EUniverse description
Categories:Adware,BHO,Hijacker,Downloader
The EUniverse adds a link to its executable file in the system registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[%PROGRAM_FILES_COMMON%]\SearchUpgrader\SearchUpgrader.exe
[%PROGRAM_FILES%]\Common files\SearchUpgrader\SearchUpgrader.exe Platforms / OS: Windows 2000, Windows XP, Windows 2003, Windows Vista
How to detecting EUniverse:
Search Files on the disk:
[%PROGRAM_FILES_COMMON%]\SearchUpgrader\SearchUpgrader.exe
[%PROGRAM_FILES%]\Common files\SearchUpgrader\SearchUpgrader.exe
[%PROGRAM_FILES_COMMON%]\SearchUpgrader\SearchUpgrader.exe
[%PROGRAM_FILES%]\Common files\SearchUpgrader\SearchUpgrader.exe
Search registry keys in system registry:
HKEY_CLASSES_ROOT\interface\{8b8f6968-2f24-41e3-b653-e9613226f14d}
HKEY_LOCAL_MACHINE\software\classes\bho.incredifindbho
HKEY_LOCAL_MACHINE\software\classes\bho.incredifindbho.1
HKEY_LOCAL_MACHINE\software\classes\bho.perfectnavbho
HKEY_LOCAL_MACHINE\software\classes\bho.perfectnavbho.1
HKEY_LOCAL_MACHINE\software\classes\clsid\{30402ff4-3e71-4a1c-9b4b-1cd3486a9fb2}
HKEY_LOCAL_MACHINE\software\classes\clsid\{5d60ff48-95be-4956-b4c6-6bb168a70310}
HKEY_LOCAL_MACHINE\software\classes\interface\{4828c95f-c5db-4ab6-a945-8d8ec44b98a8}
HKEY_LOCAL_MACHINE\software\classes\interface\{4e570f74-deee-4fcf-b960-feefa4b8c6fc}
HKEY_LOCAL_MACHINE\software\classes\interface\{8b8f6968-2f24-41e3-b653-e9613226f14d}
HKEY_LOCAL_MACHINE\software\classes\typelib\{de289bfa-737b-4abb-a4ec-f8753551b875}
HKEY_LOCAL_MACHINE\software\incredifind
HKEY_LOCAL_MACHINE\software\updater
HKEY_LOCAL_MACHINE\software\updmgr
HKEY_CLASSES_ROOT\clsid\{03fde7ea-c8c4-413f-bea1-f8c1b8b39ea6}
HKEY_CLASSES_ROOT\clsid\{08d536e8-06f5-458f-b5d1-e975d2da08db}
HKEY_CLASSES_ROOT\clsid\{0ec7cf46-c5b4-480c-8f94-eb34b98ccf44}
HKEY_CLASSES_ROOT\clsid\{17127a1c-1c1b-4430-b042-e1ca653d68e2}
HKEY_CLASSES_ROOT\clsid\{1ae63cf9-7c7a-49c8-8475-961ddd2b230a}
HKEY_CLASSES_ROOT\clsid\{1d4ee8ca-9b69-4c8f-8e7b-3e2940b329fa}
HKEY_CLASSES_ROOT\clsid\{2b54bd2f-78c0-4eaf-8347-7f37454fc61d}
HKEY_CLASSES_ROOT\clsid\{450a8754-6700-4170-8263-252e9a86de06}
HKEY_CLASSES_ROOT\clsid\{57c469e8-923a-4623-bc67-d9e18c97a2ed}
HKEY_CLASSES_ROOT\clsid\{58a7073d-4ec4-46a9-bdbd-fddcc47544ee}
HKEY_CLASSES_ROOT\clsid\{7250994f-210d-4abc-8c4d-b2c014529fd8}
HKEY_CLASSES_ROOT\clsid\{7852e0ff-f138-434e-bc32-760d05debb33}
HKEY_CLASSES_ROOT\clsid\{7e4de558-ebd9-4373-a34c-523d23b9eddb}
HKEY_CLASSES_ROOT\clsid\{af60118d-901b-4add-97d8-1676ec3a7cea}
HKEY_CLASSES_ROOT\clsid\{c14b4055-a29b-420c-9d24-71c04956189c}
HKEY_CLASSES_ROOT\clsid\{c3516ef2-41d5-4e97-8688-77ada93fb0eb}
HKEY_CLASSES_ROOT\clsid\{c6a02de1-73ef-463a-8566-bd7af8b63f88}
HKEY_CLASSES_ROOT\clsid\{ce6e551b-b8f9-4b24-81fd-59d9162da495}
HKEY_CLASSES_ROOT\clsid\{db0aad08-ca9f-4c1e-b4e1-ad3d63ee20f9}
HKEY_CLASSES_ROOT\clsid\{dcb709b4-4142-411a-8e9f-f265ae2b7bde}
HKEY_CLASSES_ROOT\clsid\{dfaba77c-f8bb-4ab9-bed7-7d48ae103e24}
HKEY_CLASSES_ROOT\typelib\{dcb709b4-4142-411a-8e9f-f265ae2b7bde}
HKEY_CLASSES_ROOT\typelib\{dfaba77c-f8bb-4ab9-bed7-7d48ae103e24}
HKEY_LOCAL_MACHINE\software\classes\typelib\{cde442a3-dc2c-467e-a311-b4bc775d86c5}
HKEY_LOCAL_MACHINE\software\euniverse
HKEY_LOCAL_MACHINE\software\keenvalue
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\keenvalue
Search registry values in system registry:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
How To Remove EUniverse:
You must download ExterminateIt. It can detect EUniverse and prevent infection.
You can run trial version of ExterminateIt to detect,and then remove EUniverse manually.
- Use Task Manager to terminate the EUniverse process.
- Delete the original EUniverse file and folders.
- Delete the system registry key parameters
Note that the easiest way is to buy antivirus software and be protected 24/7/365
This antivirus, ExterminateIt effectively and automatically removes viruses from you computer.
Download ExterminateIt! to instantly get rid of EUniverse!
Check now if your PC is infected with EUniverse
You can buy full version of ExterminateIt at RegNow.com.
Also Be Aware of the Following Threats:
Removing Win32.Naldem Trojan
Cigilog Trojan Information
Removing Yazzle.Snowball.Wars Adware