Monday, December 1, 2008

CProc Downloader

CProc malware description and removal detail
Categories:Downloader
Also known as:

[Kaspersky]Trojan-Downloader.MSIL.Agent.c;
[Other]Adware.TargetSaver

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\crunner\cproc.exe
[%SYSTEM%]\crunner\cupdater.exe
[%SYSTEM%]\crunner\cproc.exe
[%SYSTEM%]\crunner\cupdater.exe

In order to ensure that the CProc is launched automatically each time the system is booted, the CProc adds a link to its executable file in the system registry:
HKLM\Microsoft\Windows\CurrentVersion\Run
[%SYSTEM%]\crunner\cproc.exe
[%SYSTEM%]\crunner\cupdater.exe

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting CProc:

Files:
[%SYSTEM%]\crunner\cproc.exe
[%SYSTEM%]\crunner\cupdater.exe
[%SYSTEM%]\crunner\cproc.exe
[%SYSTEM%]\crunner\cupdater.exe

Folders:
[%SYSTEM%]\crunner

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\classes\clsid\{f4c4d3ae-0bb0-1033-0729-050001}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run

Removing CProc:

An up-to-date copy of ExterminateIt should detect and prevent infection from CProc.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove CProc manually.

To completely manually remove CProc malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with CProc.

  1. Use Task Manager to terminate the CProc process.
  2. Delete the original CProc file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes CProc from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of CProc!


Also Be Aware of the Following Threats:
Danschl Trojan Cleaner

WordMacro.Paper Trojan

WordMacro.Paper malware description and removal detail
Categories:Trojan,Backdoor,Downloader,DoS
Also known as:

[Computer Associates]WordMacro/Paper.A

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing WordMacro.Paper:

An up-to-date copy of ExterminateIt should detect and prevent infection from WordMacro.Paper.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove WordMacro.Paper manually.

To completely manually remove WordMacro.Paper malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with WordMacro.Paper.

  1. Use Task Manager to terminate the WordMacro.Paper process.
  2. Delete the original WordMacro.Paper file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes WordMacro.Paper from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of WordMacro.Paper!


Also Be Aware of the Following Threats:
Vxidl.ABO Trojan Removal instruction
Removing Myss Trojan
Msgmess Trojan Removal instruction

Tupcess Trojan

Tupcess malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Tupcess:

An up-to-date copy of ExterminateIt should detect and prevent infection from Tupcess.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Tupcess manually.

To completely manually remove Tupcess malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Tupcess.

  1. Use Task Manager to terminate the Tupcess process.
  2. Delete the original Tupcess file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Tupcess from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Tupcess!


Also Be Aware of the Following Threats:
Remove TrafficSector BHO

Vxidl.ALC Trojan

Vxidl.ALC malware description and removal detail
Categories:Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing Vxidl.ALC:

An up-to-date copy of ExterminateIt should detect and prevent infection from Vxidl.ALC.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Vxidl.ALC manually.

To completely manually remove Vxidl.ALC malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Vxidl.ALC.

  1. Use Task Manager to terminate the Vxidl.ALC process.
  2. Delete the original Vxidl.ALC file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Vxidl.ALC from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Vxidl.ALC!


Also Be Aware of the Following Threats:
Sdbot Trojan Symptoms

IRC.Flood.ba Trojan

IRC.Flood.ba malware description and removal detail
Categories:Trojan,Backdoor,Hacker Tool,DoS
Also known as:

[Kaspersky]Backdoor.IRC.Cloner.v,Backdoor.IRC.mIRC-based,Backdoor.mIRC-based,Trojan.BAT.Passer.a;
[Eset]IRC/Cloner.O trojan,IRC/Goodbot trojan;
[McAfee]IRC/Flood.ak.plugin,IRC/Flood.bq;
[F-Prot]security risk or a "backdoor" program;
[Panda]Bck/IRC.Mirc.Based,HackTool/Stdio.A,Trj/Passer.J;
[Computer Associates]BAT.IRCFlood,Bat/Flood.C!Trojan,IRC.Flood,mIRC/Flood!Trojan,mIRC/Shaz.A!Worm,Win32.IRCFlood,Win32/IRCFlood.Abc!Trojan

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing IRC.Flood.ba:

An up-to-date copy of ExterminateIt should detect and prevent infection from IRC.Flood.ba.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove IRC.Flood.ba manually.

To completely manually remove IRC.Flood.ba malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with IRC.Flood.ba.

  1. Use Task Manager to terminate the IRC.Flood.ba process.
  2. Delete the original IRC.Flood.ba file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes IRC.Flood.ba from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of IRC.Flood.ba!


Also Be Aware of the Following Threats:
Removing IRCFlood.RTEL Trojan
France.Sex Adware Removal
Remove WebDownloader.by Downloader
Mastab Trojan Removal
Vxidl.BEF Trojan Information

Lookup.Ineb Hijacker

Lookup.Ineb malware description and removal detail
Categories:Hijacker
Also known as:

[Other]I-LookUp

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Detecting Lookup.Ineb:

Registry Keys:
HKEY_CURRENT_USER\software\ineb

Removing Lookup.Ineb:

An up-to-date copy of ExterminateIt should detect and prevent infection from Lookup.Ineb.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove Lookup.Ineb manually.

To completely manually remove Lookup.Ineb malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with Lookup.Ineb.

  1. Use Task Manager to terminate the Lookup.Ineb process.
  2. Delete the original Lookup.Ineb file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes Lookup.Ineb from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of Lookup.Ineb!


Also Be Aware of the Following Threats:
Removing Supervisor.Plus RAT
ContextUAd Adware Removal instruction

CWS.Ld Hijacker

CWS.Ld malware description and removal detail
Categories:Hijacker

Platforms / OS: Windows 95, Windows 98, Windows 98 SE, Windows NT, Windows ME, Windows 2000, Windows XP, Windows 2003, Windows Vista

Removing CWS.Ld:

An up-to-date copy of ExterminateIt should detect and prevent infection from CWS.Ld.

If you do not have ExterminateIt and you are worried that you may have infected computer, you could run trial version of ExterminateIt, or remove CWS.Ld manually.

To completely manually remove CWS.Ld malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with CWS.Ld.

  1. Use Task Manager to terminate the CWS.Ld process.
  2. Delete the original CWS.Ld file and folders.
  3. Delete the system registry key parameters
  4. Update your antivirus databases or buy antivirus software and perform a full scan of the computer.

We recommends that all Internet users back up any important information on their computers, enable maximum protection from network attacks and malicious code on their computers, refrain from executing suspicious programs received from untrustworthy sources.


ExterminateIt effectively and automatically removes CWS.Ld from you computer and is a good solution for those who are seeking easy and effective protection for their computer from Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware).

Download ExterminateIt! to instantly get rid of CWS.Ld!


Also Be Aware of the Following Threats:
ZOMBY.Server Trojan Symptoms