Monday, February 21, 2011

How to Remove Internet Security Essentials (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Internet Security Essentials is a rogue antivirus program which acts like a real virus scanner, searching your computer for malicious software and viruses. After the fake scan, it claims to have detected Trojans, spyware, adware and other malware to make you think that your computer is infected. Then Internet Security Essentials prompts you to pay a small fee to remove the threats which do not even exist. There's no trustworthy company behind it, so you shouldn't purchase it. Besides, it gives a false sense of security. Not to mention that it won't remove any infections from your computer. What is more, Internet Security Essentials is promoted through the use of fake online scanners, drive-by downloads and other malicious software. It is not a legal and truly legitimate anti-virus. If you somehow ended up with this rogue AV on your computer, please follow the steps in the removal guide below to remove Internet Security Essentials and any related malware for free.



Internet Security Essentials is a re-branded version of Smart Internet Protection 2011 rogueware. What does this rogue program actually do? It just copies several random files into the %UserProfile% directory and then "flags" those files as malware. Some of the files that can be listed as malicious software: PE.exe, DBOLE.exe, CLSV.tmp, kernel32.exe, std.dll, grid.sys. Furthermore, Internet Security Essentials changes your Windows settings to use a proxy server that will not allow you to browse any or certain web pages. It also modifies Windows Hosts files and may even block other programs on your computer. Last, but not least, Internet Security Essentials displays fake security warnings and notifications saying that your computer is infected with dangerous malware or under attack from a remote computer.
Attention! 20 infected files detected!
Trojan.BAT.AnitV.a
Packed.Win32.PolyCrypt
SpamTool.Win32.Delf.h
Trojan-PSW.Win32.Hooker
Warning! Identity theft attempt detected
Target: Microsoft Corporation keys
System alert
Internet Security Essentials has detected potentially harmful software in your system. It is strongly recommended that you register Internet Security Essentials to remove all found threats immediately.
As you can see, Internet Security Essentials is a scam. You should not purchase it, and if you have, please contact your credit card company and dispute the charges. To remove Internet Security Essentials and any related malware, please follow the removal instructions below. Let me know if you have any questions, comments, or suggestions. You can leave a message using the contact form below. Good luck and be safe online!


Internet Security Essentials removal instructions:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Launch Internet Explorer. In Internet Explorer go to: Tools->Internet Options->Connections tab. Click Lan Settings button and uncheck the checkbox labeled Use a proxy server for your LAN. Click OK. You may have to repeat steps 1-2 if you will have problems downloading malware removal programs.



3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Alternate Internet Security Essentials removal instructions using HijackThis or Process Explorer (in Normal mode):

1. Launch Internet Explorer. In Internet Explorer go to: Tools->Internet Options->Connections tab. Click Lan Settings button and uncheck the checkbox labeled Use a proxy server for your LAN. Click OK.



2. Download Process Explorer.
3. Rename procexp.exe to iexplore.exe and run it. Look for similar process in the list and end it:
  • FN43g_392.exe
OR download iexplore.exe (NOTE: iexplore.exe file is renamed HijackThis tool from TrendMicro).
Launch the iexplore.exe and click "Do a system scan only" button.
If you can't open iexplore.exe file then download explorer.scr and run it. Search for similar entries in the scan results:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:18392
O4 - HKCU\..\Run: [Internet Security Essentials] "C:\Documents and Settings\All Users\Application Data\38gdr2\FN43g_392.exe" /s /d
Select all similar entries and click once on the "Fix checked" button. Close HijackThis tool.

4. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Internet Security Essentials associated files and registry values:

Files:
  • C:\Documents and Settings\All Users\Application Data\38gdr2\
  • C:\Documents and Settings\All Users\Application Data\38gdr2\FN43g_392.exe
  • C:\Documents and Settings\All Users\Application Data\38gdr2\[SET OF RANDOM CHARACTERS].dll
  • C:\Documents and Settings\All Users\Application Data\38gdr2\[SET OF RANDOM CHARACTERS].ocx
  • C:\Documents and Settings\All Users\Application Data\SMEYFE
  • %UserProfile%\Application Data\Internet Security Essentials\
%UserProfile% refers to:
C:\Documents and Settings\[UserName] (for Windows 2000/XP)
C:\Users\[UserName]\ (for Windows Vista & Windows 7)

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:18392"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Internet Security Essentials"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options "Debugger" = "svchost.exe"
Share this information with other people:

Thursday, February 10, 2011

How to Remove AntiVira Av (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
AntiVira Av is a rogue anti-virus program that demands money to clean up the non-existent infections. It uses malware to advertise and install itself. Usually, users get scary pop-ups that look just like legitimate security warnings while surfing the web. Cyber-criminals rely of fear tactics to dupe users into installing AntiVira Av. Spam is also an easy way to advertise rogue security software. Once installed, this fake anti-virus tries to convince you that computer is at risk or infected with spyware, Trojans and other malicious software. Anti Vira Av disables legitimate security software and blocks malware removal tools saying that they are infected. The rogue program hijacks Internet Explorer. It displays fake security warnings and notifications about critical system infections and dangerous attack from a remote computer. These alerts are all fake, of course. AntiVira Av pressures you to purchase software that actually won't protect you and won't remove threats from your PC. Hopefully, you can use real anti-malware applications to remove AntiVira Av and related malware from your computer. We've got the removal instructions to help you to remove this scareware for free. Please follow the steps in the removal guide below.



AntiVira Av is a copy of Antivirus .NET. It changes LAN settings and configures your computer to use a proxy server that displays a fake security warning instead of requested website. The rogue program will also randomly open web pages containing explicit/adult content.
Internet Explorer Warning - visiting this web site may harm your computer!
Most likely causes:
- The website contains exploits that can launch a malicious code on your computer
- Suspicious network activity detected
- There might be an active spyware running on your computer


Here are some of the fake security alerts that you will probably see if your computer gets infected with AntiVira Av:
Antivirus software alert. Virus attack!
Your computer is being attacked by an internet virus. It could be a password-stealing attack, a trojan-dropper or similar.
Threat: Win32/Nuqel.E
Do you want to block this attack?

Windows Security Alert
Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats.


When the rogue terminates the program it displays the following error message:
Security Alert
Virus Alert!
Application can't be started! The file [program_name].exe is damaged. Do you want to activate your antivirus software now?


AntiVira Av related websites: poprog.net, shopllbo.com. The fake av redirects users to one of these websites to purchase a license of AntiVira Av. As you can see, there are three versions of this malware: AntiVira Av Limited, AntiVira Av Plus and AntiVira Av Full. Thesafepc.com is also related to this fraud.



Antivira Av runs from your Temp folder. It's a single, randomly named file in a randomly named folder. In order to remove this rogue security from your computer you will have to restart your computer in safe mode with networking, disable a proxy server and download malware removal tool. For more information, please follow the removal instructions below. If you do get duped into installing this rogue program, don't panic. And do not hand over any money. If you have already purchased it, please contact your credit card company and dispute the charges. If you need help removing Antivira Av, please a comment. Look out for this piece of malware. Good luck and be safe online!


AntiVira Av removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Launch Internet Explorer. In Internet Explorer go to: Tools->Internet Options->Connections tab. Click Lan Settings button and uncheck the checkbox labeled Use a proxy server for your LAN. Click OK.



3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe, explorer.exe or winlogon.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Alternate AntiVira Av removal instructions using HijackThis (in Normal mode):

1. Download iexplore.exe (NOTE: iexplore.exe file is renamed HijackThis tool from TrendMicro).
Launch the iexplore.exe and click "Do a system scan only" button.
If you can't open iexplore.exe file then download explorer.scr and run it.

2. Search for such entry in the scan results:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:52371
O4 - HKCU\..\Run: [SET OF RANDOM CHARACTERS] %Temp%\[SET OF RANDOM CHARACTERS]\[SET OF RANDOM CHARACTERS].exe e.g. hdrwpsjf38shef.exe

Select all similar entries and click once on the "Fix checked" button. Close HijackThis tool.

OR you may download Process Explorer and end AntiVira Av process:
  • [SET OF RANDOM CHARACTERS].exe, e.g. hdrwpsjf38shef.exe
3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe, explorer.exe or winlogon.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Associated AntiVira Av files and registry values:

Files:
  • %Temp%\[SET OF RANDOM CHARACTERS]\
  • %Temp%\[SET OF RANDOM CHARACTERS]\[SET OF RANDOM CHARACTERS].exe
%Temp% refers to:
C:\Documents and Settings\[UserName]\Local Settings\Temp (in Windows 2000/XP)
C:\Users\[UserName]\AppData\Local\Temp (in Windows Vista & Windows 7)

Registry values:
  • HKEY_CURRENT_USER\Software\[SET OF RANDOM CHARACTERS]
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ''
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = 'http=127.0.0.1:52371'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
Share this information with other people:

Wednesday, February 9, 2011

How to Remove WhiteSmoke Translator (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
A few days ago we received an email from our friend explaining that a program called WhiteSmoke Translator mysteriously appeared on his computer and he doesn't know how to get rid of it. After a fair bit of research, we learned that WhiteSmoke Translator is "an all-new application that enables you to take any text from any text-based application, and automatically translate it into a destination language". We also found many complains about this program on popular tech support forums. Finally, we found a sample of a Trojan (MD5: c5a4a504e73fda80390b630643d580b9) that drops WhiteSmoke Translator and some other adware/malware onto your computer without your consents. Whitesmoke Translator appeared on our computer along with several new desktop icons including one called "Improve Your PC" which pointed to a web page promoting Uniblue RegistryBooster 2011. We installed this software on your test machine too. It found 81 moderate registry errors. We were prompted to change our default search provider to whitesmokestart.com in Internet Explorer. If you somehow ended up with this misleading application on your computer, please follow the steps in the removal guide below to remove WhiteSmoke Translator and any related malware for free.

WhiteSmoke Translator hides translated words behind its advertisements. You have to close advertisements to see the translation which is kind of annoying.



Unlike other adware or potentially unwanted applications, WhiteSmoke Translator can be removed using the Add/Remove Programs control panel. However, we got an error on attempt to uninstall this program saying that some of the files are locked by rundll32.exe process. We had to end the process in order to uninstall this program.



WhiteSmoke Translator and Uniblue RegistryBooster 2011 icons:



The user is prompted to change the default search provider or keep using Bing. Please see how misleading it looks "Change to Yahoo (www.whitesmokestart.com)".





"Improve Your PC" icon links to a web page where you can download Uniblue RegistryBooster 2011.



Such software distribution methods are unacceptable. If you got with this malware, please scan your computer with anti-malware software. To remove WhiteSmoke Translator, please follow the removal instructions below. Let me know if you need any help with malware. Just leave a comment. Good luck and be safe online!


WhiteSmoke Translator removal instructions:

Download recommended anti-malware software and run a full system scan to remove this adware from your computer.

It's possible that an infection is blocking anti-malware software from properly installing. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe. Don't forget to update the installed program before scanning.


Associated WhiteSmoke Translator files and registry values:

Files:
  • C:\Documents and Settings\All Users\Desktop\Launch WhiteSmoke Translator.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\WhiteSmoke Translator\Registration.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\WhiteSmoke Translator\Uninstall.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\WhiteSmoke Translator\WhiteSmoke Translator.lnk
  • C:\Program Files\Whitesmoke Translator
Registry values:
  • HKEY_CURRENT_USER\Software\WhiteSmokeTranslator
  • HKEY_LOCAL_MACHINE\SOFTWARE\WhiteSmokeTranslator
Share this information with other people:

Wednesday, February 2, 2011

How to Remove McAVG 2011 (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
McAVG 2011 is a misleading anti-virus program that may give false or exaggerated system security threats on your PC. McAVG 2011 displays fake security warnings and prompts to pay for a full license of the program in order to remove the threats. Here are some of the security threats it detected on our clean test machine: PcClient LP, Alureon YT, Donloz YF, Kbot F. You can get a full license of this rogue program for 5 euros (6.9 dollars). Of course, you shouldn't purchase it. It gives a false sense of security anyway. The graphical user interface of McAVG 2011 is pretty much the same as Kaspersky Anti-virus. I don't know how they came up with this name, but it seems to me that it's a combination of McAfee and AVG. Both names are well known in computer security industry. If you have this piece of malware on your computer, please follow the steps in the removal guide below to remove McAVG 2011 and any related malware for free.



McAVG 2011 related domains (212.85.33.210):
  • hydra-networks.com
  • spycheck.cn
  • spycheck.co.uk
  • spycheck.dk
  • spycheck.eu
  • spycheck.fr
  • spycheck.it
  • spycheck.jp
  • spycheck.nl
  • spycheck.pl
  • spycheck.ru
All these website, except hydra-networks.com, use the same web template which is an almost exact copy of liutilities.com process library.

A screenshot of spycheck.co.uk


A screenshot of liutilities.com


As you can see, McAVG 2011 uses misleading methods to trick users into purchase a full version of the program. It impersonates legitimate and well known software to gain more authority. It's a scam. Do not fall victim to this misleading program. If you have already purchased it, please contact your credit card company and dispute the charges as this program is an infection. To remove McAVG 2011, please follow the step in the removal guide below. You can always leave a comment if you need some help or if you have additional information about this rogue that may help other users. Don't forget to tell your friends about this threat. Good luck and be safe online!


McAVG 2011 removal instructions:

1. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

You may need to end McAVG 2011 process in order to run malware removal tool. Download Process Explorer and end rogue's process: mcavg.exe



2. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Associated McAVG 2011 files and registry values:

Files:
  • C:\Program Files\McAVG\McAVG\fasdata1.dat
  • C:\Program Files\McAVG\McAVG\fasdata2.dat
  • C:\Program Files\McAVG\McAVG\fasdata3.dat
  • C:\Program Files\McAVG\McAVG\fasdata4.dat
  • C:\Program Files\McAVG\McAVG\fasdata5.dat
  • C:\Program Files\McAVG\McAVG\fasdata6.dat
  • C:\Program Files\McAVG\McAVG\fasdata7.dat
  • C:\Program Files\McAVG\McAVG\fasdata8.dat
  • C:\Program Files\McAVG\McAVG\lang.txt
  • C:\Program Files\McAVG\McAVG\lastscan.txt
  • C:\Program Files\McAVG\McAVG\licencia.txt
  • C:\Program Files\McAVG\McAVG\mcavg.exe
  • C:\Program Files\McAVG\McAVG\mcavg.zip
  • C:\Program Files\McAVG\McAVG\versiondb.txt
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\McAVG\McAVG
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache "C:\Program Files\McAVG\McAVG\mcavg.exe"
Share the knowledge:

Tuesday, February 1, 2011

Windows Problems Remover, Windows Health Center, Windows Shield Center Removal Instructions

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Just a few days ago we reported finding the Windows Antispyware Solution scareware and today we came across another three different names for basically the same Trojan that pretends to be legitimate security software: Windows Problems Remover, Windows Health Center and Windows Shield Center (and there are even more names, see list below). It's not especially noteworthy because we have posted multiple articles about this rogue program in a last few months. The rogue program impersonates legitimate security software, reports false scan results and asks to pay for a full version of the program to remove the threats. It blocks other programs on your computer and displays fake security warnings. If you somehow ended up with Windows Problems Remover, Windows Health Center or Windows Shield Center malware, please follow the steps in the removal guide below to remove it from your computer. Please read our previous post about Windows Security & Control for more detailed analysis. The methodology and removal instructions are basically the same for this rogue program not matter how it calls itself. If you have any questions, please leave a comment. Good luck and be safe online!

Cyber-criminals change rogues' names very often. This removal guide run under quite a few different names, which I have listed below:

Rogue Names:
Windows Passport Utility Windows Stability Center Windows Process Regulator
Windows Power Expansion Windows Simple Protector Windows Expansion System
Windows Background Protector Windows Support System Windows Emergency System
Windows Efficiency Magnifier Windows Threats Removing Windows Remedy
Windows Troubles Remover Windows Servant System Windows Defence Center
Windows Error Correction Windows Debug System Windows Perfomance Manager
Windows Troubles Analyzer Windows Processes Organizer Windows Privacy Agent
Windows Express SettingsWindows Optimal Tool Windows Safety Guarantee
Windows AV Software Windows Express Help Windows User Satellite
Windows Optimal Settings Windows Optimal Solution Windows Care Tool
Windows Wise Protection Windows Software Guard Windows Software Protection
Windows Safety Protection Windows Problems Protector Windows Lowlevel Solution

Windows Troubles Remover


Windows Privacy Agent


Windows Care Tool



Removal instructions:

1. Rename the main executable of the rogue program:

In Windows XP:
C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS].exe
C:\Documents and Settings\[UserName]\Application Data\Microsoft\[SET OF RANDOM CHARACTERS].exe

In Windows Vista/7:
C:\Users\[UserName]\AppData\Roaming\[SET OF RANDOM CHARACTERS].exe
C:\Users\[UserName]\AppData\Roaming\Microsoft\[SET OF RANDOM CHARACTERS].exe



Alternate location:


Look for xmrmuy or similar file and rename it to malware. Then restart your computer. This should disable the rogue program. After reboot, please continue with the rest of the removal process. NOTE: By default, Application Data folder is hidden. If you can find it, please read Show Hidden Files and Folders in Windows.

OR you can download Process Explorer and end rogue's process.



2. Download shell-fix.reg. Double-click to run it. Click "Yes" when it asks if you want to add the information to the registry. This file will fix the Windows Shell entry.
3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus.


Alternate removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus.


Associated files and registry values:

Files:

In Windows XP:
  • C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS].exe
  • C:\Documents and Settings\[UserName]\Application Data\Microsoft\[SET OF RANDOM CHARACTERS].exe
In Windows Vista/7:
  • C:\Users\[UserName]\AppData\Roaming\[SET OF RANDOM CHARACTERS].exe
  • C:\Users\[UserName]\AppData\Roaming\Microsoft\[SET OF RANDOM CHARACTERS].exe
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = '%UserProfile%\Application Data\[SET OF RANDOM CHARACTERS].exe'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = '%UserProfile%\Application Data\Microsoft\[SET OF RANDOM CHARACTERS].exe'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'
Share this information with other people:

 
//PART 2