Tuesday, January 27, 2009

system-processes.com Hijacker

Removing system-processes.com
Categories: Hijacker,Adware,Toolbar
When the default home page is hijacked, the browser opens to the web page set by the hijacker
instead of the user's designated home page. In some cases, the hijacker may block users from
restoring their desired home page.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.

Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\navshext.dll
[%SYSTEM%]\p.dat
[%SYSTEM%]\navshext.dll
[%SYSTEM%]\p.dat

How to detect system-processes.com:

Files:
[%SYSTEM%]\navshext.dll
[%SYSTEM%]\p.dat
[%SYSTEM%]\navshext.dll
[%SYSTEM%]\p.dat

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{c2eeb4fa-b6d6-41b9-9cfa-aba87f862bcb}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C2EEB4FA-B6D6-41b9-9CFA-ABA87F862BCB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2EEB4FA-B6D6-41b9-9CFA-ABA87F862BCB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Startup
HKEY_LOCAL_MACHINE\SOFTWARE\System Process

Registry Values:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow

Removing system-processes.com:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Goreg Trojan Information
Win32.VB.gk Trojan Symptoms

No comments: