Monday, December 1, 2008

Dubfouf Adware

Removing Dubfouf
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


Dubfouf Also known as:

[Kaspersky]Trojan-Downloader.Win32.CWS.am,Trojan.Win32.LowZones.ek;
[Other]Trojan.KillAV

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\ServicePackFiles\mm1417.exe
[%WINDOWS%]\ServicePackFiles\mm182.exe
[%WINDOWS%]\ServicePackFiles\mm2570.exe
[%WINDOWS%]\ServicePackFiles\mm2715.exe
[%WINDOWS%]\ServicePackFiles\mm2840.exe
[%WINDOWS%]\ServicePackFiles\mm2919.exe
[%WINDOWS%]\ServicePackFiles\mm3200.exe
[%WINDOWS%]\ServicePackFiles\mm372.exe
[%WINDOWS%]\ServicePackFiles\mm4206.exe
[%WINDOWS%]\ServicePackFiles\mm535.exe
[%WINDOWS%]\ServicePackFiles\mm5467.exe
[%WINDOWS%]\ServicePackFiles\mm5525.exe
[%WINDOWS%]\ServicePackFiles\mm6911.exe
[%WINDOWS%]\ServicePackFiles\mm7981.exe
[%WINDOWS%]\ServicePackFiles\mm8126.exe
[%WINDOWS%]\ServicePackFiles\mm872.exe
[%WINDOWS%]\ServicePackFiles\services.exe
[%WINDOWS%]\ServicePackFiles\mm1417.exe
[%WINDOWS%]\ServicePackFiles\mm182.exe
[%WINDOWS%]\ServicePackFiles\mm2570.exe
[%WINDOWS%]\ServicePackFiles\mm2715.exe
[%WINDOWS%]\ServicePackFiles\mm2840.exe
[%WINDOWS%]\ServicePackFiles\mm2919.exe
[%WINDOWS%]\ServicePackFiles\mm3200.exe
[%WINDOWS%]\ServicePackFiles\mm372.exe
[%WINDOWS%]\ServicePackFiles\mm4206.exe
[%WINDOWS%]\ServicePackFiles\mm535.exe
[%WINDOWS%]\ServicePackFiles\mm5467.exe
[%WINDOWS%]\ServicePackFiles\mm5525.exe
[%WINDOWS%]\ServicePackFiles\mm6911.exe
[%WINDOWS%]\ServicePackFiles\mm7981.exe
[%WINDOWS%]\ServicePackFiles\mm8126.exe
[%WINDOWS%]\ServicePackFiles\mm872.exe
[%WINDOWS%]\ServicePackFiles\services.exe

How to detect Dubfouf:

Files:
[%WINDOWS%]\ServicePackFiles\mm1417.exe
[%WINDOWS%]\ServicePackFiles\mm182.exe
[%WINDOWS%]\ServicePackFiles\mm2570.exe
[%WINDOWS%]\ServicePackFiles\mm2715.exe
[%WINDOWS%]\ServicePackFiles\mm2840.exe
[%WINDOWS%]\ServicePackFiles\mm2919.exe
[%WINDOWS%]\ServicePackFiles\mm3200.exe
[%WINDOWS%]\ServicePackFiles\mm372.exe
[%WINDOWS%]\ServicePackFiles\mm4206.exe
[%WINDOWS%]\ServicePackFiles\mm535.exe
[%WINDOWS%]\ServicePackFiles\mm5467.exe
[%WINDOWS%]\ServicePackFiles\mm5525.exe
[%WINDOWS%]\ServicePackFiles\mm6911.exe
[%WINDOWS%]\ServicePackFiles\mm7981.exe
[%WINDOWS%]\ServicePackFiles\mm8126.exe
[%WINDOWS%]\ServicePackFiles\mm872.exe
[%WINDOWS%]\ServicePackFiles\services.exe
[%WINDOWS%]\ServicePackFiles\mm1417.exe
[%WINDOWS%]\ServicePackFiles\mm182.exe
[%WINDOWS%]\ServicePackFiles\mm2570.exe
[%WINDOWS%]\ServicePackFiles\mm2715.exe
[%WINDOWS%]\ServicePackFiles\mm2840.exe
[%WINDOWS%]\ServicePackFiles\mm2919.exe
[%WINDOWS%]\ServicePackFiles\mm3200.exe
[%WINDOWS%]\ServicePackFiles\mm372.exe
[%WINDOWS%]\ServicePackFiles\mm4206.exe
[%WINDOWS%]\ServicePackFiles\mm535.exe
[%WINDOWS%]\ServicePackFiles\mm5467.exe
[%WINDOWS%]\ServicePackFiles\mm5525.exe
[%WINDOWS%]\ServicePackFiles\mm6911.exe
[%WINDOWS%]\ServicePackFiles\mm7981.exe
[%WINDOWS%]\ServicePackFiles\mm8126.exe
[%WINDOWS%]\ServicePackFiles\mm872.exe
[%WINDOWS%]\ServicePackFiles\services.exe

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing Dubfouf:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Miskur Trojan Symptoms
Bancos.HLM Trojan Cleaner
Remove Biphist Trojan

No comments: