Monday, November 3, 2008

BearShare Worm

How To Remove Remove BearShare?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
BearShare is dangerous virus:
Worms can be classified according to the propagation method they use,
i.e. how they deliver copies of themselves to new victim machines.
Worms can also be classified by installation method, launch method and finally according
to characteristics standard to all malware: polymorphism, stealth etc.

Many of the worms which managed to cause significant outbreaks use more then
one propagation method as well as more than one infection technique.
The methods are listed separately below.


BearShare Symptoms:

Files:
[%DESKTOP%]\bearshare downloads.lnk
[%DESKTOP%]\bearshare.lnk
[%PROGRAMS%]\bearshare.lnk
[%PROGRAM_FILES%]\bearsh~1\bearsh~1.exe
[%DESKTOP%]\bearshare downloads.lnk
[%DESKTOP%]\bearshare.lnk
[%PROGRAMS%]\bearshare.lnk
[%PROGRAM_FILES%]\bearsh~1\bearsh~1.exe

Folders:
[%PROGRAM_FILES%]\bearshare

Registry Keys:
HKEY_CURRENT_USER\appevents\eventlabels\bearsharechatnotifymsg
HKEY_CURRENT_USER\appevents\schemes\apps\bearshare
HKEY_LOCAL_MACHINE\software\bearshare
HKEY_LOCAL_MACHINE\software\classes\clsid\{558ec983-bedb-9168-b2de-31dbf0ee543e}
HKEY_LOCAL_MACHINE\software\classes\gnu
HKEY_LOCAL_MACHINE\software\classes\gnufile\shell\open\command
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5f95e1af-2620-4f15-bdf9-7fdce4607e17}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\bearshare
HKEY_USERS\.default\appevents\eventlabels\bearsharechatnotifymsg
HKEY_USERS\.default\appevents\schemes\apps\bearshare

Registry Values:
HKEY_LOCAL_MACHINE\software\classes\gnufile
HKEY_LOCAL_MACHINE\software\classes\gnufile
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\licenses
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing CWS.SysTime Hijacker
Keycorder Spyware Cleaner
SillyDl.BYG Downloader Removal
Removing VB.hc Downloader
Livuto Trojan Removal instruction

No comments: