Monday, November 17, 2008

AntivirusGolden Ransomware

How To Remove AntivirusGolden?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
AntivirusGolden is dangerous virus:
The term ransomware is commonly used to describe such software,
although the field known as cryptovirology predates the term "ransomware".

This type of ransom attack can be accomplished by (for example) attaching
a specially crafted file/program to an e-mail message and sending this to the victim.


AntivirusGolden Symptoms:

Files:
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntiviralGolden 3.5.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Antivirus-Golden 3.4.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGold 4.8.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 3.3.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 3.5.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 3.6.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 3.7.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 3.9.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 4.0.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 4.1.lnk
[%DESKTOP%]\AntiviralGolden.lnk
[%DESKTOP%]\Antivirus-Golden.lnk
[%DESKTOP%]\AntivirusGold 4.8.lnk
[%DESKTOP%]\AntivirusGolden 3.6.lnk
[%DESKTOP%]\AntivirusGolden 3.7.lnk
[%DESKTOP%]\AntivirusGolden 3.9.lnk
[%PROGRAM_FILES%]\AntiviralGolden\Antiviralgolden.exe
[%PROGRAM_FILES%]\AntivirusGolden\AntivirusGolden.exe
[%PROGRAM_FILES%]\AntivirusGolden\DbgHelp.Dll
[%PROGRAM_FILES%]\AntivirusGolden\ignored.lst
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_07172006-101041.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_07172006-101107.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_07172006-101129.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_07172006-101235.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_07172006-102018.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_09272006-135711.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10042006-071556.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-193548.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-193856.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-200946.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-201954.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-202117.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-202127.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10142006-052359.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10272006-134658.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10272006-144212.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10272006-201905.html
[%PROGRAM_FILES%]\AntivirusGolden\monitorConfig.xml
[%PROGRAM_FILES%]\AntivirusGolden\usageStats.xml
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.6\Antivirusgold 4.6.exe
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.8\Antivirusgold 4.8.exe
[%PROGRAM_FILES%]\AVG\AntivirusGolden 3.9\antivirusgolden 3.9.exe
[%PROGRAM_FILES%]\AVG\AntivirusGolden 4.1\Antivirusgold 4.1.exe
[%STARTMENU%]\AntiviralGolden 3.5.lnk
[%STARTMENU%]\Antivirus-Golden 3.4.lnk
[%STARTMENU%]\AntivirusGold 4.8.lnk
[%STARTMENU%]\AntivirusGolden 3.5.lnk
[%STARTMENU%]\AntivirusGolden 3.6.lnk
[%STARTMENU%]\AntivirusGolden 3.7.lnk
[%STARTMENU%]\AntivirusGolden 3.8.lnk
[%STARTMENU%]\AntivirusGolden 3.9.lnk
[%STARTMENU%]\AntivirusGolden 4.0.lnk
[%STARTMENU%]\AntivirusGolden 4.1.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntiviralGolden 3.5.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Antivirus-Golden 3.4.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGold 4.8.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 3.3.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 3.5.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 3.6.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 3.7.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 3.9.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 4.0.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\AntivirusGolden 4.1.lnk
[%DESKTOP%]\AntiviralGolden.lnk
[%DESKTOP%]\Antivirus-Golden.lnk
[%DESKTOP%]\AntivirusGold 4.8.lnk
[%DESKTOP%]\AntivirusGolden 3.6.lnk
[%DESKTOP%]\AntivirusGolden 3.7.lnk
[%DESKTOP%]\AntivirusGolden 3.9.lnk
[%PROGRAM_FILES%]\AntiviralGolden\Antiviralgolden.exe
[%PROGRAM_FILES%]\AntivirusGolden\AntivirusGolden.exe
[%PROGRAM_FILES%]\AntivirusGolden\DbgHelp.Dll
[%PROGRAM_FILES%]\AntivirusGolden\ignored.lst
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_07172006-101041.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_07172006-101107.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_07172006-101129.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_07172006-101235.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_07172006-102018.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_09272006-135711.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10042006-071556.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-193548.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-193856.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-200946.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-201954.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-202117.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10112006-202127.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10142006-052359.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10272006-134658.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10272006-144212.html
[%PROGRAM_FILES%]\AntivirusGolden\Logs\scan_log_10272006-201905.html
[%PROGRAM_FILES%]\AntivirusGolden\monitorConfig.xml
[%PROGRAM_FILES%]\AntivirusGolden\usageStats.xml
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.6\Antivirusgold 4.6.exe
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.8\Antivirusgold 4.8.exe
[%PROGRAM_FILES%]\AVG\AntivirusGolden 3.9\antivirusgolden 3.9.exe
[%PROGRAM_FILES%]\AVG\AntivirusGolden 4.1\Antivirusgold 4.1.exe
[%STARTMENU%]\AntiviralGolden 3.5.lnk
[%STARTMENU%]\Antivirus-Golden 3.4.lnk
[%STARTMENU%]\AntivirusGold 4.8.lnk
[%STARTMENU%]\AntivirusGolden 3.5.lnk
[%STARTMENU%]\AntivirusGolden 3.6.lnk
[%STARTMENU%]\AntivirusGolden 3.7.lnk
[%STARTMENU%]\AntivirusGolden 3.8.lnk
[%STARTMENU%]\AntivirusGolden 3.9.lnk
[%STARTMENU%]\AntivirusGolden 4.0.lnk
[%STARTMENU%]\AntivirusGolden 4.1.lnk

Folders:
[%COMMON_PROGRAMS%]\AntiviralGolden
[%COMMON_PROGRAMS%]\AntivirusGolden 3.7
[%PROGRAMS%]\AntiviralGolden
[%PROGRAMS%]\Antivirus-Golden
[%PROGRAMS%]\AntivirusGold 4.8
[%PROGRAMS%]\AntivirusGolden 3.6
[%PROGRAMS%]\AntivirusGolden 3.7
[%PROGRAMS%]\AntivirusGolden 3.9
[%PROGRAMS%]\AntivirusGolden 4.0
[%PROGRAMS%]\AntivirusGolden 4.1
[%PROGRAMS%]\AntivirusGoldenPro
[%PROGRAM_FILES%]\AntiviralGolden
[%PROGRAM_FILES%]\Antivirus-Golden
[%PROGRAM_FILES%]\AntivirusGolden
[%PROGRAM_FILES%]\AntivirusGoldenPro
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.2
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.4
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.5
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.6
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.7
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.8
[%PROGRAM_FILES%]\AVG\AntivirusGold 4.9
[%PROGRAM_FILES%]\AVG\AntivirusGold 5.0
[%PROGRAM_FILES%]\AVG\AntivirusGolden
[%PROGRAM_FILES%]\AVG\AntivirusGolden 3.9
[%PROGRAM_FILES%]\AVG\AntivirusGolden 4.0
[%PROGRAM_FILES%]\AVG\AntivirusGolden 4.1
[%PROGRAM_FILES%]\AV\AntivirusGolden 3.7
[%PROGRAM_FILES%]\AV\AntivirusGolden 3.8

Registry Keys:
HKEY_CLASSES_ROOT\AppID\Cerberus.EXE
HKEY_CLASSES_ROOT\AppID\{70F17C8C-1744-41B6-9D07-575DB448DCC5}
HKEY_CLASSES_ROOT\Cerberus.EngineListener
HKEY_CLASSES_ROOT\Cerberus.EngineListener.1
HKEY_CLASSES_ROOT\Cerberus.Scanner
HKEY_CLASSES_ROOT\Cerberus.Scanner.1
HKEY_CLASSES_ROOT\Cerberus.ThreatCollection
HKEY_CLASSES_ROOT\Cerberus.ThreatCollection.1
HKEY_CLASSES_ROOT\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1}
HKEY_CLASSES_ROOT\CLSID\{125494B2-ACAD-414c-98B9-452F3EF7703A}
HKEY_CLASSES_ROOT\CLSID\{17152BD5-4212-FEB6-BA05-A53571CF99F2}
HKEY_CLASSES_ROOT\CLSID\{20A3D913-30EF-4e69-B3F7-93B3F1FB9D5C}
HKEY_CLASSES_ROOT\CLSID\{3D00A39C-655B-428b-AEB2-2FBA03DCC49C}
HKEY_CLASSES_ROOT\CLSID\{408F660A-9465-44a3-B557-8709DFD992BC}
HKEY_CLASSES_ROOT\CLSID\{5F6BBD8A-18CF-4d55-8B4C-C9B4C9328DFE}
HKEY_CLASSES_ROOT\CLSID\{8C56B6CE-C53F-44c4-9BDC-A9BC1711D05A}
HKEY_CLASSES_ROOT\CLSID\{8EE6BF73-B370-4d13-9126-EB0071178F2E}
HKEY_CLASSES_ROOT\CLSID\{97F56E12-C706-4aeb-9FFB-133C05EE5D38}
HKEY_CLASSES_ROOT\CLSID\{9BB7E700-4E48-476d-B75C-6F47606BE988}
HKEY_CLASSES_ROOT\CLSID\{C5F09443-D204-108C-CDFF-3724D7D881FF}
HKEY_CLASSES_ROOT\CLSID\{C65C3770-598C-A2FD-DBAA-C7A45C50338E}
HKEY_CLASSES_ROOT\CLSID\{CBCACA58-1AEE-4600-8CF0-E8B30BFF1535}
HKEY_CLASSES_ROOT\CLSID\{D6D64CDF-0363-4261-B723-29A3AF365E1D}
HKEY_CLASSES_ROOT\Engine.Backup
HKEY_CLASSES_ROOT\Engine.Backup.1
HKEY_CLASSES_ROOT\Engine.IgnoreList
HKEY_CLASSES_ROOT\Engine.IgnoreList.1
HKEY_CLASSES_ROOT\Engine.Log
HKEY_CLASSES_ROOT\Engine.Log.1
HKEY_CLASSES_ROOT\Engine.LogRecord
HKEY_CLASSES_ROOT\Engine.LogRecord.1
HKEY_CLASSES_ROOT\Engine.Paths
HKEY_CLASSES_ROOT\Engine.Paths.1
HKEY_CLASSES_ROOT\Engine.Quarantine
HKEY_CLASSES_ROOT\Engine.Quarantine.1
HKEY_CLASSES_ROOT\Engine.RunAs
HKEY_CLASSES_ROOT\Engine.RunAs.1
HKEY_CLASSES_ROOT\Engine.SearchItem
HKEY_CLASSES_ROOT\Engine.SearchItem.1
HKEY_CLASSES_ROOT\Engine.Threat
HKEY_CLASSES_ROOT\Engine.Threat.1
HKEY_CLASSES_ROOT\Interface\{0620DF3E-DEA8-47A2-995B-0D9619CB5A23}
HKEY_CLASSES_ROOT\Interface\{1405F930-EA16-4769-8587-2C27F0AC8986}
HKEY_CLASSES_ROOT\Interface\{192DB2F0-E33D-464E-9424-42BB38B09471}
HKEY_CLASSES_ROOT\Interface\{27ED4AC2-B6D8-4079-9831-017A100B391E}
HKEY_CLASSES_ROOT\Interface\{2F8992E1-0D8D-4700-AC0C-6D4C94E08918}
HKEY_CLASSES_ROOT\Interface\{3A424FA5-CB23-4B52-B1E3-10E74CCF37E1}
HKEY_CLASSES_ROOT\Interface\{3F6D6C35-FB73-45E6-9473-BB4CC25CE019}
HKEY_CLASSES_ROOT\Interface\{51CBD8EB-E73C-4683-91FF-285A3864CF6B}
HKEY_CLASSES_ROOT\Interface\{54EB8F0C-4A6F-4EEB-B281-960BCE1B3DC9}
HKEY_CLASSES_ROOT\Interface\{6E752169-6C00-41B4-94AD-3EEE6934D441}
HKEY_CLASSES_ROOT\Interface\{6F8911BF-3E5B-44B9-BCA8-A7E82CB06274}
HKEY_CLASSES_ROOT\Interface\{715D709B-2B10-42FA-A069-297D25D93601}
HKEY_CLASSES_ROOT\Interface\{78235833-2296-49FE-BE53-EAC143D26F68}
HKEY_CLASSES_ROOT\Interface\{86F62261-CCD4-4069-8B54-6DDAA972D273}
HKEY_CLASSES_ROOT\Interface\{872C1B1E-3CF0-4D3A-95E5-A0C662D2854C}
HKEY_CLASSES_ROOT\Interface\{886B1D08-B404-40F0-AA18-4E416682A2E9}
HKEY_CLASSES_ROOT\Interface\{8A5B4776-E225-4986-9E35-4FA655A7E54C}
HKEY_CLASSES_ROOT\Interface\{8B5F65CF-0B0A-4291-8DA2-86D7F7B0A6DB}
HKEY_CLASSES_ROOT\Interface\{925B0211-A1C1-4712-8FCA-5F5B8101736D}
HKEY_CLASSES_ROOT\Interface\{B01E37C4-5497-4D58-9FFD-D5653B8DC866}
HKEY_CLASSES_ROOT\Interface\{C8E9BDC3-C627-405C-A307-7780C2590ED9}
HKEY_CLASSES_ROOT\Interface\{CCAA201C-C48D-48A8-A1E8-846562CBF1C1}
HKEY_CLASSES_ROOT\Interface\{D483521B-D5CC-43FF-A45A-9BE4A8E6606E}
HKEY_CLASSES_ROOT\Interface\{ED2AFF47-B7BE-4273-A203-C796E87F72D2}
HKEY_CLASSES_ROOT\Interface\{F0FA7ED9-5A0A-4374-B63E-BEBAFD52192E}
HKEY_CLASSES_ROOT\Interface\{F16E29AF-91D2-43F8-96C0-33DDDC3F55CB}
HKEY_CLASSES_ROOT\Interface\{F2CA3C2C-0E1F-4846-A528-103BBBD73FDE}
HKEY_CLASSES_ROOT\Interface\{F431E023-5FE9-40B1-83C2-FF5FCDBA4011}
HKEY_CLASSES_ROOT\Interface\{F5DEE77C-87EB-4E00-BBF9-8CBF3BDEA7AF}
HKEY_CLASSES_ROOT\Interface\{FB5DDAB7-6AA5-4E97-9541-5A75ADDF4ABA}
HKEY_CLASSES_ROOT\Interface\{FDDF521B-0EBE-4D15-838C-73E2D851161B}
HKEY_CLASSES_ROOT\Interface\{FF609434-EB47-481B-BA0E-1D2B467629A5}
HKEY_CLASSES_ROOT\TypeLib\{2E985CF4-F2FD-44B6-91C5-CBEF78F2AA0E}
HKEY_CLASSES_ROOT\TypeLib\{60F94D7D-563E-4942-B5EC-2DE9C135C139}
HKEY_LOCAL_MACHINE\SOFTWARE\AntiviralGolden
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus-Golden
HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGold
HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGold 4.6
HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGold 4.8
HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGolden
HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGolden 3.9
HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGolden 4.0
HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGolden 4.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Antivirus-Golden.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusGold 4.6.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusGold 4.8.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusGolden 3.9.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusGolden 4.0.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusGolden.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiviralGolden
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus-Golden
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntivirusGold 4.6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntivirusGold 4.8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntivirusGolden
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntivirusGolden 3.9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntivirusGolden 4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntivirusGolden 4.1

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiviralGolden.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Antivirus-Golden.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusGolden.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing Ezula.EIM03 Adware
Propo Trojan Symptoms
Agent.SBB Trojan Removal instruction
SD.Bot Backdoor Cleaner
CoolWeb Adware Information

No comments: