Tuesday, November 11, 2008

SillyDl.DNU Trojan

How To Remove SillyDl.DNU?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
SillyDl.DNU is dangerous virus:
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.


SillyDl.DNU Symptoms:

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

StartPage.aba Hijacker

How To Remove StartPage.aba?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
StartPage.aba is dangerous virus:
A desktop hijacker replaces the desktop wallpaper with advertising
for products and services on the desktop.


StartPage.aba Symptoms:

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

Comet.DMServer Downloader

How To Remove Comet.DMServer?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Comet.DMServer is dangerous virus:
Trojans-downloaders downloads and installs new malware or adware on the computer.



Comet.DMServer It also known as:

[Kaspersky]TrojanDownloader.Win32.Comet;
[Panda]Adware/Comet

Comet.DMServer Symptoms:

Folders:
[%PROGRAM_FILES%]\comets~1

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

Teen.Searchbar Toolbar

How To Remove Teen.Searchbar?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Teen.Searchbar is dangerous virus:
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.


Teen.Searchbar Symptoms:

Files:
[%SYSTEM%]\chat.dat
[%SYSTEM%]\home.dat
[%SYSTEM%]\pics.dat
[%SYSTEM%]\videos.dat
[%SYSTEM%]\ezines.dat
[%SYSTEM%]\IdentLibDll.dll
[%SYSTEM%]\paysites.dat
[%SYSTEM%]\srchbar.dll.manifest
[%SYSTEM%]\chat.dat
[%SYSTEM%]\home.dat
[%SYSTEM%]\pics.dat
[%SYSTEM%]\videos.dat
[%SYSTEM%]\ezines.dat
[%SYSTEM%]\IdentLibDll.dll
[%SYSTEM%]\paysites.dat
[%SYSTEM%]\srchbar.dll.manifest

Registry Keys:
HKEY_CLASSES_ROOT\typelib\{15e7d23b-736e-46fa-bffd-cbec4126befd}
HKEY_CLASSES_ROOT\typelib\{edd6ba23-9ebb-11d2-b89c-00104b30757b}
HKEY_CLASSES_ROOT\typelib\{7c9e9a74-1922-409e-ab46-e48784336c3a}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\search bar


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

Xupiter.SearchSquire BHO

How To Remove Xupiter.SearchSquire?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Xupiter.SearchSquire is dangerous virus:
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.A Search hijacker redirects search results to other pages and may
transmit search and browsing data to unknown servers. An error page hijacker directs
the browser to another page, usually an advertising page, instead of the usual error
page when the requested URL is not found.


Xupiter.SearchSquire It also known as:

[Panda]Adware/SearchSquire

Xupiter.SearchSquire Symptoms:

Files:
[%WINDOWS%]\Downloaded Program Files\SearchSquire33.inf
[%SYSTEM%]\searchsquire.dll
[%SYSTEM%]\searchsquire2.dll
[%SYSTEM%]\searchupdate33.dll
[%SYSTEM%]\searchupdate33.exe
[%WINDOWS%]\system\searchsquire.dll
[%WINDOWS%]\system\searchsquire2.dll
[%WINDOWS%]\system\searchupdate33.dll
[%WINDOWS%]\Downloaded Program Files\SearchSquire33.inf
[%SYSTEM%]\searchsquire.dll
[%SYSTEM%]\searchsquire2.dll
[%SYSTEM%]\searchupdate33.dll
[%SYSTEM%]\searchupdate33.exe
[%WINDOWS%]\system\searchsquire.dll
[%WINDOWS%]\system\searchsquire2.dll
[%WINDOWS%]\system\searchupdate33.dll

Folders:
[%PROGRAM_FILES_COMMON%]\sq
[%PROGRAM_FILES%]\common files\sq

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{907ca0e5-ce84-11d6-9508-02608cdd2846}
HKEY_CLASSES_ROOT\interface\{b8cfdc9e-e634-40e3-a51e-c097f23d53b9}
HKEY_LOCAL_MACHINE\software\classes\clsid\{907ca0e5-ce84-11d6-9508-02608cdd2846}
HKEY_CLASSES_ROOT\clsid\{11990e9f-2a4d-11d6-9507-02608cdd2842}
HKEY_CLASSES_ROOT\clsid\{907ca0e5-ce84-11d6-9508-02608cdd2841}
HKEY_CLASSES_ROOT\clsid\{907ca0e5-ce84-11d6-9508-02608cdd2842}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{11990e9f-2a4d-11d6-9507-02608cdd2842}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{907ca0e5-ce84-11d6-9508-02608cdd2841}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{907ca0e5-ce84-11d6-9508-02608cdd2842}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{907ca0e5-ce84-11d6-9508-02608cdd2846}
HKEY_CLASSES_ROOT\typelib\{805af2c8-98c7-4f3c-a7c9-25ebf27567f3}
HKEY_LOCAL_MACHINE\software\classes\clsid\{11990e9f-2a4d-11d6-9507-02608cdd2842}
HKEY_LOCAL_MACHINE\software\classes\clsid\{907ca0e5-ce84-11d6-9508-02608cdd2841}
HKEY_LOCAL_MACHINE\software\classes\clsid\{907ca0e5-ce84-11d6-9508-02608cdd2842}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{11990e9f-2a4d-11d6-9507-02608cdd2842}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{907ca0e5-ce84-11d6-9508-02608cdd2841}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{907ca0e5-ce84-11d6-9508-02608cdd2842}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{907ca0e5-ce84-11d6-9508-02608cdd2846}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

VIP.NetLink BHO

How To Remove VIP.NetLink?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
VIP.NetLink is dangerous virus:
BHO (Browser Helper Object) Trojan.
The BHO waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
The method of network transport used by the attacker makes this Trojan unique.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.
Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into
the data section of an ICMP ping packet." explained the company.
Hijackers are software programs that modify users' default browser home page,
search settings, error page settings, or desktop wallpaper without adequate notice, disclosure,
or user consent.


VIP.NetLink Symptoms:

Folders:
[%PROGRAM_FILES%]\vipnetlink

Registry Keys:
HKEY_CURRENT_USER\software\vip netlink browser
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\vip netlink_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\vip netlink_is1
HKEY_LOCAL_MACHINE\software\vip netlink
HKEY_LOCAL_MACHINE\software\vipnetlink


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

ExtraToolbar Toolbar

How To Remove ExtraToolbar?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
ExtraToolbar is dangerous virus:
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.

ExtraToolbar Symptoms:

Folders:
[%PROGRAM_FILES%]\Online Casino Extra Toolbar

Registry Keys:
HKEY_CLASSES_ROOT\CLSID\{C49DD894-C6DE-4910-8C41-BA20F852D8BC}
HKEY_CLASSES_ROOT\clsid\{2d2962d0-aaf4-4477-a4b8-32f63e2906d9}
HKEY_CLASSES_ROOT\clsid\{c49dd894-c6de-4910-8c41-ba20f852d8bc}
HKEY_CLASSES_ROOT\toolband.xbtp07018
HKEY_CLASSES_ROOT\typelib\{e6ec8b58-f91c-4b09-a30c-2e2a20579e34}
HKEY_CLASSES_ROOT\xbtb07018.ietoolbar
HKEY_CLASSES_ROOT\xbtb07018.ietoolbar.1
HKEY_CLASSES_ROOT\xbtb07018.xbtb07018
HKEY_CLASSES_ROOT\xbtb07018.xbtb07018.1
HKEY_CURRENT_USER\software\xbtb07018
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{c49dd894-c6de-4910-8c41-ba20f852d8bc}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2d2962d0-aaf4-4477-a4b8-32f63e2906d9}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xbtb07018.xbtb07018too23423lbar

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats: