DyFuCa Description:
MoneyTree is an ActiveX control used to
download premium-rate dialers, generally for porn
sites. Dialers are used by a variety of web
sites, such as hotactiondating.com
Also known as: MoneyTree, NSUpdate,
NSLite, InternetOptimizer, MultiDist,
UniDist, Proclaim Telcom
DyFuCa Automatic Removal:
Using Spyware Doctor
to remove DyFuCa AUTOMATICALLY!
Sponsored Links:
DyFuCa Manual Removal:
Open the 'Downloaded Program Files' folder
(which can be found in the Windows folder), and
delete the entry for 'NSUpdateLiteCtrl Class' (NSUpdate
variant), 'NSLiteUpdateCtrl Class' (NSLitevariant),
'MoneyTree Dialer' (UniDist variant), 'MultiDist'
(MultiDist variant), or 'Software Update Manager'
(DyFuCA variant). Follow the additional
instructions below.
- Kill these running processes with Task
Manager:
programfilesdir+\dialers\stmtdlr.exe
programfilesdir+\internet optimizer\actalert.exe
programfilesdir+\internet optimizer\optimize.exe
systemroot+\system32\ssupdate.exe
systemroot+\system\ssuninstall.exe
systemroot+\system\ssupdate.exe
systemroot+\temp\msg2090.tmp10730720494655.exeblss.exe
installer.exe
safesurfing.exe
view_sex_now.exe
- Remove AutoRun Reference: Go to the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
If you find the value safesurfingupdate,
delete it and reboot the machine
immediately.
- Unregister these DLLs with Regsvr32, then reboot:
systemroot+nem207.dll
nem212.dll
nem214.dll
safesurfing.dll
\system32\opti130.dll
systemroot+\system32\ssurf022.dll
systemroot+\system\opti130.dll
systemroot+\system\ssurf022.dlliopti130.dll
- Remove these registry items (if present)
with RegEdit:
HKEY_CLASSES_ROOT\clsid\{405fd721-04ef-4ef2-ab96-fb31d32d4643}
HKEY_CLASSES_ROOT\clsid\{8f4e5661-f99e-4b3e-8d85-0ea71c0748e4}
HKEY_CLASSES_ROOT\clsid\{a0f0d762-d1de-43af-b70e-d87864743eb3}
HKEY_CLASSES_ROOT\clsid\{bf279130-3f58-4e26-8043-cd5688a4d4c9}
HKEY_CLASSES_ROOT\clsid\{c89bb48c-15d9-4f4f-803e-95d90f62be62}
HKEY_CLASSES_ROOT\clsid\{d8e25c53-9508-4f5c-9249-d98d438891d5}
HKEY_CLASSES_ROOT\clsid\{e8edb60c-951e-4130-93dc-faf1ad25f8e7}
HKEY_CLASSES_ROOT\clsid\{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
HKEY_CLASSES_ROOT\clsid\{fc87a650-207d-4392-a6a1-82adbc56fa64}
HKEY_CLASSES_ROOT\dyfuca_bh.bhobj
HKEY_CLASSES_ROOT\dyfuca_bh.bhobj.1
HKEY_CLASSES_ROOT\interface\{1c01d150-91a4-4de0-9bf8-a35d1bdf1001}
HKEY_CLASSES_ROOT\interface\{563e5df0-2c1c-4513-bbf5-d380536bb8fc}
HKEY_CLASSES_ROOT\interface\{9f2c17ac-9aa4-4c3a-82c7-ea7bcf00f03d}
HKEY_CLASSES_ROOT\interface\{ca7ccb52-6922-47e5-b784-3a3f82c51863}
HKEY_CLASSES_ROOT\interface\{f332d106-2ef3-45c4-baf2-0f739d76b26a}
HKEY_CLASSES_ROOT\multidist.multidistctrl.1
HKEY_CLASSES_ROOT\safesurfinghelper.iebho
HKEY_CLASSES_ROOT\safesurfinghelper.iebho.1
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{8f4e5661-f99e-4b3e-8d85-0ea71c0748e4}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{d8e25c53-9508-4f5c-9249-d98d438891d5}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
HKEY_CLASSES_ROOT\typelib\{00211813-6223-4c6a-be8d-4d2676cd1361}
HKEY_CLASSES_ROOT\typelib\{0be10b0d-b4db-4693-9b1f-9aead54d17dc}
HKEY_CLASSES_ROOT\typelib\{11b6f65d-7b8d-43cb-9aae-17234a1db33a}
HKEY_CLASSES_ROOT\typelib\{40b1d454-9ca4-43cc-86aa-cb175eac52fb}
HKEY_CLASSES_ROOT\typelib\{8f4e5661-f99e-4b3e-8d85-0ea71c0748e4}
HKEY_CLASSES_ROOT\typelib\{96b01a48-1317-4a87-91f7-10116f755705}
HKEY_CLASSES_ROOT\typelib\{d8e25c53-9508-4f5c-9249-d98d438891d5}
HKEY_CLASSES_ROOT\typelib\{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
HKEY_CLASSES_ROOT\unidist.unidistctrl.1
HKEY_CURRENT_USER\software\avenue media
HKEY_CURRENT_USER\software\fci
HKEY_LOCAL_MACHINE\clsid\{8f4e5661-f99e-4b3e-8d85-0ea71c0748e4}
HKEY_LOCAL_MACHINE\clsid\{d8e25c53-9508-4f5c-9249-d98d438891d5}
HKEY_LOCAL_MACHINE\clsid\{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
HKEY_LOCAL_MACHINE\software\avenue media
HKEY_LOCAL_MACHINE\software\classes\clsid\{8f4e5661-f99e-4b3e-8d85-0ea71c0748e4}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d8e25c53-9508-4f5c-9249-d98d438891d5}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
HKEY_LOCAL_MACHINE\software\fci
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{e8edb60c-951e-4130-93dc-faf1ad25f8e7}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{fc87a650-207d-4392-a6a1-82adbc56fa64}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8f4e5661-f99e-4b3e-8d85-0ea71c0748e4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d8e25c53-9508-4f5c-9249-d98d438891d5}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage
\c:/windows/downloaded program files/muldist.ocx\searchassistant
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage
\c:/windows/downloaded program files/unidist.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\internet optimizer
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\safesurfingupdate
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls
\c:\windows\downloaded program files\muldist.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls
\c:\windows\downloaded program files\unidist.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\dyfuca
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\internet optimizer
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\internet optimizer active alert
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\internet optimizer software installer
HKEY_LOCAL_MACHINE\software\safesurfing\update
- Remove these files (if present) with Windows
Explorer:
programfilesdir+\dialers\stmtdlr.exe
programfilesdir+\internet optimizer\actalert.exe
programfilesdir+\internet optimizer\optimize.exe
systemroot+\downloaded program files\moneytree dialer
systemroot+\downloaded program files\muldist.inf
systemroot+\downloaded program files\muldist.ocx
systemroot+\downloaded program files\multidist
systemroot+\downloaded program files\nsliteupdatectrl class
systemroot+\downloaded program files\nsupdatelitectrl class
systemroot+\downloaded program files\software update manager
systemroot+\downloaded program files\unidist.inf
systemroot+\downloaded program files\unidist.ocx
systemroot+\system32\opti130.dll
systemroot+\system32\ssupdate.exe
systemroot+\system32\ssurf022.dll
systemroot+\system\opti130.dll
systemroot+\system\ssuninstall.exe
systemroot+\system\ssupdate.exe
systemroot+\system\ssurf022.dll
systemroot+\temp\msg2090.tmp10730720494655.exeblss.exe
cln4380.tmp
installer.exe
iopti130.dll
nem207.dll
nem212.dll
nem214.dll
optimiser.msg
safesurfing.dll
safesurfing.exe
view_sex_now.exe
- Remove these directories (if present) with
Windows Explorer:
programfilesdir+\internet optimizer
More
Removal Instructions for Adware/Spyware Programs - 'D'
|