Thursday, November 13, 2008

WeatherStudio Toolbar

How To Remove WeatherStudio?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
WeatherStudio is dangerous virus:
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.

WeatherStudio Symptoms:

Files:
[%COMMON_PROGRAMS%]\WeatherStudio Desktop.lnk
[%PROGRAM_FILES%]\WeatherStudio348\bin\WeatherStudio348.dll
[%PROGRAM_FILES%]\WeatherStudio348\icons\1524_icon.ico
[%PROGRAM_FILES%]\WeatherStudio348\WeatherStudio348Config.xml
[%PROGRAM_FILES%]\WeatherStudio348\WeatherStudio348Uninstall.exe
[%COMMON_PROGRAMS%]\WeatherStudio Desktop.lnk
[%PROGRAM_FILES%]\WeatherStudio348\bin\WeatherStudio348.dll
[%PROGRAM_FILES%]\WeatherStudio348\icons\1524_icon.ico
[%PROGRAM_FILES%]\WeatherStudio348\WeatherStudio348Config.xml
[%PROGRAM_FILES%]\WeatherStudio348\WeatherStudio348Uninstall.exe

Folders:
[%APPDATA%]\WeatherStudio Desktop
[%APPDATA%]\WeatherStudio348
[%PROGRAM_FILES%]\WeatherStudio Desktop

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{15757333-2bca-4b77-a807-d0955132f812}
HKEY_CLASSES_ROOT\clsid\{6f45aea2-9c81-4832-8390-7134102b8de5}
HKEY_CLASSES_ROOT\clsid\{7c2fc77a-af76-4a75-ac16-b02a13829f34}\implemented categories
HKEY_CLASSES_ROOT\clsid\{a7fde125-cebe-400e-8f4d-d2c0708b7d70}\implemented categories
HKEY_CLASSES_ROOT\clsid\{ffdd804f-a7f8-4395-93d2-66a85da2bdab}
HKEY_CURRENT_USER\software\weatherstudio348
HKEY_CURRENT_USER\software\weatherstudiodesktop
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6f45aea2-9c81-4832-8390-7134102b8de5}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ffdd804f-a7f8-4395-93d2-66a85da2bdab}

Registry Values:
HKEY_CLASSES_ROOT\clsid\{7c2fc77a-af76-4a75-ac16-b02a13829f34}\inprocserver32
HKEY_CLASSES_ROOT\clsid\{a7fde125-cebe-400e-8f4d-d2c0708b7d70}\inprocserver32
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\weatherstudio348
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\weatherstudio348
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\weatherstudio348
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\weatherstudio348


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

Boiling RAT

How To Remove Boiling?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Boiling is dangerous virus:
Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.
They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,
and swap mouse buttons. However, they can be quite hard to remove.


Boiling Symptoms:

Files:
[%WINDOWS%]\system\intranet.exe
[%WINDOWS%]\system\intranet.exe


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

RVP Adware

How To Remove RVP?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
RVP is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.

The downloader either launches the new malware or registers it to enable autorun
according to the local operating system requirements.


RVP Symptoms:

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

Desktop.Snooper Spyware

How To Remove Desktop.Snooper?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Desktop.Snooper is dangerous virus:
Spyware is computer software that is installed surreptitiously on a personal computer
to with the computer, without the user's informed consent.


Desktop.Snooper Symptoms:

Folders:
[%PROGRAM_FILES%]\MTI\Desktop Snooper

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{8294d950-5630-456b-96ce-5af0028d87d2}
HKEY_CURRENT_USER\msdesksn
HKEY_CURRENT_USER\software\mti\msdesksn


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

Rbot.aeu Worm

How To Remove Rbot.aeu?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Rbot.aeu is dangerous virus:
Worms can be classified according to the propagation method they use,
i.e. how they deliver copies of themselves to new victim machines.
Worms can also be classified by installation method, launch method and finally according
to characteristics standard to all malware: polymorphism, stealth etc.

Many of the worms which managed to cause significant outbreaks use more then
one propagation method as well as more than one infection technique.
The methods are listed separately below.


Rbot.aeu Symptoms:

Registry Values:
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

ZenoSearch Adware

How To Remove ZenoSearch?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
ZenoSearch is dangerous virus:
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits


ZenoSearch It also known as:

[Kaspersky]AdWare.Win32.ZenoSearch.o;
[McAfee]Adware-Zeno;
[Other]zenosearchassistant,Adware.ZenoSearch

ZenoSearch Symptoms:

Files:
[%DESKTOP%]\Click to Find and Fix Errors.url
[%PROFILE_TEMP%]\thinksnet.exe
[%STARTUP%]\TA_Start.lnk
[%STARTUP%]\Think-Adz.lnk
[%STARTUP%]\z_start.lnk
[%SYSTEM%]\bang-006.ico
[%SYSTEM%]\dwdsregt.exe
[%SYSTEM%]\dwdsrngt.exe
[%SYSTEM%]\msnav32.ax
[%SYSTEM%]\nt68rrtc12.sys
[%SYSTEM%]\winpfg32.sys
[%SYSTEM%]\winpfz32.sys
[%SYSTEM%]\zxdnt3d.cfg
[%WINDOWS%]\TIELT001.exe
[%WINDOWS%]\ZIFI002.exe
[%WINDOWS%]\zigi.exe
[%PROFILE_TEMP%]\T0CHD001.exe
[%SYSTEM%]\kldsrngm.exe
[%SYSTEM%]\kndsrngn.exe
[%SYSTEM%]\kndsrngp.exe
[%SYSTEM%]\kodsrngo.exe
[%SYSTEM%]\kqdsrngl.exe
[%SYSTEM%]\ksdsrngr.exe
[%SYSTEM%]\ljdsrngk.exe
[%SYSTEM%]\ljdsrngs.exe
[%SYSTEM%]\lkdsrngj.exe
[%SYSTEM%]\lldsrngp.exe
[%SYSTEM%]\lmdsrngl.exe
[%SYSTEM%]\lndsrego.exe
[%SYSTEM%]\lndsrngo.exe
[%SYSTEM%]\lrdsrngp.exe
[%SYSTEM%]\lsdsrngl.exe
[%SYSTEM%]\lsdsrngs.exe
[%SYSTEM%]\mjdsregk.exe
[%SYSTEM%]\mjdsregq.exe
[%SYSTEM%]\mmdsregl.exe
[%SYSTEM%]\mmdsregs.exe
[%SYSTEM%]\mndsregp.exe
[%SYSTEM%]\mqdsregk.exe
[%SYSTEM%]\mrdsregj.exe
[%SYSTEM%]\msdsregr.exe
[%SYSTEM%]\oldsregm.exe
[%SYSTEM%]\omdsregn.exe
[%SYSTEM%]\omdsrego.exe
[%SYSTEM%]\owinkmds.exe
[%SYSTEM%]\qwintlds.exe
[%DESKTOP%]\Click to Find and Fix Errors.url
[%STARTUP%]\zeno.lnk
[%SYSTEM%]\config\systemprofile\Start Menu\Programs\Startup\TA_Start.lnk
[%SYSTEM%]\config\systemprofile\Start Menu\Programs\Startup\Think-Adz.lnk
[%SYSTEM%]\mkdsregs.exe
[%SYSTEM%]\mwinnag.exe
[%SYSTEM%]\qsdsregm.exe
[%SYSTEM%]\qwinlndt.exe
[%SYSTEM%]\twintrag.exe
[%SYSTEM%]\twintres.exe
[%SYSTEM%]\twintrez.exe
[%DESKTOP%]\Click to Find and Fix Errors.url
[%PROFILE_TEMP%]\thinksnet.exe
[%STARTUP%]\TA_Start.lnk
[%STARTUP%]\Think-Adz.lnk
[%STARTUP%]\z_start.lnk
[%SYSTEM%]\bang-006.ico
[%SYSTEM%]\dwdsregt.exe
[%SYSTEM%]\dwdsrngt.exe
[%SYSTEM%]\msnav32.ax
[%SYSTEM%]\nt68rrtc12.sys
[%SYSTEM%]\winpfg32.sys
[%SYSTEM%]\winpfz32.sys
[%SYSTEM%]\zxdnt3d.cfg
[%WINDOWS%]\TIELT001.exe
[%WINDOWS%]\ZIFI002.exe
[%WINDOWS%]\zigi.exe
[%PROFILE_TEMP%]\T0CHD001.exe
[%SYSTEM%]\kldsrngm.exe
[%SYSTEM%]\kndsrngn.exe
[%SYSTEM%]\kndsrngp.exe
[%SYSTEM%]\kodsrngo.exe
[%SYSTEM%]\kqdsrngl.exe
[%SYSTEM%]\ksdsrngr.exe
[%SYSTEM%]\ljdsrngk.exe
[%SYSTEM%]\ljdsrngs.exe
[%SYSTEM%]\lkdsrngj.exe
[%SYSTEM%]\lldsrngp.exe
[%SYSTEM%]\lmdsrngl.exe
[%SYSTEM%]\lndsrego.exe
[%SYSTEM%]\lndsrngo.exe
[%SYSTEM%]\lrdsrngp.exe
[%SYSTEM%]\lsdsrngl.exe
[%SYSTEM%]\lsdsrngs.exe
[%SYSTEM%]\mjdsregk.exe
[%SYSTEM%]\mjdsregq.exe
[%SYSTEM%]\mmdsregl.exe
[%SYSTEM%]\mmdsregs.exe
[%SYSTEM%]\mndsregp.exe
[%SYSTEM%]\mqdsregk.exe
[%SYSTEM%]\mrdsregj.exe
[%SYSTEM%]\msdsregr.exe
[%SYSTEM%]\oldsregm.exe
[%SYSTEM%]\omdsregn.exe
[%SYSTEM%]\omdsrego.exe
[%SYSTEM%]\owinkmds.exe
[%SYSTEM%]\qwintlds.exe
[%DESKTOP%]\Click to Find and Fix Errors.url
[%STARTUP%]\zeno.lnk
[%SYSTEM%]\config\systemprofile\Start Menu\Programs\Startup\TA_Start.lnk
[%SYSTEM%]\config\systemprofile\Start Menu\Programs\Startup\Think-Adz.lnk
[%SYSTEM%]\mkdsregs.exe
[%SYSTEM%]\mwinnag.exe
[%SYSTEM%]\qsdsregm.exe
[%SYSTEM%]\qwinlndt.exe
[%SYSTEM%]\twintrag.exe
[%SYSTEM%]\twintres.exe
[%SYSTEM%]\twintrez.exe

Registry Keys:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\enhanced ads by think-adz
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\think-adz search assistant
HKEY_CLASSES_ROOT\clsid\{f55930ae-3d78-4250-8980-8740db242983}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\enhanced ads by zeno
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\zeno search assistant

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\enhanced ads by think-adz
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\enhanced ads by think-adz
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\think-adz search assistant
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\think-adz search assistant
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions\approved


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:

Spyboter.gen Backdoor

How To Remove Spyboter.gen?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Spyboter.gen is dangerous virus:
Backdoors are used by virus writers to detect and download confidential information,
execute malicious code, destroy data, include the machine in bot networks and so forth.



Spyboter.gen Symptoms:

Files:
[%SYSTEM%]\aolmsngr.exe
[%SYSTEM%]\zopytlrs.exe
[%SYSTEM%]\aolmsngr.exe
[%SYSTEM%]\zopytlrs.exe


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats: