|
|
| ClkOptimizer Winsync WebNexus
|
|
ClkOptimizer
Adware:Adware/ClkOptimizer - C:\Documents and Settings\User\Local Settings\Temp\f1164218.exe
Adware:Adware/ClkOptimizer - C:\Documents and Settings\User\Local Settings\Temp\f1416781.exe
Adware:Adware/ClkOptimizer - C:\Documents and Settings\User\Local Settings\Temp\f1532093.exe
HKEY_CLASSES_ROOT\CLSID\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}
HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Winsync
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebNexus
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\fyqfmxgs
NO NAME REG_SZ {93cd1fd5-0ee7-4f0d-9a72-89ac5b9ade67}
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\fyqfmxgs]
|
Download the the FindQoologic and save it to your Desktop.
http://virus-protect.org/findqoologic.html
http://virus-protect.org/artikel/tools/quofixhttp.html
1- Extract (unzip) the files inside into their own folder called FindQoologic.
* urllogic C:\WINDOWS\JNKJM.DLL
* qoologic C:\WINDOWS\JNKJM.DLL
* ad-beh C:\WINDOWS\System32\TYGTSRP.DLL
* ad-beh C:\WINDOWS\System32\ARAAD.DLL
* ad-beh C:\WINDOWS\System32\VZNVIK.EXE
* ad-beh C:\WINDOWS\System32\BAOBDMC.EXE
»»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
* exe C:\docume~1\alluse~1\startm~1\programs\startup\NATN.EXE
|
|