1 of 2
Danger level 10
Type: Rogue Anti-Spyware
Common infection symptoms:
  • Connects to the internet without permission
  • Shows commercial adverts
  • Slow internet connection
  • System crashes
  • Slow Computer
Other mutations known as:

System Security 4.52

System Security 4.52 is a variation of the nefarious application, System Security (also known as System Security 2009), and is the latest in rogue anti-spyware applications.

System Security 4.52 has been discovered to be the exact replica of one of the most popular rogue anti-spyware families, which include the likes of Winweb Security, and WinwebSecurity.

The best thing to do if you have detected System Security 4.52 is to simply delete the application as soon as possible.

It is important to note that once embedded within a computer system, System Security 4.52 will kill all .exe processes, leaving the system without fully operational and functional processes; therefore before attempting to delete this PC parasite from a system, you must make sure you have backed up all your data.

The next step would be to download a reputable, trustworthy anti-spyware application.
Once you have downloaded this up-to-date security tool, make sure you boot your Operating System up in SAFE MODE – this way, the chances of your system and all its .exe processes being affected is greatly minimized.

Safe Mode is basically the best option when attempting to troubleshoot a computer system, whether it be a driver problem or a spyware infection one needs to fix, safe mode is the way to go.

When in Safe Mode, the computer system loads the least amount of drivers and components, thus allowing you to perform the many tasks needed to restore the system to its fully functional state.

One can boot in safe mode with networking, and without networking.

· Safe Mode without Networking:
To enable safe mode, simply press F8 (just before the Operating System’s loading screen appears) after the BIOS screen has disappeared. You will then be taken to an ‘Advanced Boot Options Menu’. You will then need to choose the safe mode you desire, by utilizing the arrow keys, once you are happy with your safe mode option, press enter.

· Safe Mode with Networking:
One should only use this mode if this functionality is required. To enable safe mode with networking, you follow the same steps as safe mode without networking, the only difference is you will need internet access.

A symptom one should watch out for, to alert one to the fact System Security 4.52 is embedded in a system, is the fake message alert as a wallpaper, which is issued by the rogue program, which reads as follows:

"WARNING
YOUR'RE IN DANGER!
YOUR COMPUTER IS INFECTED WITH SPYWARE!
ALL YOU DO WITH COMPUTER IS STORED FOREVER IN YOUR HARD DISK.
WHEN YOU VISIT SITES, SEND E-MAILS... ALL YOUR ACTIONS ARE
LOGGED. AND IT IS IMPOSSIBLE TO REMOVE THEM WITH STANDART TOOLS.
YOUR DATA IS STILL AVAILABLE FOR FORENSICS. AND IN SOME CASES
FOR YOUR BOSS, YOUR FRIENDS, YOUR WIFE, YOUR CHILDREN.

Every site you or somebody or even something, like spyware, opened in your browsers, with all images, and all downloaded and maybe later removed movies or mp3 songs - ARE STILL THERE and could break your life!
SECURE YOURSELF RIGHT NOW!
REMOVE ALL SPYWARE FROM YOUR PC!"

The desktop background message above shows text which warns You (the user) about Your infected computer. You will see the screen shot in the right side of our website, if your system is indeed infected.

System Security 4.52 usually appears on a user‘s computer once a fake video codec has been installed onto the user’s computer system.

System Security 4.52 will continue with the generation of phony scan reports and fake system pop-up error messages to coerce the user (YOU) into purchasing the “Full” version of the System Security 4.52 program.

Unless one makes a plan to get rid of System Security 4.52 promptly, the user will continue to receive annoying pop-up messages and fake system scans, accompanied by the synchronized depletion of overall system performance.

In short, SystemSecurity is simply a form of fake software with the intent to steal your money. Do NOT fall prey to its tactics of manipulation!

Download Spyware Removal Tool to Remove* System Security 4.52
  • Quick & tested solution for System Security 4.52 removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove System Security 4.52

Files associated with System Security 4.52 infection:

99064526.exe
952845811.exe
93548896.exe
7A2A9866.exe
784546C9.exe
712051F8.exe
66BD7DDB.exe
57BA2A1F.exe
562DC910.exe
501957035.exe
46561240.exe
46319321.exe
370859320.exe
2136239032.exe
20B4D341.exe
2092387666.exe
1881078529.exe
18664534.exe
17522964.exe
16826564.exe
1625593810.exe
1543779997.exe
1431580341.exe
1416040140.exe
13538904.exe
124517242.exe
1228759908.exe
11985073.exe
1139D43.exe
1137177851.exe
1029503410.exe
48603728.exe
10207964.exe
18337654.exe
16046564.exe
11563594.exe
11028594.exe
1672603317.exe
13055314.exe
14190934.exe
11929684.exe
19758124.exe
17078124.exe
11696564.exe
19900934.exe
16515004.exe
19795784.exe
13309954.exe
15690624.exe
19516874.exe
17528124.exe
19381254.exe
14391094.exe
18740004.exe
19017654.exe
14263904.exe
17948754.exe
15839064.exe
13887964.exe
18769374.exe
12751564.exe
13889684.exe
13278754.exe
13747964.exe
19404374.exe
17268594.exe
16517344.exe
15497814.exe
13569684.exe
15624534.exe
13833124.exe
12590624.exe
19248274.exe
13542964.exe
16647964.exe
15733284.exe
12273434.exe
18562654.exe
10830004.exe
13458754.exe
14026404.exe
14953904.exe
15827504.exe
15564064.exe
18967184.exe
14820604.exe
10905624.exe
12292034.exe
12571564.exe
16272034.exe
14611404.exe
16365934.exe
1888062268.exe
16439844.exe
12740624.exe
13355004.exe
16526924.exe
16281254.exe
15083594.exe
17818594.exe
17237344.exe
14038754.exe
17444894.exe
17287504.exe
13930784.exe
19665624.exe
10153594.exe
11487504.exe
10388904.exe
18986094.exe
97049526.exe
17039534.exe
99678116.exe
91402176.exe
90786246.exe
10776254.exe
151100227.exe
1915224187.exe
1819749873.exe
96641866.exe
16631874.exe
11621714.exe
91631706.exe
98573116.exe
98620456.exe
18610464.exe
14943754.exe
10994214.exe
12613754.exe
92623746.exe
11769284.exe
11846754.exe
13701144.exe
83521271.exe
10239374.exe
90249366.exe
19815934.exe
99825926.exe
16723754.exe
96733746.exe
16692344.exe
14945624.exe
94955616.exe
17722954.exe
14147964.exe
94157956.exe
99926866.exe
19916874.exe
93789346.exe
13779354.exe
10639534.exe
90649526.exe
19353904.exe
99363896.exe
91457186.exe
11447194.exe
18058594.exe
18563124.exe
96856706.exe
16846714.exe
99388276.exe
19378284.exe
14865934.exe
94875926.exe
699415262.exe
17236094.exe
97246086.exe
11120624.exe
13059684.exe
93069676.exe
00184705.exe
90188702.exe
03380828.exe
29192498.exe
06837430.exe
14610250.exe
03326093.exe
13496218.exe
52796787.exe
96484328.exe
500153984.exe
00607031.exe
02686578.exe
01560265.exe
554845319.exe
1126514300.exe
1255330437.exe
2113272685.exe
1725032906.exe
1690486455.exe
1354455340.exe
380679599.exe
25238076.exe
801085450.exe
2084498445.exe
370382475.exe
202150970.exe
1573468717.exe
375534146.exe
1743310514.exe
14894324.exe
2029503323.exe
498278020.exe
1327825314.exe
1550536869.exe
695276073.exe
650526885.exe
1767930182.exe
1940874419.exe
1947101902.exe
1431998300.exe
564DB681.exe
install[2].exe
2030350728.exe
1977868703.exe
1986350760.exe
438978017.exe
1591300478.exe
613622941.exe
432632312.exe
3DF7076F.exe
973260134.exe
931330021.exe
240844061.exe
172939276.exe
431192516.exe
800990911.exe
1610380076.exe
swapdm.dll
svchost.exe
372561511.exe
imod3.dll
vvunbwrhxa.exe
AntivirusXP.exe
winlogin.exe
oqarib.dll
cvucujahoza.dll
uxeqipuzimocin.dll
1462403437.exe
9179499.exe
i386si.sys
Hyves_Browser_Instalation.exe
Hyves_Browser.exe
loader[1].exe
Test.exe
28823330.exe
ieupdates.exe
SetupAntivirusXP[1].exe
new26[1].exe
adv111[1].exe
gr[2].exe
new23[1].exe
Omahonafazeq.dll
usp10.dll
ntos.exe
1[1].exe
StartApp.exe
SSEngine.dll
AdwarePro_Setup[1].exe
AdwarePro.exe
ert51791.exe
card[1].exe
TckBX673.exe
winkfmc.exe
ParisHilton[1].exe
winafoe.exe
load[1].exe
iii[1].exe
vamsoft.exe
bd3q0qix.exe
bnmio.exe
~tmpa.exe
setupapi.dll
281681216.exe
install[1].exe
ayscjcts.exe
19329203.exe
iehelper.exe
iehelpers[1].exe
ldycgadzmr.dll
iemodule.dll
winscenter.exe
mupd1_2_1165664.exe
torbjne.exe
cogad.exe
TubePlayer.ver.6.exe
AdobeFlash[1].exe
adobe_flash[1].exe
1003720520.exe
1714292029.exe
788573529.exe
549344438.exe
936453029.exe
SystemSecurity.exe

System Security 4.52 DLL's to remove:

swapdm.dll
imod3.dll
oqarib.dll
cvucujahoza.dll
uxeqipuzimocin.dll
Omahonafazeq.dll
usp10.dll
SSEngine.dll
setupapi.dll
ldycgadzmr.dll
iemodule.dll

System Security 4.52 processes to kill:

99064526.exe
952845811.exe
93548896.exe
7A2A9866.exe
784546C9.exe
712051F8.exe
66BD7DDB.exe
57BA2A1F.exe
562DC910.exe
501957035.exe
46561240.exe
46319321.exe
370859320.exe
2136239032.exe
20B4D341.exe
2092387666.exe
1881078529.exe
18664534.exe
17522964.exe
16826564.exe
1625593810.exe
1543779997.exe
1431580341.exe
1416040140.exe
13538904.exe
124517242.exe
1228759908.exe
11985073.exe
1139D43.exe
1137177851.exe
1029503410.exe
48603728.exe
10207964.exe
18337654.exe
16046564.exe
11563594.exe
11028594.exe
1672603317.exe
13055314.exe
14190934.exe
11929684.exe
19758124.exe
17078124.exe
11696564.exe
19900934.exe
16515004.exe
19795784.exe
13309954.exe
15690624.exe
19516874.exe
17528124.exe
19381254.exe
14391094.exe
18740004.exe
19017654.exe
14263904.exe
17948754.exe
15839064.exe
13887964.exe
18769374.exe
12751564.exe
13889684.exe
13278754.exe
13747964.exe
19404374.exe
17268594.exe
16517344.exe
15497814.exe
13569684.exe
15624534.exe
13833124.exe
12590624.exe
19248274.exe
13542964.exe
16647964.exe
15733284.exe
12273434.exe
18562654.exe
10830004.exe
13458754.exe
14026404.exe
14953904.exe
15827504.exe
15564064.exe
18967184.exe
14820604.exe
10905624.exe
12292034.exe
12571564.exe
16272034.exe
14611404.exe
16365934.exe
1888062268.exe
16439844.exe
12740624.exe
13355004.exe
16526924.exe
16281254.exe
15083594.exe
17818594.exe
17237344.exe
14038754.exe
17444894.exe
17287504.exe
13930784.exe
19665624.exe
10153594.exe
11487504.exe
10388904.exe
18986094.exe
97049526.exe
17039534.exe
99678116.exe
91402176.exe
90786246.exe
10776254.exe
151100227.exe
1915224187.exe
1819749873.exe
96641866.exe
16631874.exe
11621714.exe
91631706.exe
98573116.exe
98620456.exe
18610464.exe
14943754.exe
10994214.exe
12613754.exe
92623746.exe
11769284.exe
11846754.exe
13701144.exe
83521271.exe
10239374.exe
90249366.exe
19815934.exe
99825926.exe
16723754.exe
96733746.exe
16692344.exe
14945624.exe
94955616.exe
17722954.exe
14147964.exe
94157956.exe
99926866.exe
19916874.exe
93789346.exe
13779354.exe
10639534.exe
90649526.exe
19353904.exe
99363896.exe
91457186.exe
11447194.exe
18058594.exe
18563124.exe
96856706.exe
16846714.exe
99388276.exe
19378284.exe
14865934.exe
94875926.exe
699415262.exe
17236094.exe
97246086.exe
11120624.exe
13059684.exe
93069676.exe
00184705.exe
90188702.exe
03380828.exe
29192498.exe
06837430.exe
14610250.exe
03326093.exe
13496218.exe
52796787.exe
96484328.exe
500153984.exe
00607031.exe
02686578.exe
01560265.exe
554845319.exe
1126514300.exe
1255330437.exe
2113272685.exe
1725032906.exe
1690486455.exe
1354455340.exe
380679599.exe
25238076.exe
801085450.exe
2084498445.exe
370382475.exe
202150970.exe
1573468717.exe
375534146.exe
1743310514.exe
14894324.exe
2029503323.exe
498278020.exe
1327825314.exe
1550536869.exe
695276073.exe
650526885.exe
1767930182.exe
1940874419.exe
1947101902.exe
1431998300.exe
564DB681.exe
install[2].exe
2030350728.exe
1977868703.exe
1986350760.exe
438978017.exe
1591300478.exe
613622941.exe
432632312.exe
3DF7076F.exe
973260134.exe
931330021.exe
240844061.exe
172939276.exe
431192516.exe
800990911.exe
1610380076.exe
svchost.exe
372561511.exe
vvunbwrhxa.exe
AntivirusXP.exe
winlogin.exe
1462403437.exe
9179499.exe
Hyves_Browser_Instalation.exe
Hyves_Browser.exe
loader[1].exe
Test.exe
28823330.exe
ieupdates.exe
SetupAntivirusXP[1].exe
new26[1].exe
adv111[1].exe
gr[2].exe
new23[1].exe
ntos.exe
1[1].exe
StartApp.exe
AdwarePro_Setup[1].exe
AdwarePro.exe
ert51791.exe
card[1].exe
TckBX673.exe
winkfmc.exe
ParisHilton[1].exe
winafoe.exe
load[1].exe
iii[1].exe
vamsoft.exe
bd3q0qix.exe
bnmio.exe
~tmpa.exe
281681216.exe
install[1].exe
ayscjcts.exe
19329203.exe
iehelper.exe
iehelpers[1].exe
winscenter.exe
mupd1_2_1165664.exe
torbjne.exe
cogad.exe
TubePlayer.ver.6.exe
AdobeFlash[1].exe
adobe_flash[1].exe
1003720520.exe
1714292029.exe
788573529.exe
549344438.exe
936453029.exe
SystemSecurity.exe

Remove System Security 4.52 registry entries:

Microsoft\Windows\CurrentVersion\Run\SystemSecurity
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\cogad
Microsoft\Windows\CurrentVersion\Run\281681216
Microsoft\Windows\CurrentVersion\Run\kxva
Microsoft\Windows\CurrentVersion\Uninstall\AdwarePro
Microsoft\Windows\CurrentVersion\Run\AdwareProMFCT
Adware Pro
Microsoft\Windows\CurrentVersion\App Paths\AdwarePro.exe
Microsoft\Windows\CurrentVersion\Run\Mmexofumutokara
AntivirusXP
Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AntivirusXP
Microsoft\Windows\CurrentVersion\Uninstall\Hyves Browser
MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AntivirusXP.exe
Microsoft\Windows\CurrentVersion\Run\359F5809-00B8-4455-A73A-9EA62A51101B
Microsoft\Windows\CurrentVersion\Run\973260134
Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\System Security
Microsoft\Windows\CurrentVersion\Run\1690486455
Microsoft\Windows\CurrentVersion\Run\370382475
Microsoft\Windows\Curr
Disclaimer

Comments

  1. DMF Jul 17, 2009

    Your description as well as your fix of this virus is very elementary and indicates you don't understand it at all. This virus doesn't allow running any anti virus software, it tells me all files are infected. I can get out to my email and to google.com, but that is it. Any downloads stopped, any programs I try to run from a jump drive stopped. It is very serious and your explanations of a fix are not helpful at all.

  2. Chriss Jul 17, 2009

    I hate this program, help me to removing this stupid program

  3. RWS Jul 18, 2009

    This is clever malware and 'sees' any threats to it such as downloads to kill it and then blocks downloads or infects files needed to kill it.

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.