Monday, November 24, 2008

Unknown.Toolbar5 BHO

How To Remove Unknown.Toolbar5?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Unknown.Toolbar5 is dangerous virus:
The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.

Unknown.Toolbar5 Symptoms:

Files:
[%PROGRAM_FILES%]\creati~1\close draw.exe
[%PROGRAM_FILES%]\creati~1\peak.exe
[%PROGRAM_FILES%]\meetdo~1\locksdog.exe
[%PROGRAM_FILES%]\userbi~1\link flaw.dll
[%PROGRAM_FILES%]\userbi~1\memo inter.bin
[%PROGRAM_FILES%]\creati~1\close draw.exe
[%PROGRAM_FILES%]\creati~1\peak.exe
[%PROGRAM_FILES%]\meetdo~1\locksdog.exe
[%PROGRAM_FILES%]\userbi~1\link flaw.dll
[%PROGRAM_FILES%]\userbi~1\memo inter.bin

Folders:
[%PROGRAM_FILES%]\browsechicregs
[%PROGRAM_FILES%]\onemap~1

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{23abafbb-cea5-a0f1-7ba5-a710b7914263}
HKEY_CLASSES_ROOT\clsid\{38fb3e8c-0c50-0f82-c500-ed3f2d23adbb}
HKEY_CLASSES_ROOT\clsid\{982459f6-39b2-7390-05cd-6a68dc64916c}
HKEY_CLASSES_ROOT\clsid\{c08a5748-c2db-e419-425c-1d9726f6bac2}
HKEY_CLASSES_ROOT\clsid\{f8b7b4aa-2a4f-0064-3e7f-3e29df8c8937}
HKEY_LOCAL_MACHINE\software\classes\clsid\{23abafbb-cea5-a0f1-7ba5-a710b7914263}
HKEY_LOCAL_MACHINE\software\classes\clsid\{38fb3e8c-0c50-0f82-c500-ed3f2d23adbb}
HKEY_LOCAL_MACHINE\software\classes\clsid\{982459f6-39b2-7390-05cd-6a68dc64916c}
HKEY_LOCAL_MACHINE\software\classes\clsid\{c08a5748-c2db-e419-425c-1d9726f6bac2}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f8b7b4aa-2a4f-0064-3e7f-3e29df8c8937}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{38fb3e8c-0c50-0f82-c500-ed3f2d23adbb}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{982459f6-39b2-7390-05cd-6a68dc64916c}

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove TrojanDropper.Win32.VB Trojan

No comments: