Thursday, December 4, 2008

Aboutblank Trojan

How To Remove Aboutblank?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Aboutblank is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Backdoors are used by virus writers to detect and download confidential information,
execute malicious code, destroy data, include the machine in bot networks and so forth.

When the default home page is hijacked, the browser opens to the web page set by the hijacker
instead of the user's designated home page. In some cases, the hijacker may block users from
restoring their desired home page.


Aboutblank It also known as:

[Kaspersky]Backdoor.Agent.ac,Trojan.Win32.StartPage.ix;
[Eset]Win32/Agent.AC trojan,Win32/StartPage.IX trojan;
[Panda]Bck/Agent.E,Trj/StartPage.FH;
[Computer Associates]Win32.Mersting.B,Win32.Startpage.FZ,Win32/DlMersting.BA.30720!Trojan,Win32/Mersting.B!DLL!Trojan

Aboutblank Symptoms:

Files:
[%WINDOWS%]\svhost.exe
[%PROGRAM_FILES%]\ISSS\ZILLAbar\ZILLAbar.dll
[%SYSTEM%]\jjjhk.dll
[%SYSTEM%]\newkh.dll
[%SYSTEM%]\rzwqb.dll
[%WINDOWS%]\ausjn.dll
[%SYSTEM%]\cbme.dll
[%SYSTEM%]\xea2108l.9zt
[%WINDOWS%]\system\achpjba.dll
[%WINDOWS%]\system\wdm.dll
[%WINDOWS%]\svhost.exe
[%PROGRAM_FILES%]\ISSS\ZILLAbar\ZILLAbar.dll
[%SYSTEM%]\jjjhk.dll
[%SYSTEM%]\newkh.dll
[%SYSTEM%]\rzwqb.dll
[%WINDOWS%]\ausjn.dll
[%SYSTEM%]\cbme.dll
[%SYSTEM%]\xea2108l.9zt
[%WINDOWS%]\system\achpjba.dll
[%WINDOWS%]\system\wdm.dll

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{06abaa2d-34ab-4902-a326-409bd9b9a7a5}
HKEY_CLASSES_ROOT\clsid\{b664647f-efd5-4837-a810-a807139107e5}
HKEY_CLASSES_ROOT\clsid\{ce6a1268-9cc9-4ba3-8657-fe1132906cc4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{b664647f-efd5-4837-a810-a807139107e5}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search
HKEY_CLASSES_ROOT\protocols\filter\text/html
HKEY_CLASSES_ROOT\protocols\filter\text/plain
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
BrowserAid.SearchandClick BHO Removal instruction

No comments: