Monday, January 26, 2009

Web.Buying Adware

How To Remove Web.Buying?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Web.Buying is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


Web.Buying It also known as:

[Kaspersky]AdWare.Win32.Agent.co;
[McAfee]Adware-WebBuying;
[F-Prot]W32/Trojan.AQIP;
[Other]Adware.Webbuy,W32/Malware.XAB

Web.Buying Symptoms:

Files:
[%PROFILE_TEMP%]\uf184.exe
[%PROGRAM_FILES%]\Web Buying\v1.8.0\webbuying.exe
[%SYSTEM%]\gawgvet.dll
[%SYSTEM%]\uyyyixi.dll
[%SYSTEM%]\fhyjmff.dll
[%SYSTEM%]\miciwqo.dll
[%PROFILE_TEMP%]\uf184.exe
[%PROGRAM_FILES%]\Web Buying\v1.8.0\webbuying.exe
[%SYSTEM%]\gawgvet.dll
[%SYSTEM%]\uyyyixi.dll
[%SYSTEM%]\fhyjmff.dll
[%SYSTEM%]\miciwqo.dll

Folders:
[%PROGRAM_FILES%]\Web Buying

Registry Keys:
HKEY_CURRENT_USER\software\webbuying
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\webbuying
HKEY_CLASSES_ROOT\clsid\{1128bc62-a090-448c-a6ee-87da4a67b352}
HKEY_CLASSES_ROOT\clsid\{11deda8c-6d8f-4e48-83a1-0090346343b3}
HKEY_CLASSES_ROOT\clsid\{148d6fbc-7401-4e01-b73a-bf6e0cafb687}
HKEY_CLASSES_ROOT\clsid\{4e84ad61-31d1-406f-8e90-2ab3521efc97}
HKEY_CLASSES_ROOT\clsid\{7386ad62-3ad1-4afa-813c-67d97c4d1403}
HKEY_CLASSES_ROOT\clsid\{8d8800a6-362e-435b-8715-faa40eb3dcfd}
HKEY_CLASSES_ROOT\clsid\{c926ba1c-8ba4-4140-903c-6e6e2db0ec24}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{1128bc62-a090-448c-a6ee-87da4a67b352}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{11deda8c-6d8f-4e48-83a1-0090346343b3}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{148d6fbc-7401-4e01-b73a-bf6e0cafb687}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4e84ad61-31d1-406f-8e90-2ab3521efc97}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{7386ad62-3ad1-4afa-813c-67d97c4d1403}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c926ba1c-8ba4-4140-903c-6e6e2db0ec24}

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CLASSES_ROOT\clsid\{0bab8b9c-713c-4d25-9f75-a1b464166d72}\inprocserver32
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Cakl Trojan Symptoms
BAT.Combat Trojan Symptoms
The.Flu Trojan Cleaner

No comments: