Saturday, January 24, 2009

AntiOL Trojan

How To Remove AntiOL?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
AntiOL is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
Often the backdoor will not be visible in the log of active programs.
Exploits use vulnerabilities in operating systems and applications to achieve the same result.
DoS trojans conduct attacks from a single computer with the consent of the user.


AntiOL It also known as:

[Kaspersky]Nuker.Outlook.Robin;
[McAfee]DDoS-AntiOL;
[F-Prot]destructive program;
[Panda]Nuker/Outlook.Robin;
[Computer Associates]Win32.OutlookOverflow

AntiOL Symptoms:

Files:
[%PROGRAM_FILES%]\Save\SaveUninst.exe
[%PROGRAM_FILES%]\Save\SaveUninst.exe

Folders:
[%PROGRAMS%]\whenu
[%PROGRAM_FILES%]\save

Registry Keys:
HKEY_CLASSES_ROOT\wusn.1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\whenusavemsg
HKEY_LOCAL_MACHINE\software\whenusave

Registry Values:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Disk.Space Trojan Symptoms
Twerp Trojan Cleaner

CashBar Adware

How To Remove CashBar?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
CashBar is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
When the default home page is hijacked, the browser opens to the web page set by the hijacker
instead of the user's designated home page. In some cases, the hijacker may block users from
restoring their desired home page.


CashBar Symptoms:

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\main


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Win32.Brosser Trojan Symptoms

MultiBot.Pro Backdoor

How To Remove MultiBot.Pro?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
MultiBot.Pro is dangerous virus:
Backdoors combine the functionality of most other types of in one package.
Backdoors have one especially dangerous sub-class: variants that can propagate like worms.

Exploits use vulnerabilities in operating systems and applications to achieve the same result.


MultiBot.Pro It also known as:

[Kaspersky]Backdoor.DskLite.b;
[Panda]Backdoor Program.LC,Bck/Dsklite.A;
[Computer Associates]Backdoor/DskLite.10.A!Server,Bat/Dsklite!Trojan,Win32.DSKlite.10.A

MultiBot.Pro Symptoms:

Registry Keys:
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44bba855-cc51-11cf-bafa-00bb00b6017b}

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
BAT.DelSys Trojan Symptoms
Kodbot Trojan Removal

CIA Trojan

How To Remove CIA?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
CIA is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Spyware can even change computer settings, resulting in slow connection speeds,
different home pages, and loss of Internet or other programs.
In an attempt to increase the understanding of spyware, a more formal classification
of its included software types is captured under the term privacy-invasive software.
Backdoors combine the functionality of most other types of in one package.
Backdoors have one especially dangerous sub-class: variants that can propagate like worms.

Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.
Exploits use vulnerabilities in operating systems and applications to achieve the same result.


CIA It also known as:

[Kaspersky]Backdoor.Ciadoor.10.b,Backdoor.Ciadoor.11.a,Backdoor.Ciadoor.11.c,Backdoor.Ciadoor.11.b,Backdoor.Ciadoor.10.a,Backdoor.Ciadoor.121,Backdoor.Win32.Ciadoor.102,Backdoor.Win32.Ciadoor.12.a,Backdoor.Win32.Ciadoor.121,Backdoor.Win32.Ciadoor.a,Backdoor.Win32.Ciadoor.logger;
[Eset]Win32/Ciadoor.11.A trojan,Win32/Ciadoor.11.C trojan,Win32/Ciadoor.121.Logger trojan;
[McAfee]BackDoor-ASB;
[F-Prot]security risk or a "backdoor" program,security risk named W32/CYAdoor.A;
[Panda]Backdoor Program,Bck/Ciadoor,Backdoor Program.LC,Bck/Ciadoor.10,Bck/Ciadoor.B,Bck/Ciadoor.H,Constructor/Ciadoor.A,Trojan Horse;
[Computer Associates]Win32/Ciadoor!Backdoor!EditServe,Win32/Ciadoor.10.b!Backdoor!Serv,Win32.Ciadoor.11,Win32/Ciadoor.11!Backdoor!Server,Win32.Ciadoor.11.B,Win32/Ciadoor.11.B!Backdoor!Serv,Win32/Ciadoor.11.b!Backdoor!Serv,Win32.Ciadoor.1,Win32/Ciadoor.10!Backdoor!Server,PHP/Ciadoor!Trojan,Win32.Ciadoor.121.A,Win32.Ciadoor.121.A.plugin,Win32/Ciadoor.121.A!Backdoor!Ser,Win32/Ciadoor.121.A!Config

CIA Symptoms:

Files:
[%WINDOWS%]\system\okl.okl
[%WINDOWS%]\system\okl445.dat
[%WINDOWS%]\system\okl.okl
[%WINDOWS%]\system\okl445.dat

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove SatanCOM Trojan
Removing Bancos.GRJ Trojan
QuietEye Spyware Removal
Remove Rasaper Trojan

Jraun Trojan

How To Remove Jraun?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Jraun is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.

The downloader either launches the new malware or registers it to enable autorun
according to the local operating system requirements.


Jraun It also known as:

[Kaspersky]Trojan.Win32.KeyHost.c,TrojanDownloader.Win32.Small.ek;
[Panda]Trojan Horse

Jraun Symptoms:

Files:
[%SYSTEM%]\keyhost.htm
[%SYSTEM%]\keyhost.htm

Registry Keys:
HKEY_LOCAL_MACHINE\software\redirectkey

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\abouturls


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
SillyDl.CIG Trojan Information
W95.Sill.cav Trojan Cleaner
Removing AIMFatal Trojan
Remove PWThief RAT

CWS.Searchmeup Hijacker

How To Remove CWS.Searchmeup?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
CWS.Searchmeup is dangerous virus:
When the default home page is hijacked, the browser opens to the web page set by the hijacker
instead of the user's designated home page. In some cases, the hijacker may block users from
restoring their desired home page.


CWS.Searchmeup Symptoms:

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{0e1230f8-ea50-42a9-983c-d22abc2eed3b}
HKEY_CLASSES_ROOT\Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}
HKEY_CLASSES_ROOT\toolband.toolbandobj.1
HKEY_CURRENT_USER\software\toolband
HKEY_CLASSES_ROOT\clsid\{441354c5-911b-409b-9a66-a11d6d4e1a22}
HKEY_CLASSES_ROOT\interface\{95b92d92-8b7d-4a19-a3f1-43113b4dbcaf}
HKEY_CLASSES_ROOT\toolband.toolbandhelper
HKEY_CLASSES_ROOT\toolband.toolbandhelper.1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{441354c5-911b-409b-9a66-a11d6d4e1a22}

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remote.Hack.Remote.Administration.Tool Backdoor Information
Progent Trojan Removal instruction

SillyDl.AIA Trojan

How To Remove SillyDl.AIA?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
SillyDl.AIA is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.


SillyDl.AIA Symptoms:

Files:
[%PROFILE_TEMP%]\UNI215.tmp.exe
[%PROFILE_TEMP%]\UNI215.tmp.exe


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Win95 Trojan Removal
Removing Pigeon.AVSW Trojan
Removing Pigeon.EAE Trojan
Hellz.Addiction.10b Backdoor Information
Server Trojan Cleaner

LookThru.Cool.Search.Bar BHO

How To Remove LookThru.Cool.Search.Bar?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
LookThru.Cool.Search.Bar is dangerous virus:
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.


LookThru.Cool.Search.Bar Symptoms:

Files:
[%SYSTEM%]\coolbar.dll
[%WINDOWS%]\system\coolbar.dll
[%SYSTEM%]\coolbar.dll
[%WINDOWS%]\system\coolbar.dll

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{2af8ced6-5bd8-4310-a90c-9664efb16b10}
HKEY_CLASSES_ROOT\clsid\{a49aa76f-7215-4f80-97d6-9a7e16a5fee1}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{2af8ced6-5bd8-4310-a90c-9664efb16b10}
HKEY_LOCAL_MACHINE\software\classes\clsid\{2af8ced6-5bd8-4310-a90c-9664efb16b10}
HKEY_LOCAL_MACHINE\software\classes\clsid\{a49aa76f-7215-4f80-97d6-9a7e16a5fee1}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2af8ced6-5bd8-4310-a90c-9664efb16b10}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
CyberSpy.Keylogger Spyware Removal
Arr.Dev Trojan Information
Bancos.GXD Trojan Information
Pigeon.EYG Trojan Symptoms
Remove SillyDl.CCI Trojan

Corkye Trojan

How To Remove Corkye?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Corkye is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.


Corkye It also known as:

[Other]Win32/Corkye,Win32/Corkye.A

Corkye Symptoms:

Files:
[%SYSTEM%]\infusms.exe
[%SYSTEM%]\svcbs.sys
[%SYSTEM%]\svctcpip1.sys
[%SYSTEM%]\infusms.exe
[%SYSTEM%]\svcbs.sys
[%SYSTEM%]\svctcpip1.sys

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_remote_administration_service
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\remote administration service


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing Goldun Trojan
Remove Insecure.Executable Trojan
Remove Blah Trojan

Ezula Adware

How To Remove Ezula?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Ezula is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.

Hijackers take control of various parts of your web browser, including your home page,
search pages, and search bar. They may also redirect you to certain sites should you
mistype an address or prevent you from going to a website they would rather you not,
such as sites that combat malware. Some will even redirect you to their own search engine
when you attempt a search.
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.

Ezula It also known as:

[Panda]Adware/eZula,Adware/SearchExe,Dialer.US

Ezula Symptoms:

Files:
[%COMMON_FAVORITES%]\amazon.com.url
[%COMMON_FAVORITES%]\ebay.url
[%COMMON_FAVORITES%]\links\ebay.url
[%DESKTOP%]\amazon.com.url
[%DESKTOP%]\amazon.url
[%DESKTOP%]\ebay.url
[%FAVORITES%]\amazon.com.url
[%FAVORITES%]\amazon.url
[%FAVORITES%]\ebay.com.url
[%FAVORITES%]\ebay.url
[%FAVORITES%]\expedia.com.url
[%FAVORITES%]\links\amazon.com.url
[%FAVORITES%]\links\amazon.url
[%FAVORITES%]\links\ebay.com.url
[%FAVORITES%]\links\ebay.url
[%FAVORITES%]\links\expedia.url
[%INTERNET_CACHE%]\content.ie5\RYS371KD\upgrade[1].vrn
[%FAVORITES%]\links\amazon.com.url
[%PROFILE_TEMP%]\aupd.exe
[%PROFILE_TEMP%]\~nsu.tmp\Au_.exe
[%PROGRAM_FILES%]\sed\uninst.exe
[%PROGRAM_FILES%]\Web Offer\gendis.ez
[%PROGRAM_FILES%]\Web Offer\paramp.ez
[%PROGRAM_FILES%]\Web Offer\rwdsp.rst
[%SYSTEM%]\antispy.exe
[%SYSTEM%]\book.dll
[%SYSTEM%]\cdcore.dll
[%SYSTEM%]\cdrules.dll
[%SYSTEM%]\cdsync.dll
[%SYSTEM%]\ezpopstub.exe
[%SYSTEM%]\justin.exe
[%SYSTEM%]\msrev23.dll
[%SYSTEM%]\msrev43.dll
[%SYSTEM%]\nsb6.dll
[%SYSTEM%]\nsdD8.dll
[%SYSTEM%]\nse260A.dll
[%SYSTEM%]\nsjD4.dll
[%SYSTEM%]\nsl3F.dll
[%SYSTEM%]\nsn25FE.dll
[%SYSTEM%]\nsy129.dll
[%SYSTEM%]\ss.dll
[%SYSTEM%]\sysfile.dll
[%SYSTEM%]\thin.dll
[%WINDOWS%]\bsx32.ini
[%WINDOWS%]\conscorr.ini
[%WINDOWS%]\iconz.exe
[%WINDOWS%]\Justin.exe
[%WINDOWS%]\justin2a.exe
[%WINDOWS%]\justin_new.exe
[%WINDOWS%]\mmttil.exe
[%WINDOWS%]\preinsln.exe
[%WINDOWS%]\woinstall.exe
[%APPDATA%]\sett.exe
[%DESKTOP%]\amazon.com.url
[%DESKTOP%]\amazon.url
[%DESKTOP%]\bingo .lnk
[%DESKTOP%]\block spyware.url
[%DESKTOP%]\bsx32.ini
[%DESKTOP%]\card games.lnk
[%DESKTOP%]\casino online.lnk
[%DESKTOP%]\cheap holiday travel.url
[%DESKTOP%]\ebay.com.url
[%DESKTOP%]\ebay.url
[%DESKTOP%]\expedia.com.url
[%DESKTOP%]\free online music.url
[%DESKTOP%]\free spyware scanner.url
[%DESKTOP%]\funcade_icmediax_install.exe
[%DESKTOP%]\internet .lnk
[%DESKTOP%]\investing .lnk
[%DESKTOP%]\online dating.url
[%DESKTOP%]\pacman.lnk
[%DESKTOP%]\printer cartridges.lnk
[%DESKTOP%]\travel .lnk
[%DESKTOP%]\travel specials.url
[%DESKTOP%]\website hosting.lnk
[%DESKTOP%]\winsock2.reg
[%FAVORITES%]\ adult entertainment\adult dvd.url
[%FAVORITES%]\ adult entertainment\dating\christian dating.url
[%FAVORITES%]\ adult entertainment\dating\dating agency.url
[%FAVORITES%]\ adult entertainment\dating\dating service.url
[%FAVORITES%]\ adult entertainment\dating\internet dating.url
[%FAVORITES%]\ adult entertainment\dating\jewish dating.url
[%FAVORITES%]\ adult entertainment\dating\online dating.url
[%FAVORITES%]\ adult entertainment\dvd.url
[%FAVORITES%]\ adult entertainment\fetish.url
[%FAVORITES%]\ adult entertainment\gay.url
[%FAVORITES%]\ adult entertainment\hardcore.url
[%FAVORITES%]\ adult entertainment\lesbian.url
[%FAVORITES%]\ adult entertainment\live video feeds.url
[%FAVORITES%]\ adult entertainment\matchmaking.url
[%FAVORITES%]\ adult entertainment\photos.url
[%FAVORITES%]\ adult entertainment\sex movies.url
[%FAVORITES%]\ adult entertainment\sex toys.url
[%FAVORITES%]\ adult entertainment\shemale sex.url
[%FAVORITES%]\ adult entertainment\viagra.url
[%FAVORITES%]\ adult items\adult education.url
[%FAVORITES%]\ adult items\adult personals.url
[%FAVORITES%]\ adult items\adult toys.url
[%FAVORITES%]\ adult items\breast enhancement.url
[%FAVORITES%]\ adult items\buy adipex.url
[%FAVORITES%]\ adult items\buy viagra.url
[%FAVORITES%]\ adult items\diet pill.url
[%FAVORITES%]\ adult items\penis enlargement.url
[%FAVORITES%]\ adult items\personals.url
[%FAVORITES%]\ computers\antivirus.url
[%FAVORITES%]\ computers\communication technology.url
[%FAVORITES%]\ computers\computer jobs .url
[%FAVORITES%]\ computers\computer programming.url
[%FAVORITES%]\ computers\domain hosting.url
[%FAVORITES%]\ computers\dvd.url
[%FAVORITES%]\ computers\games\computer game.url
[%FAVORITES%]\ computers\games\gamecube.url
[%FAVORITES%]\ computers\games\microsoft.url
[%FAVORITES%]\ computers\games\playstation.url
[%FAVORITES%]\ computers\games\quake.url
[%FAVORITES%]\ computers\games\sega dreamcast.url
[%FAVORITES%]\ computers\games\xbox.url
[%FAVORITES%]\ computers\hosting.url
[%FAVORITES%]\ computers\inkjet cartridge.url
[%FAVORITES%]\ computers\instant messenger.url
[%FAVORITES%]\ computers\internet.url
[%FAVORITES%]\ computers\working from home.url
[%FAVORITES%]\ dating\christian dating.url
[%FAVORITES%]\ dating\dating agency.url
[%FAVORITES%]\ dating\dating service.url
[%FAVORITES%]\ dating\internet dating.url
[%FAVORITES%]\ dating\jewish dating.url
[%FAVORITES%]\ dating\online dating.url
[%FAVORITES%]\ home\adjustable bed.url
[%FAVORITES%]\ home\food nutrition.url
[%FAVORITES%]\ home\health plan.url
[%FAVORITES%]\ home\home equity loan.url
[%FAVORITES%]\ home\home improvements.url
[%FAVORITES%]\ home\home refinancing.url
[%FAVORITES%]\ home\home security.url
[%FAVORITES%]\ home\interior decorating .url
[%FAVORITES%]\ home\office space.url
[%FAVORITES%]\ home\outdoor cooking.url
[%FAVORITES%]\ home\outdoor furniture.url
[%FAVORITES%]\ home\phone system.url
[%FAVORITES%]\ home\satellite television.url
[%FAVORITES%]\ home\sleep aids.url
[%FAVORITES%]\ home\timeshare.url
[%FAVORITES%]\ home\working from home.url
[%FAVORITES%]\ internet\domain registrations.url
[%FAVORITES%]\ internet\education\adult education.url
[%FAVORITES%]\ internet\education\book.url
[%FAVORITES%]\ internet\education\college.url
[%FAVORITES%]\ internet\education\community.url
[%FAVORITES%]\ internet\education\education.url
[%FAVORITES%]\ internet\education\essay.url
[%FAVORITES%]\ internet\education\school.url
[%FAVORITES%]\ internet\firewall.url
[%FAVORITES%]\ internet\flowers.url
[%FAVORITES%]\ internet\free long distance.url
[%FAVORITES%]\ internet\hosting.url
[%FAVORITES%]\ internet\internet business.url
[%FAVORITES%]\ internet\investing money.url
[%FAVORITES%]\ internet\jokes.url
[%FAVORITES%]\ internet\newsgroup.url
[%FAVORITES%]\ internet\online football games.url
[%FAVORITES%]\ internet\online gaming.url
[%FAVORITES%]\ internet\spyware.url
[%FAVORITES%]\ internet\starting a business.url
[%FAVORITES%]\ internet\web marketing.url
[%FAVORITES%]\ online gaming\bingo.url
[%FAVORITES%]\ online gaming\black jack poker.url
[%FAVORITES%]\ online gaming\casino online.url
[%FAVORITES%]\ online gaming\craps.url
[%FAVORITES%]\ online gaming\gamble.url
[%FAVORITES%]\ online gaming\jackpot.url
[%FAVORITES%]\ online gaming\roulette gambling.url
[%FAVORITES%]\ online gaming\slots.url
[%FAVORITES%]\ online gaming\sport betting.url
[%FAVORITES%]\ online gaming\sport book.url
[%FAVORITES%]\ online gaming\time cards.url
[%FAVORITES%]\ online pharmacy\buy adipex.url
[%FAVORITES%]\ online pharmacy\buy celebrex.url
[%FAVORITES%]\ online pharmacy\buy fidrex.url
[%FAVORITES%]\ online pharmacy\buy ionamin.url
[%FAVORITES%]\ online pharmacy\buy meridia .url
[%FAVORITES%]\ online pharmacy\buy phentermine.url
[%FAVORITES%]\ online pharmacy\buy propecia.url
[%FAVORITES%]\ online pharmacy\buy soma.url
[%FAVORITES%]\ online pharmacy\buy tenuate.url
[%FAVORITES%]\ online pharmacy\buy ultram online.url
[%FAVORITES%]\ online pharmacy\buy viagra.url
[%FAVORITES%]\ online pharmacy\buy xenical.url
[%FAVORITES%]\ online pharmacy\consumer consulting.url
[%FAVORITES%]\ online pharmacy\doctor.url
[%FAVORITES%]\ online pharmacy\mexican pharmacy.url
[%FAVORITES%]\ online pharmacy\pass drug test.url
[%FAVORITES%]\ online pharmacy\pet med.url
[%FAVORITES%]\ online pharmacy\pharmacy online.url
[%FAVORITES%]\ shopping gifts\birthday gift.url
[%FAVORITES%]\ shopping gifts\cellular.url
[%FAVORITES%]\ shopping gifts\christmas gift.url
[%FAVORITES%]\ shopping gifts\corporate gift.url
[%FAVORITES%]\ shopping gifts\digital cameras.url
[%FAVORITES%]\ shopping gifts\dress fashion.url
[%FAVORITES%]\ shopping gifts\dvd players.url
[%FAVORITES%]\ shopping gifts\gift basket.url
[%FAVORITES%]\ shopping gifts\jewelry.url
[%FAVORITES%]\ shopping gifts\leather jackets.url
[%FAVORITES%]\ shopping gifts\perfume.url
[%FAVORITES%]\ shopping gifts\sexy lingerie.url
[%FAVORITES%]\ shopping gifts\shoes.url
[%FAVORITES%]\ shopping gifts\smoke shop.url
[%FAVORITES%]\ shopping gifts\underwear.url
[%FAVORITES%]\ shopping gifts\video surveillance.url
[%FAVORITES%]\ shopping gifts\watches.url
[%FAVORITES%]\ shopping gifts\wedding gifts.url
[%FAVORITES%]\ shopping gifts\wine gifts.url
[%FAVORITES%]\ shopping gifts\womens clothing.url
[%FAVORITES%]\ travel\air travel.url
[%FAVORITES%]\ travel\cancun vacation.url
[%FAVORITES%]\ travel\car rental.url
[%FAVORITES%]\ travel\cruises.url
[%FAVORITES%]\ travel\discount travel.url
[%FAVORITES%]\ travel\europe travel.url
[%FAVORITES%]\ travel\family vacation.url
[%FAVORITES%]\ travel\hawaii travel.url
[%FAVORITES%]\ travel\hotels.url
[%FAVORITES%]\ travel\las vegas hotel.url
[%FAVORITES%]\ travel\london hotel.url
[%FAVORITES%]\ travel\new york.url
[%FAVORITES%]\ travel\orlando hotel.url
[%FAVORITES%]\ travel\resort.url
[%FAVORITES%]\ travel\skiing.url
[%FAVORITES%]\ travel\timeshare.url
[%FAVORITES%]\ travel\travel agent.url
[%FAVORITES%]\ travel\travel insurance.url
[%FAVORITES%]\ travel\vacation.url
[%FAVORITES%]\ travel\world travel.url
[%FAVORITES%]\ antivirus.url
[%FAVORITES%]\ casino online.url
[%FAVORITES%]\ computers.url
[%FAVORITES%]\ instant messaging.url
[%FAVORITES%]\ internet.url
[%FAVORITES%]\ movie.url
[%FAVORITES%]\ web hosting.url
[%PROGRAMS%]\pacman.lnk
[%PROGRAM_FILES%]\sed\se.exe
[%PROGRAM_FILES%]\sed\sed.exe
[%PROGRAM_FILES%]\sed\uninstall.exe
[%PROGRAM_FILES%]\third close jugs\gojpuses.exe
[%PROGRAM_FILES%]\third close jugs\gridtwo.exe
[%PROGRAM_FILES%]\third close jugs\help anti.exe
[%PROGRAM_FILES%]\third close jugs\link 01 live.exe
[%PROGRAM_FILES%]\third close jugs\qiopzbor.exe
[%PROGRAM_FILES%]\user hold beep\dogmfcd.exe
[%PROGRAM_FILES%]\weboff~1\sepng.dll
[%SYSTEM%]\amtxprxy.dll
[%SYSTEM%]\aqzh0g6.exe
[%SYSTEM%]\araamon.dll
[%SYSTEM%]\atl76681.exe
[%SYSTEM%]\auaamon.dll
[%SYSTEM%]\aud.dll
[%SYSTEM%]\avwav072.exe
[%SYSTEM%]\bidispl9.exe
[%SYSTEM%]\cdfview4.exe
[%SYSTEM%]\cmpbk321.exe
[%SYSTEM%]\coreak.dll
[%SYSTEM%]\esad8.exe
[%SYSTEM%]\hotelc.exe
[%SYSTEM%]\ifojzc.exe
[%SYSTEM%]\jel387h.exe
[%SYSTEM%]\mmview_ouch.dll
[%SYSTEM%]\nsm22.dll
[%SYSTEM%]\nsu2D.dll
[%SYSTEM%]\rulesak.dll
[%SYSTEM%]\sicon.dll
[%SYSTEM%]\splashspot games.exe
[%SYSTEM%]\tfing.exe
[%SYSTEM%]\updak.dll
[%SYSTEM%]\vbbm8.exe
[%SYSTEM%]\wrgkf2.exe
[%SYSTEM%]\yzrokmen.exe
[%SYSTEM%]\zibk.exe
[%WINDOWS%]\cjijjom.ini
[%WINDOWS%]\digital signature 20040814.htm
[%COMMON_FAVORITES%]\amazon.com.url
[%COMMON_FAVORITES%]\ebay.url
[%COMMON_FAVORITES%]\links\ebay.url
[%DESKTOP%]\amazon.com.url
[%DESKTOP%]\amazon.url
[%DESKTOP%]\ebay.url
[%FAVORITES%]\amazon.com.url
[%FAVORITES%]\amazon.url
[%FAVORITES%]\ebay.com.url
[%FAVORITES%]\ebay.url
[%FAVORITES%]\expedia.com.url
[%FAVORITES%]\links\amazon.com.url
[%FAVORITES%]\links\amazon.url
[%FAVORITES%]\links\ebay.com.url
[%FAVORITES%]\links\ebay.url
[%FAVORITES%]\links\expedia.url
[%INTERNET_CACHE%]\content.ie5\RYS371KD\upgrade[1].vrn
[%FAVORITES%]\links\amazon.com.url
[%PROFILE_TEMP%]\aupd.exe
[%PROFILE_TEMP%]\~nsu.tmp\Au_.exe
[%PROGRAM_FILES%]\sed\uninst.exe
[%PROGRAM_FILES%]\Web Offer\gendis.ez
[%PROGRAM_FILES%]\Web Offer\paramp.ez
[%PROGRAM_FILES%]\Web Offer\rwdsp.rst
[%SYSTEM%]\antispy.exe
[%SYSTEM%]\book.dll
[%SYSTEM%]\cdcore.dll
[%SYSTEM%]\cdrules.dll
[%SYSTEM%]\cdsync.dll
[%SYSTEM%]\ezpopstub.exe
[%SYSTEM%]\justin.exe
[%SYSTEM%]\msrev23.dll
[%SYSTEM%]\msrev43.dll
[%SYSTEM%]\nsb6.dll
[%SYSTEM%]\nsdD8.dll
[%SYSTEM%]\nse260A.dll
[%SYSTEM%]\nsjD4.dll
[%SYSTEM%]\nsl3F.dll
[%SYSTEM%]\nsn25FE.dll
[%SYSTEM%]\nsy129.dll
[%SYSTEM%]\ss.dll
[%SYSTEM%]\sysfile.dll
[%SYSTEM%]\thin.dll
[%WINDOWS%]\bsx32.ini
[%WINDOWS%]\conscorr.ini
[%WINDOWS%]\iconz.exe
[%WINDOWS%]\Justin.exe
[%WINDOWS%]\justin2a.exe
[%WINDOWS%]\justin_new.exe
[%WINDOWS%]\mmttil.exe
[%WINDOWS%]\preinsln.exe
[%WINDOWS%]\woinstall.exe
[%APPDATA%]\sett.exe
[%DESKTOP%]\amazon.com.url
[%DESKTOP%]\amazon.url
[%DESKTOP%]\bingo .lnk
[%DESKTOP%]\block spyware.url
[%DESKTOP%]\bsx32.ini
[%DESKTOP%]\card games.lnk
[%DESKTOP%]\casino online.lnk
[%DESKTOP%]\cheap holiday travel.url
[%DESKTOP%]\ebay.com.url
[%DESKTOP%]\ebay.url
[%DESKTOP%]\expedia.com.url
[%DESKTOP%]\free online music.url
[%DESKTOP%]\free spyware scanner.url
[%DESKTOP%]\funcade_icmediax_install.exe
[%DESKTOP%]\internet .lnk
[%DESKTOP%]\investing .lnk
[%DESKTOP%]\online dating.url
[%DESKTOP%]\pacman.lnk
[%DESKTOP%]\printer cartridges.lnk
[%DESKTOP%]\travel .lnk
[%DESKTOP%]\travel specials.url
[%DESKTOP%]\website hosting.lnk
[%DESKTOP%]\winsock2.reg
[%FAVORITES%]\ adult entertainment\adult dvd.url
[%FAVORITES%]\ adult entertainment\dating\christian dating.url
[%FAVORITES%]\ adult entertainment\dating\dating agency.url
[%FAVORITES%]\ adult entertainment\dating\dating service.url
[%FAVORITES%]\ adult entertainment\dating\internet dating.url
[%FAVORITES%]\ adult entertainment\dating\jewish dating.url
[%FAVORITES%]\ adult entertainment\dating\online dating.url
[%FAVORITES%]\ adult entertainment\dvd.url
[%FAVORITES%]\ adult entertainment\fetish.url
[%FAVORITES%]\ adult entertainment\gay.url
[%FAVORITES%]\ adult entertainment\hardcore.url
[%FAVORITES%]\ adult entertainment\lesbian.url
[%FAVORITES%]\ adult entertainment\live video feeds.url
[%FAVORITES%]\ adult entertainment\matchmaking.url
[%FAVORITES%]\ adult entertainment\photos.url
[%FAVORITES%]\ adult entertainment\sex movies.url
[%FAVORITES%]\ adult entertainment\sex toys.url
[%FAVORITES%]\ adult entertainment\shemale sex.url
[%FAVORITES%]\ adult entertainment\viagra.url
[%FAVORITES%]\ adult items\adult education.url
[%FAVORITES%]\ adult items\adult personals.url
[%FAVORITES%]\ adult items\adult toys.url
[%FAVORITES%]\ adult items\breast enhancement.url
[%FAVORITES%]\ adult items\buy adipex.url
[%FAVORITES%]\ adult items\buy viagra.url
[%FAVORITES%]\ adult items\diet pill.url
[%FAVORITES%]\ adult items\penis enlargement.url
[%FAVORITES%]\ adult items\personals.url
[%FAVORITES%]\ computers\antivirus.url
[%FAVORITES%]\ computers\communication technology.url
[%FAVORITES%]\ computers\computer jobs .url
[%FAVORITES%]\ computers\computer programming.url
[%FAVORITES%]\ computers\domain hosting.url
[%FAVORITES%]\ computers\dvd.url
[%FAVORITES%]\ computers\games\computer game.url
[%FAVORITES%]\ computers\games\gamecube.url
[%FAVORITES%]\ computers\games\microsoft.url
[%FAVORITES%]\ computers\games\playstation.url
[%FAVORITES%]\ computers\games\quake.url
[%FAVORITES%]\ computers\games\sega dreamcast.url
[%FAVORITES%]\ computers\games\xbox.url
[%FAVORITES%]\ computers\hosting.url
[%FAVORITES%]\ computers\inkjet cartridge.url
[%FAVORITES%]\ computers\instant messenger.url
[%FAVORITES%]\ computers\internet.url
[%FAVORITES%]\ computers\working from home.url
[%FAVORITES%]\ dating\christian dating.url
[%FAVORITES%]\ dating\dating agency.url
[%FAVORITES%]\ dating\dating service.url
[%FAVORITES%]\ dating\internet dating.url
[%FAVORITES%]\ dating\jewish dating.url
[%FAVORITES%]\ dating\online dating.url
[%FAVORITES%]\ home\adjustable bed.url
[%FAVORITES%]\ home\food nutrition.url
[%FAVORITES%]\ home\health plan.url
[%FAVORITES%]\ home\home equity loan.url
[%FAVORITES%]\ home\home improvements.url
[%FAVORITES%]\ home\home refinancing.url
[%FAVORITES%]\ home\home security.url
[%FAVORITES%]\ home\interior decorating .url
[%FAVORITES%]\ home\office space.url
[%FAVORITES%]\ home\outdoor cooking.url
[%FAVORITES%]\ home\outdoor furniture.url
[%FAVORITES%]\ home\phone system.url
[%FAVORITES%]\ home\satellite television.url
[%FAVORITES%]\ home\sleep aids.url
[%FAVORITES%]\ home\timeshare.url
[%FAVORITES%]\ home\working from home.url
[%FAVORITES%]\ internet\domain registrations.url
[%FAVORITES%]\ internet\education\adult education.url
[%FAVORITES%]\ internet\education\book.url
[%FAVORITES%]\ internet\education\college.url
[%FAVORITES%]\ internet\education\community.url
[%FAVORITES%]\ internet\education\education.url
[%FAVORITES%]\ internet\education\essay.url
[%FAVORITES%]\ internet\education\school.url
[%FAVORITES%]\ internet\firewall.url
[%FAVORITES%]\ internet\flowers.url
[%FAVORITES%]\ internet\free long distance.url
[%FAVORITES%]\ internet\hosting.url
[%FAVORITES%]\ internet\internet business.url
[%FAVORITES%]\ internet\investing money.url
[%FAVORITES%]\ internet\jokes.url
[%FAVORITES%]\ internet\newsgroup.url
[%FAVORITES%]\ internet\online football games.url
[%FAVORITES%]\ internet\online gaming.url
[%FAVORITES%]\ internet\spyware.url
[%FAVORITES%]\ internet\starting a business.url
[%FAVORITES%]\ internet\web marketing.url
[%FAVORITES%]\ online gaming\bingo.url
[%FAVORITES%]\ online gaming\black jack poker.url
[%FAVORITES%]\ online gaming\casino online.url
[%FAVORITES%]\ online gaming\craps.url
[%FAVORITES%]\ online gaming\gamble.url
[%FAVORITES%]\ online gaming\jackpot.url
[%FAVORITES%]\ online gaming\roulette gambling.url
[%FAVORITES%]\ online gaming\slots.url
[%FAVORITES%]\ online gaming\sport betting.url
[%FAVORITES%]\ online gaming\sport book.url
[%FAVORITES%]\ online gaming\time cards.url
[%FAVORITES%]\ online pharmacy\buy adipex.url
[%FAVORITES%]\ online pharmacy\buy celebrex.url
[%FAVORITES%]\ online pharmacy\buy fidrex.url
[%FAVORITES%]\ online pharmacy\buy ionamin.url
[%FAVORITES%]\ online pharmacy\buy meridia .url
[%FAVORITES%]\ online pharmacy\buy phentermine.url
[%FAVORITES%]\ online pharmacy\buy propecia.url
[%FAVORITES%]\ online pharmacy\buy soma.url
[%FAVORITES%]\ online pharmacy\buy tenuate.url
[%FAVORITES%]\ online pharmacy\buy ultram online.url
[%FAVORITES%]\ online pharmacy\buy viagra.url
[%FAVORITES%]\ online pharmacy\buy xenical.url
[%FAVORITES%]\ online pharmacy\consumer consulting.url
[%FAVORITES%]\ online pharmacy\doctor.url
[%FAVORITES%]\ online pharmacy\mexican pharmacy.url
[%FAVORITES%]\ online pharmacy\pass drug test.url
[%FAVORITES%]\ online pharmacy\pet med.url
[%FAVORITES%]\ online pharmacy\pharmacy online.url
[%FAVORITES%]\ shopping gifts\birthday gift.url
[%FAVORITES%]\ shopping gifts\cellular.url
[%FAVORITES%]\ shopping gifts\christmas gift.url
[%FAVORITES%]\ shopping gifts\corporate gift.url
[%FAVORITES%]\ shopping gifts\digital cameras.url
[%FAVORITES%]\ shopping gifts\dress fashion.url
[%FAVORITES%]\ shopping gifts\dvd players.url
[%FAVORITES%]\ shopping gifts\gift basket.url
[%FAVORITES%]\ shopping gifts\jewelry.url
[%FAVORITES%]\ shopping gifts\leather jackets.url
[%FAVORITES%]\ shopping gifts\perfume.url
[%FAVORITES%]\ shopping gifts\sexy lingerie.url
[%FAVORITES%]\ shopping gifts\shoes.url
[%FAVORITES%]\ shopping gifts\smoke shop.url
[%FAVORITES%]\ shopping gifts\underwear.url
[%FAVORITES%]\ shopping gifts\video surveillance.url
[%FAVORITES%]\ shopping gifts\watches.url
[%FAVORITES%]\ shopping gifts\wedding gifts.url
[%FAVORITES%]\ shopping gifts\wine gifts.url
[%FAVORITES%]\ shopping gifts\womens clothing.url
[%FAVORITES%]\ travel\air travel.url
[%FAVORITES%]\ travel\cancun vacation.url
[%FAVORITES%]\ travel\car rental.url
[%FAVORITES%]\ travel\cruises.url
[%FAVORITES%]\ travel\discount travel.url
[%FAVORITES%]\ travel\europe travel.url
[%FAVORITES%]\ travel\family vacation.url
[%FAVORITES%]\ travel\hawaii travel.url
[%FAVORITES%]\ travel\hotels.url
[%FAVORITES%]\ travel\las vegas hotel.url
[%FAVORITES%]\ travel\london hotel.url
[%FAVORITES%]\ travel\new york.url
[%FAVORITES%]\ travel\orlando hotel.url
[%FAVORITES%]\ travel\resort.url
[%FAVORITES%]\ travel\skiing.url
[%FAVORITES%]\ travel\timeshare.url
[%FAVORITES%]\ travel\travel agent.url
[%FAVORITES%]\ travel\travel insurance.url
[%FAVORITES%]\ travel\vacation.url
[%FAVORITES%]\ travel\world travel.url
[%FAVORITES%]\ antivirus.url
[%FAVORITES%]\ casino online.url
[%FAVORITES%]\ computers.url
[%FAVORITES%]\ instant messaging.url
[%FAVORITES%]\ internet.url
[%FAVORITES%]\ movie.url
[%FAVORITES%]\ web hosting.url
[%PROGRAMS%]\pacman.lnk
[%PROGRAM_FILES%]\sed\se.exe
[%PROGRAM_FILES%]\sed\sed.exe
[%PROGRAM_FILES%]\sed\uninstall.exe
[%PROGRAM_FILES%]\third close jugs\gojpuses.exe
[%PROGRAM_FILES%]\third close jugs\gridtwo.exe
[%PROGRAM_FILES%]\third close jugs\help anti.exe
[%PROGRAM_FILES%]\third close jugs\link 01 live.exe
[%PROGRAM_FILES%]\third close jugs\qiopzbor.exe
[%PROGRAM_FILES%]\user hold beep\dogmfcd.exe
[%PROGRAM_FILES%]\weboff~1\sepng.dll
[%SYSTEM%]\amtxprxy.dll
[%SYSTEM%]\aqzh0g6.exe
[%SYSTEM%]\araamon.dll
[%SYSTEM%]\atl76681.exe
[%SYSTEM%]\auaamon.dll
[%SYSTEM%]\aud.dll
[%SYSTEM%]\avwav072.exe
[%SYSTEM%]\bidispl9.exe
[%SYSTEM%]\cdfview4.exe
[%SYSTEM%]\cmpbk321.exe
[%SYSTEM%]\coreak.dll
[%SYSTEM%]\esad8.exe
[%SYSTEM%]\hotelc.exe
[%SYSTEM%]\ifojzc.exe
[%SYSTEM%]\jel387h.exe
[%SYSTEM%]\mmview_ouch.dll
[%SYSTEM%]\nsm22.dll
[%SYSTEM%]\nsu2D.dll
[%SYSTEM%]\rulesak.dll
[%SYSTEM%]\sicon.dll
[%SYSTEM%]\splashspot games.exe
[%SYSTEM%]\tfing.exe
[%SYSTEM%]\updak.dll
[%SYSTEM%]\vbbm8.exe
[%SYSTEM%]\wrgkf2.exe
[%SYSTEM%]\yzrokmen.exe
[%SYSTEM%]\zibk.exe
[%WINDOWS%]\cjijjom.ini
[%WINDOWS%]\digital signature 20040814.htm

Folders:
[%PROGRAM_FILES%]\web offer
[%WINDOWS%]\ezstub.exe

Registry Keys:
HKEY_CLASSES_ROOT\appid\{0818d423-6247-11d1-abee-00d049c10000}
HKEY_CLASSES_ROOT\clsid\{23fb5add-da37-4a40-9fc0-b0e2384cde92}
HKEY_CLASSES_ROOT\clsid\{2cab0356-88e3-4902-a85d-379689c625e1}
HKEY_CLASSES_ROOT\clsid\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}
HKEY_CLASSES_ROOT\clsid\{746455fe-d059-47e7-af0e-140e03f5a447}
HKEY_CLASSES_ROOT\clsid\{8940e505-72c6-44de-be85-1d746780efbf}
HKEY_CLASSES_ROOT\clsid\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}
HKEY_CLASSES_ROOT\clsid\{ed5d884b-1a35-482e-bea1-dd52f75b6138}
HKEY_CLASSES_ROOT\crypt.core
HKEY_CLASSES_ROOT\crypt.core.1
HKEY_CLASSES_ROOT\da.bomb
HKEY_CLASSES_ROOT\da.bomb.1
HKEY_CLASSES_ROOT\interface\{241667a3-ec83-4885-84dd-c2daafc1c5ea}
HKEY_CLASSES_ROOT\interface\{25630b50-53c6-4e66-a945-9d7b6b2171ff}
HKEY_CLASSES_ROOT\interface\{370f6327-41c4-4fa6-a2df-1ba57ee0fbb9}
HKEY_CLASSES_ROOT\interface\{370f6353-41c4-4fa6-a2df-1ba57ee0fbb9}
HKEY_CLASSES_ROOT\interface\{3a951af0-53f8-4803-a565-0e1dee4b11f5}
HKEY_CLASSES_ROOT\interface\{6e0ed53c-9908-49ed-b055-7cb31b162577}
HKEY_CLASSES_ROOT\interface\{788c6f6e-c2ea-4a63-9c38-ce7d8f43bce4}
HKEY_CLASSES_ROOT\interface\{78bcf936-45b0-40a7-9391-dcc03420db35}
HKEY_CLASSES_ROOT\interface\{7edc96e1-5dd3-11d4-b185-0050dab79376}
HKEY_CLASSES_ROOT\interface\{830d3aed-2fa9-454f-b266-d931862bbf34}
HKEY_CLASSES_ROOT\interface\{8c53bd8e-b12d-4c8f-ad0e-c9ddc39d1273}
HKEY_CLASSES_ROOT\interface\{8ebb1743-9a2f-11d4-8a7e-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{955cbf48-4313-4b1f-872b-254b7822ccf2}
HKEY_CLASSES_ROOT\interface\{9bcdd51b-4a7b-446c-8452-d32d38004582}
HKEY_CLASSES_ROOT\interface\{9cfa26c2-81da-4c9d-a501-f144a4a000fa}
HKEY_CLASSES_ROOT\interface\{a1465eaa-5f48-477d-b263-3b472989ffc4}
HKEY_CLASSES_ROOT\interface\{a42dc659-33b5-409e-a433-650ac42ecca4}
HKEY_CLASSES_ROOT\interface\{a8516f49-8046-4295-8ee9-c59d5041c9e2}
HKEY_CLASSES_ROOT\interface\{a986f4db-792e-4571-8974-0bb6e024766f}
HKEY_CLASSES_ROOT\interface\{af286cea-635d-40c5-a891-b40a0f520539}
HKEY_CLASSES_ROOT\interface\{ba2a20e0-2476-43bb-bcc8-bfee2419b293}
HKEY_CLASSES_ROOT\interface\{bccab53d-0895-40c3-a942-a03538ce227a}
HKEY_CLASSES_ROOT\interface\{bd6f129a-08db-4cc5-a75a-f2ab79e55b6e}
HKEY_CLASSES_ROOT\interface\{c03351a3-6755-11d4-8a73-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{c0f88e9e-dceb-4655-968a-ae508a677c39}
HKEY_CLASSES_ROOT\interface\{c4fee4a6-4b8b-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{d0c1545e-61e1-40d5-8f8c-37d4e7758275}
HKEY_CLASSES_ROOT\interface\{d7eac2d8-2d52-4010-a4ad-dfdf60c1706c}
HKEY_CLASSES_ROOT\interface\{ef0372dc-f552-11d3-8528-0050dab79376}
HKEY_CLASSES_ROOT\interface\{ef0372de-f552-11d3-8528-0050dab79376}
HKEY_CLASSES_ROOT\interface\{efa52460-8822-4191-ba38-facdd2007910}
HKEY_CLASSES_ROOT\interface\{f50a45ec-df75-47d1-b879-3a983043aefb}
HKEY_CLASSES_ROOT\interface\{fb82ccd5-174b-4379-bc37-72d9b5adaeda}
HKEY_CLASSES_ROOT\onone.theimp
HKEY_CLASSES_ROOT\onone.theimp.1
HKEY_CLASSES_ROOT\typelib\{230290d9-946f-4276-9a91-ce2a2f376b9e}
HKEY_CLASSES_ROOT\typelib\{370f6327-41c4-4fa6-a2df-1ba57ee0fbb9}
HKEY_CLASSES_ROOT\typelib\{5e594162-60a9-487d-84b8-dbdd716cb862}
HKEY_CLASSES_ROOT\typelib\{8992b6ca-b8c9-4aed-bf89-0a17f6296a06}
HKEY_CLASSES_ROOT\typelib\{9cfa26c0-81da-4c9d-a501-f144a4a000fa}
HKEY_CLASSES_ROOT\typelib\{9cfa26c1-81da-4c9d-a501-f144a4a000fa}
HKEY_CLASSES_ROOT\typelib\{baf13496-8f72-47a1-9cee-09238efc75f0}
HKEY_CLASSES_ROOT\typelib\{fdb10602-aa12-4e76-aae2-2b328a3e950a}
HKEY_CURRENT_USER\software\mprocessor
HKEY_CURRENT_USER\software\web offer
HKEY_LOCAL_MACHINE\software\classes\typelib\{8a044396-5da2-11d4-b185-0050dab79376}
HKEY_LOCAL_MACHINE\software\coupondeals
HKEY_LOCAL_MACHINE\software\interads
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\direct2d
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\explorer bars\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\explorer bars\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{746455fe-d059-47e7-af0e-140e03f5a447}
HKEY_CLASSES_ROOT\atlbrcon.atlbrcon.1
HKEY_CLASSES_ROOT\clsid\{00320615-b6c2-40a6-8f99-f1c52d674fad}
HKEY_CLASSES_ROOT\clsid\{01eb5130-fc0c-4d75-b9ce-4801b1b854f5}\programmable
HKEY_CLASSES_ROOT\clsid\{10049d2a-2965-4e4f-8c7e-cb33ad95feb7}\programmable
HKEY_CLASSES_ROOT\clsid\{1a9880a9-5a48-15ac-b6e5-4a07a1f4df7a}
HKEY_CLASSES_ROOT\clsid\{220f9cb2-acf1-ae12-1d11-536411e35dfe}
HKEY_CLASSES_ROOT\clsid\{23358854-c851-a9c8-7858-954990bc2490}
HKEY_CLASSES_ROOT\clsid\{25630b47-53c6-4e66-a945-9d7b6b2171ff}
HKEY_CLASSES_ROOT\clsid\{2720f083-325e-7d8d-c082-7d07a8eade87}
HKEY_CLASSES_ROOT\clsid\{2ada082b-9f11-a314-9431-d7c29f458b6e}
HKEY_CLASSES_ROOT\clsid\{370f6354-41c4-4fa6-a2df-1ba57ee0fbb9}
HKEY_CLASSES_ROOT\clsid\{3a411476-c94b-4cdc-8700-6f7901ce9eeb}
HKEY_CLASSES_ROOT\clsid\{4368aaa5-c359-2ce0-c7df-4246bb5b4cb2}
HKEY_CLASSES_ROOT\clsid\{4cd4be40-22e3-ccac-bceb-69a27ddf5f89}
HKEY_CLASSES_ROOT\clsid\{4d335fff-080f-8f89-e1c4-75220c35322e}
HKEY_CLASSES_ROOT\clsid\{5c9df9e7-8687-05a2-17a3-036319e3786d}
HKEY_CLASSES_ROOT\clsid\{6df5e318-6994-4a41-85bd-45ccada616f8}
HKEY_CLASSES_ROOT\clsid\{788c6f6f-c2ea-4a63-9c38-ce7d8f43bce4}
HKEY_CLASSES_ROOT\clsid\{78bcf937-45b0-40a7-9391-dcc03420db35}
HKEY_CLASSES_ROOT\clsid\{9bcf9f0e-80c2-bd69-8c3e-b1ced587cbff}
HKEY_CLASSES_ROOT\clsid\{9cfa26c0-81da-4c9d-a501-f144a4a000fa}
HKEY_CLASSES_ROOT\clsid\{c256d608-29d9-bcf2-1c2a-6e01a66a8b51}
HKEY_CLASSES_ROOT\clsid\{c68924a3-c49a-37c2-eb92-1645f73d3e1e}
HKEY_CLASSES_ROOT\clsid\{e08b462d-2fb7-0489-54b7-1b6aafc2ecba}
HKEY_CLASSES_ROOT\clsid\{e7a05400-4cfa-4df3-a643-e40f86e8e3d7}
HKEY_CLASSES_ROOT\clsid\{f75521b8-76f1-4a4d-84b1-9e642e9c51d0}
HKEY_CLASSES_ROOT\clsid\{fa66d870-8368-1b50-fb12-631748c9752d}
HKEY_CLASSES_ROOT\clsid\{fb87796b-c1d1-a2cf-468a-03e77186d7b5}
HKEY_CLASSES_ROOT\clsid\{fc2a685e-3d0f-87b0-2045-18023d80bb50}
HKEY_CLASSES_ROOT\ezulafsearcheng.popupdispla
HKEY_CLASSES_ROOT\ezulafsearcheng.resulthelpe
HKEY_CLASSES_ROOT\ezulafsearcheng.searchhelpe
HKEY_CLASSES_ROOT\ezulamain.ezulapopsearchpipe
HKEY_CLASSES_ROOT\ezulamain.ezulapopsearchpipe.1
HKEY_CLASSES_ROOT\typelib\{82910ce3-d86a-435a-a519-6a8c369855d3}
HKEY_CLASSES_ROOT\typelib\{eb5e961f-f519-303c-9744-0d4376b1b0b5}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{01eb5130-fc0c-4d75-b9ce-4801b1b854f5}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{23fb5add-da37-4a40-9fc0-b0e2384cde92}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9cfa26c0-81da-4c9d-a501-f144a4a000fa}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{fc2a685e-3d0f-87b0-2045-18023d80bb50}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\clickfast
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\web offer
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\{23fb5add-da37-4a40-9fc0-b0e2384cde92}

Registry Values:
HKEY_CLASSES_ROOT\interface\{0fd6420a-f789-40ae-b921-3983f84e074e}\typelib
HKEY_CLASSES_ROOT\interface\{994a0535-b09c-4d1c-aa4a-2f76002349b1}\typelib
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\fileexts\.ldb\openwithlist
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\fileexts\.mdb\openwithlist
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\fileexts\.mdb\openwithlist
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_LOCAL_MACHINE\software\microsoft\compression
HKEY_CLASSES_ROOT\clsid\{01eb5130-fc0c-4d75-b9ce-4801b1b854f5}\inprocserver32
HKEY_CLASSES_ROOT\clsid\{10049d2a-2965-4e4f-8c7e-cb33ad95feb7}\inprocserver32
HKEY_CLASSES_ROOT\clsid\{1115bae4-62c1-00f9-699a-573366dc900}\{3df87d69-5120-3342-7197-45fdbaa4433}
HKEY_CLASSES_ROOT\clsid\{1115bae4-62c1-00f9-699a-573366dc900}\{b740471d-0554-fd37-0643-9d563903067}
HKEY_CLASSES_ROOT\clsid\{1115bae4-62c1-00f9-699a-573366dc900}\{b740471d-0554-fd37-0643-9d563903067}
HKEY_CLASSES_ROOT\clsid\{1115bae4-62c1-00f9-699a-573366dc900}\{b740471d-0554-fd37-0643-9d563903067}
HKEY_CLASSES_ROOT\clsid\{1115bae4-62c1-00f9-699a-573366dc900}\{b740471d-0554-fd37-0643-9d563903067}
HKEY_CLASSES_ROOT\clsid\{1115bae4-62c1-00f9-699a-573366dc900}\{bb88b15d-0943-9047-7704-ad9ab66706b}
HKEY_CLASSES_ROOT\clsid\{16c050d2-677f-2c7f-45b2-8a55c79af3c}\{2364bb4a-434a-8767-5553-87884aaac66}
HKEY_CLASSES_ROOT\clsid\{16c050d2-677f-2c7f-45b2-8a55c79af3c}\{38e4c144-9b58-7ea6-fb27-b2444944dde}
HKEY_CLASSES_ROOT\clsid\{2253ec38-a972-40a9-8967-e9b1c82e7804}\inprocserver32
HKEY_CLASSES_ROOT\clsid\{3c34c5f1-d5aa-4b44-9dbd-27dba3fb6e0f}\inprocserver32
HKEY_CLASSES_ROOT\interface\{0fd6420a-f789-40ae-b921-3983f84e074e}\typelib
HKEY_CLASSES_ROOT\interface\{994a0535-b09c-4d1c-aa4a-2f76002349b1}\typelib
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\localnrd
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\windows media\wmsdk\general
HKEY_CURRENT_USER\software\microsoft\windows media\wmsdk\general
HKEY_CURRENT_USER\software\microsoft\windows\currentversion
HKEY_CURRENT_USER\software\microsoft\windows\currentversion
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\discardable\postsetup\shellnew
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\streammru
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\streammru
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\streammru
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\streammru
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\streams\184
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\streams\185
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\streams\186
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\streams\34
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0\cache\extensible cache\mshist012004081420040815
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0\cache\extensible cache\mshist012004081420040815
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0\cache\extensible cache\mshist012004081420040815
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0\cache\extensible cache\mshist012004081420040815
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0\cache\extensible cache\mshist012004081420040815
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0\cache\extensible cache\mshist012004081520040816
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0\cache\extensible cache\mshist012004081520040816
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0\cache\extensible cache\mshist012004081520040816
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0\cache\extensible cache\mshist012004081520040816
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0\cache\extensible cache\mshist012004081520040816
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce
HKEY_LOCAL_MACHINE\software\microsoft
HKEY_LOCAL_MACHINE\software\microsoft\cryptography\services
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\secedit
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\secedit
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\secedit
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\secedit
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\secedit
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\secedit
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\secedit
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\secedit
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet settings\user agent\post platform
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions\approved
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\030da494382e
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\4784f481c85c
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\amyshorse.zip
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\amyshorse.zip
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\cake kind test
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\cake kind test
HKEY_LOCAL_MACHINE\system\mounteddevices


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
TimeDead Trojan Removal
WWW.GlobeTechnology.com Tracking Cookie Cleaner
Remove Hates Trojan
Remove Givoree Trojan

SurfSideKick Adware

How To Remove SurfSideKick?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
SurfSideKick is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


SurfSideKick Symptoms:

Files:
[%APPDATA%]\Sskcwrd.dll
[%APPDATA%]\sskdmns.dll
[%APPDATA%]\sskknwrd.dll
[%APPDATA%]\sskuknwrd.dll
[%APPDATA%]\tvmuknwrd.dll
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinAD.ebd
[%COMMON_APPDATA%]\nsv\wmv0104.dbd
[%COMMON_APPDATA%]\pcsvc\delfinAD.ebd
[%PROFILE_TEMP%]\echo.exe
[%SYSTEM%]\bk.exe
[%WINDOWS%]\SS1001.exe
[%WINDOWS%]\ss1205.exe
[%WINDOWS%]\ssk3b5doublemedia.exe
[%PROFILE_TEMP%]\ic.tmp
[%PROFILE_TEMP%]\sskupdater3.exe
[%PROFILE_TEMP%]\ssk_b5.exe
[%SYSTEM%]\repairs303169572.dll
[%SYSTEM%]\repairs303169590.dll
[%WINDOWS%]\ssk3_b5.exe
[%APPDATA%]\Sskcwrd.dll
[%APPDATA%]\sskdmns.dll
[%APPDATA%]\sskknwrd.dll
[%APPDATA%]\sskuknwrd.dll
[%APPDATA%]\tvmuknwrd.dll
[%COMMON_APPDATA%]\DelFin\PromulGate\delfinAD.ebd
[%COMMON_APPDATA%]\nsv\wmv0104.dbd
[%COMMON_APPDATA%]\pcsvc\delfinAD.ebd
[%PROFILE_TEMP%]\echo.exe
[%SYSTEM%]\bk.exe
[%WINDOWS%]\SS1001.exe
[%WINDOWS%]\ss1205.exe
[%WINDOWS%]\ssk3b5doublemedia.exe
[%PROFILE_TEMP%]\ic.tmp
[%PROFILE_TEMP%]\sskupdater3.exe
[%PROFILE_TEMP%]\ssk_b5.exe
[%SYSTEM%]\repairs303169572.dll
[%SYSTEM%]\repairs303169590.dll
[%WINDOWS%]\ssk3_b5.exe

Folders:
[%PROGRAM_FILES%]\surfsidekick 3
[%PROGRAM_FILES%]\surfsidekick
[%PROGRAM_FILES%]\surfsidekick 2

Registry Keys:
HKEY_CURRENT_USER\software\surfsidekick3
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\surf sidekick
HKEY_LOCAL_MACHINE\software\surfsidekick2
HKEY_LOCAL_MACHINE\software\surfsidekick3
HKEY_CLASSES_ROOT\clsid\{000ab005-ff12-42c2-8df5-39e12e5f9c91}
HKEY_CLASSES_ROOT\clsid\{02ee5b04-f144-47bb-83fb-a60bd91b74a9}
HKEY_CLASSES_ROOT\clsid\{ca0e28fa-1afd-4c21-a8dc-70eb5be2f076}
HKEY_CURRENT_USER\software\surfsidekick
HKEY_CURRENT_USER\software\surfsidekick2
HKEY_LOCAL_MACHINE\software\microsoft\surfsidekick3
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\surf sidekick_is1

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooks
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooks
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove SinCity Adware
Remove EXact.Advertising Adware
Remove Bancos.IEB Trojan

Kuaiso Adware

How To Remove Kuaiso?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Kuaiso is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


Kuaiso It also known as:

[Kaspersky]AdWare.Win32.Kuaiso.a,AdWare.Win32.Softomate.ak,AdWare.Win32.Mostofate.x,AdWare.Win32.Softomate.y;
[Other]Adware.Kuaiso,Eqiso

Kuaiso Symptoms:

Files:
[%SYSTEM%]\Kuaiso.exe
[%SYSTEM%]\Kuaiso.exe

Folders:
[%PROGRAM_FILES%]\Abobe Flash Play 9
[%PROGRAM_FILES%]\Abobe Flash Play9
[%PROGRAM_FILES%]\ËÑË÷À¸
[%PROGRAM_FILES%]\Kuaiso Toolsbar
[%PROGRAM_FILES%]\Micrsoft SearchBar

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{ca3eb689-8f09-4026-aa10-b9534c691ce0}
HKEY_CLASSES_ROOT\typelib\{77aa25e8-6083-4949-a831-9cb11861dc10}
HKEY_CURRENT_USER\software\xbtb03129
HKEY_CLASSES_ROOT\clsid\{33e640d8-eb95-4b22-b475-1852b7d35993}
HKEY_CLASSES_ROOT\clsid\{6029b367-250a-4696-925c-641709ca7381}
HKEY_CLASSES_ROOT\clsid\{72a7f654-0df2-4e24-8cc7-c32cabcbe3e7}
HKEY_CLASSES_ROOT\clsid\{8dd735fa-ed34-4948-9019-7703ac24ed43}
HKEY_CLASSES_ROOT\clsid\{b07d1f6b-6b8c-4904-8ee8-5e5a2b4624b3}
HKEY_CLASSES_ROOT\clsid\{bd328e49-38ab-42cb-8eea-73aa4cd2a6fd}
HKEY_CLASSES_ROOT\clsid\{df9c07b2-c8c1-4fea-b0fe-5e0709162b26}
HKEY_CLASSES_ROOT\clsid\{eec7e620-b32a-4e3b-b200-291660803474}
HKEY_CLASSES_ROOT\tbsb00889.ietoolbar
HKEY_CLASSES_ROOT\tbsb00889.tbsb00889
HKEY_CLASSES_ROOT\tbsb03263.ietoolbar
HKEY_CLASSES_ROOT\tbsb03263.ietoolbar.1
HKEY_CLASSES_ROOT\tbsb03263.tbsb03263
HKEY_CLASSES_ROOT\tbsb03263.tbsb03263.3
HKEY_CLASSES_ROOT\toolband.tbsb00889
HKEY_CLASSES_ROOT\typelib\{55a0b315-0920-4dc0-a9d7-46770e24816b}
HKEY_CLASSES_ROOT\typelib\{6307243a-cfb4-4807-9862-8093983c9b1a}
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser\{6d53adb7-6ad5-4a59-bfe4-7b57d2f4aa89}
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks\{cfbfae00-17a6-11d0-99cb-00c04fd64497}
HKEY_CURRENT_USER\software\tbsb00889
HKEY_CURRENT_USER\software\tbsb03263
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{6d53adb7-6ad5-4a59-bfe4-7b57d2f4aa89}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{df9c07b2-c8c1-4fea-b0fe-5e0709162b26}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6029b367-250a-4696-925c-641709ca7381}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{72a7f654-0df2-4e24-8cc7-c32cabcbe3e7}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8dd735fa-ed34-4948-9019-7703ac24ed43}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{b07d1f6b-6b8c-4904-8ee8-5e5a2b4624b3}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{eec7e620-b32a-4e3b-b200-291660803474}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xbtb03129.xbtb03129toolbar

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\tbsb03263.tbsb03263toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\tbsb03263.tbsb03263toolbar


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove SillyDl.DMS Downloader

SurfAccuracy Adware

How To Remove SurfAccuracy?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
SurfAccuracy is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.

This family of Trojans downloads and installs new malware or adware on the computer.
The downloader then either launches the new malware or registers it to enable autorun
according to the local operating system requirements.

The names and locations of malware to be downloaded are either coded into the
Trojan or downloaded from a specified website.


SurfAccuracy It also known as:

[Kaspersky]Trojan-Downloader.Win32.IstBar.oz,AdWare.Win32.SurfAccuracy.d;
[Other]Win32/SurfAccuracy.CFX,Adware.SurfAccuracy

SurfAccuracy Symptoms:

Files:
[%PROFILE_TEMP%]\ffcomponent.prod.v1000001.09fev2007.dll.d30d4a1b47483ec718ea41c66a8491c8
[%PROFILE_TEMP%]\SAcc.prod.v1148.01fev2006.exe.b27601ab4bce8e2f4658d8177fdb3ecf
[%PROFILE_TEMP%]\SAcc.prod.v1190.15fev2007.exe.acdec9dc7509ffcd5aeeb1e6095ec5b5
[%PROFILE_TEMP%]\uninstall.exe
[%PROFILE_TEMP%]\updater.exe
[%PROFILE_TEMP%]\updater.prod.V101168.04avr2007.exe.065faba332214522c7e10197726c0106
[%PROFILE_TEMP%]\updater.prod.V101168.18jan2007.exe.065faba332214522c7e10197726c0106
[%PROFILE_TEMP%]\updater.prod.V101168.26jan2007.exe.065faba332214522c7e10197726c0106
[%PROGRAM_FILES%]\Mozilla Firefox\components\ffcomponent.dll
[%PROGRAM_FILES%]\SurfAccuracy\SAcc.exe
[%WINDOWS%]\iwkyaenp.exe
[%PROFILE_TEMP%]\ffcomponent.prod.v1000001.09fev2007.dll.d30d4a1b47483ec718ea41c66a8491c8
[%PROFILE_TEMP%]\SAcc.prod.v1148.01fev2006.exe.b27601ab4bce8e2f4658d8177fdb3ecf
[%PROFILE_TEMP%]\SAcc.prod.v1190.15fev2007.exe.acdec9dc7509ffcd5aeeb1e6095ec5b5
[%PROFILE_TEMP%]\uninstall.exe
[%PROFILE_TEMP%]\updater.exe
[%PROFILE_TEMP%]\updater.prod.V101168.04avr2007.exe.065faba332214522c7e10197726c0106
[%PROFILE_TEMP%]\updater.prod.V101168.18jan2007.exe.065faba332214522c7e10197726c0106
[%PROFILE_TEMP%]\updater.prod.V101168.26jan2007.exe.065faba332214522c7e10197726c0106
[%PROGRAM_FILES%]\Mozilla Firefox\components\ffcomponent.dll
[%PROGRAM_FILES%]\SurfAccuracy\SAcc.exe
[%WINDOWS%]\iwkyaenp.exe

Folders:
[%PROGRAM_FILES%]\surfaccuracy

Registry Keys:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\sacc
HKEY_LOCAL_MACHINE\software\sacc

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Backdoor.AFN Trojan Removal
QQshou Trojan Removal
EraseFloppy Trojan Information

SunShineSpy Ransomware

How To Remove SunShineSpy?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
SunShineSpy is dangerous virus:
The term ransomware is commonly used to describe such software,
although the field known as cryptovirology predates the term "ransomware".

This type of ransom attack can be accomplished by (for example) attaching
a specially crafted file/program to an e-mail message and sending this to the victim.


SunShineSpy Symptoms:

Files:
[%DESKTOP%]\Sunshine Spy.lnk
[%STARTUP%]\SunshineSpy.lnk
[%DESKTOP%]\Sunshine Spy.lnk
[%STARTUP%]\SunshineSpy.lnk

Folders:
[%PROGRAMS%]\Sunshine Spy
[%PROGRAM_FILES%]\SunshineSpy

Registry Keys:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\sunshine spy 1.0
HKEY_LOCAL_MACHINE\software\wise solutions\wise installation system\repair\[%PROGRAM_FILES%]\sunshinespy\install.log\icons\1
HKEY_LOCAL_MACHINE\software\wise solutions\wise installation system\repair\[%PROGRAM_FILES%]\sunshinespy\install.log\icons\2

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\main


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
SheepGoat RAT Removal
Remove Nuclear Backdoor

Spy4PC Spyware

How To Remove Spy4PC?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Spy4PC is dangerous virus:
Spyware is computer software that is installed surreptitiously on a personal computer
to with the computer, without the user's informed consent.


Spy4PC Symptoms:

Files:
[%APPDATA%]\sfpc.dat
[%DESKTOP%]\Spy4pc Info.lnk
[%SYSTEM%]\msipv6.dll
[%SYSTEM%]\msudp.dll
[%SYSTEM%]\pppoe32.dll
[%SYSTEM%]\sfpc.chm
[%SYSTEM%]\sfpc.dat
[%SYSTEM%]\sfpc.exe
[%SYSTEM%]\sfpcinfo.exe
[%SYSTEM%]\WinPcap_3_1_beta_3.exe
[%APPDATA%]\sfpc.dat
[%DESKTOP%]\Spy4pc Info.lnk
[%SYSTEM%]\msipv6.dll
[%SYSTEM%]\msudp.dll
[%SYSTEM%]\pppoe32.dll
[%SYSTEM%]\sfpc.chm
[%SYSTEM%]\sfpc.dat
[%SYSTEM%]\sfpc.exe
[%SYSTEM%]\sfpcinfo.exe
[%SYSTEM%]\WinPcap_3_1_beta_3.exe

Folders:
[%PROGRAMS%]\SPY4PC
[%PROGRAM_FILES%]\SpYOuTSiDe

Registry Keys:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\currentchaos - sp0 -

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Bancos.HCY Trojan Removal
Removing Rewt Trojan
Removing Dream Trojan
Win32.Prodex Trojan Removal instruction
Removing Track4Win.Monitor Spyware

Beyond.telecom Adware

How To Remove Beyond.telecom?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Beyond.telecom is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.



Beyond.telecom Symptoms:

Folders:
[%PROGRAM_FILES%]\mpb\dialers

Registry Keys:
HKEY_CURRENT_USER\software\mpb\dialers
HKEY_CURRENT_USER\software\sym\dialers
HKEY_LOCAL_MACHINE\software\mpb\dialers
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\hotsexy_au
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\virgins_au

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing att.com Tracking Cookie
Delf.hf Backdoor Removal
SillyDl.CFO Downloader Removal

MicroBillSystems Adware

How To Remove MicroBillSystems?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
MicroBillSystems is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.



MicroBillSystems Symptoms:

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{d2fac024-92c0-42e5-a75b-7b4e3915cc50}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Admin.Basher Trojan Removal
Trojandownloader.win32.small.axo Trojan Removal instruction

RXToolbar Adware

How To Remove RXToolbar?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
RXToolbar is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


RXToolbar Symptoms:

Files:
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_closetabs.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_closetabs_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_closetabs_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_closetabs_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_download.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_download_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_download_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_download_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_messageuser.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_messageuser_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_messageuser_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_messageuser_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_newsearch.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_newsearch_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_newsearch_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_newsearch_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_searchuser.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_searchuser_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_searchuser_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_searchuser_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_showsearch.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_showsearch_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_showsearch_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_showsearch_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\trafficbar_resume.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\trafficbar_resume_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\trafficbar_resume_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\trafficbar_resume_sel.bmp
[%PROGRAM_FILES%]\rxtoolbar\CacheCatalog.rx
[%PROGRAM_FILES%]\rxtoolbar\CacheCatolog.rx
[%PROGRAM_FILES%]\rxtoolbar\graphics\additional.gif
[%PROGRAM_FILES%]\rxtoolbar\graphics\additional_active.gif
[%PROGRAM_FILES%]\rxtoolbar\graphics\background.jpg
[%PROGRAM_FILES%]\rxtoolbar\graphics\blue_hr_horz.GIF
[%PROGRAM_FILES%]\rxtoolbar\graphics\gray_hr_horz.GIF
[%PROGRAM_FILES%]\rxtoolbar\graphics\thumbtack.gif
[%PROGRAM_FILES%]\rxtoolbar\graphics\thumbtack_active.gif
[%PROGRAM_FILES%]\rxtoolbar\graphics\thumbtack_click.gif
[%PROGRAM_FILES%]\rxtoolbar\html\content.htm
[%PROGRAM_FILES%]\rxtoolbar\html\main.htm
[%PROGRAM_FILES%]\rxtoolbar\rx.xml
[%PROGRAM_FILES%]\rxtoolbar\rxtoolbar.cfg
[%PROGRAM_FILES%]\rxtoolbar\RXToolBar.dll
[%PROGRAM_FILES%]\rxtoolbar\rxwebsearches.xsl
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bKPack01.01.dat
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bKPack01.01.sig
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bKPack01.dat
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bKPack01.sig
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bLabels01.dat
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bLabels01.sig
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\CustomerSecret.Key
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\CustomerSecret.sig
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\nLabels01.dat
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\nLabels01.sig
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\SemanticInsight.dat
[%PROGRAM_FILES%]\RXToolBar\Semantic Insight\SemanticInsight.exe
[%PROGRAM_FILES%]\rxtoolbar\sfcont.bin
[%PROGRAM_FILES%]\rxtoolbar\sfcont.dll
[%PROGRAM_FILES%]\rxtoolbar\yahoo.xsl
[%WINDOWS%]\temp\adware\RXToolbar.exe
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_closetabs.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_closetabs_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_closetabs_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_closetabs_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_download.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_download_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_download_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_download_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_messageuser.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_messageuser_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_messageuser_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_messageuser_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_newsearch.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_newsearch_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_newsearch_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_newsearch_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_searchuser.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_searchuser_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_searchuser_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_searchuser_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_showsearch.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_showsearch_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_showsearch_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\searchbar_showsearch_sel.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\trafficbar_resume.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\trafficbar_resume_dis.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\trafficbar_resume_over.bmp
[%PROGRAM_FILES%]\Kazaa\Skins\Black Glass\trafficbar_resume_sel.bmp
[%PROGRAM_FILES%]\rxtoolbar\CacheCatalog.rx
[%PROGRAM_FILES%]\rxtoolbar\CacheCatolog.rx
[%PROGRAM_FILES%]\rxtoolbar\graphics\additional.gif
[%PROGRAM_FILES%]\rxtoolbar\graphics\additional_active.gif
[%PROGRAM_FILES%]\rxtoolbar\graphics\background.jpg
[%PROGRAM_FILES%]\rxtoolbar\graphics\blue_hr_horz.GIF
[%PROGRAM_FILES%]\rxtoolbar\graphics\gray_hr_horz.GIF
[%PROGRAM_FILES%]\rxtoolbar\graphics\thumbtack.gif
[%PROGRAM_FILES%]\rxtoolbar\graphics\thumbtack_active.gif
[%PROGRAM_FILES%]\rxtoolbar\graphics\thumbtack_click.gif
[%PROGRAM_FILES%]\rxtoolbar\html\content.htm
[%PROGRAM_FILES%]\rxtoolbar\html\main.htm
[%PROGRAM_FILES%]\rxtoolbar\rx.xml
[%PROGRAM_FILES%]\rxtoolbar\rxtoolbar.cfg
[%PROGRAM_FILES%]\rxtoolbar\RXToolBar.dll
[%PROGRAM_FILES%]\rxtoolbar\rxwebsearches.xsl
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bKPack01.01.dat
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bKPack01.01.sig
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bKPack01.dat
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bKPack01.sig
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bLabels01.dat
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\bLabels01.sig
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\CustomerSecret.Key
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\CustomerSecret.sig
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\nLabels01.dat
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\nLabels01.sig
[%PROGRAM_FILES%]\rxtoolbar\semantic insight\SemanticInsight.dat
[%PROGRAM_FILES%]\RXToolBar\Semantic Insight\SemanticInsight.exe
[%PROGRAM_FILES%]\rxtoolbar\sfcont.bin
[%PROGRAM_FILES%]\rxtoolbar\sfcont.dll
[%PROGRAM_FILES%]\rxtoolbar\yahoo.xsl
[%WINDOWS%]\temp\adware\RXToolbar.exe

Folders:
[%PROGRAM_FILES%]\rxtoolbar
[%PROGRAM_FILES%]\aaayoureweb

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{25d8bacf-3de2-4b48-ae22-d659b8d835b0}
HKEY_CLASSES_ROOT\clsid\{2ab289ae-4b90-4281-b2ae-1f4bb034b647}
HKEY_CLASSES_ROOT\clsid\{59879fa4-4790-461c-a1cc-4ec4de4ca483}
HKEY_CLASSES_ROOT\rxresult.rxresultfilter
HKEY_CLASSES_ROOT\rxresult.rxresultfilter.1
HKEY_CLASSES_ROOT\rxresult.rxresulttracker
HKEY_CLASSES_ROOT\rxresult.rxresulttracker.1
HKEY_CLASSES_ROOT\rxtoolbar.tbinfo
HKEY_CLASSES_ROOT\rxtoolbar.tbinfo.1
HKEY_CLASSES_ROOT\typelib\{05563f82-69a7-40a6-8670-153b635a7ef6}
HKEY_CLASSES_ROOT\typelib\{66b20295-dc57-42b6-acdf-52d916e86464}
HKEY_CURRENT_USER\software\rx toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{59879fa4-4790-461c-a1cc-4ec4de4ca483}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\RXToolBar
HKEY_LOCAL_MACHINE\software\rxresults
HKEY_CLASSES_ROOT\rxtoolbar.tbinfo rx toolbar
HKEY_CLASSES_ROOT\rxtoolbar.tbinfo.1 rx toolbar
HKEY_CURRENT_USER\software\aaayoureweb
HKEY_LOCAL_MACHINE\software\aaayoureweb
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar {25d8bacf-3de2-4b48-ae22-d659b8d835b0}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\rxtoolbar
HKEY_LOCAL_MACHINE\software\rtrmin

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\aaayoureweb toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\aaayoureweb toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\aaayoureweb toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\aaayoureweb toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\aaayoureweb toolbar


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Kilamp Trojan Removal instruction
Dyfuca.dm Downloader Symptoms

Cfow Trojan

How To Remove Cfow?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Cfow is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.


Cfow Symptoms:

Files:
[%PROFILE_TEMP%]\acsver.ini
[%PROFILE_TEMP%]\datacache.ini
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup16.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup32.dll
[%PROFILE_TEMP%]\acsver.ini
[%PROFILE_TEMP%]\datacache.ini
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup16.dll
[%PROFILE_TEMP%]\_istmp1.dir\_istmp0.dir\dsetup32.dll

Folders:
[%PROGRAM_FILES%]\sysai

Registry Keys:
HKEY_CLASSES_ROOT\Interface\{B548B7D8-3D03-4AED-A6A1-4251FAD00C10}


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing Iggsey Toolbar
JS.MS07 Trojan Removal
Removing QQ.Ambush RAT

Millenium Trojan

How To Remove Millenium?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Millenium is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Backdoors are used by virus writers to detect and download confidential information,
execute malicious code, destroy data, include the machine in bot networks and so forth.

Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.
They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,
and swap mouse buttons. However, they can be quite hard to remove.


Millenium It also known as:

[Kaspersky]Backdoor.Millenium.b,Backdoor.Millenium.a;
[McAfee]BackDoor-L;
[F-Prot]security risk or a "backdoor" program;
[Panda]Backdoor Program,Bck/Millenium.B,Backdoor Program.LC,Trj/Millenium;
[Computer Associates]Backdoor/Millenium_II!Client,Win32/ICQUpdater!Trojan,Backdoor/Millenium.VB!Server

Millenium Symptoms:

Files:
[%WINDOWS%]\system\hool.exe
[%WINDOWS%]\system\reg66.exe
[%WINDOWS%]\system\hool.exe
[%WINDOWS%]\system\reg66.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Omnilnet Hacker Tool Removal
Remove Tarzh Trojan
Vxidl.BAF Trojan Cleaner
Remove WinDuke Trojan
MSN.VB.ad DoS Removal