Friday, October 31, 2008

DesktopMedia Trojan

How To Remove Remove DesktopMedia?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
DesktopMedia is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


DesktopMedia It also known as:

[Kaspersky]Trojan-Downloader.Win32.Agent.ajf,AdWare.Win32.Dm.y,AdWare.Win32.Dm.e,Packed.Win32.Klone.e;
[McAfee]Adware-DesktopMedia;
[Other]Win32/SillyDl.ANJ,Win32/SillyDL.6mr!Trojan,Adware.DesktopMedia,DMCast,TROJ_DMSEC.A,Adware:Win32/DMCast

DesktopMedia Symptoms:

Files:
[%WINDOWS%]\813fb0e.exe
[%WINDOWS%]\813ib0e.exe
[%COMMON_STARTUP%]\IE-Bar.lnk
[%COMMON_STARTUP%]\×ÀÃ洫ý.lnk
[%PROFILE%]\Templates\93d0cab\1.dll
[%PROFILE%]\Templates\93d0cab\2.exe
[%PROFILE%]\Templates\93d0cab\3.dll
[%PROFILE%]\Templates\93d0cab\4.dll
[%PROFILE_TEMP%]\desktopmediasetup.exe
[%PROFILE_TEMP%]\fsprot.sys
[%PROFILE_TEMP%]\moprot.sys
[%PROFILE_TEMP%]\xxxxxx.exe
[%SYSTEM%]\409122.exe
[%SYSTEM%]\4822a73a\2ad73.exe
[%SYSTEM%]\4822a73a\2al73.dll
[%SYSTEM%]\4822a73a\2an73.dll
[%SYSTEM%]\4822a73a\2ar73.dll
[%SYSTEM%]\91dd2fa0.dll
[%SYSTEM%]\91di2fa.exe
[%SYSTEM%]\91do2fa0.dll
[%SYSTEM%]\drivers\fsprot.sys
[%SYSTEM%]\drivers\moprot.sys
[%SYSTEM%]\friendly.exe
[%SYSTEM%]\iebar.exe
[%SYSTEM%]\VIPTray.exe
[%SYSTEM%]\WinDefendor.dll
[%WINDOWS%]\Tasks\DM_Install_Program.job
[%WINDOWS%]\Temp\mssoak.exe
[%WINDOWS%]\813fb0e.exe
[%WINDOWS%]\813ib0e.exe
[%COMMON_STARTUP%]\IE-Bar.lnk
[%COMMON_STARTUP%]\×ÀÃ洫ý.lnk
[%PROFILE%]\Templates\93d0cab\1.dll
[%PROFILE%]\Templates\93d0cab\2.exe
[%PROFILE%]\Templates\93d0cab\3.dll
[%PROFILE%]\Templates\93d0cab\4.dll
[%PROFILE_TEMP%]\desktopmediasetup.exe
[%PROFILE_TEMP%]\fsprot.sys
[%PROFILE_TEMP%]\moprot.sys
[%PROFILE_TEMP%]\xxxxxx.exe
[%SYSTEM%]\409122.exe
[%SYSTEM%]\4822a73a\2ad73.exe
[%SYSTEM%]\4822a73a\2al73.dll
[%SYSTEM%]\4822a73a\2an73.dll
[%SYSTEM%]\4822a73a\2ar73.dll
[%SYSTEM%]\91dd2fa0.dll
[%SYSTEM%]\91di2fa.exe
[%SYSTEM%]\91do2fa0.dll
[%SYSTEM%]\drivers\fsprot.sys
[%SYSTEM%]\drivers\moprot.sys
[%SYSTEM%]\friendly.exe
[%SYSTEM%]\iebar.exe
[%SYSTEM%]\VIPTray.exe
[%SYSTEM%]\WinDefendor.dll
[%WINDOWS%]\Tasks\DM_Install_Program.job
[%WINDOWS%]\Temp\mssoak.exe

Folders:
[%APPDATA%]\clubmember\Cast
[%APPDATA%]\Desktop Media
[%PROGRAM_FILES%]\Desktop Media
[%PROGRAM_FILES%]\IE-BAR
[%PROGRAM_FILES_COMMON%]\IE-Bar

Registry Keys:
HKEY_LOCAL_MACHINE\software\clubmember
HKEY_CLASSES_ROOT\appid\{65ef7ad4-1340-4a36-a097-95ff17e243e1}
HKEY_CLASSES_ROOT\appid\{84d34084-4e38-4683-a4db-ca00646fee8b}
HKEY_CLASSES_ROOT\bhorun.bhelper
HKEY_CLASSES_ROOT\bhorun.bhelper.1
HKEY_CLASSES_ROOT\clsid\{16358834-52fc-4981-9a79-bfece7c08cd3}
HKEY_CLASSES_ROOT\clsid\{1fca37ba-7259-4bf1-878b-a39fa83bfbbb}
HKEY_CLASSES_ROOT\clsid\{5a6f2f95-3191-433b-8533-eb0b596a7bac}
HKEY_CLASSES_ROOT\clsid\{6a2ff9b4-c31c-4be8-86d4-4443b7411fe5}
HKEY_CLASSES_ROOT\clsid\{f2e37336-bfdb-409b-8d0e-6f013c438b20}
HKEY_CLASSES_ROOT\delayload.loadrun
HKEY_CLASSES_ROOT\delayload.loadrun.1
HKEY_CLASSES_ROOT\dmbar.dmbar
HKEY_CLASSES_ROOT\dmbar.dmbar.1
HKEY_CLASSES_ROOT\dmbho.browserhelper
HKEY_CLASSES_ROOT\dmbho.browserhelper.1
HKEY_CLASSES_ROOT\installer\features\71c455d361dea8443becf6cb15ff7b50
HKEY_CLASSES_ROOT\installer\products\71c455d361dea8443becf6cb15ff7b50
HKEY_CLASSES_ROOT\installer\upgradecodes\5db62e375a896f6408081040c15b769b
HKEY_CLASSES_ROOT\interface\{265379db-90f0-45db-9b10-640dcb1145fd}
HKEY_CLASSES_ROOT\interface\{7eb718dd-e41f-446a-9c1e-757f921168a0}
HKEY_CLASSES_ROOT\interface\{8c9377d3-d823-46a6-a8ac-b3913f9b6ca2}
HKEY_CLASSES_ROOT\typelib\{25649a6a-637d-4416-9d03-98146330492a}
HKEY_CLASSES_ROOT\typelib\{292d202f-e519-45f4-8d50-de8513b87ce9}
HKEY_CLASSES_ROOT\typelib\{86645afc-0b33-4275-bfe6-fae9fcd886d1}
HKEY_CURRENT_USER\software\desktop media
HKEY_CURRENT_USER\software\microsoft\internet explorer\explorer bars\{1fca37ba-7259-4bf1-878b-a39fa83bfbbb}
HKEY_LOCAL_MACHINE\software\desktop media
HKEY_LOCAL_MACHINE\software\dmshareware
HKEY_LOCAL_MACHINE\software\ie-bar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\explorer bars\{1fca37ba-7259-4bf1-878b-a39fa83bfbbb}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2d99e8f4-56b7-457b-9a92-61b5d247d263}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{f2e37336-bfdb-409b-8d0e-6f013c438b20}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ie-bar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{3d554c17-ed16-448a-b3ce-6fbc51ffb705}
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fsprot
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\moprot

Registry Values:
HKEY_CLASSES_ROOT\appid\bhorun.dll
HKEY_CLASSES_ROOT\appid\delayload.dll
HKEY_CLASSES_ROOT\clsid\{2d99e8f4-56b7-457b-9a92-61b5d247d263}
HKEY_CLASSES_ROOT\clsid\{2d99e8f4-56b7-457b-9a92-61b5d247d263}\inprocserver32
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\folders
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\upgradecodes\5db62e375a896f6408081040c15b769b
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing Bancos.FGE Trojan
Cuebot Trojan Cleaner
Remove Media.Tickets Spyware
Remove TrojanDownloader.Win32.Small.rn Downloader
FeaturedResults BHO Information

No comments: