Tuesday, December 9, 2008

MalwareWipe Adware

Removing MalwareWipe
Categories: Adware,Ransomware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
The term ransomware is commonly used to describe such software,
although the field known as cryptovirology predates the term "ransomware".

This type of ransom attack can be accomplished by (for example) attaching
a specially crafted file/program to an e-mail message and sending this to the victim.

Visible Symptoms:
Files in system folders:
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Malware-Wipe 4.2.lnk
[%DESKTOP%]\Malware-Wipe.lnk
[%DESKTOP%]\MalwareWipe.com.lnk
[%DESKTOP%]\MalwareWipe.lnk
[%PROFILE_TEMP%]\MWLanguage.ini
[%PROFILE_TEMP%]\~nsu.tmp\Au_.exe
[%PROFILE_TEMP%]\~nsu.tmp\Bu_.exe
[%PROGRAM_FILES%]\MalwareWipe.com\MalwareWipe.com.exe
[%PROGRAM_FILES%]\MalwareWiper\MalwareWiper.url
[%PROGRAM_FILES%]\MalwareWipe\MalwareWipe.url
[%PROGRAM_FILES%]\MW\MalwareWiped 6.0\MalwareWiped 6.0.url
[%PROGRAM_FILES%]\MW\MalwareWiped 6.1\MalwareWiped 6.1.url
[%RECENT%]\MalwareWiped 6.3.url
[%STARTMENU%]\Malware-Wipe 4.2.lnk
[%STARTMENU%]\Malware-Wiped 5.2.lnk
[%STARTMENU%]\malwarewipe 4.0.lnk
[%SYSTEM%]\asgp32.dll
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Malware-Wiped 5.2.lnk
[%DESKTOP%]\Malware-Wiped.lnk
[%DESKTOP%]\malwarewipe.lnk
[%PROFILE%]\Impostazioni locali\Temp\MWLanguage.ini
[%PROFILE%]\start menu\malwarewipe 4.0.lnk
[%STARTMENU%]\MalwareWipe.com 4.2.lnk
[%DESKTOP%]\Malware-Wipe.lnk
[%DESKTOP%]\MalwareWipe.com.lnk
[%DESKTOP%]\MalwareWipe.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Malware-Wipe 4.2.lnk
[%DESKTOP%]\Malware-Wipe.lnk
[%DESKTOP%]\MalwareWipe.com.lnk
[%DESKTOP%]\MalwareWipe.lnk
[%PROFILE_TEMP%]\MWLanguage.ini
[%PROFILE_TEMP%]\~nsu.tmp\Au_.exe
[%PROFILE_TEMP%]\~nsu.tmp\Bu_.exe
[%PROGRAM_FILES%]\MalwareWipe.com\MalwareWipe.com.exe
[%PROGRAM_FILES%]\MalwareWiper\MalwareWiper.url
[%PROGRAM_FILES%]\MalwareWipe\MalwareWipe.url
[%PROGRAM_FILES%]\MW\MalwareWiped 6.0\MalwareWiped 6.0.url
[%PROGRAM_FILES%]\MW\MalwareWiped 6.1\MalwareWiped 6.1.url
[%RECENT%]\MalwareWiped 6.3.url
[%STARTMENU%]\Malware-Wipe 4.2.lnk
[%STARTMENU%]\Malware-Wiped 5.2.lnk
[%STARTMENU%]\malwarewipe 4.0.lnk
[%SYSTEM%]\asgp32.dll
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Malware-Wiped 5.2.lnk
[%DESKTOP%]\Malware-Wiped.lnk
[%DESKTOP%]\malwarewipe.lnk
[%PROFILE%]\Impostazioni locali\Temp\MWLanguage.ini
[%PROFILE%]\start menu\malwarewipe 4.0.lnk
[%STARTMENU%]\MalwareWipe.com 4.2.lnk
[%DESKTOP%]\Malware-Wipe.lnk
[%DESKTOP%]\MalwareWipe.com.lnk
[%DESKTOP%]\MalwareWipe.lnk

How to detect MalwareWipe:

Files:
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Malware-Wipe 4.2.lnk
[%DESKTOP%]\Malware-Wipe.lnk
[%DESKTOP%]\MalwareWipe.com.lnk
[%DESKTOP%]\MalwareWipe.lnk
[%PROFILE_TEMP%]\MWLanguage.ini
[%PROFILE_TEMP%]\~nsu.tmp\Au_.exe
[%PROFILE_TEMP%]\~nsu.tmp\Bu_.exe
[%PROGRAM_FILES%]\MalwareWipe.com\MalwareWipe.com.exe
[%PROGRAM_FILES%]\MalwareWiper\MalwareWiper.url
[%PROGRAM_FILES%]\MalwareWipe\MalwareWipe.url
[%PROGRAM_FILES%]\MW\MalwareWiped 6.0\MalwareWiped 6.0.url
[%PROGRAM_FILES%]\MW\MalwareWiped 6.1\MalwareWiped 6.1.url
[%RECENT%]\MalwareWiped 6.3.url
[%STARTMENU%]\Malware-Wipe 4.2.lnk
[%STARTMENU%]\Malware-Wiped 5.2.lnk
[%STARTMENU%]\malwarewipe 4.0.lnk
[%SYSTEM%]\asgp32.dll
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Malware-Wiped 5.2.lnk
[%DESKTOP%]\Malware-Wiped.lnk
[%DESKTOP%]\malwarewipe.lnk
[%PROFILE%]\Impostazioni locali\Temp\MWLanguage.ini
[%PROFILE%]\start menu\malwarewipe 4.0.lnk
[%STARTMENU%]\MalwareWipe.com 4.2.lnk
[%DESKTOP%]\Malware-Wipe.lnk
[%DESKTOP%]\MalwareWipe.com.lnk
[%DESKTOP%]\MalwareWipe.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Malware-Wipe 4.2.lnk
[%DESKTOP%]\Malware-Wipe.lnk
[%DESKTOP%]\MalwareWipe.com.lnk
[%DESKTOP%]\MalwareWipe.lnk
[%PROFILE_TEMP%]\MWLanguage.ini
[%PROFILE_TEMP%]\~nsu.tmp\Au_.exe
[%PROFILE_TEMP%]\~nsu.tmp\Bu_.exe
[%PROGRAM_FILES%]\MalwareWipe.com\MalwareWipe.com.exe
[%PROGRAM_FILES%]\MalwareWiper\MalwareWiper.url
[%PROGRAM_FILES%]\MalwareWipe\MalwareWipe.url
[%PROGRAM_FILES%]\MW\MalwareWiped 6.0\MalwareWiped 6.0.url
[%PROGRAM_FILES%]\MW\MalwareWiped 6.1\MalwareWiped 6.1.url
[%RECENT%]\MalwareWiped 6.3.url
[%STARTMENU%]\Malware-Wipe 4.2.lnk
[%STARTMENU%]\Malware-Wiped 5.2.lnk
[%STARTMENU%]\malwarewipe 4.0.lnk
[%SYSTEM%]\asgp32.dll
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Malware-Wiped 5.2.lnk
[%DESKTOP%]\Malware-Wiped.lnk
[%DESKTOP%]\malwarewipe.lnk
[%PROFILE%]\Impostazioni locali\Temp\MWLanguage.ini
[%PROFILE%]\start menu\malwarewipe 4.0.lnk
[%STARTMENU%]\MalwareWipe.com 4.2.lnk
[%DESKTOP%]\Malware-Wipe.lnk
[%DESKTOP%]\MalwareWipe.com.lnk
[%DESKTOP%]\MalwareWipe.lnk

Folders:
[%PROGRAMS%]\Malware-Wipe
[%PROGRAMS%]\Malware-Wiped
[%PROGRAMS%]\malwarewipe
[%PROGRAMS%]\MalwareWipe.com
[%PROGRAM_FILES%]\Malware-Wipe
[%PROGRAM_FILES%]\Malware-Wiped
[%PROGRAM_FILES%]\malwarewipe
[%PROGRAM_FILES%]\MalwareWipe.com

Registry Keys:
HKEY_CLASSES_ROOT\AppID\MalwareWipe.EXE
HKEY_CLASSES_ROOT\AppID\{70F17C8C-1744-41B6-9D07-575DB448DCC5}
HKEY_CLASSES_ROOT\CLSID\{035C1836-0D78-DABC-F4A7-D5D0517EE1F9}
HKEY_CLASSES_ROOT\CLSID\{9DFD0A51-6176-5770-217C-A5BCD7E6F3E2}
HKEY_CLASSES_ROOT\Interface\{16CE4DF1-88FC-4843-9134-F13D4C7BF3EE}
HKEY_CLASSES_ROOT\Interface\{17811539-2602-4840-A189-DE2F58C61038}
HKEY_CLASSES_ROOT\interface\{1d1e9b3d-5a4c-4c70-a9b4-5a19e0c625dc}
HKEY_CLASSES_ROOT\Interface\{24368407-E9FC-45CD-B403-AC9FCDB8988C}
HKEY_CLASSES_ROOT\interface\{2a34546c-c437-460a-88af-d4703a548ea9}
HKEY_CLASSES_ROOT\Interface\{36A742EE-7EB2-428C-BF53-FD44E8D24A6B}
HKEY_CLASSES_ROOT\interface\{3d9fd47c-e0b5-4005-9ade-552980d3761f}
HKEY_CLASSES_ROOT\interface\{3e5b0894-fe91-4063-bb41-d885c7691581}
HKEY_CLASSES_ROOT\Interface\{419813FC-0271-4521-8855-4AD41884CB73}
HKEY_CLASSES_ROOT\interface\{479b1aea-4414-4e43-8cbf-94bfc7c69b56}
HKEY_CLASSES_ROOT\Interface\{49AB62F1-1F76-4D45-8830-FDA6B3C3B4DE}
HKEY_CLASSES_ROOT\interface\{4a2ecc12-46ba-4c52-9749-c0faf38d507b}
HKEY_CLASSES_ROOT\interface\{4d6079cb-fd9e-46af-a896-6e8582e52827}
HKEY_CLASSES_ROOT\interface\{511a9bb1-917a-414a-88fd-3128e37032a1}
HKEY_CLASSES_ROOT\Interface\{58120ABA-BEB7-4459-8297-8CBCB2E9D795}
HKEY_CLASSES_ROOT\Interface\{631C5E80-EF5A-436A-ACEE-603844A024B4}
HKEY_CLASSES_ROOT\Interface\{6B2C0504-130C-486F-A2BB-000E53BCF48C}
HKEY_CLASSES_ROOT\Interface\{716C0242-551E-429C-A93C-955016678C4D}
HKEY_CLASSES_ROOT\Interface\{83198DC1-CB01-457A-A375-A23CC9A0055B}
HKEY_CLASSES_ROOT\interface\{8cbed98f-8ddd-4af0-a9ea-c75e10c937bc}
HKEY_CLASSES_ROOT\interface\{a44cab15-6b7e-406b-9d9b-b1c1c6ba8cdb}
HKEY_CLASSES_ROOT\interface\{a99ac77f-4de5-4aa2-810a-35fab5fc114b}
HKEY_CLASSES_ROOT\Interface\{A9EE6184-0DFA-4296-94B4-CC19111A586B}
HKEY_CLASSES_ROOT\Interface\{B09F616C-B561-4111-BD8F-D7D7E5BD0341}
HKEY_CLASSES_ROOT\Interface\{B41D39A9-1044-4A96-979B-6B43718E5680}
HKEY_CLASSES_ROOT\interface\{b74b2b6c-9b8d-47d9-872f-e83d475aaf34}
HKEY_CLASSES_ROOT\interface\{ce5ecf63-6065-4b92-8b7e-72b5042c2f25}
HKEY_CLASSES_ROOT\interface\{d4bfbb89-4bc5-4d13-8d3a-75edcc0cf50c}
HKEY_CLASSES_ROOT\Interface\{D973304C-F078-4BA4-B295-F53006FE330A}
HKEY_CLASSES_ROOT\Interface\{E72ECD09-2B43-4687-938A-4485CA0E91F7}
HKEY_CLASSES_ROOT\interface\{e86d0281-fa5a-4e36-b993-84fd87da9df1}
HKEY_CLASSES_ROOT\typelib\{177e74d6-e1d1-4d15-9d36-85399ba00729}
HKEY_CLASSES_ROOT\TypeLib\{70BD49C5-7776-46B8-B025-E5E34CED92C3}
HKEY_LOCAL_MACHINE\SOFTWARE\Malware-Wipe
HKEY_LOCAL_MACHINE\SOFTWARE\Malware-Wiped
HKEY_LOCAL_MACHINE\SOFTWARE\MalwareWipe
HKEY_LOCAL_MACHINE\software\malwarewipe.com
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Malware-Wipe.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\malwarewipe.com.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MalwareWipe.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Malware-Wipe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MalwareWipe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\malwarewipe.com
HKEY_CLASSES_ROOT\CLSID\{89923A78-1DEA-41DC-A323-88DA2DE7B5AE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{89923A78-1DEA-41DC-A323-88DA2DE7B5AE}
HKEY_CLASSES_ROOT\appid\malwarewipe.exe
HKEY_CLASSES_ROOT\appid\{70f17c8c-1744-41b6-9d07-575db448dcc5}
HKEY_CLASSES_ROOT\clsid\{035c1836-0d78-dabc-f4a7-d5d0517ee1f9}
HKEY_CLASSES_ROOT\clsid\{9dfd0a51-6176-5770-217c-a5bcd7e6f3e2}
HKEY_CLASSES_ROOT\interface\{0b4595e3d-27be-4da1-a278-ca4d904b5823}
HKEY_CLASSES_ROOT\interface\{16ce4df1-88fc-4843-9134-f13d4c7bf3ee}
HKEY_CLASSES_ROOT\interface\{17811539-2602-4840-a189-de2f58c61038}
HKEY_CLASSES_ROOT\interface\{24368407-e9fc-45cd-b403-ac9fcdb8988c}
HKEY_CLASSES_ROOT\interface\{36a742ee-7eb2-428c-bf53-fd44e8d24a6b}
HKEY_CLASSES_ROOT\interface\{419813fc-0271-4521-8855-4ad41884cb73}
HKEY_CLASSES_ROOT\interface\{49ab62f1-1f76-4d45-8830-fda6b3c3b4de}
HKEY_CLASSES_ROOT\interface\{58120aba-beb7-4459-8297-8cbcb2e9d795}
HKEY_CLASSES_ROOT\interface\{631c5e80-ef5a-436a-acee-603844a024b4}
HKEY_CLASSES_ROOT\interface\{6b2c0504-130c-486f-a2bb-000e53bcf48c}
HKEY_CLASSES_ROOT\interface\{716c0242-551e-429c-a93c-955016678c4d}
HKEY_CLASSES_ROOT\interface\{83198dc1-cb01-457a-a375-a23cc9a0055b}
HKEY_CLASSES_ROOT\interface\{a9ee6184-0dfa-4296-94b4-cc19111a586b}
HKEY_CLASSES_ROOT\interface\{b09f616c-b561-4111-bd8f-d7d7e5bd0341}
HKEY_CLASSES_ROOT\interface\{b41d39a9-1044-4a96-979b-6b43718e5680}
HKEY_CLASSES_ROOT\interface\{d973304c-f078-4ba4-b295-f53006fe330a}
HKEY_CLASSES_ROOT\interface\{e72ecd09-2b43-4687-938a-4485ca0e91f7}
HKEY_CLASSES_ROOT\typelib\{70bd49c5-7776-46b8-b025-e5e34ced92c3}
HKEY_LOCAL_MACHINE\software\malware-wipe
HKEY_LOCAL_MACHINE\software\malware-wiped
HKEY_LOCAL_MACHINE\software\malwarewipe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\malware-wipe.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\malware-wiped.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\malwarewipe.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\malware-wipe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\malware-wiped
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\malwarewipe

Registry Values:
HKEY_CLASSES_ROOT\interface\{124051bd-57ba-4614-945e-798ac91581b4}\typelib
HKEY_CLASSES_ROOT\interface\{23fd014c-455b-4497-98e9-d66ee36f1de6}\typelib
HKEY_CLASSES_ROOT\interface\{3872760b-d0d8-41e0-9a73-e6a40e30d5ac}\typelib
HKEY_CLASSES_ROOT\interface\{3dbda661-f6d1-4a43-8eaa-9a95977257f1}\typelib
HKEY_CLASSES_ROOT\interface\{525c8f79-9bef-4f76-a28c-27f1e71bce5a}\typelib
HKEY_CLASSES_ROOT\interface\{52f3adb8-d062-4622-94fb-c0374dc4a94e}\typelib
HKEY_CLASSES_ROOT\interface\{54e16983-0202-43ec-9cac-5b8f7493bb80}\typelib
HKEY_CLASSES_ROOT\interface\{73a77f6a-c2c9-4f7e-ad8b-3ec0a7877185}\typelib
HKEY_CLASSES_ROOT\interface\{8ee388cb-a53e-49ea-9e0f-9ccfa1c016b7}\typelib
HKEY_CLASSES_ROOT\interface\{939cbb64-212b-47c5-b610-38b5811e630a}\typelib
HKEY_CLASSES_ROOT\interface\{ba0017fe-829e-4460-9dea-b969ba166b85}\typelib
HKEY_CLASSES_ROOT\interface\{d56c35e6-720f-451d-a85e-e07317479f3e}\typelib
HKEY_CLASSES_ROOT\interface\{d8e3d728-0f31-4479-b936-35eed7015282}\typelib
HKEY_CLASSES_ROOT\interface\{e4245bb7-4478-4d78-b9a6-12d3ea5befa6}\typelib
HKEY_CLASSES_ROOT\interface\{e4d111a5-a3d5-4097-bbe6-2edbc0277d61}\typelib
HKEY_CLASSES_ROOT\interface\{edf9f7f2-c764-46d6-b5a8-5a87938f9793}\typelib
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_CLASSES_ROOT\appid
HKEY_CLASSES_ROOT\interface\{124051bd-57ba-4614-945e-798ac91581b4}\typelib
HKEY_CLASSES_ROOT\interface\{23fd014c-455b-4497-98e9-d66ee36f1de6}\typelib
HKEY_CLASSES_ROOT\interface\{3872760b-d0d8-41e0-9a73-e6a40e30d5ac}\typelib
HKEY_CLASSES_ROOT\interface\{3dbda661-f6d1-4a43-8eaa-9a95977257f1}\typelib
HKEY_CLASSES_ROOT\interface\{525c8f79-9bef-4f76-a28c-27f1e71bce5a}\typelib
HKEY_CLASSES_ROOT\interface\{52f3adb8-d062-4622-94fb-c0374dc4a94e}\typelib
HKEY_CLASSES_ROOT\interface\{54e16983-0202-43ec-9cac-5b8f7493bb80}\typelib
HKEY_CLASSES_ROOT\interface\{73a77f6a-c2c9-4f7e-ad8b-3ec0a7877185}\typelib
HKEY_CLASSES_ROOT\interface\{8ee388cb-a53e-49ea-9e0f-9ccfa1c016b7}\typelib
HKEY_CLASSES_ROOT\interface\{939cbb64-212b-47c5-b610-38b5811e630a}\typelib
HKEY_CLASSES_ROOT\interface\{ba0017fe-829e-4460-9dea-b969ba166b85}\typelib
HKEY_CLASSES_ROOT\interface\{d56c35e6-720f-451d-a85e-e07317479f3e}\typelib
HKEY_CLASSES_ROOT\interface\{d8e3d728-0f31-4479-b936-35eed7015282}\typelib
HKEY_CLASSES_ROOT\interface\{e4245bb7-4478-4d78-b9a6-12d3ea5befa6}\typelib
HKEY_CLASSES_ROOT\interface\{e4d111a5-a3d5-4097-bbe6-2edbc0277d61}\typelib
HKEY_CLASSES_ROOT\interface\{edf9f7f2-c764-46d6-b5a8-5a87938f9793}\typelib
HKEY_CURRENT_USER\software\microsoft\windows\shellnoroam\muicache
HKEY_CURRENT_USER\software\microsoft\windows\shellnoroam\muicache
HKEY_CURRENT_USER\software\microsoft\windows\shellnoroam\muicache\[%DESKTOPDIRECTORY%]
HKEY_CURRENT_USER\software\microsoft\windows\shellnoroam\muicache\[%PROGRAM_FILES%]\malware-wiped
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_CURRENT_USER\software\microsoft\windows\shellnoroam\muicache
HKEY_CURRENT_USER\software\microsoft\windows\shellnoroam\muicache\[%DESKTOP%]
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%DESKTOP%]
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%LOCAL_APPDATA%]\microsoft\internet explorer\quick launch
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAMS%]
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAMS%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAMS%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAMS%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAM_FILES%]
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAM_FILES%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAM_FILES%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAM_FILES%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAM_FILES%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAM_FILES%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAM_FILES%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAM_FILES%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAM_FILES%]\malware-wiped
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%PROGRAM_FILES%]\malware-wiped\lang
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%WINDOWS%]\prefetch
HKEY_LOCAL_MACHINE\system\controlset001\services\kmxfile\createdfilestimestamp\[%WINDOWS%]\prefetch

Removing MalwareWipe:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing Mitglieder.Q Trojan
Remove SillyDl.ABB Downloader
Remove Vxidl.AIB Trojan
Remove Pigeon.APO Trojan
Remove Dynamic.Desktop.Media Trojan

No comments: