Brat Trojan

Brat malware description and removal detail
Categories:Trojan,Backdoor,RAT
Also known as:

[Kaspersky]Backdoor.Evilbot.a,Backdoor.Win32.Evilbot.a;
[Eset]Win32/Brat trojan;
[McAfee]BackDoor-OG,BackDoor.OG;
[F-Prot]security risk or a "backdoor" program;
[Panda]Bck/Brat.A;
[Computer Associates]Backdoor/Brat!Server,Backdoor/Brat.Server,Win32.Brat.02.A;
[Other]Win32/Brat.A,Backdoor.Evilbot.C

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\PTL32.EXE
[%WINDOWS%]\PTL32.EXE

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Brat:

Files:
[%WINDOWS%]\PTL32.EXE
[%WINDOWS%]\PTL32.EXE

Removing Brat:

An up-to-date copy of ExterminateIt should detect and prevent infection from Brat.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Brat manually.

To completely manually remove Brat malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Brat.

  1. Use Task Manager to terminate the Brat process.
  2. Delete the original Brat file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Brat from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Brat!

Check now if your PC is infected with Brat

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
7th.Son Trojan Removal
Briss Spyware Removal instruction
Mirtang Trojan Removal instruction

Porkodio RAT

Porkodio malware description and removal detail
Categories:RAT

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Porkodio:

An up-to-date copy of ExterminateIt should detect and prevent infection from Porkodio.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Porkodio manually.

To completely manually remove Porkodio malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Porkodio.

  1. Use Task Manager to terminate the Porkodio process.
  2. Delete the original Porkodio file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Porkodio from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Porkodio!

Check now if your PC is infected with Porkodio

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
Remove TrojanDownloader.Win32.Dluca Trojan
Removing The.Spy.Beta Trojan
Remove SuperKoD Trojan
Win32.Prosiak Trojan Removal

Win16.HookDump Trojan

Win16.HookDump malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Win16.HookDump:

An up-to-date copy of ExterminateIt should detect and prevent infection from Win16.HookDump.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Win16.HookDump manually.

To completely manually remove Win16.HookDump malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Win16.HookDump.

  1. Use Task Manager to terminate the Win16.HookDump process.
  2. Delete the original Win16.HookDump file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Win16.HookDump from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Win16.HookDump!

Check now if your PC is infected with Win16.HookDump

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
Bancos.HDR Trojan Cleaner
Agent.kf Trojan Removal instruction
XP.Antivirus Ransomware Removal
Bancos.HAN Trojan Symptoms

Pigeon.EDH Trojan

Pigeon.EDH malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Pigeon.EDH:

An up-to-date copy of ExterminateIt should detect and prevent infection from Pigeon.EDH.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Pigeon.EDH manually.

To completely manually remove Pigeon.EDH malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Pigeon.EDH.

  1. Use Task Manager to terminate the Pigeon.EDH process.
  2. Delete the original Pigeon.EDH file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Pigeon.EDH from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Pigeon.EDH!

Check now if your PC is infected with Pigeon.EDH

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
Lemir.ci Trojan Removal
Remove AntiVirusPro Ransomware
Removing DNR Trojan
JS.MS07 Trojan Removal instruction
not.virus:Joke.Win32.Krepper Trojan Removal instruction

privatecash.com Tracking Cookie

This summary is not available. Please click here to view the post.

IGetNet Adware

IGetNet malware description and removal detail
Categories:Adware,BHO,Hijacker
Also known as:

[F-Prot]security risk or a "backdoor" program;
[Panda]Adware/IGetnet

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\NLNP13.dll
[%WINDOWS%]\system\winstart001.exe
[%PROFILE_TEMP%]\nlnp41.exe
[%SYSTEM%]\rsp.dll
[%SYSTEM%]\rsp001.dll
[%SYSTEM%]\winstart.exe
[%SYSTEM%]\winstart001.exe
[%WINDOWS%]\system\install_all.dll
[%WINDOWS%]\system\nlnp29.exe
[%WINDOWS%]\system\rsp.dll
[%WINDOWS%]\system\rsp001.dll
[%WINDOWS%]\system\update_com.dll
[%WINDOWS%]\system\update_removeold.dll
[%WINDOWS%]\system\winstart.exe
[%SYSTEM%]\NLNP13.dll
[%WINDOWS%]\system\winstart001.exe
[%PROFILE_TEMP%]\nlnp41.exe
[%SYSTEM%]\rsp.dll
[%SYSTEM%]\rsp001.dll
[%SYSTEM%]\winstart.exe
[%SYSTEM%]\winstart001.exe
[%WINDOWS%]\system\install_all.dll
[%WINDOWS%]\system\nlnp29.exe
[%WINDOWS%]\system\rsp.dll
[%WINDOWS%]\system\rsp001.dll
[%WINDOWS%]\system\update_com.dll
[%WINDOWS%]\system\update_removeold.dll
[%WINDOWS%]\system\winstart.exe

In order to ensure that the IGetNet is launched automatically each time the system is booted, the IGetNet adds a link to its executable file in the system registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[%WINDOWS%]\system\winstart001.exe
[%PROFILE_TEMP%]\nlnp41.exe
[%SYSTEM%]\winstart.exe
[%SYSTEM%]\winstart001.exe
[%WINDOWS%]\system\nlnp29.exe
[%WINDOWS%]\system\winstart.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting IGetNet:

Files:
[%SYSTEM%]\NLNP13.dll
[%WINDOWS%]\system\winstart001.exe
[%PROFILE_TEMP%]\nlnp41.exe
[%SYSTEM%]\rsp.dll
[%SYSTEM%]\rsp001.dll
[%SYSTEM%]\winstart.exe
[%SYSTEM%]\winstart001.exe
[%WINDOWS%]\system\install_all.dll
[%WINDOWS%]\system\nlnp29.exe
[%WINDOWS%]\system\rsp.dll
[%WINDOWS%]\system\rsp001.dll
[%WINDOWS%]\system\update_com.dll
[%WINDOWS%]\system\update_removeold.dll
[%WINDOWS%]\system\winstart.exe
[%SYSTEM%]\NLNP13.dll
[%WINDOWS%]\system\winstart001.exe
[%PROFILE_TEMP%]\nlnp41.exe
[%SYSTEM%]\rsp.dll
[%SYSTEM%]\rsp001.dll
[%SYSTEM%]\winstart.exe
[%SYSTEM%]\winstart001.exe
[%WINDOWS%]\system\install_all.dll
[%WINDOWS%]\system\nlnp29.exe
[%WINDOWS%]\system\rsp.dll
[%WINDOWS%]\system\rsp001.dll
[%WINDOWS%]\system\update_com.dll
[%WINDOWS%]\system\update_removeold.dll
[%WINDOWS%]\system\winstart.exe

Registry Keys:
HKEY_CLASSES_ROOT\interface\{f6fbfe07-ca76-438e-b34e-4f4dc41f0123}
HKEY_CLASSES_ROOT\typelib\{95b3af07-0e4f-4cdf-acfd-3d4efd9aec0b}
HKEY_CURRENT_USER\software\vb and vba program settings\ie rsp
HKEY_CLASSES_ROOT\bho.clsurlsearch
HKEY_CLASSES_ROOT\clsid\{676058e4-89bd-11d6-8a8c-0050ba8452c0}
HKEY_CLASSES_ROOT\clsid\{94742e3f-d9a1-4780-9a87-2ffa43655da2}
HKEY_CLASSES_ROOT\interface\{226a045e-fd4e-4632-b51d-a112bd8254e5}
HKEY_CLASSES_ROOT\interface\{3683fd85-0501-40dc-9edb-9d9181800d72}
HKEY_CLASSES_ROOT\interface\{3c8cde30-d013-4093-b00e-adbc74f33315}
HKEY_CLASSES_ROOT\interface\{676058e3-89bd-11d6-8a8c-0050ba8452c0}
HKEY_CLASSES_ROOT\interface\{f94c0089-9394-4e44-b4ea-58dba1f7b84e}
HKEY_CLASSES_ROOT\rsp.bizlgk
HKEY_CLASSES_ROOT\typelib\{676058db-89bd-11d6-8a8c-0050ba8452c0}
HKEY_CLASSES_ROOT\typelib\{974cc25e-d62c-4278-84e6-a806726e37bc}
HKEY_CLASSES_ROOT\typelib\{acba087f-1547-41de-8e9e-3f0963ce4bef}
HKEY_LOCAL_MACHINE\software\classes\rsp.bizlgk
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{60e78cac-e9a7-4302-b9ee-8582ede22fbf}

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing IGetNet:

An up-to-date copy of ExterminateIt should detect and prevent infection from IGetNet.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove IGetNet manually.

To completely manually remove IGetNet malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with IGetNet.

  1. Use Task Manager to terminate the IGetNet process.
  2. Delete the original IGetNet file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes IGetNet from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of IGetNet!

Check now if your PC is infected with IGetNet

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
DP2DLB Trojan Removal instruction
Bancos.GAR Trojan Cleaner
PopUpDefence BHO Cleaner
DlAtaka Backdoor Symptoms
Globobank Trojan Removal

Delf.og Trojan

Delf.og malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Delf.og:

An up-to-date copy of ExterminateIt should detect and prevent infection from Delf.og.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Delf.og manually.

To completely manually remove Delf.og malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Delf.og.

  1. Use Task Manager to terminate the Delf.og process.
  2. Delete the original Delf.og file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Delf.og from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Delf.og!

Check now if your PC is infected with Delf.og

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
7FaSSt Spyware Information
KeyLog.KLogger Trojan Cleaner

DlFear Trojan

DlFear malware description and removal detail
Categories:Trojan,Downloader
Also known as:

[Panda]Trojan Horse;
[Computer Associates]Win32.DlFear.12

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing DlFear:

An up-to-date copy of ExterminateIt should detect and prevent infection from DlFear.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove DlFear manually.

To completely manually remove DlFear malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with DlFear.

  1. Use Task Manager to terminate the DlFear process.
  2. Delete the original DlFear file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes DlFear from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of DlFear!

Check now if your PC is infected with DlFear

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
Khurak Trojan Information
Blss Trojan Removal
RASetup RAT Removal instruction
Stealth.alpha.beta RAT Cleaner

Favadd Trojan

Favadd malware description and removal detail
Categories:Trojan
Also known as:

[Kaspersky]Trojan.Win32.FavAdd.n;
[Other]Trojan.Favadd

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Favadd:

Folders:
[%FAVORITES%]\ADULTS SITES

Registry Keys:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\menuorder\favorites\adults sites

Removing Favadd:

An up-to-date copy of ExterminateIt should detect and prevent infection from Favadd.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Favadd manually.

To completely manually remove Favadd malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Favadd.

  1. Use Task Manager to terminate the Favadd process.
  2. Delete the original Favadd file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Favadd from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Favadd!

Check now if your PC is infected with Favadd

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
Tiny.DI.Grower Trojan Removal
WordMacro.Junkface Trojan Removal
Adware.Borlan Adware Cleaner
SB Trojan Removal instruction
Kaos Backdoor Symptoms

Startpage Trojan

Startpage malware description and removal detail
Categories:Trojan,Adware,BHO,Backdoor,Hijacker,Toolbar,Downloader
Also known as:

[Kaspersky]Trojan.Win32.StartPage.y,Trojan.Win32.StartPage.aq,Trojan.Win32.StartPage.ix,Trojan.Win32.Krepper.p,Trojan-Downloader.Win32.Agent.jm,Trojan.Win32.StartPage.bg,Trojan.Win32.StartPage.aj,Trojan.Win32.StartPage.t,Trojan-Downloader.Win32.IstBar.ff,Trojan.Win32.StartPage.aia,Trojan-Downloader.Win32.Small.bxa,Trojan.Win32.StartPage.aks,Trojan.Win32.StartPage.qw,Exploit.JS.ActiveXComponent,Trojan.VBS.StartPage.be,Trojan.Win32.Startpage.aky,Trojan.Win32.StartPAge.alu,Trojan.Win32.StartPage.vr,Trojan.Win32.StartPage.is,Trojan.Win32.StartPage.uz,Trojan-Dropper.Win32.Agent.ow,Backdoor.Win32.Hupigon.ccp,Trojan.Win32.StartPage.po,Trojan.Win32.StarPage.amt,Trojan.Win32.StartPage.amn,Trojan.Win32.Kolweb.b,Trojan.Win32.BHO.f,Trojan.Win32.StartPage.amb,Trojan.Win32.StartPage.ba,Trojan-Clicker.Win32.Delf.ar,Porn-Tool.Win32.Clavusnet.b,Trojan.Win32.StartPage.agy,Trojan.Win32.StartPage.mu,Trojan.Win32.StartPage.zz,Trojan-Downlaoder.Win32.Small.rr,Trojan.BAT.StartPage.d,Trojan.Win32.StartPage.apw,Trojan.Win32.StartPage.arx,Trojan-Downloader.Win32.Hmir.du,Trojan.Win32.StartPage.amd,Trojan.Win32.Delf.cf,Trojan.Win32.StartPage.ag;
[Eset]Win32/StartPage.Y trojan,Win32/StartPage.Y2 trojan,Win32/StartPage.GV trojan,Win32/StartPage.NAI trojan,Win32/Goweh.B trojan,Win32/StartPage.IX trojan,Win32/StartPage.IX1 trojan,Win32/StartPage.IS trojan,Win32/Krepper.Q trojan,Win32/StartPage.IV trojan;
[McAfee]StartPage-Q,StartPage-GX,StartPage-FO,Generic StartPage.j,StartPage-DU.dll.dr,StartPage-DU.dll,Adware-Altnet.dr,Adware-CWS,StartPage-Al.gen,StartPage-IW,StartPage-CD,Downloader-DS.b,Gpix.gen,StartPage-T,Generic RootKit.a,Downloader.gen.a,Generic Downloader.f;
[F-Prot]security risk or a "backdoor" program,W32/Downloader.BTL,W32/StartpageX.AJS,W32/Trojan.AHSX;
[Panda]Trojan Horse,Trj/StartPage.Y,Trj/StartPage.F,Trj/Krepper.A,Adware/DNSErr,Trj/Bookmark.B,Trj/Downloader.AJ,Trj/Conspy.B,Trj/Tofger.J,Trj/StartPage.BF,Trj/StartPage.IY,Trj/Startpage.DV,Trj/Runet.A,Trj/Harnig.B,Trj/Bookmark.A,Trj/Reler.A,Trj/Harnig.C,Trj/Startpage.BS,Adware/Adtomi,Trj/Startpage.DI,Trj/StartPage.EB,Trj/Downloader.DP,Trj/Krepper.C,Trj/StartPage.ID,Trj/StartPage.gen,Trj/Goweh.A,Trj/StartPage.FH,Trj/Kreeper.A,Trj/Krepper.F,Trj/SubSearch.C,Trj/Startpage.HO,Trj/StartPage.GU,Trj/StartPage.IN,Spyware/ISTbar,Trj/Startpage.HL,Trj/StartPage.BM,Trj/Sysgotem.B,Trj/Startpage.HV,Trj/Downloader.PM,Trj/StartPage.HT,Trj/Leritand.A,Trj/Leritand.C,Trj/StartPage.EH,Trj/StartPage.AB,Adware/Look2Me,Trj/Startpage.IF,Trj/StartPage.T;
[Computer Associates]Win32.Startpage.E,Win32/StartPage.Q!Trojan,Win32.Startpage.BC,Win32/StartPage.alpha!Trojan,Win32/StartPage.AQ!Trojan,Win32.Startpage.CI,Win32.Startpage.G,Win32.Startpage.Y,Win32/StartPage.G.Trojan,Win32/Startpage.Y!Trojan,Win32.Startpage.AN!downloader,Win32/Startpage.AN!Trojan,Win32.Startpage.BJ,Win32/ClearHosts.73728!Trojan,Win32.Startpage.AG,Win32/StartPage.AG!Trojan,Win32.Startpage.BJ!downloader,Win32/ClearHosts!Downloader,Win32.Startpage.AE,Win32/Startpage.21504!Trojan,Win32.Startpage.BL,Win32/StartPage.BL.5120!Trojan,Win32.Startpage.BV,Win32/QHosts!Trojan,Win32.Startpage.AQ,Win32/StartPage.tenbiz!Trojan,Win32.Startpage.AI,Win32/StartPage.6656!Trojan,Win32.Startpage.CB,Win32.Startpage.BA,Win32/StartPage.11776.A!Trojan,Win32.Startpage.AD,Win32.Startpage.CH!downloader,Win32/StartPage!Downloader,Win32.Startpage.AM,Win32/Startpage.AM!Trojan,Win32.Startpage.CQ,Win32/StartPage.Secure!Trojan,Win32/Startpage.AU!DLL!Trojan,Win32.Startpage.J,Win32/VB.dh!Trojan,Win32/Harnig.D!Trojan,Win32.Startpage.S,Win32/StartPage.8151!Trojan,Win32.Startpage.ME,Win32.Startpage.FZ,Win32/DlMersting.CG!Trojan,Win32.Startpage.FG,Win32/StartPage.couldnotfind!Dow,Win32.Startpage.GZ,Win32/StartPage.GZ!Trojan,Win32/StartPage.GZ.3072!Trojan,Win32.Startpage.FP,Win32.Startpage.BM,Win32/Digits.23104!Trojan,Win32/DlMersting.AI.30720!DLL!Tr,Win32/DlMersting.AJ.30720!DLL!Tr,Win32/DlMersting.AK.30720!Trojan,Win32/DlMersting.AL.30720!DLL!Tr,Win32/DlMersting.AN.30720!DLL!Tr,Win32/DlMersting.AW.30720!DLL!Tr,Win32/StartPage.FZ!BHO!Trojan,Win32/Startpage.FZ.30720!DLL!Tro,Win32/Startpage.FZ.31744.Trojan,Win32/Startpage.FZ!Trojan,Win32/StartPage.GZ!BHO!Trojan,Win32/Startpage.GZ1!Trojan,Win32.Startpage.MH,Win32/Startpage.205824!Trojan,Win32.Startpage.IU,Win32/StartPage.ku!Trojan,Win32.Startpage.HE,Win32/StartPage.HT!Trojan,Win32.Startpage.GS,Win32/StartPage.freeticket!Troja,Win32.Startpage.HB,Win32/Startpage.7680!Worm,Win32.Startpage.GT,Win32.Startpage.HM,Win32/Startpage.GC!Trojan,Win32/DlMersting.AY.30720!DLL!Tr,Win32.Startpage.CN,Win32/Startpage.EB!Trojan,Win32.Startpage.GU!downloader,Win32/Startpage.DV!Downloader,Win32.Startpage.DP,Win32/StartPage.defaultsearching,Win32.Startpage.IM,Win32/StartPage.EH!DLL!Trojan,Win32.Startpage.HR,Win32/Startpage.HR!Trojan,Win32.Startpage.GO,Win32/Startpage.Nopop!Trojan,Win32.Startpage.HX,Win32.Startpage.EH,Win32.Startpage.FO,Win32/Startpage.FO.Trojan,Win32.Startpage.GF,Win32.Startpage.GG,Win32.Startpage.AV,Win32.Startpage.KF,Win32.Startpage.JG,Win32.Startpage.HA,Win32.Startpage.HI,Win32.Startpage.GK,Win32.Startpage.NF,Win32.Startpage.NI,Win32/StartPage.35840.A!Trojan,Win32/StartPage.HI!Trojan,Win32/Startpage.HX.Trojan,Win32/Startpage!Trojan,Win32.Startpage,Win32/Startpage.X!Trojan,Win32.Startpage.X,Win32/StartPage.t!Trojan,Win32.Startpage.D;
[Other]TROJ_AGENT.NR,Win32/Malum.IIB,TROJ_CLICKER.AP,Win32/StartPage.UR,Win32/Startpage.UT,Trojan.StartPage,HTML.StartPage.US,JS.StartPage,VBS/StartPage.UZ,Win32/Startpage.US,Adware.Roogoo,Win32/Startpage.VB,Win32/Startpage.FZ,Trojan.StartPage.M,Win32/Startpage.NS,CWS.DesktopHijack,PremiumSearch,Trojan Horse,Win32/Startpage.VK,Win32/Startpage.VY,Adware.MyCustomIE,Trojan:Win32/Startpage.PO,W32/Startpage.AXX,Trojan.Win32.StartPage.po,coolsearch hijacker,W32/Startpage.EAR,Win32/Startpage.VU,Adware.Margoc,Win32/Startpage.VW,Win32/Startpage.VF,Win32/Startpage.WF,Win32/Startpage.WG,Win32/Startpage.WQ,Adware.MainSearch,Trojan:Win32/Nethost.A,Win32/Startpage.WZ,Win32/Startpage.WS,Win32/Startpage.XJ,Win32/Startpage.JB,Win32/Startpage.XW,Win32/Startpage.OU,W32/Agent.ZE,Win32/Startpage.YD,TROJ_AGENT.WSI,Win32/Startpage.YI,Trojan:Win32/Anomaly.gen!B,Hijacker.StartPage.apw,Win32/Startpage.YM,Win32/Startpage.YT,Trojan:Win32/Meredrop,Mal/Basine-C,Trojan.Farfli,W32.Spybot.Worm,Win32/Startpage.YX,Trojan:Win32/Startpage,W32/Startpage.ERA,Possible_Virus

Visible Symptoms:
Files in system folders:
[%COMMON_APPDATA%]\Tools\tools.dll
[%COMMON_FAVORITES%]\Anti Spyware Soft.url
[%COMMON_FAVORITES%]\avir.ico
[%COMMON_FAVORITES%]\Buy Viagra Online.url
[%COMMON_FAVORITES%]\Cheap Viagra.url
[%COMMON_FAVORITES%]\cialis.ico
[%COMMON_FAVORITES%]\Email Spam Filter.url
[%COMMON_FAVORITES%]\Free Online Casino.url
[%COMMON_FAVORITES%]\gamb.ico
[%COMMON_FAVORITES%]\nospam.ico
[%COMMON_FAVORITES%]\Online AntiVirus and Spyware Remover.url
[%COMMON_FAVORITES%]\Online Directory of Pure Porn.url
[%COMMON_FAVORITES%]\Online Pharmacy.url
[%COMMON_FAVORITES%]\Online Poker.url
[%COMMON_FAVORITES%]\Play in the most popular online casino.url
[%COMMON_FAVORITES%]\poker.ico
[%COMMON_FAVORITES%]\Spyware Remover.url
[%COMMON_FAVORITES%]\spyware.ico
[%COMMON_FAVORITES%]\tgf.ico
[%COMMON_FAVORITES%]\viag.ico
[%FAVORITES%]\Anti Spyware Soft.url
[%FAVORITES%]\avir.ico
[%FAVORITES%]\cialis.ico
[%FAVORITES%]\Email Spam Filter.url
[%FAVORITES%]\gamb.ico
[%FAVORITES%]\nospam.ico
[%FAVORITES%]\Online AntiVirus and Spyware Remover.url
[%FAVORITES%]\Online Pharmacy.url
[%FAVORITES%]\poker.ico
[%FAVORITES%]\shopping\shopping.url
[%FAVORITES%]\Spyware Remover.url
[%FAVORITES%]\spyware.ico
[%FAVORITES%]\tgf.ico
[%FAVORITES%]\viag.ico
[%PROFILE_TEMP%]\avicodec.exe
[%PROFILE_TEMP%]\restsrv32a.sys
[%PROGRAM_FILES%]\internet explorer\ieengine.exe
[%PROGRAM_FILES%]\internet explorer\signup\presario.htm
[%SYSTEM%]\winupd.exe
[%SYSTEM%]\yxuce.dll
[%WINDOWS%]\cl2.exe
[%WINDOWS%]\enewsletterpro.exe
[%WINDOWS%]\hh.htt
[%COMMON_FAVORITES%]\Free Real-time Dating Service.url
[%COMMON_FAVORITES%]\freedating.ico
[%DESKTOP%]\ppime.exe
[%FAVORITES%]\Buy Viagra Online.url
[%FAVORITES%]\Cheap Viagra.url
[%FAVORITES%]\Free Online Casino.url
[%FAVORITES%]\Free Real-time Dating Service.url
[%FAVORITES%]\freedating.ico
[%FAVORITES%]\Online Directory of Pure Porn.url
[%FAVORITES%]\Online Poker.url
[%FAVORITES%]\Play in the most popular online casino.url
[%PROFILE%]\applic~1\setup\setup.dll
[%PROFILE_TEMP%]\se.dll
[%PROFILE_TEMP%]\wpytcnwrobw.dll
[%STARTUP%]\msupdate.exe
[%STARTUP%]\winlogin.exe
[%SYSTEM%]\576bz7yyii.dll
[%SYSTEM%]\7i0s705ifzz.dll
[%SYSTEM%]\9f2ns2sk8wlkk5.dll
[%SYSTEM%]\9qbqe.dll
[%SYSTEM%]\a5i0oof7t7dm.dll
[%SYSTEM%]\abfgoke.dll
[%SYSTEM%]\abo.dll
[%SYSTEM%]\actsie4.exe
[%SYSTEM%]\ael.dll
[%SYSTEM%]\akleaa.dll
[%SYSTEM%]\albgjd.dll
[%SYSTEM%]\bcfjp.dll
[%SYSTEM%]\blbff.dll
[%SYSTEM%]\bnijea.dll
[%SYSTEM%]\bootconf.exe
[%SYSTEM%]\cenbna.dll
[%SYSTEM%]\cjcan.dll
[%SYSTEM%]\clnfg.dll
[%SYSTEM%]\dbdegea.dll
[%SYSTEM%]\dflnca.dll
[%SYSTEM%]\dnnlk.dll
[%SYSTEM%]\drivers\paraudio.sys
[%SYSTEM%]\ebkh.dll
[%SYSTEM%]\enijbaa.dll
[%SYSTEM%]\exp1orer.exe
[%SYSTEM%]\f5u5154vus.dll
[%SYSTEM%]\faaa.dll
[%SYSTEM%]\fikol.dll
[%SYSTEM%]\ggigbca.dll
[%SYSTEM%]\ghpkea.dll
[%SYSTEM%]\gopmkc.dll
[%SYSTEM%]\hfglhh.dll
[%SYSTEM%]\hgcn.dll
[%SYSTEM%]\hipewr5.exe
[%SYSTEM%]\hjam.dll
[%SYSTEM%]\hllo.dll
[%SYSTEM%]\hlp.dll
[%SYSTEM%]\hpagc.dll
[%SYSTEM%]\ihol.dll
[%SYSTEM%]\ijmdnp.dll
[%SYSTEM%]\jajig.dll
[%SYSTEM%]\jfcbjp.dll
[%SYSTEM%]\jfdjgaa.dll
[%SYSTEM%]\jj78208.exe
[%SYSTEM%]\jmleib.dll
[%SYSTEM%]\jnmnnhc.dll
[%SYSTEM%]\joac.dll
[%SYSTEM%]\jomdj.dll
[%SYSTEM%]\jsconsole.dll
[%SYSTEM%]\jw09tin.exe
[%SYSTEM%]\kbdko.dll
[%SYSTEM%]\kea.dll
[%SYSTEM%]\kfe.dll
[%SYSTEM%]\kpnlgd.dll
[%SYSTEM%]\lfphaea.dll
[%SYSTEM%]\lgif.dll
[%SYSTEM%]\lj7i5x.dll
[%SYSTEM%]\lkkmhn.dll
[%SYSTEM%]\lll.dll
[%SYSTEM%]\lnhf.dll
[%SYSTEM%]\lomio.dll
[%SYSTEM%]\lpp.dll
[%SYSTEM%]\matrixhere.exe
[%SYSTEM%]\mbpbfc.dll
[%SYSTEM%]\moneyspj.exe
[%SYSTEM%]\msdoh.dll
[%SYSTEM%]\msspi.dll
[%SYSTEM%]\ncdjoka.dll
[%SYSTEM%]\nld.dll
[%SYSTEM%]\ntldr.exe
[%SYSTEM%]\oalgeec.dll
[%SYSTEM%]\ohnl.dll
[%SYSTEM%]\oplenh.dll
[%SYSTEM%]\pbm.dll
[%SYSTEM%]\pbpb.dll
[%SYSTEM%]\pmgafcc.dll
[%SYSTEM%]\pwl4uoo95kl5.dll
[%SYSTEM%]\QuickTime1.tx
[%SYSTEM%]\QuickTimer1.exe
[%SYSTEM%]\rcoujxlbka.dll
[%SYSTEM%]\regsvrac32.dll
[%SYSTEM%]\restsrv32a.sys
[%SYSTEM%]\SASS.EXE
[%SYSTEM%]\sndbdrv3104.exe
[%SYSTEM%]\sysstartup.exe
[%SYSTEM%]\upyyjl.exe
[%SYSTEM%]\usbhdctl.exe
[%SYSTEM%]\wdmeaii.dll
[%SYSTEM%]\winmla32.exe
[%SYSTEM%]\winmm64.exe
[%SYSTEM%]\Www.LookSoft.Net.dll
[%SYSTEM%]\Www.LookSoft.Net.exe
[%WINDOWS%]\default.css
[%WINDOWS%]\madopew.dll
[%WINDOWS%]\mwshelp.dll
[%WINDOWS%]\restsrv32a.sys
[%WINDOWS%]\run33.exe
[%WINDOWS%]\system\9xzc9d0zi98.dll
[%WINDOWS%]\system\a6z95lih1r9vd.dll
[%WINDOWS%]\system\adgjmpsv.dll
[%WINDOWS%]\system\adrerbcs.exe
[%WINDOWS%]\system\bootconf.exe
[%WINDOWS%]\system\chdekfb.dll
[%WINDOWS%]\system\dhoh.dll
[%WINDOWS%]\system\dla.dll
[%WINDOWS%]\system\flplcg.dll
[%WINDOWS%]\system\hsjnn86uhnvu.dll
[%WINDOWS%]\system\kfeehaa.dll
[%WINDOWS%]\system\kjjo.dll
[%WINDOWS%]\system\lpcoen.dll
[%WINDOWS%]\system\matrixhere.exe
[%WINDOWS%]\system\msspi.dll
[%WINDOWS%]\system\oofndd.dll
[%WINDOWS%]\system\pboola.dll
[%WINDOWS%]\system\pod.dll
[%WINDOWS%]\system\soundmx.exe
[%WINDOWS%]\system\sysstartup.exe
[%WINDOWS%]\system\winupd.exe
[%WINDOWS%]\win86.exe
[%COMMON_APPDATA%]\Tools\tools.dll
[%COMMON_FAVORITES%]\Anti Spyware Soft.url
[%COMMON_FAVORITES%]\avir.ico
[%COMMON_FAVORITES%]\Buy Viagra Online.url
[%COMMON_FAVORITES%]\Cheap Viagra.url
[%COMMON_FAVORITES%]\cialis.ico
[%COMMON_FAVORITES%]\Email Spam Filter.url
[%COMMON_FAVORITES%]\Free Online Casino.url
[%COMMON_FAVORITES%]\gamb.ico
[%COMMON_FAVORITES%]\nospam.ico
[%COMMON_FAVORITES%]\Online AntiVirus and Spyware Remover.url
[%COMMON_FAVORITES%]\Online Directory of Pure Porn.url
[%COMMON_FAVORITES%]\Online Pharmacy.url
[%COMMON_FAVORITES%]\Online Poker.url
[%COMMON_FAVORITES%]\Play in the most popular online casino.url
[%COMMON_FAVORITES%]\poker.ico
[%COMMON_FAVORITES%]\Spyware Remover.url
[%COMMON_FAVORITES%]\spyware.ico
[%COMMON_FAVORITES%]\tgf.ico
[%COMMON_FAVORITES%]\viag.ico
[%FAVORITES%]\Anti Spyware Soft.url
[%FAVORITES%]\avir.ico
[%FAVORITES%]\cialis.ico
[%FAVORITES%]\Email Spam Filter.url
[%FAVORITES%]\gamb.ico
[%FAVORITES%]\nospam.ico
[%FAVORITES%]\Online AntiVirus and Spyware Remover.url
[%FAVORITES%]\Online Pharmacy.url
[%FAVORITES%]\poker.ico
[%FAVORITES%]\shopping\shopping.url
[%FAVORITES%]\Spyware Remover.url
[%FAVORITES%]\spyware.ico
[%FAVORITES%]\tgf.ico
[%FAVORITES%]\viag.ico
[%PROFILE_TEMP%]\avicodec.exe
[%PROFILE_TEMP%]\restsrv32a.sys
[%PROGRAM_FILES%]\internet explorer\ieengine.exe
[%PROGRAM_FILES%]\internet explorer\signup\presario.htm
[%SYSTEM%]\winupd.exe
[%SYSTEM%]\yxuce.dll
[%WINDOWS%]\cl2.exe
[%WINDOWS%]\enewsletterpro.exe
[%WINDOWS%]\hh.htt
[%COMMON_FAVORITES%]\Free Real-time Dating Service.url
[%COMMON_FAVORITES%]\freedating.ico
[%DESKTOP%]\ppime.exe
[%FAVORITES%]\Buy Viagra Online.url
[%FAVORITES%]\Cheap Viagra.url
[%FAVORITES%]\Free Online Casino.url
[%FAVORITES%]\Free Real-time Dating Service.url
[%FAVORITES%]\freedating.ico
[%FAVORITES%]\Online Directory of Pure Porn.url
[%FAVORITES%]\Online Poker.url
[%FAVORITES%]\Play in the most popular online casino.url
[%PROFILE%]\applic~1\setup\setup.dll
[%PROFILE_TEMP%]\se.dll
[%PROFILE_TEMP%]\wpytcnwrobw.dll
[%STARTUP%]\msupdate.exe
[%STARTUP%]\winlogin.exe
[%SYSTEM%]\576bz7yyii.dll
[%SYSTEM%]\7i0s705ifzz.dll
[%SYSTEM%]\9f2ns2sk8wlkk5.dll
[%SYSTEM%]\9qbqe.dll
[%SYSTEM%]\a5i0oof7t7dm.dll
[%SYSTEM%]\abfgoke.dll
[%SYSTEM%]\abo.dll
[%SYSTEM%]\actsie4.exe
[%SYSTEM%]\ael.dll
[%SYSTEM%]\akleaa.dll
[%SYSTEM%]\albgjd.dll
[%SYSTEM%]\bcfjp.dll
[%SYSTEM%]\blbff.dll
[%SYSTEM%]\bnijea.dll
[%SYSTEM%]\bootconf.exe
[%SYSTEM%]\cenbna.dll
[%SYSTEM%]\cjcan.dll
[%SYSTEM%]\clnfg.dll
[%SYSTEM%]\dbdegea.dll
[%SYSTEM%]\dflnca.dll
[%SYSTEM%]\dnnlk.dll
[%SYSTEM%]\drivers\paraudio.sys
[%SYSTEM%]\ebkh.dll
[%SYSTEM%]\enijbaa.dll
[%SYSTEM%]\exp1orer.exe
[%SYSTEM%]\f5u5154vus.dll
[%SYSTEM%]\faaa.dll
[%SYSTEM%]\fikol.dll
[%SYSTEM%]\ggigbca.dll
[%SYSTEM%]\ghpkea.dll
[%SYSTEM%]\gopmkc.dll
[%SYSTEM%]\hfglhh.dll
[%SYSTEM%]\hgcn.dll
[%SYSTEM%]\hipewr5.exe
[%SYSTEM%]\hjam.dll
[%SYSTEM%]\hllo.dll
[%SYSTEM%]\hlp.dll
[%SYSTEM%]\hpagc.dll
[%SYSTEM%]\ihol.dll
[%SYSTEM%]\ijmdnp.dll
[%SYSTEM%]\jajig.dll
[%SYSTEM%]\jfcbjp.dll
[%SYSTEM%]\jfdjgaa.dll
[%SYSTEM%]\jj78208.exe
[%SYSTEM%]\jmleib.dll
[%SYSTEM%]\jnmnnhc.dll
[%SYSTEM%]\joac.dll
[%SYSTEM%]\jomdj.dll
[%SYSTEM%]\jsconsole.dll
[%SYSTEM%]\jw09tin.exe
[%SYSTEM%]\kbdko.dll
[%SYSTEM%]\kea.dll
[%SYSTEM%]\kfe.dll
[%SYSTEM%]\kpnlgd.dll
[%SYSTEM%]\lfphaea.dll
[%SYSTEM%]\lgif.dll
[%SYSTEM%]\lj7i5x.dll
[%SYSTEM%]\lkkmhn.dll
[%SYSTEM%]\lll.dll
[%SYSTEM%]\lnhf.dll
[%SYSTEM%]\lomio.dll
[%SYSTEM%]\lpp.dll
[%SYSTEM%]\matrixhere.exe
[%SYSTEM%]\mbpbfc.dll
[%SYSTEM%]\moneyspj.exe
[%SYSTEM%]\msdoh.dll
[%SYSTEM%]\msspi.dll
[%SYSTEM%]\ncdjoka.dll
[%SYSTEM%]\nld.dll
[%SYSTEM%]\ntldr.exe
[%SYSTEM%]\oalgeec.dll
[%SYSTEM%]\ohnl.dll
[%SYSTEM%]\oplenh.dll
[%SYSTEM%]\pbm.dll
[%SYSTEM%]\pbpb.dll
[%SYSTEM%]\pmgafcc.dll
[%SYSTEM%]\pwl4uoo95kl5.dll
[%SYSTEM%]\QuickTime1.tx
[%SYSTEM%]\QuickTimer1.exe
[%SYSTEM%]\rcoujxlbka.dll
[%SYSTEM%]\regsvrac32.dll
[%SYSTEM%]\restsrv32a.sys
[%SYSTEM%]\SASS.EXE
[%SYSTEM%]\sndbdrv3104.exe
[%SYSTEM%]\sysstartup.exe
[%SYSTEM%]\upyyjl.exe
[%SYSTEM%]\usbhdctl.exe
[%SYSTEM%]\wdmeaii.dll
[%SYSTEM%]\winmla32.exe
[%SYSTEM%]\winmm64.exe
[%SYSTEM%]\Www.LookSoft.Net.dll
[%SYSTEM%]\Www.LookSoft.Net.exe
[%WINDOWS%]\default.css
[%WINDOWS%]\madopew.dll
[%WINDOWS%]\mwshelp.dll
[%WINDOWS%]\restsrv32a.sys
[%WINDOWS%]\run33.exe
[%WINDOWS%]\system\9xzc9d0zi98.dll
[%WINDOWS%]\system\a6z95lih1r9vd.dll
[%WINDOWS%]\system\adgjmpsv.dll
[%WINDOWS%]\system\adrerbcs.exe
[%WINDOWS%]\system\bootconf.exe
[%WINDOWS%]\system\chdekfb.dll
[%WINDOWS%]\system\dhoh.dll
[%WINDOWS%]\system\dla.dll
[%WINDOWS%]\system\flplcg.dll
[%WINDOWS%]\system\hsjnn86uhnvu.dll
[%WINDOWS%]\system\kfeehaa.dll
[%WINDOWS%]\system\kjjo.dll
[%WINDOWS%]\system\lpcoen.dll
[%WINDOWS%]\system\matrixhere.exe
[%WINDOWS%]\system\msspi.dll
[%WINDOWS%]\system\oofndd.dll
[%WINDOWS%]\system\pboola.dll
[%WINDOWS%]\system\pod.dll
[%WINDOWS%]\system\soundmx.exe
[%WINDOWS%]\system\sysstartup.exe
[%WINDOWS%]\system\winupd.exe
[%WINDOWS%]\win86.exe

In order to ensure that the Startpage is launched automatically each time the system is booted, the Startpage adds a link to its executable file in the system registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[%PROFILE_TEMP%]\avicodec.exe
[%PROGRAM_FILES%]\internet explorer\ieengine.exe
[%SYSTEM%]\winupd.exe
[%WINDOWS%]\cl2.exe
[%WINDOWS%]\enewsletterpro.exe
[%DESKTOP%]\ppime.exe
[%STARTUP%]\msupdate.exe
[%STARTUP%]\winlogin.exe
[%SYSTEM%]\actsie4.exe
[%SYSTEM%]\bootconf.exe
[%SYSTEM%]\exp1orer.exe
[%SYSTEM%]\hipewr5.exe
[%SYSTEM%]\jj78208.exe
[%SYSTEM%]\jw09tin.exe
[%SYSTEM%]\matrixhere.exe
[%SYSTEM%]\moneyspj.exe
[%SYSTEM%]\ntldr.exe
[%SYSTEM%]\QuickTimer1.exe
[%SYSTEM%]\sndbdrv3104.exe
[%SYSTEM%]\sysstartup.exe
[%SYSTEM%]\upyyjl.exe
[%SYSTEM%]\usbhdctl.exe
[%SYSTEM%]\winmla32.exe
[%SYSTEM%]\winmm64.exe
[%SYSTEM%]\Www.LookSoft.Net.exe
[%WINDOWS%]\run33.exe
[%WINDOWS%]\system\adrerbcs.exe
[%WINDOWS%]\system\bootconf.exe
[%WINDOWS%]\system\matrixhere.exe
[%WINDOWS%]\system\soundmx.exe
[%WINDOWS%]\system\sysstartup.exe
[%WINDOWS%]\system\winupd.exe
[%WINDOWS%]\win86.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Startpage:

Files:
[%COMMON_APPDATA%]\Tools\tools.dll
[%COMMON_FAVORITES%]\Anti Spyware Soft.url
[%COMMON_FAVORITES%]\avir.ico
[%COMMON_FAVORITES%]\Buy Viagra Online.url
[%COMMON_FAVORITES%]\Cheap Viagra.url
[%COMMON_FAVORITES%]\cialis.ico
[%COMMON_FAVORITES%]\Email Spam Filter.url
[%COMMON_FAVORITES%]\Free Online Casino.url
[%COMMON_FAVORITES%]\gamb.ico
[%COMMON_FAVORITES%]\nospam.ico
[%COMMON_FAVORITES%]\Online AntiVirus and Spyware Remover.url
[%COMMON_FAVORITES%]\Online Directory of Pure Porn.url
[%COMMON_FAVORITES%]\Online Pharmacy.url
[%COMMON_FAVORITES%]\Online Poker.url
[%COMMON_FAVORITES%]\Play in the most popular online casino.url
[%COMMON_FAVORITES%]\poker.ico
[%COMMON_FAVORITES%]\Spyware Remover.url
[%COMMON_FAVORITES%]\spyware.ico
[%COMMON_FAVORITES%]\tgf.ico
[%COMMON_FAVORITES%]\viag.ico
[%FAVORITES%]\Anti Spyware Soft.url
[%FAVORITES%]\avir.ico
[%FAVORITES%]\cialis.ico
[%FAVORITES%]\Email Spam Filter.url
[%FAVORITES%]\gamb.ico
[%FAVORITES%]\nospam.ico
[%FAVORITES%]\Online AntiVirus and Spyware Remover.url
[%FAVORITES%]\Online Pharmacy.url
[%FAVORITES%]\poker.ico
[%FAVORITES%]\shopping\shopping.url
[%FAVORITES%]\Spyware Remover.url
[%FAVORITES%]\spyware.ico
[%FAVORITES%]\tgf.ico
[%FAVORITES%]\viag.ico
[%PROFILE_TEMP%]\avicodec.exe
[%PROFILE_TEMP%]\restsrv32a.sys
[%PROGRAM_FILES%]\internet explorer\ieengine.exe
[%PROGRAM_FILES%]\internet explorer\signup\presario.htm
[%SYSTEM%]\winupd.exe
[%SYSTEM%]\yxuce.dll
[%WINDOWS%]\cl2.exe
[%WINDOWS%]\enewsletterpro.exe
[%WINDOWS%]\hh.htt
[%COMMON_FAVORITES%]\Free Real-time Dating Service.url
[%COMMON_FAVORITES%]\freedating.ico
[%DESKTOP%]\ppime.exe
[%FAVORITES%]\Buy Viagra Online.url
[%FAVORITES%]\Cheap Viagra.url
[%FAVORITES%]\Free Online Casino.url
[%FAVORITES%]\Free Real-time Dating Service.url
[%FAVORITES%]\freedating.ico
[%FAVORITES%]\Online Directory of Pure Porn.url
[%FAVORITES%]\Online Poker.url
[%FAVORITES%]\Play in the most popular online casino.url
[%PROFILE%]\applic~1\setup\setup.dll
[%PROFILE_TEMP%]\se.dll
[%PROFILE_TEMP%]\wpytcnwrobw.dll
[%STARTUP%]\msupdate.exe
[%STARTUP%]\winlogin.exe
[%SYSTEM%]\576bz7yyii.dll
[%SYSTEM%]\7i0s705ifzz.dll
[%SYSTEM%]\9f2ns2sk8wlkk5.dll
[%SYSTEM%]\9qbqe.dll
[%SYSTEM%]\a5i0oof7t7dm.dll
[%SYSTEM%]\abfgoke.dll
[%SYSTEM%]\abo.dll
[%SYSTEM%]\actsie4.exe
[%SYSTEM%]\ael.dll
[%SYSTEM%]\akleaa.dll
[%SYSTEM%]\albgjd.dll
[%SYSTEM%]\bcfjp.dll
[%SYSTEM%]\blbff.dll
[%SYSTEM%]\bnijea.dll
[%SYSTEM%]\bootconf.exe
[%SYSTEM%]\cenbna.dll
[%SYSTEM%]\cjcan.dll
[%SYSTEM%]\clnfg.dll
[%SYSTEM%]\dbdegea.dll
[%SYSTEM%]\dflnca.dll
[%SYSTEM%]\dnnlk.dll
[%SYSTEM%]\drivers\paraudio.sys
[%SYSTEM%]\ebkh.dll
[%SYSTEM%]\enijbaa.dll
[%SYSTEM%]\exp1orer.exe
[%SYSTEM%]\f5u5154vus.dll
[%SYSTEM%]\faaa.dll
[%SYSTEM%]\fikol.dll
[%SYSTEM%]\ggigbca.dll
[%SYSTEM%]\ghpkea.dll
[%SYSTEM%]\gopmkc.dll
[%SYSTEM%]\hfglhh.dll
[%SYSTEM%]\hgcn.dll
[%SYSTEM%]\hipewr5.exe
[%SYSTEM%]\hjam.dll
[%SYSTEM%]\hllo.dll
[%SYSTEM%]\hlp.dll
[%SYSTEM%]\hpagc.dll
[%SYSTEM%]\ihol.dll
[%SYSTEM%]\ijmdnp.dll
[%SYSTEM%]\jajig.dll
[%SYSTEM%]\jfcbjp.dll
[%SYSTEM%]\jfdjgaa.dll
[%SYSTEM%]\jj78208.exe
[%SYSTEM%]\jmleib.dll
[%SYSTEM%]\jnmnnhc.dll
[%SYSTEM%]\joac.dll
[%SYSTEM%]\jomdj.dll
[%SYSTEM%]\jsconsole.dll
[%SYSTEM%]\jw09tin.exe
[%SYSTEM%]\kbdko.dll
[%SYSTEM%]\kea.dll
[%SYSTEM%]\kfe.dll
[%SYSTEM%]\kpnlgd.dll
[%SYSTEM%]\lfphaea.dll
[%SYSTEM%]\lgif.dll
[%SYSTEM%]\lj7i5x.dll
[%SYSTEM%]\lkkmhn.dll
[%SYSTEM%]\lll.dll
[%SYSTEM%]\lnhf.dll
[%SYSTEM%]\lomio.dll
[%SYSTEM%]\lpp.dll
[%SYSTEM%]\matrixhere.exe
[%SYSTEM%]\mbpbfc.dll
[%SYSTEM%]\moneyspj.exe
[%SYSTEM%]\msdoh.dll
[%SYSTEM%]\msspi.dll
[%SYSTEM%]\ncdjoka.dll
[%SYSTEM%]\nld.dll
[%SYSTEM%]\ntldr.exe
[%SYSTEM%]\oalgeec.dll
[%SYSTEM%]\ohnl.dll
[%SYSTEM%]\oplenh.dll
[%SYSTEM%]\pbm.dll
[%SYSTEM%]\pbpb.dll
[%SYSTEM%]\pmgafcc.dll
[%SYSTEM%]\pwl4uoo95kl5.dll
[%SYSTEM%]\QuickTime1.tx
[%SYSTEM%]\QuickTimer1.exe
[%SYSTEM%]\rcoujxlbka.dll
[%SYSTEM%]\regsvrac32.dll
[%SYSTEM%]\restsrv32a.sys
[%SYSTEM%]\SASS.EXE
[%SYSTEM%]\sndbdrv3104.exe
[%SYSTEM%]\sysstartup.exe
[%SYSTEM%]\upyyjl.exe
[%SYSTEM%]\usbhdctl.exe
[%SYSTEM%]\wdmeaii.dll
[%SYSTEM%]\winmla32.exe
[%SYSTEM%]\winmm64.exe
[%SYSTEM%]\Www.LookSoft.Net.dll
[%SYSTEM%]\Www.LookSoft.Net.exe
[%WINDOWS%]\default.css
[%WINDOWS%]\madopew.dll
[%WINDOWS%]\mwshelp.dll
[%WINDOWS%]\restsrv32a.sys
[%WINDOWS%]\run33.exe
[%WINDOWS%]\system\9xzc9d0zi98.dll
[%WINDOWS%]\system\a6z95lih1r9vd.dll
[%WINDOWS%]\system\adgjmpsv.dll
[%WINDOWS%]\system\adrerbcs.exe
[%WINDOWS%]\system\bootconf.exe
[%WINDOWS%]\system\chdekfb.dll
[%WINDOWS%]\system\dhoh.dll
[%WINDOWS%]\system\dla.dll
[%WINDOWS%]\system\flplcg.dll
[%WINDOWS%]\system\hsjnn86uhnvu.dll
[%WINDOWS%]\system\kfeehaa.dll
[%WINDOWS%]\system\kjjo.dll
[%WINDOWS%]\system\lpcoen.dll
[%WINDOWS%]\system\matrixhere.exe
[%WINDOWS%]\system\msspi.dll
[%WINDOWS%]\system\oofndd.dll
[%WINDOWS%]\system\pboola.dll
[%WINDOWS%]\system\pod.dll
[%WINDOWS%]\system\soundmx.exe
[%WINDOWS%]\system\sysstartup.exe
[%WINDOWS%]\system\winupd.exe
[%WINDOWS%]\win86.exe
[%COMMON_APPDATA%]\Tools\tools.dll
[%COMMON_FAVORITES%]\Anti Spyware Soft.url
[%COMMON_FAVORITES%]\avir.ico
[%COMMON_FAVORITES%]\Buy Viagra Online.url
[%COMMON_FAVORITES%]\Cheap Viagra.url
[%COMMON_FAVORITES%]\cialis.ico
[%COMMON_FAVORITES%]\Email Spam Filter.url
[%COMMON_FAVORITES%]\Free Online Casino.url
[%COMMON_FAVORITES%]\gamb.ico
[%COMMON_FAVORITES%]\nospam.ico
[%COMMON_FAVORITES%]\Online AntiVirus and Spyware Remover.url
[%COMMON_FAVORITES%]\Online Directory of Pure Porn.url
[%COMMON_FAVORITES%]\Online Pharmacy.url
[%COMMON_FAVORITES%]\Online Poker.url
[%COMMON_FAVORITES%]\Play in the most popular online casino.url
[%COMMON_FAVORITES%]\poker.ico
[%COMMON_FAVORITES%]\Spyware Remover.url
[%COMMON_FAVORITES%]\spyware.ico
[%COMMON_FAVORITES%]\tgf.ico
[%COMMON_FAVORITES%]\viag.ico
[%FAVORITES%]\Anti Spyware Soft.url
[%FAVORITES%]\avir.ico
[%FAVORITES%]\cialis.ico
[%FAVORITES%]\Email Spam Filter.url
[%FAVORITES%]\gamb.ico
[%FAVORITES%]\nospam.ico
[%FAVORITES%]\Online AntiVirus and Spyware Remover.url
[%FAVORITES%]\Online Pharmacy.url
[%FAVORITES%]\poker.ico
[%FAVORITES%]\shopping\shopping.url
[%FAVORITES%]\Spyware Remover.url
[%FAVORITES%]\spyware.ico
[%FAVORITES%]\tgf.ico
[%FAVORITES%]\viag.ico
[%PROFILE_TEMP%]\avicodec.exe
[%PROFILE_TEMP%]\restsrv32a.sys
[%PROGRAM_FILES%]\internet explorer\ieengine.exe
[%PROGRAM_FILES%]\internet explorer\signup\presario.htm
[%SYSTEM%]\winupd.exe
[%SYSTEM%]\yxuce.dll
[%WINDOWS%]\cl2.exe
[%WINDOWS%]\enewsletterpro.exe
[%WINDOWS%]\hh.htt
[%COMMON_FAVORITES%]\Free Real-time Dating Service.url
[%COMMON_FAVORITES%]\freedating.ico
[%DESKTOP%]\ppime.exe
[%FAVORITES%]\Buy Viagra Online.url
[%FAVORITES%]\Cheap Viagra.url
[%FAVORITES%]\Free Online Casino.url
[%FAVORITES%]\Free Real-time Dating Service.url
[%FAVORITES%]\freedating.ico
[%FAVORITES%]\Online Directory of Pure Porn.url
[%FAVORITES%]\Online Poker.url
[%FAVORITES%]\Play in the most popular online casino.url
[%PROFILE%]\applic~1\setup\setup.dll
[%PROFILE_TEMP%]\se.dll
[%PROFILE_TEMP%]\wpytcnwrobw.dll
[%STARTUP%]\msupdate.exe
[%STARTUP%]\winlogin.exe
[%SYSTEM%]\576bz7yyii.dll
[%SYSTEM%]\7i0s705ifzz.dll
[%SYSTEM%]\9f2ns2sk8wlkk5.dll
[%SYSTEM%]\9qbqe.dll
[%SYSTEM%]\a5i0oof7t7dm.dll
[%SYSTEM%]\abfgoke.dll
[%SYSTEM%]\abo.dll
[%SYSTEM%]\actsie4.exe
[%SYSTEM%]\ael.dll
[%SYSTEM%]\akleaa.dll
[%SYSTEM%]\albgjd.dll
[%SYSTEM%]\bcfjp.dll
[%SYSTEM%]\blbff.dll
[%SYSTEM%]\bnijea.dll
[%SYSTEM%]\bootconf.exe
[%SYSTEM%]\cenbna.dll
[%SYSTEM%]\cjcan.dll
[%SYSTEM%]\clnfg.dll
[%SYSTEM%]\dbdegea.dll
[%SYSTEM%]\dflnca.dll
[%SYSTEM%]\dnnlk.dll
[%SYSTEM%]\drivers\paraudio.sys
[%SYSTEM%]\ebkh.dll
[%SYSTEM%]\enijbaa.dll
[%SYSTEM%]\exp1orer.exe
[%SYSTEM%]\f5u5154vus.dll
[%SYSTEM%]\faaa.dll
[%SYSTEM%]\fikol.dll
[%SYSTEM%]\ggigbca.dll
[%SYSTEM%]\ghpkea.dll
[%SYSTEM%]\gopmkc.dll
[%SYSTEM%]\hfglhh.dll
[%SYSTEM%]\hgcn.dll
[%SYSTEM%]\hipewr5.exe
[%SYSTEM%]\hjam.dll
[%SYSTEM%]\hllo.dll
[%SYSTEM%]\hlp.dll
[%SYSTEM%]\hpagc.dll
[%SYSTEM%]\ihol.dll
[%SYSTEM%]\ijmdnp.dll
[%SYSTEM%]\jajig.dll
[%SYSTEM%]\jfcbjp.dll
[%SYSTEM%]\jfdjgaa.dll
[%SYSTEM%]\jj78208.exe
[%SYSTEM%]\jmleib.dll
[%SYSTEM%]\jnmnnhc.dll
[%SYSTEM%]\joac.dll
[%SYSTEM%]\jomdj.dll
[%SYSTEM%]\jsconsole.dll
[%SYSTEM%]\jw09tin.exe
[%SYSTEM%]\kbdko.dll
[%SYSTEM%]\kea.dll
[%SYSTEM%]\kfe.dll
[%SYSTEM%]\kpnlgd.dll
[%SYSTEM%]\lfphaea.dll
[%SYSTEM%]\lgif.dll
[%SYSTEM%]\lj7i5x.dll
[%SYSTEM%]\lkkmhn.dll
[%SYSTEM%]\lll.dll
[%SYSTEM%]\lnhf.dll
[%SYSTEM%]\lomio.dll
[%SYSTEM%]\lpp.dll
[%SYSTEM%]\matrixhere.exe
[%SYSTEM%]\mbpbfc.dll
[%SYSTEM%]\moneyspj.exe
[%SYSTEM%]\msdoh.dll
[%SYSTEM%]\msspi.dll
[%SYSTEM%]\ncdjoka.dll
[%SYSTEM%]\nld.dll
[%SYSTEM%]\ntldr.exe
[%SYSTEM%]\oalgeec.dll
[%SYSTEM%]\ohnl.dll
[%SYSTEM%]\oplenh.dll
[%SYSTEM%]\pbm.dll
[%SYSTEM%]\pbpb.dll
[%SYSTEM%]\pmgafcc.dll
[%SYSTEM%]\pwl4uoo95kl5.dll
[%SYSTEM%]\QuickTime1.tx
[%SYSTEM%]\QuickTimer1.exe
[%SYSTEM%]\rcoujxlbka.dll
[%SYSTEM%]\regsvrac32.dll
[%SYSTEM%]\restsrv32a.sys
[%SYSTEM%]\SASS.EXE
[%SYSTEM%]\sndbdrv3104.exe
[%SYSTEM%]\sysstartup.exe
[%SYSTEM%]\upyyjl.exe
[%SYSTEM%]\usbhdctl.exe
[%SYSTEM%]\wdmeaii.dll
[%SYSTEM%]\winmla32.exe
[%SYSTEM%]\winmm64.exe
[%SYSTEM%]\Www.LookSoft.Net.dll
[%SYSTEM%]\Www.LookSoft.Net.exe
[%WINDOWS%]\default.css
[%WINDOWS%]\madopew.dll
[%WINDOWS%]\mwshelp.dll
[%WINDOWS%]\restsrv32a.sys
[%WINDOWS%]\run33.exe
[%WINDOWS%]\system\9xzc9d0zi98.dll
[%WINDOWS%]\system\a6z95lih1r9vd.dll
[%WINDOWS%]\system\adgjmpsv.dll
[%WINDOWS%]\system\adrerbcs.exe
[%WINDOWS%]\system\bootconf.exe
[%WINDOWS%]\system\chdekfb.dll
[%WINDOWS%]\system\dhoh.dll
[%WINDOWS%]\system\dla.dll
[%WINDOWS%]\system\flplcg.dll
[%WINDOWS%]\system\hsjnn86uhnvu.dll
[%WINDOWS%]\system\kfeehaa.dll
[%WINDOWS%]\system\kjjo.dll
[%WINDOWS%]\system\lpcoen.dll
[%WINDOWS%]\system\matrixhere.exe
[%WINDOWS%]\system\msspi.dll
[%WINDOWS%]\system\oofndd.dll
[%WINDOWS%]\system\pboola.dll
[%WINDOWS%]\system\pod.dll
[%WINDOWS%]\system\soundmx.exe
[%WINDOWS%]\system\sysstartup.exe
[%WINDOWS%]\system\winupd.exe
[%WINDOWS%]\win86.exe

Folders:
[%PROGRAMS%]\clocksync
[%STARTMENU%]\programs\clocksync
[%PROGRAMS%]\psguard spyware remover

Registry Keys:
HKEY_CLASSES_ROOT\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3}
HKEY_CLASSES_ROOT\interface\{5cde145a-b6b9-408d-a8cc-f9ca040ba7a4}
HKEY_CLASSES_ROOT\interface\{b1e68d42-02c4-465b-8368-5ed9b732e22d}
HKEY_CLASSES_ROOT\winres.windowsresources.1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{54f7fd6e-e782-4f9f-8ff0-677090048729}
HKEY_CLASSES_ROOT\avecore.foundcollection
HKEY_CLASSES_ROOT\avecore.foundcollection.1
HKEY_CLASSES_ROOT\avecore.foundobject
HKEY_CLASSES_ROOT\avecore.foundobject.1
HKEY_CLASSES_ROOT\avecore.killedprocessescollection
HKEY_CLASSES_ROOT\avecore.killedprocessescollection.1
HKEY_CLASSES_ROOT\avecore.killedprocessinfo
HKEY_CLASSES_ROOT\avecore.killedprocessinfo.1
HKEY_CLASSES_ROOT\avecore.license
HKEY_CLASSES_ROOT\avecore.license.1
HKEY_CLASSES_ROOT\avecore.options
HKEY_CLASSES_ROOT\avecore.options.1
HKEY_CLASSES_ROOT\avecore.quarantine
HKEY_CLASSES_ROOT\avecore.quarantine.1
HKEY_CLASSES_ROOT\avecore.realtime
HKEY_CLASSES_ROOT\avecore.realtime.1
HKEY_CLASSES_ROOT\avecore.rtobject
HKEY_CLASSES_ROOT\avecore.rtobject.1
HKEY_CLASSES_ROOT\avecore.safemode
HKEY_CLASSES_ROOT\avecore.safemode.1
HKEY_CLASSES_ROOT\avecore.scaner
HKEY_CLASSES_ROOT\avecore.scaner.1
HKEY_CLASSES_ROOT\avecore.scanstatistic
HKEY_CLASSES_ROOT\avecore.scanstatistic.1
HKEY_CLASSES_ROOT\avecore.theapp
HKEY_CLASSES_ROOT\avecore.theapp.1
HKEY_CLASSES_ROOT\avecore.update
HKEY_CLASSES_ROOT\avecore.update.1
HKEY_CLASSES_ROOT\avecore.updateinfo
HKEY_CLASSES_ROOT\avecore.updateinfo.1
HKEY_CLASSES_ROOT\avecore.versioninfo
HKEY_CLASSES_ROOT\avecore.versioninfo.1
HKEY_CLASSES_ROOT\clsid\{04f3168f-5afc-4531-b3b4-16ca93720415}
HKEY_CLASSES_ROOT\clsid\{057e242f-2947-4e0a-8e61-a11345d97ea6}
HKEY_CLASSES_ROOT\clsid\{09d62e7b-f1a0-46bf-a5ae-eff9e2e22d89}
HKEY_CLASSES_ROOT\clsid\{09e22647-aed1-4025-9940-9234b091caa3}
HKEY_CLASSES_ROOT\clsid\{17016049-c758-4710-a3e8-2800c0c57f0f}
HKEY_CLASSES_ROOT\clsid\{187a8428-bd94-470d-a178-a2347f940519}
HKEY_CLASSES_ROOT\clsid\{2865930b-4588-4ff3-8227-6d4f66c92c7a}
HKEY_CLASSES_ROOT\clsid\{286b4be8-5aab-443c-806a-da7c4064e699}
HKEY_CLASSES_ROOT\clsid\{2d04df1a-015e-4b14-997a-1d9efe429b36}
HKEY_CLASSES_ROOT\clsid\{2e817c58-8b6e-42c1-8fe5-35164212b660}
HKEY_CLASSES_ROOT\clsid\{2fe2edc0-9e62-4f34-8a73-bc66dae48ef3}
HKEY_CLASSES_ROOT\clsid\{357a87ed-3e5d-437d-b334-deb7eb4982a3}
HKEY_CLASSES_ROOT\clsid\{3a3a8c24-8ff0-4140-9731-54d9483ea70b}
HKEY_CLASSES_ROOT\clsid\{3a906593-b4bd-48ed-84b0-3249bed65ef9}
HKEY_CLASSES_ROOT\clsid\{453125c3-7a5e-4581-808c-a70eea670a9b}
HKEY_CLASSES_ROOT\clsid\{49b72a72-01f5-4ae8-bbd7-daa67f1e303b}
HKEY_CLASSES_ROOT\clsid\{4fa2b39b-a7da-983c-68e6-5b095a4118fd}
HKEY_CLASSES_ROOT\clsid\{59e2d3c2-ab30-4295-b301-8849a2166e8c}
HKEY_CLASSES_ROOT\clsid\{60371670-81b9-4d06-9c42-4dec1aabe62b}
HKEY_CLASSES_ROOT\clsid\{6ae3aca6-1be3-4443-98dd-effcfa793d35}
HKEY_CLASSES_ROOT\clsid\{71bafe05-b6c5-49db-9c61-397a60343877}
HKEY_CLASSES_ROOT\clsid\{771f4f1f-643b-4049-a6d5-bca4583424c2}
HKEY_CLASSES_ROOT\clsid\{787dec39-69d0-40b3-b173-e0411c59b300}
HKEY_CLASSES_ROOT\clsid\{79ddf2ef-d881-464b-b2af-5af8816a3964}
HKEY_CLASSES_ROOT\clsid\{8066d67f-7f83-48aa-9edb-faf24d51a76b}
HKEY_CLASSES_ROOT\clsid\{813c8e86-4c90-4617-b59e-e130cc068140}
HKEY_CLASSES_ROOT\clsid\{825862c3-abef-49f1-a243-df8ea3d281d6}
HKEY_CLASSES_ROOT\clsid\{89133bce-57d0-4d2b-afaf-a97b74ad704e}
HKEY_CLASSES_ROOT\clsid\{8f40cc34-fe77-4618-aa3d-bd2efacaa8dc}
HKEY_CLASSES_ROOT\clsid\{8fa142a3-b637-4d4d-ade9-9a205e69cc1e}
HKEY_CLASSES_ROOT\clsid\{9f89e240-06a6-4e1c-ba84-f267de7db391}
HKEY_CLASSES_ROOT\clsid\{b60a0e56-548d-40ae-9383-d752531f653f}
HKEY_CLASSES_ROOT\clsid\{b67b0756-2528-4996-b4bd-c993614cc0b6}
HKEY_CLASSES_ROOT\clsid\{bbe6c0f6-e4a2-410a-9f2c-22aed33eff75}
HKEY_CLASSES_ROOT\clsid\{bcc51ea9-6340-4ebe-8736-13a752ecb0be}
HKEY_CLASSES_ROOT\clsid\{bf333890-39cd-476c-94ec-29493712426c}
HKEY_CLASSES_ROOT\clsid\{c9f55255-0e99-41e6-b302-42ed7caccea5}
HKEY_CLASSES_ROOT\clsid\{cbefb350-ed5b-4115-b846-c1041676b388}
HKEY_CLASSES_ROOT\clsid\{d682d42e-be2c-4758-ab18-926d2e7553b8}
HKEY_CLASSES_ROOT\clsid\{d918e319-211b-42f7-a9d8-e204eab2d40f}
HKEY_CLASSES_ROOT\clsid\{e9719d38-ec55-4c8b-9df0-080ade95a9fa}
HKEY_CLASSES_ROOT\clsid\{fc36e6eb-7dc7-47c7-b5d6-563ceee4608e}
HKEY_CLASSES_ROOT\customie.bho
HKEY_CLASSES_ROOT\customie.bho.1
HKEY_CLASSES_ROOT\interface\{0b6ef17e-18e5-4449-86ea-64c82d596eae}
HKEY_CLASSES_ROOT\interface\{9da65ff0-676f-48c7-9253-0020417f97ee}
HKEY_CLASSES_ROOT\typelib\{344ee577-2027-4714-82ff-0d7538488547}
HKEY_CLASSES_ROOT\typelib\{4947ddcc-d549-4d0b-9685-aa58b20e9642}
HKEY_CLASSES_ROOT\typelib\{aad9a825-7c82-4121-ab7c-c33be0853588}
HKEY_CLASSES_ROOT\winres.windowsresources
HKEY_CLASSES_ROOT\wndlayer.window
HKEY_CLASSES_ROOT\wndlayer.window.1
HKEY_CLASSES_ROOT\wndlayer.windowcollection
HKEY_CLASSES_ROOT\wndlayer.windowcollection.1
HKEY_CLASSES_ROOT\wndlayer.windowlayer
HKEY_CLASSES_ROOT\wndlayer.windowlayer.1
HKEY_CLASSES_ROOT\xmllib.xmldp
HKEY_CLASSES_ROOT\xmllib.xmldp.1
HKEY_CURRENT_USER\software\freeware\{ffb51760-344e-4ffb-bfff-4b18c7ac1d63}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d918e319-211b-42f7-a9d8-e204eab2d40f}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{ffb51760-344e-4ffb-bfff-4b18c7ac1d63}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{09d62e7b-f1a0-46bf-a5ae-eff9e2e22d89}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{09e22647-aed1-4025-9940-9234b091caa3}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{286b4be8-5aab-443c-806a-da7c4064e699}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2d04df1a-015e-4b14-997a-1d9efe429b36}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2e817c58-8b6e-42c1-8fe5-35164212b660}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{453125c3-7a5e-4581-808c-a70eea670a9b}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{59e2d3c2-ab30-4295-b301-8849a2166e8c}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{60371670-81b9-4d06-9c42-4dec1aabe62b}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8066d67f-7f83-48aa-9edb-faf24d51a76b}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{825862c3-abef-49f1-a243-df8ea3d281d6}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8fa142a3-b637-4d4d-ade9-9a205e69cc1e}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{bbe6c0f6-e4a2-410a-9f2c-22aed33eff75}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{bf333890-39cd-476c-94ec-29493712426c}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c9f55255-0e99-41e6-b302-42ed7caccea5}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{cbefb350-ed5b-4115-b846-c1041676b388}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d918e319-211b-42f7-a9d8-e204eab2d40f}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{fc36e6eb-7dc7-47c7-b5d6-563ceee4608e}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\bestsearch
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\psguard spyware remover
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xmllib
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_msqmx
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\msqmx
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\paraudio

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_CLASSES_ROOT\protocols\filter\text/html
HKEY_CLASSES_ROOT\protocols\filter\text/plain
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{524d5441-544e-524e-562d-474145575241}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{524d5441-544e-524e-562d-474145575241}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices

Removing Startpage:

An up-to-date copy of ExterminateIt should detect and prevent infection from Startpage.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Startpage manually.

To completely manually remove Startpage malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Startpage.

  1. Use Task Manager to terminate the Startpage process.
  2. Delete the original Startpage file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Startpage from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Startpage!

Check now if your PC is infected with Startpage

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
AOL.Hell Trojan Information
Vxidl.ANW Trojan Symptoms

Michael.Boot Trojan

Michael.Boot malware description and removal detail
Categories:Trojan,Backdoor,Downloader,DoS
Also known as:

[Kaspersky]Michael.c,Michael.d;
[Panda]Michael.512.C,Michael.512.D

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Michael.Boot:

An up-to-date copy of ExterminateIt should detect and prevent infection from Michael.Boot.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Michael.Boot manually.

To completely manually remove Michael.Boot malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Michael.Boot.

  1. Use Task Manager to terminate the Michael.Boot process.
  2. Delete the original Michael.Boot file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Michael.Boot from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Michael.Boot!

Check now if your PC is infected with Michael.Boot

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
KeyLog.IK97 Spyware Cleaner
FlashTrack.Ftapp Adware Removal instruction

Veloz.com Tracking Cookie

Veloz.com malware description and removal detail
Categories:Tracking Cookie

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Veloz.com:

Registry Keys:
HKEY_CLASSES_ROOT\typelib\{83f0d6aa-cd15-46b5-aa4e-bdb506b4ae53}

Removing Veloz.com:

An up-to-date copy of ExterminateIt should detect and prevent infection from Veloz.com.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Veloz.com manually.

To completely manually remove Veloz.com malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Veloz.com.

  1. Use Task Manager to terminate the Veloz.com process.
  2. Delete the original Veloz.com file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Veloz.com from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Veloz.com!

Check now if your PC is infected with Veloz.com

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
ICOO Loader Adware Removal
Removing Bulla Adware
W112.hitbox.Tracking.Cookie Tracking Cookie Removal instruction
KSLogger Spyware Removal instruction
MyGulp Trojan Cleaner

Amahkey Trojan

Amahkey malware description and removal detail
Categories:Trojan
Also known as:

[Kaspersky]Backdoor.Win32.IRCBot.zx,Backdoor.Win32.IRCBot.aaa;
[Other]Win32/Amahkey.A,Win32/Amahkey.B,W32.IRCBot,Win32/Amahkey.D

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Amahkey:

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\lsass
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\winlogon

Removing Amahkey:

An up-to-date copy of ExterminateIt should detect and prevent infection from Amahkey.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Amahkey manually.

To completely manually remove Amahkey malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Amahkey.

  1. Use Task Manager to terminate the Amahkey process.
  2. Delete the original Amahkey file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Amahkey from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Amahkey!

Check now if your PC is infected with Amahkey

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
Puzzle.Desktop.Sudoku Adware Information

Bancos.HRV Trojan

Bancos.HRV malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Bancos.HRV:

An up-to-date copy of ExterminateIt should detect and prevent infection from Bancos.HRV.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Bancos.HRV manually.

To completely manually remove Bancos.HRV malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Bancos.HRV.

  1. Use Task Manager to terminate the Bancos.HRV process.
  2. Delete the original Bancos.HRV file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Bancos.HRV from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Bancos.HRV!

Check now if your PC is infected with Bancos.HRV

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
SearchBoss Toolbar Removal instruction
NameLater Adware Removal instruction

BannerFarm Tracking Cookie

BannerFarm malware description and removal detail
Categories:Tracking Cookie

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing BannerFarm:

An up-to-date copy of ExterminateIt should detect and prevent infection from BannerFarm.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove BannerFarm manually.

To completely manually remove BannerFarm malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with BannerFarm.

  1. Use Task Manager to terminate the BannerFarm process.
  2. Delete the original BannerFarm file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes BannerFarm from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of BannerFarm!

Check now if your PC is infected with BannerFarm

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
AdvertMen Adware Cleaner

Halfa Trojan

Halfa malware description and removal detail
Categories:Trojan
Also known as:

[Kaspersky]Trojan.HLLP.Half;
[McAfee]Halfa;
[F-Prot]destructive program;
[Panda]Trj/HLLP.Half;
[Computer Associates]COMSYS!Trojan,HLLP.Half

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Halfa:

An up-to-date copy of ExterminateIt should detect and prevent infection from Halfa.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Halfa manually.

To completely manually remove Halfa malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Halfa.

  1. Use Task Manager to terminate the Halfa process.
  2. Delete the original Halfa file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Halfa from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Halfa!

Check now if your PC is infected with Halfa

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
Pigeon.AYR Trojan Information
RCPrograms Adware Removal

Zlob.Fam.XXXSoft Trojan

Zlob.Fam.XXXSoft malware description and removal detail
Categories:Trojan,Popups

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Zlob.Fam.XXXSoft:

An up-to-date copy of ExterminateIt should detect and prevent infection from Zlob.Fam.XXXSoft.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Zlob.Fam.XXXSoft manually.

To completely manually remove Zlob.Fam.XXXSoft malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Zlob.Fam.XXXSoft.

  1. Use Task Manager to terminate the Zlob.Fam.XXXSoft process.
  2. Delete the original Zlob.Fam.XXXSoft file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Zlob.Fam.XXXSoft from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Zlob.Fam.XXXSoft!

Check now if your PC is infected with Zlob.Fam.XXXSoft

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
Remove TWD.Remote.Anything RAT
Master.AOL Trojan Information

NetSetter Adware

NetSetter malware description and removal detail
Categories:Adware,Spyware
Visible Symptoms:
Files in system folders:
[%SYSTEM%]\csloa.dl_
[%SYSTEM%]\nscheck.exe
[%WINDOWS%]\cusnns.bak
[%SYSTEM%]\csloa.dl_
[%SYSTEM%]\nscheck.exe
[%WINDOWS%]\cusnns.bak

In order to ensure that the NetSetter is launched automatically each time the system is booted, the NetSetter adds a link to its executable file in the system registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[%SYSTEM%]\nscheck.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting NetSetter:

Files:
[%SYSTEM%]\csloa.dl_
[%SYSTEM%]\nscheck.exe
[%WINDOWS%]\cusnns.bak
[%SYSTEM%]\csloa.dl_
[%SYSTEM%]\nscheck.exe
[%WINDOWS%]\cusnns.bak

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing NetSetter:

An up-to-date copy of ExterminateIt should detect and prevent infection from NetSetter.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove NetSetter manually.

To completely manually remove NetSetter malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with NetSetter.

  1. Use Task Manager to terminate the NetSetter process.
  2. Delete the original NetSetter file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes NetSetter from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of NetSetter!

Check now if your PC is infected with NetSetter

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
PC.Activity.Monitor.Standard Spyware Removal instruction
Morwill Hijacker Symptoms

Erasesec Trojan

Erasesec malware description and removal detail
Categories:Trojan,Hacker Tool
Also known as:

[Panda]Trj/EraseSectors;
[Computer Associates]Erasesec.8542!Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Erasesec:

An up-to-date copy of ExterminateIt should detect and prevent infection from Erasesec.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Erasesec manually.

To completely manually remove Erasesec malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Erasesec.

  1. Use Task Manager to terminate the Erasesec process.
  2. Delete the original Erasesec file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Erasesec from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Erasesec!

Check now if your PC is infected with Erasesec

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
TrojanDownloader.Win32.Small.fl Downloader Cleaner
Pigeon.AWKM Trojan Removal instruction
date.com Tracking Cookie Information
OverSpy Spyware Removal instruction
Warez Trojan Information