Hoofdmenu
SpyLocked (of SpywareLocked) is een spywareremover van de zwarte lijst.
In de systray zie je een knipperend icoontje dat je waarschuwt dat de computer geïnfecteerd is.
Het programma wordt op de computer gedropt, vindt een aantal infecties, maar geeft aan deze pas te verwijderen als je het product koopt.

Elke keer de computer opnieuw start, start ook SpyLocked en begint het te scannen.

Kenmerken in een hijackthislog zijn ondermeer deze:
O4 -
O4 -
O4 -
O4 -
O4 -
O4 -
O4 -
O4 -
O4 -
O4 -
O22 -
O22 -
O22 -
O22 -
O22 -
O22 -
O22 -
O22 -
O22 -
Verwijdermethodes:
Smitfraudfix (gemaakt door S!Ri)
Zie hier.
Roguescanfix (gemaakt door Beamerke)
Zie hier.
Manueel verwijderen:
Rechtsklik op het icoontje van SpyLocker in de systray, en kies voor "Exit".
Bevestig de waarschuwing die je krijgt om SpyLocker af te sluiten door op "Ja" te klikken".
Ga naar start -
Hernoem het verantwoordelijk bestandje, (zie hieronder) of verwijder dit bestand met behulp van Killbox.
Download Pocket KillBox
Unzip het programma naar je bureaublad.
Klik op killbox.exe.
Selecteer de optie “Delete on reboot”.
In het veld “Full path of file to delete" plaats je volledige pad naar het verantwoordelijke bestand.
Klik dan op de knop "Single File".
Klik op de knop met de rode cirkel en het witte kruis.
Wanneer het programma vraagt om nu te rebooten, geef je hier toestemming voor. Klik op de knop "YES".
Na herstart zou de infectie verdwenen moeten zijn.
Om wijzigingen in het register op te ruimen, kan je deze regfile nog gebruiken.
Gekende varianten:
afkvvy.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{4688f900-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4688f900-
@="C:\\Windows\\system32\\afkvvy.dll
antzozc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{fa4fbf53-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fa4fbf53-
@="C:\\WINDOWS\\system32\\antzozc.dll"
czxtyx.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{0e4e5110-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0e4e5110-
@="C:\\WINDOWS\\system32\\czxtyx.dll"
dooep.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{44e670f2-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44e670f2-
@="C:\\Windows\\system32\\dooep.dll
dtjby.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{0c5a0fff-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0c5a0fff-
@="C:\\WINDOWS\\system32\\dtjby.dll"
dxovx.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{716002db-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{716002db-
@="C:\\WINDOWS\\system32\\dxovx.dll"
eeuydc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{44e670f2-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44e670f2-
@="C:\\WINDOWS\\system32\\eeuydc.dll"
egzcqg.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{ede8bed5-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ede8bed5-
@="C:\\WINDOWS\\system32\\egzcqg.dll"
fyxkaah.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{b292ec9f-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b292ec9f-
@="C:\\WINDOWS\\system32\\fyxkaah.dll"
"ThreadingModel"="Apartment"
ilmpjy.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{4233ac08-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4233ac08-
@="C:\\WINDOWS\\System32\\ilmpjy.dll"
indwvm.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{25b7d2fd-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25b7d2fd-
@="C:\\WINDOWS\\system32\\indwvm.dll"
kgkdbsk.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{735e980d-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{735e980d-
@="C:\\WINDOWS\\system32\\kgkdbsk.dll"
lcsrsrv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{f38b1b2b-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f38b1b2b-
@="C:\\WINDOWS\\system32\\lcsrsrv.dll"
onwtj.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{ceca6f2b-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ceca6f2b-
@="C:\\WINDOWS\\System32\\onwtj.dll"
"ThreadingModel"="Apartment"
oyopu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{df8c3aed-
@="C:\\WINDOWS\\system32\\oyopu.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{df8c3aed-
pjgerka.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{596e4935-
@="C:\\WINDOWS\\system32\\pjgerka.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{596e4935-
pkgvyg.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{b0ded443-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b0ded443-
@="C:\\WINDOWS\\System32\\pkgvyg.dll"
pkjcoxq.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e1d3b05d-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e1d3b05d-
@="C:\\WINDOWS\\system32\\pkjcoxq.dll"
qvjpt.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07a582e8-
@="C:\\WINDOWS\\system32\\qvjpt.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{07a582e8-
qzviz.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{bd0fc212-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bd0fc212-
@="C:\\WINDOWS\\system32\\qzviz.dll"
rcohty.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{b23dc537-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b23dc537-
@="C:\\WINDOWS\\System32\\rcohty.dll"
rxqcpn.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{68c7f143-
@="C:\\WINDOWS\\system32\\rxqcpn.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{68c7f143-
tahxqcj.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9d6fac42-
@="C:\\WINDOWS\\system32\\tahxqcj.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{9d6fac42-
uimcu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{6ad686b9-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6ad686b9-
@="C:\\WINDOWS\\system32\\uimcu.dll"
viuaoq.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{d7058baa-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d7058baa-
@="C:\\WINDOWS\\system32\\viuaoq.dll
xuoce.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{da3b49f6-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{da3b49f6-
@="C:\\WINDOWS\\system32\\xuoce.dll"
ygjun.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{abef791f-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{abef791f-
@="C:\\WINDOWS\\system32\\ygjun.dll"
yronl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1cb82d6d-
@="C:\\WINDOWS\\system32\\yronl.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{1cb82d6d-
yuspej.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{3baa1ad8-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3baa1ad8-
@="C:\\WINDOWS\\system32\\yuspej.dll"