Friday, November 21, 2008

dBASE Trojan

dBASE malware description and removal detail
Categories:Trojan,Backdoor,Downloader,DoS
Also known as:

[Panda]Dbase,DBase.1864;
[Computer Associates]dBASE

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing dBASE:

An up-to-date copy of ExterminateIt should detect and prevent infection from dBASE.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove dBASE manually.

To completely manually remove dBASE malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with dBASE.

  1. Use Task Manager to terminate the dBASE process.
  2. Delete the original dBASE file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes dBASE from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of dBASE!


Also Be Aware of the Following Threats:
ASpam.Amcis BHO Removal
Bonzo.exe Trojan Information
ujcfedweb.org Tracking Cookie Symptoms
WIC Trojan Symptoms
Clagger Trojan Removal

Neworld.Server Backdoor

Neworld.Server malware description and removal detail
Categories:Backdoor
Also known as:

[Computer Associates]Backdoor/Neworld.b.Server

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Neworld.Server:

An up-to-date copy of ExterminateIt should detect and prevent infection from Neworld.Server.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Neworld.Server manually.

To completely manually remove Neworld.Server malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Neworld.Server.

  1. Use Task Manager to terminate the Neworld.Server process.
  2. Delete the original Neworld.Server file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Neworld.Server from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Neworld.Server!


Also Be Aware of the Following Threats:
Nagem Trojan Information
Rbot.ASW Worm Cleaner
Removing BlackHole Trojan

Win32.Apeldorn Trojan

Win32.Apeldorn malware description and removal detail
Categories:Trojan
Also known as:

[Panda]Joke/Apeldorn

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Win32.Apeldorn:

An up-to-date copy of ExterminateIt should detect and prevent infection from Win32.Apeldorn.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Win32.Apeldorn manually.

To completely manually remove Win32.Apeldorn malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Win32.Apeldorn.

  1. Use Task Manager to terminate the Win32.Apeldorn process.
  2. Delete the original Win32.Apeldorn file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Win32.Apeldorn from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Win32.Apeldorn!


Also Be Aware of the Following Threats:
Bancos.FTZ Trojan Removal
TopRebates Adware Removal instruction
PestCapture Ransomware Symptoms
Browserplugin.com BHO Removal instruction

SoniTroyen Backdoor

SoniTroyen malware description and removal detail
Categories:Backdoor,RAT
Also known as:

[Kaspersky]Backdoor.Sonitro;
[Panda]Backdoor Program.LC;
[Computer Associates]Backdoor/XPriority

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing SoniTroyen:

An up-to-date copy of ExterminateIt should detect and prevent infection from SoniTroyen.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove SoniTroyen manually.

To completely manually remove SoniTroyen malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with SoniTroyen.

  1. Use Task Manager to terminate the SoniTroyen process.
  2. Delete the original SoniTroyen file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes SoniTroyen from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of SoniTroyen!


Also Be Aware of the Following Threats:
MultiDropper.DN.cfg Trojan Symptoms
Keylog.Dafunk Trojan Symptoms

MsWin.A Trojan

MsWin.A malware description and removal detail
Categories:Trojan
Visible Symptoms:
Files in system folders:
[%PROFILE%]\cmd.exe
[%STARTUP%]\MSWin--2109571593.exe
[%STARTUP%]\MSWin-1342439497.exe
[%PROFILE%]\cmd.exe
[%STARTUP%]\MSWin--2109571593.exe
[%STARTUP%]\MSWin-1342439497.exe

In order to ensure that the MsWin.A is launched automatically each time the system is booted, the MsWin.A adds a link to its executable file in the system registry:
HKLM\Microsoft\Windows\CurrentVersion\Run
[%PROFILE%]\cmd.exe
[%STARTUP%]\MSWin--2109571593.exe
[%STARTUP%]\MSWin-1342439497.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting MsWin.A:

Files:
[%PROFILE%]\cmd.exe
[%STARTUP%]\MSWin--2109571593.exe
[%STARTUP%]\MSWin-1342439497.exe
[%PROFILE%]\cmd.exe
[%STARTUP%]\MSWin--2109571593.exe
[%STARTUP%]\MSWin-1342439497.exe

Removing MsWin.A:

An up-to-date copy of ExterminateIt should detect and prevent infection from MsWin.A.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove MsWin.A manually.

To completely manually remove MsWin.A malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with MsWin.A.

  1. Use Task Manager to terminate the MsWin.A process.
  2. Delete the original MsWin.A file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes MsWin.A from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of MsWin.A!


Also Be Aware of the Following Threats:
Removing X2a RAT

Gumbsumb Trojan

Gumbsumb malware description and removal detail
Categories:Trojan
Also known as:

[Kaspersky]Trojan-PSW.Win32.Agent.im,Trojan-PSW.Win32.QQShou.hp,Trojan-PSW.Win32.Lmir.ajo,Trojan-PSW.Win32.WOW.qw,Trojan-Downloader.Win32.Delf.ain;
[McAfee]PWS-Zhengtu;
[F-Prot]W32/Backdoor.SDW;
[Other]Win32/Gumbsumb.I,TSPY_AGENT.GPF,Troj/LegMir-AHT,Infostealer,Win32/Gumbsumb!generic,Win32/Gumbsumb.K,Backdoor.Trojan,Win32/Gumbsumb.P,Win32/Gumbsumb.Q,Troj/PWS-AMU,Trojan.Dropper,W32/Agent.AZJE

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\bdscheca001.dll
[%SYSTEM%]\Cnscheck001.dll
[%SYSTEM%]\Cnscheck100.dll
[%SYSTEM%]\cs1sa1.dll
[%SYSTEM%]\cxscheca001.dll
[%WINDOWS%]\assistse.exe
[%WINDOWS%]\bbs.dll
[%WINDOWS%]\csrsc.exe
[%WINDOWS%]\system\m.EXE
[%WINDOWS%]\system\w.exe
[%WINDOWS%]\system\z.exe
[%SYSTEM%]\bdscheca001.dll
[%SYSTEM%]\Cnscheck001.dll
[%SYSTEM%]\Cnscheck100.dll
[%SYSTEM%]\cs1sa1.dll
[%SYSTEM%]\cxscheca001.dll
[%WINDOWS%]\assistse.exe
[%WINDOWS%]\bbs.dll
[%WINDOWS%]\csrsc.exe
[%WINDOWS%]\system\m.EXE
[%WINDOWS%]\system\w.exe
[%WINDOWS%]\system\z.exe

In order to ensure that the Gumbsumb is launched automatically each time the system is booted, the Gumbsumb adds a link to its executable file in the system registry:
HKLM\Microsoft\Windows\CurrentVersion\Run
[%WINDOWS%]\assistse.exe
[%WINDOWS%]\csrsc.exe
[%WINDOWS%]\system\w.exe
[%WINDOWS%]\system\z.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Gumbsumb:

Files:
[%SYSTEM%]\bdscheca001.dll
[%SYSTEM%]\Cnscheck001.dll
[%SYSTEM%]\Cnscheck100.dll
[%SYSTEM%]\cs1sa1.dll
[%SYSTEM%]\cxscheca001.dll
[%WINDOWS%]\assistse.exe
[%WINDOWS%]\bbs.dll
[%WINDOWS%]\csrsc.exe
[%WINDOWS%]\system\m.EXE
[%WINDOWS%]\system\w.exe
[%WINDOWS%]\system\z.exe
[%SYSTEM%]\bdscheca001.dll
[%SYSTEM%]\Cnscheck001.dll
[%SYSTEM%]\Cnscheck100.dll
[%SYSTEM%]\cs1sa1.dll
[%SYSTEM%]\cxscheca001.dll
[%WINDOWS%]\assistse.exe
[%WINDOWS%]\bbs.dll
[%WINDOWS%]\csrsc.exe
[%WINDOWS%]\system\m.EXE
[%WINDOWS%]\system\w.exe
[%WINDOWS%]\system\z.exe

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{9a0cfc58-5a6f-41ba-9ffe-4320f4f621ba}
HKEY_CLASSES_ROOT\clsid\{9a0cfc58-5a6f-41ba-9ffe-4320f4f62fb1}
HKEY_CLASSES_ROOT\clsid\{ad0aca58-656f-61da-9dfe-5d20f4f611ba}
HKEY_CLASSES_ROOT\clsid\{bc0cfa58-3a6f-51ba-9efe-b320f4f621ba}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices

Removing Gumbsumb:

An up-to-date copy of ExterminateIt should detect and prevent infection from Gumbsumb.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Gumbsumb manually.

To completely manually remove Gumbsumb malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Gumbsumb.

  1. Use Task Manager to terminate the Gumbsumb process.
  2. Delete the original Gumbsumb file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Gumbsumb from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Gumbsumb!


Also Be Aware of the Following Threats:
Roogoo Trojan Symptoms
Win32.Rbot Trojan Symptoms

Koska Trojan

Koska malware description and removal detail
Categories:Trojan
Also known as:

[Panda]Trj/W32.Koska;
[Computer Associates]Win32/Koska!Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Koska:

An up-to-date copy of ExterminateIt should detect and prevent infection from Koska.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Koska manually.

To completely manually remove Koska malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Koska.

  1. Use Task Manager to terminate the Koska process.
  2. Delete the original Koska file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Koska from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Koska!


Also Be Aware of the Following Threats:
Win32.Keylogger.G!Trojan Trojan Cleaner
Vxidl.BFC Trojan Symptoms