Home Malware Programs Rogue Anti-Spyware Programs IE-Security

IE-Security

Posted: January 27, 2009

Threat Metric

Threat Level: 10/10
Infected PCs: 110
First Seen: July 24, 2009
Last Seen: May 6, 2024
OS(es) Affected: Windows

IE-Security, also known as IESecurity Rogue, is a rogue anti-spyware program and is a clone of WinDefender 2009. IE-Security may be usually installed by Trojans such as Zlob, Trojan.Generic, Vundo. Once infected with Zlob, Trojan.Generic, or Vundo, you'll receive numerous fake security alerts and system scan results stating that your computer is infected with spyware. To remove the supposed spyware infections, IE-Security will then urge you to purchase IE-Security's full program from its website (ie-security.com) for $79.95 or $49.95.

Moreover, it seems that the makers of IE-Security were in such a hurry to release the program that they even forgot to change the DisplayName on one of its registry keys. If you're infected with IE-Security, you'll find the following registry key listing WinDefender 2009 as the DisplayName:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE-Security "DisplayName"
Type: REG_SZ
Data: WinDefender 2009

The registry key mentioned above makes an entry on your Add/Remove Programs tool which lists WinDefender 2009 instead of IE-Security. IE-Security may have the ability to recreate itself after reboot. It is strongly recommended to remove IE-Security and WinDefender 2009 from your system upon detection.

Aliases

TROJ_FAKEAV.AIX [TrendMicro]IE-Security [Sunbelt]IE Defender [Sophos]Medium Risk Malware [Prevx1]Adware/IE-Security [Panda]Win32/Adware.IeDefender.NID [NOD32]Trojan:Win32/Delflob.I [Microsoft]potentially unwanted program Generic PUP [McAfee]not-a-virus:FraudTool.Win32.Agent.hn [Kaspersky]Non-Virus: [K7AntiVirus]Trojan.Win32.Delflob [Ikarus]PossibleThreat [Fortinet]Rogue:W32/IeDefender.CX [F-Secure]Win32/Burgspill!generic [eTrust-Vet]Win32.IEDefender [eSafe]
More aliases (26)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



ie[1].exe File name: ie[1].exe
Size: 2.11 MB (2117304 bytes)
MD5: ab5fa2e6cbfecc197778803b0909b3de
Detection count: 55
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
C:\WINDOWS\system32\fejokt.dll File name: fejokt.dll
Size: 106.49 KB (106496 bytes)
MD5: 1a45439550017fd46fcebbe37ab9b8e0
Detection count: 25
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\WINDOWS\system32\fejokt.dll
Group: Malware file
Last Updated: June 10, 2022
C:\Users\<username>\AppData\Local\Temp\Rar$EXb3700.41635\ie.security_installer.exe File name: ie.security_installer.exe
Size: 2.3 MB (2308165 bytes)
MD5: c2c79c4dbcda629f6422623a4e334840
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\Rar$EXb3700.41635\ie.security_installer.exe
Group: Malware file
Last Updated: April 6, 2024
C:\sandboxie testing rogues\drive\C\Program Files (x86)\IE-Security\iescan.exe File name: iescan.exe
Size: 2.33 MB (2331648 bytes)
MD5: 481d71e4ee76cbc47c49f3d49a4c6c8a
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: C:\sandboxie testing rogues\drive\C\Program Files (x86)\IE-Security\iescan.exe
Group: Malware file
Last Updated: May 6, 2024

More files

Additional Information

The following cookies were detected:
ie-security
Loading...