Sunday, November 23, 2008

Storark Trojan

Removing Storark
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

Storark Also known as:

[Kaspersky]Trojan-Spy.Win32.Delf.uv,Trojan-PSW.Win32.OnLineGames.aqn,Trojan-PSW.Win32.OnLineGames.dfs,Trojan-Spy.Win32.Delf.bci,Trojan-PSW.Win32.OnLineGames.dgw,Trojan-Spy.Win32.Delf.aji,Trojan-PSW.Win32.OnLineGames.dsj,Trojan-PSW.Win32.OnLineGames.deg,Trojan-PSW:Win32.OnLineGames.fwv,Trojan-PSW.Win32.OnLineGames.fqm,Trojan-PSW.Win32.OnLineGames.dzp,Trojan-PSW.Win32.OnLineGames.fyp,Trojan-PSW.Win32.OnLineGames.ggn,Trojan-PSW.Win32.OnLineGames.enm,Trojan-PSW.Win32.OnLineGames.giv,Trojan-PWS.Win32.OnLineGames.ggm,Trojan-PSW.Win32.OnLineGames.get,Trojan-PSW.Win32.OnLineGames.fpx,Trojan-PSW.Win32.OnLineGames.fqb,Trojan-PSW.Win32.OnLineGames.fef,Trojan-PSW.Win32.OnLineGames.fpw,Trojan-PSW.Win32o.OnLineGames.ebw,Trojan-Dropper.Win32.Mudrop.fg,Trojan-PSW.Win32.OnLineGames.eax,Trojan-PSW.Win32.OnLineGames.eav,Trojan-PSW.Win32.OnLineGames.dzq,Trojan-PSW.Win32.OnLineGames.hxg,Trojan-PSW.Win32.OnLineGames.hsy;
[McAfee]PWS-OnlineGames.f,PWS-OnlineGames.a.dll,PWS-OnlineGames.i,New Malware.n,New malware.n,PWS-OnlineGames.k.dll;
[Other]Win32/Storark.C,Win32/Storark.AR,Infostealer.Gampass,Win32/Storark.AS,Win32/Storark.AT,Win32/Storark.AU,Infostealer.Gamepass,Win32/Storark.AV,Infostealer.Menghuan,Win32.Storark.AW,Win32/Storark.BB,Win32/Storark,Win32/Storark.BV,Trojan:Win32/Delf.AT!dll,Win32/Storark.BW,Win32/Storark.BX,TSPY_ONLINEG.IRZ,Mal/Delagen-A,Win32/Storark.BZ,W32/Malware.AVHG,Win32/Storark.CA,Win32/Storark!generic,Trojan:Win32/SystemHijack.gen,W32/Malware,Mal/Behav-152,Win32/Storark.CC,W32/OnLineGames.PLZ,W32/OnLineGames.QCZ,TSPY_ONLINEG.LKC,Win32/Storark.CK,W32/Delf.AYBJ,Win32/Storark.CU,W32/Malare.BCGX,Win32/Storark.CW,Trojan:Win32.Delf.AT!dll,W32/Malware.BCFF,W32/Malware.BBNR,Win32/Storark.CT,W32/Malware.BCFW,Win32/Storark.CN,W32/Malware.AZKA,W32/Malware.BCMD,Win32/Storark.CD,W32/Malware.AZEH,TSPY_ONLINEG.IUX,Win32/Storark.CG,W32/Malware.AZDV,Win32/Storark.CI,W32/Malware.AYNM,OnLineGames.gen34,W32/OnLineGames.VBH

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\avzxain.dll
[%SYSTEM%]\htzmf.log
[%SYSTEM%]\kapjacs.dll
[%SYSTEM%]\kawdacs.dll
[%SYSTEM%]\kawdbzy.dll
[%SYSTEM%]\kvdxacf.dll
[%SYSTEM%]\lktgy.txt
[%SYSTEM%]\raqjani.dll
[%SYSTEM%]\rsjzafg.dll
[%SYSTEM%]\rsmyafg.dll
[%WINDOWS%]\knnte.txt
[%WINDOWS%]\nbqdq.txt
[%SYSTEM%]\avwlain.dll
[%SYSTEM%]\avwlamn.dll
[%SYSTEM%]\avwlast.exe
[%SYSTEM%]\avwldin.dll
[%SYSTEM%]\avwldmn.dll
[%SYSTEM%]\avwldst.exe
[%SYSTEM%]\avzxamn.dll
[%SYSTEM%]\avzxast.exe
[%SYSTEM%]\avzxein.dll
[%SYSTEM%]\avzxemn.dll
[%SYSTEM%]\avzxest.exe
[%SYSTEM%]\caomsnima.dll
[%SYSTEM%]\dhdini.dll
[%SYSTEM%]\dheins.exe
[%SYSTEM%]\dhepri.dll
[%SYSTEM%]\kapjaaz.exe
[%SYSTEM%]\kapjazy.dll
[%SYSTEM%]\kapjdaz.exe
[%SYSTEM%]\kapjdcs.dll
[%SYSTEM%]\kapjdzy.dll
[%SYSTEM%]\kaqhacs.dll
[%SYSTEM%]\kaqhcaz.exe
[%SYSTEM%]\kaqhczy.dll
[%SYSTEM%]\kaqhgaz.exe
[%SYSTEM%]\kaqhgcs.dll
[%SYSTEM%]\kaqhgzy.dll
[%SYSTEM%]\kawdbaz.exe
[%SYSTEM%]\kawdcaz.exe
[%SYSTEM%]\kawdccs.dll
[%SYSTEM%]\kawdczy.dll
[%SYSTEM%]\kvdxbis.exe
[%SYSTEM%]\kvdxbma.dll
[%SYSTEM%]\kvdxgcf.dll
[%SYSTEM%]\kvdxgis.exe
[%SYSTEM%]\kvdxgma.dll
[%SYSTEM%]\kvdxsacf.dll
[%SYSTEM%]\kvdxsais.exe
[%SYSTEM%]\kvdxsama.dll
[%SYSTEM%]\kvdxsfcf.dll
[%SYSTEM%]\kvdxsfis.exe
[%SYSTEM%]\kvdxsfma.dll
[%SYSTEM%]\kvmxfcf.dll
[%SYSTEM%]\kvmxfis.exe
[%SYSTEM%]\kvmxfma.dll
[%SYSTEM%]\mxbcfg.dll
[%SYSTEM%]\mxbman.dll
[%SYSTEM%]\mxbset.exe
[%SYSTEM%]\mygini.dll
[%SYSTEM%]\myhins.exe
[%SYSTEM%]\myhpri.dll
[%SYSTEM%]\qjgpri.dll
[%SYSTEM%]\raqjapi.dll
[%SYSTEM%]\raqjatl.exe
[%SYSTEM%]\rarjani.dll
[%SYSTEM%]\rarjbpi.dll
[%SYSTEM%]\rarjbtl.exe
[%SYSTEM%]\ratbani.dll
[%SYSTEM%]\ratbfpi.dll
[%SYSTEM%]\ratbftl.exe
[%SYSTEM%]\rsjzapm.dll
[%SYSTEM%]\rsjzasp.exe
[%SYSTEM%]\rsmyapm.dll
[%SYSTEM%]\rsmyasp.exe
[%SYSTEM%]\rsmyepm.dll
[%SYSTEM%]\rsmyesp.exe
[%SYSTEM%]\rsmyfpm.dll
[%SYSTEM%]\rsmyfsp.exe
[%SYSTEM%]\rsmygfg.dll
[%SYSTEM%]\rsmygpm.dll
[%SYSTEM%]\rsmygsp.exe
[%SYSTEM%]\rsztffg.dll
[%SYSTEM%]\rsztfpm.dll
[%SYSTEM%]\rsztfsp.exe
[%SYSTEM%]\sidjbaz.exe
[%SYSTEM%]\sidjbcs.dll
[%SYSTEM%]\sidjbzy.dll
[%SYSTEM%]\sqmapi32.dll
[%SYSTEM%]\wggini.dll
[%SYSTEM%]\wggins.exe
[%SYSTEM%]\wggpri.dll
[%SYSTEM%]\wlgini.dll
[%SYSTEM%]\wlhins.exe
[%SYSTEM%]\wlhpri.dll
[%SYSTEM%]\avzxain.dll
[%SYSTEM%]\htzmf.log
[%SYSTEM%]\kapjacs.dll
[%SYSTEM%]\kawdacs.dll
[%SYSTEM%]\kawdbzy.dll
[%SYSTEM%]\kvdxacf.dll
[%SYSTEM%]\lktgy.txt
[%SYSTEM%]\raqjani.dll
[%SYSTEM%]\rsjzafg.dll
[%SYSTEM%]\rsmyafg.dll
[%WINDOWS%]\knnte.txt
[%WINDOWS%]\nbqdq.txt
[%SYSTEM%]\avwlain.dll
[%SYSTEM%]\avwlamn.dll
[%SYSTEM%]\avwlast.exe
[%SYSTEM%]\avwldin.dll
[%SYSTEM%]\avwldmn.dll
[%SYSTEM%]\avwldst.exe
[%SYSTEM%]\avzxamn.dll
[%SYSTEM%]\avzxast.exe
[%SYSTEM%]\avzxein.dll
[%SYSTEM%]\avzxemn.dll
[%SYSTEM%]\avzxest.exe
[%SYSTEM%]\caomsnima.dll
[%SYSTEM%]\dhdini.dll
[%SYSTEM%]\dheins.exe
[%SYSTEM%]\dhepri.dll
[%SYSTEM%]\kapjaaz.exe
[%SYSTEM%]\kapjazy.dll
[%SYSTEM%]\kapjdaz.exe
[%SYSTEM%]\kapjdcs.dll
[%SYSTEM%]\kapjdzy.dll
[%SYSTEM%]\kaqhacs.dll
[%SYSTEM%]\kaqhcaz.exe
[%SYSTEM%]\kaqhczy.dll
[%SYSTEM%]\kaqhgaz.exe
[%SYSTEM%]\kaqhgcs.dll
[%SYSTEM%]\kaqhgzy.dll
[%SYSTEM%]\kawdbaz.exe
[%SYSTEM%]\kawdcaz.exe
[%SYSTEM%]\kawdccs.dll
[%SYSTEM%]\kawdczy.dll
[%SYSTEM%]\kvdxbis.exe
[%SYSTEM%]\kvdxbma.dll
[%SYSTEM%]\kvdxgcf.dll
[%SYSTEM%]\kvdxgis.exe
[%SYSTEM%]\kvdxgma.dll
[%SYSTEM%]\kvdxsacf.dll
[%SYSTEM%]\kvdxsais.exe
[%SYSTEM%]\kvdxsama.dll
[%SYSTEM%]\kvdxsfcf.dll
[%SYSTEM%]\kvdxsfis.exe
[%SYSTEM%]\kvdxsfma.dll
[%SYSTEM%]\kvmxfcf.dll
[%SYSTEM%]\kvmxfis.exe
[%SYSTEM%]\kvmxfma.dll
[%SYSTEM%]\mxbcfg.dll
[%SYSTEM%]\mxbman.dll
[%SYSTEM%]\mxbset.exe
[%SYSTEM%]\mygini.dll
[%SYSTEM%]\myhins.exe
[%SYSTEM%]\myhpri.dll
[%SYSTEM%]\qjgpri.dll
[%SYSTEM%]\raqjapi.dll
[%SYSTEM%]\raqjatl.exe
[%SYSTEM%]\rarjani.dll
[%SYSTEM%]\rarjbpi.dll
[%SYSTEM%]\rarjbtl.exe
[%SYSTEM%]\ratbani.dll
[%SYSTEM%]\ratbfpi.dll
[%SYSTEM%]\ratbftl.exe
[%SYSTEM%]\rsjzapm.dll
[%SYSTEM%]\rsjzasp.exe
[%SYSTEM%]\rsmyapm.dll
[%SYSTEM%]\rsmyasp.exe
[%SYSTEM%]\rsmyepm.dll
[%SYSTEM%]\rsmyesp.exe
[%SYSTEM%]\rsmyfpm.dll
[%SYSTEM%]\rsmyfsp.exe
[%SYSTEM%]\rsmygfg.dll
[%SYSTEM%]\rsmygpm.dll
[%SYSTEM%]\rsmygsp.exe
[%SYSTEM%]\rsztffg.dll
[%SYSTEM%]\rsztfpm.dll
[%SYSTEM%]\rsztfsp.exe
[%SYSTEM%]\sidjbaz.exe
[%SYSTEM%]\sidjbcs.dll
[%SYSTEM%]\sidjbzy.dll
[%SYSTEM%]\sqmapi32.dll
[%SYSTEM%]\wggini.dll
[%SYSTEM%]\wggins.exe
[%SYSTEM%]\wggpri.dll
[%SYSTEM%]\wlgini.dll
[%SYSTEM%]\wlhins.exe
[%SYSTEM%]\wlhpri.dll

How to detect Storark:

Files:
[%SYSTEM%]\avzxain.dll
[%SYSTEM%]\htzmf.log
[%SYSTEM%]\kapjacs.dll
[%SYSTEM%]\kawdacs.dll
[%SYSTEM%]\kawdbzy.dll
[%SYSTEM%]\kvdxacf.dll
[%SYSTEM%]\lktgy.txt
[%SYSTEM%]\raqjani.dll
[%SYSTEM%]\rsjzafg.dll
[%SYSTEM%]\rsmyafg.dll
[%WINDOWS%]\knnte.txt
[%WINDOWS%]\nbqdq.txt
[%SYSTEM%]\avwlain.dll
[%SYSTEM%]\avwlamn.dll
[%SYSTEM%]\avwlast.exe
[%SYSTEM%]\avwldin.dll
[%SYSTEM%]\avwldmn.dll
[%SYSTEM%]\avwldst.exe
[%SYSTEM%]\avzxamn.dll
[%SYSTEM%]\avzxast.exe
[%SYSTEM%]\avzxein.dll
[%SYSTEM%]\avzxemn.dll
[%SYSTEM%]\avzxest.exe
[%SYSTEM%]\caomsnima.dll
[%SYSTEM%]\dhdini.dll
[%SYSTEM%]\dheins.exe
[%SYSTEM%]\dhepri.dll
[%SYSTEM%]\kapjaaz.exe
[%SYSTEM%]\kapjazy.dll
[%SYSTEM%]\kapjdaz.exe
[%SYSTEM%]\kapjdcs.dll
[%SYSTEM%]\kapjdzy.dll
[%SYSTEM%]\kaqhacs.dll
[%SYSTEM%]\kaqhcaz.exe
[%SYSTEM%]\kaqhczy.dll
[%SYSTEM%]\kaqhgaz.exe
[%SYSTEM%]\kaqhgcs.dll
[%SYSTEM%]\kaqhgzy.dll
[%SYSTEM%]\kawdbaz.exe
[%SYSTEM%]\kawdcaz.exe
[%SYSTEM%]\kawdccs.dll
[%SYSTEM%]\kawdczy.dll
[%SYSTEM%]\kvdxbis.exe
[%SYSTEM%]\kvdxbma.dll
[%SYSTEM%]\kvdxgcf.dll
[%SYSTEM%]\kvdxgis.exe
[%SYSTEM%]\kvdxgma.dll
[%SYSTEM%]\kvdxsacf.dll
[%SYSTEM%]\kvdxsais.exe
[%SYSTEM%]\kvdxsama.dll
[%SYSTEM%]\kvdxsfcf.dll
[%SYSTEM%]\kvdxsfis.exe
[%SYSTEM%]\kvdxsfma.dll
[%SYSTEM%]\kvmxfcf.dll
[%SYSTEM%]\kvmxfis.exe
[%SYSTEM%]\kvmxfma.dll
[%SYSTEM%]\mxbcfg.dll
[%SYSTEM%]\mxbman.dll
[%SYSTEM%]\mxbset.exe
[%SYSTEM%]\mygini.dll
[%SYSTEM%]\myhins.exe
[%SYSTEM%]\myhpri.dll
[%SYSTEM%]\qjgpri.dll
[%SYSTEM%]\raqjapi.dll
[%SYSTEM%]\raqjatl.exe
[%SYSTEM%]\rarjani.dll
[%SYSTEM%]\rarjbpi.dll
[%SYSTEM%]\rarjbtl.exe
[%SYSTEM%]\ratbani.dll
[%SYSTEM%]\ratbfpi.dll
[%SYSTEM%]\ratbftl.exe
[%SYSTEM%]\rsjzapm.dll
[%SYSTEM%]\rsjzasp.exe
[%SYSTEM%]\rsmyapm.dll
[%SYSTEM%]\rsmyasp.exe
[%SYSTEM%]\rsmyepm.dll
[%SYSTEM%]\rsmyesp.exe
[%SYSTEM%]\rsmyfpm.dll
[%SYSTEM%]\rsmyfsp.exe
[%SYSTEM%]\rsmygfg.dll
[%SYSTEM%]\rsmygpm.dll
[%SYSTEM%]\rsmygsp.exe
[%SYSTEM%]\rsztffg.dll
[%SYSTEM%]\rsztfpm.dll
[%SYSTEM%]\rsztfsp.exe
[%SYSTEM%]\sidjbaz.exe
[%SYSTEM%]\sidjbcs.dll
[%SYSTEM%]\sidjbzy.dll
[%SYSTEM%]\sqmapi32.dll
[%SYSTEM%]\wggini.dll
[%SYSTEM%]\wggins.exe
[%SYSTEM%]\wggpri.dll
[%SYSTEM%]\wlgini.dll
[%SYSTEM%]\wlhins.exe
[%SYSTEM%]\wlhpri.dll
[%SYSTEM%]\avzxain.dll
[%SYSTEM%]\htzmf.log
[%SYSTEM%]\kapjacs.dll
[%SYSTEM%]\kawdacs.dll
[%SYSTEM%]\kawdbzy.dll
[%SYSTEM%]\kvdxacf.dll
[%SYSTEM%]\lktgy.txt
[%SYSTEM%]\raqjani.dll
[%SYSTEM%]\rsjzafg.dll
[%SYSTEM%]\rsmyafg.dll
[%WINDOWS%]\knnte.txt
[%WINDOWS%]\nbqdq.txt
[%SYSTEM%]\avwlain.dll
[%SYSTEM%]\avwlamn.dll
[%SYSTEM%]\avwlast.exe
[%SYSTEM%]\avwldin.dll
[%SYSTEM%]\avwldmn.dll
[%SYSTEM%]\avwldst.exe
[%SYSTEM%]\avzxamn.dll
[%SYSTEM%]\avzxast.exe
[%SYSTEM%]\avzxein.dll
[%SYSTEM%]\avzxemn.dll
[%SYSTEM%]\avzxest.exe
[%SYSTEM%]\caomsnima.dll
[%SYSTEM%]\dhdini.dll
[%SYSTEM%]\dheins.exe
[%SYSTEM%]\dhepri.dll
[%SYSTEM%]\kapjaaz.exe
[%SYSTEM%]\kapjazy.dll
[%SYSTEM%]\kapjdaz.exe
[%SYSTEM%]\kapjdcs.dll
[%SYSTEM%]\kapjdzy.dll
[%SYSTEM%]\kaqhacs.dll
[%SYSTEM%]\kaqhcaz.exe
[%SYSTEM%]\kaqhczy.dll
[%SYSTEM%]\kaqhgaz.exe
[%SYSTEM%]\kaqhgcs.dll
[%SYSTEM%]\kaqhgzy.dll
[%SYSTEM%]\kawdbaz.exe
[%SYSTEM%]\kawdcaz.exe
[%SYSTEM%]\kawdccs.dll
[%SYSTEM%]\kawdczy.dll
[%SYSTEM%]\kvdxbis.exe
[%SYSTEM%]\kvdxbma.dll
[%SYSTEM%]\kvdxgcf.dll
[%SYSTEM%]\kvdxgis.exe
[%SYSTEM%]\kvdxgma.dll
[%SYSTEM%]\kvdxsacf.dll
[%SYSTEM%]\kvdxsais.exe
[%SYSTEM%]\kvdxsama.dll
[%SYSTEM%]\kvdxsfcf.dll
[%SYSTEM%]\kvdxsfis.exe
[%SYSTEM%]\kvdxsfma.dll
[%SYSTEM%]\kvmxfcf.dll
