Tuesday, October 28, 2008

Dealbar Adware

Removing Dealbar
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits

Visible Symptoms:
Files in system folders:
[%PROGRAM_FILES%]\TBONAS\BarLcher.dll
[%PROGRAM_FILES%]\TBONAS\CompBar.dll
[%PROGRAM_FILES%]\TBONAS\BarLcher.dll
[%PROGRAM_FILES%]\TBONAS\CompBar.dll

How to detect Dealbar:

Files:
[%PROGRAM_FILES%]\TBONAS\BarLcher.dll
[%PROGRAM_FILES%]\TBONAS\CompBar.dll
[%PROGRAM_FILES%]\TBONAS\BarLcher.dll
[%PROGRAM_FILES%]\TBONAS\CompBar.dll

Folders:
[%PROGRAM_FILES%]\dealbar

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}
HKEY_CLASSES_ROOT\clsid\{3d782bb3-f2a5-11d3-bf4c-000000000000}
HKEY_CLASSES_ROOT\clsid\{3ea5c408-2437-4c40-adac-dfda9aeeea96}
HKEY_CLASSES_ROOT\clsid\{9b666a44-986c-46d4-8702-765509b6712f}
HKEY_CLASSES_ROOT\compbar.getpricebar
HKEY_CLASSES_ROOT\compbar.getpricebar.1
HKEY_CLASSES_ROOT\interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}
HKEY_CLASSES_ROOT\interface\{ca5ed456-9ecb-4734-a64c-0546147a0cc2}
HKEY_CLASSES_ROOT\interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}
HKEY_CLASSES_ROOT\mynewsbarlauncher.ie5barlauncher
HKEY_CLASSES_ROOT\mynewsbarlauncher.ie5barlauncher.1
HKEY_CURRENT_USER\software\activshopper

Registry Values:
HKEY_LOCAL_MACHINE\software\activshopper
HKEY_LOCAL_MACHINE\software\activshopper
HKEY_LOCAL_MACHINE\software\activshopper
HKEY_LOCAL_MACHINE\software\activshopper
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\explorer bars\{3ea5c408-2437-4c40-adac-dfda9aeeea96}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\explorer bars\{3ea5c408-2437-4c40-adac-dfda9aeeea96}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{bfa03761-5565-41b3-93d9-82b354c0a8ec}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{bfa03761-5565-41b3-93d9-82b354c0a8ec}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{bfa03761-5565-41b3-93d9-82b354c0a8ec}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{bfa03761-5565-41b3-93d9-82b354c0a8ec}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{bfa03761-5565-41b3-93d9-82b354c0a8ec}, hoticon=[%PROGRAM_FILES%]\dealbar\compbar.dll
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{bfa03761-5565-41b3-93d9-82b354c0a8ec}, icon=[%PROGRAM_FILES%]\dealbar\compbar.dll
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{bfa03761-5565-41b3-93d9-82b354c0a8ec}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{bfa03761-5565-41b3-93d9-82b354c0a8ec}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\activshopper
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\activshopper
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\activshopper
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\activshopper

Removing Dealbar:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
ShopNav BHO Cleaner
Removing Reztuto Trojan
Removing Corkye Trojan
Removing PWS.Banker.gen Trojan
Removing EvilLife Trojan

No comments: