Tuesday, December 9, 2008

AdDestroyer Adware

How To Remove AdDestroyer?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
AdDestroyer is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


AdDestroyer It also known as:

[Panda]Adware/AdDestroyer;
[Other]Adware.AdDestroyer

AdDestroyer Symptoms:

Files:
[%STARTUP%]\addestroyer.lnk
[%SYSTEM%]\popoops.dll
[%SYSTEM%]\popoops2.dll
[%SYSTEM%]\swlad1.dll
[%SYSTEM%]\swlad2.dll
[%SYSTEM%]\SWRT01.dll
[%SYSTEM%]\swrt01.dll
[%SYSTEM%]\trans.exe
[%STARTUP%]\addestroyer.lnk
[%SYSTEM%]\popoops.dll
[%SYSTEM%]\popoops2.dll
[%SYSTEM%]\swlad1.dll
[%SYSTEM%]\swlad2.dll
[%SYSTEM%]\SWRT01.dll
[%SYSTEM%]\swrt01.dll
[%SYSTEM%]\trans.exe

Folders:
[%PROGRAM_FILES%]\addestroyer
[%STARTMENU%]\programs\addestroyer
[%APPDATA%]\addestroyer
[%PROFILE%]\start menu\programs\addestroyer

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{417386c3-8d4a-4611-9b91-e57e89d603ac}
HKEY_CLASSES_ROOT\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}
HKEY_CLASSES_ROOT\interface\{10d7db96-56dc-4617-8eab-ec506abe6c7e}
HKEY_CLASSES_ROOT\interface\{6cdc3337-01f7-4a79-a4af-0b19303cc0be}
HKEY_CLASSES_ROOT\interface\{795398d0-dc2f-4118-a69c-592273ba9c2b}
HKEY_CLASSES_ROOT\interface\{b288f21c-a144-4ca2-9b70-8afa1fae4b06}
HKEY_CLASSES_ROOT\popoops2.popoops
HKEY_CLASSES_ROOT\swlad1.swlad
HKEY_CLASSES_ROOT\typelib\{d0c29a75-7146-4737-98ee-bc4d7cf44af9}
HKEY_CLASSES_ROOT\typelib\{e0d3b292-a0b0-4640-975c-2f882e039f52}
HKEY_CURRENT_USER\software\vb and vba program settings\addestroyer
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\addestroyer
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\addestroyer

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\pgtools
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/hdplugin1018.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/hdplugin1018.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pgate
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pgate
HKEY_LOCAL_MACHINE\software\dtlbne
HKEY_LOCAL_MACHINE\software\dtlbne
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\pgtools
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/hdplugin1018.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/hdplugin1018.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pgate
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pgate


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove Bancos.HZP Trojan

No comments: