Dollarrevenue Removal: Remove Dollarrevenue Forever

Let our support team solve your problem with Dollarrevenue and repair Dollarrevenue right now!

Leave the detailed description of your Dollarrevenue problem in the form below. Our support team will contact you in several minutes and give a step-by-step instruction on how to fix Dollarrevenue problem. Please be specific. Do your best describing the problem. This will help us recommend right and complete Dollarrevenue problem removal solution.

Describe your problem here and we'll contact you in several minutes:

We'll reply you in 10 minutes or less
* Name:
* E-mail:
* Problem summary:
* Detailed problem
description:

We'll contact you in 10 minutes or less after you click on this button! Individual solution guaranteed!

Warning:

1) We hate spam as much as you do. We will not share your email with any third party or publish it anywhere. Your email is used only to contact you and give you Dollarrevenue removal solution.
2) All fields of this form are obligatory.

Guaranteed Problem Solution
Software Industry Professionals Member
Threat's description and solution are developed by Security Stronghold security team. Let professionals make your problems solved now!
Download solution for Dollarrevenue and 28[1].exe now!

What is Dollarrevenue? Technical details of Dollarrevenue problem and Dollarrevenue removal tool

Methods for manual Dollarrevenue removal

Free download of a program that will solve your problem automatically

Free instant professional support in solving Dollarrevenue error from our Security Support Team

Threat's profile

Threat indicator: HIGH
Name of the threat: Dollarrevenue
Command or file name: 28[1].exe
Threat type: Spyware\trojan
Affected OS: Win32 (Windows 9x, Windows XP, Windows Vista)

Dollarrevenue intrusion method

Dollarrevenue copies its file(s) to your hard disk. Its typical file name is 28[1].exe. Then it creates new startup key with name Dollarrevenue and value 28[1].exe. You can also find it in your processes list with name 28[1].exe or Dollarrevenue.

If you have further questions about Dollarrevenue, please fill in the form above and we'll contact you shortly.

» Download program to remove Dollarrevenue (Dollarrevenue Removal Tool)

Recommended Solution

If you are not sure what to delete, use our award winning program - Dollarrevenue Removal Tool.

Dollarrevenue Removal Tool will find and fully remove Dollarrevenue and all problems associated with Dollarrevenue virus.

Fast, easy, and handy, Dollarrevenue Removal Tool protects your computer against Dollarrevenue that does harm to your computer and breaks your privacy. Dollarrevenue Removal Tool scans your hard disks and registry and destroys any manifestation of Dollarrevenue. Standard anti-virus software can do nothing against malicious programs like Dollarrevenue. Remove Dollarrevenue straight away!

» Download Dollarrevenue Removal Tool now for free

How to fix Dollarrevenue

This problem can be solved manually by deleting all registry keys and files connected with Dollarrevenue, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by Dollarrevenue.

To get rid of Dollarrevenue, you should:

