Tuesday, January 20, 2009

FlashTrack Adware

How To Remove FlashTrack?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
FlashTrack is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.

FlashTrack It also known as:

[Panda]Adware/FlashTrack;
[Other]Adware.Flashtrack

FlashTrack Symptoms:

Files:
[%WINDOWS%]\temp\r.exe
[%PROFILE_TEMP%]\8.exe\8.exe
[%SYSTEM%]\flcp.dll
[%SYSTEM%]\flt.dll
[%SYSTEM%]\ftapp.dll
[%WINDOWS%]\system\flcp.dll
[%WINDOWS%]\system\flt.dll
[%WINDOWS%]\system\ftapp.dll
[%WINDOWS%]\temp\r.exe
[%PROFILE_TEMP%]\8.exe\8.exe
[%SYSTEM%]\flcp.dll
[%SYSTEM%]\flt.dll
[%SYSTEM%]\ftapp.dll
[%WINDOWS%]\system\flcp.dll
[%WINDOWS%]\system\flt.dll
[%WINDOWS%]\system\ftapp.dll

Folders:
[%PROGRAM_FILES%]\flt
[%PROGRAM_FILES%]\ftk
[%PROGRAM_FILES%]\reg2
[%PROGRAM_FILES%]\xml
[%PROGRAM_FILES%]\xmod
[%PROGRAM_FILES%]\fla
[%PROGRAM_FILES%]\ftapp

Registry Keys:
HKEY_CLASSES_ROOT\interface\{6e83ae1c-f69c-4aed-af98-d23c24c6fa4b}
HKEY_CLASSES_ROOT\typelib\{7955ea20-e0d6-4a77-88b6-120674d979ea}
HKEY_LOCAL_MACHINE\software\classes\interface\{6e83ae1c-f69c-4aed-af98-d23c24c6fa4b}
HKEY_LOCAL_MACHINE\software\classes\typelib\{7955ea20-e0d6-4a77-88b6-120674d979ea}
HKEY_LOCAL_MACHINE\software\flt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{665ACD90-4541-4836-9FE4-062386BB8F05}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ftapp
HKEY_CLASSES_ROOT\bredobj.bredobj
HKEY_CLASSES_ROOT\bredobj.bredobj.1
HKEY_CLASSES_ROOT\clsid\{63cf97e8-4133-438a-a831-cc9c6d47d673}
HKEY_CLASSES_ROOT\clsid\{665acd90-4541-4836-9fe4-062386bb8f05}
HKEY_CLASSES_ROOT\clsid\{7371f073-ac0f-4b80-bb2f-96a488cefb32}
HKEY_CLASSES_ROOT\clsid\{7955ea20-e0d6-4a77-88b6-120674d979ea}
HKEY_CLASSES_ROOT\interface\{06542764-7bb2-412b-80d6-d103d1474c93}
HKEY_CLASSES_ROOT\interface\{baef4039-3c02-4c9e-a2f4-87b513ab0e87}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{63cf97e8-4133-438a-a831-cc9c6d47d673}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{665acd90-4541-4836-9fe4-062386bb8f05}
HKEY_CLASSES_ROOT\typelib\{db9f4c00-65e8-4fa1-917b-e4844ddf5909}
HKEY_CLASSES_ROOT\typelib\{e6c71e83-e02b-4bc4-958d-a9194916ec19}
HKEY_LOCAL_MACHINE\software\classes\clsid\{63cf97e8-4133-438a-a831-cc9c6d47d673}
HKEY_LOCAL_MACHINE\software\classes\clsid\{665acd90-4541-4836-9fe4-062386bb8f05}
HKEY_LOCAL_MACHINE\software\classes\clsid\{7371f073-ac0f-4b80-bb2f-96a488cefb32}
HKEY_LOCAL_MACHINE\software\classes\interface\{06542764-7bb2-412b-80d6-d103d1474c93}
HKEY_LOCAL_MACHINE\software\classes\interface\{baef4039-3c02-4c9e-a2f4-87b513ab0e87}
HKEY_LOCAL_MACHINE\software\classes\typelib\{db9f4c00-65e8-4fa1-917b-e4844ddf5909}
HKEY_LOCAL_MACHINE\software\classes\typelib\{e6c71e83-e02b-4bc4-958d-a9194916ec19}
HKEY_LOCAL_MACHINE\software\ftapp
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{63cf97e8-4133-438a-a831-cc9c6d47d673}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{665acd90-4541-4836-9fe4-062386bb8f05}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{7371f073-ac0f-4b80-bb2f-96a488cefb32}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d7e588ab-a5d9-4422-b313-22a3470f9700}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\flt
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\rvp
HKEY_LOCAL_MACHINE\software\persistent bytes
HKEY_LOCAL_MACHINE\software\rvp

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\reg2
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\reg2
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xmod
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xmod
HKEY_LOCAL_MACHINE\software\netfilter
HKEY_LOCAL_MACHINE\software\netfilter
HKEY_LOCAL_MACHINE\software\netfilter
HKEY_LOCAL_MACHINE\software\netfilter
HKEY_LOCAL_MACHINE\software\netfilter
HKEY_LOCAL_MACHINE\software\netfilter
HKEY_LOCAL_MACHINE\software\netfilter
HKEY_LOCAL_MACHINE\software\netfilter
HKEY_LOCAL_MACHINE\software\xml
HKEY_LOCAL_MACHINE\software\xml
HKEY_LOCAL_MACHINE\software\xml
HKEY_LOCAL_MACHINE\software\xml
HKEY_LOCAL_MACHINE\software\xml


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
BearShare Worm Removal instruction
suggestor Adware Information
Remove Ad.Logics Tracking Cookie

No comments: