GTBot Trojan

GTBot malware description and removal detail
Categories:Trojan,Worm,Backdoor,DoS
Also known as:

[Kaspersky]Backdoor.IRC.Bnc.b,Backdoor.IRC.Cloner,Backdoor.IRC.Prison,DoS.Win32.Soldier,Trojan.VBS.Lamping,Backdoor.IRC.Flood.a;
[McAfee]DDoS-Soldier;
[F-Prot]destructive program;
[Panda]Backdoor Program,DoS/Win32.Soldier,Univ.EP,Worm Generic.LC;
[Computer Associates]IRC.Flood,mIRC/IRCFlood.C!Trojan,mIRC/Shaz.A!Worm,Pirch/Sub7.Acnu!Trojan,VBS/BackdoorPing!Trojan,Win32/Pepsi!Flooder!Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing GTBot:

An up-to-date copy of ExterminateIt should detect and prevent infection from GTBot.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove GTBot manually.

To completely manually remove GTBot malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with GTBot.

  1. Use Task Manager to terminate the GTBot process.
  2. Delete the original GTBot file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes GTBot from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of GTBot!


Also Be Aware of the Following Threats:
NeoSpy Ransomware Symptoms
Adware.SearchAid Trojan Removal instruction
Tihsho Trojan Removal
JTTP Trojan Cleaner
IRC.Zapchast Backdoor Removal

0 comments

Bancos.IMH Trojan

Bancos.IMH malware description and removal detail
Categories:Trojan
Also known as:

[Kaspersky]Trojan-Downloader.Win32.Banload.chi;
[McAfee]PWS-Banker.gen.cc

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Bancos.IMH:

An up-to-date copy of ExterminateIt should detect and prevent infection from Bancos.IMH.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Bancos.IMH manually.

To completely manually remove Bancos.IMH malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Bancos.IMH.

  1. Use Task Manager to terminate the Bancos.IMH process.
  2. Delete the original Bancos.IMH file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Bancos.IMH from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Bancos.IMH!


Also Be Aware of the Following Threats:
Triamber Trojan Symptoms
Pigeon.DZT Trojan Information
Remove Frethog.AFB Trojan
THCunREAL Trojan Removal instruction
GDY3M.Adult Adware Information

0 comments

JS.Zecho Trojan

JS.Zecho malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing JS.Zecho:

An up-to-date copy of ExterminateIt should detect and prevent infection from JS.Zecho.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove JS.Zecho manually.

To completely manually remove JS.Zecho malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with JS.Zecho.

  1. Use Task Manager to terminate the JS.Zecho process.
  2. Delete the original JS.Zecho file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes JS.Zecho from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of JS.Zecho!


Also Be Aware of the Following Threats:
HVL.ListMaker RAT Symptoms
PSW.Kuang Trojan Information
Exploder Backdoor Removal
REG.Drakken Trojan Removal instruction
Frethog.ACF Trojan Symptoms

0 comments

Vxidl.AND Trojan

Vxidl.AND malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Vxidl.AND:

An up-to-date copy of ExterminateIt should detect and prevent infection from Vxidl.AND.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Vxidl.AND manually.

To completely manually remove Vxidl.AND malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Vxidl.AND.

  1. Use Task Manager to terminate the Vxidl.AND process.
  2. Delete the original Vxidl.AND file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Vxidl.AND from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Vxidl.AND!


Also Be Aware of the Following Threats:
Pigeon.AVUG Trojan Removal instruction
Remove VBS.WordInfector.Variant Trojan
Removing TrojanClicker.Win32.Stixo Trojan
Bancos.IFZ Trojan Removal instruction
YahTools Hacker Tool Symptoms

0 comments

JTTP Trojan

JTTP malware description and removal detail
Categories:Trojan
Also known as:

[Kaspersky]Pro-Alife.3423;
[Eset]Rescue virus;
[McAfee]Univ/f;
[Computer Associates]JTTP.3423

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing JTTP:

An up-to-date copy of ExterminateIt should detect and prevent infection from JTTP.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove JTTP manually.

To completely manually remove JTTP malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with JTTP.

  1. Use Task Manager to terminate the JTTP process.
  2. Delete the original JTTP file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes JTTP from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of JTTP!


Also Be Aware of the Following Threats:
Doomob Trojan Cleaner
Ebates.MoneyMaker Adware Information
Vxidl.AXK Trojan Removal
Removing TrojanDownloader.Win32.VB.ct Trojan
Sofa.BAT Trojan Cleaner

0 comments

Win32.Joiner.F!Joiner Trojan

Win32.Joiner.F!Joiner malware description and removal detail
Categories:Trojan
Also known as:

[Kaspersky]TrojanDropper.Win32.Joiner.f;
[Panda]W32/TrojanRunner.F;
[Computer Associates]Win32.TheJoiner.15x.A

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Win32.Joiner.F!Joiner:

An up-to-date copy of ExterminateIt should detect and prevent infection from Win32.Joiner.F!Joiner.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Win32.Joiner.F!Joiner manually.

To completely manually remove Win32.Joiner.F!Joiner malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Win32.Joiner.F!Joiner.

  1. Use Task Manager to terminate the Win32.Joiner.F!Joiner process.
  2. Delete the original Win32.Joiner.F!Joiner file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Win32.Joiner.F!Joiner from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Win32.Joiner.F!Joiner!


Also Be Aware of the Following Threats:
PeopleOnPage.AproposMedia BHO Symptoms
Teflon.Oil.Patch Trojan Removal instruction
Bancos.HHZ Trojan Removal
TrojanClicker.Win32.Getfound Trojan Information
Tapiras Trojan Information

0 comments

Vxidl.AQE Trojan

Vxidl.AQE malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Vxidl.AQE:

An up-to-date copy of ExterminateIt should detect and prevent infection from Vxidl.AQE.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Vxidl.AQE manually.

To completely manually remove Vxidl.AQE malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Vxidl.AQE.

  1. Use Task Manager to terminate the Vxidl.AQE process.
  2. Delete the original Vxidl.AQE file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Vxidl.AQE from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Vxidl.AQE!


Also Be Aware of the Following Threats:
Bat.Zor Trojan Removal
Bancos.HCB Trojan Removal
SmartClicks.com Tracking Cookie Removal instruction
Zalivator.Pro.server RAT Cleaner
TrojanClicker.Win32.VB.ad Trojan Removal

0 comments

Zosu Trojan

Zosu malware description and removal detail
Categories:Trojan
Also known as:

[Kaspersky]Backdoor.Win32.Zosu,Backdoor.Win32.Zosu.b;
[McAfee]Proxy-ProxyList;
[Other]Win32/Zosu,Win32/Zosu.B,Proxy-ProxyList

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\drivers\ndisfilter.sys
[%SYSTEM%]\pfplgflt.dll
[%SYSTEM%]\drivers\ndisfilter.sys
[%SYSTEM%]\pfplgflt.dll

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Zosu:

Files:
[%SYSTEM%]\drivers\ndisfilter.sys
[%SYSTEM%]\pfplgflt.dll
[%SYSTEM%]\drivers\ndisfilter.sys
[%SYSTEM%]\pfplgflt.dll

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontroset\services\ndisfilter

Removing Zosu:

An up-to-date copy of ExterminateIt should detect and prevent infection from Zosu.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Zosu manually.

To completely manually remove Zosu malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Zosu.

  1. Use Task Manager to terminate the Zosu process.
  2. Delete the original Zosu file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Zosu from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Zosu!


Also Be Aware of the Following Threats:
Ment Trojan Symptoms
DlExaw.M!DLL!Trojan Trojan Symptoms
Remove BAT.Hexvir Trojan
Austr.Para.Lipo Trojan Removal
Complete.Keystroke.Logger Spyware Removal

0 comments

Win32.TrojanDownloader.PurityScan Trojan

Win32.TrojanDownloader.PurityScan malware description and removal detail
Categories:Trojan,Downloader
Also known as:

[Kaspersky]TrojanDownloader.Win32.PurityScan.j;
[Eset]Win32/TrojanDownloader.PurityScan.E trojan,Win32/TrojanDownloader.PurityScan.I trojan,Win32/TrojanDownloader.PurityScan.J trojan;
[Panda]Adware/PurityScan

Visible Symptoms:
Files in system folders:
[%APPDATA%]\oasb.exe
[%SYSTEM%]\bhaqjv.exe
[%SYSTEM%]\bnzzhj.dll
[%SYSTEM%]\ecm.dll
[%SYSTEM%]\edyyogo.dll
[%SYSTEM%]\ewbgup.exe
[%SYSTEM%]\fewtbdb.dll
[%SYSTEM%]\fpym.dll
[%SYSTEM%]\ghhe.exe
[%SYSTEM%]\gol.exe
[%SYSTEM%]\hfwpjpe.exe
[%SYSTEM%]\iqcmiir.exe
[%SYSTEM%]\itwiiha.dll
[%SYSTEM%]\jgxlxbdq.dll
[%SYSTEM%]\jnj.dll
[%SYSTEM%]\lunfbalo.dll
[%SYSTEM%]\lwycd.exe
[%SYSTEM%]\njw.exe
[%SYSTEM%]\ojdkpr.dll
[%SYSTEM%]\pvfw.exe
[%SYSTEM%]\qoxuzlr.exe
[%SYSTEM%]\qra.dll
[%SYSTEM%]\rea.dll
[%SYSTEM%]\rfin.dll
[%SYSTEM%]\tlb.exe
[%SYSTEM%]\uwfywiy.exe
[%SYSTEM%]\vanaiuxq.dll
[%SYSTEM%]\vnhhppe.dll
[%SYSTEM%]\vsvzv.exe
[%SYSTEM%]\wcsxecdo.exe
[%SYSTEM%]\wrkr.exe
[%SYSTEM%]\xxnagz.dll
[%SYSTEM%]\yae.exe
[%SYSTEM%]\yqatopy.dll
[%SYSTEM%]\zgpwcgsx.exe
[%WINDOWS%]\application data\ncae.exe
[%WINDOWS%]\system\plr.exe
[%WINDOWS%]\system\sqep.exe
[%WINDOWS%]\system\wtwj.dll
[%APPDATA%]\oasb.exe
[%SYSTEM%]\bhaqjv.exe
[%SYSTEM%]\bnzzhj.dll
[%SYSTEM%]\ecm.dll
[%SYSTEM%]\edyyogo.dll
[%SYSTEM%]\ewbgup.exe
[%SYSTEM%]\fewtbdb.dll
[%SYSTEM%]\fpym.dll
[%SYSTEM%]\ghhe.exe
[%SYSTEM%]\gol.exe
[%SYSTEM%]\hfwpjpe.exe
[%SYSTEM%]\iqcmiir.exe
[%SYSTEM%]\itwiiha.dll
[%SYSTEM%]\jgxlxbdq.dll
[%SYSTEM%]\jnj.dll
[%SYSTEM%]\lunfbalo.dll
[%SYSTEM%]\lwycd.exe
[%SYSTEM%]\njw.exe
[%SYSTEM%]\ojdkpr.dll
[%SYSTEM%]\pvfw.exe
[%SYSTEM%]\qoxuzlr.exe
[%SYSTEM%]\qra.dll
[%SYSTEM%]\rea.dll
[%SYSTEM%]\rfin.dll
[%SYSTEM%]\tlb.exe
[%SYSTEM%]\uwfywiy.exe
[%SYSTEM%]\vanaiuxq.dll
[%SYSTEM%]\vnhhppe.dll
[%SYSTEM%]\vsvzv.exe
[%SYSTEM%]\wcsxecdo.exe
[%SYSTEM%]\wrkr.exe
[%SYSTEM%]\xxnagz.dll
[%SYSTEM%]\yae.exe
[%SYSTEM%]\yqatopy.dll
[%SYSTEM%]\zgpwcgsx.exe
[%WINDOWS%]\application data\ncae.exe
[%WINDOWS%]\system\plr.exe
[%WINDOWS%]\system\sqep.exe
[%WINDOWS%]\system\wtwj.dll

In order to ensure that the Win32.TrojanDownloader.PurityScan is launched automatically each time the system is booted, the Win32.TrojanDownloader.PurityScan adds a link to its executable file in the system registry:
HKLM\Microsoft\Windows\CurrentVersion\Run
[%APPDATA%]\oasb.exe
[%SYSTEM%]\bhaqjv.exe
[%SYSTEM%]\ewbgup.exe
[%SYSTEM%]\ghhe.exe
[%SYSTEM%]\gol.exe
[%SYSTEM%]\hfwpjpe.exe
[%SYSTEM%]\iqcmiir.exe
[%SYSTEM%]\lwycd.exe
[%SYSTEM%]\njw.exe
[%SYSTEM%]\pvfw.exe
[%SYSTEM%]\qoxuzlr.exe
[%SYSTEM%]\tlb.exe
[%SYSTEM%]\uwfywiy.exe
[%SYSTEM%]\vsvzv.exe
[%SYSTEM%]\wcsxecdo.exe
[%SYSTEM%]\wrkr.exe
[%SYSTEM%]\yae.exe
[%SYSTEM%]\zgpwcgsx.exe
[%WINDOWS%]\application data\ncae.exe
[%WINDOWS%]\system\plr.exe
[%WINDOWS%]\system\sqep.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Win32.TrojanDownloader.PurityScan:

Files:
[%APPDATA%]\oasb.exe
[%SYSTEM%]\bhaqjv.exe
[%SYSTEM%]\bnzzhj.dll
[%SYSTEM%]\ecm.dll
[%SYSTEM%]\edyyogo.dll
[%SYSTEM%]\ewbgup.exe
[%SYSTEM%]\fewtbdb.dll
[%SYSTEM%]\fpym.dll
[%SYSTEM%]\ghhe.exe
[%SYSTEM%]\gol.exe
[%SYSTEM%]\hfwpjpe.exe
[%SYSTEM%]\iqcmiir.exe
[%SYSTEM%]\itwiiha.dll
[%SYSTEM%]\jgxlxbdq.dll
[%SYSTEM%]\jnj.dll
[%SYSTEM%]\lunfbalo.dll
[%SYSTEM%]\lwycd.exe
[%SYSTEM%]\njw.exe
[%SYSTEM%]\ojdkpr.dll
[%SYSTEM%]\pvfw.exe
[%SYSTEM%]\qoxuzlr.exe
[%SYSTEM%]\qra.dll
[%SYSTEM%]\rea.dll
[%SYSTEM%]\rfin.dll
[%SYSTEM%]\tlb.exe
[%SYSTEM%]\uwfywiy.exe
[%SYSTEM%]\vanaiuxq.dll
[%SYSTEM%]\vnhhppe.dll
[%SYSTEM%]\vsvzv.exe
[%SYSTEM%]\wcsxecdo.exe
[%SYSTEM%]\wrkr.exe
[%SYSTEM%]\xxnagz.dll
[%SYSTEM%]\yae.exe
[%SYSTEM%]\yqatopy.dll
[%SYSTEM%]\zgpwcgsx.exe
[%WINDOWS%]\application data\ncae.exe
[%WINDOWS%]\system\plr.exe
[%WINDOWS%]\system\sqep.exe
[%WINDOWS%]\system\wtwj.dll
[%APPDATA%]\oasb.exe
[%SYSTEM%]\bhaqjv.exe
[%SYSTEM%]\bnzzhj.dll
[%SYSTEM%]\ecm.dll
[%SYSTEM%]\edyyogo.dll
[%SYSTEM%]\ewbgup.exe
[%SYSTEM%]\fewtbdb.dll
[%SYSTEM%]\fpym.dll
[%SYSTEM%]\ghhe.exe
[%SYSTEM%]\gol.exe
[%SYSTEM%]\hfwpjpe.exe
[%SYSTEM%]\iqcmiir.exe
[%SYSTEM%]\itwiiha.dll
[%SYSTEM%]\jgxlxbdq.dll
[%SYSTEM%]\jnj.dll
[%SYSTEM%]\lunfbalo.dll
[%SYSTEM%]\lwycd.exe
[%SYSTEM%]\njw.exe
[%SYSTEM%]\ojdkpr.dll
[%SYSTEM%]\pvfw.exe
[%SYSTEM%]\qoxuzlr.exe
[%SYSTEM%]\qra.dll
[%SYSTEM%]\rea.dll
[%SYSTEM%]\rfin.dll
[%SYSTEM%]\tlb.exe
[%SYSTEM%]\uwfywiy.exe
[%SYSTEM%]\vanaiuxq.dll
[%SYSTEM%]\vnhhppe.dll
[%SYSTEM%]\vsvzv.exe
[%SYSTEM%]\wcsxecdo.exe
[%SYSTEM%]\wrkr.exe
[%SYSTEM%]\xxnagz.dll
[%SYSTEM%]\yae.exe
[%SYSTEM%]\yqatopy.dll
[%SYSTEM%]\zgpwcgsx.exe
[%WINDOWS%]\application data\ncae.exe
[%WINDOWS%]\system\plr.exe
[%WINDOWS%]\system\sqep.exe
[%WINDOWS%]\system\wtwj.dll

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run

Removing Win32.TrojanDownloader.PurityScan:

An up-to-date copy of ExterminateIt should detect and prevent infection from Win32.TrojanDownloader.PurityScan.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Win32.TrojanDownloader.PurityScan manually.

To completely manually remove Win32.TrojanDownloader.PurityScan malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Win32.TrojanDownloader.PurityScan.

  1. Use Task Manager to terminate the Win32.TrojanDownloader.PurityScan process.
  2. Delete the original Win32.TrojanDownloader.PurityScan file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Win32.TrojanDownloader.PurityScan from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Win32.TrojanDownloader.PurityScan!


Also Be Aware of the Following Threats:
Remove Pigeon.AUZZ Trojan
Mudrop Trojan Information
CWS.Notepad32 Hijacker Removal instruction
Bancos.GUL Trojan Symptoms
Sathi Trojan Cleaner

0 comments

Cannabis Trojan

Cannabis malware description and removal detail
Categories:Trojan,Backdoor,Downloader,DoS
Also known as:

[Panda]Cannabis.C.Drp,Cannabis

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Cannabis:

An up-to-date copy of ExterminateIt should detect and prevent infection from Cannabis.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Cannabis manually.

To completely manually remove Cannabis malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Cannabis.

  1. Use Task Manager to terminate the Cannabis process.
  2. Delete the original Cannabis file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Cannabis from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Cannabis!


Also Be Aware of the Following Threats:
Bancos.IMD Trojan Removal instruction
Remove Generic Trojan
Vxidl.BFH Trojan Removal instruction
Remove JS.Nyrobot Trojan
Win32.Slinbot Trojan Removal

0 comments

PWS.Legmir.dll Trojan

PWS.Legmir.dll malware description and removal detail
Categories:Trojan,Hacker Tool
Also known as:

[Kaspersky]Trojan-PSW.Win32.Limir.bdb,Trojan-PSW.Win32.Lmir.bgk;
[McAfee]PWS-Legmir.dll,PWS-LegMir.dll;
[Other]Infostealer.Gampass,Win32/Frethog.AJ

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing PWS.Legmir.dll:

An up-to-date copy of ExterminateIt should detect and prevent infection from PWS.Legmir.dll.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove PWS.Legmir.dll manually.

To completely manually remove PWS.Legmir.dll malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with PWS.Legmir.dll.

  1. Use Task Manager to terminate the PWS.Legmir.dll process.
  2. Delete the original PWS.Legmir.dll file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes PWS.Legmir.dll from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of PWS.Legmir.dll!


Also Be Aware of the Following Threats:
PHP.Chaploit Trojan Removal instruction
Soupy Trojan Removal instruction
Direct.Revenue Adware Symptoms
PWS.Fantast.gen Trojan Symptoms
eresmas.com Tracking Cookie Cleaner

0 comments

PeopleOnPage.AproposMedia BHO

PeopleOnPage.AproposMedia malware description and removal detail
Categories:BHO,Backdoor,Hijacker,Downloader
Also known as:

[Kaspersky]Backdoor.Agent.ag,TrojanDownloader.Win32.Apropo.b,TrojanDownloader.Win32.Apropo.g;
[Eset]Win32/Agent.AG trojan,Win32/TrojanDownloader.Apropo.B trojan,Win32/TrojanDownloader.Apropo.G trojan;
[Panda]Adware/Apropos,Adware/SideSearch,Adware/WinTools,Trj/Upseter.A

Visible Symptoms:
Files in system folders:
[%PROFILE_TEMP%]\acsdir.dll
[%PROFILE_TEMP%]\acsver.ini
[%PROFILE_TEMP%]\AutoUpdate0\auto_update_install.exe
[%PROFILE_TEMP%]\datacache.ini
[%PROFILE_TEMP%]\delcuwiz.ini
[%PROFILE_TEMP%]\delreg.ini
[%PROFILE_TEMP%]\QTInstallerHelper.dll
[%PROFILE_TEMP%]\update_1.exe
[%PROFILE_TEMP%]\write_ph.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup16.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup32.dll
[%PROFILE_TEMP%]\_ISTMP10.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP12.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\45c4b9e.DLL
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\TrueTypeFontInfo.dll
[%PROFILE_TEMP%]\~apropos0\atl.dll
[%PROFILE_TEMP%]\~apropos0\atla.dll
[%PROFILE_TEMP%]\~apropos0\atlw.dll
[%PROFILE_TEMP%]\~apropos0\setup.inf
[%PROGRAM_FILES%]\Aprps\ace.dll
[%PROGRAM_FILES%]\Aprps\ATL.DLL
[%PROGRAM_FILES%]\Aprps\CxtPls.dll
[%PROGRAM_FILES%]\Aprps\CxtPls.exe
[%PROGRAM_FILES%]\Aprps\proxystub.dll
[%PROGRAM_FILES%]\Aprps\WinGenerics.dll
[%PROGRAM_FILES%]\AutoUpdate\AutoUpdate.exe
[%SYSTEM%]\auto_update_uninstall.exe
[%SYSTEM%]\auto_update_uninstall.log
[%SYSTEM%]\cnewapi.exe
[%SYSTEM%]\config\systemprofile\Local Settings\Temp\write_ph.dll
[%SYSTEM%]\magrip.exe
[%SYSTEM%]\ntsrage.exe
[%WINDOWS%]\cxtpls_loader.exe
[%WINDOWS%]\cxtpls_loader.exe_
[%WINDOWS%]\TEMP\acsdir.dll
[%WINDOWS%]\temp\autoupdate0\auto_update_install.exe
[%WINDOWS%]\TEMP\write_ph.dll
[%DESKTOP%]\digital detective\tempfiles\wrifo.exe
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-1.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-2.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-3.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-4.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\index.htm
[%PROFILE_TEMP%]\magicinlayinstall.exe
[%PROFILE_TEMP%]\midaddle.exe
[%PROFILE_TEMP%]\mv7dizbww.exe
[%PROFILE_TEMP%]\qnqyiee.dll
[%PROFILE_TEMP%]\qnqyiee.exe
[%PROFILE_TEMP%]\sfl.exe
[%PROFILE_TEMP%]\tribbglk.htm
[%PROFILE_TEMP%]\triijhkm.htm
[%PROFILE_TEMP%]\trimepnm.htm
[%PROFILE_TEMP%]\trinjapb.htm
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\199e866.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\directxvercheck.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\truetypefontinfo.dll
[%SYSTEM%]\aproposplugin.dll
[%SYSTEM%]\dx8iext.exe
[%SYSTEM%]\rcisp.exe
[%SYSTEM%]\shmhupnp.exe
[%SYSTEM%]\sm1ay.exe
[%SYSTEM%]\wrifo.exe
[%WINDOWS%]\ororoxid.exe
[%WINDOWS%]\system\aproposplugin.dll
[%WINDOWS%]\temp\6ktkk.dll
[%WINDOWS%]\temp\7ggoo.dll
[%WINDOWS%]\temp\addit.exe
[%WINDOWS%]\temp\all_files10.exe
[%WINDOWS%]\temp\aut3cde.tmp.htm
[%WINDOWS%]\temp\mw.exe
[%WINDOWS%]\temp\mw_4s_stub.exe
[%WINDOWS%]\temp\sepinst.exe
[%WINDOWS%]\temp\updater.exe
[%WINDOWS%]\temp\update_1.exe
[%WINDOWS%]\temp\wus10e4.bat
[%WINDOWS%]\temp\z.dll
[%WINDOWS%]\temp\z.exe
[%WINDOWS%]\temp\zga.dll
[%WINDOWS%]\temp\zga.exe
[%WINDOWS%]\temp\_ps_inst.exe
[%WINDOWS%]\temp\~apropos0\atla.dll
[%WINDOWS%]\temp\~apropos0\setup.inf
[%PROFILE_TEMP%]\acsdir.dll
[%PROFILE_TEMP%]\acsver.ini
[%PROFILE_TEMP%]\AutoUpdate0\auto_update_install.exe
[%PROFILE_TEMP%]\datacache.ini
[%PROFILE_TEMP%]\delcuwiz.ini
[%PROFILE_TEMP%]\delreg.ini
[%PROFILE_TEMP%]\QTInstallerHelper.dll
[%PROFILE_TEMP%]\update_1.exe
[%PROFILE_TEMP%]\write_ph.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup16.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup32.dll
[%PROFILE_TEMP%]\_ISTMP10.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP12.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\45c4b9e.DLL
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\TrueTypeFontInfo.dll
[%PROFILE_TEMP%]\~apropos0\atl.dll
[%PROFILE_TEMP%]\~apropos0\atla.dll
[%PROFILE_TEMP%]\~apropos0\atlw.dll
[%PROFILE_TEMP%]\~apropos0\setup.inf
[%PROGRAM_FILES%]\Aprps\ace.dll
[%PROGRAM_FILES%]\Aprps\ATL.DLL
[%PROGRAM_FILES%]\Aprps\CxtPls.dll
[%PROGRAM_FILES%]\Aprps\CxtPls.exe
[%PROGRAM_FILES%]\Aprps\proxystub.dll
[%PROGRAM_FILES%]\Aprps\WinGenerics.dll
[%PROGRAM_FILES%]\AutoUpdate\AutoUpdate.exe
[%SYSTEM%]\auto_update_uninstall.exe
[%SYSTEM%]\auto_update_uninstall.log
[%SYSTEM%]\cnewapi.exe
[%SYSTEM%]\config\systemprofile\Local Settings\Temp\write_ph.dll
[%SYSTEM%]\magrip.exe
[%SYSTEM%]\ntsrage.exe
[%WINDOWS%]\cxtpls_loader.exe
[%WINDOWS%]\cxtpls_loader.exe_
[%WINDOWS%]\TEMP\acsdir.dll
[%WINDOWS%]\temp\autoupdate0\auto_update_install.exe
[%WINDOWS%]\TEMP\write_ph.dll
[%DESKTOP%]\digital detective\tempfiles\wrifo.exe
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-1.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-2.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-3.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-4.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\index.htm
[%PROFILE_TEMP%]\magicinlayinstall.exe
[%PROFILE_TEMP%]\midaddle.exe
[%PROFILE_TEMP%]\mv7dizbww.exe
[%PROFILE_TEMP%]\qnqyiee.dll
[%PROFILE_TEMP%]\qnqyiee.exe
[%PROFILE_TEMP%]\sfl.exe
[%PROFILE_TEMP%]\tribbglk.htm
[%PROFILE_TEMP%]\triijhkm.htm
[%PROFILE_TEMP%]\trimepnm.htm
[%PROFILE_TEMP%]\trinjapb.htm
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\199e866.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\directxvercheck.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\truetypefontinfo.dll
[%SYSTEM%]\aproposplugin.dll
[%SYSTEM%]\dx8iext.exe
[%SYSTEM%]\rcisp.exe
[%SYSTEM%]\shmhupnp.exe
[%SYSTEM%]\sm1ay.exe
[%SYSTEM%]\wrifo.exe
[%WINDOWS%]\ororoxid.exe
[%WINDOWS%]\system\aproposplugin.dll
[%WINDOWS%]\temp\6ktkk.dll
[%WINDOWS%]\temp\7ggoo.dll
[%WINDOWS%]\temp\addit.exe
[%WINDOWS%]\temp\all_files10.exe
[%WINDOWS%]\temp\aut3cde.tmp.htm
[%WINDOWS%]\temp\mw.exe
[%WINDOWS%]\temp\mw_4s_stub.exe
[%WINDOWS%]\temp\sepinst.exe
[%WINDOWS%]\temp\updater.exe
[%WINDOWS%]\temp\update_1.exe
[%WINDOWS%]\temp\wus10e4.bat
[%WINDOWS%]\temp\z.dll
[%WINDOWS%]\temp\z.exe
[%WINDOWS%]\temp\zga.dll
[%WINDOWS%]\temp\zga.exe
[%WINDOWS%]\temp\_ps_inst.exe
[%WINDOWS%]\temp\~apropos0\atla.dll
[%WINDOWS%]\temp\~apropos0\setup.inf

In order to ensure that the PeopleOnPage.AproposMedia is launched automatically each time the system is booted, the PeopleOnPage.AproposMedia adds a link to its executable file in the system registry:
HKLM\Microsoft\Windows\CurrentVersion\Run
[%PROFILE_TEMP%]\AutoUpdate0\auto_update_install.exe
[%PROFILE_TEMP%]\update_1.exe
[%PROGRAM_FILES%]\Aprps\CxtPls.exe
[%PROGRAM_FILES%]\AutoUpdate\AutoUpdate.exe
[%SYSTEM%]\auto_update_uninstall.exe
[%SYSTEM%]\cnewapi.exe
[%SYSTEM%]\magrip.exe
[%SYSTEM%]\ntsrage.exe
[%WINDOWS%]\cxtpls_loader.exe
[%WINDOWS%]\cxtpls_loader.exe_
[%WINDOWS%]\temp\autoupdate0\auto_update_install.exe
[%DESKTOP%]\digital detective\tempfiles\wrifo.exe
[%PROFILE_TEMP%]\magicinlayinstall.exe
[%PROFILE_TEMP%]\midaddle.exe
[%PROFILE_TEMP%]\mv7dizbww.exe
[%PROFILE_TEMP%]\qnqyiee.exe
[%PROFILE_TEMP%]\sfl.exe
[%SYSTEM%]\dx8iext.exe
[%SYSTEM%]\rcisp.exe
[%SYSTEM%]\shmhupnp.exe
[%SYSTEM%]\sm1ay.exe
[%SYSTEM%]\wrifo.exe
[%WINDOWS%]\ororoxid.exe
[%WINDOWS%]\temp\addit.exe
[%WINDOWS%]\temp\all_files10.exe
[%WINDOWS%]\temp\mw.exe
[%WINDOWS%]\temp\mw_4s_stub.exe
[%WINDOWS%]\temp\sepinst.exe
[%WINDOWS%]\temp\updater.exe
[%WINDOWS%]\temp\update_1.exe
[%WINDOWS%]\temp\z.exe
[%WINDOWS%]\temp\zga.exe
[%WINDOWS%]\temp\_ps_inst.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting PeopleOnPage.AproposMedia:

Files:
[%PROFILE_TEMP%]\acsdir.dll
[%PROFILE_TEMP%]\acsver.ini
[%PROFILE_TEMP%]\AutoUpdate0\auto_update_install.exe
[%PROFILE_TEMP%]\datacache.ini
[%PROFILE_TEMP%]\delcuwiz.ini
[%PROFILE_TEMP%]\delreg.ini
[%PROFILE_TEMP%]\QTInstallerHelper.dll
[%PROFILE_TEMP%]\update_1.exe
[%PROFILE_TEMP%]\write_ph.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup16.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup32.dll
[%PROFILE_TEMP%]\_ISTMP10.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP12.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\45c4b9e.DLL
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\TrueTypeFontInfo.dll
[%PROFILE_TEMP%]\~apropos0\atl.dll
[%PROFILE_TEMP%]\~apropos0\atla.dll
[%PROFILE_TEMP%]\~apropos0\atlw.dll
[%PROFILE_TEMP%]\~apropos0\setup.inf
[%PROGRAM_FILES%]\Aprps\ace.dll
[%PROGRAM_FILES%]\Aprps\ATL.DLL
[%PROGRAM_FILES%]\Aprps\CxtPls.dll
[%PROGRAM_FILES%]\Aprps\CxtPls.exe
[%PROGRAM_FILES%]\Aprps\proxystub.dll
[%PROGRAM_FILES%]\Aprps\WinGenerics.dll
[%PROGRAM_FILES%]\AutoUpdate\AutoUpdate.exe
[%SYSTEM%]\auto_update_uninstall.exe
[%SYSTEM%]\auto_update_uninstall.log
[%SYSTEM%]\cnewapi.exe
[%SYSTEM%]\config\systemprofile\Local Settings\Temp\write_ph.dll
[%SYSTEM%]\magrip.exe
[%SYSTEM%]\ntsrage.exe
[%WINDOWS%]\cxtpls_loader.exe
[%WINDOWS%]\cxtpls_loader.exe_
[%WINDOWS%]\TEMP\acsdir.dll
[%WINDOWS%]\temp\autoupdate0\auto_update_install.exe
[%WINDOWS%]\TEMP\write_ph.dll
[%DESKTOP%]\digital detective\tempfiles\wrifo.exe
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-1.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-2.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-3.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-4.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\index.htm
[%PROFILE_TEMP%]\magicinlayinstall.exe
[%PROFILE_TEMP%]\midaddle.exe
[%PROFILE_TEMP%]\mv7dizbww.exe
[%PROFILE_TEMP%]\qnqyiee.dll
[%PROFILE_TEMP%]\qnqyiee.exe
[%PROFILE_TEMP%]\sfl.exe
[%PROFILE_TEMP%]\tribbglk.htm
[%PROFILE_TEMP%]\triijhkm.htm
[%PROFILE_TEMP%]\trimepnm.htm
[%PROFILE_TEMP%]\trinjapb.htm
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\199e866.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\directxvercheck.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\truetypefontinfo.dll
[%SYSTEM%]\aproposplugin.dll
[%SYSTEM%]\dx8iext.exe
[%SYSTEM%]\rcisp.exe
[%SYSTEM%]\shmhupnp.exe
[%SYSTEM%]\sm1ay.exe
[%SYSTEM%]\wrifo.exe
[%WINDOWS%]\ororoxid.exe
[%WINDOWS%]\system\aproposplugin.dll
[%WINDOWS%]\temp\6ktkk.dll
[%WINDOWS%]\temp\7ggoo.dll
[%WINDOWS%]\temp\addit.exe
[%WINDOWS%]\temp\all_files10.exe
[%WINDOWS%]\temp\aut3cde.tmp.htm
[%WINDOWS%]\temp\mw.exe
[%WINDOWS%]\temp\mw_4s_stub.exe
[%WINDOWS%]\temp\sepinst.exe
[%WINDOWS%]\temp\updater.exe
[%WINDOWS%]\temp\update_1.exe
[%WINDOWS%]\temp\wus10e4.bat
[%WINDOWS%]\temp\z.dll
[%WINDOWS%]\temp\z.exe
[%WINDOWS%]\temp\zga.dll
[%WINDOWS%]\temp\zga.exe
[%WINDOWS%]\temp\_ps_inst.exe
[%WINDOWS%]\temp\~apropos0\atla.dll
[%WINDOWS%]\temp\~apropos0\setup.inf
[%PROFILE_TEMP%]\acsdir.dll
[%PROFILE_TEMP%]\acsver.ini
[%PROFILE_TEMP%]\AutoUpdate0\auto_update_install.exe
[%PROFILE_TEMP%]\datacache.ini
[%PROFILE_TEMP%]\delcuwiz.ini
[%PROFILE_TEMP%]\delreg.ini
[%PROFILE_TEMP%]\QTInstallerHelper.dll
[%PROFILE_TEMP%]\update_1.exe
[%PROFILE_TEMP%]\write_ph.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup16.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup32.dll
[%PROFILE_TEMP%]\_ISTMP10.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP12.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\45c4b9e.DLL
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\DirectXVerCheck.dll
[%PROFILE_TEMP%]\_ISTMP2.DIR\_ISTMP0.DIR\TrueTypeFontInfo.dll
[%PROFILE_TEMP%]\~apropos0\atl.dll
[%PROFILE_TEMP%]\~apropos0\atla.dll
[%PROFILE_TEMP%]\~apropos0\atlw.dll
[%PROFILE_TEMP%]\~apropos0\setup.inf
[%PROGRAM_FILES%]\Aprps\ace.dll
[%PROGRAM_FILES%]\Aprps\ATL.DLL
[%PROGRAM_FILES%]\Aprps\CxtPls.dll
[%PROGRAM_FILES%]\Aprps\CxtPls.exe
[%PROGRAM_FILES%]\Aprps\proxystub.dll
[%PROGRAM_FILES%]\Aprps\WinGenerics.dll
[%PROGRAM_FILES%]\AutoUpdate\AutoUpdate.exe
[%SYSTEM%]\auto_update_uninstall.exe
[%SYSTEM%]\auto_update_uninstall.log
[%SYSTEM%]\cnewapi.exe
[%SYSTEM%]\config\systemprofile\Local Settings\Temp\write_ph.dll
[%SYSTEM%]\magrip.exe
[%SYSTEM%]\ntsrage.exe
[%WINDOWS%]\cxtpls_loader.exe
[%WINDOWS%]\cxtpls_loader.exe_
[%WINDOWS%]\TEMP\acsdir.dll
[%WINDOWS%]\temp\autoupdate0\auto_update_install.exe
[%WINDOWS%]\TEMP\write_ph.dll
[%DESKTOP%]\digital detective\tempfiles\wrifo.exe
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-1.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-2.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-3.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn-4.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\hup8fnvn.htm
[%PROFILE_TEMP%]\homhup8fnvn.tmp\index.htm
[%PROFILE_TEMP%]\magicinlayinstall.exe
[%PROFILE_TEMP%]\midaddle.exe
[%PROFILE_TEMP%]\mv7dizbww.exe
[%PROFILE_TEMP%]\qnqyiee.dll
[%PROFILE_TEMP%]\qnqyiee.exe
[%PROFILE_TEMP%]\sfl.exe
[%PROFILE_TEMP%]\tribbglk.htm
[%PROFILE_TEMP%]\triijhkm.htm
[%PROFILE_TEMP%]\trimepnm.htm
[%PROFILE_TEMP%]\trinjapb.htm
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\199e866.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\directxvercheck.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\truetypefontinfo.dll
[%SYSTEM%]\aproposplugin.dll
[%SYSTEM%]\dx8iext.exe
[%SYSTEM%]\rcisp.exe
[%SYSTEM%]\shmhupnp.exe
[%SYSTEM%]\sm1ay.exe
[%SYSTEM%]\wrifo.exe
[%WINDOWS%]\ororoxid.exe
[%WINDOWS%]\system\aproposplugin.dll
[%WINDOWS%]\temp\6ktkk.dll
[%WINDOWS%]\temp\7ggoo.dll
[%WINDOWS%]\temp\addit.exe
[%WINDOWS%]\temp\all_files10.exe
[%WINDOWS%]\temp\aut3cde.tmp.htm
[%WINDOWS%]\temp\mw.exe
[%WINDOWS%]\temp\mw_4s_stub.exe
[%WINDOWS%]\temp\sepinst.exe
[%WINDOWS%]\temp\updater.exe
[%WINDOWS%]\temp\update_1.exe
[%WINDOWS%]\temp\wus10e4.bat
[%WINDOWS%]\temp\z.dll
[%WINDOWS%]\temp\z.exe
[%WINDOWS%]\temp\zga.dll
[%WINDOWS%]\temp\zga.exe
[%WINDOWS%]\temp\_ps_inst.exe
[%WINDOWS%]\temp\~apropos0\atla.dll
[%WINDOWS%]\temp\~apropos0\setup.inf

Folders:
[%PROGRAM_FILES%]\sysai

Registry Keys:
HKEY_CLASSES_ROOT\Interface\{B548B7D8-3D03-4AED-A6A1-4251FAD00C10}
HKEY_CLASSES_ROOT\Interface\{B99A727F-0782-4A71-BCC2-6E1E66414904}
HKEY_CLASSES_ROOT\clsid\{01c5bf6c-e699-4cd7-bea1-786fa05c83ab}
HKEY_CLASSES_ROOT\interface\{b548b7d8-3d03-4aed-a6a1-4251fad00c10}
HKEY_CLASSES_ROOT\interface\{b99a727f-0782-4a71-bcc2-6e1e66414904}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{01c5bf6c-e699-4cd7-bea1-786fa05c83ab}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{65c8c1f5-230e-4dc9-9a0d-f3159a5e7778}
HKEY_LOCAL_MACHINE\software\classes\clsid\{645fd3bc-c314-4f7a-9d2e-64d62a0fdd78}
HKEY_LOCAL_MACHINE\software\classes\clsid\{65c8c1f5-230e-4dc9-9a0d-f3159a5e7778}
HKEY_LOCAL_MACHINE\software\classes\clsid\{8023a3e7-ab95-4c23-8313-0be9842cc70e}
HKEY_LOCAL_MACHINE\software\classes\clsid\{976c4e11-b9c5-4b2b-97ef-f7d06ba4242f}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d5580d6f-0e5f-4bdb-9cdf-f8ee68beb008}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{01c5bf6c-e699-4cd7-bea1-786fa05c83ab}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{65c8c1f5-230e-4dc9-9a0d-f3159a5e7778}

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing PeopleOnPage.AproposMedia:

An up-to-date copy of ExterminateIt should detect and prevent infection from PeopleOnPage.AproposMedia.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove PeopleOnPage.AproposMedia manually.

To completely manually remove PeopleOnPage.AproposMedia malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with PeopleOnPage.AproposMedia.

  1. Use Task Manager to terminate the PeopleOnPage.AproposMedia process.
  2. Delete the original PeopleOnPage.AproposMedia file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes PeopleOnPage.AproposMedia from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of PeopleOnPage.AproposMedia!


Also Be Aware of the Following Threats:
Remove Modem.Spy Spyware
ApplePie Trojan Symptoms
Remove Bancos.GJP Trojan
Removing Silent.Keylogger Spyware
Swine.Flu Trojan Cleaner

0 comments

Late.Night Trojan

Late.Night malware description and removal detail
Categories:Trojan,Backdoor,Downloader,DoS
Also known as:

[Kaspersky]Late.248;
[Eset]probably unknown COM virus;
[Panda]Late Night

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Late.Night:

An up-to-date copy of ExterminateIt should detect and prevent infection from Late.Night.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Late.Night manually.

To completely manually remove Late.Night malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Late.Night.

  1. Use Task Manager to terminate the Late.Night process.
  2. Delete the original Late.Night file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Late.Night from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Late.Night!


Also Be Aware of the Following Threats:
Removing Hapg Trojan
Silent.Keylogger Spyware Symptoms
Whirlpool Trojan Information
Remove Goobiz Downloader
IP.Flood Trojan Information

0 comments

Pigeon.ELW Trojan

Pigeon.ELW malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Pigeon.ELW:

An up-to-date copy of ExterminateIt should detect and prevent infection from Pigeon.ELW.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Pigeon.ELW manually.

To completely manually remove Pigeon.ELW malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Pigeon.ELW.

  1. Use Task Manager to terminate the Pigeon.ELW process.
  2. Delete the original Pigeon.ELW file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Pigeon.ELW from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Pigeon.ELW!


Also Be Aware of the Following Threats:
Bancos.GJP Trojan Symptoms
WinAble Adware Cleaner
Cdset4 Trojan Cleaner
Afcore.ar Backdoor Information
Remove MailSpam.Dmb Hacker Tool

0 comments

Havar.client Trojan

Havar.client malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Havar.client:

An up-to-date copy of ExterminateIt should detect and prevent infection from Havar.client.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Havar.client manually.

To completely manually remove Havar.client malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Havar.client.

  1. Use Task Manager to terminate the Havar.client process.
  2. Delete the original Havar.client file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Havar.client from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Havar.client!


Also Be Aware of the Following Threats:
WinUpdates.MediaGateway Adware Symptoms
Win32.P2E Trojan Removal instruction
Delf.aaa Backdoor Information
Remove Agent.dw Trojan
Compiler Trojan Removal instruction

0 comments

Tomato.beta Trojan

Tomato.beta malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Tomato.beta:

An up-to-date copy of ExterminateIt should detect and prevent infection from Tomato.beta.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Tomato.beta manually.

To completely manually remove Tomato.beta malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Tomato.beta.

  1. Use Task Manager to terminate the Tomato.beta process.
  2. Delete the original Tomato.beta file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Tomato.beta from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Tomato.beta!


Also Be Aware of the Following Threats:
Whirlpool Trojan Cleaner
AOL.PS.hp Trojan Removal instruction
Removing Acropolis Trojan
Cof Trojan Cleaner
Up.Yours.0b1 Hacker Tool Symptoms

0 comments

Alien.Hacker Backdoor

Alien.Hacker malware description and removal detail
Categories:Backdoor,RAT
Also known as:

[Kaspersky]Backdoor.Broadoor.a

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Alien.Hacker:

An up-to-date copy of ExterminateIt should detect and prevent infection from Alien.Hacker.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Alien.Hacker manually.

To completely manually remove Alien.Hacker malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Alien.Hacker.

  1. Use Task Manager to terminate the Alien.Hacker process.
  2. Delete the original Alien.Hacker file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Alien.Hacker from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Alien.Hacker!


Also Be Aware of the Following Threats:
Cacogen Trojan Information
Tihsho Trojan Symptoms
Removing Z0X Trojan
Bancos.GDZ Trojan Removal instruction
Remove SillyDl.DNB Trojan

0 comments

Blog Archive