How to remove System Security 4.52 rogue anti-spyware

Malware Description:
System Security 4.52 (aka System Security version 4.52, System Security or System Security 2009) is an immensely invasive fake antispyware product that literally paralyses the infected computer and then requires the user to pay money to fix the trouble. Unfortunately, that is absolutely routine technique for rogue security programs to distribute themselves, including its direct predecessor System Security 4.51. Just like its previous version 4.51, System Security 4.52 installs under deceptive pretences and on a predominant majority of occasions employs trojans to intrude absolutely undetected. As soon as System Security 4.52 freeware creeps inside in the form of a multitude of backdoor trojans, it drops a few critical system files and registry values to gain the control over the compromised machine to the needed extent. The consequences of such System Security 4.52 pranks include the slow computer problem, inability to go online (selectively or at all), restricted options of installing executable files related to antivirus software which could remove System Security 4.52. System Security 4.52 is known to even block the Safe Mode with Networking thus preventing the users from using this alternative pathway to search for a solution. System Security 4.52 tends to issue phony popup alerts or even switch the desktop theme to notify the victim about the infections allegedly residing on the PC. System Security version 4.52 may also scan the computer for viruses without user authorisation- and, guess what, the scanner reports even a greater number of malware applications to remove. This way, System Security 4.52 drills its way into your wallet and attempts to get you pulling out some dough for purchasing its licensed version. Do not trust System Security 4.52! On the contrary – remove this pest until it makes you want to lose your computer and never get it back. Please, see more information below.

Malware Type: Rogue Anti-Spyware

Malware Author: Innovagest2000

Threat Level: Critical

Advice: Immediately remove and scan for additional malware

System Security 4.52 Free Scanner and Remover: Download Now

System Security 4.52 Screenshot:

System Security 4.52

How to remove System Security 4.52 manually:
Manual removal of System Security 4.52 is feasible if you have sufficient expertise in working with program files, system processes, .dll files and registry entries.

The files to be deleted are listed below:

  • SystemSecurity.exe
  • 936453029.exe
  • 549344438.exe
  • 788573529.exe
  • 1714292029.exe
  • 1003720520.exe
  • adobe_flash[1].exe
  • AdobeFlash[1].exe
  • TubePlayer.ver.6.exe
  • cogad.exe
  • torbjne.exe
  • mupd1_2_1165664.exe
  • winscenter.exe
  • iemodule.dll
  • ldycgadzmr.dll
  • iehelpers[1].exe
  • iehelper.exe
  • 19329203.exe
  • ayscjcts.exe
  • install[1].exe
  • 281681216.exe
  • setupapi.dll
  • ~tmpa.exe
  • bnmio.exe
  • bd3q0qix.exe
  • vamsoft.exe
  • iii[1].exe
  • load[1].exe
  • winafoe.exe
  • ParisHilton[1].exe
  • winkfmc.exe
  • TckBX673.exe
  • card[1].exe
  • ert51791.exe
  • AdwarePro.exe
  • AdwarePro_Setup[1].exe
  • SSEngine.dll
  • StartApp.exe
  • 1[1].exe
  • ntos.exe
  • usp10.dll
  • Omahonafazeq.dll
  • new23[1].exe
  • gr[2].exe
  • adv111[1].exe
  • new26[1].exe
  • SetupAntivirusXP[1].exe
  • ieupdates.exe
  • 28823330.exe
  • Test.exe
  • loader[1].exe
  • Hyves_Browser.exe
  • Hyves_Browser_Instalation.exe
  • i386si.sys
  • 9179499.exe
  • 1462403437.exe
  • uxeqipuzimocin.dll
  • cvucujahoza.dll
  • oqarib.dll
  • winlogin.exe
  • AntivirusXP.exe
  • vvunbwrhxa.exe
  • imod3.dll
  • 372561511.exe
  • svchost.exe
  • swapdm.dll
  • 1610380076.exe
  • 800990911.exe
  • 431192516.exe
  • 172939276.exe
  • 240844061.exe
  • 931330021.exe
  • 973260134.exe
  • 3DF7076F.exe
  • 432632312.exe
  • 613622941.exe
  • 1591300478.exe
  • 438978017.exe
  • 1986350760.exe
  • 1977868703.exe
  • 2030350728.exe
  • install[2].exe
  • 564DB681.exe
  • 1431998300.exe
  • 1947101902.exe
  • 1940874419.exe
  • 1767930182.exe
  • 650526885.exe
  • 695276073.exe
  • 02686578.exe
  • 00607031.exe
  • 500153984.exe
  • 96484328.exe
  • 52796787.exe
  • 13496218.exe
  • 03326093.exe
  • 14610250.exe
  • 06837430.exe
  • 29192498.exe
  • 03380828.exe
  • 90188702.exe
  • 00184705.exe
  • 93069676.exe
  • 13059684.exe
  • 11120624.exe
  • 97246086.exe

The associated registry entries to be removed are as follows:

  • HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\cogad
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\93069676
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\13059684
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\11120624
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\97246086
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\17236094
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\699415262
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\94875926
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\14865934
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\19378284
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\99388276
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\16846714
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\96856706
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\18563124
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\18058594
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\11447194
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\91457186
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\99363896
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\19353904
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\90649526
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\10639534
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\13779354
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\93789346
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\19916874
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\99926866
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\14147964
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\94157956
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\17722954
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\14945624
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\94955616
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\16723754
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\96733746
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\16692344
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\19815934
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\99825926
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\10239374
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\90249366

Please, be informed that manual removal of System Security 4.52 is a cumbersome procedure and does not always ensure complete deletion of the malware, since some files might be hidden or may automatically reanimate themselves afterwards. Moreover, manual interference of this kind may cause damage to the system. That’s why we strongly recommend automatic removal of System Security 4.52, which will save your time and enable avoiding any system malfunctions and guarantee the needed result.

Download System Security 4.52 Automatic Remover

Reader's Comments

  1. admin |

    Since System Security 4.52 rogue anti-spyware often blocks all removal effort, we advise you to try the following ways to get rid of this scareware.

    Way #1.
    1. Find System Security 4.52 folder in your system. Usually, it’s located at C:\Documents and Settings\All Users\Application Data. It’s a numbered folder (called 694157 or something similar), with a shield icon.
    2. Rename the numbered folder to 2222; delete the shield application (if possible).
    3. Restart your computer and try to download our removal tool above. System Security 4.52 shouldn’t prevent using antivirus utilities now.

    Way #2.
    1. When you are starting your computer, repeatedly press F8. It should let you enter the Safe Mode.
    2. In Safe Mode, go to Run in Start Menu. Type MSCONFIG.
    3. Then, inside the GUI that opens, uncheck all the numbered items or other suspicious items which you cannot identify as your legit programs, including the blank ones which are checked.
    4.Restart.
    5. Install our removal tool and remove System Security 4.52.

    Way #3 (sometimes, it’s needed to combine the 2 methods).
    1. Use Way #1 (items 1-2) then Way #2.

    It should work!
    Regards,
    WP

  2. Mike |

    thanks for your topic here… helped me quickly remove this virus from a buddies computer. worked flawlessly.

  3. Rich |

    TYVM!!! Renaming the folder did the trick…

  4. Brett |

    Way#1 above has let me get the upper hand. Thanks. I’m not tech savvy but was able to follow the simple instructions. Not quite there yet but have regained control.

Comment