My Security Wall - How to remove February 12, 2010 By Giedrius Majauskas My Security Wall is a fake antivirus program that is distributed using trojans and fake online antivirus websites. It is a rename of Virus Doctor – a older antivirus program that scared people into buying by displaying imaginary threats. Differently from many other rogue antivirus programs, My security wall drops various files in users’s recent folder and other places in computer PC to show that the infected files really exists. On each system startup, My Security Wall will start system scan and display a list of infected files that can not be deleted without “Full” version. The files listed are harmless in general. You can delete them, but they will reaper as the rogue antivirus will generate them anew. %UserProfile%\Recent\ANTIGEN.drv %UserProfile%\Recent\ANTIGEN.exe %UserProfile%\Recent\cid.dll %UserProfile%\Recent\CLSV.drv %UserProfile%\Recent\DBOLE.sys %UserProfile%\Recent\ddv.dll %UserProfile%\Recent\ddv.sys %UserProfile%\Recent\energy.tmp %UserProfile%\Recent\FS.drv %UserProfile%\Recent\gid.drv %UserProfile%\Recent\PE.drv %UserProfile%\Recent\PE.exe %UserProfile%\Recent\PE.sys %UserProfile%\Recent\PE.tmp %UserProfile%\Recent\runddlkey.dll %UserProfile%\Recent\std.exe %UserProfile%\Recent\tjd.drv %UserProfile%\Recent\tjd.sys As you can see, clearing recent files folder would get rid of most of these fake infections, but not of the real infection – My security wall. Additionally, you will get warnings about system being attacked by hackers or that you got no antivirus protection (even if you have one). Sure enough, these warnings are false as well – My security wall is just trying to get your attention and give away your credit card number to their manufacturers. All programs mentioned in My Security Wall popups are legitimate or harmless so removing the files it detects is useless at best. An example of My security wall’s alert might look like these : An unauthorized program has been prevented from accessing your PC remotely. #Port:433 from 92.11.127.10 An unauthorized software C:\Program Files\Internet Explorer\Iexplore.exe which is potentially malicious and able to modify system files has been prevented from being installed on your PC. My Security Wall has detected potentially harmful software in your system. It is strongly recommended that you register My Security Wall to remove all found threats immediately. Potentially harmful programs have been detected in your system and need to be dealt with immediately. Click here to remove them using My Security Wall. Your PC may still be infected with dangerous viruses. My Security Wall protection is needed to prevent data loss and avoid theft of your personal data and credit card details. Click here to activate protection. Suspicious software which may be malicious has been detected on your PC. Click here to remove this threat immediately using My Security Wall. Click here to remove all potentially harmful programs found immediately using My Security Wall. Malicious applications, which may contain Trojans, were found on your computer and are to be removed immediately. Click here to remove these potentially harmful items using My Security Wall. No real-time malware, spyware and virus protection was found. Click here to activate. I would recommend to remove My Security Wall as it hinders work of real antivirus programs and makes your PC vulnerable to further infections. The removal instructions of My security wall follows. Note: My securitywall might use random file names to avoid easy detection. For the best results, doublecheck all suspicious processes and scan your PC with good anti-malware programs. Automatic Malware removal tools Download Spyhunter for Malware detection(Win) Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Download Combo Cleaner for Malware detection(Mac) Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy , Manual removal Processes: MS339.exe ppal.exe kernel32.exe Dll: tempdoc.dll mozcrt19.dll sqlite3.dll exec.dll Files: C:\\Documents and Settings\\All Users\\Application Data\\117fc\\MS339.exe c:\\Documents and Settings\\All Users\\Application Data\\MSEAIVCW c:\\Documents and Settings\\All Users\\Application Data\\MSEAIVCW\\MSGWBQLMRPW.cfg c:\\Documents and Settings\\All Users\\Application Data\\117fc c:\\Documents and Settings\\All Users\\Application Data\\117fc\\MSW.ico c:\\Documents and Settings\\All Users\\Application Data\\117fc\\7463.mof c:\\Documents and Settings\\All Users\\Application Data\\117fc\\mozcrt19.dll c:\\Documents and Settings\\All Users\\Application Data\\117fc\\sqlite3.dll c:\\Documents and Settings\\All Users\\Application Data\\117fc\\BackUp\\Adobe Reader Speed Launch.lnk c:\\Documents and Settings\\All Users\\Application Data\\117fc\\BackUp c:\\Documents and Settings\\All Users\\Application Data\\117fc\\BackUp\\Adobe Reader Synchronizer.lnk c:\\Documents and Settings\\All Users\\Application Data\\117fc\\MSWSys c:\\Documents and Settings\\All Users\\Application Data\\117fc\\MSWSys\\vd952342.bd c:\\Documents and Settings\\All Users\\Application Data\\117fc\\Quarantine Items %UserProfile%\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\My Security Wall.lnk %UserProfile%\\Application Data\\My Security Wall %UserProfile%\\Application Data\\My Security Wall\\cookies.sqlite %UserProfile%\\Desktop\\My Security Wall.lnk %UserProfile\\Recent\\ANTIGEN.tmp %UserProfile\\Recent\\dudl.sys %UserProfile\\Recent\\energy.drv %UserProfile\\Recent\\exec.dll %UserProfile\\Recent\\exec.drv %UserProfile\\Recent\\grid.drv %UserProfile\\Recent\\hymt.drv %UserProfile\\Recent\\kernel32.exe %UserProfile\\Recent\\pal.drv %UserProfile\\Recent\\PE.drv %UserProfile\\Recent\\ppal.exe %UserProfile\\Recent\\tempdoc.dll %UserProfile\\Recent\\tempdoc.drv %UserProfile\\Recent\\tjd.tmp %UserProfile%\\Start Menu\\My Security Wall.lnk %UserProfile%\\Start Menu\\Programs\\My Security Wall.lnk c:\\Program Files\\Mozilla Firefox\\searchplugins\\search.xml Registers: HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Internet Explorer\\SearchScopes \"URL\" = \"http://findgala.com/?&uid=7&q={searchTerms}\" HKEY_CURRENT_USER\\Software\\Classes\\Software\\Microsoft\\Internet Explorer\\SearchScopes \"URL\" = \"http://findgala.com/?&uid=7&q={searchTerms}\" HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Download \"RunInvalidSignatures\" = \"1\" HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\User Agent\\Post Platform \"Build/13.00007\" HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \"My Security Wall\" HKEY_CLASSES_ROOT\\Software\\Microsoft\\Internet Explorer\\SearchScopes \"URL\" = \"http://findgala.com/?&uid=7&q={searchTerms}\" HKEY_CLASSES_ROOT\\xp_5f014.DocHostUIHandler My Security Wall facts Type: Rogue Anti-Spyware Download Spyhunter for Malware detection(Win) Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Download Combo Cleaner for Malware detection(Mac) Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy , TOC Leave a ReplyYour email address will not be published. Required fields are marked *Comment * Name * Email * Website