Home Malware Programs Spyware Files Secure

Files Secure

Posted: December 21, 2007

Threat Metric

Threat Level: 6/10
Infected PCs: 35
First Seen: July 24, 2009
Last Seen: June 10, 2022
OS(es) Affected: Windows

ScreenshotFiles Secure is a rogue anti-spyware application, which is primarily created to lure Internet users out of their money. Files Secure is advertised and pushed by Trojan-Downloader.Adload.pd, which gets into the system bundled with fake video codecs that users usually download from questionable websites.

Once executed, Trojan-Downloader.Adload.pd will hijack web search engines (for instance, Google) and display fake error messages in your search results. Moreover, Trojan-Downloader.Adload.pd will generate fake popup warning messages claiming that your PC has been infected with various Trojans, including Trojan.Win32.Agent.akk , Trojan.Win32.Gorshok.a , Trojan.Win32.LinkReplacer , Trojan.Win32.Obfuscated.gx and others. All these Trojans are fake Trojans that are only mentioned on the warning messages to trick you into downloading a rogue anti-spyware program.

The warning messages may look like the following:

Critical System Error!
Your browser was hijacked by Trojan.Win32.Gorshok.a
You need to clean your system immediately, in other case it can be crashed soon!
Click OK to download the high-tech antispyware protection software! (Recommended)

Your computer was hijacked by Trojan.Win32.LinkReplacer
It's dangerous for your system, some files can be lost and your browser can be slow!
Click OK to download the antispyware program to clean your computer! (Recommended)

If you click on any of the wanring messages given above, your browser will be redirected to the web site where Files Secure is advertised and the creators of this rogue program will do their best to trick you into purchasing the commercial version of Files Secure.

ScreenshotScreenshot

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\WINDOWS\System32\orgnavi.dll File name: orgnavi.dll
Size: 225.28 KB (225280 bytes)
MD5: 6fea945ae26241c612823dd0b48a765f
Detection count: 80
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\WINDOWS\System32\orgnavi.dll
Group: Malware file
Last Updated: June 10, 2022
setup[2].exe File name: setup[2].exe
Size: 2.98 MB (2982557 bytes)
MD5: d9c9f5d9c6020ea2343ebfbd330a3993
Detection count: 38
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
setup1[1].exe File name: setup1[1].exe
Size: 2.99 MB (2999003 bytes)
MD5: b70455d23fe65ddd79bf11146e13dada
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
secure.exe File name: secure.exe
Size: 3.08 MB (3089920 bytes)
MD5: f78198a7b04473c3a85abaa69dbb7661
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009

Additional Information

The following directories were created:
%ProgramFiles%\Files-Secure
The following cookies were detected:
files-secure

5 Comments

  • Mizan R. Sharif says:

    Above are good before infection, but I like to get one free spyware removal tool. Thanks

  • Vannesa says:

    Hi, my problem(Sorry I ám Mexican I can´t speak good) :Up Say´s Free but at the install says Purchase , soo that means this isn´t free? please. I need the anwer ,the trojan are in my computer Atte Vanny♀

  • Dincer says:

    I've got this problem,too.I don't know how to remove it.I downloaded the spyhunter but I don't have even a credit card.Can someone help me?

  • ghostrider01 says:

    Dincer, 

    If you don't have a credit card, you can't purchase SpyHunter. I suggest you to scan your computer with our free SpyHunter scanner, which will detect the infected files and show their locations. Afterwards, boot your computer in Safe Mode and delete the infected files by using Shift+Del.

  • STELIOS says:

    THANXXXXXXXXXXXXXXXX

Loading...