Posts Tagged ‘DesktopSecurity2010’

Feb 22

Desktop Security 2010 Adware Removal Instructions

The Emsi Software malware research team has discoverd a new outbreak of the Desktop Security 2010 adware. a-squared Anti-Malware detects this malware as Adware.Win32.DesktopSecurity2010.

Desktop Security 2010 is a rogue security program. This rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.

Create new files (some files and registry name are random):

  • %ProgramFiles%\Desktop Security 2010\
  • %ProgramFiles%\Desktop Security 2010\MFC71ENU.DLL
  • %ProgramFiles%\Desktop Security 2010\msvcp71.dll
  • %ProgramFiles%\Desktop Security 2010\msvcr71.dll
  • %ProgramFiles%\Desktop Security 2010\pthreadVC2.dll
  • %ProgramFiles%\Desktop Security 2010\securitycenter.exe
  • %ProgramFiles%\Desktop Security 2010\taskmgr.dll
  • %ProgramFiles%\Desktop Security 2010\uninstall.exe
  • %ProgramFiles%\Desktop Security 2010\daily.cvd
  • %ProgramFiles%\Desktop Security 2010\Desktop Security 2010.exe
  • %ProgramFiles%\Desktop Security 2010\guide.chm
  • %ProgramFiles%\Desktop Security 2010\hjengine.dll
  • %ProgramFiles%\Desktop Security 2010\mfc71.dll
  • %SystemRoot%\system32\cbrdwlvrumw6.exe
  • %UserProfile%\Local Settings\Temp\kilslmd.exex
  • %UserProfile%\Local Settings\Temp\kn.a.exe
  • %UserProfile%\Local Settings\Temp\gedx_ae09.exe
  • %UserProfile%\Local Settings\Temp\kgn.exe

Create new registry entries:

  • HKEY_LOCAL_MACHINE\software\Desktop Security 2010
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Desktop Security 2010
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, “Desktop Security 2010″
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, “SecurityCenter”
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, “cbrdwlvrumw6″

Screenshots:

How to remove the infection of Desktop Security 2010 (Adware.Win32.DesktopSecurity2010)?

To delete this malware infection, please download and install a-squared Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.