SpywareStrike description
Categories:Trojan,Downloader,Ransomware
The SpywareStrike adds a link to its executable file in the system registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[%PROGRAM_FILES%]\SpywareStrike\SpywareStrike.exe
[%DESKTOP%]\ss_setup.exe Platforms / OS: Windows 2000, Windows XP, Windows 2003, Windows Vista
How to detecting SpywareStrike:
Search Files on the disk:
[%PROFILE_TEMP%]\sslanguage.ini
[%STARTMENU%]\SpywareStrike 2.5.lnk
[%PROGRAM_FILES%]\SpywareStrike\SpywareStrike.exe
[%PROGRAM_FILES%]\SpywareStrike\spywarestrike.ini
[%WINDOWS%]\Prefetch\SPYWARESTRIKER.EXE-140AD6F1.pf
[%APPDATA%]\microsoft\internet explorer\quick launch\spywarestrike 2.5.lnk
[%DESKTOP%]\spywarestrike.lnk
[%DESKTOP%]\ss_setup.exe
[%PROFILE%]\start menu\spywarestrike 2.5.lnk
[%PROFILE_TEMP%]\sslanguage.ini
[%STARTMENU%]\SpywareStrike 2.5.lnk
[%PROGRAM_FILES%]\SpywareStrike\SpywareStrike.exe
[%PROGRAM_FILES%]\SpywareStrike\spywarestrike.ini
[%WINDOWS%]\Prefetch\SPYWARESTRIKER.EXE-140AD6F1.pf
[%APPDATA%]\microsoft\internet explorer\quick launch\spywarestrike 2.5.lnk
[%DESKTOP%]\spywarestrike.lnk
[%DESKTOP%]\ss_setup.exe
[%PROFILE%]\start menu\spywarestrike 2.5.lnk
Search Folders on the disk:
[%PROGRAMS%]\SpywareStrike
[%PROGRAM_FILES%]\SpywareStrike
[%PROGRAM_FILES%]\spywarestrike
Search registry keys in system registry:
HKEY_CLASSES_ROOT\AppID\{70F17C8C-1744-41B6-9D07-575DB448DCC5}
HKEY_CLASSES_ROOT\interface\{0f345791-d507-4f1c-9e44-8beec61d6148}
HKEY_CLASSES_ROOT\interface\{15462503-7597-4662-9c63-31c42112d4e9}
HKEY_CLASSES_ROOT\interface\{17412fea-fb37-4fc0-b689-dcf84fc7fb0a}
HKEY_CLASSES_ROOT\Interface\{2C15CDEA-3EF4-4405-90B0-19A1389B36ED}
HKEY_CLASSES_ROOT\Interface\{3115A433-3FA0-483B-AB01-2A61C951FE58}
HKEY_CLASSES_ROOT\interface\{4dc8dca1-191d-4bd9-bcfe-44df358ae036}
HKEY_CLASSES_ROOT\Interface\{51FEFA9C-1D5A-41C4-81FE-8C0FBE9254F0}
HKEY_CLASSES_ROOT\interface\{5b395871-7173-4b84-986a-a7112f1bdb45}
HKEY_CLASSES_ROOT\Interface\{5CCC8D01-9F75-4F07-9ACF-DEB314176C79}
HKEY_CLASSES_ROOT\Interface\{5E7BF614-960B-4A1F-9236-9EC01AC4C5E2}
HKEY_CLASSES_ROOT\Interface\{66F0AC1C-DED5-4965-9E31-39788DF1B264}
HKEY_CLASSES_ROOT\interface\{72daa86e-db4a-42b0-b82a-41a6de2b315e}
HKEY_CLASSES_ROOT\interface\{732eb0fc-c608-40b1-b524-b092e3915316}
HKEY_CLASSES_ROOT\Interface\{849E056A-D67A-431E-9370-2275F26D39B5}
HKEY_CLASSES_ROOT\interface\{8504b09f-e628-4af9-8f8f-f2f73e4b46ab}
HKEY_CLASSES_ROOT\Interface\{8B7AFBFD-631C-45BA-9145-F059EB58DD73}
HKEY_CLASSES_ROOT\interface\{8d6083dc-ad33-44db-a8f1-b3b520af9891}
HKEY_CLASSES_ROOT\interface\{900fe140-70c1-4043-b32d-c89412399fb6}
HKEY_CLASSES_ROOT\interface\{95a5de55-9979-4507-a521-2e1f8bcc61ab}
HKEY_CLASSES_ROOT\interface\{a1c155d5-80a0-4bf2-ac7a-53b027c47879}
HKEY_CLASSES_ROOT\Interface\{AFEB8519-0B8B-4023-8C15-FFB17D5225F9}
HKEY_CLASSES_ROOT\interface\{b5775c39-bfef-4fa2-a194-550807a95146}
HKEY_CLASSES_ROOT\Interface\{BA9CC151-4581-438E-94AF-4C703201B7CA}
HKEY_CLASSES_ROOT\Interface\{BC74C336-FF2C-40C9-AD4E-3772C208406B}
HKEY_CLASSES_ROOT\Interface\{BDF00F24-A571-4392-95EC-04FDFF82A82C}
HKEY_CLASSES_ROOT\Interface\{C4E953E6-770E-4F59-A5E3-43E9F0D682E2}
HKEY_CLASSES_ROOT\interface\{ca8beb64-4a47-411b-87a1-488643df9521}
HKEY_CLASSES_ROOT\interface\{d0ab917d-1645-4eeb-b9bb-b33103845ed9}
HKEY_CLASSES_ROOT\Interface\{E0105E7C-D0C4-4DEA-AA21-B02F2960ECAF}
HKEY_CLASSES_ROOT\interface\{e809d2ae-7550-4540-bd5c-4e214ee86661}
HKEY_CLASSES_ROOT\Interface\{ED39CB7C-1BF6-429B-A275-F183B4A3EFCB}
HKEY_CLASSES_ROOT\Interface\{F23AA637-31D5-4526-B5C6-9FF89E16202C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareStrike.exe
HKEY_CLASSES_ROOT\AppID\SpywareStrike.EXE
HKEY_CLASSES_ROOT\TypeLib\{C1A4C0C9-DBD0-493A-93F8-0B05EDC96224}
HKEY_CLASSES_ROOT\appid\spywarestrike.exe
HKEY_CLASSES_ROOT\clsid\{0f25878f-f8ae-5d5d-2bb7-31b5f803290d}
HKEY_CLASSES_ROOT\interface\{2c15cdea-3ef4-4405-90b0-19a1389b36ed}
HKEY_CLASSES_ROOT\interface\{3115a433-3fa0-483b-ab01-2a61c951fe58}
HKEY_CLASSES_ROOT\interface\{51fefa9c-1d5a-41c4-81fe-8c0fbe9254f0}
HKEY_CLASSES_ROOT\interface\{5ccc8d01-9f75-4f07-9acf-deb314176c79}
HKEY_CLASSES_ROOT\interface\{5e7bf614-960b-4a1f-9236-9ec01ac4c5e2}
HKEY_CLASSES_ROOT\interface\{66f0ac1c-ded5-4965-9e31-39788df1b264}
HKEY_CLASSES_ROOT\interface\{849e056a-d67a-431e-9370-2275f26d39b5}
HKEY_CLASSES_ROOT\interface\{8b7afbfd-631c-45ba-9145-f059eb58dd73}
HKEY_CLASSES_ROOT\interface\{afeb8519-0b8b-4023-8c15-ffb17d5225f9}
HKEY_CLASSES_ROOT\interface\{ba9cc151-4581-438e-94af-4c703201b7ca}
HKEY_CLASSES_ROOT\interface\{bc74c336-ff2c-40c9-ad4e-3772c208406b}
HKEY_CLASSES_ROOT\interface\{bdf00f24-a571-4392-95ec-04fdff82a82c}
HKEY_CLASSES_ROOT\interface\{c4e953e6-770e-4f59-a5e3-43e9f0d682e2}
HKEY_CLASSES_ROOT\interface\{e0105e7c-d0c4-4dea-aa21-b02f2960ecaf}
HKEY_CLASSES_ROOT\interface\{ed39cb7c-1bf6-429b-a275-f183b4a3efcb}
HKEY_CLASSES_ROOT\interface\{f23aa637-31d5-4526-b5c6-9ff89e16202c}
HKEY_CLASSES_ROOT\typelib\{c1a4c0c9-dbd0-493a-93f8-0b05edc96224}
HKEY_CLASSES_ROOT\typelib\{ed9f5c8f-c607-4928-9d6c-47484e9a0fee}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\spywarestrike.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spywarestrike
HKEY_LOCAL_MACHINE\software\spywarestrike
Search registry values in system registry:
HKEY_CLASSES_ROOT\interface\{0a2a702d-41d8-457b-afa7-0d7b378312b7}\typelib
HKEY_CLASSES_ROOT\interface\{13160b60-2026-444d-82dc-f6fc78cf72f6}\typelib
HKEY_CLASSES_ROOT\interface\{240c9fd0-2392-44f3-bbbb-317c26e35445}\typelib
HKEY_CLASSES_ROOT\interface\{325e096f-70c6-43b5-a760-89ac820a7f9f}\typelib
HKEY_CLASSES_ROOT\interface\{5b33e7e7-6ae8-416d-865a-436c38d1009a}\typelib
HKEY_CLASSES_ROOT\interface\{6287531a-b5de-46fc-b6b2-4034111c4d96}\typelib
HKEY_CLASSES_ROOT\interface\{7444fe9f-166f-44da-a2b8-8298a4912933}\typelib
HKEY_CLASSES_ROOT\interface\{7b17d659-3f29-48e2-9008-380c5c1cae48}\typelib
HKEY_CLASSES_ROOT\interface\{af567cf7-4c07-41ff-85e5-d8e0568cd4d4}\typelib
HKEY_CLASSES_ROOT\interface\{b215fd99-984d-4cff-ad00-286e1deecd0c}\typelib
HKEY_CLASSES_ROOT\interface\{b396b96e-0a43-483c-b2fa-de0594017020}\typelib
HKEY_CLASSES_ROOT\interface\{c09a820e-28d1-4f5d-9e26-1b3e16482ccc}\typelib
HKEY_CLASSES_ROOT\interface\{c41b3d26-9fe5-4065-a6b1-fa26652e658f}\typelib
HKEY_CLASSES_ROOT\interface\{cc7e255f-88bf-4a4f-8c45-eb5d31c7eda9}\typelib
HKEY_CLASSES_ROOT\interface\{e06f81cf-5eeb-4694-8dfa-cd12431ed6c0}\typelib
HKEY_CLASSES_ROOT\interface\{fc154a66-d0d8-4687-9bd3-26572208dd7e}\typelib
HKEY_CLASSES_ROOT\interface\{0a2a702d-41d8-457b-afa7-0d7b378312b7}\typelib
HKEY_CLASSES_ROOT\interface\{13160b60-2026-444d-82dc-f6fc78cf72f6}\typelib
HKEY_CLASSES_ROOT\interface\{240c9fd0-2392-44f3-bbbb-317c26e35445}\typelib
HKEY_CLASSES_ROOT\interface\{325e096f-70c6-43b5-a760-89ac820a7f9f}\typelib
HKEY_CLASSES_ROOT\interface\{5b33e7e7-6ae8-416d-865a-436c38d1009a}\typelib
HKEY_CLASSES_ROOT\interface\{6287531a-b5de-46fc-b6b2-4034111c4d96}\typelib
HKEY_CLASSES_ROOT\interface\{7444fe9f-166f-44da-a2b8-8298a4912933}\typelib
HKEY_CLASSES_ROOT\interface\{7b17d659-3f29-48e2-9008-380c5c1cae48}\typelib
HKEY_CLASSES_ROOT\interface\{af567cf7-4c07-41ff-85e5-d8e0568cd4d4}\typelib
HKEY_CLASSES_ROOT\interface\{b215fd99-984d-4cff-ad00-286e1deecd0c}\typelib
HKEY_CLASSES_ROOT\interface\{b396b96e-0a43-483c-b2fa-de0594017020}\typelib
HKEY_CLASSES_ROOT\interface\{c09a820e-28d1-4f5d-9e26-1b3e16482ccc}\typelib
HKEY_CLASSES_ROOT\interface\{c41b3d26-9fe5-4065-a6b1-fa26652e658f}\typelib
HKEY_CLASSES_ROOT\interface\{cc7e255f-88bf-4a4f-8c45-eb5d31c7eda9}\typelib
HKEY_CLASSES_ROOT\interface\{e06f81cf-5eeb-4694-8dfa-cd12431ed6c0}\typelib
HKEY_CLASSES_ROOT\interface\{fc154a66-d0d8-4687-9bd3-26572208dd7e}\typelib
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
How To Remove SpywareStrike:
You must download ExterminateIt. It can detect SpywareStrike and prevent infection.
You can run trial version of ExterminateIt to detect,and then remove SpywareStrike manually.
- Use Task Manager to terminate the SpywareStrike process.
- Delete the original SpywareStrike file and folders.
- Delete the system registry key parameters
Note that the easiest way is to buy antivirus software and be protected 24/7/365
This antivirus, ExterminateIt effectively and automatically removes viruses from you computer.
Download ExterminateIt! to instantly get rid of SpywareStrike!
Check now if your PC is infected with SpywareStrike
You can buy full version of ExterminateIt at RegNow.com.