Monday, November 3, 2008

AntiVirGear Ransomware

How To Remove Remove AntiVirGear?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
AntiVirGear is dangerous virus:
The term ransomware is commonly used to describe such software,
although the field known as cryptovirology predates the term "ransomware".

This type of ransom attack can be accomplished by (for example) attaching
a specially crafted file/program to an e-mail message and sending this to the victim.


AntiVirGear Symptoms:

Files:
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntiVirGear 3.8.lnk
[%DESKTOP%]\AntiVirGear 3.8.lnk
[%PROFILE_TEMP%]\~nsu.tmp\Au_.exe
[%PROFILE_TEMP%]\~nsu.tmp\Bu_.exe
[%PROGRAM_FILES%]\AntiVirGear 3.8\AntiVirGear 3.8.exe
[%STARTMENU%]\AntiVirGear 3.8.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntiVirGear 3.7.lnk
[%DESKTOP%]\AntiVirGear 3.7.lnk
[%PROFILE_TEMP%]\VPPLanguage.ini
[%PROGRAM_FILES%]\AntiVirGear 3.7\AntiVirGear 3.7.exe
[%STARTMENU%]\AntiVirGear 3.7.lnk
[%SYSTEM%]\bubbj.dll
[%SYSTEM%]\jrpkmgh.dll
[%DESKTOP%]\AntiVirGear 3.8.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntiVirGear 3.8.lnk
[%DESKTOP%]\AntiVirGear 3.8.lnk
[%PROFILE_TEMP%]\~nsu.tmp\Au_.exe
[%PROFILE_TEMP%]\~nsu.tmp\Bu_.exe
[%PROGRAM_FILES%]\AntiVirGear 3.8\AntiVirGear 3.8.exe
[%STARTMENU%]\AntiVirGear 3.8.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntiVirGear 3.7.lnk
[%DESKTOP%]\AntiVirGear 3.7.lnk
[%PROFILE_TEMP%]\VPPLanguage.ini
[%PROGRAM_FILES%]\AntiVirGear 3.7\AntiVirGear 3.7.exe
[%STARTMENU%]\AntiVirGear 3.7.lnk
[%SYSTEM%]\bubbj.dll
[%SYSTEM%]\jrpkmgh.dll
[%DESKTOP%]\AntiVirGear 3.8.lnk

Folders:
[%PROGRAMS%]\AntiVirGear 3.8
[%PROGRAM_FILES%]\AntiVirGear 3.8
[%PROGRAMS%]\AntiVirGear 3.7
[%PROGRAM_FILES%]\AntiVirGear 3.7

Registry Keys:
HKEY_CLASSES_ROOT\CLSID\{3BC3AC5B-3BBB-9DBE-8166-EC650E3B9B48}
HKEY_CLASSES_ROOT\Interface\{0A0FC1A4-41D4-4793-9AC5-0B55CDC95AE9}
HKEY_CLASSES_ROOT\Interface\{14F47CA3-2291-4B3E-9ED4-8C7E6AE80851}
HKEY_CLASSES_ROOT\Interface\{2447284F-3590-4E8C-A869-049BD87CAD07}
HKEY_CLASSES_ROOT\Interface\{38EEEF46-CA24-4ACA-A90D-540978DF7252}
HKEY_CLASSES_ROOT\Interface\{3D5E5AE1-5DED-4520-BDC2-B9292EA708CA}
HKEY_CLASSES_ROOT\Interface\{409A05EF-1B48-4198-B6BF-993B8B52790C}
HKEY_CLASSES_ROOT\Interface\{47A93011-1004-440C-9960-BD3B0348A7C2}
HKEY_CLASSES_ROOT\Interface\{50B388D5-4A80-4191-8BCC-5DD031D7F3EE}
HKEY_CLASSES_ROOT\Interface\{58A1ACE6-0DBA-45D2-8154-E8253A7B87BB}
HKEY_CLASSES_ROOT\Interface\{73D25394-992F-43D1-BF92-48494CC0D1AE}
HKEY_CLASSES_ROOT\Interface\{7D2A83A4-0687-4704-937E-A29045826F77}
HKEY_CLASSES_ROOT\Interface\{A7FE54B2-B167-4017-BCCC-CF73B2F678E3}
HKEY_CLASSES_ROOT\Interface\{C183B073-2D7F-45BC-8967-80147CECEE45}
HKEY_CLASSES_ROOT\Interface\{F6FDBF9A-19A7-4F0A-9F46-6F015A067B44}
HKEY_CLASSES_ROOT\Interface\{F90A7969-20A0-4257-B39D-9C73D64CE3B0}
HKEY_CLASSES_ROOT\Interface\{FA38F299-57F8-4FEB-9096-715460AE943C}
HKEY_CLASSES_ROOT\TypeLib\{DE6AE29A-EB7D-4656-9418-26D5FCC9ADF5}
HKEY_LOCAL_MACHINE\SOFTWARE\AntiVirGear 3.8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVirGear 3.8.exe 3.8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirGear 3.8
HKEY_CLASSES_ROOT\Interface\{418985AE-4FE4-448D-83EE-238C887D8FC2}
HKEY_CLASSES_ROOT\Interface\{5F251303-F8C4-44C3-A7C2-9E8A93C59322}
HKEY_CLASSES_ROOT\Interface\{61840430-C7CF-43A0-9D49-3B3ED563FED1}
HKEY_CLASSES_ROOT\Interface\{765A8F7D-F57B-4601-A038-3F463A4D3193}
HKEY_CLASSES_ROOT\Interface\{77E616D5-5DB4-4B6A-8BDA-2BE4103A9921}
HKEY_CLASSES_ROOT\Interface\{8742F319-C916-4930-B781-1C148134C05C}
HKEY_CLASSES_ROOT\Interface\{897F5CB6-C1C1-494E-8F17-972784193442}
HKEY_CLASSES_ROOT\Interface\{A2224C72-745E-4046-882F-1A48C9311D77}
HKEY_CLASSES_ROOT\Interface\{AA500EFC-3C92-44C9-B1D6-7A7033343A50}
HKEY_CLASSES_ROOT\Interface\{AB5E9971-7086-4E6E-ADFA-BE9C685BE68B}
HKEY_CLASSES_ROOT\Interface\{AD7CA0BC-693A-4AF9-B31A-60472248F761}
HKEY_CLASSES_ROOT\Interface\{B2882CC2-0077-426B-916D-E0B9EA23A1B5}
HKEY_CLASSES_ROOT\Interface\{EE241504-6F15-49E4-847F-B4D7DA9EA8F9}
HKEY_CLASSES_ROOT\Interface\{F1666E4E-45C8-462A-97FF-BFD5A103BFFA}
HKEY_CLASSES_ROOT\Interface\{FD9A05E8-4A1E-45E6-B3B6-37CE20140278}
HKEY_CLASSES_ROOT\TypeLib\{AF0C5CBA-52E1-4B29-A2DC-58D91D599612}
HKEY_LOCAL_MACHINE\SOFTWARE\AntiVirGear 3.7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVirGear 3.7.exe 3.7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirGear 3.7
HKEY_CLASSES_ROOT\clsid\{1817ab5d-25bf-4d5e-ba90-6e5fe658fc5f}\inprocserver32
HKEY_CLASSES_ROOT\clsid\{3bc3ac5b-3bbb-9dbe-8166-ec650e3b9b48}
HKEY_CLASSES_ROOT\clsid\{60dea04c-9817-4309-bfa2-f8a1766c3cd1}\inprocserver32
HKEY_CLASSES_ROOT\interface\{0a0fc1a4-41d4-4793-9ac5-0b55cdc95ae9}
HKEY_CLASSES_ROOT\interface\{14f47ca3-2291-4b3e-9ed4-8c7e6ae80851}
HKEY_CLASSES_ROOT\interface\{2447284f-3590-4e8c-a869-049bd87cad07}
HKEY_CLASSES_ROOT\interface\{38eeef46-ca24-4aca-a90d-540978df7252}
HKEY_CLASSES_ROOT\interface\{3d5e5ae1-5ded-4520-bdc2-b9292ea708ca}
HKEY_CLASSES_ROOT\interface\{409a05ef-1b48-4198-b6bf-993b8b52790c}
HKEY_CLASSES_ROOT\interface\{47a93011-1004-440c-9960-bd3b0348a7c2}
HKEY_CLASSES_ROOT\interface\{50b388d5-4a80-4191-8bcc-5dd031d7f3ee}
HKEY_CLASSES_ROOT\interface\{58a1ace6-0dba-45d2-8154-e8253a7b87bb}
HKEY_CLASSES_ROOT\interface\{73d25394-992f-43d1-bf92-48494cc0d1ae}
HKEY_CLASSES_ROOT\interface\{7d2a83a4-0687-4704-937e-a29045826f77}
HKEY_CLASSES_ROOT\interface\{a7fe54b2-b167-4017-bccc-cf73b2f678e3}
HKEY_CLASSES_ROOT\interface\{c183b073-2d7f-45bc-8967-80147cecee45}
HKEY_CLASSES_ROOT\interface\{f6fdbf9a-19a7-4f0a-9f46-6f015a067b44}
HKEY_CLASSES_ROOT\interface\{f90a7969-20a0-4257-b39d-9c73d64ce3b0}
HKEY_CLASSES_ROOT\interface\{fa38f299-57f8-4feb-9096-715460ae943c}
HKEY_CLASSES_ROOT\typelib\{de6ae29a-eb7d-4656-9418-26d5fcc9adf5}
HKEY_LOCAL_MACHINE\software\antivirgear 3.8
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\antivirgear 3.8.exe 3.8
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\antivirgear 3.8

Registry Values:
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\software\microsoft\windows\shellnoroam\muicache
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
EliteMedia Adware Information
Remove Dollar.Revenue Adware
Remove Win32.TrojanDropper.Delf.NAC Trojan
VB.hc Downloader Symptoms
FreeGatez Trojan Removal instruction

No comments: