Thursday, December 4, 2008

Danmec Trojan

How To Remove Danmec?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Danmec is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.


Danmec It also known as:

[Kaspersky]Backdoor.Win32.Rbot.bkz,Trojan.Win32.Agent.xm,Trojan-Proxy.Win32.Agent.hx,Backdoor.Win32.Agent.aju,Trojan-Dropper.Win32.Small.aus,Backdoor.Win32.Agent.crk;
[F-Prot]W32/Proxy.JK;
[Other]Win32/Danmec!generic,Trojan.Proxy.RemLoad.B,Trojan.MulDrop.3098,W32.Mytob@mm,Win32/Danmec.F,Trojan.Danmec,W32/Agent.LDE,Troj/Agent-JV,Win32/Danmec.W,Troj/Danmec-V,Win32/Danmec.Y,Malware.BGBC,TROJ_DROPPER.KAP,Troj/Agent-GGA

Danmec Symptoms:

Files:
[%SYSTEM%]\aspimgr.exe
[%WINDOWS%]\s32.txt
[%WINDOWS%]\ws386.ini
[%SYSTEM%]\aspi183287.exe
[%WINDOWS%]\db32.txt
[%SYSTEM%]\aspimgr.exe
[%WINDOWS%]\s32.txt
[%WINDOWS%]\ws386.ini
[%SYSTEM%]\aspi183287.exe
[%WINDOWS%]\db32.txt

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_aspimgr
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aspimgr
HKEY_CURRENT_USER\software\microsoft\sft
HKEY_LOCAL_MACHINE\software\microsoft\sft
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_aspi113210
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aspi113210

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing VB.vh Backdoor
Sgfingerd Trojan Cleaner

EGroup Adware

How To Remove EGroup?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
EGroup is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


EGroup It also known as:

[Other]Adware.InstantAccess,eGroup

EGroup Symptoms:

Files:
[%SYSTEM%]\eglivecam_1028.dll
[%SYSTEM%]\ia.dll
[%SYSTEM%]\LiveService_5.dll
[%SYSTEM%]\mseggrpid.dll
[%WINDOWS%]\downloaded program files\egdhtml.inf
[%WINDOWS%]\downloaded program files\egdhtml_pack.inf
[%WINDOWS%]\downloaded program files\ia.inf
[%WINDOWS%]\downloaded program files\ieaccess2.inf
[%WINDOWS%]\tmlpcert2005
[%PROFILE%]\spesial.nils1\start-meny\instant access.lnk
[%SYSTEM%]\egdhtml_1017.dll
[%SYSTEM%]\egdhtml_1019.dll
[%SYSTEM%]\egdhtml_1021.dll
[%SYSTEM%]\egdial.dll
[%SYSTEM%]\eghtmldialer.dll
[%SYSTEM%]\liveservice_5.dll
[%WINDOWS%]\access.exe
[%WINDOWS%]\downloaded program files\eghtmldialer.inf
[%WINDOWS%]\start menu\instant access.lnk
[%WINDOWS%]\system\egdial.dll
[%WINDOWS%]\system\eghtmldialer.dll
[%SYSTEM%]\eglivecam_1028.dll
[%SYSTEM%]\ia.dll
[%SYSTEM%]\LiveService_5.dll
[%SYSTEM%]\mseggrpid.dll
[%WINDOWS%]\downloaded program files\egdhtml.inf
[%WINDOWS%]\downloaded program files\egdhtml_pack.inf
[%WINDOWS%]\downloaded program files\ia.inf
[%WINDOWS%]\downloaded program files\ieaccess2.inf
[%WINDOWS%]\tmlpcert2005
[%PROFILE%]\spesial.nils1\start-meny\instant access.lnk
[%SYSTEM%]\egdhtml_1017.dll
[%SYSTEM%]\egdhtml_1019.dll
[%SYSTEM%]\egdhtml_1021.dll
[%SYSTEM%]\egdial.dll
[%SYSTEM%]\eghtmldialer.dll
[%SYSTEM%]\liveservice_5.dll
[%WINDOWS%]\access.exe
[%WINDOWS%]\downloaded program files\eghtmldialer.inf
[%WINDOWS%]\start menu\instant access.lnk
[%WINDOWS%]\system\egdial.dll
[%WINDOWS%]\system\eghtmldialer.dll

Folders:
[%WINDOWS%]\eghtmldialer
[%WINDOWS%]\egroup
[%WINDOWS%]\dialpass

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{486e48b5-abf2-42bb-a327-2679df3fb822}
HKEY_CLASSES_ROOT\clsid\{b843da96-2b2d-447e-90ab-b92929aa11af}
HKEY_CLASSES_ROOT\eghtmldialer.htmldialer
HKEY_CLASSES_ROOT\eghtmldialer.htmldialer.1
HKEY_CLASSES_ROOT\interface\{62bfaec2-82a5-4117-a98b-fea89413d924}
HKEY_CLASSES_ROOT\interface\{81c2f7f3-f930-455e-9aa5-0876d387c787}
HKEY_CLASSES_ROOT\interface\{901166a5-f137-4b27-bc4c-ca611debdced}
HKEY_CLASSES_ROOT\typelib\{7699aef9-f83a-44fa-b374-aa02cedf247d}
HKEY_CURRENT_USER\software\egroup
HKEY_LOCAL_MACHINE\software\classes\clsid\{50ad557e-3426-41fd-afdd-2af39bb1c387}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{50AD557E-3426-41FD-AFDD-2AF39BB1C387}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:\windows\system32\egdhtml_1021.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\instant access
HKEY_CLASSES_ROOT\clsid\{2abe804b-4d3a-41bf-a172-304627874b45}
HKEY_CLASSES_ROOT\egdhtml.egdialhtml
HKEY_CLASSES_ROOT\egdhtml.egdialhtml.1
HKEY_CLASSES_ROOT\egdialobject.egdial
HKEY_CLASSES_ROOT\egdialobject.egdial.1
HKEY_CLASSES_ROOT\interface\{2f668a6d-2ec7-4e3a-a485-819e210738d6}
HKEY_CLASSES_ROOT\nsconfig.nsbrowserconfig.2
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{486e48b5-abf2-42bb-a327-2679df3fb822}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{50ad557e-3426-41fd-afdd-2af39bb1c387}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{94742e3f-d9a1-4780-9a87-2ffa43655da2}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{b843da96-2b2d-447e-90ab-b92929aa11af}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%SYSTEM%]\egdhtml_1021.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%SYSTEM%]\eghtmldialer.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]\system\egdhtml_1021.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]\system\eghtmldialer.dll
HKEY_USERS\.default\software\egdhtml

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/system32/eglivecam_1028.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%SYSTEM%]/eglivecam_1028.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%SYSTEM%]/eglivecam_1028.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/conflict.3/navinst2.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/conflict.3/navinst2.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls
HKEY_USERS\.default\remoteaccess\addresses
HKEY_USERS\.default\software\microsoft\windows\currentversion\wintrust\trust providers\software publishing\trust database\0


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Badpapots Downloader Removal instruction
Remove Alma Trojan
DeUpgrade Trojan Cleaner
Phantom.of.the.Keyboard Spyware Removal
Removing RemoteSaucer Backdoor

Aornum Adware

How To Remove Aornum?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Aornum is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.

As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.

Aornum Symptoms:

Files:
[%SYSTEM%]\i1srchas.dll
[%WINDOWS%]\aornidle.dll
[%WINDOWS%]\aornum.exe
[%WINDOWS%]\aornumax.dll
[%WINDOWS%]\system\i1srchas.dll
[%SYSTEM%]\i1srchas.dll
[%WINDOWS%]\aornidle.dll
[%WINDOWS%]\aornum.exe
[%WINDOWS%]\aornumax.dll
[%WINDOWS%]\system\i1srchas.dll

Folders:
[%PROGRAM_FILES%]\ornum

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{70522fa2-4656-11d5-b0e9-0050dac24e8f}
HKEY_CLASSES_ROOT\clsid\{08e1c8e1-e565-44fc-a766-c9539bb3abb7}
HKEY_CLASSES_ROOT\clsid\{910e7499-6311-4843-8eb0-0100a7955a1f}
HKEY_CLASSES_ROOT\clsid\{9c813b33-52a2-466d-8c51-eb4189c1ff98}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{08e1c8e1-e565-44fc-a766-c9539bb3abb7}
HKEY_CLASSES_ROOT\typelib\{08e1c8e1-e565-44fc-a766-c9539bb3abb7}
HKEY_CURRENT_USER\software\aornum
HKEY_CURRENT_USER\software\tensoft

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove KeyLog.Powered Spyware
Remove Pot Trojan
Removing Delf.av Trojan

Dimbus Backdoor

How To Remove Dimbus?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Dimbus is dangerous virus:
Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
Often the backdoor will not be visible in the log of active programs.
Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.
They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,
and swap mouse buttons. However, they can be quite hard to remove.


Dimbus It also known as:

[Kaspersky]Backdoor.Dimbus.10;
[Panda]Bck/Dimbus,Bck/Dimbus.10;
[Computer Associates]Backdoor/Dimbus.10!Server,Win32.Dimbus.10

Dimbus Symptoms:

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Danschl Trojan Removal instruction
Removing Zlob.Fam.Image ActiveX Object Trojan
XoloX Worm Symptoms

Nuvens Trojan

How To Remove Nuvens?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Nuvens is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


Nuvens It also known as:

[Kaspersky]Trojan-Dropper.Win32.Agent.aue,Trojan-Downloader.Win32.Zlob.aaz,Trojan-Downloader.Win32.Zlob.aua,Trojan-Downloader.Win32.Zlob.asf,Trojan-Downlaoder.Win32.Zlob.asd,Trojan-Downloader.Win32.Zlob.bed,Trojan-downloader.Win32.Zlob.bon,Trojan-Downloader.Win32.Zlob.drd;
[McAfee]Puper.dr;
[F-Prot]W32/Zlob.XA;
[Other]Win32/Nuvens.G,Win32/Nuvens.L,Win32/Nuvens.F,Win32/Nuevens.AG,Trojan.Emcodec,Win32/Nuvens.AM,Win32/Nuvens.AL,Win32/Nuvens.C,Trojan.Zlob,Win32/Nuvens.D,Win32.Nuvens.AS,W32/ZlobNS.gen9,Win32/Nuvens.AW,Win32/Nuvens.BD,Win32/Nuvens.AZ,Win32/Nuvens.BB,Win32/Nuvens.BI,Win32/Nuvens.BJ,Win32/Nuvens.BG,Win32/Nuvens.BH,Troj/Zlob-VP,TROJ_ZLOB.BEJ,Win32/Nuvens.U,Win32/Nuvens.CU,Trojan-Downloader.Zlob.Media-Codec,W32/Zlob.AEZS,Troj/Zlobun-Gen,Win32/Nuvens.CH,Win32/Nuvens.DA,Win32/Nuvens.DD,Win32/Nuvens.DE,Win32/Nuvens.DH,Win32/Nuvens.FW,Win32/Nuvens.FX,Win32/Nuvens.FZ,TROJ_ZLOB.DEM,Mal/Zlob-A,Win32/Nuvens.EH,DNSChanger.gen10,TROJ_ZLOB.DOB,Win32/Nuvens.PE,TrojanDownloader:Win32/Zlob.gen!dll,TROJ_ZLOB.EDH,Troj/Zlobar-Fam,Win32/Nuvens.PG,Win32/Nuvens.PH,Trojan:Win32/Zlob.ZWC,Troj/Zlob-AGJ,TrojanDownloader:Win32/Zlob.gen!AL

Nuvens Symptoms:

Files:
[%COMMON_DESKTOPDIRECTORY%]\Online Security Guide.url
[%COMMON_DESKTOPDIRECTORY%]\Security Troubleshooting.url
[%COMMON_STARTMENU%]\Online Security Guide.url
[%COMMON_STARTMENU%]\Security Troubleshooting.url
[%PROGRAM_FILES%]\AOL Toolbar\toolbar.dll
[%PROGRAM_FILES%]\PaintingRoom\paintingroomclasses.dll
[%PROGRAM_FILES%]\PCODEC\uninst.exe
[%PROGRAM_FILES%]\Video ActiveX Object\uninst.exe
[%SYSTEM%]\update26313404.exe
[%SYSTEM%]\vcodec.exe
[%DESKTOP%]\PornMag Pass.lnk
[%DESKTOP%]\PornPass Manager.lnk
[%SYSTEM%]\sttwrd.dll
[%COMMON_DESKTOPDIRECTORY%]\Online Security Guide.url
[%COMMON_DESKTOPDIRECTORY%]\Security Troubleshooting.url
[%COMMON_STARTMENU%]\Online Security Guide.url
[%COMMON_STARTMENU%]\Security Troubleshooting.url
[%PROGRAM_FILES%]\AOL Toolbar\toolbar.dll
[%PROGRAM_FILES%]\PaintingRoom\paintingroomclasses.dll
[%PROGRAM_FILES%]\PCODEC\uninst.exe
[%PROGRAM_FILES%]\Video ActiveX Object\uninst.exe
[%SYSTEM%]\update26313404.exe
[%SYSTEM%]\vcodec.exe
[%DESKTOP%]\PornMag Pass.lnk
[%DESKTOP%]\PornPass Manager.lnk
[%SYSTEM%]\sttwrd.dll

Folders:
[%PROGRAM_FILES%]\Gold Codec
[%PROGRAM_FILES%]\Image ActiveX Access
[%PROGRAM_FILES%]\IntCodec
[%PROGRAM_FILES%]\iVideoCodec
[%PROGRAM_FILES%]\MMediaCodec
[%PROGRAM_FILES%]\MPVIDEOCODEC
[%PROGRAM_FILES%]\Online Image Add-on
[%PROGRAM_FILES%]\paintingroom
[%PROGRAM_FILES%]\PornMag Pass
[%PROGRAM_FILES%]\PornPass Manager
[%PROGRAM_FILES%]\QualityCodec
[%PROGRAM_FILES%]\SoftCodec
[%PROGRAM_FILES%]\StrCodec
[%PROGRAM_FILES%]\Video ActiveX Access
[%PROGRAM_FILES%]\Video ActiveX Object
[%PROGRAM_FILES%]\VideoCompressionCodec
[%PROGRAM_FILES%]\VideoKeyCodec
[%PROGRAM_FILES%]\VideosCodec
[%PROGRAMS%]\Gold Codec
[%PROGRAMS%]\IntCodec
[%PROGRAMS%]\PornMag Pass
[%PROGRAMS%]\PornPass Manager
[%PROGRAM_FILES%]\Brain Codec

Registry Keys:
HKEY_CLASSES_ROOT\AVZipEnchancer.Chl
HKEY_CLASSES_ROOT\clsid\{fe8aca46-adf0-4785-b550-89762dc330e6}
HKEY_CLASSES_ROOT\codecssoftwarepackage.chl
HKEY_CLASSES_ROOT\emediacodek.chl
HKEY_CLASSES_ROOT\imageactivexobject.chl
HKEY_CLASSES_ROOT\interface\{e29be7f1-e2d8-4036-91ce-c3f8aac42495}
HKEY_CLASSES_ROOT\paintingroomclasses.animatedicon
HKEY_CLASSES_ROOT\paintingroomclasses.animatedicon.1
HKEY_CLASSES_ROOT\typelib\{979c2ead-48cb-454a-adfa-a123158dd508}
HKEY_CLASSES_ROOT\videoaxobject.chl
HKEY_CLASSES_ROOT\VSEnchancer.Chl
HKEY_CURRENT_USER\Software\Internet Security
HKEY_CURRENT_USER\Software\Online Add-on
HKEY_CURRENT_USER\software\paintingroom
HKEY_CURRENT_USER\Software\PornMag Pass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iVideoCodec
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MMediaCodec
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPVIDEOCODEC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\PornMag Pass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PornPass Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QualityCodec
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftCodec
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\strCodec
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Video ActiveX Object
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Video AX Object
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoCompressionCodec
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoKeyCodec
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideosCodec
HKEY_LOCAL_MACHINE\software\paintingroom
HKEY_CLASSES_ROOT\avzipenchancer.chl
HKEY_CLASSES_ROOT\clsid\{f0c5ef8b-f4bb-4612-9ea8-361fff3da3d5}
HKEY_CLASSES_ROOT\imageactivexobject
HKEY_CLASSES_ROOT\videoaccessactivex.chl
HKEY_CLASSES_ROOT\vsenchancer.chl
HKEY_CURRENT_USER\software\online add-on
HKEY_CURRENT_USER\software\pornmag pass
HKEY_CURRENT_USER\software\\internet security
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\brain codec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\image activex solution
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ivideocodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\mmediacodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\mpvideocodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pornmag pass
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pornpass manager
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\qualitycodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\softcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\strcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\video activex object
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\video add-on
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\video ax object
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\videocompressioncodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\videokeycodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\videoscodec

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_CURRENT_USER\software\security tools
HKEY_CURRENT_USER\software\security tools
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\intcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\pcodec


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Lufoure Trojan Information

Aboutblank Trojan

How To Remove Aboutblank?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Aboutblank is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Backdoors are used by virus writers to detect and download confidential information,
execute malicious code, destroy data, include the machine in bot networks and so forth.

When the default home page is hijacked, the browser opens to the web page set by the hijacker
instead of the user's designated home page. In some cases, the hijacker may block users from
restoring their desired home page.


Aboutblank It also known as:

[Kaspersky]Backdoor.Agent.ac,Trojan.Win32.StartPage.ix;
[Eset]Win32/Agent.AC trojan,Win32/StartPage.IX trojan;
[Panda]Bck/Agent.E,Trj/StartPage.FH;
[Computer Associates]Win32.Mersting.B,Win32.Startpage.FZ,Win32/DlMersting.BA.30720!Trojan,Win32/Mersting.B!DLL!Trojan

Aboutblank Symptoms:

Files:
[%WINDOWS%]\svhost.exe
[%PROGRAM_FILES%]\ISSS\ZILLAbar\ZILLAbar.dll
[%SYSTEM%]\jjjhk.dll
[%SYSTEM%]\newkh.dll
[%SYSTEM%]\rzwqb.dll
[%WINDOWS%]\ausjn.dll
[%SYSTEM%]\cbme.dll
[%SYSTEM%]\xea2108l.9zt
[%WINDOWS%]\system\achpjba.dll
[%WINDOWS%]\system\wdm.dll
[%WINDOWS%]\svhost.exe
[%PROGRAM_FILES%]\ISSS\ZILLAbar\ZILLAbar.dll
[%SYSTEM%]\jjjhk.dll
[%SYSTEM%]\newkh.dll
[%SYSTEM%]\rzwqb.dll
[%WINDOWS%]\ausjn.dll
[%SYSTEM%]\cbme.dll
[%SYSTEM%]\xea2108l.9zt
[%WINDOWS%]\system\achpjba.dll
[%WINDOWS%]\system\wdm.dll

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{06abaa2d-34ab-4902-a326-409bd9b9a7a5}
HKEY_CLASSES_ROOT\clsid\{b664647f-efd5-4837-a810-a807139107e5}
HKEY_CLASSES_ROOT\clsid\{ce6a1268-9cc9-4ba3-8657-fe1132906cc4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{b664647f-efd5-4837-a810-a807139107e5}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search
HKEY_CLASSES_ROOT\protocols\filter\text/html
HKEY_CLASSES_ROOT\protocols\filter\text/plain
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
BrowserAid.SearchandClick BHO Removal instruction

Win.Spy Spyware

How To Remove Win.Spy?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Win.Spy is dangerous virus:
Spyware is computer software that is installed surreptitiously on a personal computer
to intercept or take partial control over the user's interaction
with the computer, without the user's informed consent.

While the term spyware suggests software that secretly monitors the user's behavior,
the functions of spyware extend well beyond simple monitoring.

Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.

Spyware can even change computer settings, resulting in slow connection speeds,
different home pages, and loss of Internet or other programs.
In an attempt to increase the understanding of spyware, a more formal classification
of its included software types is captured under the term privacy-invasive software.
Hacker Tools are designed to penetrate remote computers
in order to use them as zombies or to download other malicious programs to computer.


Win.Spy Symptoms:

Files:
[%WINDOWS%]\winsys.exe
[%WINDOWS%]\winsys.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
SpyAxe Trojan Removal
Pigeon.AJM Trojan Cleaner