Monday, November 17, 2008

SpediaBar Adware

How To Remove SpediaBar?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
SpediaBar is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.

SpediaBar It also known as:

[Panda]Adware/PortalScan

SpediaBar Symptoms:

Files:
[%PROGRAMS%]\spedia.lnk
[%WINDOWS%]\mwsvm.exe
[%PROGRAMS%]\spedia.lnk
[%WINDOWS%]\mwsvm.exe

Folders:
[%DESKTOP%]\spedia.lnk

Registry Keys:
HKEY_LOCAL_MACHINE\software\classes\adrotator.application
HKEY_LOCAL_MACHINE\software\classes\clsid\{00000000-0000-0000-0000-000000000221}
HKEY_LOCAL_MACHINE\software\classes\clsid\{00000250-0320-4dd4-be4f-7566d2314352}
HKEY_LOCAL_MACHINE\software\classes\clsid\{3e7145b1-ea07-42ce-9299-11df39ff54bd}
HKEY_LOCAL_MACHINE\software\classes\clsid\{965a592f-8efa-4250-8630-7960230792f1}
HKEY_LOCAL_MACHINE\software\classes\csie.csiecore
HKEY_LOCAL_MACHINE\software\classes\csie.csiecore.1
HKEY_LOCAL_MACHINE\software\classes\interface\{0f2a4adc-dabf-4980-8db4-19f67d7b1f95}
HKEY_LOCAL_MACHINE\software\classes\interface\{96b3b1b9-a510-4603-bd66-2bb2c9f21542}
HKEY_LOCAL_MACHINE\software\classes\swrt01.rt
HKEY_LOCAL_MACHINE\software\classes\typelib\{60494593-5408-447d-bd5e-a16640d6af99}
HKEY_LOCAL_MACHINE\software\classes\typelib\{69db5061-ff0a-418b-ada6-68ac77d69e44}
HKEY_LOCAL_MACHINE\software\classes\urlsearch.urlsearch
HKEY_LOCAL_MACHINE\software\classes\urlsearch.urlsearch.1
HKEY_LOCAL_MACHINE\software\classes\voiceipdll.voiceipdllobj.1
HKEY_LOCAL_MACHINE\software\classes\clsid\{34ef5b1c-52cb-400b-8b7c-f787018b3826}
HKEY_LOCAL_MACHINE\software\classes\interface\{e9d8697e-bea9-4170-84f3-509ad2a11951}
HKEY_LOCAL_MACHINE\software\classes\typelib\{3cd9d85e-1ff2-4bf7-a113-6669b8d1e676}
HKEY_LOCAL_MACHINE\software\classes\urllauncher.urllaunchercontrol
HKEY_LOCAL_MACHINE\software\classes\urllauncher.urllaunchercontrol.1
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{13197ace-6851-45c3-a7ff-c281324d5489}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\wise solutions\wise installation system\repair\c:/winnt/system32/innervbinstall.log
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\wise solutions\wise installation system\repair\[%SYSTEM%]/innervbinstall.log


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove suitesmart.com Tracking Cookie
ShellDoor Trojan Cleaner
Pigeon.AWL Trojan Symptoms

No comments: