Saturday, December 6, 2008

PromulGate Adware

How To Remove PromulGate?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
PromulGate is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


PromulGate Symptoms:

Files:
[%APPDATA%]\Tenebril\GhostSurf\3.0\Spyware history\Restore\d22428bb0b0bd18a61917f100a90ebeb
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinAF.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinBD.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinCO.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinDL.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinED.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinID.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinLD.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinLO.ebd
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinST.ebd
[%COMMON_APPDATA%]\nfo\arch\286.dfn
[%COMMON_APPDATA%]\nfo\mon0106.ddx
[%COMMON_APPDATA%]\nfo\mon0204.ddx
[%COMMON_APPDATA%]\nfo\mon0315.ddx
[%COMMON_APPDATA%]\nfo\mon0412.ddx
[%COMMON_APPDATA%]\nfo\mon0504.ddx
[%COMMON_APPDATA%]\nfo\mon0904.ddx
[%COMMON_APPDATA%]\nfo\mon1125.ddx
[%COMMON_APPDATA%]\nfo\mon1204.ddx
[%COMMON_APPDATA%]\nfo\mon1215.dbd
[%COMMON_APPDATA%]\nfo\mon1909.ddx
[%COMMON_APPDATA%]\nfo\mon1920.dbd
[%COMMON_APPDATA%]\nfo\mon2007.dbd
[%COMMON_APPDATA%]\nsv\cache\286.dfn
[%COMMON_APPDATA%]\nsv\cache\538.dfn
[%COMMON_APPDATA%]\nsv\wmv0106.ddx
[%COMMON_APPDATA%]\nsv\wmv0204.ddx
[%COMMON_APPDATA%]\nsv\wmv0315.ddx
[%COMMON_APPDATA%]\nsv\wmv0412.ddx
[%COMMON_APPDATA%]\nsv\wmv0504.ddx
[%COMMON_APPDATA%]\nsv\wmv0904.ddx
[%COMMON_APPDATA%]\nsv\wmv1125.ddx
[%COMMON_APPDATA%]\nsv\wmv1204.ddx
[%COMMON_APPDATA%]\nsv\wmv1215.dbd
[%COMMON_APPDATA%]\nsv\wmv1909.ddx
[%COMMON_APPDATA%]\nsv\wmv1920.dbd
[%COMMON_APPDATA%]\nsv\wmv2007.dbd
[%COMMON_APPDATA%]\pcsvc\delfinAF.edx
[%COMMON_APPDATA%]\pcsvc\delfinBD.edx
[%COMMON_APPDATA%]\pcsvc\delfinCO.edx
[%COMMON_APPDATA%]\pcsvc\delfinDL.edx
[%COMMON_APPDATA%]\pcsvc\delfinED.edx
[%COMMON_APPDATA%]\pcsvc\delfinID.edx
[%COMMON_APPDATA%]\pcsvc\delfinKY.edx
[%COMMON_APPDATA%]\pcsvc\delfinLD.edx
[%COMMON_APPDATA%]\pcsvc\delfinLO.ebd
[%COMMON_APPDATA%]\pcsvc\delfinSI.edx
[%COMMON_APPDATA%]\pcsvc\delfinST.ebd
[%COMMON_APPDATA%]\pcsvc\delfinTG.ebd
[%COMMON_APPDATA%]\wsxs\Adverts\286.dfn
[%COMMON_APPDATA%]\wsxs\delfinAF.edx
[%COMMON_APPDATA%]\wsxs\delfinBD.edx
[%COMMON_APPDATA%]\wsxs\delfinCO.edx
[%COMMON_APPDATA%]\wsxs\delfinDL.edx
[%COMMON_APPDATA%]\wsxs\delfinED.edx
[%COMMON_APPDATA%]\wsxs\delfinID.edx
[%COMMON_APPDATA%]\wsxs\delfinKY.edx
[%COMMON_APPDATA%]\wsxs\delfinLD.edx
[%COMMON_APPDATA%]\wsxs\delfinLO.ebd
[%COMMON_APPDATA%]\wsxs\delfinSI.edx
[%COMMON_APPDATA%]\wsxs\delfinST.ebd
[%COMMON_APPDATA%]\wsxs\delfinTG.ebd
[%SYSTEM%]\wsxsvc\License.txt
[%SYSTEM%]\wsxsvc\uninstall.html
[%SYSTEM%]\dp-b23011805.exe
[%APPDATA%]\Tenebril\GhostSurf\3.0\Spyware history\Restore\d22428bb0b0bd18a61917f100a90ebeb
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinAF.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinBD.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinCO.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinDL.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinED.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinID.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinLD.edx
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinLO.ebd
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinST.ebd
[%COMMON_APPDATA%]\nfo\arch\286.dfn
[%COMMON_APPDATA%]\nfo\mon0106.ddx
[%COMMON_APPDATA%]\nfo\mon0204.ddx
[%COMMON_APPDATA%]\nfo\mon0315.ddx
[%COMMON_APPDATA%]\nfo\mon0412.ddx
[%COMMON_APPDATA%]\nfo\mon0504.ddx
[%COMMON_APPDATA%]\nfo\mon0904.ddx
[%COMMON_APPDATA%]\nfo\mon1125.ddx
[%COMMON_APPDATA%]\nfo\mon1204.ddx
[%COMMON_APPDATA%]\nfo\mon1215.dbd
[%COMMON_APPDATA%]\nfo\mon1909.ddx
[%COMMON_APPDATA%]\nfo\mon1920.dbd
[%COMMON_APPDATA%]\nfo\mon2007.dbd
[%COMMON_APPDATA%]\nsv\cache\286.dfn
[%COMMON_APPDATA%]\nsv\cache\538.dfn
[%COMMON_APPDATA%]\nsv\wmv0106.ddx
[%COMMON_APPDATA%]\nsv\wmv0204.ddx
[%COMMON_APPDATA%]\nsv\wmv0315.ddx
[%COMMON_APPDATA%]\nsv\wmv0412.ddx
[%COMMON_APPDATA%]\nsv\wmv0504.ddx
[%COMMON_APPDATA%]\nsv\wmv0904.ddx
[%COMMON_APPDATA%]\nsv\wmv1125.ddx
[%COMMON_APPDATA%]\nsv\wmv1204.ddx
[%COMMON_APPDATA%]\nsv\wmv1215.dbd
[%COMMON_APPDATA%]\nsv\wmv1909.ddx
[%COMMON_APPDATA%]\nsv\wmv1920.dbd
[%COMMON_APPDATA%]\nsv\wmv2007.dbd
[%COMMON_APPDATA%]\pcsvc\delfinAF.edx
[%COMMON_APPDATA%]\pcsvc\delfinBD.edx
[%COMMON_APPDATA%]\pcsvc\delfinCO.edx
[%COMMON_APPDATA%]\pcsvc\delfinDL.edx
[%COMMON_APPDATA%]\pcsvc\delfinED.edx
[%COMMON_APPDATA%]\pcsvc\delfinID.edx
[%COMMON_APPDATA%]\pcsvc\delfinKY.edx
[%COMMON_APPDATA%]\pcsvc\delfinLD.edx
[%COMMON_APPDATA%]\pcsvc\delfinLO.ebd
[%COMMON_APPDATA%]\pcsvc\delfinSI.edx
[%COMMON_APPDATA%]\pcsvc\delfinST.ebd
[%COMMON_APPDATA%]\pcsvc\delfinTG.ebd
[%COMMON_APPDATA%]\wsxs\Adverts\286.dfn
[%COMMON_APPDATA%]\wsxs\delfinAF.edx
[%COMMON_APPDATA%]\wsxs\delfinBD.edx
[%COMMON_APPDATA%]\wsxs\delfinCO.edx
[%COMMON_APPDATA%]\wsxs\delfinDL.edx
[%COMMON_APPDATA%]\wsxs\delfinED.edx
[%COMMON_APPDATA%]\wsxs\delfinID.edx
[%COMMON_APPDATA%]\wsxs\delfinKY.edx
[%COMMON_APPDATA%]\wsxs\delfinLD.edx
[%COMMON_APPDATA%]\wsxs\delfinLO.ebd
[%COMMON_APPDATA%]\wsxs\delfinSI.edx
[%COMMON_APPDATA%]\wsxs\delfinST.ebd
[%COMMON_APPDATA%]\wsxs\delfinTG.ebd
[%SYSTEM%]\wsxsvc\License.txt
[%SYSTEM%]\wsxsvc\uninstall.html
[%SYSTEM%]\dp-b23011805.exe

Folders:
[%PROFILE%]\all users\application data\dpi
[%PROFILE%]\all users\application data\wsxs

Registry Keys:
HKEY_CLASSES_ROOT\interface\{2bb15d36-43be-4743-a3a0-3308f4b1a610}
HKEY_CLASSES_ROOT\interface\{41700749-a109-4254-af13-be54011e8783}
HKEY_CLASSES_ROOT\typelib\{2a7db8d1-43be-4ad3-a81e-9bb8c9d00073}
HKEY_LOCAL_MACHINE\software\dpi
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\dmvlite
HKEY_CURRENT_USER\software\dvx
HKEY_LOCAL_MACHINE\software\vmss

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
VB.kq Trojan Cleaner
Remove SearchTool Adware

No comments: