Emsisoft Malware-Info
Name: Adware.Win32.Ray2009
Risklevel: Low Risk
Description:
This applications contain trojan.
Removal instructions for Adware Ray2009:
To delete this malware infection, buy Emsisoft Anti-Malware.
Guaranteed removal of Adware Ray2009.
Run a full scan on all drives and move all detected items to the quarantine.
More details about this danger:
Installation: Installed through EXE
Process: iePlayer.exe
Screenshots:
Used folders:
- C:\Program Files\WindowsUpdate\
- C:\WINDOWS\
- C:\WINDOWS\ad405cn\
- C:\WINDOWS\system32\
- C:\Documents and Settings\All Users\Start Menu\
- C:\Documents and Settings\All Users\Start Menu\Programs\
- C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\
- C:\Documents and Settings\[USER]\Cookies\
- C:\Documents and Settings\[USER]\Desktop\
- C:\Documents and Settings\[USER]\Favorites\
- C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\
- C:\Documents and Settings\[USER]\Local Settings\Temp\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\
- C:\Documents and Settings\[USER]\Start Menu\
- C:\Documents and Settings\[USER]\Start Menu\Programs\
- C:\Documents and Settings\[USER]\Start Menu\Programs\Startup\
Used files:
- C:\Program Files\WindowsUpdate\tvxyzf.exe
[83968 Bytes] EXE File - C:\WINDOWS\8389156.exe
[31304 Bytes] EXE File - C:\WINDOWS\8389631.exe
[44032 Bytes] EXE File - C:\WINDOWS\conme.exe
[35840 Bytes] EXE File - C:\WINDOWS\ad405cn\045.exe
[45056 Bytes] EXE File - C:\WINDOWS\ad405cn\2847.exe
[83968 Bytes] EXE File - C:\WINDOWS\ad405cn\284734.exe
[28672 Bytes] EXE File - C:\WINDOWS\ad405cn\abc.js
[1449 Bytes] JS File - C:\WINDOWS\ad405cn\ATLcom.dll
[90112 Bytes] DLL File - C:\WINDOWS\ad405cn\iePlayer.exe
[68608 Bytes] EXE File - C:\WINDOWS\ad405cn\info2asp.exe
[41984 Bytes] EXE File - C:\WINDOWS\ad405cn\player011.exe
[184320 Bytes] EXE File - C:\WINDOWS\ad405cn\Setup.exe
[180736 Bytes] EXE File - C:\WINDOWS\ad405cn\Update.exe
[57856 Bytes] EXE File - C:\WINDOWS\ad405cn\update.txt
[227 Bytes] TXT File - C:\WINDOWS\system32\3079788e96.dll
[0 Bytes] DLL File - C:\WINDOWS\system32\svcynzyk.exe
[76288 Bytes] EXE File - C:\Documents and Settings\All Users\Start Menu\Internet Explorer.lnk
[1819 Bytes] LNK File - C:\Documents and Settings\All Users\Start Menu\Programs\Internet Explorer.lnk
[1825 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
[1837 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\QQ???.lnk
[208 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\???????????????.lnk
[615 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\????????????.lnk
[208 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\???.lnk
[208 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\??????.lnk
[192 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\???????.lnk
[208 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\????????.lnk
[202 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\????.lnk
[208 Bytes] LNK File - C:\Documents and Settings\[USER]\Cookies\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Cookies\virus demo@atdmt[1].txt
[0 Bytes] TXT File - C:\Documents and Settings\[USER]\Cookies\virus demo@bs.serving-sys[2].txt
[0 Bytes] TXT File - C:\Documents and Settings\[USER]\Cookies\virus demo@c.msn[1].txt
[0 Bytes] TXT File - C:\Documents and Settings\[USER]\Cookies\virus demo@doubleclick[1].txt
[0 Bytes] TXT File - C:\Documents and Settings\[USER]\Cookies\virus demo@live[1].txt
[0 Bytes] TXT File - C:\Documents and Settings\[USER]\Cookies\virus demo@msnportal.112.2o7[1].txt
[0 Bytes] TXT File - C:\Documents and Settings\[USER]\Cookies\virus demo@msn[2].txt
[0 Bytes] TXT File - C:\Documents and Settings\[USER]\Cookies\virus demo@rad.msn[2].txt
[0 Bytes] TXT File - C:\Documents and Settings\[USER]\Cookies\virus demo@serving-sys[1].txt
[0 Bytes] TXT File - C:\Documents and Settings\[USER]\Cookies\virus demo@www.msn[2].txt
[0 Bytes] TXT File - C:\Documents and Settings\[USER]\Desktop\7k7k????.lnk
[1755 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\Delete Sandbox.lnk
[1739 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\Internet Explorer.lnk
[1819 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\QQ???.lnk
[208 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\Sandboxie RegViewer.lnk
[1701 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\Shortcut to AppSniff.exe.lnk
[843 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\Terminate.lnk
[1717 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\???????????????.lnk
[1641 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\????????????.lnk
[208 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\???.lnk
[208 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\??????.lnk
[192 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\???????.lnk
[208 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\????????.lnk
[202 Bytes] LNK File - C:\Documents and Settings\[USER]\Desktop\????.lnk
[208 Bytes] LNK File - C:\Documents and Settings\[USER]\Favorites\???????????[??????-???????Z????].url
[144 Bytes] URL File - C:\Documents and Settings\[USER]\Favorites\??256??????--??????--????????????????.url
[148 Bytes] URL File - C:\Documents and Settings\[USER]\Favorites\????,????????,???????,7k7k????.url
[144 Bytes] URL File - C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\Temp\p19.exe
[831820 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temp\svchost.exe
[18186 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temp\~DFD36F.tmp
[16384 Bytes] TMP File - C:\Documents and Settings\[USER]\Local Settings\Temp\~DFFE49.tmp
[16384 Bytes] TMP File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\index.dat
[81920 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\082[1].exe
[44032 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\284734[1].exe
[28672 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\dll[1].htm
[1 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\function[1].js
[12084 Bytes] JS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\update[1].txt
[227 Bytes] TXT File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\19[1].exe
[868181 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\base[1].css
[1744 Bytes] CSS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\default[1].css
[31420 Bytes] CSS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\Setup[1].exe
[180736 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\123[1].exe
[31304 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\2847[1].exe
[83968 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\common[1].js
[8014 Bytes] JS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\player011[1].exe
[184320 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\045[1].exe
[45056 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\222233[1].htm
[59016 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\csrs[1].exe
[76288 Bytes] EXE File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\ver4[1].txt
[282 Bytes] TXT File - C:\Documents and Settings\[USER]\Start Menu\Internet Explorer.lnk
[1819 Bytes] LNK File - C:\Documents and Settings\[USER]\Start Menu\Programs\Internet Explorer.lnk
[1825 Bytes] LNK File - C:\Documents and Settings\[USER]\Start Menu\Programs\Startup\???????????????.lnk
[609 Bytes] LNK File
Additional information might be found here:
Search
at Google for
Adware Ray2009
Search at Bing for
Adware Ray2009
Search
at Yahoo for
Adware Ray2009
How can I protect myself from Adware Ray2009?
Important!
You essentially need an antivirus product, that is not only able to clean infections, but also protect your PC permanently from new dangers.
This is the only way to prevent data loss and unnecessary hassle and costs of new installations of your operating system.
Take your chance and buy the multiple awarded protection software Emsisoft Anti-Malware today!
Only $40 for the security of your computer.
Buy Emsisoft Anti-Malware online:
Trust only on the best protection software!
Spring Offer!
Don't miss this: To your bought 1-year license of Emsisoft Anti-Malware or Emsisoft Internet Security Pack or higher you can now get
a free license of the CyberGhost Anonymizer for free.
Your advantage: Surf anonymously and visit websites that are restricted in your country.
Only a few days left! Order here



















