567\WINSS.ico
34. %UserProfile%\Recent\DBOLE.drv
35. %UserProfile%\Recent\PE.tmp

Registry Details

WI345d may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Security Suite"
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "698909210803"

Trending

Most Viewed

Loading...