<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1481876143551850049</id><updated>2011-04-21T17:47:46.502-07:00</updated><title type='text'>Malware Info</title><subtitle type='html'>Here you can found some information about malware, virus, trojan, etc. How to remove, how to protect, how to identify.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default?start-index=101&amp;max-results=100'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1952</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3241132932855114848</id><published>2009-02-04T01:55:00.001-08:00</published><updated>2009-02-04T01:55:53.711-08:00</updated><title type='text'>Virtumonde.by Adware</title><content type='html'>Removing Virtumonde.by &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\efcccbb.dll&lt;br/&gt;[%SYSTEM%]\efcccbb.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Virtumonde.by:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\efcccbb.dll&lt;br/&gt;[%SYSTEM%]\efcccbb.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6b69e170-f59b-4897-b51c-3bb214d099ae} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Virtumonde.by:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-2411.blogspot.com/2009/02/sillydlcey-trojan.html"&gt;Removing SillyDl.CEY Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://protection-protect-details.blogspot.com/2009/01/nikademus-trojan.html"&gt;Nikademus Trojan Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3241132932855114848?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3241132932855114848/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3241132932855114848' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3241132932855114848'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3241132932855114848'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/virtumondeby-adware.html' title='Virtumonde.by Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7989722344549032425</id><published>2009-02-04T00:23:00.001-08:00</published><updated>2009-02-04T00:23:46.694-08:00</updated><title type='text'>CRS.Gate Backdoor</title><content type='html'>Removing CRS.Gate &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Backdoor,RAT&lt;br/&gt;&lt;em&gt;&lt;strong&gt;Backdoors are the most dangerous type of Trojans&lt;/strong&gt; and the most popular.&lt;br /&gt;&lt;strong&gt;Backdoors open infected machines&lt;/strong&gt; to external control via Internet.&lt;br /&gt;They function in the same way as legal remote administration programs used by system administrators.&lt;br /&gt;This makes them difficult to detect.&lt;br/&gt;&lt;br /&gt;&lt;strong&gt;Backdoors&lt;/strong&gt; are installed and launched without the consent of the user of computer.&lt;br /&gt;Often the backdoor will not be visible in the log of active programs.&lt;br/&gt;&lt;br /&gt;Once a backdoor has been successfully launched, the computer is wide open.&lt;br /&gt;Backdoor functions can include:&lt;br/&gt;&lt;br /&gt;    &lt;ul&gt;&lt;br /&gt;    &lt;li&gt; Launching/ deleting files&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Sending/ receiving files&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Deleting data&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Displaying notification&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Rebooting the machine&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Executing files&lt;/li&gt;&lt;br /&gt;    &lt;/ul&gt;&lt;br /&gt;&lt;br/&gt;&lt;br /&gt;&lt;strong&gt;Backdoors are used by virus writers to detect and download confidential information&lt;/strong&gt;,&lt;br /&gt;execute malicious code, destroy data, include the machine in bot networks and so forth.&lt;br /&gt;Backdoors combine the functionality of most other types of  in one package.&lt;br/&gt;&lt;br /&gt;Backdoors have one especially dangerous sub-class: variants that can propagate like worms. &lt;br/&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;CRS.Gate Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Backdoor.CRS-Gate;&lt;br/&gt;[Panda]Backdoor Program,Bck/CRS-Gate;&lt;br/&gt;[Computer Associates]Backdoor/CRS-Gate!Server&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\regsys32.dll&lt;br/&gt;[%WINDOWS%]\system\regsys32.exe&lt;br/&gt;[%WINDOWS%]\system\regsys32.dll&lt;br/&gt;[%WINDOWS%]\system\regsys32.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect CRS.Gate:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\regsys32.dll&lt;br/&gt;[%WINDOWS%]\system\regsys32.exe&lt;br/&gt;[%WINDOWS%]\system\regsys32.dll&lt;br/&gt;[%WINDOWS%]\system\regsys32.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing CRS.Gate:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://info-blog-protect.blogspot.com/2009/02/netadministrator-backdoor.html"&gt;Net.Administrator Backdoor Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://protect-kill-infections.blogspot.com/2009/01/countomatcom-tracking-cookie.html"&gt;countomat.com Tracking Cookie Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-4832.blogspot.com/2009/01/pcremotecontrol-rat.html"&gt;PC.Remote.Control RAT Information&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7989722344549032425?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7989722344549032425/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7989722344549032425' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7989722344549032425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7989722344549032425'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/crsgate-backdoor.html' title='CRS.Gate Backdoor'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6573207292074294840</id><published>2009-02-04T00:15:00.001-08:00</published><updated>2009-02-04T00:15:42.676-08:00</updated><title type='text'>Alureon Trojan</title><content type='html'>Removing Alureon &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,BHO,Hijacker,Downloader&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;&lt;strong&gt;BHO (Browser Helper Object) Trojan&lt;/strong&gt;.&lt;br /&gt;The BHO waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br /&gt;The method of network transport used by the attacker makes this Trojan unique.&lt;br /&gt;Typically, keyloggers of this type will send the stolen information back to the attacker via email&lt;br /&gt;or HTTP POST, which can appear suspicious.&lt;br /&gt;Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into&lt;br /&gt;the data section of an ICMP ping packet." explained the company.&lt;br/&gt;A desktop hijacker replaces the desktop wallpaper with advertising&lt;br /&gt;for products and services on the desktop.&lt;br/&gt;Trojans-downloaders downloads and installs new malware or adware on the computer.&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Alureon Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Trojan-Downloader.Win32.Small.den,Trojan.Win32.DNSChanger.ef,Trojan.Win32.DNSChanger.fc,Trojan.Win32.DNSChanger.ge,Trojan.Win32.Agent.r,Trojan-Downloader.Win32.Murlo.d,Trojan.Win32.DNSChanger.iq,Trojan.Win32.DNSChanger.iu,Trojan.Win32.DNSChanger.abk,Trojan.Win32.DNSChanger.abf,Trojan.Win32.DNSChanger.abe;&lt;br/&gt;[McAfee]DNSChanger.a,DNSChanger.gen;&lt;br/&gt;[F-Prot]W32/Trojan2.HSQ (exact),W32/Trojan2.HSG (exact);&lt;br/&gt;[Panda]Adware/Oner,Trojan Horse;&lt;br/&gt;[Computer Associates]Win32.Alureon.B,Win32/Alureon.B!DLL!Trojan,Win32.Alureon.A,Win32/Alureon.A!DLL!Trojan,Win32/Alureon.A.20285!Trojan;&lt;br/&gt;[Other]Win32.Alueon.AU,Win32.Alureon.AV,Trojan.Win32.DNSChanger.ef,Win32/Alureon.T,Win32.Alureon.AX,Win32/Alureon.AZ,Win32/Alureon.BN,Win32/Alureon.BO,Win32/Alureon.BP,Win32/Alureon.BQ,Win32/Alureon.Y,W32/Downloader.NNL,Win32/Alureon.BX,Win32/Alureon.CE,Win32/Alureon!generic,Troj/RuinDl-Gen,Win32/Alureon.A,Win32/Alureon.CH,Trujan.Flush.K,Win32/Alureon.CI,WIn32/Alureon.CJ,Win32/Alureon.CQ,Win32/Alureon.CR,Trojan.Emcodec,Win32/Alureon.CS,Trojan.Zlob,Trojan.Flush.L,DNSChanger.gen9,Troj/Zlobar-Fam,Troj/Zlob-ADO,Win32/Alureon.DB,Trojan.Flush.G,Win32/Alureon.DE,Win32/Alureon.EM&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%LOCAL_APPDATA%]\Temp\~nsu.tmp\Au_.exe&lt;br/&gt;[%SYSTEM%]\winnet.dll&lt;br/&gt;[%WINDOWS%]\image.dll&lt;br/&gt;[%DESKTOP%]\asd3.dll&lt;br/&gt;[%DESKTOP%]\playercodec1000.exe&lt;br/&gt;[%DESKTOP%]\tbar.exe&lt;br/&gt;[%FAVORITES%]\!!! exclusive youngest porn !!!.url&lt;br/&gt;[%FAVORITES%]\censored youngest porn.url&lt;br/&gt;[%FAVORITES%]\free hidden cams world.url&lt;br/&gt;[%FAVORITES%]\free spy cam.url&lt;br/&gt;[%FAVORITES%]\free web cams chats.url&lt;br/&gt;[%FAVORITES%]\free xxx pics &amp; movies.url&lt;br/&gt;[%FAVORITES%]\fresh xxx pics &amp; movie.url&lt;br/&gt;[%FAVORITES%]\get this 4 free.url&lt;br/&gt;[%FAVORITES%]\super xxx pics.url&lt;br/&gt;[%FAVORITES%]\young masha sucking huge dick until her lips teared open.url&lt;br/&gt;[%FAVORITES%]\~ fully categories porn database. enjoy!.url&lt;br/&gt;[%FAVORITES%]\~ new porn pics everyday.url&lt;br/&gt;[%PROGRAMS%]\FreeVideo\Uninstall.lnk&lt;br/&gt;[%SYSTEM%]\dmcal.exe&lt;br/&gt;[%SYSTEM%]\dmfap.exe&lt;br/&gt;[%SYSTEM%]\dmfsg.exe&lt;br/&gt;[%SYSTEM%]\dmrfp.exe&lt;br/&gt;[%SYSTEM%]\dmthp.exe&lt;br/&gt;[%SYSTEM%]\kddmx.exe&lt;br/&gt;[%SYSTEM%]\kdoxr.exe&lt;br/&gt;[%SYSTEM%]\mlwlr.exe&lt;br/&gt;[%SYSTEM%]\msmk.dll&lt;br/&gt;[%SYSTEM%]\nzbxn.exe&lt;br/&gt;[%SYSTEM%]\sysobjwertb.dll&lt;br/&gt;[%SYSTEM%]\wmstrbum.exe&lt;br/&gt;[%WINDOWS%]\cracrwinz.exe&lt;br/&gt;[%WINDOWS%]\msew\msew32.dll&lt;br/&gt;[%WINDOWS%]\msew\msiesh.dll&lt;br/&gt;[%WINDOWS%]\msew\mssearch.dll&lt;br/&gt;[%WINDOWS%]\tromomwin32.exe&lt;br/&gt;[%LOCAL_APPDATA%]\Temp\~nsu.tmp\Au_.exe&lt;br/&gt;[%SYSTEM%]\winnet.dll&lt;br/&gt;[%WINDOWS%]\image.dll&lt;br/&gt;[%DESKTOP%]\asd3.dll&lt;br/&gt;[%DESKTOP%]\playercodec1000.exe&lt;br/&gt;[%DESKTOP%]\tbar.exe&lt;br/&gt;[%FAVORITES%]\!!! exclusive youngest porn !!!.url&lt;br/&gt;[%FAVORITES%]\censored youngest porn.url&lt;br/&gt;[%FAVORITES%]\free hidden cams world.url&lt;br/&gt;[%FAVORITES%]\free spy cam.url&lt;br/&gt;[%FAVORITES%]\free web cams chats.url&lt;br/&gt;[%FAVORITES%]\free xxx pics &amp; movies.url&lt;br/&gt;[%FAVORITES%]\fresh xxx pics &amp; movie.url&lt;br/&gt;[%FAVORITES%]\get this 4 free.url&lt;br/&gt;[%FAVORITES%]\super xxx pics.url&lt;br/&gt;[%FAVORITES%]\young masha sucking huge dick until her lips teared open.url&lt;br/&gt;[%FAVORITES%]\~ fully categories porn database. enjoy!.url&lt;br/&gt;[%FAVORITES%]\~ new porn pics everyday.url&lt;br/&gt;[%PROGRAMS%]\FreeVideo\Uninstall.lnk&lt;br/&gt;[%SYSTEM%]\dmcal.exe&lt;br/&gt;[%SYSTEM%]\dmfap.exe&lt;br/&gt;[%SYSTEM%]\dmfsg.exe&lt;br/&gt;[%SYSTEM%]\dmrfp.exe&lt;br/&gt;[%SYSTEM%]\dmthp.exe&lt;br/&gt;[%SYSTEM%]\kddmx.exe&lt;br/&gt;[%SYSTEM%]\kdoxr.exe&lt;br/&gt;[%SYSTEM%]\mlwlr.exe&lt;br/&gt;[%SYSTEM%]\msmk.dll&lt;br/&gt;[%SYSTEM%]\nzbxn.exe&lt;br/&gt;[%SYSTEM%]\sysobjwertb.dll&lt;br/&gt;[%SYSTEM%]\wmstrbum.exe&lt;br/&gt;[%WINDOWS%]\cracrwinz.exe&lt;br/&gt;[%WINDOWS%]\msew\msew32.dll&lt;br/&gt;[%WINDOWS%]\msew\msiesh.dll&lt;br/&gt;[%WINDOWS%]\msew\mssearch.dll&lt;br/&gt;[%WINDOWS%]\tromomwin32.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Alureon:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%LOCAL_APPDATA%]\Temp\~nsu.tmp\Au_.exe&lt;br/&gt;[%SYSTEM%]\winnet.dll&lt;br/&gt;[%WINDOWS%]\image.dll&lt;br/&gt;[%DESKTOP%]\asd3.dll&lt;br/&gt;[%DESKTOP%]\playercodec1000.exe&lt;br/&gt;[%DESKTOP%]\tbar.exe&lt;br/&gt;[%FAVORITES%]\!!! exclusive youngest porn !!!.url&lt;br/&gt;[%FAVORITES%]\censored youngest porn.url&lt;br/&gt;[%FAVORITES%]\free hidden cams world.url&lt;br/&gt;[%FAVORITES%]\free spy cam.url&lt;br/&gt;[%FAVORITES%]\free web cams chats.url&lt;br/&gt;[%FAVORITES%]\free xxx pics &amp; movies.url&lt;br/&gt;[%FAVORITES%]\fresh xxx pics &amp; movie.url&lt;br/&gt;[%FAVORITES%]\get this 4 free.url&lt;br/&gt;[%FAVORITES%]\super xxx pics.url&lt;br/&gt;[%FAVORITES%]\young masha sucking huge dick until her lips teared open.url&lt;br/&gt;[%FAVORITES%]\~ fully categories porn database. enjoy!.url&lt;br/&gt;[%FAVORITES%]\~ new porn pics everyday.url&lt;br/&gt;[%PROGRAMS%]\FreeVideo\Uninstall.lnk&lt;br/&gt;[%SYSTEM%]\dmcal.exe&lt;br/&gt;[%SYSTEM%]\dmfap.exe&lt;br/&gt;[%SYSTEM%]\dmfsg.exe&lt;br/&gt;[%SYSTEM%]\dmrfp.exe&lt;br/&gt;[%SYSTEM%]\dmthp.exe&lt;br/&gt;[%SYSTEM%]\kddmx.exe&lt;br/&gt;[%SYSTEM%]\kdoxr.exe&lt;br/&gt;[%SYSTEM%]\mlwlr.exe&lt;br/&gt;[%SYSTEM%]\msmk.dll&lt;br/&gt;[%SYSTEM%]\nzbxn.exe&lt;br/&gt;[%SYSTEM%]\sysobjwertb.dll&lt;br/&gt;[%SYSTEM%]\wmstrbum.exe&lt;br/&gt;[%WINDOWS%]\cracrwinz.exe&lt;br/&gt;[%WINDOWS%]\msew\msew32.dll&lt;br/&gt;[%WINDOWS%]\msew\msiesh.dll&lt;br/&gt;[%WINDOWS%]\msew\mssearch.dll&lt;br/&gt;[%WINDOWS%]\tromomwin32.exe&lt;br/&gt;[%LOCAL_APPDATA%]\Temp\~nsu.tmp\Au_.exe&lt;br/&gt;[%SYSTEM%]\winnet.dll&lt;br/&gt;[%WINDOWS%]\image.dll&lt;br/&gt;[%DESKTOP%]\asd3.dll&lt;br/&gt;[%DESKTOP%]\playercodec1000.exe&lt;br/&gt;[%DESKTOP%]\tbar.exe&lt;br/&gt;[%FAVORITES%]\!!! exclusive youngest porn !!!.url&lt;br/&gt;[%FAVORITES%]\censored youngest porn.url&lt;br/&gt;[%FAVORITES%]\free hidden cams world.url&lt;br/&gt;[%FAVORITES%]\free spy cam.url&lt;br/&gt;[%FAVORITES%]\free web cams chats.url&lt;br/&gt;[%FAVORITES%]\free xxx pics &amp; movies.url&lt;br/&gt;[%FAVORITES%]\fresh xxx pics &amp; movie.url&lt;br/&gt;[%FAVORITES%]\get this 4 free.url&lt;br/&gt;[%FAVORITES%]\super xxx pics.url&lt;br/&gt;[%FAVORITES%]\young masha sucking huge dick until her lips teared open.url&lt;br/&gt;[%FAVORITES%]\~ fully categories porn database. enjoy!.url&lt;br/&gt;[%FAVORITES%]\~ new porn pics everyday.url&lt;br/&gt;[%PROGRAMS%]\FreeVideo\Uninstall.lnk&lt;br/&gt;[%SYSTEM%]\dmcal.exe&lt;br/&gt;[%SYSTEM%]\dmfap.exe&lt;br/&gt;[%SYSTEM%]\dmfsg.exe&lt;br/&gt;[%SYSTEM%]\dmrfp.exe&lt;br/&gt;[%SYSTEM%]\dmthp.exe&lt;br/&gt;[%SYSTEM%]\kddmx.exe&lt;br/&gt;[%SYSTEM%]\kdoxr.exe&lt;br/&gt;[%SYSTEM%]\mlwlr.exe&lt;br/&gt;[%SYSTEM%]\msmk.dll&lt;br/&gt;[%SYSTEM%]\nzbxn.exe&lt;br/&gt;[%SYSTEM%]\sysobjwertb.dll&lt;br/&gt;[%SYSTEM%]\wmstrbum.exe&lt;br/&gt;[%WINDOWS%]\cracrwinz.exe&lt;br/&gt;[%WINDOWS%]\msew\msew32.dll&lt;br/&gt;[%WINDOWS%]\msew\msiesh.dll&lt;br/&gt;[%WINDOWS%]\msew\mssearch.dll&lt;br/&gt;[%WINDOWS%]\tromomwin32.exe &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\HQvideo&lt;br/&gt;[%PROGRAMS%]\MovieBox&lt;br/&gt;[%PROGRAMS%]\PornoPlayer&lt;br/&gt;[%PROGRAMS%]\VideoBox&lt;br/&gt;[%PROGRAMS%]\VideoPlugin&lt;br/&gt;[%PROGRAMS%]\XXXAccess&lt;br/&gt;[%PROGRAMS%]\XXXPlugin&lt;br/&gt;[%PROGRAM_FILES%]\FreeVideo&lt;br/&gt;[%PROGRAM_FILES%]\HQvideo&lt;br/&gt;[%PROGRAM_FILES%]\MovieBox&lt;br/&gt;[%PROGRAM_FILES%]\PornoPlayer&lt;br/&gt;[%PROGRAM_FILES%]\VideoBox&lt;br/&gt;[%PROGRAM_FILES%]\VideoPlugin&lt;br/&gt;[%PROGRAM_FILES%]\XXXAccess&lt;br/&gt;[%PROGRAM_FILES%]\XXXPlugin&lt;br/&gt;[%PROGRAMS%]\SelectiveAdmission&lt;br/&gt;[%PROGRAM_FILES%]\SelectiveAdmission&lt;br/&gt;[%PROGRAM_FILES%]\WinMsg &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\freevideo&lt;br/&gt;HKEY_CLASSES_ROOT\HQvideo&lt;br/&gt;HKEY_CLASSES_ROOT\MovieBox&lt;br/&gt;HKEY_CLASSES_ROOT\pornoplayer&lt;br/&gt;HKEY_CLASSES_ROOT\VideoBox&lt;br/&gt;HKEY_CLASSES_ROOT\videoplugin&lt;br/&gt;HKEY_CLASSES_ROOT\xxxaccess&lt;br/&gt;HKEY_CLASSES_ROOT\xxxplugin&lt;br/&gt;HKEY_CURRENT_USER\software\freevideo&lt;br/&gt;HKEY_CURRENT_USER\Software\HQvideo&lt;br/&gt;HKEY_CURRENT_USER\Software\MovieBox&lt;br/&gt;HKEY_CURRENT_USER\software\pornoplayer&lt;br/&gt;HKEY_CURRENT_USER\Software\VideoBox&lt;br/&gt;HKEY_CURRENT_USER\software\videoplugin&lt;br/&gt;HKEY_CURRENT_USER\software\xxxaccess&lt;br/&gt;HKEY_CURRENT_USER\software\xxxplugin&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeVideo&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoBox&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\videoplugin&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xxxplugin&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{85cbfde0-b26b-4ee5-bd3c-4de111de763e}&lt;br/&gt;HKEY_CLASSES_ROOT\hqvideo&lt;br/&gt;HKEY_CLASSES_ROOT\moviebox&lt;br/&gt;HKEY_CLASSES_ROOT\selectiveadmission&lt;br/&gt;HKEY_CLASSES_ROOT\videobox&lt;br/&gt;HKEY_CURRENT_USER\software\hqvideo&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\_r&lt;br/&gt;HKEY_CURRENT_USER\software\moviebox&lt;br/&gt;HKEY_CURRENT_USER\software\selectiveadmission&lt;br/&gt;HKEY_CURRENT_USER\software\videobox&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversino\uninstall\moviebox&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversino\uninstall\pornoplayer&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{85cbfde0-b26b-4ee5-bd3c-4de111de763e}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\freevideo&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\selectiveadmission&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\videobox&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xxxaccess&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\windows management service &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\searchbar&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{9c830788-3ef6-4c70-8fce-1e890dc53533}, dhcpnameserver=85.255.115.42&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{9c830788-3ef6-4c70-8fce-1e890dc53533}, dhcpnameserver=85.255.115.82&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{9c830788-3ef6-4c70-8fce-1e890dc53533}, nameserver=85.255.115.82 &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Alureon:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-05.blogspot.com/2009/01/spytector-spyware.html"&gt;Spytector Spyware Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-77.blogspot.com/2009/01/jeem-trojan.html"&gt;Jeem Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://keylogger-listing-protection.blogspot.com/2009/01/win32sdbotbackdoorservervari-worm.html"&gt;Win32.SDBot!Backdoor!Server.Vari Worm Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-52.blogspot.com/2009/01/zapchastbl-trojan.html"&gt;Remove Zapchast.bl Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6573207292074294840?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6573207292074294840/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6573207292074294840' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6573207292074294840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6573207292074294840'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/alureon-trojan.html' title='Alureon Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-1624342601983337402</id><published>2009-02-03T23:39:00.001-08:00</published><updated>2009-02-03T23:39:35.128-08:00</updated><title type='text'>Starware.Recipe Hijacker</title><content type='html'>Removing Starware.Recipe &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Hijacker&lt;br/&gt;&lt;em&gt;&lt;strong&gt;Hijackers are software programs that modify users' default browser home page&lt;/strong&gt;,&lt;br /&gt;search settings, error page settings, or desktop wallpaper without adequate notice, disclosure,&lt;br /&gt;or user consent.&lt;br/&gt;&lt;br /&gt;When the default home page is hijacked, the browser opens to the web page set by the hijacker&lt;br /&gt;instead of the user's designated home page. In some cases, the hijacker may block users from&lt;br /&gt;restoring their desired home page.&lt;br/&gt;&lt;br /&gt;A &lt;strong&gt;search hijacker&lt;/strong&gt; redirects search results to other pages and may&lt;br /&gt;transmit search and browsing data to unknown servers. An error page hijacker directs&lt;br /&gt;the browser to another page, usually an advertising page, instead of the usual error&lt;br /&gt;page when the requested URL is not found.&lt;br/&gt;&lt;br /&gt;A &lt;strong&gt;desktop hijacker&lt;/strong&gt; replaces the desktop wallpaper with advertising&lt;br /&gt;for products and services on the desktop.&lt;br/&gt;&lt;br /&gt;Hijackers take control of various parts of your web browser, including your home page,&lt;br /&gt;search pages, and search bar. They may also redirect you to certain sites should you&lt;br /&gt;mistype an address or prevent you from going to a website they would rather you not,&lt;br /&gt;such as sites that combat malware. Some will even redirect you to their own search engine&lt;br /&gt;when you attempt a search. NB: hijackers almost exclusively target Internet Explorer.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\Starware316\bin\Starware316.dll&lt;br/&gt;[%PROGRAM_FILES%]\Starware316\bin\Starware316.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Starware.Recipe:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\Starware316\bin\Starware316.dll&lt;br/&gt;[%PROGRAM_FILES%]\Starware316\bin\Starware316.dll &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%APPDATA%]\Starware337&lt;br/&gt;[%PROGRAM_FILES%]\Starware337 &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{1962c5bc-e475-465b-823b-133e711bceb9}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{ab3dfa03-f743-4302-81dd-c370bffeca23}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{e550dc77-ef3b-474f-b59c-b3e2aa1fa6a5}&lt;br/&gt;HKEY_CURRENT_USER\software\starware337&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{1962c5bc-e475-465b-823b-133e711bceb9}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Starware.Recipe:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-19.blogspot.com/2009/01/vxskey-trojan.html"&gt;VxsKey Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-30.blogspot.com/2009/01/bancosiem-trojan.html"&gt;Bancos.IEM Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-58.blogspot.com/2009/01/pigeonavjq-trojan.html"&gt;Pigeon.AVJQ Trojan Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-1624342601983337402?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/1624342601983337402/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=1624342601983337402' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1624342601983337402'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1624342601983337402'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/starwarerecipe-hijacker.html' title='Starware.Recipe Hijacker'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-5981611951242916201</id><published>2009-02-03T23:00:00.001-08:00</published><updated>2009-02-03T23:00:23.670-08:00</updated><title type='text'>Kraimer Trojan</title><content type='html'>Removing Kraimer &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Spyware,Backdoor,RAT&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;Spyware is computer software that is installed surreptitiously on a personal computer&lt;br /&gt;to &lt;strong&gt;intercept or take partial control&lt;/strong&gt; over the user's interaction&lt;br /&gt;with the computer, without the user's informed consent.&lt;br/&gt;&lt;br /&gt;While the term spyware suggests software that secretly monitors the user's behavior,&lt;br /&gt;the functions of spyware extend well beyond simple monitoring.&lt;br/&gt;&lt;br /&gt;Spyware programs can collect various types of personal information,&lt;br /&gt;such as Internet surfing habit, sites that have been visited,&lt;br /&gt;but can also interfere with user control of the computer in other ways,&lt;br /&gt;such as installing additional software, redirecting Web browser activity,&lt;br /&gt;accessing websites blindly that will cause more harmful viruses,&lt;br /&gt;or diverting advertising revenue to a third party.&lt;br/&gt;&lt;br /&gt;Spyware can even change computer settings, resulting in slow connection speeds,&lt;br /&gt;different home pages, and loss of Internet or other programs.&lt;br /&gt;In an attempt to increase the understanding of spyware, a more formal classification&lt;br /&gt;of its included software types is captured under the term privacy-invasive software.        &lt;br/&gt;Backdoors are the most dangerous type of Trojans and the most popular.&lt;br /&gt;Backdoors open infected machines to external control via Internet.&lt;br /&gt;Often the backdoor will not be visible in the log of active programs.&lt;br/&gt;Many trojans and backdoors now have &lt;strong&gt;remote administration capabilities&lt;/strong&gt;&lt;br /&gt;allowing an individual to control the victim's computer.&lt;br /&gt;Many times a file called the server must be opened on the victim's computer before&lt;br /&gt;the trojan can have access to it.&lt;br/&gt;&lt;br /&gt;These are generally sent through email, P2P file sharing software,&lt;br /&gt;and in internet downloads. They are usually disguised as a legitimate program or file.&lt;br /&gt;Many server files will display a fake error message when opened, to make it seem like it didn't open.&lt;br /&gt;Some will also kill antivirus and firewall software.&lt;br/&gt;&lt;br /&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,&lt;br /&gt;and swap mouse buttons. However, they can be quite hard to remove.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Kraimer Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Backdoor.Kraimer.11,Trojan.Spy.Kraimer.12,TrojanSpy.Win32.Kraimer.12,Sniffer.Win32.IPGrabber,Backdoor.Kraimer.13;&lt;br/&gt;[Eset]Win32/Kraimer.13 trojan;&lt;br/&gt;[McAfee]W32/Kraimer.worm,Kraimer;&lt;br/&gt;[F-Prot]security risk or a "backdoor" program;&lt;br/&gt;[Panda]Bck/Kraimer.11,Trojan Horse,Backdoor Program;&lt;br/&gt;[Computer Associates]Backdoor/Kraimer.11,Win32.Kraimer.11,Backdoor/Kraimer.12,Win32.Kraimer.12,Win32.KraimGrab,Win32/Ipgrab2!Worm,Backdoor/KrAIMer.13,Win32.Kraimer.13&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%STARTUP%]\aolstart.exe&lt;br/&gt;[%STARTUP%]\aolstart.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Kraimer:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%STARTUP%]\aolstart.exe&lt;br/&gt;[%STARTUP%]\aolstart.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Kraimer:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-61.blogspot.com/2009/02/infantile-backdoor.html"&gt;Infantile Backdoor Symptoms&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-5981611951242916201?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/5981611951242916201/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=5981611951242916201' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5981611951242916201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5981611951242916201'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/kraimer-trojan.html' title='Kraimer Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-8680214375467456480</id><published>2009-02-03T22:31:00.001-08:00</published><updated>2009-02-03T22:31:38.911-08:00</updated><title type='text'>KnightSeven Backdoor</title><content type='html'>Removing KnightSeven &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Backdoor,RAT&lt;br/&gt;&lt;em&gt;&lt;strong&gt;Backdoors are the most dangerous type of Trojans&lt;/strong&gt; and the most popular.&lt;br /&gt;&lt;strong&gt;Backdoors open infected machines&lt;/strong&gt; to external control via Internet.&lt;br /&gt;They function in the same way as legal remote administration programs used by system administrators.&lt;br /&gt;This makes them difficult to detect.&lt;br/&gt;&lt;br /&gt;&lt;strong&gt;Backdoors&lt;/strong&gt; are installed and launched without the consent of the user of computer.&lt;br /&gt;Often the backdoor will not be visible in the log of active programs.&lt;br/&gt;&lt;br /&gt;Once a backdoor has been successfully launched, the computer is wide open.&lt;br /&gt;Backdoor functions can include:&lt;br/&gt;&lt;br /&gt;    &lt;ul&gt;&lt;br /&gt;    &lt;li&gt; Launching/ deleting files&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Sending/ receiving files&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Deleting data&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Displaying notification&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Rebooting the machine&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Executing files&lt;/li&gt;&lt;br /&gt;    &lt;/ul&gt;&lt;br /&gt;&lt;br/&gt;&lt;br /&gt;&lt;strong&gt;Backdoors are used by virus writers to detect and download confidential information&lt;/strong&gt;,&lt;br /&gt;execute malicious code, destroy data, include the machine in bot networks and so forth.&lt;br /&gt;Backdoors combine the functionality of most other types of  in one package.&lt;br/&gt;&lt;br /&gt;Backdoors have one especially dangerous sub-class: variants that can propagate like worms. &lt;br/&gt;Many trojans and backdoors now have &lt;strong&gt;remote administration capabilities&lt;/strong&gt;&lt;br /&gt;allowing an individual to control the victim's computer.&lt;br /&gt;Many times a file called the server must be opened on the victim's computer before&lt;br /&gt;the trojan can have access to it.&lt;br/&gt;&lt;br /&gt;These are generally sent through email, P2P file sharing software,&lt;br /&gt;and in internet downloads. They are usually disguised as a legitimate program or file.&lt;br /&gt;Many server files will display a fake error message when opened, to make it seem like it didn't open.&lt;br /&gt;Some will also kill antivirus and firewall software.&lt;br/&gt;&lt;br /&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,&lt;br /&gt;and swap mouse buttons. However, they can be quite hard to remove.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;KnightSeven Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Backdoor.Knightseven.10;&lt;br/&gt;[Panda]Backdoor Program;&lt;br/&gt;[Computer Associates]Backdoor/Knightseven.1_0&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\sndctl32.cfg&lt;br/&gt;[%WINDOWS%]\sndctl32.exe&lt;br/&gt;[%WINDOWS%]\sndctl32.cfg&lt;br/&gt;[%WINDOWS%]\sndctl32.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect KnightSeven:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\sndctl32.cfg&lt;br/&gt;[%WINDOWS%]\sndctl32.exe&lt;br/&gt;[%WINDOWS%]\sndctl32.cfg&lt;br/&gt;[%WINDOWS%]\sndctl32.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing KnightSeven:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-28.blogspot.com/2009/02/cpasecom-tracking-cookie.html"&gt;cpase.com Tracking Cookie Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-4229.blogspot.com/2009/02/destruction-dos.html"&gt;Destruction DoS Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://malwarepedia-protect-listing.blogspot.com/2009/01/whitehousecn-dos.html"&gt;WhitehouseCn DoS Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-35.blogspot.com/2009/02/00d-adware.html"&gt;00d Adware Information&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-8680214375467456480?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/8680214375467456480/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=8680214375467456480' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8680214375467456480'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8680214375467456480'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/knightseven-backdoor.html' title='KnightSeven Backdoor'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-9020229392125607490</id><published>2009-02-03T21:47:00.001-08:00</published><updated>2009-02-03T21:47:56.752-08:00</updated><title type='text'>ActualNames.SearchPike BHO</title><content type='html'>Removing ActualNames.SearchPike &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; BHO,Hijacker&lt;br/&gt;&lt;em&gt;As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and&lt;br /&gt;sent back to the attacker. &lt;br /&gt;Typically, keyloggers of this type will send the stolen information back to the attacker via email&lt;br /&gt;or HTTP POST, which can appear suspicious.Hijackers are software programs that modify users' default browser home page,&lt;br /&gt;search settings, error page settings, or desktop wallpaper without adequate notice, disclosure,&lt;br /&gt;or user consent.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\spredirect.dll&lt;br/&gt;[%WINDOWS%]\system\spredirect.dll&lt;br/&gt;[%SYSTEM%]\spredirect.dll&lt;br/&gt;[%WINDOWS%]\system\spredirect.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect ActualNames.SearchPike:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\spredirect.dll&lt;br/&gt;[%WINDOWS%]\system\spredirect.dll&lt;br/&gt;[%SYSTEM%]\spredirect.dll&lt;br/&gt;[%WINDOWS%]\system\spredirect.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{92c7d65c-52f3-4545-8a35-213d730db1ed}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{92c7d65c-52f3-4545-8a35-213d730db1ed}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{92c7d65c-52f3-4545-8a35-213d730db1ed} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing ActualNames.SearchPike:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://details-list-pc.blogspot.com/2009/01/elotus-trojan.html"&gt;Elotus Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-3747.blogspot.com/2009/01/bancoshnb-trojan.html"&gt;Removing Bancos.HNB Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-0715.blogspot.com/2009/02/trojandownloaderwin32skoob-downloader.html"&gt;Remove TrojanDownloader.Win32.Skoob Downloader&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-9020229392125607490?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/9020229392125607490/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=9020229392125607490' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/9020229392125607490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/9020229392125607490'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/actualnamessearchpike-bho.html' title='ActualNames.SearchPike BHO'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7750040546309901649</id><published>2009-02-03T21:43:00.001-08:00</published><updated>2009-02-03T21:43:30.666-08:00</updated><title type='text'>Win32.TrojanDownloader.Dyfica Trojan</title><content type='html'>Removing Win32.TrojanDownloader.Dyfica &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Downloader&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;This family of Trojans &lt;strong&gt;downloads and installs new malware or adware on the computer&lt;/strong&gt;.&lt;br /&gt;The downloader then either launches the new malware or registers it to enable autorun&lt;br /&gt;according to the local operating system requirements.&lt;br/&gt;&lt;br /&gt;The names and locations of malware to be downloaded are either coded into the&lt;br /&gt;Trojan or downloaded from a specified website.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Win32.TrojanDownloader.Dyfica Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]TrojanDownloader.Win32.Dyfuca.da;&lt;br/&gt;[Panda]Spyware/Dyfuca&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\optimize.exe&lt;br/&gt;[%PROFILE_TEMP%]\optimize.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Win32.TrojanDownloader.Dyfica:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\optimize.exe&lt;br/&gt;[%PROFILE_TEMP%]\optimize.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Win32.TrojanDownloader.Dyfica:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-05.blogspot.com/2009/01/jt-adware.html"&gt;JT Adware Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-24.blogspot.com/2009/01/pigeonavp-trojan.html"&gt;Removing Pigeon.AVP Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-78.blogspot.com/2009/02/vxidlakg-trojan.html"&gt;Vxidl.AKG Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-23.blogspot.com/2009/01/bancosgom-trojan.html"&gt;Bancos.GOM Trojan Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7750040546309901649?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7750040546309901649/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7750040546309901649' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7750040546309901649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7750040546309901649'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/win32trojandownloaderdyfica-trojan.html' title='Win32.TrojanDownloader.Dyfica Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-421314817014194876</id><published>2009-02-03T21:40:00.001-08:00</published><updated>2009-02-03T21:40:13.745-08:00</updated><title type='text'>Sectemp Adware</title><content type='html'>Removing Sectemp &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        &lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect Sectemp:&lt;/h2&gt;&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\sectemp&lt;br/&gt;HKEY_LOCAL_MACHINE\software\sectemp&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\sectemp&lt;br/&gt;HKEY_LOCAL_MACHINE\software\sectemp&lt;br/&gt;HKEY_LOCAL_MACHINE\software\sectemp&lt;br/&gt;HKEY_LOCAL_MACHINE\software\sectemp&lt;br/&gt;HKEY_LOCAL_MACHINE\software\sectemp&lt;br/&gt;HKEY_LOCAL_MACHINE\software\sectemp &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Sectemp:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-33.blogspot.com/2009/01/smalljf-trojan.html"&gt;Small.jf Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://remove-listing-pc.blogspot.com/2009/01/cwsxxxvideo-hijacker.html"&gt;Remove CWS.XXXVideo Hijacker&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-88.blogspot.com/2009/01/bancosgnc-trojan.html"&gt;Bancos.GNC Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-68.blogspot.com/2009/01/bancoshjm-trojan.html"&gt;Bancos.HJM Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://description-info-remove.blogspot.com/2009/02/backdooraqi-trojan.html"&gt;Removing Backdoor.AQI Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-421314817014194876?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/421314817014194876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=421314817014194876' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/421314817014194876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/421314817014194876'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/sectemp-adware.html' title='Sectemp Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-4337439928881371827</id><published>2009-02-03T20:31:00.001-08:00</published><updated>2009-02-03T20:31:35.652-08:00</updated><title type='text'>Checkin Adware</title><content type='html'>Removing Checkin &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware,Downloader&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        This family of Trojans &lt;strong&gt;downloads and installs new malware or adware on the computer&lt;/strong&gt;.&lt;br /&gt;The downloader then either launches the new malware or registers it to enable autorun&lt;br /&gt;according to the local operating system requirements.&lt;br/&gt;&lt;br /&gt;The names and locations of malware to be downloaded are either coded into the&lt;br /&gt;Trojan or downloaded from a specified website.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\owmngr.exe&lt;br/&gt;[%SYSTEM%]\ttps.exe&lt;br/&gt;[%WINDOWS%]\system\owmngr.exe&lt;br/&gt;[%WINDOWS%]\system\ttps.exe&lt;br/&gt;[%SYSTEM%]\owmngr.exe&lt;br/&gt;[%SYSTEM%]\ttps.exe&lt;br/&gt;[%WINDOWS%]\system\owmngr.exe&lt;br/&gt;[%WINDOWS%]\system\ttps.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Checkin:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\owmngr.exe&lt;br/&gt;[%SYSTEM%]\ttps.exe&lt;br/&gt;[%WINDOWS%]\system\owmngr.exe&lt;br/&gt;[%WINDOWS%]\system\ttps.exe&lt;br/&gt;[%SYSTEM%]\owmngr.exe&lt;br/&gt;[%SYSTEM%]\ttps.exe&lt;br/&gt;[%WINDOWS%]\system\owmngr.exe&lt;br/&gt;[%WINDOWS%]\system\ttps.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Checkin:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-26.blogspot.com/2009/01/trojandownloaderwin32swizzoran-bho.html"&gt;TrojanDownloader.Win32.Swizzor.an BHO Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://viruslist-c.blogspot.com/2009/01/faketelnet-trojan_26.html"&gt;Fake.Telnet Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://computer-protect-virus.blogspot.com/2009/02/swfwob-trojan.html"&gt;Removing Swfwob Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-14.blogspot.com/2009/01/crazywin-adware.html"&gt;Removing CrazyWin Adware&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-0913.blogspot.com/2009/01/kewrih-trojan.html"&gt;Removing Kewrih Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-4337439928881371827?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/4337439928881371827/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=4337439928881371827' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4337439928881371827'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4337439928881371827'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/checkin-adware.html' title='Checkin Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6801777332144514158</id><published>2009-02-03T19:07:00.001-08:00</published><updated>2009-02-03T19:07:22.295-08:00</updated><title type='text'>Delf.az Trojan</title><content type='html'>Removing Delf.az &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Downloader&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;This family of Trojans &lt;strong&gt;downloads and installs new malware or adware on the computer&lt;/strong&gt;.&lt;br /&gt;The downloader then either launches the new malware or registers it to enable autorun&lt;br /&gt;according to the local operating system requirements.&lt;br/&gt;&lt;br /&gt;The names and locations of malware to be downloaded are either coded into the&lt;br /&gt;Trojan or downloaded from a specified website.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\comnt32.dll&lt;br/&gt;[%SYSTEM%]\inetconnect.dll&lt;br/&gt;[%SYSTEM%]\comnt32.dll&lt;br/&gt;[%SYSTEM%]\inetconnect.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Delf.az:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\comnt32.dll&lt;br/&gt;[%SYSTEM%]\inetconnect.dll&lt;br/&gt;[%SYSTEM%]\comnt32.dll&lt;br/&gt;[%SYSTEM%]\inetconnect.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{1bb87441-6b7f-4b60-885c-b7af9f9afde3}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{fd3a6ab4-5527-4b52-90af-f90cd3270861}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0cdaaec2-e245-44cc-8357-cab70172d017}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{77566c2a-2987-44bc-ac81-a02d19ee271b}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8e668361-c801-41b7-bf89-2fc2c8de9167}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{c0dadd7e-d3f1-430d-b735-39dc6033592c}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{1bb87441-6b7f-4b60-885c-b7af9f9afde3} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing Delf.az:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://viruslist-d.blogspot.com/2009/01/inserviceja-downloader.html"&gt;INService.ja Downloader Information&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6801777332144514158?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6801777332144514158/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6801777332144514158' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6801777332144514158'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6801777332144514158'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/delfaz-trojan.html' title='Delf.az Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7675446579809487597</id><published>2009-02-03T19:00:00.001-08:00</published><updated>2009-02-03T19:00:42.993-08:00</updated><title type='text'>Zlob.Fam.Security Messenger Trojan</title><content type='html'>Removing Zlob.Fam.Security Messenger &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Popups&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;Adware is the class of programs that &lt;strong&gt;place advertisements on your screen&lt;/strong&gt;.&lt;br /&gt;These may be in the form of pop-ups, pop-unders, advertisements embedded in programs,&lt;br /&gt;advertisements placed on top of ads in web sites, or any other way the authors can&lt;br /&gt;think of showing you an ad.&lt;br/&gt;&lt;br /&gt;The pop-ups generally will not be stopped by pop-up stoppers, and often are&lt;br /&gt;not dependent on your having Internet Explorer open.&lt;br /&gt;They may show up when you are playing a game, writing a document, listening to music,&lt;br /&gt;or anything else. Should you be surfing, the advertisements will often be related to&lt;br /&gt;the web page you are viewing.         &lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect Zlob.Fam.Security Messenger:&lt;/h2&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Messenger &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing Zlob.Fam.Security Messenger:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-47.blogspot.com/2009/01/priosted-trojan.html"&gt;Remove Priosted Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-74.blogspot.com/2009/01/doubleheart-trojan.html"&gt;Doubleheart Trojan Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7675446579809487597?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7675446579809487597/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7675446579809487597' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7675446579809487597'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7675446579809487597'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/zlobfamsecurity-messenger-trojan.html' title='Zlob.Fam.Security Messenger Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-1456643198263840671</id><published>2009-02-03T15:27:00.001-08:00</published><updated>2009-02-03T15:27:46.766-08:00</updated><title type='text'>MSBot Backdoor</title><content type='html'>Removing MSBot &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Backdoor&lt;br/&gt;&lt;em&gt;Backdoors are used by virus writers to detect and download confidential information,&lt;br /&gt;execute malicious code, destroy data, include the machine in bot networks and so forth.&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;MSBot Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Backdoor.MSBot.b;&lt;br/&gt;[McAfee]BackDoor-DT;&lt;br/&gt;[F-Prot]security risk or a "backdoor" program;&lt;br/&gt;[Panda]Bck/MSbot.B&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\msstat32.exe&lt;br/&gt;[%WINDOWS%]\system\msstat32.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect MSBot:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\msstat32.exe&lt;br/&gt;[%WINDOWS%]\system\msstat32.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing MSBot:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-4345.blogspot.com/2009/02/win32pwsallight-backdoor.html"&gt;Win32.PWS.AlLight Backdoor Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-4834.blogspot.com/2009/02/pigeonegc-trojan.html"&gt;Pigeon.EGC Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-0333.blogspot.com/2009/02/searchingbooth-tracking-cookie.html"&gt;Removing SearchingBooth Tracking Cookie&lt;/a&gt;&lt;br/&gt;&lt;a href="http://details-pc-keylogger.blogspot.com/2009/01/sillydlcra-downloader.html"&gt;SillyDl.CRA Downloader Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-24.blogspot.com/2009/01/ipromnet-tracking-cookie.html"&gt;iprom.net Tracking Cookie Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-1456643198263840671?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/1456643198263840671/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=1456643198263840671' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1456643198263840671'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1456643198263840671'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/msbot-backdoor.html' title='MSBot Backdoor'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-5704721090912032478</id><published>2009-02-03T15:23:00.001-08:00</published><updated>2009-02-03T15:23:29.299-08:00</updated><title type='text'>Win32.TrojanClicker.Delf Trojan</title><content type='html'>Removing Win32.TrojanClicker.Delf &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Adware&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Win32.TrojanClicker.Delf Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Eset]Win32/TrojanClicker.Delf.R trojan;&lt;br/&gt;[Panda]Adware/WinTools&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????&lt;br/&gt;[%WINDOWS%]\2_0_1browserhelper2.dll&lt;br/&gt;[%WINDOWS%]\2_0_1browserhelper2.dll_tobedeleted&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????&lt;br/&gt;[%WINDOWS%]\2_0_1browserhelper2.dll&lt;br/&gt;[%WINDOWS%]\2_0_1browserhelper2.dll_tobedeleted &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Win32.TrojanClicker.Delf:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????&lt;br/&gt;[%WINDOWS%]\2_0_1browserhelper2.dll&lt;br/&gt;[%WINDOWS%]\2_0_1browserhelper2.dll_tobedeleted&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????&lt;br/&gt;[%WINDOWS%]\2_0_1browserhelper2.dll&lt;br/&gt;[%WINDOWS%]\2_0_1browserhelper2.dll_tobedeleted &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Win32.TrojanClicker.Delf:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-1609.blogspot.com/2009/02/bancosguu-trojan.html"&gt;Bancos.GUU Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://infections-information-protect.blogspot.com/2009/01/bridgew-backdoor.html"&gt;BridgeW Backdoor Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://details-pc-keylogger.blogspot.com/2009/01/batattrib-trojan.html"&gt;Remove Bat.Attrib Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-28.blogspot.com/2009/01/pigeonavqp-trojan.html"&gt;Removing Pigeon.AVQP Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-73.blogspot.com/2009/02/msksoftstudy-corp-trojan.html"&gt;MskSoftStudy Corp. Trojan Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-5704721090912032478?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/5704721090912032478/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=5704721090912032478' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5704721090912032478'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5704721090912032478'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/win32trojanclickerdelf-trojan.html' title='Win32.TrojanClicker.Delf Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-65669443439435311</id><published>2009-02-03T13:31:00.001-08:00</published><updated>2009-02-03T13:31:31.570-08:00</updated><title type='text'>abxtoolbar BHO</title><content type='html'>Removing abxtoolbar &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; BHO&lt;br/&gt;&lt;em&gt;As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and&lt;br /&gt;sent back to the attacker. &lt;br /&gt;Typically, keyloggers of this type will send the stolen information back to the attacker via email&lt;br /&gt;or HTTP POST, which can appear suspicious.&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect abxtoolbar:&lt;/h2&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00ceaf8f-bf59-429b-a1d9-91c88ccfe94b}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{544f12d3-0b83-4ddb-b73a-53e1b4bba4af}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{17bbff9a-5d7b-4a5b-8265-15b4b86be90f}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{1e5c9fae-43b0-47c3-ba51-ba5a08e44322}&lt;br/&gt;HKEY_CLASSES_ROOT\toolband.xbtb01186&lt;br/&gt;HKEY_CLASSES_ROOT\toolband.xbtb01186.1&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{483d2273-2c22-4053-94ca-6a99b2778bf2}&lt;br/&gt;HKEY_CLASSES_ROOT\xbtb01186.ietoolbar&lt;br/&gt;HKEY_CLASSES_ROOT\xbtb01186.ietoolbar.1&lt;br/&gt;HKEY_CLASSES_ROOT\xbtb01186.xbtb01186&lt;br/&gt;HKEY_CLASSES_ROOT\xbtb01186.xbtb01186.1&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser\{544f12d3-0b83-4ddb-b73a-53e1b4bba4af}&lt;br/&gt;HKEY_CURRENT_USER\software\xbtb01186&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{544f12d3-0b83-4ddb-b73a-53e1b4bba4af}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{544f12d3-0b83-4ddb-b73a-53e1b4bba4af}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00ceaf8f-bf59-429b-a1d9-91c88ccfe94b}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xbtb01186.xbtb01186toolbar &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing abxtoolbar:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-55.blogspot.com/2009/01/pigeonauzy-trojan.html"&gt;Remove Pigeon.AUZY Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-0935.blogspot.com/2009/01/loofeer-trojan.html"&gt;Removing Loofeer Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-89.blogspot.com/2009/01/tpebosnia-trojan.html"&gt;Removing TPE.Bosnia Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-65669443439435311?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/65669443439435311/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=65669443439435311' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/65669443439435311'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/65669443439435311'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/abxtoolbar-bho_03.html' title='abxtoolbar BHO'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-4388384124200335907</id><published>2009-02-03T12:55:00.001-08:00</published><updated>2009-02-03T12:55:27.962-08:00</updated><title type='text'>abxtoolbar BHO</title><content type='html'>Removing abxtoolbar &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; BHO&lt;br/&gt;&lt;em&gt;&lt;strong&gt;BHO (Browser Helper Object) Trojan&lt;/strong&gt;.&lt;br /&gt;The BHO waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br /&gt;The method of network transport used by the attacker makes this Trojan unique.&lt;br /&gt;Typically, keyloggers of this type will send the stolen information back to the attacker via email&lt;br /&gt;or HTTP POST, which can appear suspicious.&lt;br /&gt;Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into&lt;br /&gt;the data section of an ICMP ping packet." explained the company.&lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect abxtoolbar:&lt;/h2&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00ceaf8f-bf59-429b-a1d9-91c88ccfe94b}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{544f12d3-0b83-4ddb-b73a-53e1b4bba4af}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{17bbff9a-5d7b-4a5b-8265-15b4b86be90f}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{1e5c9fae-43b0-47c3-ba51-ba5a08e44322}&lt;br/&gt;HKEY_CLASSES_ROOT\toolband.xbtb01186&lt;br/&gt;HKEY_CLASSES_ROOT\toolband.xbtb01186.1&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{483d2273-2c22-4053-94ca-6a99b2778bf2}&lt;br/&gt;HKEY_CLASSES_ROOT\xbtb01186.ietoolbar&lt;br/&gt;HKEY_CLASSES_ROOT\xbtb01186.ietoolbar.1&lt;br/&gt;HKEY_CLASSES_ROOT\xbtb01186.xbtb01186&lt;br/&gt;HKEY_CLASSES_ROOT\xbtb01186.xbtb01186.1&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser\{544f12d3-0b83-4ddb-b73a-53e1b4bba4af}&lt;br/&gt;HKEY_CURRENT_USER\software\xbtb01186&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{544f12d3-0b83-4ddb-b73a-53e1b4bba4af}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{544f12d3-0b83-4ddb-b73a-53e1b4bba4af}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00ceaf8f-bf59-429b-a1d9-91c88ccfe94b}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xbtb01186.xbtb01186toolbar &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing abxtoolbar:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-70.blogspot.com/2009/01/vxidlait-trojan.html"&gt;Vxidl.AIT Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-55.blogspot.com/2009/01/tribefloodnetwork-dos.html"&gt;Remove Tribe.Flood.Network DoS&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-51.blogspot.com/2009/01/drzip-trojan.html"&gt;Drzip Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://details-pc-keylogger.blogspot.com/2009/01/bancosfyw-trojan.html"&gt;Remove Bancos.FYW Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-26.blogspot.com/2009/01/pigeonejm-trojan.html"&gt;Pigeon.EJM Trojan Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-4388384124200335907?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/4388384124200335907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=4388384124200335907' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4388384124200335907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4388384124200335907'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/abxtoolbar-bho.html' title='abxtoolbar BHO'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-614037590379636481</id><published>2009-02-03T12:51:00.001-08:00</published><updated>2009-02-03T12:51:28.853-08:00</updated><title type='text'>DetectSatan Ransomware</title><content type='html'>Removing DetectSatan &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Ransomware&lt;br/&gt;&lt;em&gt;A &lt;strong&gt;cryptovirus, cryptotrojan or cryptoworm&lt;/strong&gt; is a type of&lt;br /&gt;malware that encrypts the data belonging to an individual on a computer,&lt;br /&gt;demanding a ransom for its restoration.&lt;br/&gt;&lt;br /&gt;The term ransomware is commonly used to describe software that encrypts the data&lt;br /&gt;belonging to an individual on a computer, demanding a ransom for its restoration.&lt;br /&gt;Although the field known as cryptovirology predates the term "ransomware".&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\DetectSatan 2.0.lnk&lt;br/&gt;[%DESKTOP%]\UnusualSoftware.com.lnk&lt;br/&gt;[%DESKTOP%]\DetectSatan 2.0.lnk&lt;br/&gt;[%DESKTOP%]\UnusualSoftware.com.lnk &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect DetectSatan:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\DetectSatan 2.0.lnk&lt;br/&gt;[%DESKTOP%]\UnusualSoftware.com.lnk&lt;br/&gt;[%DESKTOP%]\DetectSatan 2.0.lnk&lt;br/&gt;[%DESKTOP%]\UnusualSoftware.com.lnk &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\DetectSatan 2.0&lt;br/&gt;[%PROGRAM_FILES%]\Unusual Software &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;  &lt;h2&gt;Removing DetectSatan:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-28.blogspot.com/2009/01/vclcmp-trojan.html"&gt;VCL.cmp Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://protection-protect-details.blogspot.com/2009/01/win32telhack-dos.html"&gt;Removing Win32.TelHack DoS&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-614037590379636481?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/614037590379636481/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=614037590379636481' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/614037590379636481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/614037590379636481'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/detectsatan-ransomware.html' title='DetectSatan Ransomware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-4215517268004080393</id><published>2009-02-03T12:31:00.001-08:00</published><updated>2009-02-03T12:31:26.106-08:00</updated><title type='text'>CommonName.Zenet Hijacker</title><content type='html'>Removing CommonName.Zenet &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Hijacker&lt;br/&gt;&lt;em&gt;&lt;strong&gt;Hijackers are software programs that modify users' default browser home page&lt;/strong&gt;,&lt;br /&gt;search settings, error page settings, or desktop wallpaper without adequate notice, disclosure,&lt;br /&gt;or user consent.&lt;br/&gt;&lt;br /&gt;When the default home page is hijacked, the browser opens to the web page set by the hijacker&lt;br /&gt;instead of the user's designated home page. In some cases, the hijacker may block users from&lt;br /&gt;restoring their desired home page.&lt;br/&gt;&lt;br /&gt;A &lt;strong&gt;search hijacker&lt;/strong&gt; redirects search results to other pages and may&lt;br /&gt;transmit search and browsing data to unknown servers. An error page hijacker directs&lt;br /&gt;the browser to another page, usually an advertising page, instead of the usual error&lt;br /&gt;page when the requested URL is not found.&lt;br/&gt;&lt;br /&gt;A &lt;strong&gt;desktop hijacker&lt;/strong&gt; replaces the desktop wallpaper with advertising&lt;br /&gt;for products and services on the desktop.&lt;br/&gt;&lt;br /&gt;Hijackers take control of various parts of your web browser, including your home page,&lt;br /&gt;search pages, and search bar. They may also redirect you to certain sites should you&lt;br /&gt;mistype an address or prevent you from going to a website they would rather you not,&lt;br /&gt;such as sites that combat malware. Some will even redirect you to their own search engine&lt;br /&gt;when you attempt a search. NB: hijackers almost exclusively target Internet Explorer.&lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect CommonName.Zenet:&lt;/h2&gt;&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing CommonName.Zenet:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://description-info-remove.blogspot.com/2009/01/fdosudpstorm-dos.html"&gt;Remove FDoS.Udp.Storm DoS&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-67.blogspot.com/2009/01/systemprocess-adware.html"&gt;SystemProcess Adware Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-71.blogspot.com/2009/02/bancosijo-trojan.html"&gt;Bancos.IJO Trojan Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-4215517268004080393?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/4215517268004080393/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=4215517268004080393' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4215517268004080393'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4215517268004080393'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/commonnamezenet-hijacker.html' title='CommonName.Zenet Hijacker'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7958227799121492509</id><published>2009-02-03T12:15:00.001-08:00</published><updated>2009-02-03T12:15:24.155-08:00</updated><title type='text'>Remote.Control Backdoor</title><content type='html'>Removing Remote.Control &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Backdoor,RAT&lt;br/&gt;&lt;em&gt;Backdoors combine the functionality of most other types of  in one package.&lt;br /&gt;Backdoors have one especially dangerous sub-class: variants that can propagate like worms.&lt;br /&gt;&lt;br/&gt;Many trojans and backdoors now have &lt;strong&gt;remote administration capabilities&lt;/strong&gt;&lt;br /&gt;allowing an individual to control the victim's computer.&lt;br /&gt;Many times a file called the server must be opened on the victim's computer before&lt;br /&gt;the trojan can have access to it.&lt;br/&gt;&lt;br /&gt;These are generally sent through email, P2P file sharing software,&lt;br /&gt;and in internet downloads. They are usually disguised as a legitimate program or file.&lt;br /&gt;Many server files will display a fake error message when opened, to make it seem like it didn't open.&lt;br /&gt;Some will also kill antivirus and firewall software.&lt;br/&gt;&lt;br /&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,&lt;br /&gt;and swap mouse buttons. However, they can be quite hard to remove.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Remote.Control Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Backdoor.RC,Backdoor.Remotrol.11,Backdoor.Remotcon.10,Backdoor.VB.ey;&lt;br/&gt;[McAfee]BackDoor-FU,BackDoor-APD,BackDoor-AQY.gen;&lt;br/&gt;[F-Prot]security risk or a "backdoor" program;&lt;br/&gt;[Panda]Bck/Rc,Bck/RC.1.0,Bck/Remotrol.B,Backdoor Program,Backdoor Program.LC;&lt;br/&gt;[Computer Associates]Backdoor/RC!Server,Backdoor/Remotrol.1_1,Backdoor/VB.ey,Backdoor/VB.HU&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\Shareaza\Plugins\MediaPlayer.dll&lt;br/&gt;[%PROGRAM_FILES%]\Shareaza\Plugins\RazaWebHook.dll&lt;br/&gt;[%PROGRAM_FILES%]\Shareaza\Plugins\MediaPlayer.dll&lt;br/&gt;[%PROGRAM_FILES%]\Shareaza\Plugins\RazaWebHook.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Remote.Control:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\Shareaza\Plugins\MediaPlayer.dll&lt;br/&gt;[%PROGRAM_FILES%]\Shareaza\Plugins\RazaWebHook.dll&lt;br/&gt;[%PROGRAM_FILES%]\Shareaza\Plugins\MediaPlayer.dll&lt;br/&gt;[%PROGRAM_FILES%]\Shareaza\Plugins\RazaWebHook.dll &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Remote.Control:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-0611.blogspot.com/2009/01/istbarep-downloader.html"&gt;Remove IstBar.ep Downloader&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7958227799121492509?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7958227799121492509/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7958227799121492509' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7958227799121492509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7958227799121492509'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/remotecontrol-backdoor.html' title='Remote.Control Backdoor'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3998782181656246954</id><published>2009-02-03T11:55:00.001-08:00</published><updated>2009-02-03T11:55:19.843-08:00</updated><title type='text'>Cytron BHO</title><content type='html'>Removing Cytron &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; BHO&lt;br/&gt;&lt;em&gt;The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\downloaded program files\potd.dll&lt;br/&gt;[%WINDOWS%]\downloaded program files\sec.dll&lt;br/&gt;[%WINDOWS%]\downloaded program files\potd.dll&lt;br/&gt;[%WINDOWS%]\downloaded program files\sec.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Cytron:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\downloaded program files\potd.dll&lt;br/&gt;[%WINDOWS%]\downloaded program files\sec.dll&lt;br/&gt;[%WINDOWS%]\downloaded program files\potd.dll&lt;br/&gt;[%WINDOWS%]\downloaded program files\sec.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\potd &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing Cytron:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-1036.blogspot.com/2009/02/seed-trojan.html"&gt;Seed Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-18.blogspot.com/2009/01/ocspl-trojan.html"&gt;OC.spl Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-29.blogspot.com/2009/01/mbkwbar-toolbar.html"&gt;Remove MBKWBar Toolbar&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-14.blogspot.com/2009/01/globalnetcominc-trojan.html"&gt;Global.Netcom.Inc Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-07.blogspot.com/2009/01/pigeonawhr-trojan.html"&gt;Pigeon.AWHR Trojan Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3998782181656246954?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3998782181656246954/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3998782181656246954' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3998782181656246954'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3998782181656246954'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/cytron-bho.html' title='Cytron BHO'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-5785145369850674891</id><published>2009-02-03T11:35:00.001-08:00</published><updated>2009-02-03T11:35:35.250-08:00</updated><title type='text'>Dluca.gen Downloader</title><content type='html'>Removing Dluca.gen &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Downloader&lt;br/&gt;&lt;em&gt;Trojans-downloaders downloads and installs new malware or adware on the computer.&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\gwmpivue.exe&lt;br/&gt;[%SYSTEM%]\kmrptame.exe&lt;br/&gt;[%SYSTEM%]\msgb1.exe&lt;br/&gt;[%SYSTEM%]\gwmpivue.exe&lt;br/&gt;[%SYSTEM%]\kmrptame.exe&lt;br/&gt;[%SYSTEM%]\msgb1.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Dluca.gen:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\gwmpivue.exe&lt;br/&gt;[%SYSTEM%]\kmrptame.exe&lt;br/&gt;[%SYSTEM%]\msgb1.exe&lt;br/&gt;[%SYSTEM%]\gwmpivue.exe&lt;br/&gt;[%SYSTEM%]\kmrptame.exe&lt;br/&gt;[%SYSTEM%]\msgb1.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Dluca.gen:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-26.blogspot.com/2009/01/3xterm-trojan.html"&gt;3xterm Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-66.blogspot.com/2009/01/netrax-backdoor.html"&gt;Netrax Backdoor Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://keylogger-listing-protection.blogspot.com/2009/02/pigeonebq-trojan.html"&gt;Pigeon.EBQ Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-2701.blogspot.com/2009/02/vxidlafk-trojan.html"&gt;Vxidl.AFK Trojan Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-5785145369850674891?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/5785145369850674891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=5785145369850674891' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5785145369850674891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5785145369850674891'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/dlucagen-downloader.html' title='Dluca.gen Downloader'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-1598291673725536161</id><published>2009-02-03T10:35:00.001-08:00</published><updated>2009-02-03T10:35:19.365-08:00</updated><title type='text'>Ohbeeb Trojan</title><content type='html'>Removing Ohbeeb &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,DoS&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;DoS programs attack web servers by sending numerous requests to the specified server,&lt;br /&gt;often causing it to crash under an excessive volume of requests.&lt;br/&gt;&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Ohbeeb Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Trojan-Downlaoder.Win32.Tiny.cl,Trojan.Win32.Agent.zw,Trojan-Downlaoder.Win32.Small.dsx,Trojan.Win32.Zapxhast.cd,Trojan-Downlaoder.Win32.Small.dqt,Trojan-Downloader.Win32.tiny.bm,Trojan.Win32.Agent.zq,Trojan-Downlaoder.win32.Tiny.ad,Trojan-Downlaoder.Win32.Small.cug;&lt;br/&gt;[McAfee]Generic Downloader.ab,Downloader-AUw,Downloader-AUW,Downloader-BAB;&lt;br/&gt;[F-Prot]W32/Trojan.SCN;&lt;br/&gt;[Other]Win32/Ohbeeb,Win32.Ohbeeb,Win32/Ohbeeb.R,Win32/Ohbeeb.S,Downloader,Win32/Ohbeeb.T,Win32/Ohbeeb.N,win32/Ohbeeb.O,Win32/Ohbeeb.P,Win32.Ohbeeb.Q,Win32/Ohbeeb.V,Win32/Ohbeeb!generic,Win32/Ohbeeb.AF,Win32/Ohbeeb.AI,Win32/Ohbeeb.AH&lt;/code&gt;  &lt;p&gt;&lt;h2&gt;How to detect Ohbeeb:&lt;/h2&gt;&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Ohbeeb:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://malwarepedia-protect-listing.blogspot.com/2009/02/pigeonaveh-trojan.html"&gt;Remove Pigeon.AVEH Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://kill-computer-virus.blogspot.com/2009/01/mecapaw-trojan.html"&gt;Mecapaw Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-97.blogspot.com/2009/01/blackmonday-trojan.html"&gt;Black.Monday Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://information-details-removal.blogspot.com/2009/01/hoaveldoor-trojan.html"&gt;Removing Hoaveldoor Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-3831.blogspot.com/2009/02/elotus-trojan.html"&gt;Elotus Trojan Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-1598291673725536161?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/1598291673725536161/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=1598291673725536161' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1598291673725536161'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1598291673725536161'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/ohbeeb-trojan.html' title='Ohbeeb Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3331669617305108981</id><published>2009-02-03T10:11:00.001-08:00</published><updated>2009-02-03T10:11:42.281-08:00</updated><title type='text'>IEPageHelper Adware</title><content type='html'>Removing IEPageHelper &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware,BHO&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\inetdctr.dll&lt;br/&gt;[%WINDOWS%]\system\inetdctr.dll&lt;br/&gt;[%SYSTEM%]\inetdctr.dll&lt;br/&gt;[%WINDOWS%]\system\inetdctr.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect IEPageHelper:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\inetdctr.dll&lt;br/&gt;[%WINDOWS%]\system\inetdctr.dll&lt;br/&gt;[%SYSTEM%]\inetdctr.dll&lt;br/&gt;[%WINDOWS%]\system\inetdctr.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1C4DA27D-4D52-4465-A089-98E01BB725CA}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6F42CAD-2559-48DF-AF30-89E480AF5DFA}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{1c4da27d-4d52-4465-a089-98e01bb725ca}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{a6f42cad-2559-48df-af30-89e480af5dfa}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{1c4da27d-4d52-4465-a089-98e01bb725ca}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{a6f42cad-2559-48df-af30-89e480af5dfa}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{1c4da27d-4d52-4465-a089-98e01bb725ca}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a6f42cad-2559-48df-af30-89e480af5dfa} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing IEPageHelper:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-4832.blogspot.com/2009/02/gatesofhell-backdoor.html"&gt;Gates.of.Hell Backdoor Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-74.blogspot.com/2009/01/inetspeakiexplorr-adware.html"&gt;INetSpeak.Iexplorr Adware Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://list-details-trojanpedia.blogspot.com/2009/01/webprefix-adware.html"&gt;Remove Webprefix Adware&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-1943.blogspot.com/2009/02/hoolaxy-trojan.html"&gt;Removing Hoolaxy Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-malwarepedia-info.blogspot.com/2009/01/bancosgtb-trojan.html"&gt;Bancos.GTB Trojan Symptoms&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3331669617305108981?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3331669617305108981/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3331669617305108981' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3331669617305108981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3331669617305108981'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/iepagehelper-adware.html' title='IEPageHelper Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-8278810289268648369</id><published>2009-02-03T09:01:00.001-08:00</published><updated>2009-02-03T09:01:05.162-08:00</updated><title type='text'>ShopForGood Adware</title><content type='html'>Removing ShopForGood &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware,BHO,Hijacker,Toolbar&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br/&gt;A Search hijacker redirects search results to other pages and may&lt;br /&gt;transmit search and browsing data to unknown servers. An error page hijacker directs&lt;br /&gt;the browser to another page, usually an advertising page, instead of the usual error&lt;br /&gt;page when the requested URL is not found.&lt;br/&gt;Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\winy.dll&lt;br/&gt;[%WINDOWS%]\system\winy.dll&lt;br/&gt;[%SYSTEM%]\winy.dll&lt;br/&gt;[%WINDOWS%]\system\winy.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect ShopForGood:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\winy.dll&lt;br/&gt;[%WINDOWS%]\system\winy.dll&lt;br/&gt;[%SYSTEM%]\winy.dll&lt;br/&gt;[%WINDOWS%]\system\winy.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{05bbb56a-2a69-4a5c-bfda-43295dd67434}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{05bbb56a-2a69-4a5c-bfda-43295dd67434}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{05bbb56a-2a69-4a5c-bfda-43295dd67434}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{05bbb56a-2a69-4a5c-bfda-43295dd67434} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing ShopForGood:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-03.blogspot.com/2009/01/trojandownloaderwin32smallcsn-trojan.html"&gt;Trojan.Downloader.Win32.Small.csn Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-3039.blogspot.com/2009/01/dos-trojan.html"&gt;Dos Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-74.blogspot.com/2009/01/velozcom-tracking-cookie.html"&gt;Veloz.com Tracking Cookie Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-8278810289268648369?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/8278810289268648369/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=8278810289268648369' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8278810289268648369'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8278810289268648369'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/shopforgood-adware.html' title='ShopForGood Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-134444778392700534</id><published>2009-02-03T07:27:00.001-08:00</published><updated>2009-02-03T07:27:39.587-08:00</updated><title type='text'>Zlob.QK Trojan</title><content type='html'>Removing Zlob.QK &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Downloader,Popups&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;This family of Trojans &lt;strong&gt;downloads and installs new malware or adware on the computer&lt;/strong&gt;.&lt;br /&gt;The downloader then either launches the new malware or registers it to enable autorun&lt;br /&gt;according to the local operating system requirements.&lt;br/&gt;&lt;br /&gt;The names and locations of malware to be downloaded are either coded into the&lt;br /&gt;Trojan or downloaded from a specified website.&lt;br/&gt;Adware is the class of programs that &lt;strong&gt;place advertisements on your screen&lt;/strong&gt;.&lt;br /&gt;These may be in the form of pop-ups, pop-unders, advertisements embedded in programs,&lt;br /&gt;advertisements placed on top of ads in web sites, or any other way the authors can&lt;br /&gt;think of showing you an ad.&lt;br/&gt;&lt;br /&gt;The pop-ups generally will not be stopped by pop-up stoppers, and often are&lt;br /&gt;not dependent on your having Internet Explorer open.&lt;br /&gt;They may show up when you are playing a game, writing a document, listening to music,&lt;br /&gt;or anything else. Should you be surfing, the advertisements will often be related to&lt;br /&gt;the web page you are viewing.         &lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect Zlob.QK:&lt;/h2&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\AVZipEnchancer.Chl&lt;br/&gt;HKEY_CLASSES_ROOT\codecssoftwarepackage.chl &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing Zlob.QK:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-00.blogspot.com/2009/01/daviddropper-trojan.html"&gt;David!Dropper Trojan Symptoms&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-134444778392700534?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/134444778392700534/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=134444778392700534' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/134444778392700534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/134444778392700534'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/zlobqk-trojan.html' title='Zlob.QK Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-2847421700992050157</id><published>2009-02-03T06:51:00.001-08:00</published><updated>2009-02-03T06:51:39.486-08:00</updated><title type='text'>Samsa Trojan</title><content type='html'>Removing Samsa &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Samsa Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Trojan.Win32/Samsa.b,Trojan.Win32.Samsa,Trojan.Win32.Samsa.v;&lt;br/&gt;[McAfee]Enfal;&lt;br/&gt;[F-Prot]W32/Trojan2.LSU (exact);&lt;br/&gt;[Other]Win32/Samsa.A,Win32/Samsa&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\inbackup.exe&lt;br/&gt;[%SYSTEM%]\inbackup.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Samsa:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\inbackup.exe&lt;br/&gt;[%SYSTEM%]\inbackup.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Samsa:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-30.blogspot.com/2009/01/browsertoolbar-adware.html"&gt;BrowserToolbar Adware Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-81.blogspot.com/2009/01/mitgliederdz-trojan.html"&gt;Mitglieder.dz Trojan Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-2847421700992050157?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/2847421700992050157/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=2847421700992050157' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2847421700992050157'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2847421700992050157'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/samsa-trojan.html' title='Samsa Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-9118864687546451619</id><published>2009-02-03T06:47:00.001-08:00</published><updated>2009-02-03T06:47:43.445-08:00</updated><title type='text'>AdBreak.FHFMM BHO</title><content type='html'>Removing AdBreak.FHFMM &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; BHO&lt;br/&gt;&lt;em&gt;The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\fhfmm.exe&lt;br/&gt;[%WINDOWS%]\fhfmm-Uninstaller.exe&lt;br/&gt;[%WINDOWS%]\fhfmm.dll&lt;br/&gt;[%WINDOWS%]\fhfmm.txt&lt;br/&gt;[%WINDOWS%]\fhfmm1.tmp&lt;br/&gt;[%WINDOWS%]\fhfmm2.tmp&lt;br/&gt;[%WINDOWS%]\fhfmm3.tmp&lt;br/&gt;[%WINDOWS%]\liqui-Uninstaller.exe&lt;br/&gt;[%WINDOWS%]\fhfmm.exe&lt;br/&gt;[%WINDOWS%]\fhfmm-Uninstaller.exe&lt;br/&gt;[%WINDOWS%]\fhfmm.dll&lt;br/&gt;[%WINDOWS%]\fhfmm.txt&lt;br/&gt;[%WINDOWS%]\fhfmm1.tmp&lt;br/&gt;[%WINDOWS%]\fhfmm2.tmp&lt;br/&gt;[%WINDOWS%]\fhfmm3.tmp&lt;br/&gt;[%WINDOWS%]\liqui-Uninstaller.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect AdBreak.FHFMM:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\fhfmm.exe&lt;br/&gt;[%WINDOWS%]\fhfmm-Uninstaller.exe&lt;br/&gt;[%WINDOWS%]\fhfmm.dll&lt;br/&gt;[%WINDOWS%]\fhfmm.txt&lt;br/&gt;[%WINDOWS%]\fhfmm1.tmp&lt;br/&gt;[%WINDOWS%]\fhfmm2.tmp&lt;br/&gt;[%WINDOWS%]\fhfmm3.tmp&lt;br/&gt;[%WINDOWS%]\liqui-Uninstaller.exe&lt;br/&gt;[%WINDOWS%]\fhfmm.exe&lt;br/&gt;[%WINDOWS%]\fhfmm-Uninstaller.exe&lt;br/&gt;[%WINDOWS%]\fhfmm.dll&lt;br/&gt;[%WINDOWS%]\fhfmm.txt&lt;br/&gt;[%WINDOWS%]\fhfmm1.tmp&lt;br/&gt;[%WINDOWS%]\fhfmm2.tmp&lt;br/&gt;[%WINDOWS%]\fhfmm3.tmp&lt;br/&gt;[%WINDOWS%]\liqui-Uninstaller.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing AdBreak.FHFMM:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-description-blog.blogspot.com/2009/01/bancosaks-trojan.html"&gt;Bancos.AKS Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://information-details-removal.blogspot.com/2009/01/vxidlacm-trojan.html"&gt;Remove Vxidl.ACM Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-68.blogspot.com/2009/01/formatkill-trojan.html"&gt;Remove Format.Kill Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-0329.blogspot.com/2009/01/mute-trojan.html"&gt;Removing Mute Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://protect-kill-infections.blogspot.com/2009/01/nethiefxpsp1-rat.html"&gt;Nethief.XP.SP1 RAT Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-9118864687546451619?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/9118864687546451619/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=9118864687546451619' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/9118864687546451619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/9118864687546451619'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/adbreakfhfmm-bho.html' title='AdBreak.FHFMM BHO'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-8199788768196904188</id><published>2009-02-03T06:39:00.001-08:00</published><updated>2009-02-03T06:39:36.263-08:00</updated><title type='text'>PassAlert Trojan</title><content type='html'>Removing PassAlert &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Downloader&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;This family of Trojans &lt;strong&gt;downloads and installs new malware or adware on the computer&lt;/strong&gt;.&lt;br /&gt;The downloader then either launches the new malware or registers it to enable autorun&lt;br /&gt;according to the local operating system requirements.&lt;br/&gt;&lt;br /&gt;The names and locations of malware to be downloaded are either coded into the&lt;br /&gt;Trojan or downloaded from a specified website.&lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect PassAlert:&lt;/h2&gt;&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing PassAlert:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://viruslist-d.blogspot.com/2009/01/pluto-trojan.html"&gt;Pluto Trojan Symptoms&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-8199788768196904188?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/8199788768196904188/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=8199788768196904188' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8199788768196904188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8199788768196904188'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/passalert-trojan.html' title='PassAlert Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6402478841125401919</id><published>2009-02-03T06:35:00.001-08:00</published><updated>2009-02-03T06:35:31.034-08:00</updated><title type='text'>Need2Find Adware</title><content type='html'>Removing Need2Find &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\Need2Find\bar\1.bin\ND2FNBAR.DLL&lt;br/&gt;[%PROGRAM_FILES%]\Need2Find\bar\1.bin\ND2FNBAR.DLL &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Need2Find:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\Need2Find\bar\1.bin\ND2FNBAR.DLL&lt;br/&gt;[%PROGRAM_FILES%]\Need2Find\bar\1.bin\ND2FNBAR.DLL &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{4D1C4E81-A32A-416b-BCDB-33B3EF3617D3}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{630d6140-04c5-4db0-b27a-020d766ff09b}&lt;br/&gt;HKEY_CLASSES_ROOT\need2findbar.settingsplugin&lt;br/&gt;HKEY_CLASSES_ROOT\need2findbar.settingsplugin.1&lt;br/&gt;HKEY_CLASSES_ROOT\need2findbar.toolbarplugin&lt;br/&gt;HKEY_CLASSES_ROOT\need2findbar.toolbarplugin.1&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{4d1c4e81-a32a-416b-bcdb-33b3ef3617d3} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\need2findbar uninstall&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\need2findbar uninstall&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\need2findbar uninstall&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\need2findbar uninstall&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\need2findbar uninstall&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\need2findbar uninstall &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Need2Find:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-95.blogspot.com/2009/01/backdoorbladerunner-trojan.html"&gt;Backdoor.Bladerunner Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-41.blogspot.com/2009/01/tcsinstallationampconfiguration-trojan.html"&gt;Remove TCS.Installation.&amp;.Configuration Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-84.blogspot.com/2009/01/mosaic-trojan.html"&gt;Mosaic Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-3211.blogspot.com/2009/02/defie-trojan.html"&gt;Remove DefIE Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6402478841125401919?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6402478841125401919/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6402478841125401919' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6402478841125401919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6402478841125401919'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/need2find-adware.html' title='Need2Find Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-1955775245217152811</id><published>2009-02-03T06:32:00.001-08:00</published><updated>2009-02-03T06:32:16.921-08:00</updated><title type='text'>BrowserAid.FindIt.Quick BHO</title><content type='html'>Removing BrowserAid.FindIt.Quick &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; BHO,Toolbar&lt;br/&gt;&lt;em&gt;&lt;strong&gt;BHO (Browser Helper Object) Trojan&lt;/strong&gt;.&lt;br /&gt;The BHO waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br /&gt;The method of network transport used by the attacker makes this Trojan unique.&lt;br /&gt;Typically, keyloggers of this type will send the stolen information back to the attacker via email&lt;br /&gt;or HTTP POST, which can appear suspicious.&lt;br /&gt;Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into&lt;br /&gt;the data section of an ICMP ping packet." explained the company.&lt;br/&gt;Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect BrowserAid.FindIt.Quick:&lt;/h2&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{72ceae02-df9c-49f3-9689-10d1b82dc343}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{72ceae02-df9c-49f3-9689-10d1b82dc343} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing BrowserAid.FindIt.Quick:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-05.blogspot.com/2009/01/pigeonavnn-trojan.html"&gt;Remove Pigeon.AVNN Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-32.blogspot.com/2009/01/pathfindercom-tracking-cookie.html"&gt;pathfinder.com Tracking Cookie Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-04.blogspot.com/2009/01/avocadoserverdll-trojan.html"&gt;Remove Avocado.ServerDLL Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-1817.blogspot.com/2009/02/dowqueabw-trojan.html"&gt;Dowque.ABW Trojan Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-1955775245217152811?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/1955775245217152811/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=1955775245217152811' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1955775245217152811'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1955775245217152811'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/browseraidfinditquick-bho.html' title='BrowserAid.FindIt.Quick BHO'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-8968119309235692228</id><published>2009-02-03T06:00:00.001-08:00</published><updated>2009-02-03T06:00:03.764-08:00</updated><title type='text'>Hellraider RAT</title><content type='html'>Removing Hellraider &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; RAT&lt;br/&gt;&lt;em&gt;Many trojans and backdoors now have &lt;strong&gt;remote administration capabilities&lt;/strong&gt;&lt;br /&gt;allowing an individual to control the victim's computer.&lt;br /&gt;Many times a file called the server must be opened on the victim's computer before&lt;br /&gt;the trojan can have access to it.&lt;br/&gt;&lt;br /&gt;These are generally sent through email, P2P file sharing software,&lt;br /&gt;and in internet downloads. They are usually disguised as a legitimate program or file.&lt;br /&gt;Many server files will display a fake error message when opened, to make it seem like it didn't open.&lt;br /&gt;Some will also kill antivirus and firewall software.&lt;br/&gt;&lt;br /&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,&lt;br /&gt;and swap mouse buttons. However, they can be quite hard to remove.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\hellraider.exe&lt;br/&gt;[%WINDOWS%]\hellraider.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Hellraider:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\hellraider.exe&lt;br/&gt;[%WINDOWS%]\hellraider.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\mirabilis\icq\agent\apps\cxyfp&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Hellraider:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-96.blogspot.com/2009/01/araradr-rat.html"&gt;Arara.dr RAT Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://description-info-remove.blogspot.com/2009/01/priosted-trojan.html"&gt;Priosted Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://malware-list-info.blogspot.com/2009/01/bancoshxj-trojan.html"&gt;Bancos.HXJ Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://viruslist-d.blogspot.com/2009/01/agentfz-trojan.html"&gt;Agent.FZ Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-01.blogspot.com/2009/02/pigeonemg-trojan.html"&gt;Removing Pigeon.EMG Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-8968119309235692228?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/8968119309235692228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=8968119309235692228' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8968119309235692228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8968119309235692228'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/hellraider-rat.html' title='Hellraider RAT'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3666474844277632920</id><published>2009-02-03T03:43:00.001-08:00</published><updated>2009-02-03T03:43:22.294-08:00</updated><title type='text'>CWS Homepage Hijacker Hijacker</title><content type='html'>Removing CWS Homepage Hijacker &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Hijacker&lt;br/&gt;&lt;em&gt;Hijackers take control of various parts of your web browser, including your home page,&lt;br /&gt;search pages, and search bar. They may also redirect you to certain sites should you&lt;br /&gt;mistype an address or prevent you from going to a website they would rather you not,&lt;br /&gt;such as sites that combat malware. Some will even redirect you to their own search engine&lt;br /&gt;when you attempt a search.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\COMMONNAME\TOOLBAR\cnbabe.dll&lt;br/&gt;[%PROGRAM_FILES%]\Dianlei\Plugins\DLManager.dll&lt;br/&gt;[%PROGRAM_FILES%]\FlashGet\Jccatch.dll&lt;br/&gt;[%PROGRAM_FILES%]\ICOO Loader\addons\icoou.dll&lt;br/&gt;[%PROGRAM_FILES%]\ICOO Loader\addons\icooue.dll&lt;br/&gt;[%SYSTEM%]\afontext.dll&lt;br/&gt;[%SYSTEM%]\atlwt32.dll&lt;br/&gt;[%SYSTEM%]\msacmx.dll&lt;br/&gt;[%WINDOWS%]\apilx32.dll&lt;br/&gt;[%WINDOWS%]\apizu32.dll&lt;br/&gt;[%WINDOWS%]\g230320000.dll&lt;br/&gt;[%WINDOWS%]\ipec32.dll&lt;br/&gt;[%WINDOWS%]\mfchi32.dll&lt;br/&gt;[%WINDOWS%]\wingj.dll&lt;br/&gt;[%PROGRAM_FILES%]\COMMONNAME\TOOLBAR\cnbabe.dll&lt;br/&gt;[%PROGRAM_FILES%]\Dianlei\Plugins\DLManager.dll&lt;br/&gt;[%PROGRAM_FILES%]\FlashGet\Jccatch.dll&lt;br/&gt;[%PROGRAM_FILES%]\ICOO Loader\addons\icoou.dll&lt;br/&gt;[%PROGRAM_FILES%]\ICOO Loader\addons\icooue.dll&lt;br/&gt;[%SYSTEM%]\afontext.dll&lt;br/&gt;[%SYSTEM%]\atlwt32.dll&lt;br/&gt;[%SYSTEM%]\msacmx.dll&lt;br/&gt;[%WINDOWS%]\apilx32.dll&lt;br/&gt;[%WINDOWS%]\apizu32.dll&lt;br/&gt;[%WINDOWS%]\g230320000.dll&lt;br/&gt;[%WINDOWS%]\ipec32.dll&lt;br/&gt;[%WINDOWS%]\mfchi32.dll&lt;br/&gt;[%WINDOWS%]\wingj.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect CWS Homepage Hijacker:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\COMMONNAME\TOOLBAR\cnbabe.dll&lt;br/&gt;[%PROGRAM_FILES%]\Dianlei\Plugins\DLManager.dll&lt;br/&gt;[%PROGRAM_FILES%]\FlashGet\Jccatch.dll&lt;br/&gt;[%PROGRAM_FILES%]\ICOO Loader\addons\icoou.dll&lt;br/&gt;[%PROGRAM_FILES%]\ICOO Loader\addons\icooue.dll&lt;br/&gt;[%SYSTEM%]\afontext.dll&lt;br/&gt;[%SYSTEM%]\atlwt32.dll&lt;br/&gt;[%SYSTEM%]\msacmx.dll&lt;br/&gt;[%WINDOWS%]\apilx32.dll&lt;br/&gt;[%WINDOWS%]\apizu32.dll&lt;br/&gt;[%WINDOWS%]\g230320000.dll&lt;br/&gt;[%WINDOWS%]\ipec32.dll&lt;br/&gt;[%WINDOWS%]\mfchi32.dll&lt;br/&gt;[%WINDOWS%]\wingj.dll&lt;br/&gt;[%PROGRAM_FILES%]\COMMONNAME\TOOLBAR\cnbabe.dll&lt;br/&gt;[%PROGRAM_FILES%]\Dianlei\Plugins\DLManager.dll&lt;br/&gt;[%PROGRAM_FILES%]\FlashGet\Jccatch.dll&lt;br/&gt;[%PROGRAM_FILES%]\ICOO Loader\addons\icoou.dll&lt;br/&gt;[%PROGRAM_FILES%]\ICOO Loader\addons\icooue.dll&lt;br/&gt;[%SYSTEM%]\afontext.dll&lt;br/&gt;[%SYSTEM%]\atlwt32.dll&lt;br/&gt;[%SYSTEM%]\msacmx.dll&lt;br/&gt;[%WINDOWS%]\apilx32.dll&lt;br/&gt;[%WINDOWS%]\apizu32.dll&lt;br/&gt;[%WINDOWS%]\g230320000.dll&lt;br/&gt;[%WINDOWS%]\ipec32.dll&lt;br/&gt;[%WINDOWS%]\mfchi32.dll&lt;br/&gt;[%WINDOWS%]\wingj.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0000-0000-0000-000000000000}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{008764D5-773A-A0CE-0E07-D1A50B2AEB9C}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{027602E2-163B-E675-169C-61D11C7D6D27}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{0519A9C9-064A-4cbc-BC47-D0EACD581477}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{093646C5-CDDB-2035-BD50-008A30E3EA96}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{0E0649E4-4EF1-5350-5D27-33BAD0093516}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{0FEE7E33-7D50-E2F1-5115-7D9B474CAEA8}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{18A2EFFD-B6E8-69B5-4ABB-1F1C8F860433}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{199D9E0B-2F5F-DA98-2B62-FA9AA3710DD5}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{1C72FEB7-4D6C-FAF3-195A-D51516EDCC77}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{242B315F-5E97-AB86-1F6E-F73703F03993}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{255FEB8E-6196-9318-D570-21DED5FF9E37}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{30C15F1B-B902-8769-7E97-07B632351674}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{32646C8A-BB54-7D47-C6A8-722B0FA51A6C}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{32FD5A16-7B87-D254-57E3-C8A486AA74D6}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{35211BE1-8EDF-F9D6-D61F-027B7DB286D4}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{38B38285-1192-F79E-1DFC-91016F827D80}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{39497903-FC95-F850-8965-3C13F3D7274A}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{3C6CC514-0686-8D4A-3795-115CE35C21E9}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{3F300A97-6990-3673-92B7-FCDF52055C5F}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{4129401E-E0CC-8390-738E-DCC2CDEFBA2B}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{41A0091F-BE0B-897D-16F8-5BD81668DD3F}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{46016C67-D3FF-4014-621E-C121E994E090}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{465A59EC-20E5-4fca-A38A-E5EC3C480218}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{467FAEB2-5F5B-4C81-BAE0-2A4752CA7F4E}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{47E71DA2-60FF-677A-1484-28704F9ABE46}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{4D3F045A-9870-CF55-CF30-851993A3AF6F}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{4D7C2D84-2B00-146D-CAF2-38E8743204A2}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{513E86B0-D516-B255-E656-DEF35121232E}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{521B84C2-EFEB-DC8C-B02A-9089847972E1}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{5742F79A-1D91-42C4-990C-B46CF55A6478}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{59708803-B475-5C15-39AD-7A1D62317282}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{5BCE8A80-9FA3-A229-B315-13932E0AA5D8}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{605B61F1-324E-B844-52EA-08A764AA37D9}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{60B33657-9E08-DEB2-4980-97C2352D4AEF}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{624D0ED6-FBD6-D488-B435-B1E924C175C0}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{6259AAB6-979D-83C5-B2DB-ABC95EA1C8B2}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{68258D5A-F48D-99E0-FFBF-35C3BFB74C94}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{6A9852CC-FCBB-61A5-41A1-2EDA8230AEC5}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{6D5064E5-DB4F-986D-4AD0-EC06E8821EA9}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{7363BA68-FA5B-4BC9-8DEF-84263F54F53D}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{741EF1A1-D9CC-94D4-0B32-52C18D0ED509}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{77E35B59-5DBF-CA0F-2037-00B52E21E874}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{8227E624-0D80-2ABA-0149-6F487ADE838B}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{869819CE-8035-1170-64C2-6EE1E98B3458}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{87680A9A-4595-032D-4F84-B593061B9FC5}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{8F6B33B6-05DF-FAF4-C592-388E843E5ADB}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{904D6A45-F3FF-1A6D-7B1D-0DB4E2E1F3E7}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{90B46B07-282D-8DDE-D296-452CDBB0603B}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{90C2CAE8-913A-DBA5-AC8E-D0896D0378CA}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{92CDA6FC-1C7D-E1DC-676E-761A6ECC0847}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{98A9B656-1029-E870-F0CD-CA151569B86D}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{9E2E0AAF-55CD-8D02-957C-C88F3AC0AE90}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{A0B5AE4D-89E5-F22A-060E-06256A646F77}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{A2BEDD84-A226-805F-8E96-0121145966E2}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00401}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{a5366673-e8ca-11d3-9cd9-0090271d075b}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{A6AB0709-374D-2F77-3E70-0DE0910A9568}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{A7FA3C2B-428C-A94F-686F-2252E4F3A02C}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{AA0A9B7C-1E92-535C-0904-539590028603}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{AB9D62B8-7E56-2DB3-A516-E377F1010DCD}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{B063B761-34B8-42D9-CBCD-08B0A1D3E8D4}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{B9D90B27-AD4A-413A-88CB-3E6DDC10DC2D}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{BEF00307-0846-75C4-B6F5-84A949B91F47}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{CDF3AE9D-4F8C-67BC-66A6-A9252CCD81A1}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{D572A88C-5F1B-7EFE-45C7-5E070937FBFC}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{DEFC684A-30AD-8E93-CC49-E8F76A63D101}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{DFD57175-D4E1-532D-8EE9-D8E60D7C3992}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{E2E6C0E2-FA3A-8992-181C-3BA9E7ED6D56}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{E32E2C23-F6D7-0593-005D-8AE4C8C742A8}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{E38ED9F3-91EA-355E-5715-27B3113CA15D}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{E66BEB61-721E-FA12-3F4B-CC71F7910CF0}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{E6F23682-174F-AF3C-0738-3DEF6F7B9091}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{E902A02C-DD59-5DE4-624F-8012F9AFA9B9}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{E97E5AE0-29D6-7DFA-7E92-29CC5D770DA3}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{F9567894-1E9F-4452-79FF-F795A197EFBA}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{FC2593E3-3E5A-410F-AF3D-82613CCE58E5}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{FD7786C4-36BE-9F97-70B6-B4EF1D3FBA8B}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{FF52FC75-302C-5DED-C090-F77905337D75}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000000-0000-0000-0000-000000000000}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00110011-4b0b-44d5-9718-90c88817369b}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{008764D5-773A-A0CE-0E07-D1A50B2AEB9C}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01295AD0-0541-D9B9-7631-E16A07785229}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{027602E2-163B-E675-169C-61D11C7D6D27}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0519A9C9-064A-4cbc-BC47-D0EACD581477}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0566E16E-2A99-5084-E121-5895960CC230}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07F009CC-0ADE-5083-F469-92CE6474B119}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{086ae192-23a6-48d6-96ec-715f53797e85}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{093646C5-CDDB-2035-BD50-008A30E3EA96}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ABCE593-A2F9-DA6D-2B6D-D92E2B05E875}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E0649E4-4EF1-5350-5D27-33BAD0093516}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FEE7E33-7D50-E2F1-5115-7D9B474CAEA8}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11BA77F1-683B-FBF7-B61E-4821BC229D98}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{12869A5D-0FF9-B9AA-8BD8-9337FB04C5C6}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1289C13B-DC64-888A-AC41-234F521546F5}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{150fa160-130d-451f-b863-b655061432ba}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{17da0c9e-4a27-4ac5-bb75-5d24b8cdb972}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{182318D0-C69A-F785-8040-72D18DFA96ED}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18A2EFFD-B6E8-69B5-4ABB-1F1C8F860433}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18ECE89C-2542-91DE-E39B-39C5120593D7}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{199D9E0B-2F5F-DA98-2B62-FA9AA3710DD5}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1A0D767B-0C24-CB78-0876-5F7AEE9294F4}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1b68470c-2def-493b-8a4a-8e2d81be4ea5}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1C72FEB7-4D6C-FAF3-195A-D51516EDCC77}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{20FA44E2-4117-97B3-21C4-ABFD27838805}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{213FF3C4-933A-5728-4344-750F1EBB3DD5}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{242B315F-5E97-AB86-1F6E-F73703F03993}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{255FEB8E-6196-9318-D570-21DED5FF9E37}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2761A38B-D828-B1C6-1039-1395C426EDDA}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{29C196DF-2556-96EE-B27D-089B4B07F011}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2d38a51a-23c9-48a1-a33c-48675aa2b494}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2FCA15DA-4534-DA39-35D0-ED78D3F19541}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30C15F1B-B902-8769-7E97-07B632351674}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32646C8A-BB54-7D47-C6A8-722B0FA51A6C}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32A6B01D-983B-8AF2-A16D-062280B34476}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32FD5A16-7B87-D254-57E3-C8A486AA74D6}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33C7D509-2F1B-1150-D9B4-4CAEA87399FC}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35211BE1-8EDF-F9D6-D61F-027B7DB286D4}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{38729DB3-1DF3-C16A-63B7-BE2CC5DC8D27}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3881EB3F-A5F4-4CF3-F9B2-25986B2B2656}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{38B38285-1192-F79E-1DFC-91016F827D80}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3901E8B9-569B-50AA-35AC-D0FC976E91F1}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39497903-FC95-F850-8965-3C13F3D7274A}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395654E0-C152-DEFC-F1D5-D4ED74FC94EC}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3959283E-C72B-D2BA-8167-B27A8FA8F55B}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3C6CC514-0686-8D4A-3795-115CE35C21E9}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3DF3AE97-927A-A988-F257-18F61D1C5ABA}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E634ABC-AA83-3403-5DD5-43546E8735F1}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3F300A97-6990-3673-92B7-FCDF52055C5F}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{40967C3E-0316-B8F3-7AC2-AC680D6E22D9}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4129401E-E0CC-8390-738E-DCC2CDEFBA2B}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41A0091F-BE0B-897D-16F8-5BD81668DD3F}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44A73433-E13D-79D4-D26D-9CDD83E71551}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{46016C67-D3FF-4014-621E-C121E994E090}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{465A59EC-20E5-4fca-A38A-E5EC3C480218}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{467FAEB2-5F5B-4C81-BAE0-2A4752CA7F4E}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{47E71DA2-60FF-677A-1484-28704F9ABE46}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A50DB5A-1456-7EE4-9AD0-BD52FA677D5F}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4AA3BB56-37CA-AC96-1BCE-57B02E6C007B}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D3F045A-9870-CF55-CF30-851993A3AF6F}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D7C2D84-2B00-146D-CAF2-38E8743204A2}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9FC428-C242-144C-B27B-F27F0CC116BE}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E367784-F4CD-00AD-8490-A4619B7AAF21}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{513E86B0-D516-B255-E656-DEF35121232E}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51704C8A-007A-8362-32D7-C2EE36CE9214}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{521B84C2-EFEB-DC8C-B02A-9089847972E1}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56602600-9335-D10F-A0C5-C6602AA24FD3}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5742F79A-1D91-42C4-990C-B46CF55A6478}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{58A18AE6-6FAA-D8C2-14DB-4B8800933F55}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59708803-B475-5C15-39AD-7A1D62317282}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BCE8A80-9FA3-A229-B315-13932E0AA5D8}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{605B61F1-324E-B844-52EA-08A764AA37D9}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{605BB929-10FB-81EB-196F-7822E1EA2567}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60B33657-9E08-DEB2-4980-97C2352D4AEF}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{624D0ED6-FBD6-D488-B435-B1E924C175C0}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6259AAB6-979D-83C5-B2DB-ABC95EA1C8B2}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66E7A648-A2D0-B506-715E-8D564D8364C2}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68258D5A-F48D-99E0-FFBF-35C3BFB74C94}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A9852CC-FCBB-61A5-41A1-2EDA8230AEC5}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6BFC7DB0-C871-9935-DEC2-92E086CE9435}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D5064E5-DB4F-986D-4AD0-EC06E8821EA9}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7070A8F9-08A4-CA47-0AB0-1EB9E4EE1F3B}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7363BA68-FA5B-4BC9-8DEF-84263F54F53D}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{741EF1A1-D9CC-94D4-0B32-52C18D0ED509}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77E35B59-5DBF-CA0F-2037-00B52E21E874}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{791E9324-130C-DB07-16B3-102D31B10114}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7B30F33D-4323-2428-D014-8BE0A8C8C8ED}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C461C96-0310-49FA-767A-6D27FEB941E6}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7D6BFD31-52A5-44A7-6A16-E14766D2A648}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8227E624-0D80-2ABA-0149-6F487ADE838B}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{826B2228-BC09-49F2-B5F8-42CE26B1B712}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8327E127-2658-4B06-86B0-8D575DE1575B}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84AA3CA6-585D-1802-BCC6-20C398800817}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{869819CE-8035-1170-64C2-6EE1E98B3458}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87680A9A-4595-032D-4F84-B593061B9FC5}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8795D063-4F75-198C-F00B-C7FF75B8735D}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{882631A5-5AE7-4F3B-DA2D-18C71F0FDF23}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{89DA6847-5449-92CF-67AA-38AE4BD6F831}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8F6B33B6-05DF-FAF4-C592-388E843E5ADB}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{904C63F5-2041-CB09-DEEA-722D9B6F8DEF}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{904D6A45-F3FF-1A6D-7B1D-0DB4E2E1F3E7}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90965649-8DEF-CF3B-37E1-4CB76DC73681}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90B46B07-282D-8DDE-D296-452CDBB0603B}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90C2CAE8-913A-DBA5-AC8E-D0896D0378CA}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92CDA6FC-1C7D-E1DC-676E-761A6ECC0847}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98A9B656-1029-E870-F0CD-CA151569B86D}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9A8F5394-C42E-426F-B539-E4F44D9C9347}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E1A8018-A9B5-1BCD-91E7-FC63C21F3EAF}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E2E0AAF-55CD-8D02-957C-C88F3AC0AE90}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6480CF-41D5-ADA6-566E-13AE9287A0CD}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A0B5AE4D-89E5-F22A-060E-06256A646F77}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A2BEDD84-A226-805F-8E96-0121145966E2}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00311}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00401}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5366673-E8CA-11D3-9CD9-0090271D075B}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6AB0709-374D-2F77-3E70-0DE0910A9568}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7FA3C2B-428C-A94F-686F-2252E4F3A02C}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A9A674BF-771F-42E5-A440-D20DDA85A862}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA0A9B7C-1E92-535C-0904-539590028603}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA21D960-C084-D85E-9E3A-1D4E146F5773}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB9D62B8-7E56-2DB3-A516-E377F1010DCD}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B063B761-34B8-42D9-CBCD-08B0A1D3E8D4}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B1EA2010-07E4-3D19-B07F-C5DA991481C8}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4A7D9ED-89B3-E958-4A80-16026C986728}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B6007EAD-B9FB-819A-9125-AF6A6A50A711}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9D90B27-AD4A-413A-88CB-3E6DDC10DC2D}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BEF00307-0846-75C4-B6F5-84A949B91F47}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C3D292B4-683A-18D1-852B-943823CD81BF}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C448539A-1A24-DCB9-3152-D2DCA94E1831}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C500B6E9-8A37-3168-2346-44B58FB04FA8}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C643F570-05B9-FEDB-D764-AC5B786D4B39}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C97FF6D5-D8E9-6EAE-0F99-AC588DF99F9C}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CB9BF6D5-EA1D-0B43-F3D0-8964A6728480}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CDF3AE9D-4F8C-67BC-66A6-A9252CCD81A1}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0CEC06E-821E-9959-CABB-8F52B1005BA8}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D572A88C-5F1B-7EFE-45C7-5E070937FBFC}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DB29A986-131A-F212-4C89-18F9E42C205A}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DD6F50C0-9F8F-A41C-291E-7B3FB818EF18}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DEFC684A-30AD-8E93-CC49-E8F76A63D101}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DFD57175-D4E1-532D-8EE9-D8E60D7C3992}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e2ddf680-9905-4dee-8c64-0a5de7fe133c}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E2E6C0E2-FA3A-8992-181C-3BA9E7ED6D56}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E32E2C23-F6D7-0593-005D-8AE4C8C742A8}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E38ED9F3-91EA-355E-5715-27B3113CA15D}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E3BB58FA-9E29-5453-8515-DD85FF9C16C7}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6510F00-8D63-A5DF-5C50-00AE920791E7}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E66BEB61-721E-FA12-3F4B-CC71F7910CF0}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6F23682-174F-AF3C-0738-3DEF6F7B9091}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E72EF259-0958-844E-2249-322BFBF6B069}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E902A02C-DD59-5DE4-624F-8012F9AFA9B9}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E97E5AE0-29D6-7DFA-7E92-29CC5D770DA3}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EAF521EB-5513-475B-B2B3-4D4B1195A1B0}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EB230940-8256-ABD5-52BD-BE5EBE5DA35B}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE7178C-BBC3-4153-9DDE-CD0E9AB1B5B6}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F21BD77E-0CCE-C6CD-4F85-AA3B7895988E}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9567894-1E9F-4452-79FF-F795A197EFBA}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC2593E3-3E5A-410F-AF3D-82613CCE58E5}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC90281A-715F-5453-5E27-FF1B02AE0DA5}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD7786C4-36BE-9F97-70B6-B4EF1D3FBA8B}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fd9bc004-8331-4457-b830-4759ff704c22}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FEB58C92-D119-8F66-A8FA-72D46A544DA9}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF52FC75-302C-5DED-C090-F77905337D75}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF731508-CD28-E0B0-3E85-0CF55FDE9FBA} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing CWS Homepage Hijacker:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-2124.blogspot.com/2009/02/fdosretrace-dos.html"&gt;Remove FDoS.Retrace DoS&lt;/a&gt;&lt;br/&gt;&lt;a href="http://kill-computer-virus.blogspot.com/2009/01/cufrab-downloader.html"&gt;Cufrab Downloader Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-51.blogspot.com/2009/01/aolselide-trojan.html"&gt;AOL.Selide Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-62.blogspot.com/2009/01/vxidlbbm-trojan.html"&gt;Vxidl.BBM Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-23.blogspot.com/2009/01/helwix-trojan.html"&gt;Helwix Trojan Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3666474844277632920?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3666474844277632920/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3666474844277632920' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3666474844277632920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3666474844277632920'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/cws-homepage-hijacker-hijacker.html' title='CWS Homepage Hijacker Hijacker'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-9028314948236665842</id><published>2009-02-03T01:40:00.001-08:00</published><updated>2009-02-03T01:40:06.473-08:00</updated><title type='text'>Banker.anv Spyware</title><content type='html'>Removing Banker.anv &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Spyware&lt;br/&gt;&lt;em&gt;Spyware can even change computer settings, resulting in slow connection speeds,&lt;br /&gt;different home pages, and loss of Internet or other programs.&lt;br /&gt;In an attempt to increase the understanding of spyware, a more formal classification&lt;br /&gt;of its included software types is captured under the term privacy-invasive software.        &lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\media\winework.exe&lt;br/&gt;[%WINDOWS%]\media\winework.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Banker.anv:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\media\winework.exe&lt;br/&gt;[%WINDOWS%]\media\winework.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Banker.anv:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-88.blogspot.com/2009/01/warpigsc-trojan.html"&gt;WarPigs.C Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://malware-list-info.blogspot.com/2009/02/term-trojan.html"&gt;Term Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-05.blogspot.com/2009/02/wordmacroeraser-trojan.html"&gt;Remove WordMacro.Eraser Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-33.blogspot.com/2009/01/bancosied-trojan.html"&gt;Remove Bancos.IED Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-9028314948236665842?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/9028314948236665842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=9028314948236665842' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/9028314948236665842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/9028314948236665842'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/bankeranv-spyware.html' title='Banker.anv Spyware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-4817176901254735855</id><published>2009-02-03T01:12:00.001-08:00</published><updated>2009-02-03T01:12:13.300-08:00</updated><title type='text'>AdClicker.Oddbot Adware</title><content type='html'>Removing AdClicker.Oddbot &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\CCFDV.DLL&lt;br/&gt;[%SYSTEM%]\nodeipproc.dll&lt;br/&gt;[%SYSTEM%]\CCFDV.DLL&lt;br/&gt;[%SYSTEM%]\nodeipproc.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect AdClicker.Oddbot:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\CCFDV.DLL&lt;br/&gt;[%SYSTEM%]\nodeipproc.dll&lt;br/&gt;[%SYSTEM%]\CCFDV.DLL&lt;br/&gt;[%SYSTEM%]\nodeipproc.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\interface\{251df512-6faf-4aaf-bf19-d99b5f1c9250}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{2b896072-f6e3-4ff7-ade6-43d5bec6557c}&lt;br/&gt;HKEY_CLASSES_ROOT\oddbot.adclicker&lt;br/&gt;HKEY_CLASSES_ROOT\oddbot.adclicker.1&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2b896072-f6e3-4ff7-ade6-43d5bec6557c} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\nodeipproc&lt;br/&gt;HKEY_LOCAL_MACHINE\software\nodeipproc&lt;br/&gt;HKEY_LOCAL_MACHINE\software\nodeipproc &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing AdClicker.Oddbot:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-57.blogspot.com/2009/01/bufalobot-trojan.html"&gt;BufaloBot Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-36.blogspot.com/2009/01/evasivekeylog-trojan.html"&gt;Evasive.KeyLog Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-60.blogspot.com/2009/01/remove-rat.html"&gt;Remove RAT Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-4817176901254735855?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/4817176901254735855/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=4817176901254735855' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4817176901254735855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4817176901254735855'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/adclickeroddbot-adware.html' title='AdClicker.Oddbot Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-4187884576953317639</id><published>2009-02-03T01:08:00.001-08:00</published><updated>2009-02-03T01:08:21.377-08:00</updated><title type='text'>VB.tf Trojan</title><content type='html'>Removing VB.tf &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\win3208160-15319522006.exe&lt;br/&gt;[%WINDOWS%]\win3208160-15319522006.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect VB.tf:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\win3208160-15319522006.exe&lt;br/&gt;[%WINDOWS%]\win3208160-15319522006.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing VB.tf:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-63.blogspot.com/2009/01/rahack-trojan.html"&gt;Rahack Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://malwarepedia-protect-listing.blogspot.com/2009/01/benuti-trojan.html"&gt;Benuti Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-4345.blogspot.com/2009/01/vulwingar-downloader.html"&gt;Vulwingar Downloader Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://ridethe-pc-info.blogspot.com/2009/01/bancosgnd-trojan.html"&gt;Removing Bancos.GND Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-4187884576953317639?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/4187884576953317639/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=4187884576953317639' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4187884576953317639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4187884576953317639'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/vbtf-trojan.html' title='VB.tf Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-460927171287612313</id><published>2009-02-03T01:03:00.001-08:00</published><updated>2009-02-03T01:03:42.440-08:00</updated><title type='text'>PWS.Banker.gen.bu Trojan</title><content type='html'>Removing PWS.Banker.gen.bu &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;PWS.Banker.gen.bu Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[McAfee]PWS-Banker.gen.bu;&lt;br/&gt;[Panda]Trj/Banker.IBT;&lt;br/&gt;[Other]Infostealer.Banker.D,Trojan.Nethell,VirTool:Win32/Obfuscator.C&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\w1m.dll&lt;br/&gt;[%SYSTEM%]\w1m.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect PWS.Banker.gen.bu:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\w1m.dll&lt;br/&gt;[%SYSTEM%]\w1m.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{b3056695-ce91-404e-bd3b-62a4a3e6adfd}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{b3056695-ce91-404e-bd3b-62a4a3e6adfd} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing PWS.Banker.gen.bu:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-69.blogspot.com/2009/01/sensi-worm.html"&gt;SenSi Worm Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-78.blogspot.com/2009/01/y3kremoteadministrationtoolpro-backdoor_19.html"&gt;Y3K.Remote.Administration.Tool.Pro Backdoor Information&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-460927171287612313?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/460927171287612313/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=460927171287612313' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/460927171287612313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/460927171287612313'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/pwsbankergenbu-trojan.html' title='PWS.Banker.gen.bu Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3445303647356437042</id><published>2009-02-03T00:51:00.001-08:00</published><updated>2009-02-03T00:51:42.424-08:00</updated><title type='text'>Win Trojan</title><content type='html'>Removing Win &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Hacker Tool,Downloader&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;Hacker Tools are designed to penetrate remote computers&lt;br /&gt;in order to use them as zombies or to download other malicious programs to computer.&lt;br/&gt;This family of Trojans &lt;strong&gt;downloads and installs new malware or adware on the computer&lt;/strong&gt;.&lt;br /&gt;The downloader then either launches the new malware or registers it to enable autorun&lt;br /&gt;according to the local operating system requirements.&lt;br/&gt;&lt;br /&gt;The names and locations of malware to be downloaded are either coded into the&lt;br /&gt;Trojan or downloaded from a specified website.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Win Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Panda]Trj/Crack;&lt;br/&gt;[Computer Associates]Win/183935&lt;/code&gt;  &lt;p&gt;&lt;h2&gt;How to detect Win:&lt;/h2&gt;&lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\winsniffer &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\winsniffer&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\win sniffer 1.2 &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing Win:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-63.blogspot.com/2009/01/hundredpc-trojan.html"&gt;HundredPC Trojan Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3445303647356437042?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3445303647356437042/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3445303647356437042' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3445303647356437042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3445303647356437042'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/win-trojan.html' title='Win Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-810992417012467656</id><published>2009-02-03T00:47:00.001-08:00</published><updated>2009-02-03T00:47:31.117-08:00</updated><title type='text'>Cobfinn Trojan</title><content type='html'>Removing Cobfinn &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Cobfinn Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Backdoor.Win32.ShBot.a,Backdoor.Win32.ShBot.b;&lt;br/&gt;[McAfee]BackDoor-CYL;&lt;br/&gt;[Other]Win32/Cobfinn.I,Backdoor.Shellbot,BackDoor-CYL,Win32/Cobfinn.H&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\svchctrl.dll&lt;br/&gt;[%WINDOWS%]\system\svchctrl.exe&lt;br/&gt;[%WINDOWS%]\system\svchostw.dll&lt;br/&gt;[%WINDOWS%]\system\svchostw.exe&lt;br/&gt;[%WINDOWS%]\system\svchctrl.dll&lt;br/&gt;[%WINDOWS%]\system\svchctrl.exe&lt;br/&gt;[%WINDOWS%]\system\svchostw.dll&lt;br/&gt;[%WINDOWS%]\system\svchostw.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Cobfinn:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\svchctrl.dll&lt;br/&gt;[%WINDOWS%]\system\svchctrl.exe&lt;br/&gt;[%WINDOWS%]\system\svchostw.dll&lt;br/&gt;[%WINDOWS%]\system\svchostw.exe&lt;br/&gt;[%WINDOWS%]\system\svchctrl.dll&lt;br/&gt;[%WINDOWS%]\system\svchctrl.exe&lt;br/&gt;[%WINDOWS%]\system\svchostw.dll&lt;br/&gt;[%WINDOWS%]\system\svchostw.exe &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellbotr&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellbot &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Cobfinn:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-66.blogspot.com/2009/01/pigeonavec-trojan.html"&gt;Pigeon.AVEC Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-81.blogspot.com/2009/01/paszczus-trojan.html"&gt;Paszczus Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://remove-listing-pc.blogspot.com/2009/01/sillydlcof-trojan.html"&gt;SillyDl.COF Trojan Symptoms&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-810992417012467656?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/810992417012467656/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=810992417012467656' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/810992417012467656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/810992417012467656'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/cobfinn-trojan.html' title='Cobfinn Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-2129385190532381408</id><published>2009-02-03T00:31:00.001-08:00</published><updated>2009-02-03T00:31:24.941-08:00</updated><title type='text'>Kzmmultitv.class Trojan</title><content type='html'>Removing Kzmmultitv.class &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%APPDATA%]\Sun\Java\Deployment\cache\6.0\27\3966f95b-1c21ba47&lt;br/&gt;[%APPDATA%]\Sun\Java\Deployment\cache\javapi\v1.0\file\KzmMultiTV.class-32126837-2a334ffd.class&lt;br/&gt;[%APPDATA%]\Sun\Java\Deployment\cache\6.0\27\3966f95b-1c21ba47&lt;br/&gt;[%APPDATA%]\Sun\Java\Deployment\cache\javapi\v1.0\file\KzmMultiTV.class-32126837-2a334ffd.class &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Kzmmultitv.class:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%APPDATA%]\Sun\Java\Deployment\cache\6.0\27\3966f95b-1c21ba47&lt;br/&gt;[%APPDATA%]\Sun\Java\Deployment\cache\javapi\v1.0\file\KzmMultiTV.class-32126837-2a334ffd.class&lt;br/&gt;[%APPDATA%]\Sun\Java\Deployment\cache\6.0\27\3966f95b-1c21ba47&lt;br/&gt;[%APPDATA%]\Sun\Java\Deployment\cache\javapi\v1.0\file\KzmMultiTV.class-32126837-2a334ffd.class &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Kzmmultitv.class:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-description-blog.blogspot.com/2009/01/backdoorslackbot-backdoor.html"&gt;Backdoor.Slackbot Backdoor Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://malware-list-info.blogspot.com/2009/01/puddy-trojan.html"&gt;Removing Puddy Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-2129385190532381408?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/2129385190532381408/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=2129385190532381408' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2129385190532381408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2129385190532381408'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/kzmmultitvclass-trojan.html' title='Kzmmultitv.class Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-5863697268029325642</id><published>2009-02-02T22:27:00.001-08:00</published><updated>2009-02-02T22:27:40.221-08:00</updated><title type='text'>MS06 Trojan</title><content type='html'>Removing MS06 &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Hacker Tool&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;Exploits use vulnerabilities in operating systems and applications to achieve the same result.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;MS06 Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Other]VBS/MS06-014!exploit&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%INTERNET_CACHE%]\Content.IE5\45AV45Q3\count[3].htm&lt;br/&gt;[%INTERNET_CACHE%]\Content.IE5\C3RVUOH5\count[1].htm&lt;br/&gt;[%INTERNET_CACHE%]\Content.IE5\45AV45Q3\count[3].htm&lt;br/&gt;[%INTERNET_CACHE%]\Content.IE5\C3RVUOH5\count[1].htm &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect MS06:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%INTERNET_CACHE%]\Content.IE5\45AV45Q3\count[3].htm&lt;br/&gt;[%INTERNET_CACHE%]\Content.IE5\C3RVUOH5\count[1].htm&lt;br/&gt;[%INTERNET_CACHE%]\Content.IE5\45AV45Q3\count[3].htm&lt;br/&gt;[%INTERNET_CACHE%]\Content.IE5\C3RVUOH5\count[1].htm &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing MS06:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-70.blogspot.com/2009/01/pigeondsg-trojan.html"&gt;Pigeon.DSG Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-97.blogspot.com/2009/01/lithiumserver-backdoor.html"&gt;Lithium.server Backdoor Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-3335.blogspot.com/2009/02/pigeonavau-trojan.html"&gt;Pigeon.AVAU Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-95.blogspot.com/2009/01/satcah-trojan.html"&gt;Satcah Trojan Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-5863697268029325642?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/5863697268029325642/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=5863697268029325642' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5863697268029325642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5863697268029325642'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/ms06-trojan.html' title='MS06 Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7471467836550610446</id><published>2009-02-02T22:03:00.001-08:00</published><updated>2009-02-02T22:03:47.449-08:00</updated><title type='text'>SillyDl.DLK Trojan</title><content type='html'>Removing SillyDl.DLK &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\ctfmona.exe&lt;br/&gt;[%SYSTEM%]\ctfmona.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect SillyDl.DLK:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\ctfmona.exe&lt;br/&gt;[%SYSTEM%]\ctfmona.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\software notifier&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing SillyDl.DLK:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://info-blog-protect.blogspot.com/2009/01/fawx-dos.html"&gt;Fawx DoS Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://spyware-list-infections.blogspot.com/2009/01/intellitracker-tracking-cookie.html"&gt;Intelli.tracker Tracking Cookie Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-0610.blogspot.com/2009/01/180search-assistant-spyware.html"&gt;180Search Assistant Spyware Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-13.blogspot.com/2009/01/trojandownloaderwin32swizzorbh.html"&gt;TrojanDownloader.Win32.Swizzor.bh Downloader Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7471467836550610446?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7471467836550610446/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7471467836550610446' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7471467836550610446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7471467836550610446'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/sillydldlk-trojan.html' title='SillyDl.DLK Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7122397782736418826</id><published>2009-02-02T21:43:00.001-08:00</published><updated>2009-02-02T21:43:22.766-08:00</updated><title type='text'>Jakposh Trojan</title><content type='html'>Removing Jakposh &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Hijacker&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;A desktop hijacker replaces the desktop wallpaper with advertising&lt;br /&gt;for products and services on the desktop.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Jakposh Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Trojan-Clicker.Win32.Agent.hz;&lt;br/&gt;[McAfee]Adware-LugSearch;&lt;br/&gt;[F-Prot]W32/Trojan.AGCF;&lt;br/&gt;[Other]Trojan.Jakposh,Troj/Agent-DMT,Win32/Jakposh.C,Trojan.Adclicker,TrojanClicker:Win32/Agent!4276&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\82541744.dll&lt;br/&gt;[%SYSTEM%]\82541744.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Jakposh:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\82541744.dll&lt;br/&gt;[%SYSTEM%]\82541744.dll &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Jakposh:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://keylogger-listing-protection.blogspot.com/2009/01/vxidlbee-trojan.html"&gt;Removing Vxidl.BEE Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://malware-list-info.blogspot.com/2009/01/lyusane-trojan.html"&gt;Removing Lyusane Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-0444.blogspot.com/2009/01/bdirect-trojan.html"&gt;BDirect Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-4529.blogspot.com/2009/02/vb11176-trojan.html"&gt;Removing VB11176 Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-53.blogspot.com/2009/01/zdl-trojan.html"&gt;Zdl Trojan Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7122397782736418826?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7122397782736418826/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7122397782736418826' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7122397782736418826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7122397782736418826'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/jakposh-trojan.html' title='Jakposh Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-1630489648296356272</id><published>2009-02-02T21:31:00.001-08:00</published><updated>2009-02-02T21:31:50.999-08:00</updated><title type='text'>Crystalys.Media Toolbar</title><content type='html'>Removing Crystalys.Media &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Toolbar&lt;br/&gt;&lt;em&gt;Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect Crystalys.Media:&lt;/h2&gt;&lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\Crystalys Media &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\crystalys media internet assistant &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media&lt;br/&gt;HKEY_LOCAL_MACHINE\software\crystalys media &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Crystalys.Media:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://info-blog-protect.blogspot.com/2009/01/bancosgfj-trojan.html"&gt;Removing Bancos.GFJ Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-25.blogspot.com/2009/02/bancoshko-trojan.html"&gt;Bancos.HKO Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://viruslist-malware-infections.blogspot.com/2009/01/esyndicate-adware.html"&gt;Removing ESyndicate Adware&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-64.blogspot.com/2009/01/ircaladinz-backdoor_22.html"&gt;Removing IRC.Aladinz Backdoor&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-1630489648296356272?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/1630489648296356272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=1630489648296356272' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1630489648296356272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1630489648296356272'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/crystalysmedia-toolbar.html' title='Crystalys.Media Toolbar'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-2842564897315310577</id><published>2009-02-02T20:31:00.001-08:00</published><updated>2009-02-02T20:31:17.772-08:00</updated><title type='text'>Messenger.Blocker Ransomware</title><content type='html'>Removing Messenger.Blocker &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Ransomware&lt;br/&gt;&lt;em&gt;A &lt;strong&gt;cryptovirus, cryptotrojan or cryptoworm&lt;/strong&gt; is a type of&lt;br /&gt;malware that encrypts the data belonging to an individual on a computer,&lt;br /&gt;demanding a ransom for its restoration.&lt;br/&gt;&lt;br /&gt;The term ransomware is commonly used to describe software that encrypts the data&lt;br /&gt;belonging to an individual on a computer, demanding a ransom for its restoration.&lt;br /&gt;Although the field known as cryptovirology predates the term "ransomware".&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%FAVORITES%]\Messenger Blocker.url&lt;br/&gt;[%FAVORITES%]\Messenger Blocker.url &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Messenger.Blocker:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%FAVORITES%]\Messenger Blocker.url&lt;br/&gt;[%FAVORITES%]\Messenger Blocker.url &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%COMMON_PROGRAMS%]\Messenger Blocker&lt;br/&gt;[%PROGRAM_FILES%]\MBlocker &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Messenger.Blocker:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-87.blogspot.com/2009/01/agentbj-downloader.html"&gt;Removing Agent.bj Downloader&lt;/a&gt;&lt;br/&gt;&lt;a href="http://viruslist-malware-infections.blogspot.com/2009/01/vxidlavh-trojan.html"&gt;Removing Vxidl.AVH Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-2842564897315310577?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/2842564897315310577/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=2842564897315310577' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2842564897315310577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2842564897315310577'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/messengerblocker-ransomware.html' title='Messenger.Blocker Ransomware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-8780737561893441281</id><published>2009-02-02T20:27:00.001-08:00</published><updated>2009-02-02T20:27:43.125-08:00</updated><title type='text'>Winlogon Malware Malware</title><content type='html'>Removing Winlogon Malware &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Malware&lt;br/&gt;&lt;em&gt;Malware includes a range of programs that do not threaten computers directly,&lt;br /&gt;but are used to create viruses or Trojans, or used to carry out illegal activities&lt;br /&gt;such as DoS attacks and breaking into other computers.        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\explorer.dll&lt;br/&gt;[%SYSTEM%]\iexplorer.dll&lt;br/&gt;[%SYSTEM%]\j40s0ed7eh0.dll&lt;br/&gt;[%SYSTEM%]\req.dat&lt;br/&gt;[%SYSTEM%]\ssldr32.dll&lt;br/&gt;[%SYSTEM%]\winbug32.dll&lt;br/&gt;[%SYSTEM%]\wineil32.dll&lt;br/&gt;[%SYSTEM%]\winfon32.dll&lt;br/&gt;[%SYSTEM%]\wingsa32.dll&lt;br/&gt;[%SYSTEM%]\winhab32.dll&lt;br/&gt;[%SYSTEM%]\winhfp32.dll&lt;br/&gt;[%SYSTEM%]\winjgf32.dll&lt;br/&gt;[%SYSTEM%]\winmmt32.dll&lt;br/&gt;[%SYSTEM%]\winowl32.dll&lt;br/&gt;[%SYSTEM%]\winpsa32.dll&lt;br/&gt;[%SYSTEM%]\winrge32.dll&lt;br/&gt;[%SYSTEM%]\wintts32.dll&lt;br/&gt;[%SYSTEM%]\winvhi32.dll&lt;br/&gt;[%SYSTEM%]\winwly32.dll&lt;br/&gt;[%SYSTEM%]\winysc32.dll&lt;br/&gt;[%SYSTEM%]\winzwr32.dll&lt;br/&gt;[%SYSTEM%]\yvpp01.dll&lt;br/&gt;[%WINDOWS%]\$NtUninstallKB823559$\run.dll&lt;br/&gt;[%SYSTEM%]\explorer.dll&lt;br/&gt;[%SYSTEM%]\iexplorer.dll&lt;br/&gt;[%SYSTEM%]\j40s0ed7eh0.dll&lt;br/&gt;[%SYSTEM%]\req.dat&lt;br/&gt;[%SYSTEM%]\ssldr32.dll&lt;br/&gt;[%SYSTEM%]\winbug32.dll&lt;br/&gt;[%SYSTEM%]\wineil32.dll&lt;br/&gt;[%SYSTEM%]\winfon32.dll&lt;br/&gt;[%SYSTEM%]\wingsa32.dll&lt;br/&gt;[%SYSTEM%]\winhab32.dll&lt;br/&gt;[%SYSTEM%]\winhfp32.dll&lt;br/&gt;[%SYSTEM%]\winjgf32.dll&lt;br/&gt;[%SYSTEM%]\winmmt32.dll&lt;br/&gt;[%SYSTEM%]\winowl32.dll&lt;br/&gt;[%SYSTEM%]\winpsa32.dll&lt;br/&gt;[%SYSTEM%]\winrge32.dll&lt;br/&gt;[%SYSTEM%]\wintts32.dll&lt;br/&gt;[%SYSTEM%]\winvhi32.dll&lt;br/&gt;[%SYSTEM%]\winwly32.dll&lt;br/&gt;[%SYSTEM%]\winysc32.dll&lt;br/&gt;[%SYSTEM%]\winzwr32.dll&lt;br/&gt;[%SYSTEM%]\yvpp01.dll&lt;br/&gt;[%WINDOWS%]\$NtUninstallKB823559$\run.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Winlogon Malware:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\explorer.dll&lt;br/&gt;[%SYSTEM%]\iexplorer.dll&lt;br/&gt;[%SYSTEM%]\j40s0ed7eh0.dll&lt;br/&gt;[%SYSTEM%]\req.dat&lt;br/&gt;[%SYSTEM%]\ssldr32.dll&lt;br/&gt;[%SYSTEM%]\winbug32.dll&lt;br/&gt;[%SYSTEM%]\wineil32.dll&lt;br/&gt;[%SYSTEM%]\winfon32.dll&lt;br/&gt;[%SYSTEM%]\wingsa32.dll&lt;br/&gt;[%SYSTEM%]\winhab32.dll&lt;br/&gt;[%SYSTEM%]\winhfp32.dll&lt;br/&gt;[%SYSTEM%]\winjgf32.dll&lt;br/&gt;[%SYSTEM%]\winmmt32.dll&lt;br/&gt;[%SYSTEM%]\winowl32.dll&lt;br/&gt;[%SYSTEM%]\winpsa32.dll&lt;br/&gt;[%SYSTEM%]\winrge32.dll&lt;br/&gt;[%SYSTEM%]\wintts32.dll&lt;br/&gt;[%SYSTEM%]\winvhi32.dll&lt;br/&gt;[%SYSTEM%]\winwly32.dll&lt;br/&gt;[%SYSTEM%]\winysc32.dll&lt;br/&gt;[%SYSTEM%]\winzwr32.dll&lt;br/&gt;[%SYSTEM%]\yvpp01.dll&lt;br/&gt;[%WINDOWS%]\$NtUninstallKB823559$\run.dll&lt;br/&gt;[%SYSTEM%]\explorer.dll&lt;br/&gt;[%SYSTEM%]\iexplorer.dll&lt;br/&gt;[%SYSTEM%]\j40s0ed7eh0.dll&lt;br/&gt;[%SYSTEM%]\req.dat&lt;br/&gt;[%SYSTEM%]\ssldr32.dll&lt;br/&gt;[%SYSTEM%]\winbug32.dll&lt;br/&gt;[%SYSTEM%]\wineil32.dll&lt;br/&gt;[%SYSTEM%]\winfon32.dll&lt;br/&gt;[%SYSTEM%]\wingsa32.dll&lt;br/&gt;[%SYSTEM%]\winhab32.dll&lt;br/&gt;[%SYSTEM%]\winhfp32.dll&lt;br/&gt;[%SYSTEM%]\winjgf32.dll&lt;br/&gt;[%SYSTEM%]\winmmt32.dll&lt;br/&gt;[%SYSTEM%]\winowl32.dll&lt;br/&gt;[%SYSTEM%]\winpsa32.dll&lt;br/&gt;[%SYSTEM%]\winrge32.dll&lt;br/&gt;[%SYSTEM%]\wintts32.dll&lt;br/&gt;[%SYSTEM%]\winvhi32.dll&lt;br/&gt;[%SYSTEM%]\winwly32.dll&lt;br/&gt;[%SYSTEM%]\winysc32.dll&lt;br/&gt;[%SYSTEM%]\winzwr32.dll&lt;br/&gt;[%SYSTEM%]\yvpp01.dll&lt;br/&gt;[%WINDOWS%]\$NtUninstallKB823559$\run.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\artm_newreg&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\browsela&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\debugg&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\directpt&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\explorer&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Extensions&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gatexkey&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gdiwxp&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gs&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Hints&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\hpprintx&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\htproc&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ideusr50&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iexplorer&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\lanH32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msgnap&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msupdate&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OemStartMenuData&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pptp16&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Reliability&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\req&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Run&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunOnce&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunOnceEx&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensSrv&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\seppgs&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SharedDlls&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellServiceObjectDelayLoad&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssldr&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\st3&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\URL&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vistax&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\welcome&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winbug32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WindowsUpdate&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wineil32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winfon32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wingsa32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winhab32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winhfp32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winjgf32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winjyp32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkvh32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmfu32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmhw32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmiu32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmmt32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winnjx32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winowl32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winpsa32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrge32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrgq32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrnt32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrvc32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winsdr32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winstu32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wintfj32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wintts32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winuns32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winuqw32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winvhi32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winwil32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winwly32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winxtn32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winysc32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winzdn32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winzwr32&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ydsvgd&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\yvpp01 &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing Winlogon Malware:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-88.blogspot.com/2009/01/sillydlcfr-trojan.html"&gt;Removing SillyDl.CFR Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-59.blogspot.com/2009/01/pigeonadn-trojan.html"&gt;Pigeon.ADN Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-81.blogspot.com/2009/01/vbfk-trojan.html"&gt;VB.fk Trojan Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-8780737561893441281?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/8780737561893441281/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=8780737561893441281' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8780737561893441281'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8780737561893441281'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/winlogon-malware-malware.html' title='Winlogon Malware Malware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-618215720402340612</id><published>2009-02-02T19:19:00.001-08:00</published><updated>2009-02-02T19:19:13.260-08:00</updated><title type='text'>TX Adware</title><content type='html'>Removing TX &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware,BHO,RAT&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br/&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\apphelp32.dll&lt;br/&gt;[%SYSTEM%]\asferror32.dll&lt;br/&gt;[%SYSTEM%]\asycfilt32.dll&lt;br/&gt;[%SYSTEM%]\athprxy32.dll&lt;br/&gt;[%SYSTEM%]\ati2dvaa32.dll&lt;br/&gt;[%SYSTEM%]\ati2dvag32.dll&lt;br/&gt;[%SYSTEM%]\audiosrv32.dll&lt;br/&gt;[%SYSTEM%]\autodisc32.dll&lt;br/&gt;[%SYSTEM%]\avifile32.dll&lt;br/&gt;[%SYSTEM%]\avisynthex32.dll&lt;br/&gt;[%SYSTEM%]\aviwrap32.dll&lt;br/&gt;[%SYSTEM%]\browserad.dll&lt;br/&gt;[%WINDOWS%]\system\apphelp32.dll&lt;br/&gt;[%WINDOWS%]\system\asferror32.dll&lt;br/&gt;[%WINDOWS%]\system\asycfilt32.dll&lt;br/&gt;[%WINDOWS%]\system\athprxy32.dll&lt;br/&gt;[%WINDOWS%]\system\ati2dvaa32.dll&lt;br/&gt;[%WINDOWS%]\system\ati2dvag32.dll&lt;br/&gt;[%WINDOWS%]\system\audiosrv32.dll&lt;br/&gt;[%WINDOWS%]\system\autodisc32.dll&lt;br/&gt;[%WINDOWS%]\system\avifile32.dll&lt;br/&gt;[%WINDOWS%]\system\avisynthex32.dll&lt;br/&gt;[%WINDOWS%]\system\aviwrap32.dll&lt;br/&gt;[%WINDOWS%]\system\browserad.dll&lt;br/&gt;[%SYSTEM%]\apphelp32.dll&lt;br/&gt;[%SYSTEM%]\asferror32.dll&lt;br/&gt;[%SYSTEM%]\asycfilt32.dll&lt;br/&gt;[%SYSTEM%]\athprxy32.dll&lt;br/&gt;[%SYSTEM%]\ati2dvaa32.dll&lt;br/&gt;[%SYSTEM%]\ati2dvag32.dll&lt;br/&gt;[%SYSTEM%]\audiosrv32.dll&lt;br/&gt;[%SYSTEM%]\autodisc32.dll&lt;br/&gt;[%SYSTEM%]\avifile32.dll&lt;br/&gt;[%SYSTEM%]\avisynthex32.dll&lt;br/&gt;[%SYSTEM%]\aviwrap32.dll&lt;br/&gt;[%SYSTEM%]\browserad.dll&lt;br/&gt;[%WINDOWS%]\system\apphelp32.dll&lt;br/&gt;[%WINDOWS%]\system\asferror32.dll&lt;br/&gt;[%WINDOWS%]\system\asycfilt32.dll&lt;br/&gt;[%WINDOWS%]\system\athprxy32.dll&lt;br/&gt;[%WINDOWS%]\system\ati2dvaa32.dll&lt;br/&gt;[%WINDOWS%]\system\ati2dvag32.dll&lt;br/&gt;[%WINDOWS%]\system\audiosrv32.dll&lt;br/&gt;[%WINDOWS%]\system\autodisc32.dll&lt;br/&gt;[%WINDOWS%]\system\avifile32.dll&lt;br/&gt;[%WINDOWS%]\system\avisynthex32.dll&lt;br/&gt;[%WINDOWS%]\system\aviwrap32.dll&lt;br/&gt;[%WINDOWS%]\system\browserad.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect TX:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\apphelp32.dll&lt;br/&gt;[%SYSTEM%]\asferror32.dll&lt;br/&gt;[%SYSTEM%]\asycfilt32.dll&lt;br/&gt;[%SYSTEM%]\athprxy32.dll&lt;br/&gt;[%SYSTEM%]\ati2dvaa32.dll&lt;br/&gt;[%SYSTEM%]\ati2dvag32.dll&lt;br/&gt;[%SYSTEM%]\audiosrv32.dll&lt;br/&gt;[%SYSTEM%]\autodisc32.dll&lt;br/&gt;[%SYSTEM%]\avifile32.dll&lt;br/&gt;[%SYSTEM%]\avisynthex32.dll&lt;br/&gt;[%SYSTEM%]\aviwrap32.dll&lt;br/&gt;[%SYSTEM%]\browserad.dll&lt;br/&gt;[%WINDOWS%]\system\apphelp32.dll&lt;br/&gt;[%WINDOWS%]\system\asferror32.dll&lt;br/&gt;[%WINDOWS%]\system\asycfilt32.dll&lt;br/&gt;[%WINDOWS%]\system\athprxy32.dll&lt;br/&gt;[%WINDOWS%]\system\ati2dvaa32.dll&lt;br/&gt;[%WINDOWS%]\system\ati2dvag32.dll&lt;br/&gt;[%WINDOWS%]\system\audiosrv32.dll&lt;br/&gt;[%WINDOWS%]\system\autodisc32.dll&lt;br/&gt;[%WINDOWS%]\system\avifile32.dll&lt;br/&gt;[%WINDOWS%]\system\avisynthex32.dll&lt;br/&gt;[%WINDOWS%]\system\aviwrap32.dll&lt;br/&gt;[%WINDOWS%]\system\browserad.dll&lt;br/&gt;[%SYSTEM%]\apphelp32.dll&lt;br/&gt;[%SYSTEM%]\asferror32.dll&lt;br/&gt;[%SYSTEM%]\asycfilt32.dll&lt;br/&gt;[%SYSTEM%]\athprxy32.dll&lt;br/&gt;[%SYSTEM%]\ati2dvaa32.dll&lt;br/&gt;[%SYSTEM%]\ati2dvag32.dll&lt;br/&gt;[%SYSTEM%]\audiosrv32.dll&lt;br/&gt;[%SYSTEM%]\autodisc32.dll&lt;br/&gt;[%SYSTEM%]\avifile32.dll&lt;br/&gt;[%SYSTEM%]\avisynthex32.dll&lt;br/&gt;[%SYSTEM%]\aviwrap32.dll&lt;br/&gt;[%SYSTEM%]\browserad.dll&lt;br/&gt;[%WINDOWS%]\system\apphelp32.dll&lt;br/&gt;[%WINDOWS%]\system\asferror32.dll&lt;br/&gt;[%WINDOWS%]\system\asycfilt32.dll&lt;br/&gt;[%WINDOWS%]\system\athprxy32.dll&lt;br/&gt;[%WINDOWS%]\system\ati2dvaa32.dll&lt;br/&gt;[%WINDOWS%]\system\ati2dvag32.dll&lt;br/&gt;[%WINDOWS%]\system\audiosrv32.dll&lt;br/&gt;[%WINDOWS%]\system\autodisc32.dll&lt;br/&gt;[%WINDOWS%]\system\avifile32.dll&lt;br/&gt;[%WINDOWS%]\system\avisynthex32.dll&lt;br/&gt;[%WINDOWS%]\system\aviwrap32.dll&lt;br/&gt;[%WINDOWS%]\system\browserad.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0000-5dfc-5652-1705043f6518}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0000-7ebf-57c6-0bae047ea682}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0001-0345-2280-0287f27a63ee}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0001-1dbe-075a-39ec04bd88af}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0001-f7a6-1f38-0204019e355e}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0002-53d4-0622-35ea0235778e}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0008-d357-0798-004401965d4a}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0009-1c42-7d61-6cff050894a7}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0015-bd9c-263a-493001ba0c6c}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0033-c1ac-0e62-0c1f0537605d}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-008c-1e65-6aa6-3a270279f027}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-00fa-71ed-4aba-348801baa0a9}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{00000000-0c95-b1f8-547a-405204d6961a}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{00387fb8-4a60-5f01-44bf-1e5143bd1781}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0000-5dfc-5652-1705043f6518}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0000-7ebf-57c6-0bae047ea682}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0001-0345-2280-0287f27a63ee}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0001-1dbe-075a-39ec04bd88af}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0001-f7a6-1f38-0204019e355e}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0002-53d4-0622-35ea0235778e}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0008-d357-0798-004401965d4a}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0009-1c42-7d61-6cff050894a7}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0015-bd9c-263a-493001ba0c6c}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0033-c1ac-0e62-0c1f0537605d}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-008c-1e65-6aa6-3a270279f027}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-00fa-71ed-4aba-348801baa0a9}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0c95-b1f8-547a-405204d6961a}&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{1e5534b7-22be-2828-4397-5fb302849962}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0000-5dfc-5652-1705043f6518}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0000-7ebf-57c6-0bae047ea682}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0001-0345-2280-0287f27a63ee}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0001-1dbe-075a-39ec04bd88af}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0001-f7a6-1f38-0204019e355e}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0002-53d4-0622-35ea0235778e}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0008-d357-0798-004401965d4a}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0009-1c42-7d61-6cff050894a7}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0015-bd9c-263a-493001ba0c6c}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0033-c1ac-0e62-0c1f0537605d}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-008c-1e65-6aa6-3a270279f027}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-00fa-71ed-4aba-348801baa0a9}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0c95-b1f8-547a-405204d6961a}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0000-5dfc-5652-1705043f6518}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0000-7ebf-57c6-0bae047ea682}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0001-0345-2280-0287f27a63ee}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0001-1dbe-075a-39ec04bd88af}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0001-f7a6-1f38-0204019e355e}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0002-53d4-0622-35ea0235778e}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0008-d357-0798-004401965d4a}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0009-1c42-7d61-6cff050894a7}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0015-bd9c-263a-493001ba0c6c}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0033-c1ac-0e62-0c1f0537605d}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-008c-1e65-6aa6-3a270279f027}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-00fa-71ed-4aba-348801baa0a9}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0c95-b1f8-547a-405204d6961a} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing TX:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-45.blogspot.com/2009/01/dagger-backdoor.html"&gt;Dagger Backdoor Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://ridethe-pc-info.blogspot.com/2009/01/viennafog-trojan.html"&gt;Vienna.Fog Trojan Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-618215720402340612?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/618215720402340612/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=618215720402340612' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/618215720402340612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/618215720402340612'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/tx-adware.html' title='TX Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6188808265304598931</id><published>2009-02-02T19:00:00.001-08:00</published><updated>2009-02-02T19:00:18.752-08:00</updated><title type='text'>AgoBot.ST Worm</title><content type='html'>Removing AgoBot.ST &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Worm&lt;br/&gt;&lt;em&gt;Worms can be classified according to the propagation method they use,&lt;br /&gt;i.e. how they deliver copies of themselves to new victim machines.&lt;br /&gt;Worms can also be classified by installation method, launch method and finally according&lt;br /&gt;to characteristics standard to all malware: polymorphism, stealth etc.&lt;br/&gt;&lt;br /&gt;Many of the worms which managed to cause significant outbreaks use more then&lt;br /&gt;one propagation method as well as more than one infection technique.&lt;br /&gt;The methods are listed separately below.&lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect AgoBot.ST:&lt;/h2&gt;&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing AgoBot.ST:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-3329.blogspot.com/2009/01/pigeonavur-trojan.html"&gt;Pigeon.AVUR Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-01.blogspot.com/2009/02/pigeonemg-trojan.html"&gt;Pigeon.EMG Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-81.blogspot.com/2009/01/bancosgjb-trojan.html"&gt;Bancos.GJB Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-26.blogspot.com/2009/01/medbannercom-tracking-cookie.html"&gt;Removing medbanner.com Tracking Cookie&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6188808265304598931?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6188808265304598931/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6188808265304598931' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6188808265304598931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6188808265304598931'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/agobotst-worm.html' title='AgoBot.ST Worm'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-720675588670275620</id><published>2009-02-02T18:09:00.001-08:00</published><updated>2009-02-02T18:09:24.436-08:00</updated><title type='text'>Pcclient Trojan</title><content type='html'>Removing Pcclient &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Backdoor&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;Backdoors are used by virus writers to detect and download confidential information,&lt;br /&gt;execute malicious code, destroy data, include the machine in bot networks and so forth.&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Pcclient Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Trojan.Win32.Pakes,Backdoor.Win32.PcClient.gg,Backdoor.Win32.Pcclient.ty,Backdoor.Win32.PCClient.vr,Backdoor.Win32.Pcclient.ii,Backdoor.Win32.PcClient.fc,Backdoor.Win32.PcClient.wi,Backdoor.Win32.PcClient.aai;&lt;br/&gt;[Eset]Win32/PcClient.B trojan;&lt;br/&gt;[McAfee]BackDoor-CKB,Backdoor-CKB.gen;&lt;br/&gt;[Computer Associates]Win32.Pcclient.B,Win32/PcClient.Trojan;&lt;br/&gt;[Other]Win32/Pcclient.BA,Win32/PcClient.GG!Trojan,Backdoor.Formador,Troj/Bckdr-HRX,Win32/Pcclient.BD,win32/Pcclient.BC,Win32/Pcclient!generic,Win32/Pcclient.BJ,Backdoor.Pcclient.B,Win32/Pcclient.BH,Win32/Pcclient.BO,Win32.Pcclient.CD&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%RECYCLER%]\autorun.exe&lt;br/&gt;[%SYSTEM%]\autorun3.exe&lt;br/&gt;[%SYSTEM%]\KOfcpfwSvcs.exe&lt;br/&gt;[%SYSTEM%]\OfcpfwSvcs.exe&lt;br/&gt;[%DESKTOP%]\My Lockbox.lnk&lt;br/&gt;[%PROGRAM_FILES%]\xerox\folderlockbox.exe&lt;br/&gt;[%SYSTEM%]\drivers\mprifl.sys&lt;br/&gt;[%SYSTEM%]\drivers\Yrfzvmec.sys&lt;br/&gt;[%SYSTEM%]\Xubkmwau.d1l&lt;br/&gt;[%SYSTEM%]\Xubkmwau.sys&lt;br/&gt;[%SYSTEM%]\Yrfzvmec.d1l&lt;br/&gt;[%RECYCLER%]\autorun.exe&lt;br/&gt;[%SYSTEM%]\autorun3.exe&lt;br/&gt;[%SYSTEM%]\KOfcpfwSvcs.exe&lt;br/&gt;[%SYSTEM%]\OfcpfwSvcs.exe&lt;br/&gt;[%DESKTOP%]\My Lockbox.lnk&lt;br/&gt;[%PROGRAM_FILES%]\xerox\folderlockbox.exe&lt;br/&gt;[%SYSTEM%]\drivers\mprifl.sys&lt;br/&gt;[%SYSTEM%]\drivers\Yrfzvmec.sys&lt;br/&gt;[%SYSTEM%]\Xubkmwau.d1l&lt;br/&gt;[%SYSTEM%]\Xubkmwau.sys&lt;br/&gt;[%SYSTEM%]\Yrfzvmec.d1l &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Pcclient:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%RECYCLER%]\autorun.exe&lt;br/&gt;[%SYSTEM%]\autorun3.exe&lt;br/&gt;[%SYSTEM%]\KOfcpfwSvcs.exe&lt;br/&gt;[%SYSTEM%]\OfcpfwSvcs.exe&lt;br/&gt;[%DESKTOP%]\My Lockbox.lnk&lt;br/&gt;[%PROGRAM_FILES%]\xerox\folderlockbox.exe&lt;br/&gt;[%SYSTEM%]\drivers\mprifl.sys&lt;br/&gt;[%SYSTEM%]\drivers\Yrfzvmec.sys&lt;br/&gt;[%SYSTEM%]\Xubkmwau.d1l&lt;br/&gt;[%SYSTEM%]\Xubkmwau.sys&lt;br/&gt;[%SYSTEM%]\Yrfzvmec.d1l&lt;br/&gt;[%RECYCLER%]\autorun.exe&lt;br/&gt;[%SYSTEM%]\autorun3.exe&lt;br/&gt;[%SYSTEM%]\KOfcpfwSvcs.exe&lt;br/&gt;[%SYSTEM%]\OfcpfwSvcs.exe&lt;br/&gt;[%DESKTOP%]\My Lockbox.lnk&lt;br/&gt;[%PROGRAM_FILES%]\xerox\folderlockbox.exe&lt;br/&gt;[%SYSTEM%]\drivers\mprifl.sys&lt;br/&gt;[%SYSTEM%]\drivers\Yrfzvmec.sys&lt;br/&gt;[%SYSTEM%]\Xubkmwau.d1l&lt;br/&gt;[%SYSTEM%]\Xubkmwau.sys&lt;br/&gt;[%SYSTEM%]\Yrfzvmec.d1l &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\Folder Lockbox&lt;br/&gt;[%PROGRAMS%]\My Lockbox&lt;br/&gt;[%PROGRAM_FILES%]\Folder Lockbox&lt;br/&gt;[%PROGRAM_FILES%]\My Lockbox &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{1627e1fe-69fa-4943-9d87-2a40de9075bf}&lt;br/&gt;HKEY_CLASSES_ROOT\flockbox.dochostuihandler&lt;br/&gt;HKEY_CURRENT_USER\software\fspro labs\folder lockbox&lt;br/&gt;HKEY_LOCAL_MACHINE\software\fspro labs\folder lockbox&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\folder lockbox_is1&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\my lockbox_is1&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_mprifl&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_yrfzvmec&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mprifl&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\xubkmwau&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\yrfzvmec &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Pcclient:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-30.blogspot.com/2009/01/exitwinpredator-trojan.html"&gt;Exit.Win.Predator Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://computer-protect-virus.blogspot.com/2009/02/pigeonavfm-trojan.html"&gt;Remove Pigeon.AVFM Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-720675588670275620?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/720675588670275620/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=720675588670275620' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/720675588670275620'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/720675588670275620'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/pcclient-trojan.html' title='Pcclient Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6863919600839481125</id><published>2009-02-02T17:16:00.001-08:00</published><updated>2009-02-02T17:16:44.463-08:00</updated><title type='text'>NewAds Adware</title><content type='html'>Removing NewAds &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\BattyRun.dll&lt;br/&gt;[%SYSTEM%]\BattyRun.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect NewAds:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\BattyRun.dll&lt;br/&gt;[%SYSTEM%]\BattyRun.dll &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\batty&lt;br/&gt;[%PROGRAM_FILES%]\AdSponsor&lt;br/&gt;[%PROGRAM_FILES%]\Exolon&lt;br/&gt;[%PROGRAM_FILES%]\PSupport &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\adband.bandbho&lt;br/&gt;HKEY_CLASSES_ROOT\adband.bandbho.1&lt;br/&gt;HKEY_CLASSES_ROOT\adband.bandimpl&lt;br/&gt;HKEY_CLASSES_ROOT\adband.bandimpl.1&lt;br/&gt;HKEY_CLASSES_ROOT\appid\adband.dll&lt;br/&gt;HKEY_CLASSES_ROOT\appid\{36946a0a-05a1-4cf7-934b-270571338e55}&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{1b8b502e-455b-4022-be27-736d9f808a18}&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{d5599fae-28aa-4c2b-a29c-6c0cd5b245aa}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{04dcb17c-ab45-83ad-a86a-6dfb90277939}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{2bc9c452-bb57-4896-a9a2-64611e06c5aa}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{6ca1c00b-90fc-4f3e-911f-95306aba43aa}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{994d478a-45d0-4db4-ae28-738b1e346f99}&lt;br/&gt;HKEY_CURRENT_USER\software\adsponsor&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\ext\stats\{04dcb17c-ab45-83ad-a86a-6dfb90277939}&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\ext\stats\{6ca1c00b-90fc-4f3e-911f-95306aba43aa}&lt;br/&gt;HKEY_CURRENT_USER\software\padsysassistant&lt;br/&gt;HKEY_CURRENT_USER\software\psupport&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\explorer bars\{2bc9c452-bb57-4896-a9a2-64611e06c5aa}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{04dcb17c-ab45-83ad-a86a-6dfb90277939}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6ca1c00b-90fc-4f3e-911f-95306aba43aa}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\adsponsor &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\protocols\filter\text/html &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing NewAds:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-67.blogspot.com/2009/01/blubster-worm.html"&gt;Remove Blubster Worm&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-68.blogspot.com/2009/01/agobotad-trojan.html"&gt;Agobot.ad Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-39.blogspot.com/2009/01/sillydlczf-trojan.html"&gt;SillyDl.CZF Trojan Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6863919600839481125?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6863919600839481125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6863919600839481125' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6863919600839481125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6863919600839481125'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/newads-adware_02.html' title='NewAds Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3795735157735846383</id><published>2009-02-02T17:00:00.001-08:00</published><updated>2009-02-02T17:00:01.539-08:00</updated><title type='text'>Abetear Trojan</title><content type='html'>Removing Abetear &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Adware&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Abetear Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Trojan.Win32.Agent.aoy,Trojan.Win32.Agent.bck;&lt;br/&gt;[F-Prot]W32/Trojan.CGOY;&lt;br/&gt;[Other]Win32/Abetear.A,Trojan.Vundo,Trojan:Win32/Fotomoto.A,Win32/Abetear.B,W32/Agent.BUYH,Troj/Agent-FXL,Win32/Abetear.C,W32/Agent.BWQY,Win32/Abetear.G,Trojan:Win32/Agent.AGA,Troj/Bckdr-QJL,W32/Vundo.dam&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%APPDATA%]\tmp2.tmp.exe&lt;br/&gt;[%APPDATA%]\tmp4.tmp.exe&lt;br/&gt;[%SYSTEM%]\qwerty12.exe&lt;br/&gt;[%APPDATA%]\tmp2.tmp.exe&lt;br/&gt;[%APPDATA%]\tmp4.tmp.exe&lt;br/&gt;[%SYSTEM%]\qwerty12.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Abetear:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%APPDATA%]\tmp2.tmp.exe&lt;br/&gt;[%APPDATA%]\tmp4.tmp.exe&lt;br/&gt;[%SYSTEM%]\qwerty12.exe&lt;br/&gt;[%APPDATA%]\tmp2.tmp.exe&lt;br/&gt;[%APPDATA%]\tmp4.tmp.exe&lt;br/&gt;[%SYSTEM%]\qwerty12.exe &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\domainservice&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_domainservice&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\domainservice &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing Abetear:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-2044.blogspot.com/2009/02/angrychair-trojan.html"&gt;AngryChair Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojanpedia-infections-keylogger.blogspot.com/2009/01/oplads-trojan.html"&gt;Removing Oplads Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-2942.blogspot.com/2009/02/rauser-trojan.html"&gt;Rauser Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-4713.blogspot.com/2009/02/easysearch-adware.html"&gt;EasySearch Adware Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3795735157735846383?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3795735157735846383/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3795735157735846383' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3795735157735846383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3795735157735846383'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/abetear-trojan.html' title='Abetear Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3290826179712571033</id><published>2009-02-02T16:48:00.001-08:00</published><updated>2009-02-02T16:48:44.825-08:00</updated><title type='text'>Ofpo Trojan</title><content type='html'>Removing Ofpo &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Ofpo Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Rootkit.Win32.Agent.cf;&lt;br/&gt;[Other]WIn32/Ofpo,Hacktool.Rootkit,Win32.Ofpo.C&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\ntio256.sys&lt;br/&gt;[%SYSTEM%]\ntio256.sys&lt;br/&gt;[%SYSTEM%]\poof&lt;br/&gt;[%SYSTEM%]\ntio256.sys&lt;br/&gt;[%SYSTEM%]\ntio256.sys&lt;br/&gt;[%SYSTEM%]\poof &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Ofpo:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\ntio256.sys&lt;br/&gt;[%SYSTEM%]\ntio256.sys&lt;br/&gt;[%SYSTEM%]\poof&lt;br/&gt;[%SYSTEM%]\ntio256.sys&lt;br/&gt;[%SYSTEM%]\ntio256.sys&lt;br/&gt;[%SYSTEM%]\poof &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Ofpo:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-14.blogspot.com/2009/01/wonder-spyware.html"&gt;Wonder Spyware Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-19.blogspot.com/2009/01/wanderer-trojan.html"&gt;Wanderer Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-3526.blogspot.com/2009/01/unclassified-trojan.html"&gt;Removing Unclassified Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-16.blogspot.com/2009/01/bancosgps-trojan.html"&gt;Bancos.GPS Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-48.blogspot.com/2009/01/pswjiakong-trojan.html"&gt;Remove PSW.Jiakong Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3290826179712571033?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3290826179712571033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3290826179712571033' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3290826179712571033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3290826179712571033'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/ofpo-trojan.html' title='Ofpo Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3158068684511307046</id><published>2009-02-02T16:39:00.001-08:00</published><updated>2009-02-02T16:39:41.890-08:00</updated><title type='text'>Netster.Smart.Browse BHO</title><content type='html'>Removing Netster.Smart.Browse &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; BHO,Toolbar&lt;br/&gt;&lt;em&gt;As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and&lt;br /&gt;sent back to the attacker. &lt;br /&gt;Typically, keyloggers of this type will send the stolen information back to the attacker via email&lt;br /&gt;or HTTP POST, which can appear suspicious.Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROFILE%]\netster.dll&lt;br/&gt;[%SYSTEM%]\netster.dll&lt;br/&gt;[%SYSTEM%]\_netster.dll&lt;br/&gt;[%WINDOWS%]\system\netster.dll&lt;br/&gt;[%WINDOWS%]\system\_netster.dll&lt;br/&gt;[%PROFILE%]\netster.dll&lt;br/&gt;[%SYSTEM%]\netster.dll&lt;br/&gt;[%SYSTEM%]\_netster.dll&lt;br/&gt;[%WINDOWS%]\system\netster.dll&lt;br/&gt;[%WINDOWS%]\system\_netster.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Netster.Smart.Browse:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROFILE%]\netster.dll&lt;br/&gt;[%SYSTEM%]\netster.dll&lt;br/&gt;[%SYSTEM%]\_netster.dll&lt;br/&gt;[%WINDOWS%]\system\netster.dll&lt;br/&gt;[%WINDOWS%]\system\_netster.dll&lt;br/&gt;[%PROFILE%]\netster.dll&lt;br/&gt;[%SYSTEM%]\netster.dll&lt;br/&gt;[%SYSTEM%]\_netster.dll&lt;br/&gt;[%WINDOWS%]\system\netster.dll&lt;br/&gt;[%WINDOWS%]\system\_netster.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{359f7e49-1ea0-4671-92e9-61e32fe25c5e}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{856d6a8e-a24c-498a-a55a-2b25c606a6b4}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{acc63168-5876-439b-95bc-3bae59ca860c}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{b98f79f4-3619-49fb-a7e7-b737e58c5727}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{aa644580-8f8a-4f8b-9263-42e14c7c2fcb}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{b4fadc3f-7c5f-4fc8-a050-dbeb2c119dd5}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{eed9bcbf-d40e-408f-8080-e4afc9fddb36}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{f5619700-a76a-462b-abdd-6372ff10eab7}&lt;br/&gt;HKEY_CLASSES_ROOT\netster.bho&lt;br/&gt;HKEY_CLASSES_ROOT\netster.bho.1&lt;br/&gt;HKEY_CLASSES_ROOT\netster.initscript&lt;br/&gt;HKEY_CLASSES_ROOT\netster.initscript.1&lt;br/&gt;HKEY_CLASSES_ROOT\netster.netsterband&lt;br/&gt;HKEY_CLASSES_ROOT\netster.netsterband.1&lt;br/&gt;HKEY_CLASSES_ROOT\netster.netsterph&lt;br/&gt;HKEY_CLASSES_ROOT\netster.netsterph.1&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{b98f79f4-3619-49fb-a7e7-b737e58c5727}&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{e1c643a6-8b7b-4f28-b652-f712fe4f7402}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{856d6a8e-a24c-498a-a55a-2b25c606a6b4}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{b98f79f4-3619-49fb-a7e7-b737e58c5727}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{b98f79f4-3619-49fb-a7e7-b737e58c5727}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{856d6a8e-a24c-498a-a55a-2b25c606a6b4}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\netster &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Netster.Smart.Browse:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-21.blogspot.com/2009/01/sranda-trojan.html"&gt;Removing Sranda Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-67.blogspot.com/2009/01/dowqueaaj-trojan.html"&gt;Remove Dowque.AAJ Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://malware-info.blogspot.com/2009/01/lookup-adware.html"&gt;Lookup Adware Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-96.blogspot.com/2009/01/filebackup-hostile-code.html"&gt;File.Backup Hostile Code Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3158068684511307046?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3158068684511307046/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3158068684511307046' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3158068684511307046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3158068684511307046'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/netstersmartbrowse-bho.html' title='Netster.Smart.Browse BHO'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-2465969756963045989</id><published>2009-02-02T16:16:00.001-08:00</published><updated>2009-02-02T16:16:01.233-08:00</updated><title type='text'>WinFetcher Adware</title><content type='html'>Removing WinFetcher &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\WM_FUINS.bat&lt;br/&gt;[%PROFILE_TEMP%]\update_1.exe&lt;br/&gt;[%WINDOWS%]\temp\nr1beo9r.dll&lt;br/&gt;[%WINDOWS%]\temp\nr1beo9r.exe&lt;br/&gt;[%WINDOWS%]\temp\winwildapp.exe&lt;br/&gt;[%WINDOWS%]\temp\_istmp4.dir\_istmp0.dir\29389bdd.dll&lt;br/&gt;[%PROFILE_TEMP%]\WM_FUINS.bat&lt;br/&gt;[%PROFILE_TEMP%]\update_1.exe&lt;br/&gt;[%WINDOWS%]\temp\nr1beo9r.dll&lt;br/&gt;[%WINDOWS%]\temp\nr1beo9r.exe&lt;br/&gt;[%WINDOWS%]\temp\winwildapp.exe&lt;br/&gt;[%WINDOWS%]\temp\_istmp4.dir\_istmp0.dir\29389bdd.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect WinFetcher:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\WM_FUINS.bat&lt;br/&gt;[%PROFILE_TEMP%]\update_1.exe&lt;br/&gt;[%WINDOWS%]\temp\nr1beo9r.dll&lt;br/&gt;[%WINDOWS%]\temp\nr1beo9r.exe&lt;br/&gt;[%WINDOWS%]\temp\winwildapp.exe&lt;br/&gt;[%WINDOWS%]\temp\_istmp4.dir\_istmp0.dir\29389bdd.dll&lt;br/&gt;[%PROFILE_TEMP%]\WM_FUINS.bat&lt;br/&gt;[%PROFILE_TEMP%]\update_1.exe&lt;br/&gt;[%WINDOWS%]\temp\nr1beo9r.dll&lt;br/&gt;[%WINDOWS%]\temp\nr1beo9r.exe&lt;br/&gt;[%WINDOWS%]\temp\winwildapp.exe&lt;br/&gt;[%WINDOWS%]\temp\_istmp4.dir\_istmp0.dir\29389bdd.dll &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\winwildapp.exe &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\wildmedia &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing WinFetcher:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-42.blogspot.com/2009/01/vxidlbfn-trojan.html"&gt;Vxidl.BFN Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-92.blogspot.com/2009/01/agobotaz-trojan.html"&gt;Removing Agobot.az Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-2465969756963045989?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/2465969756963045989/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=2465969756963045989' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2465969756963045989'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2465969756963045989'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/winfetcher-adware.html' title='WinFetcher Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-5759594480680687679</id><published>2009-02-02T15:43:00.001-08:00</published><updated>2009-02-02T15:43:36.615-08:00</updated><title type='text'>Brave.A Trojan</title><content type='html'>Removing Brave.A &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\adirss.exe&lt;br/&gt;[%SYSTEM%]\adirss.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Brave.A:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\adirss.exe&lt;br/&gt;[%SYSTEM%]\adirss.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Brave.A:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojanpedia-infections-keylogger.blogspot.com/2009/01/bancoshgx-trojan.html"&gt;Bancos.HGX Trojan Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-5759594480680687679?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/5759594480680687679/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=5759594480680687679' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5759594480680687679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5759594480680687679'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/bravea-trojan.html' title='Brave.A Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7103133207859198184</id><published>2009-02-02T14:47:00.001-08:00</published><updated>2009-02-02T14:47:31.958-08:00</updated><title type='text'>WinADiscount Adware</title><content type='html'>Removing WinADiscount &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\adwin.exe&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\bundle.cfg&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\combosearch_button_1.acs&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\eraser001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\hide002.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\logo.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\movies001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\popupblocker002.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\search013.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\searchresults.xsl&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\shopping004.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\sk.ini&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\skbho.dll&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\uninstall001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\weather003.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\winadiscounttb0401.cfg&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\toolbar.ini&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\uninstall.exe&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\winadiscount.dll&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\adwin.exe&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\bundle.cfg&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\combosearch_button_1.acs&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\eraser001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\hide002.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\logo.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\movies001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\popupblocker002.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\search013.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\searchresults.xsl&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\shopping004.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\sk.ini&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\skbho.dll&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\uninstall001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\weather003.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\winadiscounttb0401.cfg&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\toolbar.ini&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\uninstall.exe&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\winadiscount.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect WinADiscount:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\adwin.exe&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\bundle.cfg&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\combosearch_button_1.acs&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\eraser001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\hide002.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\logo.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\movies001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\popupblocker002.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\search013.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\searchresults.xsl&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\shopping004.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\sk.ini&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\skbho.dll&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\uninstall001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\weather003.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\winadiscounttb0401.cfg&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\toolbar.ini&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\uninstall.exe&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\winadiscount.dll&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\adwin.exe&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\bundle.cfg&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\combosearch_button_1.acs&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\eraser001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\hide002.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\logo.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\movies001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\popupblocker002.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\search013.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\searchresults.xsl&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\shopping004.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\sk.ini&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\skbho.dll&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\uninstall001.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\weather003.bmp&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\winadiscounttb0401.cfg&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\toolbar.ini&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\uninstall.exe&lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\winadiscount.dll &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\winadiscount\cache\newcfg &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{4961a993-7f48-4c50-a30e-d597ac571707}&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount\config&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4961a993-7f48-4c50-a30e-d597ac571707}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4e7bd74f-2b8d-469e-87be-a334b786b339} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-87be-a334b786b339}\inprocserver32&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-87be-a334b786b33a}\inprocserver32&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-87be-a334b786b33b}\inprocserver32&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount\ages&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount\ages&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount\ages&lt;br/&gt;HKEY_CURRENT_USER\software\winadiscount\options&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\winadiscount&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\winadiscount &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing WinADiscount:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-98.blogspot.com/2009/02/inserviceja-downloader.html"&gt;INService.ja Downloader Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-19.blogspot.com/2009/01/toolband-bho.html"&gt;toolband BHO Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-57.blogspot.com/2009/01/stealthwebpagerecorder-spyware.html"&gt;Remove Stealth.Web.Page.Recorder Spyware&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7103133207859198184?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7103133207859198184/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7103133207859198184' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7103133207859198184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7103133207859198184'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/winadiscount-adware.html' title='WinADiscount Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6477539489030750992</id><published>2009-02-02T14:27:00.001-08:00</published><updated>2009-02-02T14:27:36.580-08:00</updated><title type='text'>KCGame RAT</title><content type='html'>Removing KCGame &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; RAT&lt;br/&gt;&lt;em&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\winsys.exe&lt;br/&gt;[%WINDOWS%]\system\y!.ocx&lt;br/&gt;[%WINDOWS%]\system\winsys.exe&lt;br/&gt;[%WINDOWS%]\system\y!.ocx &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect KCGame:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\winsys.exe&lt;br/&gt;[%WINDOWS%]\system\y!.ocx&lt;br/&gt;[%WINDOWS%]\system\winsys.exe&lt;br/&gt;[%WINDOWS%]\system\y!.ocx &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing KCGame:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-15.blogspot.com/2009/01/fakeloginforyahoo-trojan.html"&gt;Fake.login.for.Yahoo! Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-10.blogspot.com/2009/01/archive-trojan.html"&gt;Archive Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://malware-info.blogspot.com/2009/01/netcontrol-spyware.html"&gt;Removing NetControl Spyware&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-0108.blogspot.com/2009/01/vbsflood-trojan.html"&gt;VBS.Flood Trojan Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6477539489030750992?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6477539489030750992/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6477539489030750992' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6477539489030750992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6477539489030750992'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/kcgame-rat.html' title='KCGame RAT'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-8435206147165788152</id><published>2009-02-02T14:00:00.001-08:00</published><updated>2009-02-02T14:00:13.190-08:00</updated><title type='text'>AntiLamer Trojan</title><content type='html'>Removing AntiLamer &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Backdoor,RAT&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;strong&gt;Backdoors are the most dangerous type of Trojans&lt;/strong&gt; and the most popular.&lt;br /&gt;&lt;strong&gt;Backdoors open infected machines&lt;/strong&gt; to external control via Internet.&lt;br /&gt;They function in the same way as legal remote administration programs used by system administrators.&lt;br /&gt;This makes them difficult to detect.&lt;br/&gt;&lt;br /&gt;&lt;strong&gt;Backdoors&lt;/strong&gt; are installed and launched without the consent of the user of computer.&lt;br /&gt;Often the backdoor will not be visible in the log of active programs.&lt;br/&gt;&lt;br /&gt;Once a backdoor has been successfully launched, the computer is wide open.&lt;br /&gt;Backdoor functions can include:&lt;br/&gt;&lt;br /&gt;    &lt;ul&gt;&lt;br /&gt;    &lt;li&gt; Launching/ deleting files&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Sending/ receiving files&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Deleting data&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Displaying notification&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Rebooting the machine&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Executing files&lt;/li&gt;&lt;br /&gt;    &lt;/ul&gt;&lt;br /&gt;&lt;br/&gt;&lt;br /&gt;&lt;strong&gt;Backdoors are used by virus writers to detect and download confidential information&lt;/strong&gt;,&lt;br /&gt;execute malicious code, destroy data, include the machine in bot networks and so forth.&lt;br /&gt;Backdoors combine the functionality of most other types of  in one package.&lt;br/&gt;&lt;br /&gt;Backdoors have one especially dangerous sub-class: variants that can propagate like worms. &lt;br/&gt;Many trojans and backdoors now have &lt;strong&gt;remote administration capabilities&lt;/strong&gt;&lt;br /&gt;allowing an individual to control the victim's computer.&lt;br /&gt;Many times a file called the server must be opened on the victim's computer before&lt;br /&gt;the trojan can have access to it.&lt;br/&gt;&lt;br /&gt;These are generally sent through email, P2P file sharing software,&lt;br /&gt;and in internet downloads. They are usually disguised as a legitimate program or file.&lt;br /&gt;Many server files will display a fake error message when opened, to make it seem like it didn't open.&lt;br /&gt;Some will also kill antivirus and firewall software.&lt;br/&gt;&lt;br /&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,&lt;br /&gt;and swap mouse buttons. However, they can be quite hard to remove.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;AntiLamer Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Backdoor.Antilam.13.b,Backdoor.Antilam.14.a,Backdoor.Antilam.14.c,Backdoor.FC.a,TrojanDropper.Win32.ZomJoiner.10,Backdoor.Antilam.20.a,Backdoor.Antilam.20.k,Backdoor.Antilam.11,Backdoor.Antilam.g1,Backdoor.Antilam.20.l,Backdoor.Antilam.20.m,Backdoor.Antilam.14.b;&lt;br/&gt;[Eset]Win32/Antilam.13.B trojan,Win32/Antilam.14.A trojan,Win32/Antilam.14.C trojan,Win32/TrojanDropper.Antivirus.10 trojan,Win32/Antilam.20 trojan,Win32/Antilam.20.K trojan,Win32/Antilam.20.L trojan,Win32/Antilam.20.M trojan,Win32/Antilam.14.B trojan;&lt;br/&gt;[McAfee]BackDoor-AED,MultiDropper-DN.cfg,BackDoor-AJW;&lt;br/&gt;[F-Prot]security risk or a "backdoor" program,security risk named W32/AntiLam.B;&lt;br/&gt;[Panda]Backdoor Program,Bck/Antilam,Bck/AntiLam.14,Trojan Horse,Bck/Antilam.F;&lt;br/&gt;[Computer Associates]Backdoor/Latinus Server family,Win32.Antilam.13.B,Backdoor/Antilam.14.c,Win32.Antilam.14,Backdoor/Antilam.20,Backdoor/Antilam.20.k,Backdoor/AntiLamer Server family,Win32.Antilam.20,Backdoor/AntiLam,Backdoor/Antilam.20.m,Win32.Antilam.D,Win32/Antilam.14!Trojan&lt;/code&gt;  &lt;p&gt;&lt;h2&gt;How to detect AntiLamer:&lt;/h2&gt;&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing AntiLamer:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-23.blogspot.com/2009/01/advsearch-adware.html"&gt;AdvSearch Adware Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-40.blogspot.com/2009/01/aimwatch-trojan.html"&gt;AIM.Watch Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-04.blogspot.com/2009/01/nympho-trojan.html"&gt;Remove Nympho Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-51.blogspot.com/2009/01/pingserver-rat.html"&gt;Ping.Server RAT Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-47.blogspot.com/2009/01/pigeoneki-trojan.html"&gt;Removing Pigeon.EKI Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-8435206147165788152?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/8435206147165788152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=8435206147165788152' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8435206147165788152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8435206147165788152'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/antilamer-trojan.html' title='AntiLamer Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3618247311488063417</id><published>2009-02-02T13:35:00.001-08:00</published><updated>2009-02-02T13:35:38.405-08:00</updated><title type='text'>Deskbar Adware</title><content type='html'>Removing Deskbar &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware,Hijacker,Toolbar&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;strong&gt;Hijackers are software programs that modify users' default browser home page&lt;/strong&gt;,&lt;br /&gt;search settings, error page settings, or desktop wallpaper without adequate notice, disclosure,&lt;br /&gt;or user consent.&lt;br/&gt;&lt;br /&gt;When the default home page is hijacked, the browser opens to the web page set by the hijacker&lt;br /&gt;instead of the user's designated home page. In some cases, the hijacker may block users from&lt;br /&gt;restoring their desired home page.&lt;br/&gt;&lt;br /&gt;A &lt;strong&gt;search hijacker&lt;/strong&gt; redirects search results to other pages and may&lt;br /&gt;transmit search and browsing data to unknown servers. An error page hijacker directs&lt;br /&gt;the browser to another page, usually an advertising page, instead of the usual error&lt;br /&gt;page when the requested URL is not found.&lt;br/&gt;&lt;br /&gt;A &lt;strong&gt;desktop hijacker&lt;/strong&gt; replaces the desktop wallpaper with advertising&lt;br /&gt;for products and services on the desktop.&lt;br/&gt;&lt;br /&gt;Hijackers take control of various parts of your web browser, including your home page,&lt;br /&gt;search pages, and search bar. They may also redirect you to certain sites should you&lt;br /&gt;mistype an address or prevent you from going to a website they would rather you not,&lt;br /&gt;such as sites that combat malware. Some will even redirect you to their own search engine&lt;br /&gt;when you attempt a search. NB: hijackers almost exclusively target Internet Explorer.&lt;br/&gt;Toolbar presents itself as a &lt;strong&gt;helpful add-on for Internet Explorer&lt;/strong&gt; but it is a real pest.&lt;br /&gt;It replaces your start page, continuosly open a number of pop up windows and so on. &lt;br/&gt;       &lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Deskbar Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Other]desktop bar,Adware.Look2Me&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\SpyLocked 3.1.lnk&lt;br/&gt;[%DESKTOP%]\SpyLocked.lnk&lt;br/&gt;[%PROGRAM_FILES%]\DeskAlerts\deskbar.dll&lt;br/&gt;[%PROGRAM_FILES%]\Deskbar\deskbar.dll&lt;br/&gt;[%STARTMENU%]\SpyLocked 3.1.lnk&lt;br/&gt;[%SYSTEM%]\Deskbar\deskbar.dll&lt;br/&gt;[%SYSTEM%]\Favorites\deskbar.dll&lt;br/&gt;[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\SpyLocked 3.1.lnk&lt;br/&gt;[%DESKTOP%]\SpyLocked.lnk&lt;br/&gt;[%PROGRAM_FILES%]\DeskAlerts\deskbar.dll&lt;br/&gt;[%PROGRAM_FILES%]\Deskbar\deskbar.dll&lt;br/&gt;[%STARTMENU%]\SpyLocked 3.1.lnk&lt;br/&gt;[%SYSTEM%]\Deskbar\deskbar.dll&lt;br/&gt;[%SYSTEM%]\Favorites\deskbar.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Deskbar:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\SpyLocked 3.1.lnk&lt;br/&gt;[%DESKTOP%]\SpyLocked.lnk&lt;br/&gt;[%PROGRAM_FILES%]\DeskAlerts\deskbar.dll&lt;br/&gt;[%PROGRAM_FILES%]\Deskbar\deskbar.dll&lt;br/&gt;[%STARTMENU%]\SpyLocked 3.1.lnk&lt;br/&gt;[%SYSTEM%]\Deskbar\deskbar.dll&lt;br/&gt;[%SYSTEM%]\Favorites\deskbar.dll&lt;br/&gt;[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\SpyLocked 3.1.lnk&lt;br/&gt;[%DESKTOP%]\SpyLocked.lnk&lt;br/&gt;[%PROGRAM_FILES%]\DeskAlerts\deskbar.dll&lt;br/&gt;[%PROGRAM_FILES%]\Deskbar\deskbar.dll&lt;br/&gt;[%STARTMENU%]\SpyLocked 3.1.lnk&lt;br/&gt;[%SYSTEM%]\Deskbar\deskbar.dll&lt;br/&gt;[%SYSTEM%]\Favorites\deskbar.dll &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\SpyLocked&lt;br/&gt;[%PROGRAM_FILES%]\SpyLocked&lt;br/&gt;[%PROGRAM_FILES%]\Deskbar &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{1F101905-C9C7-4B92-BDE6-4F8E76C5A7DB}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{5121B863-FAE8-4935-BA76-0ABE0239AECA}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{652383EE-CA01-4aec-A763-50A08062AC58}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{65E03378-E22E-4F50-BE9D-588A889B24C9}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{67A8D847-B79F-403e-8D2B-D2CADE3A967F}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{69DACF5A-70EF-4363-A036-89450346121F}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{9DD77D09-901B-4af0-8F89-812950DB6FF2}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{a8b28872-3324-4cd2-8aa3-7d555c872d96}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{CC79522A-9E3B-4bc9-9218-D95EC5DA5349}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D06E2EAE-1922-4A0B-6A7C-8D9E3DE0E708}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2C5B5226-045D-4A46-B4FC-228B0891FEEC}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{314120E4-5A05-492C-9BF2-22558CF0F202}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{392D4A36-6ADF-4A99-A820-3014A53E62E3}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3BF6C840-4D12-4FB5-88A2-E2BC03461DC2}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{42F16135-D0A4-43A2-990C-27FCABD9C19F}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43DF1CEE-70B3-4E2D-A740-4AC468786207}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5CA1A9F6-10F8-4008-B884-755B25B6848A}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{630CBF61-54CC-4AC3-97B0-D4071345807C}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AFB5B8E-ACFD-4489-91B3-DAA1388A31EC}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{815B01A0-BF97-41E9-ACF2-32B76F98A960}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C5BF4465-5322-462F-B41F-459F649F3996}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E4703CF2-7F82-4AD7-B317-8EC1CBC9B619}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E9817993-83FF-4343-B14E-6CDFB378B21D}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EDE2A2B4-B1CB-4BF8-93D1-154E49284A71}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F5D23930-23C6-440E-AB55-D019E1171539}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{50450F27-B90B-422B-A4C9-5EC5A5B78001}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyLocked.exe&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1F101905-C9C7-4B92-BDE6-4F8E76C5A7DB}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5121B863-FAE8-4935-BA76-0ABE0239AECA}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{652383EE-CA01-4aec-A763-50A08062AC58}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{65E03378-E22E-4F50-BE9D-588A889B24C9}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67A8D847-B79F-403e-8D2B-D2CADE3A967F}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{69DACF5A-70EF-4363-A036-89450346121F}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9DD77D09-901B-4af0-8F89-812950DB6FF2}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A8B28872-3324-4CD2-8AA3-7D555C872D96}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC79522A-9E3B-4bc9-9218-D95EC5DA5349}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyLocked&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\SpyLocked&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{d7cc80d4-376c-4586-b023-4f35c2ceb28e}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{d8c2d4b4-eeaf-4ec4-b1f8-9b6ed15d5a38}&lt;br/&gt;HKEY_CLASSES_ROOT\dbtb00001.dbtb00001&lt;br/&gt;HKEY_CLASSES_ROOT\dbtb00001.dbtb00001.1&lt;br/&gt;HKEY_CLASSES_ROOT\dbtb00001.deskbar&lt;br/&gt;HKEY_CLASSES_ROOT\dbtb00001.deskbar.1&lt;br/&gt;HKEY_CLASSES_ROOT\dbtb00001.deskbarbho&lt;br/&gt;HKEY_CLASSES_ROOT\dbtb00001.deskbarbho.1&lt;br/&gt;HKEY_CLASSES_ROOT\dbtb00001.deskbarenabler&lt;br/&gt;HKEY_CLASSES_ROOT\dbtb00001.deskbarenabler.1&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{8f15b157-40d9-4b20-8d3b-b1f8b475b58d}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{a0881aa1-68be-41ac-9c0d-4c8a69c6c72c}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{e827ffd9-95d1-4b49-beb3-5d49e688c108}&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{a4c8f181-6cdb-4dcc-9fc9-bb9933c81e1f}&lt;br/&gt;HKEY_CURRENT_USER\software\dbtb00001&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a8b28872-3324-4cd2-8aa3-7d555c872d96}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\dbtb00001.dbtb00001deskbar &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Deskbar:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-62.blogspot.com/2009/01/palremover-ransomware.html"&gt;pal.remover Ransomware Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-4832.blogspot.com/2009/01/pcremotecontrol-rat.html"&gt;PC.Remote.Control RAT Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-3403.blogspot.com/2009/02/sillydlcpd-trojan.html"&gt;SillyDl.CPD Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-2228.blogspot.com/2009/01/haxspy-trojan.html"&gt;Remove Haxspy Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3618247311488063417?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3618247311488063417/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3618247311488063417' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3618247311488063417'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3618247311488063417'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/deskbar-adware.html' title='Deskbar Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3050804802928946447</id><published>2009-02-02T13:27:00.001-08:00</published><updated>2009-02-02T13:27:33.175-08:00</updated><title type='text'>Zlob.Fam.ProtectionBar Trojan</title><content type='html'>Removing Zlob.Fam.ProtectionBar &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Popups&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;Adware is the class of programs that &lt;strong&gt;place advertisements on your screen&lt;/strong&gt;.&lt;br /&gt;These may be in the form of pop-ups, pop-unders, advertisements embedded in programs,&lt;br /&gt;advertisements placed on top of ads in web sites, or any other way the authors can&lt;br /&gt;think of showing you an ad.&lt;br/&gt;&lt;br /&gt;The pop-ups generally will not be stopped by pop-up stoppers, and often are&lt;br /&gt;not dependent on your having Internet Explorer open.&lt;br /&gt;They may show up when you are playing a game, writing a document, listening to music,&lt;br /&gt;or anything else. Should you be surfing, the advertisements will often be related to&lt;br /&gt;the web page you are viewing.         &lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\Brain Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Gold Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Gold Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image Access ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image Access ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Access\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image AX Object\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image AX Object\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\IntCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Internet Security\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Internet Security\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\iVideoCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Media-Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Media-Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\MediaCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\MMediaCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\MMediaCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\PCODEC\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Perfect Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Perfect Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Protection Tools\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Protection Tools\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\QualityCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\QualityCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Security Tools\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\strCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\strCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\VidCodecs\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video Access ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video Access ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Access\iesbpl.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Access\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video AX Object\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video AX Object\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\VideoKeyCodec\isaddon.dll&lt;br/&gt;[%SYSTEM%]\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\Brain Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Gold Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Gold Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image Access ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image Access ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Access\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image AX Object\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image AX Object\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\IntCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Internet Security\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Internet Security\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\iVideoCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Media-Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Media-Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\MediaCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\MMediaCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\MMediaCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\PCODEC\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Perfect Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Perfect Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Protection Tools\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Protection Tools\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\QualityCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\QualityCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Security Tools\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\strCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\strCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\VidCodecs\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video Access ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video Access ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Access\iesbpl.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Access\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video AX Object\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video AX Object\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\VideoKeyCodec\isaddon.dll&lt;br/&gt;[%SYSTEM%]\iesplg.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Zlob.Fam.ProtectionBar:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\Brain Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Gold Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Gold Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image Access ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image Access ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Access\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image AX Object\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image AX Object\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\IntCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Internet Security\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Internet Security\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\iVideoCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Media-Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Media-Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\MediaCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\MMediaCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\MMediaCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\PCODEC\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Perfect Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Perfect Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Protection Tools\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Protection Tools\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\QualityCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\QualityCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Security Tools\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\strCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\strCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\VidCodecs\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video Access ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video Access ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Access\iesbpl.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Access\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video AX Object\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video AX Object\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\VideoKeyCodec\isaddon.dll&lt;br/&gt;[%SYSTEM%]\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\Brain Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Gold Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Gold Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image Access ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image Access ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Access\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image ActiveX Object\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image AX Object\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Image AX Object\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\IntCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Internet Security\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Internet Security\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\iVideoCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Key Generator\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Media-Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Media-Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\MediaCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\MMediaCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\MMediaCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\PCODEC\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Perfect Codec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Perfect Codec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Protection Tools\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Protection Tools\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\QualityCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\QualityCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Security Tools\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\strCodec\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\strCodec\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\VidCodecs\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video Access ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video Access ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Access\iesbpl.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Access\iesplg.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\iesplugin.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\isadd.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video ActiveX Object\isaddon.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video AX Object\bpvol.dll&lt;br/&gt;[%PROGRAM_FILES%]\Video AX Object\splug.dll&lt;br/&gt;[%PROGRAM_FILES%]\VideoKeyCodec\isaddon.dll&lt;br/&gt;[%SYSTEM%]\iesplg.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{184746EC-9E9D-4C7D-B9E7-9039EBD801A9}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{192c5b4a-3efd-40c7-9f99-c472deb8efc0}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{1a1ddc19-5893-43ab-a73f-f41a0f34d115}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{1a29a79a-b9c8-44a9-bedf-7fadde3cf33f}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{202a961f-23ae-42b1-9505-ffe3c818d717}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{274c0420-ebe0-4f1d-b473-edd1aa9b85dd}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{2810fba5-55ec-4bee-8263-0e2fa5883768}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{31615D5C-5126-448A-818A-A7CDFEE85A9B}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{36ADA89D-2440-4DC4-820A-3A05E8630935}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{44d22a64-2399-4edf-8b32-f2c729c1e8a7}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{4734044c-7427-43d8-adbe-df942e52bef2}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{479fd0cf-5be9-4c63-8cda-b6d371c67bd5}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{74a49269-9779-48b4-a0e6-3a5af2a3ade6}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{7A8F5B7A-A74F-495E-8A33-DF6226D2BAD8}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{7b4d79df-9ef0-429d-a0e9-d9b138c6a53b}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{84938242-5C5B-4A55-B6B9-A1507543B418}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{860c2f6b-ca82-4282-9187-beccbb66f0af}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{8aed5df3-6e0b-4930-b1a5-f8aa8d757497}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{8bf5b8fc-11cb-409f-8c91-4d4ca04a1b6d}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{96ebbe6a-2864-4345-b32b-26ee9be524b5}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{a2595f37-48d0-46a1-9b51-478591a97764}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{A6ACAE64-F798-4930-AD86-BD3FB32038DB}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{ae18da4e-be15-4925-81bb-890c04af0200}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{bf1ced2c-4b3f-4079-a330-864eda5a4cff}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{d1ac752e-883f-4ed8-8828-b618c3a72152}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{d869742a-e5d2-4624-96c7-aae26170665e}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{f7d40011-29bb-43eb-9c97-875ce89e9e36}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{fe2d25c1-c1db-4b5e-9390-af1cb5302f32}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta\{f7d40011-29bb-43eb-9c97-875ce89e9e36}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{184746EC-9E9D-4C7D-B9E7-9039EBD801A9}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{192c5b4a-3efd-40c7-9f99-c472deb8efc0}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1a1ddc19-5893-43ab-a73f-f41a0f34d115}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{202a961f-23ae-42b1-9505-ffe3c818d717}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{274c0420-ebe0-4f1d-b473-edd1aa9b85dd}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2810fba5-55ec-4bee-8263-0e2fa5883768}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{36ADA89D-2440-4DC4-820A-3A05E8630935}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4734044c-7427-43d8-adbe-df942e52bef2}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{479fd0cf-5be9-4c63-8cda-b6d371c67bd5}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7A8F5B7A-A74F-495E-8A33-DF6226D2BAD8}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7b4d79df-9ef0-429d-a0e9-d9b138c6a53b}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8bf5b8fc-11cb-409f-8c91-4d4ca04a1b6d}&lt;br/&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a2595f37-48d0-46a1-9b51-478591a97764}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6ACAE64-F798-4930-AD86-BD3FB32038DB}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ae18da4e-be15-4925-81bb-890c04af0200}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d869742a-e5d2-4624-96c7-aae26170665e}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f7d40011-29bb-43eb-9c97-875ce89e9e36}&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fe2d25c1-c1db-4b5e-9390-af1cb5302f32}&lt;br/&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On&lt;br/&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\PCODEC&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Zlob.Fam.ProtectionBar:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-83.blogspot.com/2009/01/win32incommander-trojan.html"&gt;Win32.InCommander Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://info-blog-protect.blogspot.com/2009/01/iebar-hijacker.html"&gt;IEBAR Hijacker Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://viruslist-a.blogspot.com/2009/01/pigeonehb-trojan.html"&gt;Pigeon.EHB Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-42.blogspot.com/2009/01/tequila-trojan.html"&gt;Removing Tequila Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3050804802928946447?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3050804802928946447/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3050804802928946447' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3050804802928946447'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3050804802928946447'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/zlobfamprotectionbar-trojan.html' title='Zlob.Fam.ProtectionBar Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-876563740074426422</id><published>2009-02-02T12:51:00.001-08:00</published><updated>2009-02-02T12:51:11.224-08:00</updated><title type='text'>Ebates.MoneyMaker Adware</title><content type='html'>Removing Ebates.MoneyMaker &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware,Hacker Tool&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        Hacker Tools are designed to penetrate remote computers&lt;br /&gt;in order to use them as zombies or to download other malicious programs to computer.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Ebates.MoneyMaker Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Panda]Adware/MoeMoney,Adware/TopMoxie,HackTool/Jkill.A&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\djebmm350.exe&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Ap350\psid399.dat&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_counv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_couyv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_non.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_nv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\pref350a_dis.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\scri350a.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\spec350a_yv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Sy350\350_0.dat&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Sy350\350_2.dat&lt;br/&gt;[%PROFILE_TEMP%]\THI11E0.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI2BE3.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI376A.tmp\MMaker4b.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI575D.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI76A.tmp\MMaker4b.exe&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\System\Code\o.class&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\System\Temp\couponsandoffers.exe&lt;br/&gt;[%PROGRAM_FILES%]\LimeShop\Popup.exe&lt;br/&gt;[%DESKTOP%]\earn money.lnk&lt;br/&gt;[%PROFILE_TEMP%]\ebatesmoemoneymaker.exe&lt;br/&gt;[%PROGRAM_FILES%]\care2gtu\popup.exe&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\couponsandoffers1.exe&lt;br/&gt;[%STARTMENU%]\casino.url&lt;br/&gt;[%WINDOWS%]\dkry.exe&lt;br/&gt;[%PROFILE_TEMP%]\djebmm350.exe&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Ap350\psid399.dat&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_counv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_couyv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_non.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_nv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\pref350a_dis.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\scri350a.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\spec350a_yv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Sy350\350_0.dat&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Sy350\350_2.dat&lt;br/&gt;[%PROFILE_TEMP%]\THI11E0.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI2BE3.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI376A.tmp\MMaker4b.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI575D.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI76A.tmp\MMaker4b.exe&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\System\Code\o.class&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\System\Temp\couponsandoffers.exe&lt;br/&gt;[%PROGRAM_FILES%]\LimeShop\Popup.exe&lt;br/&gt;[%DESKTOP%]\earn money.lnk&lt;br/&gt;[%PROFILE_TEMP%]\ebatesmoemoneymaker.exe&lt;br/&gt;[%PROGRAM_FILES%]\care2gtu\popup.exe&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\couponsandoffers1.exe&lt;br/&gt;[%STARTMENU%]\casino.url&lt;br/&gt;[%WINDOWS%]\dkry.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Ebates.MoneyMaker:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\djebmm350.exe&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Ap350\psid399.dat&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_counv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_couyv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_non.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_nv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\pref350a_dis.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\scri350a.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\spec350a_yv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Sy350\350_0.dat&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Sy350\350_2.dat&lt;br/&gt;[%PROFILE_TEMP%]\THI11E0.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI2BE3.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI376A.tmp\MMaker4b.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI575D.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI76A.tmp\MMaker4b.exe&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\System\Code\o.class&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\System\Temp\couponsandoffers.exe&lt;br/&gt;[%PROGRAM_FILES%]\LimeShop\Popup.exe&lt;br/&gt;[%DESKTOP%]\earn money.lnk&lt;br/&gt;[%PROFILE_TEMP%]\ebatesmoemoneymaker.exe&lt;br/&gt;[%PROGRAM_FILES%]\care2gtu\popup.exe&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\couponsandoffers1.exe&lt;br/&gt;[%STARTMENU%]\casino.url&lt;br/&gt;[%WINDOWS%]\dkry.exe&lt;br/&gt;[%PROFILE_TEMP%]\djebmm350.exe&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Ap350\psid399.dat&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_counv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_couyv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_non.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\popo350a_nv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\pref350a_dis.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\scri350a.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Html\spec350a_yv.htm&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Sy350\350_0.dat&lt;br/&gt;[%PROFILE_TEMP%]\temp.fr????\Sy350\Sy350\350_2.dat&lt;br/&gt;[%PROFILE_TEMP%]\THI11E0.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI2BE3.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI376A.tmp\MMaker4b.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI575D.tmp\TRebates.exe&lt;br/&gt;[%PROFILE_TEMP%]\THI76A.tmp\MMaker4b.exe&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\System\Code\o.class&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\System\Temp\couponsandoffers.exe&lt;br/&gt;[%PROGRAM_FILES%]\LimeShop\Popup.exe&lt;br/&gt;[%DESKTOP%]\earn money.lnk&lt;br/&gt;[%PROFILE_TEMP%]\ebatesmoemoneymaker.exe&lt;br/&gt;[%PROGRAM_FILES%]\care2gtu\popup.exe&lt;br/&gt;[%PROGRAM_FILES%]\couponsandoffers\couponsandoffers1.exe&lt;br/&gt;[%STARTMENU%]\casino.url&lt;br/&gt;[%WINDOWS%]\dkry.exe &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\ebatesmoemoneymaker&lt;br/&gt;[%PROGRAM_FILES%]\ebates_moemoneymaker&lt;br/&gt;[%PROGRAM_FILES%]\webrebates&lt;br/&gt;[%PROGRAM_FILES%]\websearch &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{6685509E-B47B-4f47-8E16-9A5F3A62F683}&lt;br/&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{7F241C00-DAB6-11d5-AAA8-0001028DF1BC}&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\ebates&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\ext\stats\{6685509e-b47b-4f47-8e16-9a5f3a62f683}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\ebatesver2.xml&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping\{6685509e-b47b-4f47-8e16-9a5f3a62f683}&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping\{7f241c00-dab6-11d5-aaa8-0001028df1bc}&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\{6685509e-b47b-4f47-8e16-9a5f3a62f683}&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\{7f241c00-dab6-11d5-aaa8-0001028df1bc}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ebatesver2.xml &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Ebates.MoneyMaker:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-0329.blogspot.com/2009/02/pigeonawy-trojan.html"&gt;Remove Pigeon.AWY Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-876563740074426422?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/876563740074426422/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=876563740074426422' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/876563740074426422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/876563740074426422'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/ebatesmoneymaker-adware.html' title='Ebates.MoneyMaker Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-1699750972366924265</id><published>2009-02-02T12:11:00.001-08:00</published><updated>2009-02-02T12:11:22.269-08:00</updated><title type='text'>Myss.Variant Adware</title><content type='html'>Removing Myss.Variant &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware,Spyware,Hijacker&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        Spyware is computer software that is installed surreptitiously on a personal computer&lt;br /&gt;to &lt;intercept or take partial control over the user's interaction&lt;br /&gt;with the computer, without the user's informed consent.&lt;br/&gt;A desktop hijacker replaces the desktop wallpaper with advertising&lt;br /&gt;for products and services on the desktop.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Myss.Variant Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Computer Associates]Win32/Myss.Variant!Trojan&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\spchost.exe&lt;br/&gt;[%SYSTEM%]\stfer32.dll&lt;br/&gt;[%WINDOWS%]\srchost.exe&lt;br/&gt;[%SYSTEM%]\spchost.exe&lt;br/&gt;[%SYSTEM%]\stfer32.dll&lt;br/&gt;[%WINDOWS%]\srchost.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Myss.Variant:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\spchost.exe&lt;br/&gt;[%SYSTEM%]\stfer32.dll&lt;br/&gt;[%WINDOWS%]\srchost.exe&lt;br/&gt;[%SYSTEM%]\spchost.exe&lt;br/&gt;[%SYSTEM%]\stfer32.dll&lt;br/&gt;[%WINDOWS%]\srchost.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Myss.Variant:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://protect-trojan-info.blogspot.com/2009/01/anticad-trojan.html"&gt;Anticad Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-16.blogspot.com/2009/01/win32botten-trojan.html"&gt;Win32.Botten Trojan Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-1699750972366924265?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/1699750972366924265/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=1699750972366924265' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1699750972366924265'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1699750972366924265'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/myssvariant-adware.html' title='Myss.Variant Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3317418002355553456</id><published>2009-02-02T12:00:00.001-08:00</published><updated>2009-02-02T12:00:09.380-08:00</updated><title type='text'>Procin Trojan</title><content type='html'>Removing Procin &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Procin Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Trojan-Spy.Win32.Sters.y;&lt;br/&gt;[Other]Win32/Procin.E,Infostealer&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\winlogon.exe&lt;br/&gt;[%WINDOWS%]\winlogon.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Procin:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\winlogon.exe&lt;br/&gt;[%WINDOWS%]\winlogon.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Procin:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://malwarepedia-protect-listing.blogspot.com/2009/01/litesocks-backdoor.html"&gt;Lite.SOCKS Backdoor Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3317418002355553456?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3317418002355553456/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3317418002355553456' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3317418002355553456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3317418002355553456'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/procin-trojan.html' title='Procin Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7653956863679617209</id><published>2009-02-02T11:23:00.001-08:00</published><updated>2009-02-02T11:23:21.853-08:00</updated><title type='text'>User.Logger Spyware</title><content type='html'>Removing User.Logger &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Spyware&lt;br/&gt;&lt;em&gt;Spyware can even change computer settings, resulting in slow connection speeds,&lt;br /&gt;different home pages, and loss of Internet or other programs.&lt;br /&gt;In an attempt to increase the understanding of spyware, a more formal classification&lt;br /&gt;of its included software types is captured under the term privacy-invasive software.        &lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect User.Logger:&lt;/h2&gt;&lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\User Logger&lt;br/&gt;[%PROGRAMS%]\User Logger &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\user logger_is1 &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing User.Logger:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-09.blogspot.com/2009/01/vxidlazz-trojan.html"&gt;Vxidl.AZZ Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://kill-computer-virus.blogspot.com/2009/01/security-toolbar.html"&gt;Removing Security Toolbar&lt;/a&gt;&lt;br/&gt;&lt;a href="http://viruslist-d.blogspot.com/2009/01/bancosfzu-trojan.html"&gt;Bancos.FZU Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-34.blogspot.com/2009/01/netdevilcginotify-trojan.html"&gt;Removing Net.Devil.CGI.Notify Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7653956863679617209?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7653956863679617209/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7653956863679617209' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7653956863679617209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7653956863679617209'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/userlogger-spyware.html' title='User.Logger Spyware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-5960071241734423261</id><published>2009-02-02T10:43:00.001-08:00</published><updated>2009-02-02T10:43:12.999-08:00</updated><title type='text'>BKW Trojan</title><content type='html'>Removing BKW &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;BKW Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[F-Prot]W32/TrojanX.ABXD;&lt;br/&gt;[Other]Trojan.Dropper,Malware.AWGD,TROJ_VB.FBV,Mal/Generic-A&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\RBvBm1066.exe&lt;br/&gt;[%SYSTEM%]\vMW03a\vMW03a1066.exe&lt;br/&gt;[%PROFILE_TEMP%]\RBvBm1066.exe&lt;br/&gt;[%SYSTEM%]\vMW03a\vMW03a1066.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect BKW:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\RBvBm1066.exe&lt;br/&gt;[%SYSTEM%]\vMW03a\vMW03a1066.exe&lt;br/&gt;[%PROFILE_TEMP%]\RBvBm1066.exe&lt;br/&gt;[%SYSTEM%]\vMW03a\vMW03a1066.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing BKW:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://kill-computer-virus.blogspot.com/2009/01/glieder-trojan.html"&gt;Glieder Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-27.blogspot.com/2009/01/cdenor-trojan_25.html"&gt;Cdenor Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-72.blogspot.com/2009/01/battiny-trojan.html"&gt;Bat.Tiny Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-36.blogspot.com/2009/01/internet-explorer-settings-hijacker.html"&gt;Remove Internet Explorer Settings Hijacker Hijacker&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-5960071241734423261?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/5960071241734423261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=5960071241734423261' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5960071241734423261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5960071241734423261'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/bkw-trojan.html' title='BKW Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-2295896620646696403</id><published>2009-02-02T08:03:00.001-08:00</published><updated>2009-02-02T08:03:07.594-08:00</updated><title type='text'>AdLogix.Zamingo BHO</title><content type='html'>Removing AdLogix.Zamingo &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; BHO&lt;br/&gt;&lt;em&gt;The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect AdLogix.Zamingo:&lt;/h2&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0b90aa1b-f649-44c3-9fd3-736c332cbbcf} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing AdLogix.Zamingo:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://details-pc-keylogger.blogspot.com/2009/01/webstatnet-tracking-cookie.html"&gt;webstat.net Tracking Cookie Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-58.blogspot.com/2009/01/tvi-backdoor.html"&gt;Removing TVI Backdoor&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-2295896620646696403?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/2295896620646696403/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=2295896620646696403' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2295896620646696403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2295896620646696403'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/adlogixzamingo-bho.html' title='AdLogix.Zamingo BHO'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7975781798820759676</id><published>2009-02-02T07:47:00.001-08:00</published><updated>2009-02-02T07:47:39.631-08:00</updated><title type='text'>QBar Adware</title><content type='html'>Removing QBar &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\qbup.qup&lt;br/&gt;[%SYSTEM%]\qbup.qup &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect QBar:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\qbup.qup&lt;br/&gt;[%SYSTEM%]\qbup.qup &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\qbar &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;  &lt;h2&gt;Removing QBar:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://viruslist-d.blogspot.com/2009/01/aupdate-adware.html"&gt;AUpdate Adware Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojanpedia-infections-keylogger.blogspot.com/2009/01/trojandropperwin32vbau-trojan.html"&gt;TrojanDropper.Win32.VB.au Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-03.blogspot.com/2009/01/jerusalemmummy-trojan.html"&gt;Removing Jerusalem.Mummy Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7975781798820759676?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7975781798820759676/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7975781798820759676' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7975781798820759676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7975781798820759676'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/qbar-adware.html' title='QBar Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7645799539677882262</id><published>2009-02-02T07:03:00.001-08:00</published><updated>2009-02-02T07:03:38.214-08:00</updated><title type='text'>Clandestine Trojan</title><content type='html'>Removing Clandestine &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Backdoor,RAT&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;Backdoors are the most dangerous type of Trojans and the most popular.&lt;br /&gt;Backdoors open infected machines to external control via Internet.&lt;br /&gt;Often the backdoor will not be visible in the log of active programs.&lt;br/&gt;Many trojans and backdoors now have &lt;strong&gt;remote administration capabilities&lt;/strong&gt;&lt;br /&gt;allowing an individual to control the victim's computer.&lt;br /&gt;Many times a file called the server must be opened on the victim's computer before&lt;br /&gt;the trojan can have access to it.&lt;br/&gt;&lt;br /&gt;These are generally sent through email, P2P file sharing software,&lt;br /&gt;and in internet downloads. They are usually disguised as a legitimate program or file.&lt;br /&gt;Many server files will display a fake error message when opened, to make it seem like it didn't open.&lt;br /&gt;Some will also kill antivirus and firewall software.&lt;br/&gt;&lt;br /&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,&lt;br /&gt;and swap mouse buttons. However, they can be quite hard to remove.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Clandestine Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Backdoor.Clindestine.10,Backdoor.ScreenGrab,Backdoor.Clindestine.152.a;&lt;br/&gt;[Eset]Win32/Clindestine.10.Server trojan;&lt;br/&gt;[McAfee]Backdoor-SK,BackDoor-SQ;&lt;br/&gt;[F-Prot]security risk or a "backdoor" program;&lt;br/&gt;[Panda]Bck/Clandestine.10,Bck/ScreenGrab,Backdoor Program;&lt;br/&gt;[Computer Associates]Backdoor/Canvas!Server,Backdoor/Clindestine.10!Server,Backdoor/Clindestine.1.5.2.A&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\remoto.exe&lt;br/&gt;[%WINDOWS%]\system\win32.exe&lt;br/&gt;[%WINDOWS%]\system\remoto.exe&lt;br/&gt;[%WINDOWS%]\system\win32.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Clandestine:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\remoto.exe&lt;br/&gt;[%WINDOWS%]\system\win32.exe&lt;br/&gt;[%WINDOWS%]\system\remoto.exe&lt;br/&gt;[%WINDOWS%]\system\win32.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Clandestine:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-83.blogspot.com/2009/01/vbsdelfile-trojan.html"&gt;VBS.DelFile Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://details-pc-keylogger.blogspot.com/2009/01/sinteridown-downloader.html"&gt;Removing SinteriDown Downloader&lt;/a&gt;&lt;br/&gt;&lt;a href="http://details-pc-keylogger.blogspot.com/2009/01/garden-tracking-cookie.html"&gt;Garden Tracking Cookie Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://viruslist-d.blogspot.com/2009/02/dluca-trojan.html"&gt;Removing Dluca Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-22.blogspot.com/2009/01/filevectorclass-trojan.html"&gt;Filevector.class Trojan Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7645799539677882262?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7645799539677882262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7645799539677882262' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7645799539677882262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7645799539677882262'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/clandestine-trojan.html' title='Clandestine Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-4940912930748158686</id><published>2009-02-02T04:07:00.001-08:00</published><updated>2009-02-02T04:07:07.409-08:00</updated><title type='text'>VeryCD Toolbar</title><content type='html'>Removing VeryCD &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Toolbar&lt;br/&gt;&lt;em&gt;Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\YOK³¬¼¶ËÑË÷.lnk&lt;br/&gt;[%DESKTOP%]\YOK³¬¼¶ËÑË÷.lnk &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect VeryCD:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\YOK³¬¼¶ËÑË÷.lnk&lt;br/&gt;[%DESKTOP%]\YOK³¬¼¶ËÑË÷.lnk &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\YOK.com &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{88351cef-bac0-4a9b-8380-31a173e2926f}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{a29f7f71-dcdb-412d-b19a-2002dc966e33}&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{F869BB38-FFEF-4589-B986-610B7AD0ADA2}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{3020099a-d1ef-4bb5-bca5-63cd8d110233}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{3a42c888-43d4-4bce-b3bc-99e5e15c631c}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{5bf5a044-328c-42ca-8edb-c513a4a49c69}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{8a74c2af-d08c-41e4-b6c0-11f1c7ed86a5}&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{7b18218b-2551-4f18-b94d-10d7ca4c14ec}&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar.band&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar.band.1&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar.contextsearch&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar.contextsearch.1&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar.yoktoolbarbho&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar.yoktoolbarbho.1&lt;br/&gt;HKEY_CURRENT_USER\software\yok&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\yok&lt;br/&gt;HKEY_LOCAL_MACHINE\system\yserialnumber&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{564cb59a-2813-4cee-b387-03d85322b54d}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{75fe2b5a-d3a4-4efa-ac11-adc9c9459688}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{7d0e8987-ba21-483a-b1ac-149da2f39a5a}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{f869bb38-ffef-4589-b986-610b7ad0ada2}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{7772d684-fdc9-46d1-8b1a-977eb5596a2a}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{9e3cddf5-b0a7-43fb-a882-b6b177fd4f01}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{bf9920a4-f4fd-4a14-92e6-3043a31c7abe}&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar.yokcommband&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar.yokcommband.1&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar.yokhttpfilter&lt;br/&gt;HKEY_CLASSES_ROOT\yoktoolbar.yokhttpfilter.1&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{f869bb38-ffef-4589-b986-610b7ad0ada2}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{75fe2b5a-d3a4-4efa-ac11-adc9c9459688}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\yok.supersearch &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\appid\yoktoolbar.dll&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing VeryCD:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-11.blogspot.com/2009/01/svug50megs-tracking-cookie.html"&gt;Svug.50megs Tracking Cookie Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://computer-protect-virus.blogspot.com/2009/01/cwsiefeads-hijacker.html"&gt;CWS.IEFeads Hijacker Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-1008.blogspot.com/2009/01/win32ntrootkit-backdoor.html"&gt;Win32.NTRootKit Backdoor Symptoms&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-4940912930748158686?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/4940912930748158686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=4940912930748158686' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4940912930748158686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4940912930748158686'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/verycd-toolbar.html' title='VeryCD Toolbar'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7245887818817251478</id><published>2009-02-02T03:03:00.001-08:00</published><updated>2009-02-02T03:03:25.830-08:00</updated><title type='text'>DFch Backdoor</title><content type='html'>Removing DFch &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Backdoor,RAT&lt;br/&gt;&lt;em&gt;Backdoors are the most dangerous type of Trojans and the most popular.&lt;br /&gt;Backdoors open infected machines to external control via Internet.&lt;br /&gt;Often the backdoor will not be visible in the log of active programs.&lt;br/&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;DFch Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Backdoor.Grisch.01.a;&lt;br/&gt;[Panda]Bck/Grisch.01;&lt;br/&gt;[Computer Associates]Backdoor/Grish.0_1,Win32.Grisch.01.A;&lt;br/&gt;[Other]Grisch&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\iosyss.exe&lt;br/&gt;[%WINDOWS%]\iosyss.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect DFch:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\iosyss.exe&lt;br/&gt;[%WINDOWS%]\iosyss.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing DFch:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-74.blogspot.com/2009/01/jsms06-trojan.html"&gt;JS.MS06 Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://viruslist-d.blogspot.com/2009/01/opalcot-trojan.html"&gt;Opalcot Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-16.blogspot.com/2009/01/pwspexp-trojan.html"&gt;PWS.Pexp Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-40.blogspot.com/2009/01/100hot-tracking-cookie.html"&gt;Remove 100hot Tracking Cookie&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-34.blogspot.com/2009/01/pigeonefr-trojan.html"&gt;Pigeon.EFR Trojan Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7245887818817251478?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7245887818817251478/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7245887818817251478' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7245887818817251478'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7245887818817251478'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/dfch-backdoor.html' title='DFch Backdoor'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-1247336457409574757</id><published>2009-02-02T02:03:00.001-08:00</published><updated>2009-02-02T02:03:06.772-08:00</updated><title type='text'>NewAds Adware</title><content type='html'>Removing NewAds &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\BattyRun.dll&lt;br/&gt;[%SYSTEM%]\BattyRun.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect NewAds:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\BattyRun.dll&lt;br/&gt;[%SYSTEM%]\BattyRun.dll &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\batty&lt;br/&gt;[%PROGRAM_FILES%]\AdSponsor&lt;br/&gt;[%PROGRAM_FILES%]\Exolon&lt;br/&gt;[%PROGRAM_FILES%]\PSupport &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\adband.bandbho&lt;br/&gt;HKEY_CLASSES_ROOT\adband.bandbho.1&lt;br/&gt;HKEY_CLASSES_ROOT\adband.bandimpl&lt;br/&gt;HKEY_CLASSES_ROOT\adband.bandimpl.1&lt;br/&gt;HKEY_CLASSES_ROOT\appid\adband.dll&lt;br/&gt;HKEY_CLASSES_ROOT\appid\{36946a0a-05a1-4cf7-934b-270571338e55}&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{1b8b502e-455b-4022-be27-736d9f808a18}&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{d5599fae-28aa-4c2b-a29c-6c0cd5b245aa}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{04dcb17c-ab45-83ad-a86a-6dfb90277939}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{2bc9c452-bb57-4896-a9a2-64611e06c5aa}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{6ca1c00b-90fc-4f3e-911f-95306aba43aa}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{994d478a-45d0-4db4-ae28-738b1e346f99}&lt;br/&gt;HKEY_CURRENT_USER\software\adsponsor&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\ext\stats\{04dcb17c-ab45-83ad-a86a-6dfb90277939}&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\ext\stats\{6ca1c00b-90fc-4f3e-911f-95306aba43aa}&lt;br/&gt;HKEY_CURRENT_USER\software\padsysassistant&lt;br/&gt;HKEY_CURRENT_USER\software\psupport&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\explorer bars\{2bc9c452-bb57-4896-a9a2-64611e06c5aa}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{04dcb17c-ab45-83ad-a86a-6dfb90277939}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6ca1c00b-90fc-4f3e-911f-95306aba43aa}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\adsponsor &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\protocols\filter\text/html &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing NewAds:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://remove-listing-pc.blogspot.com/2009/01/notpest-adware.html"&gt;NOT.Pest Adware Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-63.blogspot.com/2009/01/napsterhack-trojan.html"&gt;Napster.Hack Trojan Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-1247336457409574757?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/1247336457409574757/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=1247336457409574757' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1247336457409574757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1247336457409574757'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/newads-adware.html' title='NewAds Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-2424030693721674113</id><published>2009-02-02T01:52:00.001-08:00</published><updated>2009-02-02T01:52:14.961-08:00</updated><title type='text'>Moses Backdoor</title><content type='html'>Removing Moses &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Backdoor,RAT&lt;br/&gt;&lt;em&gt;Backdoors are the most dangerous type of Trojans and the most popular.&lt;br /&gt;Backdoors open infected machines to external control via Internet.&lt;br /&gt;Often the backdoor will not be visible in the log of active programs.&lt;br/&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Moses Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Backdoor.Moses.115,Backdoor.Win32.Moses.115;&lt;br/&gt;[McAfee]BackDoor-PA;&lt;br/&gt;[F-Prot]security risk or a "backdoor" program;&lt;br/&gt;[Panda]Bck/Moses.115;&lt;br/&gt;[Computer Associates]Win32.Moses.115,Backdoor/Moses.115,Backdoor/Moses.115!Installer&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\userprof.dll&lt;br/&gt;[%WINDOWS%]\system\userprof.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Moses:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\userprof.dll&lt;br/&gt;[%WINDOWS%]\system\userprof.dll &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Moses:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojanpedia-infections-keylogger.blogspot.com/2009/01/pigeonakj-trojan.html"&gt;Pigeon.AKJ Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-20.blogspot.com/2009/01/shadow-trojan.html"&gt;Shadow Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-33.blogspot.com/2009/01/hates-trojan.html"&gt;Hates Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-82.blogspot.com/2009/01/sillydldaf-trojan.html"&gt;Remove SillyDl.DAF Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-09.blogspot.com/2009/01/versiontrackercom-tracking-cookie.html"&gt;versiontracker.com Tracking Cookie Cleaner&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-2424030693721674113?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/2424030693721674113/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=2424030693721674113' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2424030693721674113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2424030693721674113'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/moses-backdoor.html' title='Moses Backdoor'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-5411671721457882792</id><published>2009-02-01T23:59:00.001-08:00</published><updated>2009-02-01T23:59:58.520-08:00</updated><title type='text'>GuardCenter Ransomware</title><content type='html'>Removing GuardCenter &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Ransomware&lt;br/&gt;&lt;em&gt;The term ransomware is commonly used to describe such software,&lt;br /&gt;although the field known as cryptovirology predates the term "ransomware".&lt;br/&gt;&lt;br /&gt;This type of ransom attack can be accomplished by (for example) attaching&lt;br /&gt;a specially crafted file/program to an e-mail message and sending this to the victim.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\GuardCenter.lnk&lt;br/&gt;[%DESKTOP%]\GuardCenter.lnk &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect GuardCenter:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\GuardCenter.lnk&lt;br/&gt;[%DESKTOP%]\GuardCenter.lnk &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\GuardCenter&lt;br/&gt;[%PROGRAM_FILES%]\GuardCenter &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\guardcenter&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\guardcenter&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\guardcenter &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing GuardCenter:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-72.blogspot.com/2009/02/vbsbogus-trojan.html"&gt;VBS.Bogus Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-73.blogspot.com/2009/01/bancosgig-trojan.html"&gt;Bancos.GIG Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-3339.blogspot.com/2009/02/banloadbba-trojan.html"&gt;Remove Banload.BBA Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-5411671721457882792?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/5411671721457882792/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=5411671721457882792' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5411671721457882792'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5411671721457882792'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/guardcenter-ransomware.html' title='GuardCenter Ransomware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-4443728018809418602</id><published>2009-02-01T21:39:00.001-08:00</published><updated>2009-02-01T21:39:29.154-08:00</updated><title type='text'>PigSearch Trojan</title><content type='html'>Removing PigSearch &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Adware&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;string&gt;PigSearch Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]AdWare.Win32.WSearch.j,Trojan-Downloader.Win32.AdLoad.ji;&lt;br/&gt;[McAfee]Adware-PigSearch;&lt;br/&gt;[Other]Adware.PigSearch,W32/Adload.FPQ&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\CharSet.dll&lt;br/&gt;[%SYSTEM%]\CreateDomTree.dll&lt;br/&gt;[%SYSTEM%]\drivers\mspcidrv.sys&lt;br/&gt;[%SYSTEM%]\CharSet.dll&lt;br/&gt;[%SYSTEM%]\CreateDomTree.dll&lt;br/&gt;[%SYSTEM%]\drivers\mspcidrv.sys &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect PigSearch:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\CharSet.dll&lt;br/&gt;[%SYSTEM%]\CreateDomTree.dll&lt;br/&gt;[%SYSTEM%]\drivers\mspcidrv.sys&lt;br/&gt;[%SYSTEM%]\CharSet.dll&lt;br/&gt;[%SYSTEM%]\CreateDomTree.dll&lt;br/&gt;[%SYSTEM%]\drivers\mspcidrv.sys &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{8E25AC4A-B129-451B-BEE2-3B510BB751DA}&lt;br/&gt;HKEY_CLASSES_ROOT\ntdll32.advance&lt;br/&gt;HKEY_CLASSES_ROOT\ntdll32.advance.1&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E25AC4A-B129-451B-BEE2-3B510BB751DA}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{8e25ac4a-b129-451b-bee2-3b510bb751da}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{d0903a3b-f0ea-434a-9742-98c5335c7946}&lt;br/&gt;HKEY_CLASSES_ROOT\iehelper.bho&lt;br/&gt;HKEY_CLASSES_ROOT\iehelper.bho.1&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{900f9840-be29-48cc-8a4e-acad94164139}&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{8899d7f9-c544-4bab-8cdc-d16c9d6b3af4}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8e25ac4a-b129-451b-bee2-3b510bb751da}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d0903a3b-f0ea-434a-9742-98c5335c7946}&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_mspcidrv&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mspcidrv &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\internet connection manager&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\internet connection manager&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\internet connection manager&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\internet connection manager&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\internet connection manager&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\internet connection manager&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\internet connection manager&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\internet connection manager\security&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mspath &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing PigSearch:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-54.blogspot.com/2009/01/loseexec-trojan.html"&gt;LoseExec Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-00.blogspot.com/2009/01/sillydlctu-trojan.html"&gt;Remove SillyDl.CTU Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-4443728018809418602?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/4443728018809418602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=4443728018809418602' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4443728018809418602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4443728018809418602'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/pigsearch-trojan.html' title='PigSearch Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6497949120645319479</id><published>2009-02-01T21:19:00.001-08:00</published><updated>2009-02-01T21:19:38.753-08:00</updated><title type='text'>TrojanClicker.Win32.Delf.ab Trojan</title><content type='html'>Removing TrojanClicker.Win32.Delf.ab &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Adware&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;string&gt;TrojanClicker.Win32.Delf.ab Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Panda]Trj/Clicker.S&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\bvm202.dll&lt;br/&gt;[%WINDOWS%]\bvm202.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect TrojanClicker.Win32.Delf.ab:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\bvm202.dll&lt;br/&gt;[%WINDOWS%]\bvm202.dll &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing TrojanClicker.Win32.Delf.ab:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://viruslist-3337.blogspot.com/2009/01/asshole-trojan.html"&gt;Remove Asshole Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-37.blogspot.com/2009/01/uniq-trojan.html"&gt;Uniq Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-65.blogspot.com/2009/01/exefwrapper-trojan.html"&gt;ExefWrapper Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-1036.blogspot.com/2009/01/win32formmail-dos.html"&gt;Win32.FormMail DoS Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6497949120645319479?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6497949120645319479/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6497949120645319479' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6497949120645319479'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6497949120645319479'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/trojanclickerwin32delfab-trojan.html' title='TrojanClicker.Win32.Delf.ab Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6496404250335038612</id><published>2009-02-01T18:11:00.001-08:00</published><updated>2009-02-01T18:11:36.592-08:00</updated><title type='text'>Comet Adware</title><content type='html'>Removing Comet &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%MYPICTURES%]\Funstuff\sinstaller2.exe&lt;br/&gt;[%PROGRAM_FILES%]\Screensavers.com\SSSInst\bin\SSSInst.dll&lt;br/&gt;[%PROGRAM_FILES%]\Screensavers.com\SSSInst\temp\pltbinst.exe&lt;br/&gt;[%MYPICTURES%]\Funstuff\sinstaller2.exe&lt;br/&gt;[%PROGRAM_FILES%]\Screensavers.com\SSSInst\bin\SSSInst.dll&lt;br/&gt;[%PROGRAM_FILES%]\Screensavers.com\SSSInst\temp\pltbinst.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Comet:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%MYPICTURES%]\Funstuff\sinstaller2.exe&lt;br/&gt;[%PROGRAM_FILES%]\Screensavers.com\SSSInst\bin\SSSInst.dll&lt;br/&gt;[%PROGRAM_FILES%]\Screensavers.com\SSSInst\temp\pltbinst.exe&lt;br/&gt;[%MYPICTURES%]\Funstuff\sinstaller2.exe&lt;br/&gt;[%PROGRAM_FILES%]\Screensavers.com\SSSInst\bin\SSSInst.dll&lt;br/&gt;[%PROGRAM_FILES%]\Screensavers.com\SSSInst\temp\pltbinst.exe &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{722D2939-A14A-41A9-9EAC-AB8F4E295819}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{88d758a3-d33b-45fd-91e3-67749b4057fa}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{760aca60-79c3-4875-9d19-b14a5b3fea77}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{883ea659-ed80-46f9-9ed2-83327f67789f}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{b64c73d7-459e-4816-91f9-1348f8e36984}&lt;br/&gt;HKEY_CLASSES_ROOT\screensaversinstaller.installer&lt;br/&gt;HKEY_CLASSES_ROOT\screensaversinstaller.sinstaller&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{0ab5b0d8-2b74-4c1c-8fa4-e52550b8b45b}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{722d2939-a14a-41a9-9eac-ab8f4e295819} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing Comet:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-18.blogspot.com/2009/01/smarttags-bho.html"&gt;Removing SmartTags BHO&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-07.blogspot.com/2009/01/win95cih-trojan.html"&gt;Win95.CIH Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojanpedia-viruslist-list.blogspot.com/2009/01/pigeonepi-trojan.html"&gt;Removing Pigeon.EPI Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://malwarepedia-protect-listing.blogspot.com/2009/01/win32inteter-trojan.html"&gt;Win32.Inteter Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://viruslist-c.blogspot.com/2009/01/netspy-backdoor.html"&gt;Remove Net.Spy Backdoor&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6496404250335038612?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6496404250335038612/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6496404250335038612' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6496404250335038612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6496404250335038612'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/comet-adware.html' title='Comet Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3751715351356089709</id><published>2009-02-01T16:06:00.001-08:00</published><updated>2009-02-01T16:06:59.778-08:00</updated><title type='text'>Wosrist Trojan</title><content type='html'>Removing Wosrist &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Adware,Hijacker,Downloader&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        Hijackers take control of various parts of your web browser, including your home page,&lt;br /&gt;search pages, and search bar. They may also redirect you to certain sites should you&lt;br /&gt;mistype an address or prevent you from going to a website they would rather you not,&lt;br /&gt;such as sites that combat malware. Some will even redirect you to their own search engine&lt;br /&gt;when you attempt a search.&lt;br/&gt;The downloader either launches the new malware or registers it to enable autorun&lt;br /&gt;according to the local operating system requirements.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Wosrist Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Trojan-Downloader.Win32.Agent.baw,Trojan-Spy.Win32.Agent.oy;&lt;br/&gt;[Other]Troj/DwnLdr-FVD,Win32/Wosrist.A,Downloader,Win32.Wosrist.B,Infostealer&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\iexpl0re.exe&lt;br/&gt;[%SYSTEM%]\aelupsvc32.dll&lt;br/&gt;[%SYSTEM%]\drivers\wsfit32.sys&lt;br/&gt;[%SYSTEM%]\exmple.dll&lt;br/&gt;[%SYSTEM%]\sexmple.exe&lt;br/&gt;[%WINDOWS%]\system\Setup-238.exe&lt;br/&gt;[%WINDOWS%]\iexpl0re.exe&lt;br/&gt;[%SYSTEM%]\aelupsvc32.dll&lt;br/&gt;[%SYSTEM%]\drivers\wsfit32.sys&lt;br/&gt;[%SYSTEM%]\exmple.dll&lt;br/&gt;[%SYSTEM%]\sexmple.exe&lt;br/&gt;[%WINDOWS%]\system\Setup-238.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Wosrist:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\iexpl0re.exe&lt;br/&gt;[%SYSTEM%]\aelupsvc32.dll&lt;br/&gt;[%SYSTEM%]\drivers\wsfit32.sys&lt;br/&gt;[%SYSTEM%]\exmple.dll&lt;br/&gt;[%SYSTEM%]\sexmple.exe&lt;br/&gt;[%WINDOWS%]\system\Setup-238.exe&lt;br/&gt;[%WINDOWS%]\iexpl0re.exe&lt;br/&gt;[%SYSTEM%]\aelupsvc32.dll&lt;br/&gt;[%SYSTEM%]\drivers\wsfit32.sys&lt;br/&gt;[%SYSTEM%]\exmple.dll&lt;br/&gt;[%SYSTEM%]\sexmple.exe&lt;br/&gt;[%WINDOWS%]\system\Setup-238.exe &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_wsfit32&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\wsfit32 &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Wosrist:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://details-list-pc.blogspot.com/2009/01/bionix-trojan.html"&gt;Remove Bionix Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3751715351356089709?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3751715351356089709/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3751715351356089709' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3751715351356089709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3751715351356089709'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/wosrist-trojan.html' title='Wosrist Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-689318823949274017</id><published>2009-02-01T14:15:00.001-08:00</published><updated>2009-02-01T14:15:36.194-08:00</updated><title type='text'>SpyAnytime.PC.Spy Spyware</title><content type='html'>Removing SpyAnytime.PC.Spy &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Spyware&lt;br/&gt;&lt;em&gt;Spyware is computer software that is installed surreptitiously on a personal computer&lt;br /&gt;to &lt;intercept or take partial control over the user's interaction&lt;br /&gt;with the computer, without the user's informed consent.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\keybhook.dll&lt;br/&gt;[%SYSTEM%]\sa2help.chm&lt;br/&gt;[%SYSTEM%]\sysmgr32.dat&lt;br/&gt;[%DESKTOP%]\spyanytime pc spy.lnk&lt;br/&gt;[%SYSTEM%]\sa2.lnk&lt;br/&gt;[%WINDOWS%]\desktop\spyanytime pc spy.lnk&lt;br/&gt;[%WINDOWS%]\start menu\programs\spyanytime pc spy online faq.lnk&lt;br/&gt;[%SYSTEM%]\keybhook.dll&lt;br/&gt;[%SYSTEM%]\sa2help.chm&lt;br/&gt;[%SYSTEM%]\sysmgr32.dat&lt;br/&gt;[%DESKTOP%]\spyanytime pc spy.lnk&lt;br/&gt;[%SYSTEM%]\sa2.lnk&lt;br/&gt;[%WINDOWS%]\desktop\spyanytime pc spy.lnk&lt;br/&gt;[%WINDOWS%]\start menu\programs\spyanytime pc spy online faq.lnk &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect SpyAnytime.PC.Spy:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\keybhook.dll&lt;br/&gt;[%SYSTEM%]\sa2help.chm&lt;br/&gt;[%SYSTEM%]\sysmgr32.dat&lt;br/&gt;[%DESKTOP%]\spyanytime pc spy.lnk&lt;br/&gt;[%SYSTEM%]\sa2.lnk&lt;br/&gt;[%WINDOWS%]\desktop\spyanytime pc spy.lnk&lt;br/&gt;[%WINDOWS%]\start menu\programs\spyanytime pc spy online faq.lnk&lt;br/&gt;[%SYSTEM%]\keybhook.dll&lt;br/&gt;[%SYSTEM%]\sa2help.chm&lt;br/&gt;[%SYSTEM%]\sysmgr32.dat&lt;br/&gt;[%DESKTOP%]\spyanytime pc spy.lnk&lt;br/&gt;[%SYSTEM%]\sa2.lnk&lt;br/&gt;[%WINDOWS%]\desktop\spyanytime pc spy.lnk&lt;br/&gt;[%WINDOWS%]\start menu\programs\spyanytime pc spy online faq.lnk &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\system&lt;br/&gt;[%APPDATA%]\sysdata&lt;br/&gt;[%PROGRAMS%]\spyanytime pc spy&lt;br/&gt;[%PROGRAM_FILES%]\common files\microsoft shared\dao\system&lt;br/&gt;[%PROGRAM_FILES%]\waresight&lt;br/&gt;[%PROGRAM_FILES_COMMON%]\sysdata &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;  &lt;h2&gt;Removing SpyAnytime.PC.Spy:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-41.blogspot.com/2009/01/directadsmcafee-tracking-cookie.html"&gt;DirectAds.McAfee Tracking Cookie Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://details-list-pc.blogspot.com/2009/01/sillydlckn-trojan.html"&gt;SillyDl.CKN Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://details-protect-pc.blogspot.com/2009/01/elfchsh30rootkittrojan-trojan.html"&gt;ELF.Chsh.30!Rootkit!Trojan Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-16.blogspot.com/2009/01/linksponsorcom-tracking-cookie.html"&gt;Remove LinkSponsor.com Tracking Cookie&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-689318823949274017?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/689318823949274017/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=689318823949274017' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/689318823949274017'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/689318823949274017'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/spyanytimepcspy-spyware.html' title='SpyAnytime.PC.Spy Spyware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6474416911151853931</id><published>2009-02-01T12:27:00.001-08:00</published><updated>2009-02-01T12:27:50.913-08:00</updated><title type='text'>Pigeon.AWE Trojan</title><content type='html'>Removing Pigeon.AWE &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect Pigeon.AWE:&lt;/h2&gt;&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_*00d6*00b4*00d0*00d0*00cf*00b5*00cd*00b3*00bb*00b9*00d4*00ad*00b9*00a6*00c4*00dc*00a1*00a3_*00d2*00aa*00cd*00a3*00d6*00b9*00b7*00fe*00ce*00f1&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_*00d6*00b4*00d0*00d0*00cf*00b5*00cd*00b3*00bb*00b9*00d4*00ad*00b9*00a6*00c4*00dc*00a1*00a3_*00d2*00aa*00cd*00a3*00d6*00b9*00b7*00fe*00ce*00f1\0000&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_*00d6*00b4*00d0*00d0*00cf*00b5*00cd*00b3*00bb*00b9*00d4*00ad*00b9*00a6*00c4*00dc*00a1*00a3_*00d2*00aa*00cd*00a3*00d6*00b9*00b7*00fe*00ce*00f1\0000&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_*00d6*00b4*00d0*00d0*00cf*00b5*00cd*00b3*00bb*00b9*00d4*00ad*00b9*00a6*00c4*00dc*00a1*00a3_*00d2*00aa*00cd*00a3*00d6*00b9*00b7*00fe*00ce*00f1\0000&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_*00d6*00b4*00d0*00d0*00cf*00b5*00cd*00b3*00bb*00b9*00d4*00ad*00b9*00a6*00c4*00dc*00a1*00a3_*00d2*00aa*00cd*00a3*00d6*00b9*00b7*00fe*00ce*00f1\0000&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_*00d6*00b4*00d0*00d0*00cf*00b5*00cd*00b3*00bb*00b9*00d4*00ad*00b9*00a6*00c4*00dc*00a1*00a3_*00d2*00aa*00cd*00a3*00d6*00b9*00b7*00fe*00ce*00f1\0000&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_*00d6*00b4*00d0*00d0*00cf*00b5*00cd*00b3*00bb*00b9*00d4*00ad*00b9*00a6*00c4*00dc*00a1*00a3_*00d2*00aa*00cd*00a3*00d6*00b9*00b7*00fe*00ce*00f1\0000\control &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Pigeon.AWE:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-77.blogspot.com/2009/01/pigeonedz-trojan.html"&gt;Pigeon.EDZ Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://viruslist-d.blogspot.com/2009/01/mixmarketbiz-tracking-cookie.html"&gt;mixmarket.biz Tracking Cookie Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6474416911151853931?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6474416911151853931/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6474416911151853931' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6474416911151853931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6474416911151853931'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/pigeonawe-trojan.html' title='Pigeon.AWE Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-3007189100779401208</id><published>2009-02-01T12:00:00.001-08:00</published><updated>2009-02-01T12:00:16.416-08:00</updated><title type='text'>Key.Captor Spyware</title><content type='html'>Removing Key.Captor &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Spyware&lt;br/&gt;&lt;em&gt;Spyware is computer software that is installed surreptitiously on a personal computer&lt;br /&gt;to &lt;strong&gt;intercept or take partial control&lt;/strong&gt; over the user's interaction&lt;br /&gt;with the computer, without the user's informed consent.&lt;br/&gt;&lt;br /&gt;While the term spyware suggests software that secretly monitors the user's behavior,&lt;br /&gt;the functions of spyware extend well beyond simple monitoring.&lt;br/&gt;&lt;br /&gt;Spyware programs can collect various types of personal information,&lt;br /&gt;such as Internet surfing habit, sites that have been visited,&lt;br /&gt;but can also interfere with user control of the computer in other ways,&lt;br /&gt;such as installing additional software, redirecting Web browser activity,&lt;br /&gt;accessing websites blindly that will cause more harmful viruses,&lt;br /&gt;or diverting advertising revenue to a third party.&lt;br/&gt;&lt;br /&gt;Spyware can even change computer settings, resulting in slow connection speeds,&lt;br /&gt;different home pages, and loss of Internet or other programs.&lt;br /&gt;In an attempt to increase the understanding of spyware, a more formal classification&lt;br /&gt;of its included software types is captured under the term privacy-invasive software.        &lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\spysplash.dat&lt;br/&gt;[%WINDOWS%]\spysplash.dat &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Key.Captor:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\spysplash.dat&lt;br/&gt;[%WINDOWS%]\spysplash.dat &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\Keycaptor&lt;br/&gt;[%PROGRAM_FILES%]\KeyCaptor &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Key.Captor:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://malware-info.blogspot.com/2009/01/win32bankerckj-trojan.html"&gt;Win32.Banker.ckj Trojan Removal&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-3007189100779401208?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/3007189100779401208/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=3007189100779401208' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3007189100779401208'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/3007189100779401208'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/keycaptor-spyware.html' title='Key.Captor Spyware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-291945151399402355</id><published>2009-02-01T11:43:00.001-08:00</published><updated>2009-02-01T11:43:28.929-08:00</updated><title type='text'>CFour RAT</title><content type='html'>Removing CFour &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; RAT&lt;br/&gt;&lt;em&gt;Many trojans and backdoors now have &lt;strong&gt;remote administration capabilities&lt;/strong&gt;&lt;br /&gt;allowing an individual to control the victim's computer.&lt;br /&gt;Many times a file called the server must be opened on the victim's computer before&lt;br /&gt;the trojan can have access to it.&lt;br/&gt;&lt;br /&gt;These are generally sent through email, P2P file sharing software,&lt;br /&gt;and in internet downloads. They are usually disguised as a legitimate program or file.&lt;br /&gt;Many server files will display a fake error message when opened, to make it seem like it didn't open.&lt;br /&gt;Some will also kill antivirus and firewall software.&lt;br/&gt;&lt;br /&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,&lt;br /&gt;and swap mouse buttons. However, they can be quite hard to remove.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\c4.exe&lt;br/&gt;[%WINDOWS%]\system\c4.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect CFour:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\c4.exe&lt;br/&gt;[%WINDOWS%]\system\c4.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing CFour:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-95.blogspot.com/2009/01/anyplay-adware.html"&gt;Anyplay Adware Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-malwarepedia-info.blogspot.com/2009/02/backdoordeathserverfamily-trojan.html"&gt;Removing Backdoor.Death.Server.family Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-11.blogspot.com/2009/01/vclheevahava-trojan.html"&gt;VCL.Heevahava Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-95.blogspot.com/2009/01/bancoshzo-trojan.html"&gt;Bancos.HZO Trojan Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-291945151399402355?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/291945151399402355/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=291945151399402355' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/291945151399402355'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/291945151399402355'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/cfour-rat.html' title='CFour RAT'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-2202150474898736156</id><published>2009-02-01T10:59:00.001-08:00</published><updated>2009-02-01T10:59:42.513-08:00</updated><title type='text'>Neol Backdoor</title><content type='html'>Removing Neol &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Backdoor&lt;br/&gt;&lt;em&gt;&lt;strong&gt;Backdoors are the most dangerous type of Trojans&lt;/strong&gt; and the most popular.&lt;br /&gt;&lt;strong&gt;Backdoors open infected machines&lt;/strong&gt; to external control via Internet.&lt;br /&gt;They function in the same way as legal remote administration programs used by system administrators.&lt;br /&gt;This makes them difficult to detect.&lt;br/&gt;&lt;br /&gt;&lt;strong&gt;Backdoors&lt;/strong&gt; are installed and launched without the consent of the user of computer.&lt;br /&gt;Often the backdoor will not be visible in the log of active programs.&lt;br/&gt;&lt;br /&gt;Once a backdoor has been successfully launched, the computer is wide open.&lt;br /&gt;Backdoor functions can include:&lt;br/&gt;&lt;br /&gt;    &lt;ul&gt;&lt;br /&gt;    &lt;li&gt; Launching/ deleting files&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Sending/ receiving files&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Deleting data&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Displaying notification&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Rebooting the machine&lt;/li&gt;&lt;br /&gt;    &lt;li&gt; Executing files&lt;/li&gt;&lt;br /&gt;    &lt;/ul&gt;&lt;br /&gt;&lt;br/&gt;&lt;br /&gt;&lt;strong&gt;Backdoors are used by virus writers to detect and download confidential information&lt;/strong&gt;,&lt;br /&gt;execute malicious code, destroy data, include the machine in bot networks and so forth.&lt;br /&gt;Backdoors combine the functionality of most other types of  in one package.&lt;br/&gt;&lt;br /&gt;Backdoors have one especially dangerous sub-class: variants that can propagate like worms. &lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect Neol:&lt;/h2&gt;&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Neol:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://ridethe-pc-info.blogspot.com/2009/01/phishbankaub-trojan.html"&gt;Removing Phishbank.AUB Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-2202150474898736156?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/2202150474898736156/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=2202150474898736156' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2202150474898736156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2202150474898736156'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/neol-backdoor.html' title='Neol Backdoor'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-2872029565020380581</id><published>2009-02-01T10:31:00.001-08:00</published><updated>2009-02-01T10:31:47.398-08:00</updated><title type='text'>BHOMoneyGainer Adware</title><content type='html'>Removing BHOMoneyGainer &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\shginasn.xml&lt;br/&gt;[%WINDOWS%]\shginasn.xml &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect BHOMoneyGainer:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\shginasn.xml&lt;br/&gt;[%WINDOWS%]\shginasn.xml &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\bookmark.bhomoneygainer&lt;br/&gt;HKEY_CLASSES_ROOT\bookmark.bhomoneygainer.1&lt;br/&gt;HKEY_CLASSES_ROOT\CLSID\{C815ACE8-3DBF-4FFD-8231-AB1D21E8B7EE}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{feaa3402-e101-4abd-9337-bdeefc6d29ca}&lt;br/&gt;HKEY_CLASSES_ROOT\typelib\{27195441-54b0-4dd3-820c-699ac3ef8d37}&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\ext\stats\{c815ace8-3dbf-4ffd-8231-ab1d21e8b7ee}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\iasadc&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C815ACE8-3DBF-4FFD-8231-AB1D21E8B7EE}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{c815ace8-3dbf-4ffd-8231-ab1d21e8b7ee}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c815ace8-3dbf-4ffd-8231-ab1d21e8b7ee} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing BHOMoneyGainer:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-1538.blogspot.com/2009/02/akosh-trojan.html"&gt;Remove Akosh Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-11.blogspot.com/2009/01/win32haxdoor-trojan.html"&gt;Removing Win32.Haxdoor Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-2872029565020380581?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/2872029565020380581/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=2872029565020380581' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2872029565020380581'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2872029565020380581'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/bhomoneygainer-adware.html' title='BHOMoneyGainer Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7770312450254602279</id><published>2009-02-01T10:23:00.001-08:00</published><updated>2009-02-01T10:23:13.046-08:00</updated><title type='text'>PerMedia Adware</title><content type='html'>Removing PerMedia &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware,BHO&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;strong&gt;BHO (Browser Helper Object) Trojan&lt;/strong&gt;.&lt;br /&gt;The BHO waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br /&gt;The method of network transport used by the attacker makes this Trojan unique.&lt;br /&gt;Typically, keyloggers of this type will send the stolen information back to the attacker via email&lt;br /&gt;or HTTP POST, which can appear suspicious.&lt;br /&gt;Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into&lt;br /&gt;the data section of an ICMP ping packet." explained the company.&lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect PerMedia:&lt;/h2&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{8cdc6a46-08ab-435b-a3fa-7cc00e74ec9f} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing PerMedia:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-1005.blogspot.com/2009/01/fdoskrate-dos.html"&gt;Removing FDoS.Krate DoS&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-02.blogspot.com/2009/01/gayol-backdoor.html"&gt;GayOL Backdoor Information&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-7770312450254602279?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/7770312450254602279/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=7770312450254602279' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7770312450254602279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/7770312450254602279'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/permedia-adware.html' title='PerMedia Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6788442243359292191</id><published>2009-02-01T08:47:00.001-08:00</published><updated>2009-02-01T08:47:16.988-08:00</updated><title type='text'>Yazzle Adware</title><content type='html'>Removing Yazzle &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\mfc42.dll&lt;br/&gt;[%SYSTEM%]\msvcrt.dll&lt;br/&gt;[%SYSTEM%]\olepro32.dll&lt;br/&gt;[%SYSTEM%]\mfc42.dll&lt;br/&gt;[%SYSTEM%]\msvcrt.dll&lt;br/&gt;[%SYSTEM%]\olepro32.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Yazzle:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\mfc42.dll&lt;br/&gt;[%SYSTEM%]\msvcrt.dll&lt;br/&gt;[%SYSTEM%]\olepro32.dll&lt;br/&gt;[%SYSTEM%]\mfc42.dll&lt;br/&gt;[%SYSTEM%]\msvcrt.dll&lt;br/&gt;[%SYSTEM%]\olepro32.dll &lt;/CODE&gt; &lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{74CD40EA-EF77-4BAD-808A-B5982DA73F20} &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing Yazzle:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-4138.blogspot.com/2009/02/vbfu-trojan.html"&gt;Remove VB.fu Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6788442243359292191?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6788442243359292191/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6788442243359292191' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6788442243359292191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6788442243359292191'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/yazzle-adware.html' title='Yazzle Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-2346465948872309728</id><published>2009-02-01T07:59:00.001-08:00</published><updated>2009-02-01T07:59:43.777-08:00</updated><title type='text'>Randex.E Trojan</title><content type='html'>Removing Randex.E &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROFILE%]\cmd.exe&lt;br/&gt;[%PROFILE%]\start&lt;br/&gt;[%PROFILE%]\cmd.exe&lt;br/&gt;[%PROFILE%]\start &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Randex.E:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROFILE%]\cmd.exe&lt;br/&gt;[%PROFILE%]\start&lt;br/&gt;[%PROFILE%]\cmd.exe&lt;br/&gt;[%PROFILE%]\start &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing Randex.E:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-96.blogspot.com/2009/01/dowqueafe-trojan.html"&gt;Dowque.AFE Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://protect-kill-infections.blogspot.com/2009/01/countomatcom-tracking-cookie.html"&gt;Removing countomat.com Tracking Cookie&lt;/a&gt;&lt;br/&gt;&lt;a href="http://details-protect-pc.blogspot.com/2009/01/bombing-trojan.html"&gt;Bombing Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://malware-info.blogspot.com/2009/01/zhong-adware.html"&gt;Zhong Adware Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-81.blogspot.com/2009/01/qdial-adware.html"&gt;Removing Qdial Adware&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-2346465948872309728?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/2346465948872309728/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=2346465948872309728' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2346465948872309728'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2346465948872309728'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/randexe-trojan.html' title='Randex.E Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-4925745973514617387</id><published>2009-02-01T07:31:00.001-08:00</published><updated>2009-02-01T07:31:30.063-08:00</updated><title type='text'>Tatss Adware</title><content type='html'>Removing Tatss &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Adware&lt;br/&gt;&lt;em&gt;Adware are programs that facilitate delivery for &lt;strong&gt;advertising content&lt;/strong&gt;&lt;br /&gt;to the user and in some cases gather information from the user's computer,&lt;br /&gt;including information related to Internet browser usage or other computer habits&lt;br/&gt;        &lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\pgtools\init.dll&lt;br/&gt;[%SYSTEM%]\pgtools\tataccess.ocx&lt;br/&gt;[%SYSTEM%]\pgtools\tatss.dll&lt;br/&gt;[%SYSTEM%]\pgtools\tatss.exe&lt;br/&gt;[%SYSTEM%]\pgtools\init.dll&lt;br/&gt;[%SYSTEM%]\pgtools\tataccess.ocx&lt;br/&gt;[%SYSTEM%]\pgtools\tatss.dll&lt;br/&gt;[%SYSTEM%]\pgtools\tatss.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Tatss:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\pgtools\init.dll&lt;br/&gt;[%SYSTEM%]\pgtools\tataccess.ocx&lt;br/&gt;[%SYSTEM%]\pgtools\tatss.dll&lt;br/&gt;[%SYSTEM%]\pgtools\tatss.exe&lt;br/&gt;[%SYSTEM%]\pgtools\init.dll&lt;br/&gt;[%SYSTEM%]\pgtools\tataccess.ocx&lt;br/&gt;[%SYSTEM%]\pgtools\tatss.dll&lt;br/&gt;[%SYSTEM%]\pgtools\tatss.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Tatss:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-59.blogspot.com/2009/01/dp2dlb-trojan.html"&gt;DP2DLB Trojan Information&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-4925745973514617387?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/4925745973514617387/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=4925745973514617387' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4925745973514617387'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4925745973514617387'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/tatss-adware.html' title='Tatss Adware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-2581032528813856139</id><published>2009-02-01T07:14:00.001-08:00</published><updated>2009-02-01T07:14:59.789-08:00</updated><title type='text'>Kongrid Trojan</title><content type='html'>Removing Kongrid &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan&lt;br/&gt;&lt;em&gt;This loose category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;&lt;br /&gt;Multi-purpose Trojans are also included in this group, as some virus writers&lt;br /&gt;create multi-functional Trojans rather than Trojan packs.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;Kongrid Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Trojan.Win32.Agent.ado,Virus.Win32.Agent.l;&lt;br/&gt;[McAfee]BackDoor-DIQ,W32/Generic.y;&lt;br/&gt;[Other]Win32/Kongrid.A,Backdoor:Win32/Difeqs.gen,W32/Agent.AWLA,W32.SillyFDC,Worm:Win32/SillyFDC,WORM_SILLYFDC.BN&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\cologsver.exe&lt;br/&gt;[%SYSTEM%]\cscripts.exe&lt;br/&gt;[%SYSTEM%]\xbox.dll&lt;br/&gt;[%SYSTEM%]\cologsver.exe&lt;br/&gt;[%SYSTEM%]\cscripts.exe&lt;br/&gt;[%SYSTEM%]\xbox.dll &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Kongrid:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%SYSTEM%]\cologsver.exe&lt;br/&gt;[%SYSTEM%]\cscripts.exe&lt;br/&gt;[%SYSTEM%]\xbox.dll&lt;br/&gt;[%SYSTEM%]\cologsver.exe&lt;br/&gt;[%SYSTEM%]\cscripts.exe&lt;br/&gt;[%SYSTEM%]\xbox.dll &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{72637363-7069-7374-652e-336d65747300} &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Kongrid:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-3726.blogspot.com/2009/01/win32vbgf-trojan.html"&gt;Win32.VB.gf Trojan Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-60.blogspot.com/2009/01/squatter-trojan.html"&gt;Squatter Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-27.blogspot.com/2009/01/jura6235-trojan.html"&gt;Jura6235 Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-description-blog.blogspot.com/2009/01/desktopauthority-rat.html"&gt;Desktop.Authority RAT Information&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-63.blogspot.com/2009/01/andum-trojan.html"&gt;Andum Trojan Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-2581032528813856139?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/2581032528813856139/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=2581032528813856139' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2581032528813856139'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/2581032528813856139'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/kongrid-trojan.html' title='Kongrid Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-8155793040598880184</id><published>2009-02-01T06:51:00.001-08:00</published><updated>2009-02-01T06:51:39.363-08:00</updated><title type='text'>ahv Downloader</title><content type='html'>Removing ahv &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Downloader&lt;br/&gt;&lt;em&gt;The downloader either launches the new malware or registers it to enable autorun&lt;br /&gt;according to the local operating system requirements.&lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect ahv:&lt;/h2&gt;&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, w034b6b0.dll=rundll32.exe w034b6b0.dll&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, w07124c8.dll=rundll32.exe w07124c8.dll &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing ahv:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://remove-malware.blogspot.com/2009/01/aolimspammer-trojan.html"&gt;Remove AolImSpammer Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-24.blogspot.com/2009/01/pigeonavpm-trojan.html"&gt;Pigeon.AVPM Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-47.blogspot.com/2009/01/sillydlcid-downloader.html"&gt;Removing SillyDl.CID Downloader&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-55.blogspot.com/2009/01/sensiscomau-tracking-cookie.html"&gt;Removing sensis.com.au Tracking Cookie&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-8155793040598880184?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/8155793040598880184/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=8155793040598880184' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8155793040598880184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8155793040598880184'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/ahv-downloader.html' title='ahv Downloader'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-8623827622509634528</id><published>2009-02-01T06:16:00.001-08:00</published><updated>2009-02-01T06:16:08.207-08:00</updated><title type='text'>Freddy.ASE RAT</title><content type='html'>Removing Freddy.ASE &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; RAT&lt;br/&gt;&lt;em&gt;Many trojans and backdoors now have remote administration capabilities&lt;br /&gt;allowing an individual to control the victim's computer.&lt;br /&gt;Many times a file called the server must be opened on the victim's computer before&lt;br /&gt;the trojan can have access to it.&lt;br/&gt;&lt;br /&gt;These are generally sent through email, P2P file sharing software,&lt;br /&gt;and in internet downloads. They are usually disguised as a legitimate program or file.&lt;br /&gt;Many server files will display a fake error message when opened, to make it seem like it didn't open.&lt;br /&gt;Some will also kill antivirus and firewall software.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\wintool.exe&lt;br/&gt;[%WINDOWS%]\wintool.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Freddy.ASE:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\wintool.exe&lt;br/&gt;[%WINDOWS%]\wintool.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Freddy.ASE:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-description-blog.blogspot.com/2009/01/nulware-spyware.html"&gt;Nulware Spyware Symptoms&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-8623827622509634528?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/8623827622509634528/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=8623827622509634528' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8623827622509634528'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8623827622509634528'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/freddyase-rat.html' title='Freddy.ASE RAT'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6802209590567271703</id><published>2009-02-01T06:00:00.001-08:00</published><updated>2009-02-01T06:00:28.355-08:00</updated><title type='text'>Zlob.Fam.VideoAccess Trojan</title><content type='html'>Removing Zlob.Fam.VideoAccess &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Popups&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;Adware is the class of programs that &lt;strong&gt;place advertisements on your screen&lt;/strong&gt;.&lt;br /&gt;These may be in the form of pop-ups, pop-unders, advertisements embedded in programs,&lt;br /&gt;advertisements placed on top of ads in web sites, or any other way the authors can&lt;br /&gt;think of showing you an ad.&lt;br/&gt;&lt;br /&gt;The pop-ups generally will not be stopped by pop-up stoppers, and often are&lt;br /&gt;not dependent on your having Internet Explorer open.&lt;br /&gt;They may show up when you are playing a game, writing a document, listening to music,&lt;br /&gt;or anything else. Should you be surfing, the advertisements will often be related to&lt;br /&gt;the web page you are viewing.         &lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\VideoAccess\Uninstall.lnk&lt;br/&gt;[%PROGRAM_FILES%]\VideoAccess\Uninstall.exe&lt;br/&gt;[%PROGRAMS%]\VideoAccess\Uninstall.lnk&lt;br/&gt;[%PROGRAM_FILES%]\VideoAccess\Uninstall.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Zlob.Fam.VideoAccess:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\VideoAccess\Uninstall.lnk&lt;br/&gt;[%PROGRAM_FILES%]\VideoAccess\Uninstall.exe&lt;br/&gt;[%PROGRAMS%]\VideoAccess\Uninstall.lnk&lt;br/&gt;[%PROGRAM_FILES%]\VideoAccess\Uninstall.exe &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\VideoAccess&lt;br/&gt;[%PROGRAM_FILES%]\VideoAccess &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\VideoAccess&lt;br/&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoAccess &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing Zlob.Fam.VideoAccess:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://viruslist-viruspedia-list.blogspot.com/2009/01/pigeonefd-trojan.html"&gt;Pigeon.EFD Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-90.blogspot.com/2009/01/bancosfvk-trojan.html"&gt;Bancos.FVK Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-14.blogspot.com/2009/01/nucscansabine-trojan.html"&gt;Remove NucScan.Sabine Trojan&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-55.blogspot.com/2009/01/ackcmd-trojan.html"&gt;Ack.Cmd Trojan Information&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6802209590567271703?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6802209590567271703/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6802209590567271703' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6802209590567271703'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6802209590567271703'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/zlobfamvideoaccess-trojan.html' title='Zlob.Fam.VideoAccess Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-5860075743769194434</id><published>2009-02-01T05:35:00.001-08:00</published><updated>2009-02-01T05:35:23.599-08:00</updated><title type='text'>InclinedRoad RAT</title><content type='html'>Removing InclinedRoad &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; RAT&lt;br/&gt;&lt;em&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\inclinedroad.exe&lt;br/&gt;[%WINDOWS%]\system\winroad.exe&lt;br/&gt;[%WINDOWS%]\system\inclinedroad.exe&lt;br/&gt;[%WINDOWS%]\system\winroad.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect InclinedRoad:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%WINDOWS%]\system\inclinedroad.exe&lt;br/&gt;[%WINDOWS%]\system\winroad.exe&lt;br/&gt;[%WINDOWS%]\system\inclinedroad.exe&lt;br/&gt;[%WINDOWS%]\system\winroad.exe &lt;/CODE&gt; &lt;/p&gt;     &lt;p&gt;  &lt;h2&gt;Removing InclinedRoad:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://remove-listing-pc.blogspot.com/2009/01/bvi-trojan.html"&gt;BVI Trojan Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-5860075743769194434?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/5860075743769194434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=5860075743769194434' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5860075743769194434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/5860075743769194434'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/inclinedroad-rat.html' title='InclinedRoad RAT'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-8675639375928546891</id><published>2009-02-01T05:18:00.001-08:00</published><updated>2009-02-01T05:18:55.476-08:00</updated><title type='text'>VNC RAT</title><content type='html'>Removing VNC &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; RAT&lt;br/&gt;&lt;em&gt;Many trojans and backdoors now have &lt;strong&gt;remote administration capabilities&lt;/strong&gt;&lt;br /&gt;allowing an individual to control the victim's computer.&lt;br /&gt;Many times a file called the server must be opened on the victim's computer before&lt;br /&gt;the trojan can have access to it.&lt;br/&gt;&lt;br /&gt;These are generally sent through email, P2P file sharing software,&lt;br /&gt;and in internet downloads. They are usually disguised as a legitimate program or file.&lt;br /&gt;Many server files will display a fake error message when opened, to make it seem like it didn't open.&lt;br /&gt;Some will also kill antivirus and firewall software.&lt;br/&gt;&lt;br /&gt;Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on&lt;br /&gt;April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.&lt;br /&gt;They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,&lt;br /&gt;and swap mouse buttons. However, they can be quite hard to remove.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;VNC Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]RemoteAdmin.Win32.WinVNC.4&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Server 4 (Service-Mode)\Set License Key.lnk&lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Viewer 4\Run Listening VNC Viewer.lnk&lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Viewer 4\Run VNC Viewer.lnk&lt;br/&gt;[%DESKTOP%]\vnc viewer 4.lnk&lt;br/&gt;[%DESKTOP%]\vnc viewer.lnk&lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Server 4 (Service-Mode)\Set License Key.lnk&lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Viewer 4\Run Listening VNC Viewer.lnk&lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Viewer 4\Run VNC Viewer.lnk&lt;br/&gt;[%DESKTOP%]\vnc viewer 4.lnk&lt;br/&gt;[%DESKTOP%]\vnc viewer.lnk &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect VNC:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Server 4 (Service-Mode)\Set License Key.lnk&lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Viewer 4\Run Listening VNC Viewer.lnk&lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Viewer 4\Run VNC Viewer.lnk&lt;br/&gt;[%DESKTOP%]\vnc viewer 4.lnk&lt;br/&gt;[%DESKTOP%]\vnc viewer.lnk&lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Server 4 (Service-Mode)\Set License Key.lnk&lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Viewer 4\Run Listening VNC Viewer.lnk&lt;br/&gt;[%COMMON_PROGRAMS%]\RealVNC\VNC Viewer 4\Run VNC Viewer.lnk&lt;br/&gt;[%DESKTOP%]\vnc viewer 4.lnk&lt;br/&gt;[%DESKTOP%]\vnc viewer.lnk &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\realvnc&lt;br/&gt;[%PROGRAM_FILES%]\realvnc &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\realvnc_is1&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\winvnc_is1&lt;br/&gt;HKEY_LOCAL_MACHINE\software\realvnc&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\eventlog\application\winvnc4&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\winvnc4 &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;  &lt;h2&gt;Removing VNC:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://malwarepedia-protect-listing.blogspot.com/2009/01/lockdirs-trojan.html"&gt;Lockdirs Trojan Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-8675639375928546891?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/8675639375928546891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=8675639375928546891' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8675639375928546891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/8675639375928546891'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/vnc-rat.html' title='VNC RAT'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-4704884770288718755</id><published>2009-02-01T04:51:00.001-08:00</published><updated>2009-02-01T04:51:26.591-08:00</updated><title type='text'>SystemSleuth Spyware</title><content type='html'>Removing SystemSleuth &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Spyware&lt;br/&gt;&lt;em&gt;Spyware programs can collect various types of personal information,&lt;br /&gt;such as Internet surfing habit, sites that have been visited,&lt;br /&gt;but can also interfere with user control of the computer in other ways,&lt;br /&gt;such as installing additional software, redirecting Web browser activity,&lt;br /&gt;accessing websites blindly that will cause more harmful viruses,&lt;br /&gt;or diverting advertising revenue to a third party.&lt;br/&gt;&lt;/em&gt;  &lt;p&gt;&lt;h2&gt;How to detect SystemSleuth:&lt;/h2&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\installer\products\550e28ff89756b140a7ac6ee275e2c49&lt;br/&gt;HKEY_CURRENT_USER\software\microsoft\installer\upgradecodes\35dd57b63ac91b249aa3c668e74bd75e&lt;br/&gt;HKEY_LOCAL_MACHINE\software\divine downloads&lt;br/&gt;HKEY_LOCAL_MACHINE\software\rebrandsoftware\computer monitor keylogger &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\folders&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing SystemSleuth:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-4138.blogspot.com/2009/01/vxidlatv-trojan.html"&gt;Vxidl.ATV Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-90.blogspot.com/2009/01/win32prodex-trojan.html"&gt;Win32.Prodex Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-74.blogspot.com/2009/01/osxcosmac-trojan.html"&gt;Removing OSX.Cosmac Trojan&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-4704884770288718755?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/4704884770288718755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=4704884770288718755' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4704884770288718755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/4704884770288718755'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/systemsleuth-spyware.html' title='SystemSleuth Spyware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-204330802581717093</id><published>2009-02-01T04:27:00.001-08:00</published><updated>2009-02-01T04:27:51.587-08:00</updated><title type='text'>INetSpeak Trojan</title><content type='html'>Removing INetSpeak &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Trojan,Adware,BHO&lt;br/&gt;&lt;em&gt;This category includes a variety of Trojans that damage victim machines or&lt;br /&gt;threaten data integrity, or impair the functioning of the victim machine.&lt;br/&gt;Adware are programs that facilitate delivery for advertising content&lt;br /&gt;to the user and in some cases gather information from the user's computer.&lt;br /&gt;&lt;br/&gt;        &lt;strong&gt;BHO (Browser Helper Object) Trojan&lt;/strong&gt;.&lt;br /&gt;The BHO waits for the user to post personal information to a monitored website.&lt;br /&gt;As this information is entered by the user, it is captured by the BHO and sent back to the attacker.&lt;br /&gt;The method of network transport used by the attacker makes this Trojan unique.&lt;br /&gt;Typically, keyloggers of this type will send the stolen information back to the attacker via email&lt;br /&gt;or HTTP POST, which can appear suspicious.&lt;br /&gt;Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into&lt;br /&gt;the data section of an ICMP ping packet." explained the company.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;string&gt;INetSpeak Also known as:&lt;/strong&gt;&lt;br/&gt;&lt;code&gt;&lt;br/&gt;[Kaspersky]Trojan.Win32.Toras.b&lt;/code&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\accele~1\anti-v~1\email_update.exe&lt;br/&gt;[%SYSTEM%]\bho.dll&lt;br/&gt;[%WINDOWS%]\Downloaded Program Files\BHO.INF&lt;br/&gt;[%FAVORITES%]\maria.lnk&lt;br/&gt;[%PROFILE%]\administrator\start menu\programs\musicmagnet\uninstall.lnk&lt;br/&gt;[%PROGRAMS%]\musicmagnet\music magnet.lnk&lt;br/&gt;[%PROGRAMS%]\musicmagnet\uninstall.lnk&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\boombar.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr11.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr22.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr23.dll&lt;br/&gt;[%SYSTEM%]\windowsie.dll&lt;br/&gt;[%WINDOWS%]\system\bho.dll&lt;br/&gt;[%WINDOWS%]\system\windowsie.dll&lt;br/&gt;[%WINDOWS%]\windowsie.dll&lt;br/&gt;[%WINDOWS%]\winietoolbar.ini&lt;br/&gt;[%PROGRAM_FILES%]\accele~1\anti-v~1\email_update.exe&lt;br/&gt;[%SYSTEM%]\bho.dll&lt;br/&gt;[%WINDOWS%]\Downloaded Program Files\BHO.INF&lt;br/&gt;[%FAVORITES%]\maria.lnk&lt;br/&gt;[%PROFILE%]\administrator\start menu\programs\musicmagnet\uninstall.lnk&lt;br/&gt;[%PROGRAMS%]\musicmagnet\music magnet.lnk&lt;br/&gt;[%PROGRAMS%]\musicmagnet\uninstall.lnk&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\boombar.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr11.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr22.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr23.dll&lt;br/&gt;[%SYSTEM%]\windowsie.dll&lt;br/&gt;[%WINDOWS%]\system\bho.dll&lt;br/&gt;[%WINDOWS%]\system\windowsie.dll&lt;br/&gt;[%WINDOWS%]\windowsie.dll&lt;br/&gt;[%WINDOWS%]\winietoolbar.ini &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect INetSpeak:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\accele~1\anti-v~1\email_update.exe&lt;br/&gt;[%SYSTEM%]\bho.dll&lt;br/&gt;[%WINDOWS%]\Downloaded Program Files\BHO.INF&lt;br/&gt;[%FAVORITES%]\maria.lnk&lt;br/&gt;[%PROFILE%]\administrator\start menu\programs\musicmagnet\uninstall.lnk&lt;br/&gt;[%PROGRAMS%]\musicmagnet\music magnet.lnk&lt;br/&gt;[%PROGRAMS%]\musicmagnet\uninstall.lnk&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\boombar.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr11.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr22.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr23.dll&lt;br/&gt;[%SYSTEM%]\windowsie.dll&lt;br/&gt;[%WINDOWS%]\system\bho.dll&lt;br/&gt;[%WINDOWS%]\system\windowsie.dll&lt;br/&gt;[%WINDOWS%]\windowsie.dll&lt;br/&gt;[%WINDOWS%]\winietoolbar.ini&lt;br/&gt;[%PROGRAM_FILES%]\accele~1\anti-v~1\email_update.exe&lt;br/&gt;[%SYSTEM%]\bho.dll&lt;br/&gt;[%WINDOWS%]\Downloaded Program Files\BHO.INF&lt;br/&gt;[%FAVORITES%]\maria.lnk&lt;br/&gt;[%PROFILE%]\administrator\start menu\programs\musicmagnet\uninstall.lnk&lt;br/&gt;[%PROGRAMS%]\musicmagnet\music magnet.lnk&lt;br/&gt;[%PROGRAMS%]\musicmagnet\uninstall.lnk&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\boombar.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr11.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr22.dll&lt;br/&gt;[%PROGRAM_FILES%]\internet explorer\iexplorr23.dll&lt;br/&gt;[%SYSTEM%]\windowsie.dll&lt;br/&gt;[%WINDOWS%]\system\bho.dll&lt;br/&gt;[%WINDOWS%]\system\windowsie.dll&lt;br/&gt;[%WINDOWS%]\windowsie.dll&lt;br/&gt;[%WINDOWS%]\winietoolbar.ini &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\music magnet.lnk&lt;br/&gt;[%PROFILE%]\start menu\programs\musicmagnet&lt;br/&gt;[%PROGRAM_FILES%]\mm050102&lt;br/&gt;[%PROGRAM_FILES%]\mm052202&lt;br/&gt;[%PROGRAM_FILES%]\musicmagnet &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CLASSES_ROOT\bho42602.clsinetspeak&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{2e12b523-3d4c-4fac-9b04-0376a8f5e879}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{c389f2cf-26ed-11d5-a212-004005f6feb6}&lt;br/&gt;HKEY_CLASSES_ROOT\clsid\{d6862a22-1dd6-11d3-bb7c-444553540000}&lt;br/&gt;HKEY_CLASSES_ROOT\interface\{d16f4f72-24df-4775-b444-167af5b30620}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{2e12b523-3d4c-4fac-9b04-0376a8f5e879}&lt;br/&gt;HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{d6862a22-1dd6-11d3-bb7c-444553540000}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\bho42602.clsdockwindow&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\bho42602.clsinetspeak&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{236826b1-8fdb-4d3c-8f70-e154f874703d}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{2e12b523-3d4c-4fac-9b04-0376a8f5e879}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{4cf5275b-cdbc-11d3-a8af-0090279a5978}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\clsid\{d6862a22-1dd6-11d3-bb7c-444553540000}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\interface\{072d14ef-99b6-49dd-9be5-76142727b7ac}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\interface\{4b191b11-a44c-4d42-b4ac-6fcd5f61587c}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\interface\{943f44c0-44da-40d5-98d7-9aac4c15c603}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\interface\{d16f4f72-24df-4775-b444-167af5b30620}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\typelib\{d6862a20-1dd6-11d3-bb7c-444553540000}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\windowsie.clsdw&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\windowsie.clsis&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2e12b523-3d4c-4fac-9b04-0376a8f5e879}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d6862a22-1dd6-11d3-bb7c-444553540000}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\musicmagnet &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\bho426022&lt;br/&gt;HKEY_LOCAL_MACHINE\software\classes\windowsie&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\windowsie&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\windowsie&lt;br/&gt;HKEY_LOCAL_MACHINE\software\nsis_musicmagnet &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing INetSpeak:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-95.blogspot.com/2009/01/antischooltef-trojan.html"&gt;Anti.School.Tef Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-09.blogspot.com/2009/01/yayaveratl-adware.html"&gt;YayaVerAtl Adware Removal instruction&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-204330802581717093?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/204330802581717093/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=204330802581717093' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/204330802581717093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/204330802581717093'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/inetspeak-trojan.html' title='INetSpeak Trojan'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6514367933426643378</id><published>2009-02-01T03:35:00.001-08:00</published><updated>2009-02-01T03:35:30.633-08:00</updated><title type='text'>Super.Killer Ransomware</title><content type='html'>Removing Super.Killer &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Ransomware&lt;br/&gt;&lt;em&gt;A &lt;strong&gt;cryptovirus, cryptotrojan or cryptoworm&lt;/strong&gt; is a type of&lt;br /&gt;malware that encrypts the data belonging to an individual on a computer,&lt;br /&gt;demanding a ransom for its restoration.&lt;br/&gt;&lt;br /&gt;The term ransomware is commonly used to describe software that encrypts the data&lt;br /&gt;belonging to an individual on a computer, demanding a ransom for its restoration.&lt;br /&gt;Although the field known as cryptovirology predates the term "ransomware".&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\SuperSpywareKiller.lnk&lt;br/&gt;[%DESKTOP%]\SuperSpywareKiller.lnk &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Super.Killer:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\SuperSpywareKiller.lnk&lt;br/&gt;[%DESKTOP%]\SuperSpywareKiller.lnk &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%COMMON_PROGRAMS%]\SuperSpywareKiller&lt;br/&gt;[%PROGRAM_FILES%]\SuperSpywareKiller &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\spywarekiller&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\superspywarekiller_is1 &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Super.Killer:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://virusinfo-2217.blogspot.com/2009/01/bigbot-backdoor.html"&gt;Bigbot Backdoor Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-14.blogspot.com/2009/01/monabomber-rat.html"&gt;MonaBomber RAT Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-description-blog.blogspot.com/2009/01/commissionjunctioncom-tracking-cookie.html"&gt;Remove Commission.Junction.com Tracking Cookie&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6514367933426643378?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6514367933426643378/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6514367933426643378' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6514367933426643378'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6514367933426643378'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/superkiller-ransomware.html' title='Super.Killer Ransomware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-6294214284077235722</id><published>2009-02-01T02:43:00.001-08:00</published><updated>2009-02-01T02:43:05.929-08:00</updated><title type='text'>Easy.Keyboard.Logger Spyware</title><content type='html'>Removing Easy.Keyboard.Logger &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Spyware&lt;br/&gt;&lt;em&gt;Spyware is computer software that is installed surreptitiously on a personal computer&lt;br /&gt;to &lt;intercept or take partial control over the user's interaction&lt;br /&gt;with the computer, without the user's informed consent.&lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\EasyKeylog.txt&lt;br/&gt;[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Easy Keyboard Logger.lnk&lt;br/&gt;[%DESKTOP%]\Easy Keyboard Logger.lnk&lt;br/&gt;[%PROFILE_TEMP%]\EasyKeylog.txt&lt;br/&gt;[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Easy Keyboard Logger.lnk&lt;br/&gt;[%DESKTOP%]\Easy Keyboard Logger.lnk &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect Easy.Keyboard.Logger:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROFILE_TEMP%]\EasyKeylog.txt&lt;br/&gt;[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Easy Keyboard Logger.lnk&lt;br/&gt;[%DESKTOP%]\Easy Keyboard Logger.lnk&lt;br/&gt;[%PROFILE_TEMP%]\EasyKeylog.txt&lt;br/&gt;[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Easy Keyboard Logger.lnk&lt;br/&gt;[%DESKTOP%]\Easy Keyboard Logger.lnk &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAM_FILES%]\Easy Keyboard Logger&lt;br/&gt;[%PROGRAMS%]\Easy Keyboard Logger &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_CURRENT_USER\software\ekl&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\easy keyboard logger_is1&lt;br/&gt;HKEY_LOCAL_MACHINE\software\softsaga easy keyboard logger &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing Easy.Keyboard.Logger:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-33.blogspot.com/2009/01/delalot-trojan.html"&gt;Delalot Trojan Symptoms&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-16.blogspot.com/2009/01/radr-trojan.html"&gt;RA.dr Trojan Removal instruction&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-39.blogspot.com/2009/01/ntrc-backdoor.html"&gt;Removing NTRC Backdoor&lt;/a&gt;&lt;br/&gt;&lt;a href="http://trojan-list-22.blogspot.com/2009/01/computer-key-logger-spyware.html"&gt;Computer Key Logger Spyware Information&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-6294214284077235722?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/6294214284077235722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=6294214284077235722' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6294214284077235722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/6294214284077235722'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/easykeyboardlogger-spyware.html' title='Easy.Keyboard.Logger Spyware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-1416084767639570894</id><published>2009-02-01T01:47:00.001-08:00</published><updated>2009-02-01T01:47:22.627-08:00</updated><title type='text'>WinSession.Logger Spyware</title><content type='html'>Removing WinSession.Logger &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Spyware&lt;br/&gt;&lt;em&gt;Spyware is computer software that is installed surreptitiously on a personal computer&lt;br /&gt;to &lt;strong&gt;intercept or take partial control&lt;/strong&gt; over the user's interaction&lt;br /&gt;with the computer, without the user's informed consent.&lt;br/&gt;&lt;br /&gt;While the term spyware suggests software that secretly monitors the user's behavior,&lt;br /&gt;the functions of spyware extend well beyond simple monitoring.&lt;br/&gt;&lt;br /&gt;Spyware programs can collect various types of personal information,&lt;br /&gt;such as Internet surfing habit, sites that have been visited,&lt;br /&gt;but can also interfere with user control of the computer in other ways,&lt;br /&gt;such as installing additional software, redirecting Web browser activity,&lt;br /&gt;accessing websites blindly that will cause more harmful viruses,&lt;br /&gt;or diverting advertising revenue to a third party.&lt;br/&gt;&lt;br /&gt;Spyware can even change computer settings, resulting in slow connection speeds,&lt;br /&gt;different home pages, and loss of Internet or other programs.&lt;br /&gt;In an attempt to increase the understanding of spyware, a more formal classification&lt;br /&gt;of its included software types is captured under the term privacy-invasive software.        &lt;br/&gt;&lt;/em&gt;&lt;hr/&gt;&lt;strong&gt;Visible Symptoms:&lt;/strong&gt; &lt;br/&gt;Files in system folders:&lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\ws logger.lnk&lt;br/&gt;[%SYSTEM%]\9500\svchost.exe&lt;br/&gt;[%SYSTEM%]\bootldr.exe&lt;br/&gt;[%SYSTEM%]\conwxrl.bin&lt;br/&gt;[%SYSTEM%]\delservicew.exe&lt;br/&gt;[%SYSTEM%]\digiwin.dll&lt;br/&gt;[%SYSTEM%]\exwin32m.exe&lt;br/&gt;[%SYSTEM%]\nxkernel32.dll&lt;br/&gt;[%SYSTEM%]\Old_date32.dll&lt;br/&gt;[%SYSTEM%]\svclsv.exe&lt;br/&gt;[%SYSTEM%]\unicode_digi.dll&lt;br/&gt;[%SYSTEM%]\xwboot.exe&lt;br/&gt;[%DESKTOP%]\ws logger.lnk&lt;br/&gt;[%SYSTEM%]\9500\svchost.exe&lt;br/&gt;[%SYSTEM%]\bootldr.exe&lt;br/&gt;[%SYSTEM%]\conwxrl.bin&lt;br/&gt;[%SYSTEM%]\delservicew.exe&lt;br/&gt;[%SYSTEM%]\digiwin.dll&lt;br/&gt;[%SYSTEM%]\exwin32m.exe&lt;br/&gt;[%SYSTEM%]\nxkernel32.dll&lt;br/&gt;[%SYSTEM%]\Old_date32.dll&lt;br/&gt;[%SYSTEM%]\svclsv.exe&lt;br/&gt;[%SYSTEM%]\unicode_digi.dll&lt;br/&gt;[%SYSTEM%]\xwboot.exe &lt;/CODE&gt;  &lt;p&gt;&lt;h2&gt;How to detect WinSession.Logger:&lt;/h2&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Files:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%DESKTOP%]\ws logger.lnk&lt;br/&gt;[%SYSTEM%]\9500\svchost.exe&lt;br/&gt;[%SYSTEM%]\bootldr.exe&lt;br/&gt;[%SYSTEM%]\conwxrl.bin&lt;br/&gt;[%SYSTEM%]\delservicew.exe&lt;br/&gt;[%SYSTEM%]\digiwin.dll&lt;br/&gt;[%SYSTEM%]\exwin32m.exe&lt;br/&gt;[%SYSTEM%]\nxkernel32.dll&lt;br/&gt;[%SYSTEM%]\Old_date32.dll&lt;br/&gt;[%SYSTEM%]\svclsv.exe&lt;br/&gt;[%SYSTEM%]\unicode_digi.dll&lt;br/&gt;[%SYSTEM%]\xwboot.exe&lt;br/&gt;[%DESKTOP%]\ws logger.lnk&lt;br/&gt;[%SYSTEM%]\9500\svchost.exe&lt;br/&gt;[%SYSTEM%]\bootldr.exe&lt;br/&gt;[%SYSTEM%]\conwxrl.bin&lt;br/&gt;[%SYSTEM%]\delservicew.exe&lt;br/&gt;[%SYSTEM%]\digiwin.dll&lt;br/&gt;[%SYSTEM%]\exwin32m.exe&lt;br/&gt;[%SYSTEM%]\nxkernel32.dll&lt;br/&gt;[%SYSTEM%]\Old_date32.dll&lt;br/&gt;[%SYSTEM%]\svclsv.exe&lt;br/&gt;[%SYSTEM%]\unicode_digi.dll&lt;br/&gt;[%SYSTEM%]\xwboot.exe &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Folders:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;[%PROGRAMS%]\WinSession Logger&lt;br/&gt;[%PROGRAM_FILES%]\wlogs&lt;br/&gt;[%PROGRAM_FILES%]\wslogger &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Keys:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\mcap4_software&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ebt9l2db0-b607-11d2-9cbd-0000f87a369e}&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\winsession logger_is1&lt;br/&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\subsystem64r &lt;/CODE&gt; &lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Registry Values:&lt;/strong&gt; &lt;CODE&gt; &lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run&lt;br/&gt;HKEY_LOCAL_MACHINE\software\msc_software &lt;/CODE&gt; &lt;/p&gt;  &lt;p&gt;  &lt;h2&gt;Removing WinSession.Logger:&lt;/h2&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can download trial version of "Exterminate-It" antivirus software &lt;a href="http://ihitec.com/t.php?path=av-dl/m-i/1" rel="nofollow"&gt;here&lt;/a&gt;, to check your computer instantly.&lt;/p&gt;Or &lt;a href="http://ihitec.com/t.php?path=av-buy/m-i/1" rel="nofollow"&gt;buy it&lt;/a&gt; to remove ALL viruses from your computer.&lt;hr/&gt;&lt;p&gt;Also Be Aware of the Following Threats:&lt;br/&gt;&lt;a href="http://trojan-list-09.blogspot.com/2009/01/lameness-trojan.html"&gt;Lameness Trojan Cleaner&lt;/a&gt;&lt;br/&gt;&lt;a href="http://ridethe-pc-info.blogspot.com/2009/01/bancosgyr-trojan.html"&gt;Bancos.GYR Trojan Removal&lt;/a&gt;&lt;br/&gt;&lt;a href="http://virusinfo-0929.blogspot.com/2009/01/sillydldme-trojan.html"&gt;SillyDl.DME Trojan Symptoms&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1481876143551850049-1416084767639570894?l=malware-info.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malware-info.blogspot.com/feeds/1416084767639570894/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1481876143551850049&amp;postID=1416084767639570894' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1416084767639570894'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1481876143551850049/posts/default/1416084767639570894'/><link rel='alternate' type='text/html' href='http://malware-info.blogspot.com/2009/02/winsessionlogger-spyware.html' title='WinSession.Logger Spyware'/><author><name>Andres Damian</name><uri>http://www.blogger.com/profile/09684340360941054571</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481876143551850049.post-7265603380845065984</id><published>2009-02-01T01:24:00.001-08:00</published><updated>2009-02-01T01:24:34.624-08:00</updated><title type='text'>SpywareRemover Ransomware</title><content type='html'>Removing SpywareRemover &lt;br/&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Ransomware&lt;br/&gt;&lt;em&gt;A &lt;strong&gt;cryptovirus, cryptotrojan or cryptoworm&lt;/strong&gt; is a type of&lt;br /&gt;malware that encrypts the data belonging to an individual on a computer,&lt;br /&gt;demanding a ransom for its restoration.&lt;br/&gt;&lt;br /&gt;The term ransom
