Tuesday, January 27, 2009

Lemmy BHO

Removing Lemmy
Categories: BHO,Downloader
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.Trojans-downloaders downloads and installs new malware or adware on the computer.


Visible Symptoms:
Files in system folders:
[%WINDOWS%]\nbfmkzbe.dll
[%WINDOWS%]\gieeumr.dll
[%WINDOWS%]\grbrof.dll
[%WINDOWS%]\hohrychue.dll
[%WINDOWS%]\jmyg.dll
[%WINDOWS%]\mcdhgosa.dll
[%WINDOWS%]\nhteose.dll
[%WINDOWS%]\njjpmlil.dll
[%WINDOWS%]\ntzjeiyup.dll
[%WINDOWS%]\ptfdtcet.dll
[%WINDOWS%]\ugki.dll
[%WINDOWS%]\wcszaalu.dll
[%WINDOWS%]\wtznh.dll
[%WINDOWS%]\zkfmtdehl.dll
[%WINDOWS%]\nbfmkzbe.dll
[%WINDOWS%]\gieeumr.dll
[%WINDOWS%]\grbrof.dll
[%WINDOWS%]\hohrychue.dll
[%WINDOWS%]\jmyg.dll
[%WINDOWS%]\mcdhgosa.dll
[%WINDOWS%]\nhteose.dll
[%WINDOWS%]\njjpmlil.dll
[%WINDOWS%]\ntzjeiyup.dll
[%WINDOWS%]\ptfdtcet.dll
[%WINDOWS%]\ugki.dll
[%WINDOWS%]\wcszaalu.dll
[%WINDOWS%]\wtznh.dll
[%WINDOWS%]\zkfmtdehl.dll

How to detect Lemmy:

Files:
[%WINDOWS%]\nbfmkzbe.dll
[%WINDOWS%]\gieeumr.dll
[%WINDOWS%]\grbrof.dll
[%WINDOWS%]\hohrychue.dll
[%WINDOWS%]\jmyg.dll
[%WINDOWS%]\mcdhgosa.dll
[%WINDOWS%]\nhteose.dll
[%WINDOWS%]\njjpmlil.dll
[%WINDOWS%]\ntzjeiyup.dll
[%WINDOWS%]\ptfdtcet.dll
[%WINDOWS%]\ugki.dll
[%WINDOWS%]\wcszaalu.dll
[%WINDOWS%]\wtznh.dll
[%WINDOWS%]\zkfmtdehl.dll
[%WINDOWS%]\nbfmkzbe.dll
[%WINDOWS%]\gieeumr.dll
[%WINDOWS%]\grbrof.dll
[%WINDOWS%]\hohrychue.dll
[%WINDOWS%]\jmyg.dll
[%WINDOWS%]\mcdhgosa.dll
[%WINDOWS%]\nhteose.dll
[%WINDOWS%]\njjpmlil.dll
[%WINDOWS%]\ntzjeiyup.dll
[%WINDOWS%]\ptfdtcet.dll
[%WINDOWS%]\ugki.dll
[%WINDOWS%]\wcszaalu.dll
[%WINDOWS%]\wtznh.dll
[%WINDOWS%]\zkfmtdehl.dll

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{8e339f58-0553-4ca7-9ba3-042905614fb6}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8e339f58-0553-4ca7-9ba3-042905614fb6}

Removing Lemmy:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing Pigeon.AVOZ Trojan
Vxidl.AHD Trojan Removal instruction

QaBar.Adult.Links.Toolband BHO

Removing QaBar.Adult.Links.Toolband
Categories: BHO
BHO (Browser Helper Object) Trojan.
The BHO waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
The method of network transport used by the attacker makes this Trojan unique.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.
Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into
the data section of an ICMP ping packet." explained the company.

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\insqcb.ins
[%SYSTEM%]\QaBar.dll
[%WINDOWS%]\downloaded program files\qabar.dll
[%WINDOWS%]\downloaded program files\qabar.inf
[%WINDOWS%]\temp\qabar.dll
[%WINDOWS%]\temp\qabar.inf
[%SYSTEM%]\insqcb.ins
[%SYSTEM%]\QaBar.dll
[%WINDOWS%]\downloaded program files\qabar.dll
[%WINDOWS%]\downloaded program files\qabar.inf
[%WINDOWS%]\temp\qabar.dll
[%WINDOWS%]\temp\qabar.inf

How to detect QaBar.Adult.Links.Toolband:

Files:
[%SYSTEM%]\insqcb.ins
[%SYSTEM%]\QaBar.dll
[%WINDOWS%]\downloaded program files\qabar.dll
[%WINDOWS%]\downloaded program files\qabar.inf
[%WINDOWS%]\temp\qabar.dll
[%WINDOWS%]\temp\qabar.inf
[%SYSTEM%]\insqcb.ins
[%SYSTEM%]\QaBar.dll
[%WINDOWS%]\downloaded program files\qabar.dll
[%WINDOWS%]\downloaded program files\qabar.inf
[%WINDOWS%]\temp\qabar.dll
[%WINDOWS%]\temp\qabar.inf

Registry Keys:
HKEY_LOCAL_MACHINE\software\classes\qabar\clsid
HKEY_LOCAL_MACHINE\software\classes\qabar\curver
HKEY_CLASSES_ROOT\clsid\{6d7d135e-f7c2-4a27-a87c-c0dfeb3a628f}
HKEY_CLASSES_ROOT\clsid\{d02ee3a0-1881-419f-a5ed-737223463292}
HKEY_CLASSES_ROOT\clsid\{d1320cbb-403d-483d-ae9a-688960a96977}
HKEY_LOCAL_MACHINE\software\classes\qabar.adultsearch\clsid
HKEY_LOCAL_MACHINE\software\classes\qabar.adultsearch\curver

Removing QaBar.Adult.Links.Toolband:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Remove Tomato.beta Trojan
Removing SillyDl.COV Trojan
Pigeon.AZK Trojan Information
Remove SillyDl.CLX Trojan

Comforest Trojan

Removing Comforest
Categories: Trojan,Adware,Hijacker
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.

Hijackers take control of various parts of your web browser, including your home page,
search pages, and search bar. They may also redirect you to certain sites should you
mistype an address or prevent you from going to a website they would rather you not,
such as sites that combat malware. Some will even redirect you to their own search engine
when you attempt a search.

Comforest Also known as:

[Kaspersky]Trojan.Win32.Delf.cn;
[Other]ComforestDial,comforest dialer,W32/Delf.TWV

Visible Symptoms:
Files in system folders:
[%DESKTOP%]\Club del Vizio - Foto Video Calendari - VM18.lnk
[%PROGRAMS%]\Club del Vizio - Foto Video Calendari - VM18.lnk
[%SYSTEM%]\Winsystemas\fotoieri.EXE
[%WINDOWS%]\$hf_mig$\KB090545\semail.exe
[%WINDOWS%]\$hf_mig$\KB090545\semail.tpl
[%WINDOWS%]\$hf_mig$\KB090545\target.dat
[%DESKTOP%]\Club del Vizio - Foto Video Calendari - VM18.lnk
[%PROGRAMS%]\Club del Vizio - Foto Video Calendari - VM18.lnk
[%SYSTEM%]\Winsystemas\fotoieri.EXE
[%WINDOWS%]\$hf_mig$\KB090545\semail.exe
[%WINDOWS%]\$hf_mig$\KB090545\semail.tpl
[%WINDOWS%]\$hf_mig$\KB090545\target.dat

How to detect Comforest:

Files:
[%DESKTOP%]\Club del Vizio - Foto Video Calendari - VM18.lnk
[%PROGRAMS%]\Club del Vizio - Foto Video Calendari - VM18.lnk
[%SYSTEM%]\Winsystemas\fotoieri.EXE
[%WINDOWS%]\$hf_mig$\KB090545\semail.exe
[%WINDOWS%]\$hf_mig$\KB090545\semail.tpl
[%WINDOWS%]\$hf_mig$\KB090545\target.dat
[%DESKTOP%]\Club del Vizio - Foto Video Calendari - VM18.lnk
[%PROGRAMS%]\Club del Vizio - Foto Video Calendari - VM18.lnk
[%SYSTEM%]\Winsystemas\fotoieri.EXE
[%WINDOWS%]\$hf_mig$\KB090545\semail.exe
[%WINDOWS%]\$hf_mig$\KB090545\semail.tpl
[%WINDOWS%]\$hf_mig$\KB090545\target.dat

Folders:
[%SYSTEM%]\Winsystemp

Registry Keys:
HKEY_CURRENT_USER\software\freeware\{491a5872-c30f-4e54-8ff1-bf31cc73dc4b}

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{1de8619d-8dd8-40ba-8a42-e1d12f119524}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{1de8619d-8dd8-40ba-8a42-e1d12f119524}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{1de8619d-8dd8-40ba-8a42-e1d12f119524}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{1de8619d-8dd8-40ba-8a42-e1d12f119524}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{1de8619d-8dd8-40ba-8a42-e1d12f119524}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{1de8619d-8dd8-40ba-8a42-e1d12f119524}

Removing Comforest:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Remove Spyboter.aq Backdoor
Delf.id Trojan Removal
Removing Pigeon.ACZ Trojan
SMEG.encrypted Trojan Information

BestPics Trojan

Removing BestPics
Categories: Trojan,Backdoor,RAT
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Backdoors combine the functionality of most other types of in one package.
Backdoors have one especially dangerous sub-class: variants that can propagate like worms.

Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.
They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,
and swap mouse buttons. However, they can be quite hard to remove.

BestPics Also known as:

[Kaspersky]Backdoor.Bestpics;
[Eset]Win32/Bestpics.A trojan;
[McAfee]BackDoor-ZG;
[F-Prot]security risk or a "backdoor" program

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\system\ntss.exe
[%WINDOWS%]\system\ntss.exe

How to detect BestPics:

Files:
[%WINDOWS%]\system\ntss.exe
[%WINDOWS%]\system\ntss.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing BestPics:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Bancos.GRI Trojan Information
Falsified.Formatter Trojan Symptoms
Bancos.GDS Trojan Removal instruction

SpywareWall Adware

Removing SpywareWall
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


Visible Symptoms:
Files in system folders:
[%SYSTEM%]\DrPMon.dll
[%SYSTEM%]\openconf.exe
[%SYSTEM%]\sysmnt.dat
[%WINDOWS%]\dinst.exe
[%WINDOWS%]\dsr.dll
[%WINDOWS%]\dsr.exe
[%WINDOWS%]\svcproc.exe
[%APPDATA%]\nsv\keys.dat
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\faq.url
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\svchost.exe\svchost.exe
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\website.url
[%STARTUP%]\popupwall.lnk
[%SYSTEM%]\drpmon.dll
[%SYSTEM%]\qumgdn.exe
[%SYSTEM%]\rldsregn.exe
[%SYSTEM%]\rndsregs.exe
[%SYSTEM%]\spnping.exe\spnping.exe
[%SYSTEM%]\winuptd.exe
[%SYSTEM%]\ysyssuuz.exe
[%WINDOWS%]\12868461b2545a878a7767e188056a07.ini
[%WINDOWS%]\bundles\spywarewall.exe
[%WINDOWS%]\temp\new105.tmp\upgrade.exe\00008260.exe
[%SYSTEM%]\DrPMon.dll
[%SYSTEM%]\openconf.exe
[%SYSTEM%]\sysmnt.dat
[%WINDOWS%]\dinst.exe
[%WINDOWS%]\dsr.dll
[%WINDOWS%]\dsr.exe
[%WINDOWS%]\svcproc.exe
[%APPDATA%]\nsv\keys.dat
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\faq.url
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\svchost.exe\svchost.exe
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\website.url
[%STARTUP%]\popupwall.lnk
[%SYSTEM%]\drpmon.dll
[%SYSTEM%]\qumgdn.exe
[%SYSTEM%]\rldsregn.exe
[%SYSTEM%]\rndsregs.exe
[%SYSTEM%]\spnping.exe\spnping.exe
[%SYSTEM%]\winuptd.exe
[%SYSTEM%]\ysyssuuz.exe
[%WINDOWS%]\12868461b2545a878a7767e188056a07.ini
[%WINDOWS%]\bundles\spywarewall.exe
[%WINDOWS%]\temp\new105.tmp\upgrade.exe\00008260.exe

How to detect SpywareWall:

Files:
[%SYSTEM%]\DrPMon.dll
[%SYSTEM%]\openconf.exe
[%SYSTEM%]\sysmnt.dat
[%WINDOWS%]\dinst.exe
[%WINDOWS%]\dsr.dll
[%WINDOWS%]\dsr.exe
[%WINDOWS%]\svcproc.exe
[%APPDATA%]\nsv\keys.dat
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\faq.url
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\svchost.exe\svchost.exe
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\website.url
[%STARTUP%]\popupwall.lnk
[%SYSTEM%]\drpmon.dll
[%SYSTEM%]\qumgdn.exe
[%SYSTEM%]\rldsregn.exe
[%SYSTEM%]\rndsregs.exe
[%SYSTEM%]\spnping.exe\spnping.exe
[%SYSTEM%]\winuptd.exe
[%SYSTEM%]\ysyssuuz.exe
[%WINDOWS%]\12868461b2545a878a7767e188056a07.ini
[%WINDOWS%]\bundles\spywarewall.exe
[%WINDOWS%]\temp\new105.tmp\upgrade.exe\00008260.exe
[%SYSTEM%]\DrPMon.dll
[%SYSTEM%]\openconf.exe
[%SYSTEM%]\sysmnt.dat
[%WINDOWS%]\dinst.exe
[%WINDOWS%]\dsr.dll
[%WINDOWS%]\dsr.exe
[%WINDOWS%]\svcproc.exe
[%APPDATA%]\nsv\keys.dat
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\faq.url
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\svchost.exe\svchost.exe
[%PROGRAM_FILES_COMMON%]\microsoft shared\dao\website.url
[%STARTUP%]\popupwall.lnk
[%SYSTEM%]\drpmon.dll
[%SYSTEM%]\qumgdn.exe
[%SYSTEM%]\rldsregn.exe
[%SYSTEM%]\rndsregs.exe
[%SYSTEM%]\spnping.exe\spnping.exe
[%SYSTEM%]\winuptd.exe
[%SYSTEM%]\ysyssuuz.exe
[%WINDOWS%]\12868461b2545a878a7767e188056a07.ini
[%WINDOWS%]\bundles\spywarewall.exe
[%WINDOWS%]\temp\new105.tmp\upgrade.exe\00008260.exe

Folders:
[%APPDATA%]\linkbho
[%APPDATA%]\spywarewall
[%PROGRAMS%]\popupwall
[%PROGRAMS%]\spywarewall
[%PROGRAM_FILES%]\popupwall
[%PROGRAM_FILES%]\spywarewall

Registry Keys:
HKEY_CLASSES_ROOT\appid\atlbrowser.exe
HKEY_CLASSES_ROOT\atlbrcon.atlbrcon
HKEY_CLASSES_ROOT\typelib\{6600d220-083f-11d6-99de-d172e92ebc2a}
HKEY_CURRENT_USER\Software\inst
HKEY_LOCAL_MACHINE\software\ddate
HKEY_LOCAL_MACHINE\system\controlset001\services\svcproc
HKEY_CLASSES_ROOT\interface\{ca621437-cb64-462a-94c4-0386e6158416}
HKEY_CURRENT_USER\software\inst
HKEY_CURRENT_USER\software\vb and vba program settings\popupwall
HKEY_CURRENT_USER\software\vb and vba program settings\spywarewall
HKEY_LOCAL_MACHINE\software\linkbho
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\popupwall
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spywarewall
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ssw_searchtool
HKEY_LOCAL_MACHINE\software\spywarewall

Registry Values:
HKEY_LOCAL_MACHINE\software\wise solutions\wise installation system\repair
HKEY_LOCAL_MACHINE\software\wise solutions\wise installation system\repair

Removing SpywareWall:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
TrojanDownloader.Win32.Small.fi Trojan Removal
CWD Backdoor Information
Removing MBat Trojan
Bancos.GLA Trojan Information
Removing Mechbot Backdoor

Belcaro.GoldenRetriever Spyware

Removing Belcaro.GoldenRetriever
Categories: Spyware
Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.

How to detect Belcaro.GoldenRetriever:

Registry Keys:
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{30402ff4-3e71-4a1c-9b4b-1cd3486a9fb2}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/lsp_.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/lsp_.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/sahagent_.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/sahagent_.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/sahhtml_.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/sahhtml_.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/sahuninstall_.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/sahuninstall_.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/sporder_.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/sporder_.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/webinstaller.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/webinstaller.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/xmlparse_.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/xmlparse_.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/xmltok_.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/xmltok_.dll

Removing Belcaro.GoldenRetriever:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
SillyDl.DMT Trojan Symptoms
Pigeon.AKW Trojan Cleaner
Bancos.GUU Trojan Information
Remove Pigeon.AQF Trojan
Bancos.GQJ Trojan Information

TrojanDownloader.Win32.PurityScan Downloader

Removing TrojanDownloader.Win32.PurityScan
Categories: Downloader
Trojans-downloaders downloads and installs new malware or adware on the computer.


TrojanDownloader.Win32.PurityScan Also known as:

[Panda]Adware/BuddyLinks,Adware/PurityScan

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\lib.dll
[%SYSTEM%]\wdm.dll
[%APPDATA%]\edtc.exe
[%APPDATA%]\lmur.exe
[%APPDATA%]\saei.exe
[%APPDATA%]\ttuh.exe
[%SYSTEM%]\bgurfny.dll
[%SYSTEM%]\clxyf.exe
[%SYSTEM%]\djnzgde.dll
[%SYSTEM%]\ekdcxir.dll
[%SYSTEM%]\eqlv.dll
[%SYSTEM%]\imjhv.dll
[%SYSTEM%]\lsi.dll
[%SYSTEM%]\ltjouq.dll
[%SYSTEM%]\nbgs.dll
[%SYSTEM%]\oozdaqbc.exe
[%SYSTEM%]\ownrggx.dll
[%SYSTEM%]\qdg.dll
[%SYSTEM%]\rass.exe
[%SYSTEM%]\rvlyklrt.exe
[%SYSTEM%]\spqh.exe
[%SYSTEM%]\svpyq.dll
[%SYSTEM%]\tmno.exe
[%SYSTEM%]\umnt.exe
[%SYSTEM%]\vbcj.dll
[%SYSTEM%]\viav.dll
[%SYSTEM%]\vylod.exe
[%SYSTEM%]\xlkpncbm.dll
[%WINDOWS%]\application data\ssme.exe
[%WINDOWS%]\system\exaz.dll
[%WINDOWS%]\system\mvfpecjl.exe
[%WINDOWS%]\system\vnkjipfc.dll
[%SYSTEM%]\lib.dll
[%SYSTEM%]\wdm.dll
[%APPDATA%]\edtc.exe
[%APPDATA%]\lmur.exe
[%APPDATA%]\saei.exe
[%APPDATA%]\ttuh.exe
[%SYSTEM%]\bgurfny.dll
[%SYSTEM%]\clxyf.exe
[%SYSTEM%]\djnzgde.dll
[%SYSTEM%]\ekdcxir.dll
[%SYSTEM%]\eqlv.dll
[%SYSTEM%]\imjhv.dll
[%SYSTEM%]\lsi.dll
[%SYSTEM%]\ltjouq.dll
[%SYSTEM%]\nbgs.dll
[%SYSTEM%]\oozdaqbc.exe
[%SYSTEM%]\ownrggx.dll
[%SYSTEM%]\qdg.dll
[%SYSTEM%]\rass.exe
[%SYSTEM%]\rvlyklrt.exe
[%SYSTEM%]\spqh.exe
[%SYSTEM%]\svpyq.dll
[%SYSTEM%]\tmno.exe
[%SYSTEM%]\umnt.exe
[%SYSTEM%]\vbcj.dll
[%SYSTEM%]\viav.dll
[%SYSTEM%]\vylod.exe
[%SYSTEM%]\xlkpncbm.dll
[%WINDOWS%]\application data\ssme.exe
[%WINDOWS%]\system\exaz.dll
[%WINDOWS%]\system\mvfpecjl.exe
[%WINDOWS%]\system\vnkjipfc.dll

How to detect TrojanDownloader.Win32.PurityScan:

Files:
[%SYSTEM%]\lib.dll
[%SYSTEM%]\wdm.dll
[%APPDATA%]\edtc.exe
[%APPDATA%]\lmur.exe
[%APPDATA%]\saei.exe
[%APPDATA%]\ttuh.exe
[%SYSTEM%]\bgurfny.dll
[%SYSTEM%]\clxyf.exe
[%SYSTEM%]\djnzgde.dll
[%SYSTEM%]\ekdcxir.dll
[%SYSTEM%]\eqlv.dll
[%SYSTEM%]\imjhv.dll
[%SYSTEM%]\lsi.dll
[%SYSTEM%]\ltjouq.dll
[%SYSTEM%]\nbgs.dll
[%SYSTEM%]\oozdaqbc.exe
[%SYSTEM%]\ownrggx.dll
[%SYSTEM%]\qdg.dll
[%SYSTEM%]\rass.exe
[%SYSTEM%]\rvlyklrt.exe
[%SYSTEM%]\spqh.exe
[%SYSTEM%]\svpyq.dll
[%SYSTEM%]\tmno.exe
[%SYSTEM%]\umnt.exe
[%SYSTEM%]\vbcj.dll
[%SYSTEM%]\viav.dll
[%SYSTEM%]\vylod.exe
[%SYSTEM%]\xlkpncbm.dll
[%WINDOWS%]\application data\ssme.exe
[%WINDOWS%]\system\exaz.dll
[%WINDOWS%]\system\mvfpecjl.exe
[%WINDOWS%]\system\vnkjipfc.dll
[%SYSTEM%]\lib.dll
[%SYSTEM%]\wdm.dll
[%APPDATA%]\edtc.exe
[%APPDATA%]\lmur.exe
[%APPDATA%]\saei.exe
[%APPDATA%]\ttuh.exe
[%SYSTEM%]\bgurfny.dll
[%SYSTEM%]\clxyf.exe
[%SYSTEM%]\djnzgde.dll
[%SYSTEM%]\ekdcxir.dll
[%SYSTEM%]\eqlv.dll
[%SYSTEM%]\imjhv.dll
[%SYSTEM%]\lsi.dll
[%SYSTEM%]\ltjouq.dll
[%SYSTEM%]\nbgs.dll
[%SYSTEM%]\oozdaqbc.exe
[%SYSTEM%]\ownrggx.dll
[%SYSTEM%]\qdg.dll
[%SYSTEM%]\rass.exe
[%SYSTEM%]\rvlyklrt.exe
[%SYSTEM%]\spqh.exe
[%SYSTEM%]\svpyq.dll
[%SYSTEM%]\tmno.exe
[%SYSTEM%]\umnt.exe
[%SYSTEM%]\vbcj.dll
[%SYSTEM%]\viav.dll
[%SYSTEM%]\vylod.exe
[%SYSTEM%]\xlkpncbm.dll
[%WINDOWS%]\application data\ssme.exe
[%WINDOWS%]\system\exaz.dll
[%WINDOWS%]\system\mvfpecjl.exe
[%WINDOWS%]\system\vnkjipfc.dll

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run

Removing TrojanDownloader.Win32.PurityScan:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Bancos.GMY Trojan Removal instruction
For.Guest Trojan Information
Bancos.HCC Trojan Cleaner