1. Kill the following processes and delete the appropriate files:

• 3138302D2D2D.exe
• 45atq2v13x[1].exe
• 919_133[1].exe
• aboxinst_int20[1].exe
• ac3c[1].txt
• ac3[1].txt
• ac3_0010[1].exe
• adsnw883.exe
• al3[1].txt
• atde5f72.dll
• atde5f72.sys
• awtsr.dll
• bgvakh.dll
• bykcfljb.dll
• ccnfmsp.dll
• cfin
• cfout.txt
• d451b964.exe
• ddnhupnp.dll
• defender21.exe
• dfndrff_12[1].exe
• dfndrff_9[1].exe
• dfndrff_e27.exe
• dfndrff_e_uit[1].exe
• dfrgsrv.exe
• dkdim.dll
• dmonwv.dll
• dollar.exe
• domains.txt
• dqcompos.dll
• drsmartload2.dat
• drsmartload45a[1].exe
• drsmartload46a[1].exe
• drsmartload618a.exe
• drsmartload849a[1].exe
• drsmartload[1].exe
• DUCE6.EXE
• f189859.exe
• frsvabb.dll
• fwv60c22.dll
• fwv60c22.sys
• gck26.exe
• ghhkj.bak1
• ghhkj.ini
• glb7.tmp
• glc1c.tmp
• glk1d.tmp
• guard.tmp
• hore.dll
• horefon
• horefon.dll
• howypyd.html
• htnhkvpp.dll
• inqlx.exe
• intro[1].htm
• jkhhg.dll
• KVLKB.EXE
• kybrdff_12[1].exe
• kybrdff_9[1].exe
• kybrdff_e[1].exe
• kyzer.html
• l11[1].exe
• lmbmbddn.dll
• mao3q2b7r6[1].exe
• march_of_dimes[1].gif
• march_of_dimes_bg[1].gif
• mhos.dll
• mpwsock.dll
• ms030876474-132006.exe
• ms043308651949.exe
• ms0433086519492006.exe
• ms0576474-1308.exe
• mst1.tmp
• mst9.tmp
• mte3ndi6odoxngv2[1].exe
• mte3ndi6odoxng[1].exe
• mulbin32[1].exe
• mwintpex.exe
• mzwfa.exe
• mzwfm.exe
• nctman.dll
• nnmsapi.dll
• nwnmff_9[1].exe
• nwnmff_e27.exe
• nwnmff_e[1].exe
• opnkhfe.dll
• p4yrsrl5qi1kwa6ivzcktrlwurhxsqcx.vbs
• pmnlmmj.dll
• rcqgxsi.dll
• RDFX4.exe
• rdfx4[1].exe
• rfmnilih.exe
• rzkoa.exe
• rzkom.exe
• setup100.exe
• sloopy7.exe
• srvcjiqjfg.exe
• srvqyzydlr.exe
• srvvsmarpm.exe
• srvzcgokpf.exe
• srvzggcrfn.exe
• srvzwxwyfu.exe
• stub_113_4_0_4_0[1].exe
• sys019493308651.exe
• sys0230876474-1.exe
• sys024933086519.exe
• sys02798072025.exe
• sys030876474-13.exe
• tagasaurus.exe
• TMTGBX.EXE
• txrmsrv.dll
• uninst104.exe
• uninst108.exe
• uninst2.htm
• uni_e6h.exe
• uni_ehhhh.exe
• unwn.exe
• uwvkeap.exe
• uwvkeapa.exe
• v1201[1].exe
• vapeg22.exe
• visfx500[1].exe
• w001f6bf.dll
• w00274b9.dll
• w0044756.dll
• w004a719.dll
• w004a7b6.dll
• w0083820.dll
• w00dadf4.dll
• wallpap[1].exe
• win10.tmp
• win15.tmp
• win16.tmp
• win19.tmp
• win1a.tmp
• win3.tmp
• win3206596677631.exe
• win32066474-130872006.exe
• win3206704745326.exe
• win3207249-724289.exe
• win3207474-130876.exe
• win320786519493302006.exe
• win320865194933082006.exe
• win32092-93227568.exe
• win32095194933086.exe
• win3210-400812153.exe
• win321019493308652006.exe
• wincjw32.dll
• winf.tmp.exe
• winss32[1].exe
• wixbpib.dll
• wlzip32[1].exe
• xtqe282f.dll
• xtqe282f.sys
• yvn56ea5.dll
• yvn56ea5.sys
• zkkma.exe
• zkkmm.exe
• ~df1bcf.tmp
• ~df350b.tmp
• ~df47d3.tmp
• ~dfbfb2.tmp

Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use Dollarrevenue Removal Tool for safe problem solution.

2. Delete the following malicious folders:

• ꮫ뾡䐐뾡\
• C:\Windows\vk1xyxjlwfbqcm9ob25qzxjzaxn0yw50\
• C:\Documents and Settings\User\Application Data\netmon\
• progra~1\common~1\zkkm\
• progra~1\common~1\rzko\
• progra~1\common~1\mzwf\
• C:\Program Files\windows nt\
• C:\Program Files\messenger\
• C:\Program Files\online services\
• C:\Documents and Settings\User\local settings\temporary internet files\content.ie5\k9unohq7\
• C:\Documents and Settings\User\Desktop\$\
• C:\Program Files\netmeeting\
• C:\Windows\System\kpltxev\

3. Delete the following malicious registry entries and\or values:

• Key: Interface\{6A288140-3E1C-4CD9-AAC5-E20FDD4F5D64}

• Key: Interface\{F9B9C9A3-9D2D-423D-ABA5-80D83A915023}

• Key: CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8}

• Key: CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\InprocServer32
  Value: ThreadingModel

• Key: CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\TypeLib

• Key: CLSID\{FB70936E-7941-4F31-85D1-3C5D56E46767}\InprocServer32

• Key: CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}\InprocServer32
  Value: ThreadingModel

• Key: CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}\TypeLib

• Key: TypeLib\{58D419E8-1321-4DD2-A6FC-7B41C14DCD79}\1.0

• Key: TypeLib\{58D419E8-1321-4DD2-A6FC-7B41C14DCD79}\1.0\FLAGS

• Key: TypeLib\{58D419E8-1321-4DD2-A6FC-7B41C14DCD79}\1.0\0\win32

• Key: TypeLib\{58D419E8-1321-4DD2-A6FC-7B41C14DCD79}\1.0\HELPDIR

• Key: Interface\{F9B9C9A3-9D2D-423D-ABA5-80D83A915023}\ProxyStubClsid

• Key: Interface\{F9B9C9A3-9D2D-423D-ABA5-80D83A915023}\ProxyStubClsid32

• Key: Interface\{F9B9C9A3-9D2D-423D-ABA5-80D83A915023}\TypeLib
  Value: Version

• Key: Interface\{6A288140-3E1C-4CD9-AAC5-E20FDD4F5D64}\ProxyStubClsid

• Key: Interface\{6A288140-3E1C-4CD9-AAC5-E20FDD4F5D64}\ProxyStubClsid32

• Key: Interface\{6A288140-3E1C-4CD9-AAC5-E20FDD4F5D64}\TypeLib
  Value: Version

• Key: CLSID\{69135BDE-5FDC-4B61-98AA-82AD2091BCCC}\InprocServer32
  Value: ThreadingModel

• Key: CLSID\{499152D4-F97F-47B8-AAEE-54B1D075060D}\InprocServer32
  Value: ThreadingModel

• Key: CLSID\{499152D4-F97F-47B8-AAEE-54B1D075060D}
  Value: IDEx

• Key: CLSID\{499152D4-F97F-47B8-AAEE-54B1D075060D}\Implemented Categories

• Key: CLSID\{499152D4-F97F-47B8-AAEE-54B1D075060D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}

• Key: CLSID\{27DF93D3-712D-4AF1-B3D4-5BCA65DD3DAB}
  Value: IDEx

• Key: CLSID\{27DF93D3-712D-4AF1-B3D4-5BCA65DD3DAB}\Implemented Categories

• Key: CLSID\{27DF93D3-712D-4AF1-B3D4-5BCA65DD3DAB}\Implemented Categories\{00021492-0000-0000-C000-000000000046}

• Key: CLSID\{27DF93D3-712D-4AF1-B3D4-5BCA65DD3DAB}\InprocServer32
  Value: ThreadingModel

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8BF9EAC8-6C67-4CD7-8C14-877FE95F4988}

• Key: CLSID\{8BF9EAC8-6C67-4CD7-8C14-877FE95F4988}

• Key: CLSID\{8BF9EAC8-6C67-4CD7-8C14-877FE95F4988}\InProcServer32
  Value: ThreadingModel

• Key: SOFTWARE\System\sysold\ms030876474-132006.exe

• Key: SOFTWARE\System\sysold\Gck26.exe

• Key: CLSID\{23C61979-E85C-4195-9F67-6081CDC26F19}
  Value: IDEx

• Key: CLSID\{23C61979-E85C-4195-9F67-6081CDC26F19}\Implemented Categories

• Key: CLSID\{23C61979-E85C-4195-9F67-6081CDC26F19}\Implemented Categories\{00021492-0000-0000-C000-000000000046}

• Key: CLSID\{23C61979-E85C-4195-9F67-6081CDC26F19}\InprocServer32
  Value: ThreadingModel

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C48E5CD-8519-48B9-9F2B-B70595716ABD}

• Key: CLSID\{7C48E5CD-8519-48B9-9F2B-B70595716ABD}

• Key: CLSID\{7C48E5CD-8519-48B9-9F2B-B70595716ABD}\InProcServer32
  Value: ThreadingModel

• Key: CLSID\{48E59294-9880-11CF-9754-00AA00C00908}\InprocServer32\ThreadingModel

• Key: CLSID\{48E59295-9880-11CF-9754-00AA00C00908}\InprocServer32\ThreadingModel

• Key: SOFTWARE\System\sysold\ms043308651949

• Key: SOFTWARE\System\sysold\ms043308651949.exe

• Key: SOFTWARE\System\sysold\win32095194933086

• Key: SOFTWARE\System\sysold\win32095194933086.exe

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{40C050C8-2DED-4F16-BC5F-1B3267A68432}

• Key: CLSID\{40C050C8-2DED-4F16-BC5F-1B3267A68432}

• Key: CLSID\{40C050C8-2DED-4F16-BC5F-1B3267A68432}\InProcServer32
  Value: ThreadingModel

• Key: CLSID\{FF120560-3028-41D1-8831-0D29066BB8C4}\InProcServer32
  Value: ThreadingModel

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF120560-3028-41D1-8831-0D29066BB8C4}

• Key: CLSID\{FF120560-3028-41D1-8831-0D29066BB8C4}

• Key: SOFTWARE\AdwareDisableKey3

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Run\13c2dabe.exe

• Key: CLSID\{630B5231-3A4A-73A1-B4B1-0B811CAE84F7}\InprocServer32
  Value: ThreadingModel

• Key: CLSID\{21CCDF3C-A76F-412F-A2F2-DF8255D58781}\InprocServer32
  Value: ThreadingModel

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{9B0C7A02-A17A-4C81-BD7D-30A622701C36}

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Run\f8badabe.exe

• Key: Software\Microsoft\Internet Explorer\New Windows\Allow
  Value: www.firstgoodsearch.com

• Key: Software\Microsoft\Internet Explorer\New Windows\Allow
  Value: www.adnet-plus.com

• Key: Software\qstat
  Value: brr

• Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\webnexus
  Value: UninstallString

• Key: Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
  Value: {499152D4-F97F-47B8-AAEE-54B1D075060D}

• Key: Software\Microsoft\drsmartload2
  Value: Installed

• Key: Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
  Value: {27DF93D3-712D-4AF1-B3D4-5BCA65DD3DAB}

• Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Telephony
  Value: DllName

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{70883937-61A2-FFDF-F1F6-C8E81C701B87}
  Value: Display Name

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{70883937-61A2-FFDF-F1F6-C8E81C701B87}
  Value: NoModify

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8BF9EAC8-6C67-4CD7-8C14-877FE95F4988}\iexplore
  Value: Type

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8BF9EAC8-6C67-4CD7-8C14-877FE95F4988}\iexplore
  Value: Count

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8BF9EAC8-6C67-4CD7-8C14-877FE95F4988}\iexplore
  Value: Time

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8BF9EAC8-6C67-4CD7-8C14-877FE95F4988}\iexplore
  Value: Count

• Key: Software\Microsoft\Internet Explorer\URLSearchHooks
  Value: _{A8B28872-3324-4CD2-8AA3-7D555C872D96}

• Key: SOFTWARE\System\sysold
  Value: ms0576474-1308

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\iexplore
  Value: Type

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\iexplore
  Value: Count

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\iexplore
  Value: Time

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\iexplore
  Value: Count

• Key: Software\Microsoft\Internet Explorer\Desktop\Components\0
  Value: Source

• Key: Software\Microsoft\Internet Explorer\Desktop\Components\1
  Value: Source

• Key: SOFTWARE\System\sysold
  Value: win3207474-130876

• Key: SOFTWARE\System\sysold
  Value: sys030876474-13

• Key: SOFTWARE\Policies
  Value: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

• Key: Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
  Value: {23C61979-E85C-4195-9F67-6081CDC26F19}

• Key: SOFTWARE\System\sysold
  Value: win32095194933086.exe

• Key: Software\Classes\CLSID\{14306DB1-08A2-1033-1203-0500002}
  Value: Request

• Key: Software\Classes\CLSID\{14306DB1-08A2-1033-1203-0500002}
  Value: Register

• Key: Software\Classes\CLSID\{14306DB1-08A2-1033-1203-0500002}
  Value: Installation

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{21CCDF3C-A76F-412F-A2F2-DF8255D58781}\iexplore
  Value: Type

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{21CCDF3C-A76F-412F-A2F2-DF8255D58781}\iexplore
  Value: Count

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{21CCDF3C-A76F-412F-A2F2-DF8255D58781}\iexplore
  Value: Time

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35F7813A-AF74-4474-B1DC-7EE6FB6C43C6}\iexplore
  Value: Type

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35F7813A-AF74-4474-B1DC-7EE6FB6C43C6}\iexplore
  Value: Count

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35F7813A-AF74-4474-B1DC-7EE6FB6C43C6}\iexplore
  Value: Time

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}\iexplore
  Value: Type

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}\iexplore
  Value: Count

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}\iexplore
  Value: Time

• Key: Software\Classes\CLSID\{14306DB1-0897-1033-1203-0500002}
  Value: Register

• Key: Software\Classes\CLSID\{14306DB1-0897-1033-1203-0500002}
  Value: Installation

• Key: Software\Microsoft\Internet Explorer\URLSearchHooks
  Value: {1760F74B-1AA2-4305-A7AE-6043B467F7BF}

• Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1760F74B-1AA2-4305-A7AE-6043B467F7BF}
  Value: {1760F74B-1AA2-4305-A7AE-6043B467F7BF}

• Key: Software\Microsoft\Internet Explorer\Desktop\Components\0
  Value: Source

• Key: Software\Microsoft\Internet Explorer\Desktop\Components\1
  Value: Source

• Key: Software\Microsoft\Internet Explorer\Desktop\Components\1
  Value: Source

Warning: If value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use Dollarrevenue Removal Tool for safe problem solution.

Here are the descriptions of problems connected with Dollarrevenue and 28[1].exe we received earlier:



Dollarrevenue on pc and cant connect to net.

Problem Summary: Dollarrevenue on pc and cant connect to net.
Loss of connection since a friend went on and now see dollar revenue popping up everywhere.
Connection to net just stopped and was advised I need to reload windows? Have no clue how to do such a thing!

Our support has contacted the author of this message, simon, and helped to solve his problem.


GLB7.tmp-Entry Point Not Found

Problem Summary: GLB7.tmp-Entry Point Not Found
The procedure entry point RichEdit10ANSIWndProc could not be located in the dynamic link library RICHED20.dll.

Our support has contacted the author of this message, bogdan, and helped to solve his problem.

Next threat: Domcom »

Learn more about Dollarrevenue and 28[1].exe »

« Back to catalog

Solution: 2039
Home | Partners | Shop | Support | Contact Us | Privacy Policy | Sitemap

Copyright © 2003-2009 Security Stronghold. All Rights Reserved.