Monday, November 24, 2008

QuickLinks Spyware

Removing QuickLinks
Categories: Spyware,Downloader,Adware
Spyware is computer software that is installed surreptitiously on a personal computer
to with the computer, without the user's informed consent.
Trojans-downloaders downloads and installs new malware or adware on the computer.

Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


Visible Symptoms:
Files in system folders:
[%SYSTEM%]\intlib.bin
[%SYSTEM%]\lmf32.dll
[%SYSTEM%]\qldf.bin
[%SYSTEM%]\Quicklinks.exe
[%SYSTEM%]\igps.exe
[%SYSTEM%]\pgws.exe
[%SYSTEM%]\intlib.bin
[%SYSTEM%]\lmf32.dll
[%SYSTEM%]\qldf.bin
[%SYSTEM%]\Quicklinks.exe
[%SYSTEM%]\igps.exe
[%SYSTEM%]\pgws.exe

How to detect QuickLinks:

Files:
[%SYSTEM%]\intlib.bin
[%SYSTEM%]\lmf32.dll
[%SYSTEM%]\qldf.bin
[%SYSTEM%]\Quicklinks.exe
[%SYSTEM%]\igps.exe
[%SYSTEM%]\pgws.exe
[%SYSTEM%]\intlib.bin
[%SYSTEM%]\lmf32.dll
[%SYSTEM%]\qldf.bin
[%SYSTEM%]\Quicklinks.exe
[%SYSTEM%]\igps.exe
[%SYSTEM%]\pgws.exe

Folders:
[%PROGRAM_FILES%]\QL
[%PROGRAM_FILES%]\quick links
[%PROGRAM_FILES%]\jalmp

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{3551784b-e99a-474f-b782-3ec814442918}
HKEY_CLASSES_ROOT\CLSID\{8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22}
HKEY_CLASSES_ROOT\interface\{4162d910-6167-42e7-91ae-6a522c4121d2}
HKEY_CLASSES_ROOT\quicklinks.linktracker
HKEY_CLASSES_ROOT\quicklinks.linktracker.1
HKEY_CLASSES_ROOT\quicklinks.quicklinksfilter
HKEY_CLASSES_ROOT\quicklinks.quicklinksfilter.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39C78B50-7E98-4AA0-B007-D83114EA6E0F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\quick links
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\quicklinks
HKEY_LOCAL_MACHINE\software\ql
HKEY_CLASSES_ROOT\clsid\{2f6e85dc-8d2d-4896-8a4f-7df8a7b1749d}
HKEY_CLASSES_ROOT\clsid\{39c78b50-7e98-4aa0-b007-d83114ea6e0f}
HKEY_CLASSES_ROOT\clsid\{8b6da27e-7f64-4694-8f8f-dc87ab8c6b22}
HKEY_CLASSES_ROOT\interface\{39c78b50-7e98-4aa0-b007-d83114ea6e0f}
HKEY_CLASSES_ROOT\permeation.permeater
HKEY_CLASSES_ROOT\permeation.permeater.1
HKEY_CLASSES_ROOT\permeation.trecker
HKEY_CLASSES_ROOT\permeation.trecker.1
HKEY_CLASSES_ROOT\typelib\{2f6e85dc-8d2d-4896-8a4f-7df8a7b1749d}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{39c78b50-7e98-4aa0-b007-d83114ea6e0f}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8b6da27e-7f64-4694-8f8f-dc87ab8c6b22}

Registry Values:
HKEY_CLASSES_ROOT\protocols\filter\text/html
HKEY_CLASSES_ROOT\protocols\filter\text/html
HKEY_LOCAL_MACHINE\software\meld
HKEY_LOCAL_MACHINE\software\meld
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing QuickLinks:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Outerinfo Malware Information
BrowserAid.Featured.Results BHO Removal
TrojanDownloader.Win32.Tibser Adware Removal instruction
Remove DataSpy.Network Trojan
Fonesex Trojan Symptoms

No comments: