Monday, December 8, 2008

Video ActiveX Object Trojan

How To Remove Video ActiveX Object?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Video ActiveX Object is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
The pop-ups generally will not be stopped by pop-up stoppers, and often are
not dependent on your having Internet Explorer open.



Video ActiveX Object Symptoms:

Registry Keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Video ActiveX Object
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Video ActiveX Object-delete


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove Watch.Me! Spyware
Agent.rw Backdoor Removal instruction
Win.Blondie.joke Trojan Removal instruction
IRCBot.VR Worm Cleaner
Removing Bancos.GTL Trojan

Dagger Backdoor

How To Remove Dagger?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Dagger is dangerous virus:
Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
They function in the same way as legal remote administration programs used by system administrators.
This makes them difficult to detect.

Backdoors are installed and launched without the consent of the user of computer.
Often the backdoor will not be visible in the log of active programs.

Once a backdoor has been successfully launched, the computer is wide open.
Backdoor functions can include:


  • Launching/ deleting files

  • Sending/ receiving files

  • Deleting data

  • Displaying notification

  • Rebooting the machine

  • Executing files




Backdoors are used by virus writers to detect and download confidential information,
execute malicious code, destroy data, include the machine in bot networks and so forth.
Backdoors combine the functionality of most other types of in one package.

Backdoors have one especially dangerous sub-class: variants that can propagate like worms.
Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.
They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,
and swap mouse buttons. However, they can be quite hard to remove.


Dagger It also known as:

[Kaspersky]Backdoor.Dagger.140;
[McAfee]BackDoor-NU;
[F-Prot]security risk or a "backdoor" program;
[Panda]Bck/Dagger.140;
[Computer Associates]Backdoor/Dagger,Win32.Dagger.140

Dagger Symptoms:

Files:
[%WINDOWS%]\system\manager.exe
[%WINDOWS%]\system\manager.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
DosLoop DoS Removal
Vxidl.AHA Trojan Cleaner

Zlob.Fam.ActiveX Enhancement Trojan

How To Remove Zlob.Fam.ActiveX Enhancement?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Zlob.Fam.ActiveX Enhancement is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
The pop-ups generally will not be stopped by pop-up stoppers, and often are
not dependent on your having Internet Explorer open.



Zlob.Fam.ActiveX Enhancement Symptoms:

Registry Keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Video ActiveX Enhancement


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove Corkye Trojan
Remove Pigeon.EPZ Trojan
Zlob.Fam.VideoAXObject Trojan Removal instruction
ISTbar.MSCache Hijacker Removal instruction
PSW.Hiddukel.VI.Beta Trojan Symptoms

180Solutions.Zango Spyware

How To Remove 180Solutions.Zango?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
180Solutions.Zango is dangerous virus:
Spyware is computer software that is installed surreptitiously on a personal computer
to intercept or take partial control over the user's interaction
with the computer, without the user's informed consent.

While the term spyware suggests software that secretly monitors the user's behavior,
the functions of spyware extend well beyond simple monitoring.

Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.

Spyware can even change computer settings, resulting in slow connection speeds,
different home pages, and loss of Internet or other programs.
In an attempt to increase the understanding of spyware, a more formal classification
of its included software types is captured under the term privacy-invasive software.


180Solutions.Zango Symptoms:

Files:
[%DESKTOP%]\Viruz\npclntax.dll
[%PROFILE_TEMP%]\1801FC.mht
[%PROFILE_TEMP%]\18035E.mht
[%PROFILE_TEMP%]\1804.mht
[%PROFILE_TEMP%]\180520.mht
[%PROFILE_TEMP%]\18055D.mht
[%PROFILE_TEMP%]\180B.mht
[%PROFILE_TEMP%]\180E.mht
[%PROFILE_TEMP%]\temp.fr????\zanuhook.dll
[%PROFILE_TEMP%]\Upgrade.exe
[%PROFILE_TEMP%]\ZangoTBInstaller.exe
[%PROGRAM_FILES%]\Mozilla Firefox\plugins\npclntax.dll
[%PROFILE_TEMP%]\ToolbarUpgrade.exe
[%PROFILE_TEMP%]\ZangoClient.exe
[%DESKTOP%]\Viruz\npclntax.dll
[%PROFILE_TEMP%]\1801FC.mht
[%PROFILE_TEMP%]\18035E.mht
[%PROFILE_TEMP%]\1804.mht
[%PROFILE_TEMP%]\180520.mht
[%PROFILE_TEMP%]\18055D.mht
[%PROFILE_TEMP%]\180B.mht
[%PROFILE_TEMP%]\180E.mht
[%PROFILE_TEMP%]\temp.fr????\zanuhook.dll
[%PROFILE_TEMP%]\Upgrade.exe
[%PROFILE_TEMP%]\ZangoTBInstaller.exe
[%PROGRAM_FILES%]\Mozilla Firefox\plugins\npclntax.dll
[%PROFILE_TEMP%]\ToolbarUpgrade.exe
[%PROFILE_TEMP%]\ZangoClient.exe

Folders:
[%COMMON_PROGRAMS%]\Zango
[%PROGRAM_FILES%]\zango
[%PROGRAM_FILES%]\zango programs
[%PROGRAM_FILES%]\zangoclient
[%PROGRAMS%]\zango
[%PROGRAMS%]\zango programs

Registry Keys:
HKEY_CLASSES_ROOT\appid\zangotoolbar.dll
HKEY_CLASSES_ROOT\appid\{d28cd14c-50be-4cfa-951e-b37f25da3472}
HKEY_CLASSES_ROOT\appid\{f1f040d5-e8f8-4680-b101-9334e9773841}
HKEY_CLASSES_ROOT\clientax.zangoclientax
HKEY_CLASSES_ROOT\clientax.zangoclientax.1
HKEY_CLASSES_ROOT\clsid\{144b9c7e-235a-4316-9eb3-5e393714c77a}
HKEY_CLASSES_ROOT\clsid\{51cf80dc-a309-4735-bb11-ef18bf4e3ad9}
HKEY_CLASSES_ROOT\CLSID\{56F1D444-11BF-4879-A12B-79CF0177F038}
HKEY_CLASSES_ROOT\clsid\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}
HKEY_CLASSES_ROOT\CLSID\{EA0D26BD-9029-431A-86E0-83152D67828A}
HKEY_CLASSES_ROOT\interface\{031cbf6a-c70e-4177-a0d4-c5268ee311fb}
HKEY_CLASSES_ROOT\interface\{dd469a88-316c-441d-b712-783d9b9a6707}
HKEY_CLASSES_ROOT\typelib\{01bf19c2-59d3-43e9-a2cc-c2d62d8878d3}
HKEY_CLASSES_ROOT\typelib\{91e523db-2a1c-4231-bb06-9be27c28739a}
HKEY_CLASSES_ROOT\typelib\{981bda1d-c8ad-46ff-be2c-fddd859ac6f5}
HKEY_CURRENT_USER\software\zango
HKEY_CURRENT_USER\software\zanu
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FCDF9D9-A28B-480F-8C3D-581F119A8AB8}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\zango
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56F1D444-11BF-4879-A12B-79CF0177F038}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\zango
HKEY_LOCAL_MACHINE\software\zango
HKEY_LOCAL_MACHINE\software\zanu
HKEY_CLASSES_ROOT\clsid\{391b0aa4-1e17-485f-b635-0fe26219e87e}
HKEY_CLASSES_ROOT\clsid\{56f1d444-11bf-4879-a12b-79cf0177f038}
HKEY_CLASSES_ROOT\clsid\{ea0d26bd-9029-431a-86e0-83152d67828a}
HKEY_CLASSES_ROOT\interface\{d5175f49-39e5-4af1-ba98-e2234869276d}
HKEY_CLASSES_ROOT\typelib\{15ea8944-438e-471e-860d-6743d4383a37}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{56f1d444-11bf-4879-a12b-79cf0177f038}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\zanu
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{c1b52e99-7ee0-4217-a072-e4742850e517}

Registry Values:
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\folders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\gimmysmileys
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\gimmysmileys\favorites\1
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\folders
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove TrojanClicker.Win32.NetBuie Trojan
TrojanDownloader.aaa00000DLL Downloader Removal
2nd.Thought Trojan Cleaner
Applet.ActiveXComponent Trojan Removal instruction
HLLP.6248!Dropper Trojan Information

Mdrop.BLR Trojan

How To Remove Mdrop.BLR?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Mdrop.BLR is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Trojans-downloaders downloads and installs new malware or adware on the computer.



Mdrop.BLR Symptoms:

Files:
[%PROGRAM_FILES_COMMON%]\{204EF476-0A21-1033-1003-030313200001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{8C01E9C8-04B2-1033-1128-010713200001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{C40346B1-0AEF-1033-0827-040715200001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{C40346B1-0AF0-1033-0827-040715200001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{CC4709E3-067E-1033-0814-0314030001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{F4A223A7-08DA-1033-0626-020409020001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{204EF476-0A21-1033-1003-030313200001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{8C01E9C8-04B2-1033-1128-010713200001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{C40346B1-0AEF-1033-0827-040715200001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{C40346B1-0AF0-1033-0827-040715200001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{CC4709E3-067E-1033-0814-0314030001}\Update.exe
[%PROGRAM_FILES_COMMON%]\{F4A223A7-08DA-1033-0626-020409020001}\Update.exe

Folders:
[%PROGRAM_FILES_COMMON%]\{204EF476-0A21-1033-1003-030313200001}
[%PROGRAM_FILES_COMMON%]\{8C01E9C8-04B2-1033-1128-010713200001}
[%PROGRAM_FILES_COMMON%]\{C40346B1-0AEF-1033-0827-040715200001}
[%PROGRAM_FILES_COMMON%]\{C40346B1-0AF0-1033-0827-040715200001}
[%PROGRAM_FILES_COMMON%]\{CC4709E3-067E-1033-0814-0314030001}
[%PROGRAM_FILES_COMMON%]\{F4A223A7-08DA-1033-0626-020409020001}

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Free.Keylogger Spyware Removal instruction
Ehg.sonyesolutions.hitbox Tracking Cookie Cleaner
STIEBar Adware Symptoms
Removing SillyDl.DJW Trojan
Connob Trojan Symptoms

H2000 Spyware

How To Remove H2000?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
H2000 is dangerous virus:
Spyware is computer software that is installed surreptitiously on a personal computer
to with the computer, without the user's informed consent.
Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.
They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,
and swap mouse buttons. However, they can be quite hard to remove.


H2000 Symptoms:

Files:
[%SYSTEM%]\win32vxd.exe
[%SYSTEM%]\win32vxd.exe


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
2nd.Thought Trojan Removal instruction
DLL Backdoor Removal

Wantvi Trojan

How To Remove Wantvi?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Wantvi is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.


Wantvi It also known as:

[Kaspersky]Trojan.Win32.Qhost.of,Hoax.Win32.Renos.jg,Trojan.Win32.Qhost.pq,Trojan.Win32.Qhost.qb,Backdoor.Win32.Small.cls,Hoax.Win32.Renos.vj;
[McAfee]FakeAlert-B,New Malware.bc;
[F-Prot]W32/Fathom.3-based!Maximus;
[Other]Win32/Wantvi.M,Mal/EncPk-AV,Win32/Wantvi.U,Trojan.KillAV,Trojan:Win32/SystemHijack.gen,Mal/HckPk-A,Program:Win32/FakeAlert.G,Win32/Wantvi.W,WORM_NUCRP.GEN,Win32/Wantvi.V,Win32/Wantvi.AD,Win32/Wantvi.AC,Win32/Wantvi.AG,Win32/Wantvi.AR,Trojan:Win32/Wantvi.A!dll,W32/Smalldoor.AUHS

Wantvi Symptoms:

Files:
[%COMMON_STARTUP%]\autos.exe
[%STARTUP%]\infos.exe
[%SYSTEM%]\proper.exe
[%SYSTEM%]\winter.exe
[%COMMON_STARTUP%]\autos.exe
[%STARTUP%]\infos.exe
[%SYSTEM%]\proper.exe
[%SYSTEM%]\winter.exe

Registry Keys:
HKEY_CLASSES_ROOT\appid\{d27987b8-7244-4de0-ae10-39b826b492f1}
HKEY_CLASSES_ROOT\clsid\{d27987b8-7244-4de0-ae10-39b826b492f1}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d27987b8-7244-4de0-ae10-39b826b492f1}

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Yeam Trojan Removal
W95.Leviathan Trojan Information
Pigeon.EPI Trojan Symptoms
Remove HidePE Trojan

IRC.Flood.bc Worm

How To Remove IRC.Flood.bc?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
IRC.Flood.bc is dangerous virus:
Worms can be classified by installation method, launch method and finally according
to characteristics standard to all malware: polymorphism, stealth etc.

Many of the worms which managed to cause significant outbreaks use more then
one propagation method as well as more than one infection technique.

Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
They function in the same way as legal remote administration programs used by system administrators.
This makes them difficult to detect.

Backdoors are installed and launched without the consent of the user of computer.
Often the backdoor will not be visible in the log of active programs.

Once a backdoor has been successfully launched, the computer is wide open.
Backdoor functions can include:


  • Launching/ deleting files

  • Sending/ receiving files

  • Deleting data

  • Displaying notification

  • Rebooting the machine

  • Executing files




Backdoors are used by virus writers to detect and download confidential information,
execute malicious code, destroy data, include the machine in bot networks and so forth.
Backdoors combine the functionality of most other types of in one package.

Backdoors have one especially dangerous sub-class: variants that can propagate like worms.
DoS trojans conduct attacks from a single computer with the consent of the user.


IRC.Flood.bc It also known as:

[Panda]Application/SlimFTP.C,Bck/Dobea,Bck/IRCFlood.N,Bck/Zcrew.B,mIRC/Winhelp,W32/Tzet.B.worm,Worm Generic.LC;
[Computer Associates]Backdoor/IRC.Flood.bc,Backdoor/IRC.Flood.F,Backdoor/IRCFlood.C,mIRC/Flood.D,Pirch/Sub7.Acnu!Trojan

IRC.Flood.bc Symptoms:

Files:
[%SYSTEM%]\aliases.ini
[%SYSTEM%]\control.ini
[%SYSTEM%]\crtdll.svc
[%SYSTEM%]\fpx.ini
[%SYSTEM%]\include\dmb.txt
[%SYSTEM%]\include\fullname.txt
[%SYSTEM%]\kasbeer.exe
[%SYSTEM%]\kasber.exe
[%SYSTEM%]\mirc.ico
[%SYSTEM%]\mirc.ini
[%SYSTEM%]\MWWW\a
[%SYSTEM%]\MWWW\f
[%SYSTEM%]\MWWW\scans
[%SYSTEM%]\MWWW\test
[%SYSTEM%]\nicks.txt
[%SYSTEM%]\perform.ini
[%SYSTEM%]\remote.ini
[%SYSTEM%]\script.ini
[%SYSTEM%]\servers.ini
[%SYSTEM%]\sup.reg
[%SYSTEM%]\System Drive\kasber.exe
[%SYSTEM%]\System Drive\m1RC.exe
[%SYSTEM%]\users.ini
[%SYSTEM%]\xt34mxxx
[%SYSTEM%]\sup.bat
[%SYSTEM%]\aliases.ini
[%SYSTEM%]\control.ini
[%SYSTEM%]\crtdll.svc
[%SYSTEM%]\fpx.ini
[%SYSTEM%]\include\dmb.txt
[%SYSTEM%]\include\fullname.txt
[%SYSTEM%]\kasbeer.exe
[%SYSTEM%]\kasber.exe
[%SYSTEM%]\mirc.ico
[%SYSTEM%]\mirc.ini
[%SYSTEM%]\MWWW\a
[%SYSTEM%]\MWWW\f
[%SYSTEM%]\MWWW\scans
[%SYSTEM%]\MWWW\test
[%SYSTEM%]\nicks.txt
[%SYSTEM%]\perform.ini
[%SYSTEM%]\remote.ini
[%SYSTEM%]\script.ini
[%SYSTEM%]\servers.ini
[%SYSTEM%]\sup.reg
[%SYSTEM%]\System Drive\kasber.exe
[%SYSTEM%]\System Drive\m1RC.exe
[%SYSTEM%]\users.ini
[%SYSTEM%]\xt34mxxx
[%SYSTEM%]\sup.bat

Folders:
[%SYSTEM%]\lavan
[%SYSTEM%]\system securety

Registry Keys:
HKEY_CLASSES_ROOT\apd
HKEY_CURRENT_USER\software\obcd
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\obcd

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows
HKEY_CURRENT_USER\software\winrar sfx
HKEY_LOCAL_MACHINE\software\microsoft\windowsd\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\mirc


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Liberty.SSSS Trojan Symptoms
Zrk Trojan Cleaner
Removing TrojanDownloader.aaa00000DLL Downloader
NHVMP Trojan Information

Nanpy.A Worm

How To Remove Nanpy.A?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Nanpy.A is dangerous virus:
Many of the worms which managed to cause significant outbreaks use more then
one propagation method as well as more than one infection technique.



Nanpy.A Symptoms:

Files:
[%SYSTEM%]\mmsvc32.exe
[%SYSTEM%]\mmsvc32.exe

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
SpotOn.Browser.plugin BHO Information
Removing PWS.AC.cfg Trojan
Bancos.HNC Trojan Removal

AdClicker.Oddbot Adware

How To Remove AdClicker.Oddbot?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
AdClicker.Oddbot is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.



AdClicker.Oddbot Symptoms:

Files:
[%SYSTEM%]\CCFDV.DLL
[%SYSTEM%]\nodeipproc.dll
[%SYSTEM%]\CCFDV.DLL
[%SYSTEM%]\nodeipproc.dll

Registry Keys:
HKEY_CLASSES_ROOT\interface\{251df512-6faf-4aaf-bf19-d99b5f1c9250}
HKEY_CLASSES_ROOT\clsid\{2b896072-f6e3-4ff7-ade6-43d5bec6557c}
HKEY_CLASSES_ROOT\oddbot.adclicker
HKEY_CLASSES_ROOT\oddbot.adclicker.1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2b896072-f6e3-4ff7-ade6-43d5bec6557c}

Registry Values:
HKEY_LOCAL_MACHINE\software\nodeipproc
HKEY_LOCAL_MACHINE\software\nodeipproc
HKEY_LOCAL_MACHINE\software\nodeipproc


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
XConsole.beta Trojan Removal
Computer.Monitor.KeyLogger Spyware Cleaner
Zlob.yt Downloader Removal

ADSPY Trojan

How To Remove ADSPY?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
ADSPY is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.

ADSPY Symptoms:

Files:
[%PROFILE_TEMP%]\PolicyExplore.exe
[%WINDOWS%]\iedrives.dll
[%WINDOWS%]\iedrives.dll
[%WINDOWS%]\iexploree.dll
[%WINDOWS%]\Policies.dll
[%WINDOWS%]\Policies.dll
[%WINDOWS%]\tlhelper.dll
[%PROFILE_TEMP%]\PolicyExplore.exe
[%WINDOWS%]\iedrives.dll
[%WINDOWS%]\iedrives.dll
[%WINDOWS%]\iexploree.dll
[%WINDOWS%]\Policies.dll
[%WINDOWS%]\Policies.dll
[%WINDOWS%]\tlhelper.dll

Registry Keys:
HKEY_CLASSES_ROOT\CLSID\{27A7FB75-FB40-4F94-BCF6-4945BCC8BAAF}
HKEY_CLASSES_ROOT\CLSID\{366B2151-E1C7-44a3-86A3-E5686C2A3D2F}
HKEY_CLASSES_ROOT\CLSID\{A5845A98-EBDA-4670-9DE6-5201C506E741}
HKEY_CLASSES_ROOT\CLSID\{A646CE7E-951E-44D1-B93C-F7136DA41E58}
HKEY_CLASSES_ROOT\CLSID\{A717DBE3-D78D-4AA7-BDCF-2CC06B36371B}
HKEY_CLASSES_ROOT\CLSID\{A717DBE3-D78D-4AA7-BDCF-2CC06B36371B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27A7FB75-FB40-4F94-BCF6-4945BCC8BAAF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{366B2151-E1C7-44a3-86A3-E5686C2A3D2F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5845A98-EBDA-4670-9DE6-5201C506E741}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A646CE7E-951E-44D1-B93C-F7136DA41E58}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A717DBE3-D78D-4AA7-BDCF-2CC06B36371B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A717DBE3-D78D-4AA7-BDCF-2CC06B36371B}

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Torafacire Trojan Removal instruction
Pigeon.EQB Trojan Removal
JS.Teeodl Hostile Code Cleaner
mcgaming.com Tracking Cookie Cleaner
Win32.Camking Trojan Symptoms

HuntBar.Stoolbar BHO

How To Remove HuntBar.Stoolbar?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
HuntBar.Stoolbar is dangerous virus:
The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
Hijackers take control of various parts of your web browser, including your home page,
search pages, and search bar. They may also redirect you to certain sites should you
mistype an address or prevent you from going to a website they would rather you not,
such as sites that combat malware. Some will even redirect you to their own search engine
when you attempt a search.
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.


HuntBar.Stoolbar Symptoms:

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{0a5cf411-f0bf-4af8-a2a4-8233f3109bed}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{0a5cf411-f0bf-4af8-a2a4-8233f3109bed}
HKEY_LOCAL_MACHINE\software\classes\clsid\{0a5cf411-f0bf-4af8-a2a4-8233f3109bed}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0a5cf411-f0bf-4af8-a2a4-8233f3109bed}


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Fiu Trojan Removal instruction
Remove SillyDl.BCE Trojan

FastVideoPlayer Adware

How To Remove FastVideoPlayer?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
FastVideoPlayer is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


FastVideoPlayer It also known as:

[Kaspersky]Trojan-Downloader.Win32.Agent.oc;
[Other]Dialer.Adultchat

FastVideoPlayer Symptoms:

Files:
[%SYSTEM%]\fvp.dll
[%SYSTEM%]\fvp.dll

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{b5dd9a64-5c4b-4a48-be56-97c1a8f85708}
HKEY_CLASSES_ROOT\fastvideoplayerlite.fastvideoplayerlitectrl
HKEY_CLASSES_ROOT\fastvideoplayerlite.fastvideoplayerlitectrl.1
HKEY_CLASSES_ROOT\interface\{9ff86c1b-7e6f-4a7f-932a-244fe7296dae}
HKEY_CLASSES_ROOT\interface\{ee7e970d-3d17-4645-8660-d7f40b917092}
HKEY_CLASSES_ROOT\typelib\{022850cb-74fd-486d-8b1c-573ecfd599ad}


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Funked Trojan Removal

MRA Spyware

How To Remove MRA?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
MRA is dangerous virus:
Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.
Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.



MRA Symptoms:

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
RBackdoor.NTRootKit.044K RAT Cleaner
Remove LinkGrabber Adware

Awnent Trojan

How To Remove Awnent?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Awnent is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.


Awnent It also known as:

[Other]Win32/Awnent.A

Awnent Symptoms:

Files:
[%SYSTEM%]\tarkmgr.exe
[%WINDOWS%]\IE\winB.exe
[%SYSTEM%]\tarkmgr.exe
[%WINDOWS%]\IE\winB.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Gosock Trojan Removal

Diamini Trojan

How To Remove Diamini?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Diamini is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.



Diamini It also known as:

[Kaspersky]Trojan.Win32.Diamin,Trojan.Win32.Diamin.ag,Trojan.Win32.Diamin.l;
[Other]Win32/Diamini,Win32/Diamini.B,Dialer.Trafficadvance

Diamini Symptoms:

Files:
[%DESKTOP%]\Passepartout.lnk
[%PROGRAMS%]\FASTTRACK\Passepartout Disinstalla.lnk
[%PROGRAMS%]\FASTTRACK\Passepartout.lnk
[%DESKTOP%]\Passepartout.lnk
[%PROGRAMS%]\FASTTRACK\Passepartout Disinstalla.lnk
[%PROGRAMS%]\FASTTRACK\Passepartout.lnk

Registry Values:
HKEY_CURRENT_USER\software\fasttrack
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing Dluca.gen Downloader

PopUp.Network Hijacker

How To Remove PopUp.Network?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
PopUp.Network is dangerous virus:
A desktop hijacker replaces the desktop wallpaper with advertising
for products and services on the desktop.


PopUp.Network Symptoms:

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{d0b0c04a-dc73-4a91-9307-41f3e36579bf}


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
XSRemover Trojan Removal instruction
Win32.MindControl Trojan Information

Dynamic.Desktop.Media Trojan

How To Remove Dynamic.Desktop.Media?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Dynamic.Desktop.Media is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.

BHO (Browser Helper Object) Trojan.
The BHO waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
The method of network transport used by the attacker makes this Trojan unique.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.
Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into
the data section of an ICMP ping packet." explained the company.
Trojans-downloaders downloads and installs new malware or adware on the computer.



Dynamic.Desktop.Media It also known as:

[Panda]Trojan Horse

Dynamic.Desktop.Media Symptoms:

Files:
[%SYSTEM%]\ddmp.dll
[%SYSTEM%]\redirect.dll
[%WINDOWS%]\system\ddmp.dll
[%WINDOWS%]\system\redirect.dll
[%SYSTEM%]\ddmp.dll
[%SYSTEM%]\redirect.dll
[%WINDOWS%]\system\ddmp.dll
[%WINDOWS%]\system\redirect.dll

Folders:
[%PROGRAM_FILES%]\ddm

Registry Keys:
HKEY_LOCAL_MACHINE\software\ddm
HKEY_CLASSES_ROOT\clsid\{2bc43670-c0bd-4794-bb11-f60f3e001dc5}
HKEY_CLASSES_ROOT\clsid\{9819c369-5f62-4d37-9a42-44043a742c1e}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{2bc43670-c0bd-4794-bb11-f60f3e001dc5}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{9819c369-5f62-4d37-9a42-44043a742c1e}
HKEY_LOCAL_MACHINE\software\classes\clsid\{2bc43670-c0bd-4794-bb11-f60f3e001dc5}
HKEY_LOCAL_MACHINE\software\classes\clsid\{9819c369-5f62-4d37-9a42-44043a742c1e}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2bc43670-c0bd-4794-bb11-f60f3e001dc5}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9819c369-5f62-4d37-9a42-44043a742c1e}


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove adtools Adware
idregie.com Tracking Cookie Symptoms
Remove SillyDl.CAH Trojan

DIEssgol Trojan

How To Remove DIEssgol?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
DIEssgol is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.


DIEssgol It also known as:

[Kaspersky]Trojan-Dropper.Win32.Agent.asq;
[McAfee]PWS-Goldun.dldr;
[Other]Win32/DIEssgol.B,Trojan.Goldun

DIEssgol Symptoms:

Files:
[%SYSTEM%]\msvoid.dll
[%SYSTEM%]\msvoid.dll

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{78934132-3451-67a2-8919-678931572311}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{78934132-3451-67a2-8919-678931572311}


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Dowque.ABK Trojan Information
Removing mystat.in.net Tracking Cookie
Removing Pigeon.EOE Trojan

Pigeon.DSH Trojan

How To Remove Pigeon.DSH?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Pigeon.DSH is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.


Pigeon.DSH It also known as:

[Other]Backdoor.Graybird

Pigeon.DSH Symptoms:

Files:
[%SYSTEM%]\csrssar
[%SYSTEM%]\csrssar

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_remate_run_rpc_(asp)
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\remate run rpc (asp)


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
SillyDl.DHN Trojan Cleaner
Anti.Netbus Trojan Removal instruction
Pigeon.AVSS Trojan Removal
Zlob.Fam.SoftCodec Trojan Cleaner

StartPage.Sphtml.Troja Trojan

How To Remove StartPage.Sphtml.Troja?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
StartPage.Sphtml.Troja is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
The downloader either launches the new malware or registers it to enable autorun
according to the local operating system requirements.


StartPage.Sphtml.Troja Symptoms:

Files:
[%SYSTEM%]\appfd.dll
[%SYSTEM%]\appfd.dll


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing AIM.Rip Trojan
Remove BearShare Worm
Zvel4449 Trojan Information
Deckhog Trojan Cleaner
Pigeon.AWJS Trojan Symptoms

AdRoad.Cpr Adware

How To Remove AdRoad.Cpr?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
AdRoad.Cpr is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.

AdRoad.Cpr Symptoms:

Files:
[%WINDOWS%]\cpr.exe
[%WINDOWS%]\cpr.exe

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-c0ff-fd7ba7d5fa7d}
HKEY_CLASSES_ROOT\swbar.swbar
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4e7bd74f-2b8d-469e-c0ff-fd7ba7d5fa7d}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\cpr
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\cpr
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/swbar.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/swbar.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
valuead.com Tracking Cookie Cleaner
Removing Kryptonic.Ghost.Command Trojan
Lineage.AAW Trojan Information

Banker.CNX Trojan

How To Remove Banker.CNX?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Banker.CNX is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.


Banker.CNX It also known as:

[Kaspersky]Trojan-Spy.Win32.Banker.cnx;
[F-Prot]W32/Banker.AHRF;
[Other]Infostealer.Bancos,W32/Banker.BOEE

Banker.CNX Symptoms:

Files:
[%SYSTEM%]\crim.dll
[%SYSTEM%]\helper.sys
[%SYSTEM%]\rem.dll
[%SYSTEM%]\torm.dll
[%SYSTEM%]\crim.dll
[%SYSTEM%]\helper.sys
[%SYSTEM%]\rem.dll
[%SYSTEM%]\torm.dll

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{0df9b1ba-08de-4718-af73-63cffaf5ea36}
HKEY_CLASSES_ROOT\clsid\{5142fe17-20e6-4121-a925-a4c6385cddaa}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0df9b1ba-08de-4718-af73-63cffaf5ea36}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5142fe17-20e6-4121-a925-a4c6385cddaa}

Registry Values:
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper
HKEY_LOCAL_MACHINE\software\helper


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
SpyArsenal.Print.Monitor Spyware Cleaner

DelAutorun Trojan

How To Remove DelAutorun?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
DelAutorun is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.


DelAutorun Symptoms:

Files:
[%WINDOWS%]\DelAutorun.bat
[%WINDOWS%]\DelAutorun.ini
[%WINDOWS%]\DelAutorun.bat
[%WINDOWS%]\DelAutorun.ini

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Tatfo Trojan Removal instruction

DDY Trojan

How To Remove DDY?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
DDY is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
The downloader either launches the new malware or registers it to enable autorun
according to the local operating system requirements.
Hacker Tools are designed to penetrate remote computers
in order to use them as zombies or to download other malicious programs to computer.


DDY It also known as:

[Kaspersky]Trojan-Downloader.Win32.Small.ddy;
[F-Prot]W32/Downloader.AYPN

DDY Symptoms:

Files:
[%SYSTEM%]\avgbqnct.exe
[%SYSTEM%]\hapeludi.exe
[%SYSTEM%]\avgbqnct.exe
[%SYSTEM%]\hapeludi.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Zdown Downloader Removal
Cabdrop Trojan Cleaner
NaughtyPops Adware Removal
Pigeon.FBI Trojan Removal
Remove BlackFrost.Booter DoS

Whazit BHO

How To Remove Whazit?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Whazit is dangerous virus:
The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
Hijackers take control of various parts of your web browser, including your home page,
search pages, and search bar. They may also redirect you to certain sites should you
mistype an address or prevent you from going to a website they would rather you not,
such as sites that combat malware. Some will even redirect you to their own search engine
when you attempt a search.
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.


Whazit Symptoms:

Files:
[%WINDOWS%]\downloaded program files\downloader.inf
[%WINDOWS%]\kyf.dat
[%SYSTEM%]\newones.dll
[%SYSTEM%]\outones.dll
[%SYSTEM%]\whattn.dll
[%SYSTEM%]\whattt.dll
[%WINDOWS%]\cards.ico
[%WINDOWS%]\downloaded program files\download_ul.inf
[%WINDOWS%]\newones.dll
[%WINDOWS%]\system\newones.dll
[%WINDOWS%]\system\outones.dll
[%WINDOWS%]\system\whattn.dll
[%WINDOWS%]\system\whattt.dll
[%WINDOWS%]\wanobsi.exe
[%WINDOWS%]\whattn.dll
[%WINDOWS%]\whattt.dll
[%WINDOWS%]\downloaded program files\downloader.inf
[%WINDOWS%]\kyf.dat
[%SYSTEM%]\newones.dll
[%SYSTEM%]\outones.dll
[%SYSTEM%]\whattn.dll
[%SYSTEM%]\whattt.dll
[%WINDOWS%]\cards.ico
[%WINDOWS%]\downloaded program files\download_ul.inf
[%WINDOWS%]\newones.dll
[%WINDOWS%]\system\newones.dll
[%WINDOWS%]\system\outones.dll
[%WINDOWS%]\system\whattn.dll
[%WINDOWS%]\system\whattt.dll
[%WINDOWS%]\wanobsi.exe
[%WINDOWS%]\whattn.dll
[%WINDOWS%]\whattt.dll

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{dcf0768d-ba7a-101a-b57a-0000c0c3ed5f}
HKEY_CLASSES_ROOT\clsid\{10955232-b671-11d7-8066-0040f6f477e4}
HKEY_CLASSES_ROOT\clsid\{267d5bd3-0dc2-4724-a196-7f4794fbb9eb}
HKEY_CLASSES_ROOT\clsid\{66f67511-2665-4c34-9e20-fac2c0954ef2}
HKEY_CLASSES_ROOT\clsid\{c9176930-9c9f-4cba-9723-0f58c3e7ced6}
HKEY_CLASSES_ROOT\clsid\{d5b72aed-e54a-11d6-b1b2-444553540000}
HKEY_CLASSES_ROOT\clsid\{d7d7004c-a763-4f8c-b0d4-55a7e017e69d}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{10955232-b671-11d7-8066-0040f6f477e4}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{267d5bd3-0dc2-4724-a196-7f4794fbb9eb}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{66f67511-2665-4c34-9e20-fac2c0954ef2}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{d5b72aed-e54a-11d6-b1b2-444553540000}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{d7d7004c-a763-4f8c-b0d4-55a7e017e69d}
HKEY_CLASSES_ROOT\typelib\{d130f0d2-bcfd-4b15-a5e7-415159ef4969}
HKEY_CLASSES_ROOT\wharederer.class1
HKEY_CURRENT_USER\software\whazit
HKEY_LOCAL_MACHINE\software\classes\clsid\{10955232-b671-11d7-8066-0040f6f477e4}
HKEY_LOCAL_MACHINE\software\classes\clsid\{267d5bd3-0dc2-4724-a196-7f4794fbb9eb}
HKEY_LOCAL_MACHINE\software\classes\clsid\{66f67511-2665-4c34-9e20-fac2c0954ef2}
HKEY_LOCAL_MACHINE\software\classes\clsid\{c9176930-9c9f-4cba-9723-0f58c3e7ced6}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d5b72aed-e54a-11d6-b1b2-444553540000}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d7d7004c-a763-4f8c-b0d4-55a7e017e69d}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{dcf0768d-ba7a-101a-b57a-0000c0c3ed5f}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{10955232-b671-11d7-8066-0040f6f477e4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{267d5bd3-0dc2-4724-a196-7f4794fbb9eb}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{66f67511-2665-4c34-9e20-fac2c0954ef2}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d5b72aed-e54a-11d6-b1b2-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d7d7004c-a763-4f8c-b0d4-55a7e017e69d}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\redwhazit
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\whazitwhazit toolbar
HKEY_LOCAL_MACHINE\software\wms

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Bancos.HNI Trojan Symptoms
Queso Trojan Removal instruction
Uniform Trojan Removal instruction
ActiveX Malware Malware Information

Small.nm Trojan

How To Remove Small.nm?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Small.nm is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.


Small.nm Symptoms:

Files:
[%SYSTEM%]\fwa.exe
[%SYSTEM%]\fwa.exe


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Sectemp Adware Removal
PSW.Lmir.bh Trojan Removal
Push Trojan Removal
Bancos.HHM Trojan Cleaner

SideStep Adware

How To Remove SideStep?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
SideStep is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.



SideStep Symptoms:

Files:
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\SbCIe02b.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\SbCIe02d.dll
[%WINDOWS%]\Downloaded Program Files\SbCIe028.dll
[%WINDOWS%]\Downloaded Program Files\SbCIe02a.dll
[%WINDOWS%]\Downloaded Program Files\SbCIe02b.dll
[%WINDOWS%]\Downloaded Program Files\SbCIe02d.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\SbCIe02b.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\SbCIe02d.dll
[%WINDOWS%]\Downloaded Program Files\SbCIe028.dll
[%WINDOWS%]\Downloaded Program Files\SbCIe02a.dll
[%WINDOWS%]\Downloaded Program Files\SbCIe02b.dll
[%WINDOWS%]\Downloaded Program Files\SbCIe02d.dll

Registry Keys:
HKEY_CLASSES_ROOT\CLSID\{D714A94F-123A-45CC-8F03-040BCAF82AD6}
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{3E230861-5C87-11D3-A1C6-00105A1B41B8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D714A94F-123A-45CC-8F03-040BCAF82AD6}


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Pigeon.AVP Trojan Information
Zlob Trojan Removal
Vdrw.Class.Reg.Key BHO Removal
Remove Pigeon.BEW Trojan
InCommand.7b2 Backdoor Removal

NetVisor Spyware

How To Remove NetVisor?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
NetVisor is dangerous virus:
Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.
These utilities are designed to penetrate remote computers
in order to use them as zombies (by using backdoors) or to download other malicious programs to computer.

Exploits use vulnerabilities in operating systems and applications to achieve the same result.


NetVisor It also known as:

[Kaspersky]Password protected

NetVisor Symptoms:

Files:
[%WINDOWS%]\mpapi.dll
[%WINDOWS%]\mpapi.dll


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
SillyDl.CKO Trojan Cleaner

Advanced.Computer.Monitor Spyware

How To Remove Advanced.Computer.Monitor?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Advanced.Computer.Monitor is dangerous virus:
Spyware is computer software that is installed surreptitiously on a personal computer
to intercept or take partial control over the user's interaction
with the computer, without the user's informed consent.

While the term spyware suggests software that secretly monitors the user's behavior,
the functions of spyware extend well beyond simple monitoring.

Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.

Spyware can even change computer settings, resulting in slow connection speeds,
different home pages, and loss of Internet or other programs.
In an attempt to increase the understanding of spyware, a more formal classification
of its included software types is captured under the term privacy-invasive software.


Advanced.Computer.Monitor Symptoms:

Files:
[%PROFILE_TEMP%]\Perflib_Perfdata_378.dat
[%PROFILE%]\Recent\AdvancedComputerMonitor.lnk
[%PROFILE%]\Recent\downloadlocation.txt.lnk
[%PROFILE_TEMP%]\Perflib_Perfdata_378.dat
[%PROFILE%]\Recent\AdvancedComputerMonitor.lnk
[%PROFILE%]\Recent\downloadlocation.txt.lnk

Folders:
[%PROGRAM_FILES%]\ACM
[%APPDATA%]\acm_pro
[%DESKTOP%]\AdvancedComputerMonitor
[%PROGRAMS%]\ACM

Registry Keys:
HKEY_CLASSES_ROOT\ccrptimers6.ccrpcountdown
HKEY_CLASSES_ROOT\ccrptimers6.ccrpstopwatch
HKEY_CLASSES_ROOT\ccrptimers6.ccrptimer
HKEY_CLASSES_ROOT\ccrptimers6.ccrptimerstats
HKEY_CLASSES_ROOT\ccrptimers6.iccrpcountdownnotify
HKEY_CLASSES_ROOT\ccrptimers6.iccrpcountdownnotifyex
HKEY_CLASSES_ROOT\ccrptimers6.iccrptimernotify
HKEY_CLASSES_ROOT\ccrptimers6.iccrptimernotifyex
HKEY_CLASSES_ROOT\clsid\{0c69356e-1275-4df8-9a67-6c0a6caafac8}
HKEY_CLASSES_ROOT\clsid\{2e675021-9b3b-49ca-a8d5-d1829f999808}
HKEY_CLASSES_ROOT\clsid\{98d28f39-6b87-4424-846d-a18e35c8ce1a}
HKEY_CLASSES_ROOT\clsid\{bbda50f9-4374-4697-b004-943d3cda4a6a}
HKEY_CLASSES_ROOT\interface\{2af0c41d-44ba-4dbc-83ff-effa10350b7e}
HKEY_CLASSES_ROOT\interface\{48d03ff6-6d19-4415-852e-c0b506239979}
HKEY_CLASSES_ROOT\interface\{629d9912-49ec-4623-bc26-49ec151e94f2}
HKEY_CLASSES_ROOT\interface\{66a6a2f6-5598-44d6-824e-ce8967617983}
HKEY_CLASSES_ROOT\interface\{6d63dd88-6b66-4f03-af75-48cae256547b}
HKEY_CLASSES_ROOT\interface\{871e1dcf-f823-4d33-b7e5-de6a67f8571b}
HKEY_CLASSES_ROOT\interface\{a3218b31-bda4-431f-b41a-82fa6af432c9}
HKEY_CLASSES_ROOT\interface\{c3034eb9-9ce5-46ac-9a4b-c3c15c81f163}
HKEY_CLASSES_ROOT\pdssmtplib.smtp
HKEY_CLASSES_ROOT\typelib\{19cd2397-d366-425f-ae02-07cff09aa02d}
HKEY_CLASSES_ROOT\typelib\{7560bf71-2ac0-4792-8b39-e4bf8f82dffc}
HKEY_CLASSES_ROOT\acmdll.serviceentry
HKEY_CLASSES_ROOT\clsid\{1ccf94e6-ba0c-4218-9280-d6339663dcf3}
HKEY_CLASSES_ROOT\interface\{4a50ce9d-456f-4c97-9872-f569816ed5bd}
HKEY_CLASSES_ROOT\typelib\{b48ef08a-d99c-4ab3-b873-968b2f4653ec}
HKEY_LOCAL_MACHINE\system\controlset001\services\acmservice
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\acmservice

Registry Values:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_acmservice\0000
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_acmservice\0000\control


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Bancos.FTZ Trojan Information
Gpix Trojan Removal instruction

UnSpyPC Trojan

How To Remove UnSpyPC?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
UnSpyPC is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
A cryptovirus, cryptotrojan or cryptoworm is a type of
malware that encrypts the data belonging to an individual on a computer,
demanding a ransom for its restoration.

The term ransomware is commonly used to describe such software,
although the field known as cryptovirology predates the term "ransomware".

This type of ransom attack can be accomplished by (for example) attaching
a specially crafted file/program to an e-mail message and sending this to the victim.

If the victim opens/executes the attachment, the program encrypts
a number of files on the victim's computer. A ransom note is then left behind for the victim.

The victim will be unable to open the encrypted files without the correct decryption key.
Once the ransom demanded in the ransom note is paid, the cracker may (or may not)
send the decryption key, enabling decryption of the "kidnapped" files.


UnSpyPC It also known as:

[McAfee]UnSpyPC;
[Other]KillAndClean,SafeandClean

UnSpyPC Symptoms:

Files:
[%DESKTOP%]\UnSpyPC Scanner & Monitor.lnk
[%SYSTEM%]\filesafer23.exe
[%SYSTEM%]\kilacln.exe
[%SYSTEM%]\{4E6CBA2C-D692-4DCD-AE1D-B96B0D705428}.exe
[%SYSTEM%]\{761A3A12-B18D-450C-A9A2-AE11214F075E}.exe
[%SYSTEM%]\{9B26E2B7-5703-4F8C-A280-0CD5E708BC13}.exe
[%SYSTEM%]\{BEF65F9A-121B-41E4-95F6-2DDDDFEA6DB5}.exe
[%PROGRAM_FILES%]\UnSpyPC\warez.dat
[%PROGRAM_FILES%]\UnSpyPC\wover.dat
[%DESKTOP%]\Kill & Clean Scanner and Monitor.lnk
[%DESKTOP%]\UnSpyPC Scanner & Monitor.lnk
[%PROGRAMS%]\UnSpyPC\Uninstall.lnk
[%PROGRAMS%]\UnSpyPC\UnSpyPC.lnk
[%DESKTOP%]\UnSpyPC Scanner & Monitor.lnk
[%SYSTEM%]\filesafer23.exe
[%SYSTEM%]\kilacln.exe
[%SYSTEM%]\{4E6CBA2C-D692-4DCD-AE1D-B96B0D705428}.exe
[%SYSTEM%]\{761A3A12-B18D-450C-A9A2-AE11214F075E}.exe
[%SYSTEM%]\{9B26E2B7-5703-4F8C-A280-0CD5E708BC13}.exe
[%SYSTEM%]\{BEF65F9A-121B-41E4-95F6-2DDDDFEA6DB5}.exe
[%PROGRAM_FILES%]\UnSpyPC\warez.dat
[%PROGRAM_FILES%]\UnSpyPC\wover.dat
[%DESKTOP%]\Kill & Clean Scanner and Monitor.lnk
[%DESKTOP%]\UnSpyPC Scanner & Monitor.lnk
[%PROGRAMS%]\UnSpyPC\Uninstall.lnk
[%PROGRAMS%]\UnSpyPC\UnSpyPC.lnk

Folders:
[%PROGRAM_FILES%]\KillAndClean
[%PROGRAM_FILES%]\UnSpyPC
[%PROGRAMS%]\KillAndClean

Registry Keys:
HKEY_CURRENT_USER\software\killandclean
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{BF69DF00-2734-477F-8257-27CD04F88779}
HKEY_CURRENT_USER\Software\UnSpyPC
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\unspypc
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{BF69DF00-4734-477F-8257-27CD04F88779}
HKEY_LOCAL_MACHINE\SOFTWARE\UnSpyPC
HKEY_CLASSES_ROOT\clsid\{b38e64af-3400-22ac-c701-cbf9a237575e}
HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\{bf69df00-2734-477f-8257-27cd04f88779}
HKEY_CURRENT_USER\software\unspypc
HKEY_LOCAL_MACHINE\software\killandclean
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\killandclean

Registry Values:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\unspypc


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing Bancos.HLD Trojan

FHZ Backdoor

How To Remove FHZ?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
FHZ is dangerous virus:
Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
Often the backdoor will not be visible in the log of active programs.


FHZ Symptoms:

Files:
[%DESKTOP%]\server.exe
[%DESKTOP%]\W32Backdoor-FHZ.exe
[%SYSTEM%]\lrhu.dll
[%SYSTEM%]\svvdll.com
[%SYSTEM%]\svvdll.dll
[%SYSTEM%]\svvdll.exe
[%DESKTOP%]\server.exe
[%DESKTOP%]\W32Backdoor-FHZ.exe
[%SYSTEM%]\lrhu.dll
[%SYSTEM%]\svvdll.com
[%SYSTEM%]\svvdll.dll
[%SYSTEM%]\svvdll.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{hkmlo03-ii-df45d-2fdfdg}


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing QQPlus Spyware

McqUpdater Adware

How To Remove McqUpdater?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
McqUpdater is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.



McqUpdater It also known as:

[Kaspersky]Trojan-Dropper.Win32.Agent.ath,Trojan-Dwonloader.Win32.Agent.apu;
[Other]Adware.PigSearch,win32/SillyDl.AWL

McqUpdater Symptoms:

Files:
[%WINDOWS%]\mcUpdate.exe
[%WINDOWS%]\mcUpdate.exe

Folders:
[%SYSTEM%]\drivers\mcq

Registry Keys:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\mcq

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Constructor.VBS.HPWG Trojan Information
Removing Pigeon.EPS Trojan
Tiniloz Trojan Removal instruction
Remove Pigeon.EUB Trojan

Adware.Regifast Adware

How To Remove Adware.Regifast?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Adware.Regifast is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


Adware.Regifast It also known as:

[McAfee]Adware.Regifast

Adware.Regifast Symptoms:

Files:
[%PROFILE_TEMP%]\stdrun3.exe
[%WINDOWS%]\Downloaded Program Files\RegiFastSI.ocx
[%PROFILE_TEMP%]\stdrun3.exe
[%WINDOWS%]\Downloaded Program Files\RegiFastSI.ocx

Folders:
[%PROGRAM_FILES%]\RegiFast

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{191978c5-f642-4ee6-b8fd-97a95c435e7d}
HKEY_CLASSES_ROOT\clsid\{c67a62c7-a68d-484c-9617-880c1f70d3f7}
HKEY_CLASSES_ROOT\interface\{b4b66483-e499-485e-b77b-000d31c1656f}
HKEY_CLASSES_ROOT\interface\{b7bee73a-84e0-4b4f-a5ed-0100f2590b05}
HKEY_CLASSES_ROOT\regifastobj.regifastobj
HKEY_CLASSES_ROOT\regifastobj.regifastobj.1
HKEY_CLASSES_ROOT\regifastsi.silentinstall
HKEY_CLASSES_ROOT\regifastsi.silentinstall.1
HKEY_CLASSES_ROOT\typelib\{af3db5f5-93aa-4f48-b4ae-0a28bc4270bf}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{191978c5-f642-4ee6-b8fd-97a95c435e7d}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c67a62c7-a68d-484c-9617-880c1f70d3f7}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]\downloaded program files\regifastsi.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\regifast
HKEY_LOCAL_MACHINE\software\regifast

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Tatfo Trojan Symptoms

Conspy Trojan

How To Remove Conspy?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Conspy is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.


Conspy It also known as:

[Panda]Trj/Conspy.A;
[Computer Associates]Win32/Conspy.e!Spy!Trojan

Conspy Symptoms:

Files:
[%WINDOWS%]\waol.exe
[%WINDOWS%]\waol.exe

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing Skype.Defender Trojan
ActMon Spyware Information
JS.SelfExecHtml Spyware Information
Spy.Recon Ransomware Removal
Remove AR Trojan