Thursday, January 22, 2009

CashDeluxe Adware

Removing CashDeluxe
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits

Visible Symptoms:
Files in system folders:
[%DESKTOP%]\intxt783.exe
[%DESKTOP%]\intxt784.dll
[%SYSTEM%]\its.txt
[%WINDOWS%]\OEM.exe
[%DESKTOP%]\intxt783.exe
[%DESKTOP%]\intxt784.dll
[%SYSTEM%]\its.txt
[%WINDOWS%]\OEM.exe

How to detect CashDeluxe:

Files:
[%DESKTOP%]\intxt783.exe
[%DESKTOP%]\intxt784.dll
[%SYSTEM%]\its.txt
[%WINDOWS%]\OEM.exe
[%DESKTOP%]\intxt783.exe
[%DESKTOP%]\intxt784.dll
[%SYSTEM%]\its.txt
[%WINDOWS%]\OEM.exe

Removing CashDeluxe:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Homiak Backdoor Information
Kuang2.veryFun Trojan Removal
Delf.eg Trojan Cleaner

Daemon Trojan

Removing Daemon
Categories: Trojan,Backdoor,Downloader,Hacker Tool,DoS
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Backdoors are used by virus writers to detect and download confidential information,
execute malicious code, destroy data, include the machine in bot networks and so forth.

The downloader either launches the new malware or registers it to enable autorun
according to the local operating system requirements.
These utilities are designed to penetrate remote computers
in order to use them as zombies (by using backdoors) or to download other malicious programs to computer.

Exploits use vulnerabilities in operating systems and applications to achieve the same result.
These programs attack web servers by sending numerous requests to the specified server,
often causing it to crash under an excessive volume of requests.

DoS trojans conduct such attacks from a single computer with the consent of the user.

Worms can carry a DoS procedure as part of their payload.

Daemon Also known as:

[Kaspersky]Daemaen.2041.b,Daemaen.2048;
[Panda]Daemaen.2048,Talon.2041.MBR;
[Computer Associates]Daemaen.2048,Talon.2041

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\System32\bounce.exe
[%WINDOWS%]\System32\bounce.exe

How to detect Daemon:

Files:
[%WINDOWS%]\System32\bounce.exe
[%WINDOWS%]\System32\bounce.exe

Removing Daemon:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Vxidl.AQV Trojan Symptoms
Pigeon.ATR Trojan Removal instruction

Lamers.Death Backdoor

Removing Lamers.Death
Categories: Backdoor,RAT
Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
Often the backdoor will not be visible in the log of active programs.
Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Lamers.Death Also known as:

[Kaspersky]Backdoor.Death.24,Backdoor.Death.21,Backdoor.Death.22,Backdoor.Death.23,Backdoor.Death.25.a,Backdoor.Death.26,Backdoor.Death.25.b,Backdoor.Death.25.f,Backdoor.Death.25.i,Backdoor.Death.25.k,Backdoor.Death.27.a,Backdoor.Death.25.c,Backdoor.Death.25.g,Backdoor.Death.26.f,Backdoor.Death.25.e,Backdoor.Death.25.j,Backdoor.Death.26.c,Backdoor.Death.26.d;
[McAfee]BackDoor-FP,BackDoor-FP.svr,BackDoor-FP.cfg;
[F-Prot]security risk or a "backdoor" program;
[Panda]Bck/LamersDeath.2.4,Bck/Death.2.1.I,Bck/Death.2.1.II,Bck/Death.23.I,Bck/Death.23.II,Bck/Death.23.III,Bck/Death.23.IV,Bck/Death.25,Bck/Death.25.B,Bck/Death.22.II,Bck/Death.22.IV,Bck/Detah.22.I,Bck/Death.26,Backdoor Program,Bck/Death.25.k,Bck/Death.27.a,Bck/Death.25.C,Backdoor Program.LC,Bck/Death.25.E,Bck/Death.25.J,Bck/Death.26.C,Bck/Death.26.D;
[Computer Associates]Backdoor/Death.2.4,Backdoor/Death.24!Server.B,Backdoor/Death_Server_family,Death!Trojan,Backdoor/Death.2.2,Backdoor/Death.2.3,Backdoor/Death.23,Backdoor/Death.25.G,Win32.Death.25.A/C,Backdoor/Death.22,Backdoor/Death.26!DLL,Backdoor/Death.26!Server,Win32.Death.26.I,Win32/Death.26.A!PWS!Trojan,Win32.Death.26.J,Backdoor/Death.27!stub,Win32.Death.27,Win32.Death.25.D,Win32/LamersDeath!Worm,Win32.Death.26.K,Win32.Death.26.A,Win32/Death.K!Trojan,Win32.Death.26.C,Win32.Death.26.E

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\interface.dll
[%WINDOWS%]\system\runexec.dll
[%WINDOWS%]\winsock.exe
[%WINDOWS%]\interface.dll
[%WINDOWS%]\system\runexec.dll
[%WINDOWS%]\winsock.exe

How to detect Lamers.Death:

Files:
[%WINDOWS%]\interface.dll
[%WINDOWS%]\system\runexec.dll
[%WINDOWS%]\winsock.exe
[%WINDOWS%]\interface.dll
[%WINDOWS%]\system\runexec.dll
[%WINDOWS%]\winsock.exe

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices

Removing Lamers.Death:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Win32.Spy.BiSpy Adware Cleaner

BrowserAid.SearchandClick BHO

Removing BrowserAid.SearchandClick
Categories: BHO
BHO (Browser Helper Object) Trojan.
The BHO waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
The method of network transport used by the attacker makes this Trojan unique.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.
Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into
the data section of an ICMP ping packet." explained the company.

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\inetp60.dll
[%WINDOWS%]\system\inetp60.dll
[%SYSTEM%]\inetp60.dll
[%WINDOWS%]\system\inetp60.dll

How to detect BrowserAid.SearchandClick:

Files:
[%SYSTEM%]\inetp60.dll
[%WINDOWS%]\system\inetp60.dll
[%SYSTEM%]\inetp60.dll
[%WINDOWS%]\system\inetp60.dll

Registry Keys:
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{087173ef-9829-4f49-8340-a524177d3f60}
HKEY_LOCAL_MACHINE\software\classes\clsid\{087173ef-9829-4f49-8340-a524177d3f60}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{087173ef-9829-4f49-8340-a524177d3f60}

Removing BrowserAid.SearchandClick:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Pigeon.AOR Trojan Cleaner

JessicaSimpsonScreenSaver Trojan

Removing JessicaSimpsonScreenSaver
Categories: Trojan,Adware
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


JessicaSimpsonScreenSaver Also known as:

[Kaspersky]AdWare.Win32.MediaMotor.a

Visible Symptoms:
Files in system folders:
[%PROGRAMS%]\filesubmit\Install jessicasimpsonsetup.exe.lnk
[%PROGRAMS%]\filesubmit\Uninstall jessicasimpsonsetup.exe.lnk
[%SYSTEM%]\Jessica Simpson.scr
[%PROGRAMS%]\filesubmit\Install jessicasimpsonsetup.exe.lnk
[%PROGRAMS%]\filesubmit\Uninstall jessicasimpsonsetup.exe.lnk
[%SYSTEM%]\Jessica Simpson.scr

How to detect JessicaSimpsonScreenSaver:

Files:
[%PROGRAMS%]\filesubmit\Install jessicasimpsonsetup.exe.lnk
[%PROGRAMS%]\filesubmit\Uninstall jessicasimpsonsetup.exe.lnk
[%SYSTEM%]\Jessica Simpson.scr
[%PROGRAMS%]\filesubmit\Install jessicasimpsonsetup.exe.lnk
[%PROGRAMS%]\filesubmit\Uninstall jessicasimpsonsetup.exe.lnk
[%SYSTEM%]\Jessica Simpson.scr

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\jessica simpson1.0
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\jessica simpson1.0
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\jessicasimpsonsetup.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\jessicasimpsonsetup.exe

Removing JessicaSimpsonScreenSaver:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
PlayTetris Trojan Symptoms
Win32.IrcContact Trojan Removal
Removing Comasp.V472 RAT
CPUHog Trojan Information
Countbot Trojan Removal instruction

Lutefed Downloader

Removing Lutefed
Categories: Downloader
This family of Trojans downloads and installs new malware or adware on the computer.
The downloader then either launches the new malware or registers it to enable autorun
according to the local operating system requirements.

The names and locations of malware to be downloaded are either coded into the
Trojan or downloaded from a specified website.

Lutefed Also known as:

[Kaspersky]Trojan-Downlaoder.Win32.Agent,Trojan-Downlaoder.Win32Agent.are;
[McAfee]Generic Downloader,Generic Downloader.u;
[Other]Win32/Lutefed,Win32/Lutefed.A

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\Updateb.exe
[%WINDOWS%]\Updateb.exe

How to detect Lutefed:

Files:
[%WINDOWS%]\Updateb.exe
[%WINDOWS%]\Updateb.exe

Removing Lutefed:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing FastTracker Spyware
Removing Arusiek Trojan
Vxidl.AWN Trojan Information
Danton Trojan Removal instruction
Remove Pigeon.EES Trojan

Redvoz Trojan

Removing Redvoz
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

Redvoz Also known as:

[Other]Win32/Redvoz.A

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\wpdss.exe
[%WINDOWS%]\Temp\wpdss000.tmp
[%SYSTEM%]\wpdss.exe
[%WINDOWS%]\Temp\wpdss000.tmp

How to detect Redvoz:

Files:
[%SYSTEM%]\wpdss.exe
[%WINDOWS%]\Temp\wpdss000.tmp
[%SYSTEM%]\wpdss.exe
[%WINDOWS%]\Temp\wpdss000.tmp

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_wpdss
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\wpdss

Removing Redvoz:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Kbd.Turkce.Aciklamasi Backdoor Cleaner
Ardamax.KeyLogger.Common.Components Spyware Information
RedHanded Spyware Symptoms
Removing VirTool.Win32.BatCrypt Backdoor
Backdoor.Osirdoor Backdoor Information