INSTALLDLL.DLL - Dangerous
INSTALLDLL.DLL
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
INSTALLDLL.DLL is known as: Trojan.StartPage [Ikarus].
MD5 of INSTALLDLL.DLL = 974CE1263F4E01F399FE19D89C428DFC
INSTALLDLL.DLL size is 479232 bytes.
Full path on a computer: %PROGRAMFILES%\SOFTGUID\INSTALLDLL.DLL
Related Files:
%COMMONAPPDATA%\KINGSOFT\KIS\HG.DAT
%COMMONAPPDATA%\KINGSOFT\KIS\KCLT\COMMON_DUBA_INSTALLACT1415461838.INF
%COMMONAPPDATA%\KINGSOFT\KIS\KCLT\COMMON_DUBA_INSTALLACT1415463879.INF
%COMMONAPPDATA%\KINGSOFT\KIS\KCLT\COMMON_DUBA_INSTALLER1415313879.INF
%COMMONAPPDATA%\KINGSOFT\KIS\LOG\UPLIVE\COMMON_LIB.LOG
%COMMONAPPDATA%\KINGSOFT\KIS\LOG\UPLIVE\KLIVESETUP.LOG
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\INDEXOPKG.DAT
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\INDEXOPKG.TXT
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\OEM\0X00000000\DATASTREAM.DAT
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\OEM\0X00000000\INDEX.DAT
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\OEM\0X00000000\INDEX.TXT
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\OEM\0X00000000\INFOSTREAM.DAT
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\OEM\INDEX.DAT
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\OEM\INDEX.TXT
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\OPKG\80D35ABBBF3D6552C6E935C33E115458
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\OPKG\INDEX.DAT
%COMMONAPPDATA%\KINGSOFT\KIS\ONLINEINSTALL\KAV\OPKG\INDEX.TXT
%WINDIR%\TRY32E\INSTALL.TMP
%PROGRAMFILES%\SOFTGUID\INSTALLDLL.DLL
%PROGRAMFILES%\SOFTGUID\UNINS000.DAT
%PROGRAMFILES%\SOFTGUID\UNINS000.EXE
C:\SPECIALFOLDER\KUAIZIP_SETUP.EXE
%SYSTEM%\KBD101B.DLL
%SYSTEM%\KBD101C.DLL
%SYSTEM%\KBD103.DLL
%SYSTEM%\KBD106.DLL
%SYSTEM%\KBDJPN.DLL
%SYSTEM%\KBDKOR.DLL
%WINDIR%\TRY32E\CONFIG.INI
%WINDIR%\TRY32E\INFOFILE.TMP
%WINDIR%\TRY32E\KAV_97_10.EXE
%WINDIR%\TRY32E\RD.TXT
%WINDIR%\TRY32E\RERUNNOW.REW
%WINDIR%\TRY32E\SERVERID.TXT
%WINDIR%\TRY32E\TAOBAO.ICO
%WINDIR%\TRY32E\UVWX.TCT
%WINDIR%\TRY32E\VIS32.XHG
%WINDIR%\VIS32.LNK