EliteMedia virus description
Technical details:
Categories: Adware
EliteMedia Files:
[%PROFILE_TEMP%]\ICD2.tmp\amm06.inf
[%PROFILE_TEMP%]\ICD2.tmp\amm06.ocx
[%PROFILE_TEMP%]\ICD3.tmp\amm06.inf
[%PROFILE_TEMP%]\ICD3.tmp\amm06.ocx
[%PROFILE_TEMP%]\ICD8.tmp\amm06.inf
[%PROFILE_TEMP%]\stdrun2.exe
[%PROGRAM_FILES_COMMON%]\elitemediagroupoinuninstaller.exe
[%PROGRAM_FILES_COMMON%]\EliteMediaGroupOinUninstaller.exe
[%SYSTEM%]\ObjSafe.tlb
[%SYSTEM%]\WinATS.dll
[%SYSTEM%]\Winwcd.dll
[%WINDOWS%]\109uninst.exe
[%WINDOWS%]\amm06.ocx
[%WINDOWS%]\elitemediagroup.ini
[%WINDOWS%]\elitepop06.exe
[%WINDOWS%]\eliteunstall.exe
[%WINDOWS%]\elpp100drop.exe
[%WINDOWS%]\em06z.ini
[%WINDOWS%]\hancerdoem.exe
[%WINDOWS%]\Help\nocontnt.GID
[%WINDOWS%]\Setup90.exe
[%WINDOWS%]\temp\backups\backup-20060602-131509-273.inf
[%WINDOWS%]\TIELT001.exe
[%WINDOWS%]\uni_7eh.exe
[%WINDOWS%]\yoinsi.exe
[%PROGRAM_FILES%]\common files\elitemediagroupoinuninstaller.exe
[%PROGRAM_FILES%]\elticons\chadppicon100.exe
[%SYSTEM%]\hpsw.exe
[%SYSTEM%]\nsf66.dll
[%SYSTEM%]\ts_www.exe
[%SYSTEM%]\ttve2eee.dll
[%SYSTEM%]\ttve2eee.sys
[%SYSTEM%]\w50779cf.dll
[%SYSTEM%]\wgse.exe
[%WINDOWS%]\1011_justin.exe
[%WINDOWS%]\elitemediapop.exe
[%WINDOWS%]\elite_media.exe
[%WINDOWS%]\justin2.exe
[%WINDOWS%]\Sos28.exe
[%WINDOWS%]\thiselt.exe
[%WINDOWS%]\titsvotf.exe
[%PROFILE_TEMP%]\ICD2.tmp\amm06.inf
[%PROFILE_TEMP%]\ICD2.tmp\amm06.ocx
[%PROFILE_TEMP%]\ICD3.tmp\amm06.inf
[%PROFILE_TEMP%]\ICD3.tmp\amm06.ocx
[%PROFILE_TEMP%]\ICD8.tmp\amm06.inf
[%PROFILE_TEMP%]\stdrun2.exe
[%PROGRAM_FILES_COMMON%]\elitemediagroupoinuninstaller.exe
[%PROGRAM_FILES_COMMON%]\EliteMediaGroupOinUninstaller.exe
[%SYSTEM%]\ObjSafe.tlb
[%SYSTEM%]\WinATS.dll
[%SYSTEM%]\Winwcd.dll
[%WINDOWS%]\109uninst.exe
[%WINDOWS%]\amm06.ocx
[%WINDOWS%]\elitemediagroup.ini
[%WINDOWS%]\elitepop06.exe
[%WINDOWS%]\eliteunstall.exe
[%WINDOWS%]\elpp100drop.exe
[%WINDOWS%]\em06z.ini
[%WINDOWS%]\hancerdoem.exe
[%WINDOWS%]\Help\nocontnt.GID
[%WINDOWS%]\Setup90.exe
[%WINDOWS%]\temp\backups\backup-20060602-131509-273.inf
[%WINDOWS%]\TIELT001.exe
[%WINDOWS%]\uni_7eh.exe
[%WINDOWS%]\yoinsi.exe
[%PROGRAM_FILES%]\common files\elitemediagroupoinuninstaller.exe
[%PROGRAM_FILES%]\elticons\chadppicon100.exe
[%SYSTEM%]\hpsw.exe
[%SYSTEM%]\nsf66.dll
[%SYSTEM%]\ts_www.exe
[%SYSTEM%]\ttve2eee.dll
[%SYSTEM%]\ttve2eee.sys
[%SYSTEM%]\w50779cf.dll
[%SYSTEM%]\wgse.exe
[%WINDOWS%]\1011_justin.exe
[%WINDOWS%]\elitemediapop.exe
[%WINDOWS%]\elite_media.exe
[%WINDOWS%]\justin2.exe
[%WINDOWS%]\Sos28.exe
[%WINDOWS%]\thiselt.exe
[%WINDOWS%]\titsvotf.exe
EliteMedia Registry Keys:
HKEY_CLASSES_ROOT\clsid\{5526b4c6-63d6-41a1-9783-0fabf529859a}
HKEY_CLASSES_ROOT\clsid\{e4c29fdc-f547-4219-acfd-571f2a7a564a}
HKEY_CLASSES_ROOT\interface\{49217364-e570-4f9d-9cd2-62eb4780b2ee}
HKEY_CLASSES_ROOT\interface\{597aa130-f00b-40b8-adaf-529d4da9be52}
HKEY_CLASSES_ROOT\interface\{7682c1a6-c500-4c78-93b9-5a76a91520f8}
HKEY_CLASSES_ROOT\interface\{ce76ac70-161f-4b37-ac96-53e314c7ff95}
HKEY_CLASSES_ROOT\interface\{fc4be248-2d1d-4271-8054-0385774b078c}
HKEY_CLASSES_ROOT\mm06ocx.mm06ocxf
HKEY_CLASSES_ROOT\typelib\{42298ff7-5dcd-4dff-825a-225eee6ff0c7}
HKEY_CLASSES_ROOT\typelib\{7ac21a02-5b24-47ae-9b0e-b05ae3a50fc4}
HKEY_CLASSES_ROOT\typelib\{d13decbb-52f8-4bf4-ba6c-b0cc603963c9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5526B4C6-63D6-41A1-9783-0FABF529859A}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{e4c29fdc-f547-4219-acfd-571f2a7a564a}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:\windows\system32\objsafe.tlb
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:\windows\system32\winwcd.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\elitemediagroupoin
HKEY_LOCAL_MACHINE\software\mm
HKEY_CLASSES_ROOT\clsid\{9ac54695-69a4-46f1-be10-10c74f9520d5}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5526b4c6-63d6-41a1-9783-0fabf529859a}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{eec590d8-0a3c-4464-bb20-25a4747992f9}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%SYSTEM%]\objsafe.tlb
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%SYSTEM%]\winwcd.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]\downloaded program files\motorsix.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\elitemediagroup.net
EliteMedia Registry Values:
HKEY_LOCAL_MACHINE\software\em
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\elitemediagroup
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\elitemediagroup
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\zonemap\domains\elitemediagroup.net
HKEY_LOCAL_MACHINE\software\em
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%SYSTEM%]/safe.tlb
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\elitemediagroup
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\elitemediagroup
EliteMedia indications of infection
This symptoms of EliteMedia detection are the files, registry, and network communication referenced in the technical details section.
Method of Infection
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial.Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.
Buy
Exterminate-It antivirus software and perform a full scan of the computer.
You can also
Download Free Trial Version of ExterminateIt! to check your your computer just NOW.
Also Be Aware of the Following Threats:
Remove Galorion Trojan
DuvxUpd Trojan Removal
For.Guest Trojan Removal instruction
MIRC.MircGirl Trojan Information
Tatss Adware Cleaner