Tuesday, November 18, 2008

Protect Trojan

Removing Protect
Categories: Trojan,DoS
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
DoS programs attack web servers by sending numerous requests to the specified server,
often causing it to crash under an excessive volume of requests.



Protect Also known as:

[Kaspersky]Trojan.Protect;
[McAfee]Protect;
[F-Prot]destructive program;
[Panda]Trj/5486;
[Computer Associates]Protect!Trojan

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\mswsck32.dll
[%SYSTEM%]\\mstds.exe
[%SYSTEM%]\mswsck32.dll
[%SYSTEM%]\\mstds.exe

How to detect Protect:

Files:
[%SYSTEM%]\mswsck32.dll
[%SYSTEM%]\\mstds.exe
[%SYSTEM%]\mswsck32.dll
[%SYSTEM%]\\mstds.exe

Removing Protect:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Sprincape Trojan Symptoms
Removing Win32.Rbot.ACI Trojan
Chiclen Trojan Removal
Pigeon.AVDT Trojan Removal
Pigeon.AZM Trojan Removal

SysUp Trojan

Removing SysUp
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

SysUp Also known as:

[Other]Smalldrp.JDU,Trojan.Dropper,Troj/VB-AZA

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\sysupd.exe
[%SYSTEM%]\sysupd.exe

How to detect SysUp:

Files:
[%SYSTEM%]\sysupd.exe
[%SYSTEM%]\sysupd.exe

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{7765f8fd-d9a4-444f-8a60-ac8cdb7871d9}
HKEY_CLASSES_ROOT\interface\{3fa7aca5-84e6-4d48-99a5-86ee52226170}
HKEY_CLASSES_ROOT\interface\{6393eaf6-7913-498e-b84e-e578a2181552}
HKEY_CLASSES_ROOT\interface\{726ad182-3357-4300-85bd-e051aa264cdc}
HKEY_CLASSES_ROOT\prjbdunionext20060711.cfiledownload
HKEY_CLASSES_ROOT\prjbdunionext20060711.cvsvirus
HKEY_CLASSES_ROOT\typelib\{693b2d0e-7dcd-4169-9428-c91941c1e1ea}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing SysUp:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing TrojanDownloader.Win32.Swizzor.bn Trojan
CNNIC.Update Hijacker Removal instruction
Small.ab Trojan Symptoms
Removing Espionage Spyware
Win32.Keylogger.G!Trojan Trojan Cleaner

XMLid BHO

Removing XMLid
Categories: BHO
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.

How to detect XMLid:

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{11111111-1111-1111-1111-11111111111}

Removing XMLid:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Spaeher Trojan Cleaner

EnergyPlugin Adware

Removing EnergyPlugin
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


Visible Symptoms:
Files in system folders:
[%COMMON_PROGRAMS%]\E-nrgyPlus\E-nrgyPlus.lnk
[%COMMON_PROGRAMS%]\E-nrgyPlus\homepage.lnk
[%COMMON_PROGRAMS%]\E-nrgyPlus\UnInstall.lnk
[%COMMON_PROGRAMS%]\E-nrgyPlus\E-nrgyPlus.lnk
[%COMMON_PROGRAMS%]\E-nrgyPlus\homepage.lnk
[%COMMON_PROGRAMS%]\E-nrgyPlus\UnInstall.lnk

How to detect EnergyPlugin:

Files:
[%COMMON_PROGRAMS%]\E-nrgyPlus\E-nrgyPlus.lnk
[%COMMON_PROGRAMS%]\E-nrgyPlus\homepage.lnk
[%COMMON_PROGRAMS%]\E-nrgyPlus\UnInstall.lnk
[%COMMON_PROGRAMS%]\E-nrgyPlus\E-nrgyPlus.lnk
[%COMMON_PROGRAMS%]\E-nrgyPlus\homepage.lnk
[%COMMON_PROGRAMS%]\E-nrgyPlus\UnInstall.lnk

Folders:
[%PROGRAM_FILES%]\E-nrgyPlus
[%PROGRAMS%]\energyplugin
[%PROGRAM_FILES%]\energyplugin

Registry Keys:
HKEY_CLASSES_ROOT\dial\defaulticon
HKEY_CLASSES_ROOT\dial\shell

Registry Values:
HKEY_CLASSES_ROOT\dial
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet settings\user agent\post platform
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet settings\user agent\post platform
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet settings\user agent\post platform
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet settings\user agent\post platform
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet settings\user agent\post platform
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing EnergyPlugin:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
SystemMD Adware Removal instruction
Vxidl.AWE Trojan Removal instruction
Toledorz Backdoor Information
Istbar.dr Downloader Symptoms
Zlob.Fam.Image ActiveX Access Trojan Symptoms

Pigeon.APO Trojan

Removing Pigeon.APO
Categories: Trojan
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

How to detect Pigeon.APO:

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_applitcation_log
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\windows applitcation log

Removing Pigeon.APO:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Adex Trojan Removal
Removing Web.Asylum Trojan
Surila Trojan Symptoms
RelatedLinks Adware Information

MBKWBar Toolbar

Removing MBKWBar
Categories: Toolbar
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.

Visible Symptoms:
Files in system folders:
[%PROFILE_TEMP%]\mbkwnst.exe
[%PROFILE_TEMP%]\mbkwnst.inf
[%WINDOWS%]\mbkwnst.exe
[%PROFILE_TEMP%]\mbkwnst.exe
[%PROFILE_TEMP%]\mbkwnst.inf
[%WINDOWS%]\mbkwnst.exe

How to detect MBKWBar:

Files:
[%PROFILE_TEMP%]\mbkwnst.exe
[%PROFILE_TEMP%]\mbkwnst.inf
[%WINDOWS%]\mbkwnst.exe
[%PROFILE_TEMP%]\mbkwnst.exe
[%PROFILE_TEMP%]\mbkwnst.inf
[%WINDOWS%]\mbkwnst.exe

Folders:
[%PROGRAM_FILES%]\mbkwbar

Registry Keys:
HKEY_CLASSES_ROOT\CLSID\{EA5A82FB-D6BE-44F9-9363-B1ABABC153C1}
HKEY_CLASSES_ROOT\ietoolbar.toolbarimpl
HKEY_CLASSES_ROOT\ietoolbar.toolbarimpl.1
HKEY_CLASSES_ROOT\typelib\{4a7dba74-e729-4ec8-92e2-ffd83921449f}
HKEY_CURRENT_USER\software\mbkwbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\mbkwbar
HKEY_CLASSES_ROOT\clsid\{ea5a82fb-d6be-44f9-9363-b1ababc153c1}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{ea5a82fb-d6be-44f9-9363-b1ababc153c1}

Removing MBKWBar:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
KillSpy Ransomware Removal instruction

Pigeon.Graybird Trojan

Removing Pigeon.Graybird
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

Pigeon.Graybird Also known as:

[Kaspersky]Backdoor.Win32.Hupigon.ayj;
[Other]Win32/Pigeon!generic,Win32/Pigeon.780288!

How to detect Pigeon.Graybird:

Registry Values:
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\graypigeon_hacker.com.cn

Removing Pigeon.Graybird:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Sub7Finder Backdoor Removal
Scoob Trojan Information
Remove Delf.cc Trojan