Tuesday, November 18, 2008

sqwire Adware

Removing sqwire
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\sqwire.log
[%WINDOWS%]\temp\tsl_rc0_wrap.exe
[%SYSTEM%]\sqwire.log
[%WINDOWS%]\temp\tsl_rc0_wrap.exe

How to detect sqwire:

Files:
[%SYSTEM%]\sqwire.log
[%WINDOWS%]\temp\tsl_rc0_wrap.exe
[%SYSTEM%]\sqwire.log
[%WINDOWS%]\temp\tsl_rc0_wrap.exe

Folders:
[%COMMON_FAVORITES%]\favorites\shopping
[%FAVORITES%]\favorites\business
[%FAVORITES%]\favorites\computers
[%FAVORITES%]\favorites\finance
[%FAVORITES%]\favorites\shopping
[%FAVORITES%]\favorites\cool stuff
[%FAVORITES%]\favorites\entertainment
[%FAVORITES%]\favorites\free stuff
[%FAVORITES%]\favorites\gambling
[%FAVORITES%]\favorites\gaming
[%FAVORITES%]\favorites\inernet
[%FAVORITES%]\favorites\lifestyle

Registry Keys:
HKEY_CLASSES_ROOT\classes\sqloader.loader
HKEY_CLASSES_ROOT\classes\sqloader.loader.1
HKEY_CLASSES_ROOT\interface\{32e715f3-6481-4118-a689-504312933ce6}
HKEY_CLASSES_ROOT\typelib\{118af62f-21b1-4492-8111-c1a03c5e09cb}
HKEY_CLASSES_ROOT\typelib\{4d0ac936-bde8-4ea2-b4fb-9f89e5b4c186}
HKEY_CURRENT_USER\software\sq
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3c5ba506-6c30-4738-9ced-797acadea8dc}

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing sqwire:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing Triplethreat Hostile Code
Y3K.Remote.Administration.Tool.MegaSecurity RAT Information
Remove Attitude Trojan
XP.Antivirus Ransomware Cleaner

No comments: