Thursday, November 13, 2008

BaciamiStupido Adware

Removing BaciamiStupido
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


BaciamiStupido Also known as:

[Kaspersky]Trojan-Clicker.Win32.Small.hj;
[McAfee]Generic AdClicker.o;
[Other]Dialer.BaciamiStupido

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\ciakaisen.exe
[%SYSTEM%]\smallActive.dll
[%SYSTEM%]\ciakaisen.exe
[%SYSTEM%]\smallActive.dll

How to detect BaciamiStupido:

Files:
[%SYSTEM%]\ciakaisen.exe
[%SYSTEM%]\smallActive.dll
[%SYSTEM%]\ciakaisen.exe
[%SYSTEM%]\smallActive.dll

Registry Keys:
HKEY_CLASSES_ROOT\activexcom.myactivexcom
HKEY_CLASSES_ROOT\activexcom.myactivexcom.1
HKEY_CLASSES_ROOT\clsid\{9f5bb9e1-31ae-4a13-8734-15ced0f60a3d}
HKEY_CLASSES_ROOT\interface\{303bc80e-d805-41c8-9456-566be6bb44c7}
HKEY_CLASSES_ROOT\typelib\{8dab5c8c-c784-4651-84f7-b6c9f4eec53d}
HKEY_CURRENT_USER\software\adwhere component
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\ext\stats\{9f5bb9e1-31ae-4a13-8734-15ced0f60a3d}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{9f5bb9e1-31ae-4a13-8734-15ced0f60a3d}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%SYSTEM%]\ciakaisen.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%SYSTEM%]\smallactive.dll

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls

Removing BaciamiStupido:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:

No comments: