Wednesday, January 28, 2009

Scratch.and.Win Adware

Removing Scratch.and.Win
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\downloaded program files\conflict.1\fswinst.ocx
[%WINDOWS%]\downloaded program files\conflict.1\fswinst.ocx

How to detect Scratch.and.Win:

Files:
[%WINDOWS%]\downloaded program files\conflict.1\fswinst.ocx
[%WINDOWS%]\downloaded program files\conflict.1\fswinst.ocx

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{d04e6445-dff4-457b-8f24-444cf3061e5d}

Removing Scratch.and.Win:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Remove BDPlugin BHO

SupaSleep Adware

Removing SupaSleep
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


SupaSleep Also known as:

[Kaspersky]Trojan-Clicker.Win32.Small.lt;
[McAfee]Generic AdClicker.b

How to detect SupaSleep:

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run

Removing SupaSleep:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing QDel314 Trojan

Veygolk Trojan

Removing Veygolk
Categories: Trojan
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Veygolk Also known as:

[Kaspersky]Trojan-Spy.Win32.Agent.awr

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\drivers\kbd.dll
[%SYSTEM%]\drivers\test.dll
[%SYSTEM%]\drivers\kbd.dll
[%SYSTEM%]\drivers\test.dll

How to detect Veygolk:

Files:
[%SYSTEM%]\drivers\kbd.dll
[%SYSTEM%]\drivers\test.dll
[%SYSTEM%]\drivers\kbd.dll
[%SYSTEM%]\drivers\test.dll

Removing Veygolk:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Sendmail Trojan Removal
dx50codec Trojan Removal instruction
Pigeon.EPR Trojan Cleaner
Removing Eps Trojan
Vxidl.APQ Trojan Cleaner

Golid Trojan

Removing Golid
Categories: Trojan,Downloader
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
The downloader either launches the new malware or registers it to enable autorun
according to the local operating system requirements.

Golid Also known as:

[Kaspersky]Trojan.WIn32.Agent.aw;
[McAfee]Downloader-VA;
[Panda]Adware/Iagold;
[Computer Associates]Win32/Golid!Trojan;
[Other]W32/Agent.BCD

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\d15.0xe
[%SYSTEM%]\d15.exe
[%SYSTEM%]\drivers\wsgutrkn.sys
[%SYSTEM%]\GoGo9CP.0ll
[%SYSTEM%]\ndesjcoq6.exe
[%SYSTEM%]\drivers\kjjivgjs.sys
[%SYSTEM%]\qgwyaicl6.exe
[%SYSTEM%]\d15.0xe
[%SYSTEM%]\d15.exe
[%SYSTEM%]\drivers\wsgutrkn.sys
[%SYSTEM%]\GoGo9CP.0ll
[%SYSTEM%]\ndesjcoq6.exe
[%SYSTEM%]\drivers\kjjivgjs.sys
[%SYSTEM%]\qgwyaicl6.exe

How to detect Golid:

Files:
[%SYSTEM%]\d15.0xe
[%SYSTEM%]\d15.exe
[%SYSTEM%]\drivers\wsgutrkn.sys
[%SYSTEM%]\GoGo9CP.0ll
[%SYSTEM%]\ndesjcoq6.exe
[%SYSTEM%]\drivers\kjjivgjs.sys
[%SYSTEM%]\qgwyaicl6.exe
[%SYSTEM%]\d15.0xe
[%SYSTEM%]\d15.exe
[%SYSTEM%]\drivers\wsgutrkn.sys
[%SYSTEM%]\GoGo9CP.0ll
[%SYSTEM%]\ndesjcoq6.exe
[%SYSTEM%]\drivers\kjjivgjs.sys
[%SYSTEM%]\qgwyaicl6.exe

Removing Golid:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
ICQ.Chat.Kicker Trojan Symptoms
AdManager Adware Information

Blurax Trojan

Removing Blurax
Categories: Trojan,Backdoor
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
Often the backdoor will not be visible in the log of active programs.

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\SysPr.prx
[%SYSTEM%]\greeno.exe
[%SYSTEM%]\svvhostc.dat
[%SYSTEM%]\svvhostc.exe
[%SYSTEM%]\svvhostt.dat
[%SYSTEM%]\svvhostt.exe
[%SYSTEM%]\SysPr.prx
[%SYSTEM%]\greeno.exe
[%SYSTEM%]\svvhostc.dat
[%SYSTEM%]\svvhostc.exe
[%SYSTEM%]\svvhostt.dat
[%SYSTEM%]\svvhostt.exe

How to detect Blurax:

Files:
[%SYSTEM%]\SysPr.prx
[%SYSTEM%]\greeno.exe
[%SYSTEM%]\svvhostc.dat
[%SYSTEM%]\svvhostc.exe
[%SYSTEM%]\svvhostt.dat
[%SYSTEM%]\svvhostt.exe
[%SYSTEM%]\SysPr.prx
[%SYSTEM%]\greeno.exe
[%SYSTEM%]\svvhostc.dat
[%SYSTEM%]\svvhostc.exe
[%SYSTEM%]\svvhostt.dat
[%SYSTEM%]\svvhostt.exe

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\greeno
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\network\greeno
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\greeno
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\svvhost

Registry Values:
HKEY_LOCAL_MACHINE\microsoft\active setup\installed components\{9492c3b6-c349-36d4-a437-88cbb3453251}
HKEY_LOCAL_MACHINE\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9492c3b6-c349-36d4-a437-88cbb3453251}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing Blurax:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Als Backdoor Cleaner
Fatal.ckup.Reborn DoS Cleaner
TrojanDownloader.Win32.Swizzor.bg Downloader Symptoms

OptServe Adware

Removing OptServe
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\optserve.dll
[%SYSTEM%]\optserve.exe
[%SYSTEM%]\optserve.dll
[%SYSTEM%]\optserve.exe

How to detect OptServe:

Files:
[%SYSTEM%]\optserve.dll
[%SYSTEM%]\optserve.exe
[%SYSTEM%]\optserve.dll
[%SYSTEM%]\optserve.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing OptServe:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
CC Trojan Cleaner
Deltabar.Deltaclick BHO Symptoms
Network1.Popups Adware Removal

Superlogy.com BHO

Removing Superlogy.com
Categories: BHO,Hijacker,Toolbar
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.When the default home page is hijacked, the browser opens to the web page set by the hijacker
instead of the user's designated home page. In some cases, the hijacker may block users from
restoring their desired home page.
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\aadl.dll
[%WINDOWS%]\system\aadl.dll
[%SYSTEM%]\aadl.dll
[%WINDOWS%]\system\aadl.dll

How to detect Superlogy.com:

Files:
[%SYSTEM%]\aadl.dll
[%WINDOWS%]\system\aadl.dll
[%SYSTEM%]\aadl.dll
[%WINDOWS%]\system\aadl.dll

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{95e02c52-05fc-425d-8378-9da70f9cd763}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{95e02c52-05fc-425d-8378-9da70f9cd763}
HKEY_LOCAL_MACHINE\software\classes\clsid\{95e02c52-05fc-425d-8378-9da70f9cd763}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{95e02c52-05fc-425d-8378-9da70f9cd763}

Removing Superlogy.com:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Remove Sconhep Trojan