IBM Server Site

IBS Home Up Virus _scui.cpl Backdoor.Win32.Transistor.11.e

Various Viruses Encountered on Client PCs

Virus Research & Download Site

Adware Trojan - Trayicon.ocx

Spyware Memory Watcher Information
Name: Memory Watcher
Category: Adware
Date: 2005-03-19
Dangerous:
Yes
Memory Watcher belongs to Adware spyware category.
It's presense means that your computer is infected with malicious software and is insecure.
Memory Watcher description by publisher:
from the web site: ´Have you noticed that your computer runs a bit slow when you run many programs at the same time? Have programs crashed or, even worse, has your computer frozen such that the only alternative left for you is to reboot your machine, leaving you with unsaved work? If so, then you are running short on memory resources. By downloading Memory Monitorer, you can now watch your computer´s memory usage. If you find that you are running low on memory resources, Memory Monitorer will make you aware of this by displaying a meter that tells you how much memory resources are being used. With Memory Monitorer, you can now avoid running low on memory & having your computer crash before it is too late.´ -- www.memorymonitorer.com
This Adware is also known as:
Adware/MemoryWatcher - named by Panda.
Backdoor.VB.oq - named by a.
Win32.Memwatch.B - named by Computer Associates.
Win32/Raquad.B!Trojan - named by Computer Associates.

Below listed processes registry entries files directories are part of this spyware. To manually get rid of it, follow these instructions (at your own risk).
Memory Watcher Removal Instructions
Kill the following processes
memorywatcher_b.exe, memorywatcher_b.exe, memorywatcher.exe, memorywatcher.exe, uninst.exe, wowex32.exe, jqvgne.exe, mcl7.exe, ncisp.exe, pnkdb03.exe, qbk7x.exe, rpbbf5.exe, sdelh.exe, vchsyjo.exe, wprx.exe, wyrgmw.exe, xtgcu7.exe, zvbyl.exe, memorywatcher_b.exe, wowex32[1].exe
Delete these registry entries
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2#9s2kp4ztk7b@
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2#myg@j2k5x@kh
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\26ayhse3@8zpx7
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2dh3bz554zbkry
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2hhypx@3tn4pxc
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2kad2lz3h23#ma
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2ljpns64g5gclq
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2pkwz@j3fmzmrh
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2tnw49j45s2ltl
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2w62w2f5kb2@cy
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2xr4f6w2w9jjgg
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\2zd2bm23y3xhst
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\33lel3q3xzawbs
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\35sjwd74#zbj36
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\3aczez@23gtazq
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\3gmdsrs2ng449t
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\3lq#pte4s5kqew
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\3p@ypjy3ckbtyz
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\3pw#hs@2n34ja9
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\3yrarps2zt8rwd
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\4#yqtfx5pxdzth
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\47gp8ys4shn7x8
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\4a692ay5nrf@3a
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\4aweywx3kr4jel
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\4b#abzb3lxzlex
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\4gmpqkj5la227a
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\4hkmkb74y4ka78
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\522fqqr2akctsm
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\56t2ewf5lccem6
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\5cp9ql238zgwnf
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\5csjp@x23qlbma
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\5p92l533d5#zq@
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\5prkgek5k6l8xe
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\5rr6pl73h594cx
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\5w48w7a5y87h34
HKEY_LOCAL_MACHINE\software\2qcn@364d3eekk\5yzq#tp4wn82hp
HKEY_LOCAL_MACHINE\software\46cq6434r8hj77\3s63s7t5aha@b4
HKEY_LOCAL_MACHINE\software\46cq6434r8hj77\4g4rh6f5#6l9ch
HKEY_LOCAL_MACHINE\software\memorywatcher
HKEY_LOCAL_MACHINE\software\memorywatcher\install_dir
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\2fndpqy4pt3bdm
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\4g9tkjy5b9c7p9
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\memorywatcher
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\memorywatcher\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\memorywatcher\uninstallstring
Remove the following files
wowex32[1].exe.
memorywatcher_b.exe in c:\
memorywatcher_b.exe in Documents and Settings\UserName\local settings\temp\
memorywatcher.exe in Program Files\
comctl32.ocx, eula.url, memorywatcher.exe, trayicon.ocx, uninst.exe, wowex32.exe in Program Files\memorywatcher\
jqvgne.exe, mcl7.exe, ncisp.exe, pnkdb03.exe, qbk7x.exe, rpbbf5.exe, sdelh.exe, vchsyjo.exe, wprx.exe, wyrgmw.exe, xtgcu7.exe, zvbyl.exe in Windows\system32\
memorywatcher_b.exe in Windows\temp\
Remove the following directories
Program Files\memorywatcher

Viruses

TROJ_SMALL.JG
Aliases:
CVDL W32/Small.JF.trj.dldr CyberSoft VFind Security Toolkit
Downloader-TS trojan McAfee Virus Scan for Linux
Downloader.Small.6.M Grisoft AVG for Linux
Troj/Small-JG Sophos SWEEP virus detection utility
Trojan-Downloader.Win32.Small.jf Kaspersky On-Demand Scanner for Linux
Trojan-Downloader.Win32.Small.jf [AVP] F-Secure Anti-Virus for Linux
Trojan-Downloader.Win32.Small.JL Ikarus
Trojan.DL.Small.IT Central Command / Vexira
Trojan.DL.Small.IT VirusBuster Scanner 2005
Trojan.DownLoader.320 Doctor Web Ltd, Dr.Web (R) for Linux
Trojan.Downloader.Small.JF G Data AVK for Linux
Trojan.Downloader.Small.JF Clam AntiVirus
Trojan.Downloader.Small.JF Bitdefender/Linux-Console
Trojan.Downloader.Small.Jg MKS_VIR
Trojan.Downloader.Small.Jg Arcavir
Trojan/Dldr.Dyfuca.BQ.3 trojan AVIRA Desktop for UNIX
TrojanDownloader.Win32.Small. CAT Quick Heal
W32/Downloader.DZ F-PROT ANTIVIRUS for Linux
Win32.TrojanDownloader.Small.jl VirusBlokAda Vba32
Win32/TrojanDownloader.Small.JG ESET NOD32 on demand scanner for Linux
Win32:Trojano-149 [Trj ALWIL software avast! antivirus

IBS Lumber and Building Material Software Copyright © 2006 IBS Lumber Software Inc (TM)
Last modified: November 7, 2011

IBS Sales & Support 888-640-1252
Main Office 888-640-1252
Fax IBS 877-712-8937

All pages contained in this support website are not intended for general public distribution. Any material here can be considered private, confidential with various copyrights and restrictions against public release. You 'the browser' cannot legally release this information for general public distribution.

remote support: http://www.gotomeeting.com | remote support download program