Archive for the 'Startup Type' Category

Setup.pif

Sunday, February 1st, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: Setup
Filename: Setup.pif
Registry key:

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acd4847d-9849-11dc-b2f6-9d22d1eb4b51}

Command: C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif
CLSID: acd4847d-9849-11dc-b2f6-9d22d1eb4b51
Startup Type: autorun.inf
Description: autorun.inf trojan component, Troj/DownLd-AAP Trojan [sophos]

How to remove: How to remove trojans that uses autorun.inf file

cmcfg3n.dll

Sunday, February 1st, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: cmcfg3n
Filename: cmcfg3n.dll
Registry key:

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{91754c08-fbce-11dc-b351-00c09fa32033}

Command: rundll32.exe .\\cmcfg3n.dll,InstallM
CLSID: 91754c08-fbce-11dc-b351-00c09fa32033
Startup Type: autorun.inf
Description: unknown autorun.inf trojan component

How to remove: How to remove trojans that uses autorun.inf file

kbdyl.dll is a backdoor trojan

Sunday, February 1st, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: kbdyl
Filename: kbdyl.dll
Registry key:

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{89e65cc6-517d-11dd-b402-00c09fa32033}

Command: rundll32.exe .\\kbdyl.dll,InstallM
CLSID: 89e65cc6-517d-11dd-b402-00c09fa32033
Startup Type: autorun.inf
Description: autorun.inf trojan component, Backdoor.Darkmoon.C [Symantec]

How to remove: How to remove trojans that uses autorun.inf file

MS32DLL.dll.vbs

Saturday, January 31st, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: MS32DLL.dll
Filename: MS32DLL.dll.vbs
Registry key:

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{665e2d89-b71e-11dc-b303-a1d3c996a05f}

Command: C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs
CLSID: 665e2d89-b71e-11dc-b303-a1d3c996a05f
Startup Type: autorun.inf
Description: autorun.inf trojan, VBS.Zodgila [Symantec]

How to remove: How to remove trojans that uses autorun.inf file

tel.xls.exe

Saturday, January 31st, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: tel.xls
Filename: tel.xls.exe
Registry key:

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4f4d33b2-3b87-11dc-a66c-db09a7dc4b52}

Command: C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tel.xls.exe
CLSID: 4f4d33b2-3b87-11dc-a66c-db09a7dc4b52
Startup Type: autorun.inf
Description: autorun.inf trojan component
Threat Alias:

Backdoor.VB.ESE [PC Tools]
W32/USBAgent [McAfee]
W32.SillyFDC [Symantec]
WORM_VB.ERF [Trend Micro]
Trojan.Win32.VB.atg [Kaspersky Lab]

How to remove: How to remove trojans that uses autorun.inf file

d.com

Saturday, January 31st, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: d
Filename: d.com
Registry key:

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10219a1d-d86f-11dc-b316-a69dd264945f}

Command: F:\d.com
Startup Type: autorun.inf
Description: autorun.inf trojan component

How to remove: How to remove trojans that uses autorun.inf file

What is msansspc.dll, How to remove msansspc.dll

Saturday, January 31st, 2009

msansspc.dll is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: msansspc
Filename: msansspc.dll
Registry key:

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders | “SecurityProviders”=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll

Command: C:\WINDOWS\system32\msansspc.dll
Startup Type: SecurityProviders
Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
“SecurityProviders”=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll

Description: trojan

How to remove: use Malwarebytes Anti-malware.

vdac.cmd

Saturday, January 31st, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: vdac
Filename: vdac.cmd
Registry key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{781ab33f-85fd-11dd-98e0-0015afe71045}
Command: J:\vdac.cmd
Startup Type: autorun.inf
Description: autorun.inf trojan component

How to remove: How to remove trojans that uses autorun.inf file

nqecmus.exe

Saturday, January 31st, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: nqecmus
Filename: nqecmus.exe
Registry key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30f0e414-95d0-11dd-992b-001f3ad30b24}
Startup Type: autorun.inf
Description: autorun.inf trojan component
Threat Alias:

Generic.dx [McAfee]
Packed/NSPack [PC Tools]
WORM_NSPACK.AG [Trend Micro]

How to remove: How to remove trojans that uses autorun.inf file

y82td3td.com

Saturday, January 31st, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: y82td3td
Filename: y82td3td.com
Registry key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{156348aa-6f7d-11dd-a36f-ffb4bd6902f1}
Command: G:\y82td3td.com
Startup Type: autorun.inf
Description: autorun.inf trojan component
Threat Aliases:

Trojan.Lineage.Gen!Pac.3 [PC Tools]
Mal/EncPk-CE [Sophos]
PWS-Gamania.gen.a [McAfee]
PWS-LegMir.gen.k [McAfee]
PWS:Win32/Frethog.gen!L [Microsoft]
Trojan.Packed.NsAnti [Symantec]
Worm.Win32.AutoRun.cva [Kaspersky Lab]
Mal_NSAnti-1 [Trend Micro]
Packed.Win32.PolyCrypt.h [Kaspersky Lab]
PE_SALITY.M [Trend Micro]
TSPY_ONLINEG.CTR [Trend Micro]
W32.Gammima.AG [Symantec]
W32/Sality.ae [McAfee]
Win32.Sality.AK [PC Tools]
Worm:Win32/Taterf.gen!C [Microsoft]

How to remove: How to remove trojans that uses autorun.inf file