Back to home page
 
Malware is any "malicious software" that runs without the users knowledge or consent
  Table of Contents:
  1. Purpose (go to Purpose)
  2. Important Terminology (go to Trminology)
  3. Warnings (go to Warnings)
  4. Where to begin? (go to Where to begin?)
  5. Symptoms (go to Symptoms)
  6. Alphabetical checklist on handling malware
  1. Purpose(next)
  The following is a list of malicious software ("malware") considered harmful to end users most often runs without their knowledge or consent. The hyperlinks and checklist categories, provided below, illustrate how the software should be removed from the users workstation.
  Removal often entails detailed technical support. If a novice user attempts to remove items from this list the control panel locks up and\or the software cannot be removed simply by using the add and remove programs option in the control panel.
  The list below is kept up to date as new harmful software is detected through popup-blockers, Symantec anti-virus software detection or best practices of the user that keeps themselves informed of the latest attacks.
  Note: Any software which redirects you back to an internet site to uninstall software is considered intrusive and should not remain on the PC.
  2. Important Terminology(next) (back to Table of Contents) For more detailed source for terms go this symantec link.
  a. Adware - Programs that facilitate delivery of advertising content to the user through their own window, or by utilizing another program's interface. In some cases, these programs may gather information from the user's computer, including information related to Internet browser usage or other computing
habits, and relay this information back to a remote computer or other location in cyber-space. Adware can be downloaded from Web sites (typically in shareware or freeware), email messages, and instant messengers. Additionally, a user may unknowingly receive and/or trigger adware by
accepting an End User License Agreement from a software program linked to the adware or from visiting a website that downloads the adware with or without an End User License Agreement.
  b. BHO - A Browser Helper Object, or BHO, is a small program that runs automatically every time you start your Internet browser. Usually, a BHO is installed on your system by another software program. It is a DLL. They can also routinely conflict with other running programs, cause a variety of page faults, run time errors, and the like, and generally impede browsing. If you simply rename the discovered .DLL coming from spyware or adware - you may render connectivity to the internet inoperable. BHO can be linked to Adware or Spyware. It's purpose is to monitor the end user's web serfing habits and sends this data to a remote server. The remote server then can contract with other vendors and send the end user pop-up advertisements. Some types of BHO's detects the time the user has spent on that site and sends that information to affiliated websites. The user then may get other Adware or Spyware from sources they have not connected to.
  c. Data miner - A data miner is a program that can collect information on how you browse and use websites. The collected information can include data gathered from forms you fill in and submit. Usually data miners work without your knowledge. Some spyware tools use this term instead of BHO.
  d. Dialers - Any dialer programs running on a user's workstation should be regarded as a security incident and should be reported immediately because they effect billing and security. Programs that use a computer or modem to dial out to a toll number or internet site, typically to accrue charges. Dialers can be installed with or without a user’s explicit knowledge, and may perform their dialing activity without a user’s specific consent prior to dialing. To get a list of dialer programs click here. For more explicit idea of what dialers do and why they are forbidden click here
  e. Hack Tools - Hack Tools can be used by a hacker or unauthorized user to attack, gain unwelcome access to or perform identification or fingerprinting of your computer. While some hack tools may also be valid for legitimate purposes, their ability to facilitate unwanted access makes them a risk. Hack tools also generally:
 

(1) Attempt to gain information on or access hosts surreptitiously, utilizing methods that circumvent or bypass obvious security mechanisms inherent to the system it is installed on, and/or Facilitate an attempt at disabling a target computer, preventing its normal use.

 

(2) One example of a hack tool is a keystroke logger -- this program that tracks and records individual keystrokes and can send this information back to the hacker. Hack Tool also applies to programs that facilitate attacks on third-party computers as part of a direct or distributed denial-of-service attempt.

  f. Joke - It is a malicious display of messages or distortion of monitor activity Simple scans should be able to remove these files. Some messages give users message that their PC is inoperative. They are closer to hoaxes than adware.
  g. Remote Access - Are programs that allow one computer to access another computer (or facilitate such access) without explicit authorization when an access attempt is made. Once access is gained, usually over the Internet or by direct dial access, the remote access program can attack
or alter other computers. It may also have the ability to gather personal information, or infect or delete files. They may also create the risk that third party programs can exploit its presence to obtain access. Such remote access programs generally:
Attempt to remain unnoticed, either by actively hiding or simply not making their presence on a system known to the user, and/or attempt to hide any evidence of their being accessed remotely over a network or via the internet. These programs provide access that may include notifying a remote host of the machine by sending its address or location, or employing functionality that wholly or partially automates access to the computer on which the program is installed.
  h. Spyware - Programs that have the ability to scan systems or monitor activity and relay information to other computers or locations in cyber-space. Among the information that may be actively or passively gathered and disseminated by Spyware: passwords, log-in details, account numbers, personal information, individual files or other personal documents. Spyware may also gather and distribute information related to the user's computer, applications running on the computer, Internet browser usage or other computing habits. Spyware frequently attempts to remain unnoticed, either by actively hiding or by simply not making its presence on a system known to the user. Spyware can be downloaded from Web sites (typically in shareware or freeware), email messages, and instant messengers. Additionally, a user may unknowingly receive and/or trigger spyware by accepting an End User License Agreement from a software program linked to the spyware or from visiting a website that downloads the spyware with or without an End User License Agreement.
  i. Trackware - Programs that track system activity, gather system information, or track user habits and relay this information to third-party organizations. The information gathered by such programs is neither personally identifiable nor confidential. Trackware programs are installed with the user's consent and may also be packaged as part of other software installed by the user.
  j. Trojan Horse- A destructive program that masquerades as a benign application. Unlike viruses, Trojan horses do not replicate themselves but they can be just as destructive. One of the most insidious types of Trojan horse is a program that claims to rid your computer of viruses but instead introduces viruses onto your computer. Trojan horses can steals system information and send it to predetermined Web servers. An example are false warning notices to users to upgrade Microsoft's Internet Explorer.
  3. Warnings (next) (back to table of contents)
  a. If anyone ignores the message to fix any malware in safe mode with system restore off they may wind up corrupting their workstation.
  b. If the workstation is reimaged because it is badly infected with lots of malware, and the end user does not change their habits of surfing on the internet then the likelihood of the workstation being reinfected is very high.
  c. There are two places to look: Threat History and Tamper History - the vast major of times Threat History will be sufficient
 

(1) Threat History - Four common sources of threats exist - floppies that are infected, CD's that cantain applications that go to the internet to download applications that have spyware or adware attached, surfing sites that contain threats or most common downloading shareware or freeware that carries with it adware/spyware.

 

(2) Tamper History - If internal or external sources attempted to alter the method of Symantec's tamper protection then this would flag identifying the source of the tampering.

  4. Where to begin? (next) (back to table of contents)
  a. Go to Norton Symantec's website search tool as a good starting point . Click here
  b. There is a alphabetical and chronological list of removal tools on Symantec's web site is next place to check. Click here
  c. A list of removal tools from Symantec can be found easily enough Click here.
  d. If the user has not experienced viruses or popups in the past then it is very sound it to check for the most recent attacks.
  e. Another useful link if the malware is not on the list below is Click here Still another useful auxiliary link is Click here
  f. Sometimes it is important to check what processes are running(Ctrl+Alt+Del Task List Processes) to see if they may contain hidden malicious programs unknown to the end user. Click here to check the list of processes and their purpose.
  g. A brief glossary of terms to assist in documentation can be found Click here.
  5. Symptoms: This is a checklist of questions for the end user: (next) (back to table of contents)
    a. Does the workstation run consistently slower than normal?
    b. Does the workstation stop responding or lock up often?
    c. Does the workstation crash or restart every few minutes?
    d. Does the workstation restart on its own and then fails to run normally?
    e. Do applications fail to work properly?
    f. Are disks or disk drives are inaccessible?
    g. Does printing doesn't work correctly?
    h. Does the end user see unusual error messages?
    i. Do Key word searches on the internet redirect the users to unrelated topic?
    j. Does the end user see distorted menus and dialog boxes?
    k. Does the end user receive or respond to unsolicited email with warnings or fixes to applications?
6. Check list for troubleshooting known malware (back to Table of Contents)
Malware Name Types of Risk Safe Mode Use Registry Clean-up Added Action Control Panel?
404 Search Adware Yes Yes  None None Yes
Active Alert Adware Yes Yes Explorer scan Notify Me Do not use
Adware.180Search Adware Yes Yes Explorer scan None Yes
Adware.180 Search Assistant Adware Yes Yes Explorer scan None Yes
Adware.180Solutions Adware Yes Yes Explorer scan None Yes
Adware.AdDestoyer Adware Yes Yes None None Yes
Adware.Adlogix Adware Yes Yes None None No
Adware.Aurora Adware Yes Yes  Explorer scan None Yes
Adware.Bargain Buddy Adware Yes Yes Fix available None Yes
Adware.Begin2search Adware Yes Yes None Notify Me Yes
Adware.BetterIinternet Adware Yes Yes Explorer scan None No
Adware.BlazeFind Adware Yes Yes Fix available None Yes
Adware.Bonzi Adware Yes Yes Explorer scan IE Settings Yes
Adware.Bookedspace Adware Yes Yes None DOS Yes
Adware.Broadcastpc Adware Yes Yes None None Yes
Adware.BrowserAid Adware/BHO Yes Yes IE settings None No
Adware.Buddylinks
Adware Yes Yes Explorer scan None Yes
Adware.Bullseye
Adware Yes Yes Explorer scan None Yes
Adware.CashBackBuddy Adware Yes Yes Explorer scan None Yes
Adware.CDT Adware Yes Yes Fix available None Yes
Adware.ClearSearch Adware Yes Yes Fix available None Yes
Adware.ClickAlchemy Adware Yes Yes Fix available None Yes
Adware.ClickDLoader Adware Yes No None None No
Adware.ClickDLoader.B Adware Yes No None None No
Adware.CoolWebSearch Adware/BHO Yes Yes _ IE settings None No
Adware.Cydoor Adware Yes Yes Kazaa None No
Adware.DashBar Adware Yes Yes None None Yes
Adware.DateManager Adware Yes Yes None None Yes
Adware.DealHelper Adware Yes  Yes Explorer scan None Yes
Adware.DelFin Adware Yes  Yes Explorer scan Kazaa Yes
Adware.DWare Adware Yes  Yes Explorer scan None Yes
Adware.eAnthology Adware UNK UNK No documentation None UNK
Adware.EnhanceMSearch Adware Yes  Yes Explorer scan None No
Adware.Exactbar Adware Yes  Yes Explorer scan None Yes
Adware.EZToolbar Adware/BHO Yes Yes None None No
Adware.Ezula Adware Yes  Yes Explorer scan None Yes
Adware.Fastfind Adware Yes  Yes Explorer scan None No
Adware.Fastfind.B Adware Yes  Yes Explorer scan None No
Adware.FavoriteMan Adware Yes  Yes _ IE Favorites None No
Adware.FlashEnhancer Adware Yes  Yes None None No
Adware.GAIN Adware Yes  Yes Fix available None Yes
Adware.GatorEWallet Adware Yes  Yes Explorer scan Explorer scan Yes
Adware.HalfLemon Adware Yes  Yes IE settings None No
Adware.HelpExpress Adware Yes  Yes Explorer scan None Yes
Adware.Horoscope Adware Yes  Yes Explorer scan None No
Adware Hotbar Adware Yes Yes Fix available  None Yes
Adware.IEDriver Adware Yes  Yes IE settings None Yes
Adware.Iefeats Adware Yes  Yes Fix Available None Yes
Adware.Iefeats!dr Adware Yes  Yes Documentation incomplete None Yes
Adware.IeMenuExt Adware/BHO Yes  Yes None None No
Adware.IEPlugin Adware Yes  Yes Fix available None No
Adware.Incredifind Adware Yes  Yes Explorer scan Explorer scan Yes
Adware.IntDel Adware Yes  Yes Explorer scan None Yes
Adware.iPend Adware Yes  Yes Key word scan None No
Adware.Ipinsight Adware Yes  Yes Fix available None Yes
Adware.Istbar Adware Yes Yes Fix available None Yes
Adware.keenvalue Adware Yes Yes Fix available None No
Adware.Iefeats!dr Adware No No Explorer scan None No
Adware.LinkMaker Adware Yes Yes _ IE Redirect None No
Adware.Look2Me Adware No No _ IE Settings None No
Adware.Lop Adware Yes Yes Restore IE Settings None No
Adware.MainSearch Adware Yes No Restore IE Settings None No
Adware.Margoc Adware Yes Yes Explorer scan None No
Adware.MBKWbar Adware Yes No None None No
Adware.MediaPass Adware Yes Yes None None Yes
Adware.Medload Adware Yes Yes None other adwares No
Adware.MemoryMeter Adware No No EULA settings None Yes- a must
Adware.MoeMoney Adware Yes Yes Explorer scan None No
Adware.Multidropper Adware Yes No None None No
Adware.MXTarget Adware Yes Yes Explorer scan None No
Adware.MXTarget.B Adware Yes Yes Explorer scan None No
Adware.NaviSearch Adware Yes Yes Explorer scan None Yes
Adware.NDotNet Adware Yes Yes Fix available  None Yes
Adware.NeededWare Adware Yes Yes Explorer scan None No
Adware.NetOptimizer Adware Yes Yes Fix available  None Yes
Adware.OMI Adware No No Explorer scan Delete temp folders No
Adware.OverPro Adware Yes No Explorer scan None Yes
Adware.PortalScan Adware Yes Yes Explorer scan _ popup blocker No
Adware.PowerScan Adware Yes No Rescan None No
Adware.PrecisionTime Adware Yes Yes Explorer scan None Yes
Adware.PStrip Adware No No Explorer scan Delete spec files No
Adware.Purity Scan Adware No No Special Instructions None/porn hoax Yes
Adware.QoolAid Adware Yes Yes Explorer scan None No
Adware.Quadro Adware Yes Yes Explorer scan Random executables No
Adware.Raxums Adware Yes Yes Explorer scan registry No
Adware.SAHAgent Adware Yes Yes Explorer scan Vendor allowed Yes allowed by RTP
Adware.Savenow Adware Yes Yes Explorer scan None Yes
Adware.ScreenScenes Adware Yes Yes Explorer scan None Yes
Adware.SecondThought Adware Yes Yes Explorer scan None No
Adware.Shazaa Adware/BHO Yes Yes IE Settings None No
Adware.ShowBehind Adware Yes Yes freeware None No
Adware.SideFind Adware Yes Yes ISTSvc None No
Adware.SideSearch Adware Yes Yes Explorer scan None Yes
Adware.Starware Adware Yes Yes Explorer scan None Yes
Adware.StopPopupAdsNow Adware/BHO Yes Yes Explorer scan None No
Adware.SurfAccuracy Adware Yes Yes None None Yes
Adware.SurfSideKick Adware Yes Yes None None Yes
Adware.SyncroAd Adware Yes Yes None None Yes
Adware.TargetSaver Adware Yes Yes Explorer scan None No
Adware.TopMoxie Adware Yes Yes Explorer scan None Yes
Adware.Topsearch Adware Yes Yes Explorer scan special instructions Yes
Adware.TSAdbot Adware Yes Yes Explorer scan None Yes
Adware.Twaintec Adware/BHO Yes Yes Delete IE history Delete cookies No
Adware.UCMore Adware Yes Yes None None No
Adware.VirtualBouncer Adware Yes Yes See details None Yes
Adware.VirtuMonde Adware Yes Yes Fix available None None
Adware.WebBar Adware No No Run scan only None No
Adware.Webrebates Adware Yes Yes Explorer scan None Yes
Adware.Websearch Adware Yes Yes Fix available IE settings Yes
Adware.WebSecureAlert Adware Yes Yes Explorer scan None Yes
Adware.WhenUSearchBar Adware Yes Yes Explorer scan None Yes
Adware.Windupdate Adware No  No Kill Process None Yes
Adware.Winpup Adware Yes Yes Explorer scan None No
Adware.Winfavorites Adware Yes Yes Explorer scan None Yes
Adware.Winfetch Adware Yes Yes Explorer scan None Yes
Adware.WinTaskAd Adware Yes Yes IE settings None No
Adware.YourSiteBar Adware Yes Yes Chk for Trojan.ISTsvc None Yes
Adware.ZangoSearch Adware Yes Yes None None Yes
Adware.ZestyFind Adware Yes Yes None None No
Alexia Adware No Yes Explorer scan None No
Attempted bho Adware Yes Yes Fix available None No
ATP Adware Yes Yes None Notify Me Do not use
Backdoor.Graybird Trojan Horse Yes Yes Run DOS win.ini No
Backdoor.Tofger Trojan Horse Yes Yes Keystroke Logger Notify Me No
Bonzi buddy Adware Yes Yes Explorer scan IE Settings Yes
BrowserAid Adware Yes Yes Explorer scan None Yes
Bullseye Network Adware Yes Yes Explorer scan None Yes
Cashback buddy Adware Yes Yes Explorer scan None Yes
Clearsearch Adware Yes Yes fix available None No
Context Display Adware Yes Yes None None Do not use
CWS-aboutblank Adware No  Yes  Explorer scan  None No 
daosearch Adware Yes Yes None None No
Desktoptraffic Adware Yes Yes Explorer scan   None Yes 
D-Helper Web Driver Adware Yes  Yes Explorer scan   None No
Dealhelper 1.0.0.49 Adware Yes  Yes Explorer scan None Yes
Dialer.DialPlatform Adware Yes Yes Stop all activity   Notify Me Do not use
Dialer.Generic Adware Yes  Yes Stop all activity Notify Me Do not use
Dialer.Sfonditalia Adware Yes  Yes Stop all activity Notify Me Do not use
Dialer.Teens Adware Yes  Yes Stop all activity Notify Me Do not use
Dialer.WSV Adware Yes  Yes modem ? Notify Me Yes
Dialer_Erotic_Access Adware Yes Yes Stop all activity   Notify Me Do not use
Display Utility Adware Yes Yes Explorer scan None Do not use
Download.Adware Adware Yes Yes Explorer scan None Yes
Download.Psyme Trojan hourse Yes No Run scan None No
Downloader.Trojan Trojan Yes Yes Explorer scan None No
DWARE Adware Yes Yes Explorer scan None Yes
Ebates Moe Money Maker Adware Yes  Yes Explorer scan   None Yes 
Elitebar Internet Explorer Adware Yes  Yes Explorer scan None Yes
Elitehas32 Adware Yes  Yes Internet Options   None No
Elitum Adware Yes  Yes Internet Options None Yes 
EUNIVERSE Adware No  No Explorer scan None Yes
Exactbar Adware Yes Yes Explorer scan None Yes
Farsighter Adware Yes  Yes None None No
FavoriteMan Adware Yes  Yes None None Yes
Form Virus No No Floppy files None No
Gain Adware No  No  Fix available  None  No 
Hacktool.JohntheRipper Hack Tool No No None Notify Me  No
httper Adware No  Can use None None Yes 
Joke.Bonus Joke Yes  No  Check this link scan and remove  No
Joke.Boredom Joke Yes  No  Check this link scan and remove  No
Joke.Geschenk Joke Yes  No  Check this link scan and remove  No
JokeFlipped Joke Yes  No  Check this link scan and remove  No 
Joke.Idiot Joke Yes  No  Check this link scan and remove  No 
Joke.Noise Joke Yes  No  Check this link scan and remove  No 
Joke.Nonsense Joke Yes  No  Check this link scan and remove  No 
Joke.Train Joke Yes  No  Check this link scan and remove  No 
IE Host Adware Yes  Yes Fix available  None No
iLookup Adware Yes Yes None   Notify Me  Do not use
Incredifind Adware Yes  Yes Explorer scan None No 
Instafinder Adware Yes  Yes Internet Options None No
Internet Optimizer Adware Yes Yes Fix available None Yes
LOP Adware Yes Yes IE Toolbar None Yes
Maxspeed Adware Yes Yes Explorer scan None Yes
MDS Search Booster Adware Yes Yes None None Yes
Media Motor Adware Yes  Yes None None No
Megasearch Toolbar Adware Yes  Yes None None No
Memory Watcher Adware Yes  Yes None None Yes
MidAddle Adware Yes Yes  Explorer scan   None Yes 
MHTMLRedir.Exploit Trojan horse No No Update Patches None Yes 
MKWbar Adware No No Email   None Yes 
Napster Unauth Yes Yes Stop all activity   Notify Me  May not be clean
Navisearch Adware Yes Yes  Explorer scan   None Yes 
NCase Adware Yes  Yes Explorer scan None Yes
Outlook Express Unauth Yes No  Explorer scan None No 
Pgate Basic Adware Yes  Yes Regclean  None Yes
Remacc.Radmin Remote Admin Yes  Yes Is user Admin? Notify Me No 
Ron Display Adware Yes Yes None  None Do not use
RX Bar Adware Yes  Yes Explorer scan Notify Me  Do not use
Screensaver Installer Adware No  No Explorer scan None Yes
Search Assistant Adware No  Yes Explorer scan None Yes 
SecurityRisk.Downldr Security Risk Yes Yes Close down FTP w\MMC None Yes
SecurityRisk.NavHelper Security Risk Yes Yes Close down FTP w\MMC None Yes
SEP Adware No No Explorer scan None Yes
shopathomeselect Adware Yes  Yes Explorer scan None Yes
showbehind Adware Yes  Yes Explorer scan None Yes
Sidesbarsearch Adware No No Explorer scan None Yes 
SmartPops Adware Yes Yes  Explorer scan   None No
SmartPops2 Adware Yes Yes  Explorer scan   None No
Software Update Manager Adware No  No Explorer scan None Yes 
Spyware.2020search Spyware/BHO Yes Yes IE settings None No
Spyware.ActivMonAgent Spyware Yes Yes None None No
Spyware.Alexa Trackware Yes Yes IE settings None No
Spyware.Apropos Spyware Yes Yes Fix available Notify Me  Yes - a must
Spyware.ClientMan Spyware/BHO Yes Yes None None No
Spyware.CometCursor Spyware Yes Yes IE Settings Notify Me  Yes
Spyware.e2give Spyware Yes Yes IE Settings Notify Me  Yes - a must
Spyware.Goidr Spyware/bho Yes Yes None None No
Spyware.Marketscore Spyware Yes Yes See special instructions Notify Me  Yes
Spyware.MegaSearch Spyware Yes Yes None None No
Spyware.Seekseek Spyware Yes Yes None None No
Spyware.Shopnav Spyware Yes Yes IE Settings Notify Me  No
Spyware.Webhancer Trackware No No Fix available None Yes
Starware Adware Yes  Yes Explorer scan None Yes
SUBSEARCH Adware No  No Run Spybot None No
T Context Adware No NO Explorer scan None Yes
TIBSDIALER Adware Yes Yes Stop all activity   Notify Me  Do not use
Top Text iLookup Adware No  No Explorer scan None Yes
Trackware Abwiz.C Trojan horse Yes Yes None None No
Trackware Alexa Trackware Yes Yes IE Toolbar None No
Trojan.Adclicker Adware Yes Yes _ service ports None No
Trojan.ByteVerify Spyware/BHO Yes Yes IE Settings None No
Trojan.Desktophijack Trojan horse Yes Yes IE Settings Notify Me  Yes
Trojan.Dropper Trojan horse Yes Yes IE Settings None No
Trojan Horse Trojan Horse No No edit msconfig None None
Trojan.ISTsvc       untested removal tool    
Trojan.LowZones Trojan horse Yes Yes IE Settings None No
Trojan.Repsamo Trojan horse Yes Yes Services None No
Trojan.Stwoyle Trojan horse Yes Yes IE Settings None No
TV Media Adware No  No  Install patch KB88650 None Yes 
URL Display Adware Yes Yes None  None Do not use
VBS.Hart@mm Worm Yes Yes Remove Outlook Notify Me  Run DOS Checks
Virtual Bouncer Adware Yes Yes None  None Yes
W32.Sasser.worm Worm Yes Yes Fix available None None
W32.Sasser.B.worm Worm Yes Yes Fix available None None
W32.Welchia.gen Worm Yes Yes Fix from network None Update patches
Web Savings from Ebates Adware Yes Yes  Explorer scan  None Yes
Weboffer Adware Yes Yes Explorer scan None Yes
Websearch toolbar Adware No  No Run ad-ware None No 
WinTools Easy Installer Adware Yes  Yes Explorer scan None Yes
WMConcept.A Worm Yes Yes Explorer scan Delete file No
WSEM Update Adware Yes  Yes Fix available None Yes 
WSUP Adware No No Install patch KB899588 None No
WTOOLSA Adware Yes  Yes Norton re-scan None No
xxx.toolbar Adware Yes  Yes Stop all activity Notify Me Do not use
Zsearch Adware Yes  Yes Explorer scan None Yes