Backdoor Lixy and Lixy.B Description:
Lixy is a Backdoor Trojan Horse that opens a proxy server on TCP port 1080.
Lixy.B is a variant of Lixy, also a Backdoor Trojan Horse that
opens a proxy server and allows unauthorized access to an infected machine. You should remove them immediately.
Backdoor Lixy and Lixy.B Automatic Removal:
Using Spyware Doctor to remove Backdoor Lixy and Lixy.B AUTOMATICALLY!
Sponsored Links:
Backdoor Lixy and Lixy.B Manual Removal:
Warning:
The following instructions are only for advanced
computer users. We recommend you to backup your
system registry or create a System Restore Point
before any risky step. We offers no warranty of
any kind to manual operators. For common users we
recommend to remove malwares using anti-spyware
tools, such as Spyware Doctor,
Spyware Doctor, BPS
Spyware&Adware Remover, ...
To uninstall Backdoor Lixy and Lixy.B:
- Press ctrl+alt+del, terminate the process FindService.exe from the Tasklist.
- Click Start > Run. Type
REGSVR32 -u %Dll_name%. Then click OK. Replace %Dll_name% with followings:
%ProgramFiles%\AdvSearch\mailbookproxy.dll
%ProgramFiles%\AdvSearch\updaterproxy.dll
- Click Start > Run. Type regedit.
Then
click OK.
Navigate to and delete the registry keys:
HKEY_CLASSES_ROOT\CLSID\{1E1B2879-88FF-11D2-8D96-D7ACAC95951A}
HKEY_CLASSES_ROOT\HTMLEdit.SSocks5
HKEY_CLASSES_ROOT\HTMLEdit.SSocks5.1
HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{1E1B2879-88FF-11D2-8D96-D7ACAC95951A}
HKEY_LOCAL_MACHINE\Software\CLASSES\HTMLEdit.SSocks5
HKEY_LOCAL_MACHINE\Software\CLASSES\HTMLEdit.SSocks5.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1E1B2879-88FF-11D2-8D96-D7ACAC95951A}
HKEY_CLASSES_ROOT\CLSID\{1E1B2879-88FF-11D2-8D96- 000000000004 }
HKEY_CLASSES_ROOT\HTMLEdit.SSocks32
HKEY_CLASSES_ROOT\HTMLEdit.SSocks32.1
HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{1E1B2879-88FF-11D2-8D96- 000000000004 }
HKEY_LOCAL_MACHINE\Software\CLASSES\HTMLEdit.SSocks32
HKEY_LOCAL_MACHINE\Software\CLASSES\HTMLEdit.SSocks32.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1E1B2879-88FF-11D2-8D96- 000000000004 }
Exit the Registry Editor.
- Remove files in explorer:
%ProgramFiles%\rlid.exe
%ProgramFiles%\lid.exe
%Windows%\lid.dll %Windows%\ssocks32.dll %Windows%\ssocks5.dll
However, a few of registry entries
may be left
behind deleting. You can ask for Spyware Doctor to clean up.
More
Removal Instructions for Emerging Adware Spyware
|