Monday, November 10, 2008

SA Adware

Removing SA
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


SA Also known as:

[Kaspersky]Trojan.Win32.Dialer.bi;
[McAfee]Dialer-RAS.de;
[Other]Spyware.BHO.sasetup

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\sasent.dll
[%WINDOWS%]\sasetup.dll
[%WINDOWS%]\sasent.dll
[%WINDOWS%]\sasetup.dll

How to detect SA:

Files:
[%WINDOWS%]\sasent.dll
[%WINDOWS%]\sasetup.dll
[%WINDOWS%]\sasent.dll
[%WINDOWS%]\sasetup.dll

Registry Keys:
HKEY_CLASSES_ROOT\CLSID\{38D4D5D0-423E-4220-B6F9-30918C2AE4A4}
HKEY_CLASSES_ROOT\CLSID\{7b55bb05-0b4d-44fd-81a6-b136188f5deb}
HKEY_CLASSES_ROOT\interface\{18e6c36a-c45f-4b60-a1a4-5c0bb16d4cc2}
HKEY_CLASSES_ROOT\interface\{8a94c367-815a-4d4f-a6b6-d4eb877a126c}
HKEY_CLASSES_ROOT\interface\{d6188a7d-376c-4970-91ad-675bfcf3762e}
HKEY_CLASSES_ROOT\typelib\{00a322e2-7d50-4dba-bea4-5c8078d47269}
HKEY_CLASSES_ROOT\typelib\{8ea362bd-39cb-40f5-9226-73cd40999095}
HKEY_CLASSES_ROOT\typelib\{ced445e2-8c78-4f40-87d7-f7fb6f1b6791}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7b55bb05-0b4d-44fd-81a6-b136188f5deb}
HKEY_CLASSES_ROOT\classes\interface\{d6188a7d-376c-4970-91ad-675bfcf3762e}
HKEY_CLASSES_ROOT\clsid\{0191abf4-9421-435e-9ffd-cd827a2a82d8}
HKEY_CLASSES_ROOT\clsid\{38d4d5d0-423e-4220-b6f9-30918c2ae4a4}
HKEY_CLASSES_ROOT\clsid\{4bcf322b-9621-4e90-9678-f1424eb7584e}
HKEY_CLASSES_ROOT\clsid\{7b55bb05-0b4d-44fd-81a6-b136188f5deb}
HKEY_CLASSES_ROOT\clsid\{860ce847-8298-4114-b142-14043c2942b1}
HKEY_CLASSES_ROOT\interface\{3ca4f168-fdc3-425d-8812-bb1379581e85}
HKEY_CLASSES_ROOT\interface\{d47bd4de-b880-4610-8a8b-c173dec4272f}
HKEY_CLASSES_ROOT\sbitax7.sbitax7ctrl
HKEY_CLASSES_ROOT\sbitax7.sbitax7ctrl.1
HKEY_CLASSES_ROOT\typelib\{85a886b2-29bb-4189-8046-a66733b242e9}
HKEY_CLASSES_ROOT\typelib\{d6637f05-74ed-4ccf-80ab-20c8ec66877a}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4bcf322b-9621-4e90-9678-f1424eb7584e}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{7b55bb05-0b4d-44fd-81a6-b136188f5deb}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{860ce847-8298-4114-b142-14043c2942b1}

Registry Values:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler

Removing SA:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:

No comments: