Friday, November 28, 2008

Nusexplorer Adware

Removing Nusexplorer
Categories: Adware,Downloader
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.

This family of Trojans downloads and installs new malware or adware on the computer.
The downloader then either launches the new malware or registers it to enable autorun
according to the local operating system requirements.

The names and locations of malware to be downloaded are either coded into the
Trojan or downloaded from a specified website.

Nusexplorer Also known as:

[Kaspersky]Trojan-Downloader.Win32.Small.or,Trojan-Downloader.Win32.Agent.ez,Trojan-Downloader.Win32.Small.aeb;
[McAfee]Downloader-RP;
[Other]Win32/SillyDl.GO,Downloader-RP,Dialer.SexFiles

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\internet.exe
[%WINDOWS%]\KB813744.log
[%WINDOWS%]\switchagreement.txt
[%WINDOWS%]\wstamp.bin
[%COMMON_DESKTOPDIRECTORY%]\MeetMe.lnk
[%COMMON_DESKTOPDIRECTORY%]\TheDoctor.lnk
[%COMMON_STARTMENU%]\LipGame.lnk
[%COMMON_STARTMENU%]\VirtualGirl.lnk
[%DESKTOP%]\paypal hacking tool.exe
[%DESKTOP%]\Paypal Hacking Tool.lnk
[%PROFILE%]\Recent\Paypal Hacking Tool.lnk
[%PROFILE%]\Recent\Paypal.hta.lnk
[%PROGRAMS%]\Paypal Hacking Tool\Paypal Hacking Tool.lnk
[%PROGRAMS%]\Paypal Hacking Tool\Uninstall Paypal Hacking Tool.lnk
[%WINDOWS%]\internet.exe
[%WINDOWS%]\KB813744.log
[%WINDOWS%]\switchagreement.txt
[%WINDOWS%]\wstamp.bin
[%COMMON_DESKTOPDIRECTORY%]\MeetMe.lnk
[%COMMON_DESKTOPDIRECTORY%]\TheDoctor.lnk
[%COMMON_STARTMENU%]\LipGame.lnk
[%COMMON_STARTMENU%]\VirtualGirl.lnk
[%DESKTOP%]\paypal hacking tool.exe
[%DESKTOP%]\Paypal Hacking Tool.lnk
[%PROFILE%]\Recent\Paypal Hacking Tool.lnk
[%PROFILE%]\Recent\Paypal.hta.lnk
[%PROGRAMS%]\Paypal Hacking Tool\Paypal Hacking Tool.lnk
[%PROGRAMS%]\Paypal Hacking Tool\Uninstall Paypal Hacking Tool.lnk

How to detect Nusexplorer:

Files:
[%WINDOWS%]\internet.exe
[%WINDOWS%]\KB813744.log
[%WINDOWS%]\switchagreement.txt
[%WINDOWS%]\wstamp.bin
[%COMMON_DESKTOPDIRECTORY%]\MeetMe.lnk
[%COMMON_DESKTOPDIRECTORY%]\TheDoctor.lnk
[%COMMON_STARTMENU%]\LipGame.lnk
[%COMMON_STARTMENU%]\VirtualGirl.lnk
[%DESKTOP%]\paypal hacking tool.exe
[%DESKTOP%]\Paypal Hacking Tool.lnk
[%PROFILE%]\Recent\Paypal Hacking Tool.lnk
[%PROFILE%]\Recent\Paypal.hta.lnk
[%PROGRAMS%]\Paypal Hacking Tool\Paypal Hacking Tool.lnk
[%PROGRAMS%]\Paypal Hacking Tool\Uninstall Paypal Hacking Tool.lnk
[%WINDOWS%]\internet.exe
[%WINDOWS%]\KB813744.log
[%WINDOWS%]\switchagreement.txt
[%WINDOWS%]\wstamp.bin
[%COMMON_DESKTOPDIRECTORY%]\MeetMe.lnk
[%COMMON_DESKTOPDIRECTORY%]\TheDoctor.lnk
[%COMMON_STARTMENU%]\LipGame.lnk
[%COMMON_STARTMENU%]\VirtualGirl.lnk
[%DESKTOP%]\paypal hacking tool.exe
[%DESKTOP%]\Paypal Hacking Tool.lnk
[%PROFILE%]\Recent\Paypal Hacking Tool.lnk
[%PROFILE%]\Recent\Paypal.hta.lnk
[%PROGRAMS%]\Paypal Hacking Tool\Paypal Hacking Tool.lnk
[%PROGRAMS%]\Paypal Hacking Tool\Uninstall Paypal Hacking Tool.lnk

Folders:
[%PROGRAM_FILES%]\Paypal Hacking Tool

Registry Keys:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\paypal hacking tool

Removing Nusexplorer:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
agent.em Trojan Cleaner
Ksenia Trojan Symptoms
Removing NTbindshell RAT
ExpertAntiVirus Adware Removal instruction
Goblin Trojan Symptoms

No comments: