Monday, January 26, 2009

System.Sleuth Spyware

Removing System.Sleuth
Categories: Spyware
Spyware is computer software that is installed surreptitiously on a personal computer
to intercept or take partial control over the user's interaction
with the computer, without the user's informed consent.

While the term spyware suggests software that secretly monitors the user's behavior,
the functions of spyware extend well beyond simple monitoring.

Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.

Spyware can even change computer settings, resulting in slow connection speeds,
different home pages, and loss of Internet or other programs.
In an attempt to increase the understanding of spyware, a more formal classification
of its included software types is captured under the term privacy-invasive software.

Visible Symptoms:
Files in system folders:
[%DESKTOP%]\SystemSleuth Demo.lnk
[%DESKTOP%]\SystemSleuth Demo.lnk

How to detect System.Sleuth:

Files:
[%DESKTOP%]\SystemSleuth Demo.lnk
[%DESKTOP%]\SystemSleuth Demo.lnk

Folders:
[%PROGRAMS%]\Divine Downloads Software\SystemSleuth
[%PROGRAMS%]\Divine Downloads Software\SystemSleuth Demo
[%PROGRAM_FILES%]\DDSS
[%PROGRAM_FILES%]\DDSS Demo

Registry Keys:
HKEY_CURRENT_USER\software\microsoft\installer\features\ea50a778f651be748af9cbf6c24d2981
HKEY_CURRENT_USER\software\microsoft\installer\products\ea50a778f651be748af9cbf6c24d2981
HKEY_CURRENT_USER\software\microsoft\installer\upgradecodes\6b7c89967f8073b489687cea2a1d9744
HKEY_LOCAL_MACHINE\software\microsoft\shared modules\[random]
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\upgradecodes\6b7c89967f8073b489687cea2a1d9744
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata\administrator\products\ea50a778f651be748af9cbf6c24d2981
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{877a05ae-156f-47eb-a89f-bc6f2cd49218}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\folders

Removing System.Sleuth:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Remove Carbonator Trojan
Remove SillyCER Trojan
Removing Shockdown Downloader
Vxidl.BBX Trojan Symptoms

No comments: