Tuesday, October 14, 2008

Emusaffil Trojan

Removing Emusaffil
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers create multi-functional Trojans rather than Trojan packs.

Visible Symptoms:
Files in system folders:
[%PROGRAM_FILES%]\Winamp\eMusic\eMusicClient.exe
[%SYSTEM%]\eMusicTDB3P.exe
[%WINDOWS%]\eMusicSetup.exe
[%DESKTOP%]\50 FREE MP3s from eMusic!.url
[%PROGRAMS%]\50 FREE MP3s from eMusic!.url
[%PROGRAM_FILES%]\eMusic\eMusicClient.exe
[%PROGRAM_FILES%]\eMusic\eMusicClient.ini
[%PROGRAM_FILES%]\eMusic\eMusicSetup.exe
[%PROGRAM_FILES%]\eMusic\Round.ico
[%WINDOWS%]\eMusicClient.ini
[%PROGRAM_FILES%]\Winamp\eMusic\eMusicClient.exe
[%SYSTEM%]\eMusicTDB3P.exe
[%WINDOWS%]\eMusicSetup.exe
[%DESKTOP%]\50 FREE MP3s from eMusic!.url
[%PROGRAMS%]\50 FREE MP3s from eMusic!.url
[%PROGRAM_FILES%]\eMusic\eMusicClient.exe
[%PROGRAM_FILES%]\eMusic\eMusicClient.ini
[%PROGRAM_FILES%]\eMusic\eMusicSetup.exe
[%PROGRAM_FILES%]\eMusic\Round.ico
[%WINDOWS%]\eMusicClient.ini

How to detect Emusaffil:

Files:
[%PROGRAM_FILES%]\Winamp\eMusic\eMusicClient.exe
[%SYSTEM%]\eMusicTDB3P.exe
[%WINDOWS%]\eMusicSetup.exe
[%DESKTOP%]\50 FREE MP3s from eMusic!.url
[%PROGRAMS%]\50 FREE MP3s from eMusic!.url
[%PROGRAM_FILES%]\eMusic\eMusicClient.exe
[%PROGRAM_FILES%]\eMusic\eMusicClient.ini
[%PROGRAM_FILES%]\eMusic\eMusicSetup.exe
[%PROGRAM_FILES%]\eMusic\Round.ico
[%WINDOWS%]\eMusicClient.ini
[%PROGRAM_FILES%]\Winamp\eMusic\eMusicClient.exe
[%SYSTEM%]\eMusicTDB3P.exe
[%WINDOWS%]\eMusicSetup.exe
[%DESKTOP%]\50 FREE MP3s from eMusic!.url
[%PROGRAMS%]\50 FREE MP3s from eMusic!.url
[%PROGRAM_FILES%]\eMusic\eMusicClient.exe
[%PROGRAM_FILES%]\eMusic\eMusicClient.ini
[%PROGRAM_FILES%]\eMusic\eMusicSetup.exe
[%PROGRAM_FILES%]\eMusic\Round.ico
[%WINDOWS%]\eMusicClient.ini

Registry Keys:
HKEY_CLASSES_ROOT\typelib\{53f066f0-a4c0-4f46-83eb-2dfd03f938cf}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{686c970f-1d7d-4469-85d1-4b35763b56cc}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\emusicsetup

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping
HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping
HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping
HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping
HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping
HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing Emusaffil:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
CWS.LoadBAT Hijacker Information
Removing SurfAccuracyUpdater Downloader
TrojanDownloader.Win32.Rameh Trojan Cleaner
Excel.Yohimbe Trojan Symptoms
Remove IGetNet.Keywords BHO

No comments: