Wednesday, January 28, 2009

Remote.Keylogger Spyware

How To Remove Remote.Keylogger?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Remote.Keylogger is dangerous virus:
Spyware is computer software that is installed surreptitiously on a personal computer
to with the computer, without the user's informed consent.
Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.



Remote.Keylogger Symptoms:

Files:
[%PROGRAM_FILES%]\AZPR\license.txt
[%PROGRAM_FILES%]\WinACE WinRAR WinZip WinISO + password & cracker\WinZIP\Password Recovery V3.54\license.txt
[%PROGRAM_FILES%]\AZPR\license.txt
[%PROGRAM_FILES%]\WinACE WinRAR WinZip WinISO + password & cracker\WinZIP\Password Recovery V3.54\license.txt

Folders:
[%COMMON_PROGRAMS%]\Remote KeyLogger
[%PROGRAMS%]\remote keylogger
[%PROGRAM_FILES%]\remote keylogger
[%PROGRAM_FILES_COMMON%]\remote keylogger\disk1

Registry Keys:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{3b0c7994-f456-4bcc-b3f0-49c35bfa8199}


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
P3 Adware Symptoms
IRC.Chamel DoS Symptoms
IESEARCHBAR Adware Symptoms
Bancos.HDZ Trojan Symptoms
Bancos.GQK Trojan Cleaner

AHS RAT

How To Remove AHS?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
AHS is dangerous virus:
Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.
They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,
and swap mouse buttons. However, they can be quite hard to remove.


AHS Symptoms:

Files:
[%WINDOWS%]\system\httpget.sys
[%WINDOWS%]\system\httpkhk.dll
[%WINDOWS%]\system\httpklg.sys
[%WINDOWS%]\system\httpget.sys
[%WINDOWS%]\system\httpkhk.dll
[%WINDOWS%]\system\httpklg.sys

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Bancos.HVD Trojan Information

TrojanDownloader.Win32.Agent Trojan

How To Remove TrojanDownloader.Win32.Agent?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
TrojanDownloader.Win32.Agent is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
This family of Trojans downloads and installs new malware or adware on the computer.
The downloader then either launches the new malware or registers it to enable autorun
according to the local operating system requirements.

The names and locations of malware to be downloaded are either coded into the
Trojan or downloaded from a specified website.
Exploits use vulnerabilities in operating systems and applications to achieve the same result.


TrojanDownloader.Win32.Agent It also known as:

[Kaspersky]TrojanProxy.Win32.Agent.q;
[Eset]Win32/TrojanProxy.Agent.Q trojan;
[Panda]Adware/Fuel,Adware/Nsupdate,Trj/Agent.E,Adware/SearchAid,Trj/Agent.O,Trj/Downloader.HO,Spyware/Virtumonde;
[Computer Associates]Win32.SuxxProxy.A,Win32/Mitglieder!Proxy!Trojan

TrojanDownloader.Win32.Agent Symptoms:

Files:
[%WINDOWS%]\mfcau.exe
[%WINDOWS%]\sdkxs32.exe
[%SYSTEM%]\winhost32.exe
[%WINDOWS%]\apirb32.exe
[%WINDOWS%]\javaos.exe
[%WINDOWS%]\msuj32.exe
[%WINDOWS%]\system\ipuw.exe
[%WINDOWS%]\mfcau.exe
[%WINDOWS%]\sdkxs32.exe
[%SYSTEM%]\winhost32.exe
[%WINDOWS%]\apirb32.exe
[%WINDOWS%]\javaos.exe
[%WINDOWS%]\msuj32.exe
[%WINDOWS%]\system\ipuw.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Mark Trojan Symptoms
SdBot.gen Worm Symptoms
Remove Stats.webtrendslive.Tracking.Cookie Tracking Cookie
Ieasis Ransomware Removal instruction

Super.Spider Trojan

How To Remove Super.Spider?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Super.Spider is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Hijackers are software programs that modify users' default browser home page,
search settings, error page settings, or desktop wallpaper without adequate notice, disclosure,
or user consent.

When the default home page is hijacked, the browser opens to the web page set by the hijacker
instead of the user's designated home page. In some cases, the hijacker may block users from
restoring their desired home page.

A search hijacker redirects search results to other pages and may
transmit search and browsing data to unknown servers. An error page hijacker directs
the browser to another page, usually an advertising page, instead of the usual error
page when the requested URL is not found.

A desktop hijacker replaces the desktop wallpaper with advertising
for products and services on the desktop.

Hijackers take control of various parts of your web browser, including your home page,
search pages, and search bar. They may also redirect you to certain sites should you
mistype an address or prevent you from going to a website they would rather you not,
such as sites that combat malware. Some will even redirect you to their own search engine
when you attempt a search. NB: hijackers almost exclusively target Internet Explorer.


Super.Spider It also known as:

[Kaspersky]Trojan.Win32.Krepper.g;
[Panda]Trojan Horse

Super.Spider Symptoms:

Registry Keys:
HKEY_CURRENT_USER\software\microsoft\internet explorer\vd
HKEY_CLASSES_ROOT\clsid\{93ed38ae-aebf-4c58-8758-501d6d56ffb5}
HKEY_CURRENT_USER\software\microsoft\internet explorer\cassandra
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{93ed38ae-aebf-4c58-8758-501d6d56ffb5}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\hd

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove Pigeon.AKV Trojan
Remove attack.against.Avirt.Mail.Server DoS
Bancos.GQU Trojan Removal instruction

ProcHide Trojan

How To Remove ProcHide?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
ProcHide is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.


ProcHide It also known as:

[Other]Win32/ProcHide.L,Hacktool.Rootkit

ProcHide Symptoms:

Files:
[%SYSTEM%]\ssipod1.sys
[%SYSTEM%]\ssipod1.sys

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ssipod1
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ssipod1


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove GenKart Trojan
Remove Pigeon.ELT Trojan
Removing EraseFloppy Trojan

VBS.BackdoorPing Trojan

How To Remove VBS.BackdoorPing?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
VBS.BackdoorPing is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
Often the backdoor will not be visible in the log of active programs.
DoS programs attack web servers by sending numerous requests to the specified server,
often causing it to crash under an excessive volume of requests.




VBS.BackdoorPing It also known as:

[Kaspersky]Backdoor.FlyAgent.a,Trojan.VBS.Lava,Trojan.Win32.VB.hs,TrojanDropper.DOS.Mypic,Backdoor.Netbus.160.a,Trojan.Win32.StartPage.ix,Trojan.BAT.Nonstop.a,TrojanDownloader.Win32.Small.al,TrojanDownloader.Win32.Turown.a,TrojanDownloader.Win32.Wintrim.az,TrojanDownloader.Win32.Wintrim.bu,TrojanDownloader.Win32.Agent.ad,TrojanDownloader.Win32.Wintrim.ba,Backdoor.Xeol.a,Trojan.VBS.Lamping,Backdoor.Thunk.e,Trojan.Win32.StartPage.np,Trojan-Downloader.Win32.IstBar.gen,Trojan.Win32.Small.i,TrojanProxy.Win32.Delf.h;
[Eset]Win32/Flyagent.A trojan,Mypic trojan,Win32/TrojanDownloader.Wintrim.BU trojan,Win32/TrojanDownloader.Agent.AD trojan,Win32/TrojanDownloader.Wintrim.BA trojan,IRC/Mimic.B trojan,Win32/Thunk.E trojan,Win32/TrojanDownloader.Wintrim.AC trojan;
[McAfee]NetBusPro.dr,Netbus,Bat/tf;
[F-Prot]destructive program,W32/NetBus.backdoor.567296;
[Panda]BAT/Muma,VBS/Trojan.Lava,Trj/NotepaDLL.A,Trj/DOS.Mypic,Trj/Passer.J,Trj/Netbus.160,Trj/StartPage.FH,Trojan Horse.LC,Adware/Look2Me,Dialer.LS,Dialer.B,Trj/Legmir.gen,Trj/StartPage.EB,Spyware/Omi,W32/Randon.CL.worm;
[Computer Associates]VBS/BackdoorPing!Trojan,VBS/BackdoorPing.Trojan,VBS.DoS.Soldier,Backdoor/FlyAgent,Win32.FlyAgent.A,VBS/Dome!Worm,VBS.Dome,Win32/DllFlood!Trojan,Win32.DllFlood.A,MyPics!Dropper,MyPics.Dropper,Bat/Flood.C!Trojan,BAT.IRCFlood,Backdoor/Netbus!Server,Win32.Netbus.160,Bat/Lameness!Trojan,BAT.Nonstop.A,Win32/SearchBar.sb!Downloader,Win32.Startpage.JK!downloader,Win32/StartPage.JG!DLL!Trojan,Win32.Startpage.JG,Win32/Wintrim.BU!Trojan,Win32.Wintrim.AO,Win32/Lemir.27220!DLL!Trojan,Win32.Lemir.BD,Win32/DlMersting.CG!Trojan,Win32.Startpage.FZ

VBS.BackdoorPing Symptoms:

Files:
[%PROFILE_TEMP%]\ICD1.tmp\SearchInstall3.exe
[%PROFILE_TEMP%]\ICD3.tmp\SearchInstall3.exe
[%SYSTEM%]\dailytoolbar.dll
[%SYSTEM%]\msedpb.exe
[%SYSTEM%]\x.bat
[%SYSTEM%]\___synmgr.exe
[%WINDOWS%]\Downloaded Program Files\OSD1C03.OSD
[%WINDOWS%]\___n.EXE
[%PROFILE_TEMP%]\ICD1.tmp\SearchInstall3.exe
[%PROFILE_TEMP%]\ICD3.tmp\SearchInstall3.exe
[%SYSTEM%]\dailytoolbar.dll
[%SYSTEM%]\msedpb.exe
[%SYSTEM%]\x.bat
[%SYSTEM%]\___synmgr.exe
[%WINDOWS%]\Downloaded Program Files\OSD1C03.OSD
[%WINDOWS%]\___n.EXE

Registry Keys:
HKEY_CLASSES_ROOT\appid\{951b3138-ae8e-4676-a05a-250a5f111631}
HKEY_CLASSES_ROOT\CLSID\{58F9B276-E1CC-458e-8159-21CBC021874B}
HKEY_CLASSES_ROOT\CLSID\{8333C319-0669-4893-A418-F56D9249FCA6}
HKEY_CLASSES_ROOT\dailytoolbar.ieband
HKEY_CLASSES_ROOT\dailytoolbar.sysmgr
HKEY_CLASSES_ROOT\ietoolbar.affiliatectl
HKEY_CLASSES_ROOT\interface\{10195311-e434-47a9-adba-48839e3f7e4e}
HKEY_CLASSES_ROOT\interface\{abafa0b4-f78d-42e5-8c31-1a441d01c1df}
HKEY_CURRENT_USER\software\nix solutions\dailytoolbar
HKEY_LOCAL_MACHINE\software\classes\clsid\{8333c319-0669-4893-a418-f56d9249fca6}
HKEY_LOCAL_MACHINE\SOFTWARE\DailyToolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\dailytoolbar
HKEY_LOCAL_MACHINE\software\nix solutions\dailytoolbar


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Fadieck Trojan Information
Removing QQuse Trojan
SogouPush Adware Removal instruction
Hupigon.nh Trojan Symptoms
Insurector Backdoor Cleaner

VB.hb Backdoor

How To Remove VB.hb?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
VB.hb is dangerous virus:
Backdoors combine the functionality of most other types of in one package.
Backdoors have one especially dangerous sub-class: variants that can propagate like worms.

Trojans-downloaders downloads and installs new malware or adware on the computer.



VB.hb Symptoms:

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Lemmings Trojan Symptoms