Saturday, December 6, 2008

Adware.Baidu Trojan

Removing Adware.Baidu
Categories: Trojan,Adware,Toolbar
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.

Adware.Baidu Also known as:

[McAfee]Adware-Baidu;
[Panda]Adware/6781ToolBar

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\advport.dll
[%SYSTEM%]\wbem\ocmor.dll
[%SYSTEM%]\agyst.dll
[%SYSTEM%]\lqbag.dll
[%SYSTEM%]\wbem\kblfu.dll
[%SYSTEM%]\wbem\vicqr.dll
[%WINDOWS%]\toolsp.exe
[%SYSTEM%]\advport.dll
[%SYSTEM%]\wbem\ocmor.dll
[%SYSTEM%]\agyst.dll
[%SYSTEM%]\lqbag.dll
[%SYSTEM%]\wbem\kblfu.dll
[%SYSTEM%]\wbem\vicqr.dll
[%WINDOWS%]\toolsp.exe

How to detect Adware.Baidu:

Files:
[%SYSTEM%]\advport.dll
[%SYSTEM%]\wbem\ocmor.dll
[%SYSTEM%]\agyst.dll
[%SYSTEM%]\lqbag.dll
[%SYSTEM%]\wbem\kblfu.dll
[%SYSTEM%]\wbem\vicqr.dll
[%WINDOWS%]\toolsp.exe
[%SYSTEM%]\advport.dll
[%SYSTEM%]\wbem\ocmor.dll
[%SYSTEM%]\agyst.dll
[%SYSTEM%]\lqbag.dll
[%SYSTEM%]\wbem\kblfu.dll
[%SYSTEM%]\wbem\vicqr.dll
[%WINDOWS%]\toolsp.exe

Folders:
[%PROGRAM_FILES%]\superutilbar
[%PROGRAM_FILES%]\supertoolbar

Registry Keys:
HKEY_CLASSES_ROOT\6781.toolbar
HKEY_CLASSES_ROOT\6781.toolbar.1
HKEY_CLASSES_ROOT\6781.toolbarloader
HKEY_CLASSES_ROOT\6781.toolbarloader.1
HKEY_CLASSES_ROOT\CLSID\{03465FF5-00AE-411A-9C34-960ED566EC03}
HKEY_CLASSES_ROOT\CLSID\{6CFD436C-7AAD-4E50-992F-C0C87A94CAD2}
HKEY_CLASSES_ROOT\typelib\{03d0c547-ebad-43d9-8b57-de16e7a93b52}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CFD436C-7AAD-4E50-992F-C0C87A94CAD2}
HKEY_CLASSES_ROOT\clsid\{03465ff5-00ae-411a-9c34-960ed566ec03}
HKEY_CLASSES_ROOT\clsid\{6cfd436c-7aad-4e50-992f-c0c87a94cad2}
HKEY_LOCAL_MACHINE\software\03d0c547-ebad-43d9-8b57-de16e7a93b52
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6cfd436c-7aad-4e50-992f-c0c87a94cad2}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ʵÓÃËÑË÷¹¤¾ßÌõ

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar

Removing Adware.Baidu:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
BlueAngel Trojan Information
Borlander Downloader Information
Bancos.FVL Trojan Information
VirusLocker Ransomware Symptoms
SillyDl.BBT Trojan Removal instruction

No comments: