Wednesday, January 28, 2009

AntiSpyStorm Ransomware

Removing AntiSpyStorm
Categories: Ransomware
The term ransomware is commonly used to describe such software,
although the field known as cryptovirology predates the term "ransomware".

This type of ransom attack can be accomplished by (for example) attaching
a specially crafted file/program to an e-mail message and sending this to the victim.

Visible Symptoms:
Files in system folders:
[%COMMON_DESKTOPDIRECTORY%]\AntispyStorm.lnk
[%PROGRAM_FILES%]\AntispyStorm\AntispyStorm.exe
[%COMMON_DESKTOPDIRECTORY%]\AntispyStorm.lnk
[%PROGRAM_FILES%]\AntispyStorm\AntispyStorm.exe

How to detect AntiSpyStorm:

Files:
[%COMMON_DESKTOPDIRECTORY%]\AntispyStorm.lnk
[%PROGRAM_FILES%]\AntispyStorm\AntispyStorm.exe
[%COMMON_DESKTOPDIRECTORY%]\AntispyStorm.lnk
[%PROGRAM_FILES%]\AntispyStorm\AntispyStorm.exe

Folders:
[%APPDATA%]\AntispyStorm
[%COMMON_PROGRAMS%]\AntispyStorm
[%PROGRAM_FILES%]\AntispyStorm

Registry Keys:
HKEY_CLASSES_ROOT\as_ie_monitor.ie_monitor
HKEY_CLASSES_ROOT\CLSID\{0723CAE4-C2AB-4995-B749-6BC9BE984564}
HKEY_CLASSES_ROOT\CLSID\{EA201C93-F34A-47A5-B65D-AA7C95068E92}
HKEY_CLASSES_ROOT\Interface\{4619EC5B-EF8F-44E9-9A74-6E7B5F1C4188}
HKEY_CLASSES_ROOT\Interface\{EFBD98B0-0C01-4325-85F8-5E791AB33570}
HKEY_CLASSES_ROOT\mdReg.clsReg
HKEY_CLASSES_ROOT\TypeLib\{C8EBBFFA-881D-4F15-9D29-7435462E4294}
HKEY_CLASSES_ROOT\TypeLib\{D8478214-61AD-4C83-9D76-2BE980A51452}
HKEY_LOCAL_MACHINE\SOFTWARE\AntispyStorm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntispyStorm

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Removing AntiSpyStorm:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
HS.Bot Trojan Symptoms
SdBot.gen Worm Information

Popper Trojan

Removing Popper
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\arqugeu.exe
[%WINDOWS%]\nqphygo.exe
[%WINDOWS%]\obxscfj.exe
[%WINDOWS%]\pgnxnzv.exe
[%WINDOWS%]\srycase.exe
[%WINDOWS%]\arqugeu.exe
[%WINDOWS%]\nqphygo.exe
[%WINDOWS%]\obxscfj.exe
[%WINDOWS%]\pgnxnzv.exe
[%WINDOWS%]\srycase.exe

How to detect Popper:

Files:
[%WINDOWS%]\arqugeu.exe
[%WINDOWS%]\nqphygo.exe
[%WINDOWS%]\obxscfj.exe
[%WINDOWS%]\pgnxnzv.exe
[%WINDOWS%]\srycase.exe
[%WINDOWS%]\arqugeu.exe
[%WINDOWS%]\nqphygo.exe
[%WINDOWS%]\obxscfj.exe
[%WINDOWS%]\pgnxnzv.exe
[%WINDOWS%]\srycase.exe

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\windows overlay components

Removing Popper:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Pigeon.EYD Trojan Removal instruction
SillyDl.CXF Trojan Removal

Znhatnnh Trojan

Removing Znhatnnh
Categories: Trojan
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\znhatnnh.exe
[%WINDOWS%]\znhatnnh.exe

How to detect Znhatnnh:

Files:
[%WINDOWS%]\znhatnnh.exe
[%WINDOWS%]\znhatnnh.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing Znhatnnh:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Katherdoor Trojan Information
Removing IRCBot.gen Backdoor
SillyDl.DDQ Trojan Information

Razor Trojan

Removing Razor
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

Razor Also known as:

[Kaspersky]Trojan.DiskEraser.Razor,Trojan.Razor;
[McAfee]Razor;
[F-Prot]destructive program;
[Panda]Trj/Razor;
[Computer Associates]Razor!Trojan

Visible Symptoms:
Files in system folders:
[%PROFILE_TEMP%]\WBCM_Installer.exe
[%SYSTEM%]\WBCMUninst.exe
[%SYSTEM%]\WBCMUninst_Helper.exe
[%PROFILE_TEMP%]\WBCM_Installer.exe
[%SYSTEM%]\WBCMUninst.exe
[%SYSTEM%]\WBCMUninst_Helper.exe

How to detect Razor:

Files:
[%PROFILE_TEMP%]\WBCM_Installer.exe
[%SYSTEM%]\WBCMUninst.exe
[%SYSTEM%]\WBCMUninst_Helper.exe
[%PROFILE_TEMP%]\WBCM_Installer.exe
[%SYSTEM%]\WBCMUninst.exe
[%SYSTEM%]\WBCMUninst_Helper.exe

Removing Razor:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Vxidl.AQP Trojan Symptoms
MSBot.C1.Server Trojan Symptoms
Remove ExecTCP RAT
Delf.ig Trojan Information

Cmapp Adware

Removing Cmapp
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


Visible Symptoms:
Files in system folders:
[%PROFILE_TEMP%]\cmfibula.exe
[%SYSTEM%]\Targets.dat
[%SYSTEM%]\tpuninstall.exe
[%PROFILE_TEMP%]\cmfibula.exe
[%SYSTEM%]\Targets.dat
[%SYSTEM%]\tpuninstall.exe

How to detect Cmapp:

Files:
[%PROFILE_TEMP%]\cmfibula.exe
[%SYSTEM%]\Targets.dat
[%SYSTEM%]\tpuninstall.exe
[%PROFILE_TEMP%]\cmfibula.exe
[%SYSTEM%]\Targets.dat
[%SYSTEM%]\tpuninstall.exe

Folders:
[%PROGRAM_FILES%]\cmfibula

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing Cmapp:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Bancos.IDP Trojan Symptoms
Pigeon.EMI Trojan Cleaner
Cimpark Trojan Information
FakeSecurityAlert Trojan Information
Bancos.FUR Trojan Symptoms

Win32 Trojan

Removing Win32
Categories: Trojan,Adware,BHO,Worm,Backdoor,RAT,Hacker Tool,DoS
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.Worms can be classified according to the propagation method they use,
i.e. how they deliver copies of themselves to new victim machines.
Worms can also be classified by installation method, launch method and finally according
to characteristics standard to all malware: polymorphism, stealth etc.

Many of the worms which managed to cause significant outbreaks use more then
one propagation method as well as more than one infection technique.
The methods are listed separately below.
Backdoors combine the functionality of most other types of in one package.
Backdoors have one especially dangerous sub-class: variants that can propagate like worms.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.

Hacker Tools are designed to penetrate remote computers
in order to use them as zombies or to download other malicious programs to computer.
DoS programs attack web servers by sending numerous requests to the specified server,
often causing it to crash under an excessive volume of requests.



Win32 Also known as:

[Kaspersky]Backdoor.GF.13,Nuker.c2;
[Eset]Win32/Dialer.U trojan;
[McAfee]GirlFriend;
[F-Prot]destructive program;
[Panda]Trj/AF.20,Dialer.Gen,Dialer.UM,Dialer.JL,Dialer.BB,Trojan Horse,Dialer.KI,Bck/GF.13,Trj/W32.Nuker.c2;
[Other]Adware-SafeSurf.dr,W32/Agen.HLE

Visible Symptoms:
Files in system folders:
[%PROFILE%]\start menu\w1inmovieplugin.lnk
[%SYSTEM%]\services\dial.exe
[%WINDOWS%]\system\services\coolers.exe
[%WINDOWS%]\system\services\dale.exe
[%WINDOWS%]\system\services\losvse.exe
[%PROFILE%]\start menu\w1inmovieplugin.lnk
[%SYSTEM%]\services\dial.exe
[%WINDOWS%]\system\services\coolers.exe
[%WINDOWS%]\system\services\dale.exe
[%WINDOWS%]\system\services\losvse.exe

How to detect Win32:

Files:
[%PROFILE%]\start menu\w1inmovieplugin.lnk
[%SYSTEM%]\services\dial.exe
[%WINDOWS%]\system\services\coolers.exe
[%WINDOWS%]\system\services\dale.exe
[%WINDOWS%]\system\services\losvse.exe
[%PROFILE%]\start menu\w1inmovieplugin.lnk
[%SYSTEM%]\services\dial.exe
[%WINDOWS%]\system\services\coolers.exe
[%WINDOWS%]\system\services\dale.exe
[%WINDOWS%]\system\services\losvse.exe

Folders:
[%PROGRAM_FILES%]\dfind.x32
[%PROGRAM_FILES%]\dfind.x64

Registry Keys:
HKEY_CURRENT_USER\software\dfind.x32
HKEY_CURRENT_USER\software\dfind.x64
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\dfind32109
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\dfind64109

Removing Win32:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing TrojanSpy.Win32.KeyLogger.al Trojan
p0rn.related Adware Removal instruction
Noob Trojan Cleaner
Bancos.BQO Trojan Symptoms

CashDialer Adware

Removing CashDialer
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


CashDialer Also known as:

[McAfee]CashDialer

How to detect CashDialer:

Folders:
[%PROGRAM_FILES%]\incredifind
[%PROGRAM_FILES%]\incred~1\bho

Removing CashDialer:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
SillyDl.CIX Trojan Cleaner
Removing Vxidl.AHC Trojan