Hijack.SecurityRun
Short bio
Hijack.SecurityRun is Malwarebytes’ detection name for a Software Restriction Policy used against security software.
Type and source of infection
Hijack.SecurityRun is a detection-only rule that looks at the subkeys of the registry key: HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowssafer codeidentifiers Paths and flags a detection if it finds a rule to block security software from running. Hijack.SecurityRun can be an indicator for a more serious threat that has disabled certain security software.
Remediation
Malwarebytes can detect and remove Hijack.SecurityRun without further user interaction.
- Please download Malwarebytes to your desktop.
- Double-click MBSetup.exe and follow the prompts to install the program.
- When your Malwarebytes for Windows installation completes, the program opens to the Welcome to Malwarebytes screen.
- Click on the Get started button.
- Click Scan to start a Threat Scan.
- Click Quarantine to remove the found threats.
- Reboot the system if prompted to complete the removal process.
Traces/IOCs
HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowssafercodeidentifiers Paths{CLSID} “itemdata”=”{targeted security software}“