[%SYSTEM%]\kvmxfis.exe
[%SYSTEM%]\kvmxfma.dll
[%SYSTEM%]\mxbcfg.dll
[%SYSTEM%]\mxbman.dll
[%SYSTEM%]\mxbset.exe
[%SYSTEM%]\mygini.dll
[%SYSTEM%]\myhins.exe
[%SYSTEM%]\myhpri.dll
[%SYSTEM%]\qjgpri.dll
[%SYSTEM%]\raqjapi.dll
[%SYSTEM%]\raqjatl.exe
[%SYSTEM%]\rarjani.dll
[%SYSTEM%]\rarjbpi.dll
[%SYSTEM%]\rarjbtl.exe
[%SYSTEM%]\ratbani.dll
[%SYSTEM%]\ratbfpi.dll
[%SYSTEM%]\ratbftl.exe
[%SYSTEM%]\rsjzapm.dll
[%SYSTEM%]\rsjzasp.exe
[%SYSTEM%]\rsmyapm.dll
[%SYSTEM%]\rsmyasp.exe
[%SYSTEM%]\rsmyepm.dll
[%SYSTEM%]\rsmyesp.exe
[%SYSTEM%]\rsmyfpm.dll
[%SYSTEM%]\rsmyfsp.exe
[%SYSTEM%]\rsmygfg.dll
[%SYSTEM%]\rsmygpm.dll
[%SYSTEM%]\rsmygsp.exe
[%SYSTEM%]\rsztffg.dll
[%SYSTEM%]\rsztfpm.dll
[%SYSTEM%]\rsztfsp.exe
[%SYSTEM%]\sidjbaz.exe
[%SYSTEM%]\sidjbcs.dll
[%SYSTEM%]\sidjbzy.dll
[%SYSTEM%]\sqmapi32.dll
[%SYSTEM%]\wggini.dll
[%SYSTEM%]\wggins.exe
[%SYSTEM%]\wggpri.dll
[%SYSTEM%]\wlgini.dll
[%SYSTEM%]\wlhins.exe
[%SYSTEM%]\wlhpri.dll

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{28907901-1416-3389-9981-372178569982}
HKEY_CLASSES_ROOT\clsid\{e3a77057-d10b-b02a-d823-22e020c583b5}
HKEY_CLASSES_ROOT\clsid\{12faacde-34da-ccd4-ab4d-da34485a3421}
HKEY_CLASSES_ROOT\clsid\{131ab311-16f1-f13b-1e43-11a24b51afd1}
HKEY_CLASSES_ROOT\clsid\{14783410-4f90-34a0-7820-3230acd05f41}
HKEY_CLASSES_ROOT\clsid\{1859245f-345d-bc13-ac4f-145d47da34f1}
HKEY_CLASSES_ROOT\clsid\{18847374-8323-fadc-b443-4732abcd3781}
HKEY_CLASSES_ROOT\clsid\{1960356a-458e-de24-bd50-268f589a56a1}
HKEY_CLASSES_ROOT\clsid\{1a321487-4977-d98a-c8d5-6488257545a1}
HKEY_CLASSES_ROOT\clsid\{1d561258-45f3-a451-f908-a258458226d1}
HKEY_CLASSES_ROOT\clsid\{1e32fa58-3453-fa2d-bc49-f340348acce1}
HKEY_CLASSES_ROOT\clsid\{2231a43a-1642-641a-64fd-146adab223b2}
HKEY_CLASSES_ROOT\clsid\{22faacde-34da-ccd4-ab4d-da34485a3422}
HKEY_CLASSES_ROOT\clsid\{24783410-4f90-34a0-7820-3230acd05f42}
HKEY_CLASSES_ROOT\clsid\{2598ff45-da60-f48a-bc43-10ac47853d52}
HKEY_CLASSES_ROOT\clsid\{28847374-8323-fadc-b443-4732abcd3782}
HKEY_CLASSES_ROOT\clsid\{2960356a-458e-de24-bd50-268f589a56a2}
HKEY_CLASSES_ROOT\clsid\{2a321487-4977-d98a-c8d5-6488257545a2}
HKEY_CLASSES_ROOT\clsid\{2c87a354-abc3-dede-ff33-3213fd7447c2}
HKEY_CLASSES_ROOT\clsid\{37d81718-1314-5200-2597-587901018073}
HKEY_CLASSES_ROOT\clsid\{38907901-1416-3389-9981-372178569983}
HKEY_CLASSES_ROOT\clsid\{3960356a-458e-de24-bd50-268f589a56a3}
HKEY_CLASSES_ROOT\clsid\{3c87a354-abc3-dede-ff33-3213fd7447c3}
HKEY_CLASSES_ROOT\clsid\{3d561258-45f3-a451-f908-a258458226d3}
HKEY_CLASSES_ROOT\clsid\{434345f1-dacf-3452-cb7d-4620f34a1534}
HKEY_CLASSES_ROOT\clsid\{4960356a-458e-de24-bd50-268f589a56a4}
HKEY_CLASSES_ROOT\clsid\{4a321487-4977-d98a-c8d5-6488257545a4}
HKEY_CLASSES_ROOT\clsid\{5182c1eb-375c-573d-1f5e-234552345215}
HKEY_CLASSES_ROOT\clsid\{52311a42-ac1b-158f-fd32-5674345f23a5}
HKEY_CLASSES_ROOT\clsid\{5859245f-345d-bc13-ac4f-145d47da34f5}
HKEY_CLASSES_ROOT\clsid\{5bd41097-3693-4133-820e-fdac57af00e2}
HKEY_CLASSES_ROOT\clsid\{5c87a354-abc3-dede-ff33-3213fd7447c5}
HKEY_CLASSES_ROOT\clsid\{5e32fa58-3453-fa2d-bc49-f340348acce5}
HKEY_CLASSES_ROOT\clsid\{634345f1-dacf-3452-cb7d-4620f34a1536}
HKEY_CLASSES_ROOT\clsid\{66650011-3344-6688-4899-345fabcd1566}
HKEY_CLASSES_ROOT\clsid\{6d47b341-43df-4563-753f-345ffa3157d6}
HKEY_CLASSES_ROOT\clsid\{6d561258-45f3-a451-f908-a258458226d6}
HKEY_CLASSES_ROOT\clsid\{6e32fa58-3453-fa2d-bc49-f340348acce6}
HKEY_CLASSES_ROOT\clsid\{725ab2f3-234a-7469-2f43-e341713abfa7}
HKEY_CLASSES_ROOT\clsid\{74123ff1-8371-9834-9021-184518451fa7}
HKEY_CLASSES_ROOT\clsid\{77d81718-1314-5200-2597-587901018077}
HKEY_CLASSES_ROOT\clsid\{7c87a354-abc3-dede-ff33-3213fd7447c7}
HKEY_CLASSES_ROOT\clsid\{7e32fa58-3453-fa2d-bc49-f340348acce7}
HKEY_CLASSES_ROOT\clsid\{8562452f-fa36-ba4f-892a-ff5fbbac5318}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows\appinit_dlls
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing Storark:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing KD Adware
Removing BackDoor.CYL Trojan

No comments: