PurityScan Trojan

Virus description: PurityScan
Category:Trojan,Adware,BHO,Downloader
Another names:

[Kaspersky]AdWare.Win32.PurityScan.bu,AdWare.Win32.PurityScan.ak;
[McAfee]Adware-ClickSpring;
[Panda]Adware/PurityScan,Trj/W32.Serty;
[Other]ClickSpring.PuritySCAN,W32/PurityScan.AKG.dropper,Adware.Purityscan

PurityScan Detection :

Files:
[%PROFILE_TEMP%]\pscanw.exe
[%PROFILE_TEMP%]\wups.exe
[%PROGRAMS%]\purityscan\purityscan.lnk
[%SYSTEM%]\dvdplay.dll
[%SYSTEM%]\Shex.exe
[%SYSTEM%]\wtssvtr.exe
[%WINDOWS%]\srvajooeuw.exe
[%WINDOWS%]\srvhevzlzm.exe
[%WINDOWS%]\srvnmbmaii.exe
[%WINDOWS%]\srvqjehoce.exe
[%WINDOWS%]\srvsqknuok.exe
[%APPDATA%]\mnss.exe
[%APPDATA%]\oeet.exe
[%PROFILE%]\recent\addestroyer.lnk
[%PROFILE_TEMP%]\ps_install-grokster.exe
[%SYSTEM%]\hetxnj.exe
[%SYSTEM%]\lgnkrv.exe
[%SYSTEM%]\qyemk.dll
[%SYSTEM%]\wapiit.exe
[%SYSTEM%]\winservn.exe
[%SYSTEM%]\xuzxa.dll
[%WINDOWS%]\srvdiyylcz.exe
[%WINDOWS%]\srvfgzuqxw.exe
[%WINDOWS%]\srvsmgdbdl.exe
[%WINDOWS%]\srvulwpepa.exe
[%WINDOWS%]\system\vfmsugip.dll
[%PROFILE_TEMP%]\pscanw.exe
[%PROFILE_TEMP%]\wups.exe
[%PROGRAMS%]\purityscan\purityscan.lnk
[%SYSTEM%]\dvdplay.dll
[%SYSTEM%]\Shex.exe
[%SYSTEM%]\wtssvtr.exe
[%WINDOWS%]\srvajooeuw.exe
[%WINDOWS%]\srvhevzlzm.exe
[%WINDOWS%]\srvnmbmaii.exe
[%WINDOWS%]\srvqjehoce.exe
[%WINDOWS%]\srvsqknuok.exe
[%APPDATA%]\mnss.exe
[%APPDATA%]\oeet.exe
[%PROFILE%]\recent\addestroyer.lnk
[%PROFILE_TEMP%]\ps_install-grokster.exe
[%SYSTEM%]\hetxnj.exe
[%SYSTEM%]\lgnkrv.exe
[%SYSTEM%]\qyemk.dll
[%SYSTEM%]\wapiit.exe
[%SYSTEM%]\winservn.exe
[%SYSTEM%]\xuzxa.dll
[%WINDOWS%]\srvdiyylcz.exe
[%WINDOWS%]\srvfgzuqxw.exe
[%WINDOWS%]\srvsmgdbdl.exe
[%WINDOWS%]\srvulwpepa.exe
[%WINDOWS%]\system\vfmsugip.dll

Folders:
[%PROGRAM_FILES%]\psdream
[%PROGRAM_FILES%]\PSLister
[%PROGRAM_FILES%]\purityscan
[%STARTMENU%]\programs\purityscan
[%APPDATA%]\psue
[%PROFILE%]\menu start\programma's\purityscan
[%PROFILE%]\start menu\programs\purityscan
[%PROGRAMS%]\PurityScan
[%PROGRAM_FILES%]\appliedsearch_autoinstall
[%PROGRAM_FILES%]\pscloner

Registry Keys:
HKEY_CLASSES_ROOT\interface\{20f13844-04bc-4987-9964-2502f0da54d3}
HKEY_CLASSES_ROOT\interface\{3e43040c-73c1-4898-a4f8-e2c9428b1167}
HKEY_CLASSES_ROOT\typelib\{ee6f3f6a-ad8e-48da-9b1d-d5204b2d227d}
HKEY_CURRENT_USER\software\purityscan
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\purityscan
HKEY_CLASSES_ROOT\clsid\{25ae1a9b-87d2-418f-a3a6-5a46edc37a84}
HKEY_CLASSES_ROOT\clsid\{38fd6621-c311-0ce3-8757-105504a62619}
HKEY_CLASSES_ROOT\clsid\{43acaeec-4072-40dc-2b76-38b60d1df6c2}
HKEY_CLASSES_ROOT\clsid\{9cc6f6d3-8b13-4206-abc1-8b285f9413a7}
HKEY_CLASSES_ROOT\clsid\{9fe4d9e6-13bb-43e0-8c74-9800573da4d6}
HKEY_CLASSES_ROOT\clsid\{a85c505e-aae3-4cb0-aee1-cb8213b140fb}
HKEY_CLASSES_ROOT\clsid\{cf0fbbf5-1ddd-4d58-b480-ac2c2a4186d3}
HKEY_CLASSES_ROOT\clsid\{eec056ce-3e1b-4571-bee1-eab9876b35f8}
HKEY_CLASSES_ROOT\typelib\{73d7abfe-d325-430a-817f-64c7bfd48813}
HKEY_CLASSES_ROOT\vbdnr.ccookie
HKEY_CLASSES_ROOT\vbdnr.cerrorlog
HKEY_CLASSES_ROOT\vbdnr.chistory
HKEY_CLASSES_ROOT\vbdnr.cregistryrouti
HKEY_CLASSES_ROOT\vbdnr.cscheduler
HKEY_CLASSES_ROOT\vbdnr.csignature
HKEY_CLASSES_ROOT\vbdnr.cusersettings
HKEY_CURRENT_USER\software\aubt
HKEY_CURRENT_USER\software\etds
HKEY_CURRENT_USER\software\meow
HKEY_CURRENT_USER\software\pslister
HKEY_CURRENT_USER\software\toos
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{38fd6621-c311-0ce3-8757-105504a62619}
HKEY_USERS\.default\software\ttee

Registry Values:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing PurityScan:

you can run trial version of ExterminateIt, or remove PurityScan manually..


ExterminateIt effectively and automatically removes Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware) from you computer.

Download ExterminateIt! to instantly get rid of PurityScan!


Also Be Aware of the Following Threats:
3X Trojan Cleaner
4Arcade.PBar Toolbar Removal
Removing Adware.ISTbar Trojan
180Solutions ZangoSearch Adware Information
AdwarePro Ransomware Information