AntiLamer.Light Trojan

AntiLamer.Light malware description and removal detail
Categories:Trojan,Adware,Spyware,RAT,Hacker Tool
Also known as:

[Kaspersky]Trojan.PSW.AlLight.201;
[Eset]Win32/PSW.AlLight.201 trojan;
[Panda]Trj/PSW.AlLight,Dialer.DQ;
[Computer Associates]Win32.AntilamLite.201,Win32/PSW.AlLight.201.Trojan

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\runwin32.exe
[%DESKTOP%]\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\programs\5-1-14-24.lnk
[%WINDOWS%]\system\runwin.exe
[%WINDOWS%]\system\runwindows32.exe
[%WINDOWS%]\runwin32.exe
[%DESKTOP%]\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\programs\5-1-14-24.lnk
[%WINDOWS%]\system\runwin.exe
[%WINDOWS%]\system\runwindows32.exe

In order to ensure that the AntiLamer.Light is launched automatically each time the system is booted, the AntiLamer.Light adds a link to its executable file in the system registry:
HKLM\Microsoft\Windows\CurrentVersion\Run
[%WINDOWS%]\runwin32.exe
[%WINDOWS%]\system\runwin.exe
[%WINDOWS%]\system\runwindows32.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting AntiLamer.Light:

Files:
[%WINDOWS%]\runwin32.exe
[%DESKTOP%]\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\programs\5-1-14-24.lnk
[%WINDOWS%]\system\runwin.exe
[%WINDOWS%]\system\runwindows32.exe
[%WINDOWS%]\runwin32.exe
[%DESKTOP%]\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\programs\5-1-14-24.lnk
[%WINDOWS%]\system\runwin.exe
[%WINDOWS%]\system\runwindows32.exe

Folders:
[%PROGRAM_FILES%]\websx

Registry Keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7589EEE6-E336-11D4-8A7E-EE1D971D9B47}
HKEY_LOCAL_MACHINE\software\classes\acontixcontrol
HKEY_LOCAL_MACHINE\software\classes\clsid\{7589eee6-e336-11d4-8a7e-ee1d971d9b47}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{7589eee6-e336-11d4-8a7e-ee1d971d9b47}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/acontix.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/acontix.ocx
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\window
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/acontix.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/acontix.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\5-1-14-24
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\5-1-14-24
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\5-1-14-24

Removing AntiLamer.Light:

An up-to-date copy of ExterminateIt should detect and prevent infection from AntiLamer.Light.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove AntiLamer.Light manually.

To completely manually remove AntiLamer.Light malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with AntiLamer.Light.

  1. Use Task Manager to terminate the AntiLamer.Light process.
  2. Delete the original AntiLamer.Light file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes AntiLamer.Light from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of AntiLamer.Light!


Also Be Aware of the Following Threats:
Remove tackletour.com Tracking Cookie
Insurector Backdoor Cleaner
Remove Pigeon.EYP Trojan
Slagent Trojan Removal
Zalivator.Pro.server RAT Removal

0 comments:

Post a Comment

Blog Archive