UCmore Adware

UCmore malware description and removal detail
Categories:Adware,BHO,Toolbar
Also known as:

[Panda]Adware/Ucmore

Visible Symptoms:
Files in system folders:
[%PROGRAMS%]\UCmore - The Search Accelerator\UCmore Tour.lnk
[%PROGRAM_FILES%]\TheSearchAccelerator\UCMTSAIE.dll
[%SYSTEM%]\uc.dll
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\how to unistall.lnk
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\ucmore tour.lnk
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\ucmore xp - the search accelerator.lnk
[%SYSTEM%]\ucmie.dll
[%SYSTEM%]\ucmtsaie.dll
[%WINDOWS%]\system\uc.dll
[%WINDOWS%]\system\ucmie.dll
[%WINDOWS%]\system\ucmtsaie.dll
[%WINDOWS%]\ucmoreiex.exe
[%PROGRAMS%]\UCmore - The Search Accelerator\UCmore Tour.lnk
[%PROGRAM_FILES%]\TheSearchAccelerator\UCMTSAIE.dll
[%SYSTEM%]\uc.dll
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\how to unistall.lnk
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\ucmore tour.lnk
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\ucmore xp - the search accelerator.lnk
[%SYSTEM%]\ucmie.dll
[%SYSTEM%]\ucmtsaie.dll
[%WINDOWS%]\system\uc.dll
[%WINDOWS%]\system\ucmie.dll
[%WINDOWS%]\system\ucmtsaie.dll
[%WINDOWS%]\ucmoreiex.exe

In order to ensure that the UCmore is launched automatically each time the system is booted, the UCmore adds a link to its executable file in the system registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[%WINDOWS%]\ucmoreiex.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting UCmore:

Files:
[%PROGRAMS%]\UCmore - The Search Accelerator\UCmore Tour.lnk
[%PROGRAM_FILES%]\TheSearchAccelerator\UCMTSAIE.dll
[%SYSTEM%]\uc.dll
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\how to unistall.lnk
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\ucmore tour.lnk
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\ucmore xp - the search accelerator.lnk
[%SYSTEM%]\ucmie.dll
[%SYSTEM%]\ucmtsaie.dll
[%WINDOWS%]\system\uc.dll
[%WINDOWS%]\system\ucmie.dll
[%WINDOWS%]\system\ucmtsaie.dll
[%WINDOWS%]\ucmoreiex.exe
[%PROGRAMS%]\UCmore - The Search Accelerator\UCmore Tour.lnk
[%PROGRAM_FILES%]\TheSearchAccelerator\UCMTSAIE.dll
[%SYSTEM%]\uc.dll
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\how to unistall.lnk
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\ucmore tour.lnk
[%PROFILE%]\administrator\start menu\programs\ucmore xp - the search accelerator\ucmore xp - the search accelerator.lnk
[%SYSTEM%]\ucmie.dll
[%SYSTEM%]\ucmtsaie.dll
[%WINDOWS%]\system\uc.dll
[%WINDOWS%]\system\ucmie.dll
[%WINDOWS%]\system\ucmtsaie.dll
[%WINDOWS%]\ucmoreiex.exe

Folders:
[%PROGRAMS%]\ucmore - the search accelerator
[%PROGRAM_FILES%]\thesearchaccelerator
[%PROGRAM_FILES%]\ucmore
[%PROFILE%]\start menu\programs\ucmore xp - the search accelerator

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{267395c4-3cba-4e6e-8fe1-efaa33185685}
HKEY_CLASSES_ROOT\CLSID\{44BE0690-5429-47f0-85BB-3FFD8020233E}
HKEY_CLASSES_ROOT\CLSID\{53CBEE82-D747-11D3-9ED0-005004189684}
HKEY_CLASSES_ROOT\clsid\{ed8db0fd-d8f4-4b2c-bb5b-9ef040fe104d}
HKEY_CLASSES_ROOT\interface\{67f59627-8b6d-4643-97f3-1c58b28d8b17}
HKEY_CLASSES_ROOT\iucmore.ucmoreapp
HKEY_CLASSES_ROOT\iucmore.ucmoreapp.1
HKEY_CLASSES_ROOT\typelib\{c347eca2-ef7d-46ba-ae8e-92a10e559514}
HKEY_CURRENT_USER\software\effective-i\thesearchaccelerator
HKEY_CURRENT_USER\software\maxthon\plugin\toolbar\{44be0690-5429-47f0-85bb-3ffd8020233e}
HKEY_LOCAL_MACHINE\software\classes\apuc.urlcatcher.1\clsid
HKEY_LOCAL_MACHINE\software\classes\clsid\{44be0690-5429-47f0-85bb-3ffd8020233e}
HKEY_LOCAL_MACHINE\software\classes\clsid\{53cbee82-d747-11d3-9ed0-005004189684}
HKEY_LOCAL_MACHINE\software\classes\clsid\{ed8db0fd-d8f4-4b2c-bb5b-9ef040fe104d}
HKEY_LOCAL_MACHINE\software\effective-i\thesearchaccelerator
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED8DB0FD-D8F4-4B2C-BB5B-9EF040FE104D}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ucmore
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ucmore - the search accelerator
HKEY_LOCAL_MACHINE\software\ucmore
HKEY_CLASSES_ROOT\clsid\{44be0690-5429-47f0-85bb-3ffd8020233e}
HKEY_CLASSES_ROOT\clsid\{53cbee82-d747-11d3-9ed0-005004189684}
HKEY_CLASSES_ROOT\clsid\{71cc3bd4-6217-44ab-b8d0-96aeaf9a8678}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{ed8db0fd-d8f4-4b2c-bb5b-9ef040fe104d}
HKEY_CURRENT_USER\software\ucmore
HKEY_LOCAL_MACHINE\software\classes\clsid\{71cc3bd4-6217-44ab-b8d0-96aeaf9a8678}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ed8db0fd-d8f4-4b2c-bb5b-9ef040fe104d}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ucmore - the search accelerator displayversion ucmore xp - the search accelerator 4.5.1.0
HKEY_LOCAL_MACHINE\software\microsoft\windows\ucid

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows

Removing UCmore:

An up-to-date copy of ExterminateIt should detect and prevent infection from UCmore.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove UCmore manually.

To completely manually remove UCmore malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with UCmore.

  1. Use Task Manager to terminate the UCmore process.
  2. Delete the original UCmore file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes UCmore from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of UCmore!

Check now if your PC is infected with UCmore

You can buy full version of ExterminateIt at RegNow.com.


Also Be Aware of the Following Threats:
Removing Sylvia.Hong.Kong Trojan
Pigeon.ERX Trojan Symptoms
Key.Emulator Trojan Cleaner

No comments: