Tuesday, January 27, 2009

WebD Trojan

Removing WebD
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\webd.exe
[%WINDOWS%]\webd.exe

How to detect WebD:

Files:
[%WINDOWS%]\webd.exe
[%WINDOWS%]\webd.exe

Removing WebD:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing Qcbar.AdultLinks BHO

PWS.Zhengtu Trojan

Removing PWS.Zhengtu
Categories: Trojan,Hacker Tool
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Hacker Tools are designed to penetrate remote computers
in order to use them as zombies or to download other malicious programs to computer.

PWS.Zhengtu Also known as:

[McAfee]PWS-Zhengtu;
[Other]Win32/Frethog.BG,Infostealer.Gampass,Win32/Tuzheng

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\CN_SPI32.DLL
[%SYSTEM%]\CN_SPI32.DLL

How to detect PWS.Zhengtu:

Files:
[%SYSTEM%]\CN_SPI32.DLL
[%SYSTEM%]\CN_SPI32.DLL

Removing PWS.Zhengtu:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Inud Trojan Removal instruction
Mmail.olly2html Trojan Information
Removing Ping Backdoor

Aureate.Group.Mail Adware

Removing Aureate.Group.Mail
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


Visible Symptoms:
Files in system folders:
[%SYSTEM%]\adimage.dll
[%SYSTEM%]\ajj.exe
[%SYSTEM%]\gmaglue.exe
[%PROFILE%]\start menu\aureate group mail.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail help.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail homepage.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail.lnk
[%PROGRAMS%]\aureate group mail\read me.lnk
[%SYSTEM%]\amcis2.dll
[%SYSTEM%]\adimage.dll
[%SYSTEM%]\ajj.exe
[%SYSTEM%]\gmaglue.exe
[%PROFILE%]\start menu\aureate group mail.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail help.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail homepage.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail.lnk
[%PROGRAMS%]\aureate group mail\read me.lnk
[%SYSTEM%]\amcis2.dll

How to detect Aureate.Group.Mail:

Files:
[%SYSTEM%]\adimage.dll
[%SYSTEM%]\ajj.exe
[%SYSTEM%]\gmaglue.exe
[%PROFILE%]\start menu\aureate group mail.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail help.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail homepage.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail.lnk
[%PROGRAMS%]\aureate group mail\read me.lnk
[%SYSTEM%]\amcis2.dll
[%SYSTEM%]\adimage.dll
[%SYSTEM%]\ajj.exe
[%SYSTEM%]\gmaglue.exe
[%PROFILE%]\start menu\aureate group mail.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail help.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail homepage.lnk
[%PROGRAMS%]\aureate group mail\aureate group mail.lnk
[%PROGRAMS%]\aureate group mail\read me.lnk
[%SYSTEM%]\amcis2.dll

Folders:
[%PROFILE%]\start menu\programs\aureate group mail
[%PROGRAM_FILES%]\aureate\group mail

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{ebbfe26d-bdf0-11d2-bbe5-00609419f467}
HKEY_LOCAL_MACHINE\software\classes\typelib\{ebbfe26d-bdf0-11d2-bbe5-00609419f467}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\aureate group mail

Removing Aureate.Group.Mail:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Win32.Killlav.ay Trojan Removal
Remove Adserver.pollstar.Tracking.Cookie Tracking Cookie
cj Adware Removal
Bancos.GTQ Trojan Symptoms
Bancos.HEC Trojan Symptoms

WinSpyControl Ransomware

Removing WinSpyControl
Categories: Ransomware
A cryptovirus, cryptotrojan or cryptoworm is a type of
malware that encrypts the data belonging to an individual on a computer,
demanding a ransom for its restoration.

The term ransomware is commonly used to describe such software,
although the field known as cryptovirology predates the term "ransomware".

This type of ransom attack can be accomplished by (for example) attaching
a specially crafted file/program to an e-mail message and sending this to the victim.

If the victim opens/executes the attachment, the program encrypts
a number of files on the victim's computer. A ransom note is then left behind for the victim.

The victim will be unable to open the encrypted files without the correct decryption key.
Once the ransom demanded in the ransom note is paid, the cracker may (or may not)
send the decryption key, enabling decryption of the "kidnapped" files.

Visible Symptoms:
Files in system folders:
[%COMMON_DESKTOPDIRECTORY%]\WinSpyControl.lnk
[%PROFILE_TEMP%]\NI.UGA6P_0001_N115M0110\settings.ini
[%COMMON_DESKTOPDIRECTORY%]\WinSpyControl.lnk
[%PROFILE_TEMP%]\NI.UGA6P_0001_N115M0110\settings.ini

How to detect WinSpyControl:

Files:
[%COMMON_DESKTOPDIRECTORY%]\WinSpyControl.lnk
[%PROFILE_TEMP%]\NI.UGA6P_0001_N115M0110\settings.ini
[%COMMON_DESKTOPDIRECTORY%]\WinSpyControl.lnk
[%PROFILE_TEMP%]\NI.UGA6P_0001_N115M0110\settings.ini

Folders:
[%APPDATA%]\WinSpyControl
[%COMMON_PROGRAMS%]\WinSpyControl
[%PROGRAM_FILES%]\WinSpyControl
[%PROGRAM_FILES_COMMON%]\WinSpyControl

Registry Keys:
HKEY_CURRENT_USER\software\winspycontrol

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\products
HKEY_LOCAL_MACHINE\software\products
HKEY_LOCAL_MACHINE\software\winspycontrol
HKEY_LOCAL_MACHINE\software\winspycontrol
HKEY_LOCAL_MACHINE\software\winspycontrol
HKEY_LOCAL_MACHINE\software\winspycontrol
HKEY_LOCAL_MACHINE\software\winspycontrol
HKEY_LOCAL_MACHINE\software\winspycontrol\settings

Removing WinSpyControl:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing Microsoft.Media.Server.Denial.of.Service.Attack DoS
TrojanDownloader.Win32.Small.nu Trojan Removal instruction
Removing Daum Hijacker

IP Adware

This summary is not available. Please click here to view the post.

cl Trojan

Removing cl
Categories: Trojan,Adware
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits

How to detect cl:

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing cl:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing PSW.Mewey Trojan
Banker.CNQ Trojan Cleaner

Coced.ASPask!PWS!Troja Trojan

Removing Coced.ASPask!PWS!Troja
Categories: Trojan,Hacker Tool
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
These utilities are designed to penetrate remote computers
in order to use them as zombies (by using backdoors) or to download other malicious programs to computer.

Exploits use vulnerabilities in operating systems and applications to achieve the same result.

Visible Symptoms:
Files in system folders:
[%COMMON_DOCUMENTS%]\Program\Zipclix\zipclix.dll
[%COMMON_DOCUMENTS%]\Program\Zipclix\zipclix.dll

How to detect Coced.ASPask!PWS!Troja:

Files:
[%COMMON_DOCUMENTS%]\Program\Zipclix\zipclix.dll
[%COMMON_DOCUMENTS%]\Program\Zipclix\zipclix.dll

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\zipclix
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\zipclix

Removing Coced.ASPask!PWS!Troja:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Remove Foqerc DoS
ComLoad RAT Removal instruction
Pigeon.ABD Trojan Cleaner