SecurityStronghold SecurityStronghold SecurityStronghold SecurityStronghold    
SecurityStronghold SecurityStronghold
 
   

MoneyTree and 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe - Easily eliminate this problem

Let our support team solve your problem with MoneyTree and repair 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe right now!

Leave the detailed description of your problem in the form below. Our support team will contact you in several minutes and give a step-by-step instruction on how to solve your problem. Please be specific. Do your best describing the problem. This will help us recommend right and complete solution.

Describe your problem here and we'll contact you in several minutes:

We'll reply you in 10 minutes or less
* Name:
* Email:
* Problem summary:
* Detailed problem description:
Enable this image please (result of arithmetic expression at left)

We'll contact you in 10 minutes or less after you click on this button! Individual solution guaranteed!

Warning:

1) We hate spam as much as you do. We will not share your email with any third party or publish it anywhere. Your email is used only to contact you and give you the solution of your problem.
2) All fields of this form are obligatory.

Guaranteed Problem Solution
Software Industry Professionals Member
Threat's description and solution are developed by Security Stronghold security team. Let professionals make your problems solved now!

What is MoneyTree? Technical details of MoneyTree problem and 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe file

Manual solution methods

Free download of a program that will solve your problem automatically

Free instant professional support in solving MoneyTree and 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe error from our Security Support Team

Download solution for MoneyTree and 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe now!

Threat's profile

Threat indicator: HIGH
Name of the threat: MoneyTree
Command or file name: 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe
Threat type: Dialer
Affected OS: Win32 (Windows 9x, Windows XP, Windows Vista)

Intrusion method

This threat copies its file(s) to your hard disk. Its typical file name is MoneyTree. Then it creates new startup key with name MoneyTree and value 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe. You can also find it in your processes list with name 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe or MoneyTree.

If you have further questions about this threat, please fill in the form below and we'll contact you shortly.

» Download program for 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe removal (True Sword Threat Remover)

Recommended Solution

If you are not sure what to delete, use our award winning program - True Sword. True Sword will find and fully remove MoneyTree and 316 214 other dangerous threats including trojans, spyware, adware, riskware, problemware, keyloggers, dialers, viruses and other kinds of malicious programs in several seconds. Fast, easy, and handy, True Sword protects your computer against malicious programs that do harm to your computer and break your privacy. True Sword scans your hard disks and registry and destroys any manifestation of such malicious programs. Standard anti-virus software can do nothing against privacy breakers and malicious programs like that. Get rid of trojans, spyware, adware, trackware, dialers and keyloggers in one click now!

» Download True Sword now for free

How to fix MoneyTree

This problem can be solved manually by deleting all registry keys and files connected with this software, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by MoneyTree. To fix this threat, you should:

1. Kill the following processes and delete the appropriate files:

• 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe
• 644cb054e1fe6e18505d548f93bfb90b.exe
• aaec91ad3637826c6879a51ebd7b9e31.exe
• actalert.exe
• blss.exe
• cln4380.tmp
• free_sex_download.*
• iopti130.dll
• links.*
• MoneyTree Dialer
• msg2090.tmp10730720494655.exe
• muldist.*
• muldist.inf
• muldist.ocx
• MultiDist
• multidistfc[1].cab
• nem207.dll
• nem210.dll
• nem214.dll
• NSLiteUpdateCtrl Class
• NSUpdateLiteCtrl Class
• opti130.dll
• optimiser.msg
• safesurfing.dll
• safesurfing.exe
• Software Update Manager
• ssuninstall.exe
• ssupdate.exe
• stmtdlr.exe
• trojandownloader.win32.dyfuca.aa.dll
• trojandownloader.win32.dyfuca.j.dll
• trojandownloader.win32.dyfuca.k.dll
• trojandownloader.win32.dyfuca.q.dll
• trojandownloader.win32.dyfuca.r.dll
• trojandownloader.win32.dyfuca.t.dll
• trojandownloader.win32.dyfuca.w.dll
• trojandownloader.win32.dyfuca.z.dll
• unidist.*
• unidist.inf
• unidist.ocx
• view_sex_now.exe
• wsem210.dll
• wsem300.dll

Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use True Sword for safe problem solution.

2. Delete the following malicious folders:

• C:\Program Files\dialers\
• C:\Program Files\Common Files\startup\register morpheus upgrade suite3.exe\

3. Delete the following malicious registry entries and\or values:

• Key: CLSID\{a0f0d762-d1de-43af-b70e-d87864743eb3}

• Key: CLSID\{BF279130-3F58-4E26-8043-CD5688A4D4C9}

• Key: CLSID\{c89bb48c-15d9-4f4f-803e-95d90f62be62}

• Key: CLSID\{e8edb60c-951e-4130-93dc-faf1ad25f8e7}

• Key: CLSID\{FC87A650-207D-4392-A6A1-82ADBC56FA64}

• Key: interface\{563e5df0-2c1c-4513-bbf5-d380536bb8fc}

• Key: interface\{9f2c17ac-9aa4-4c3a-82c7-ea7bcf00f03d}

• Key: Interface\{CA7CCB52-6922-47E5-B784-3A3F82C51863}

• Key: Interface\{F332D106-2EF3-45C4-BAF2-0F739D76B26A}

• Key: MULTIDIST.MultiDistCtrl.1

• Key: software\microsoft\windows\currentversion\explorer\browser helper objects\{8f4e5661-f99e-4b3e-8d85-0ea71c0748e4}
  Value: @

• Key: software\microsoft\windows\currentversion\explorer\browser helper objects\{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
  Value: @

• Key: TypeLib\{11B6F65D-7B8D-43CB-9AAE-17234A1DB33A}

• Key: typelib\{8f4e5661-f99e-4b3e-8d85-0ea71c0748e4}
  Value: @

• Key: TypeLib\{96B01A48-1317-4A87-91F7-10116F755705}

• Key: typelib\{d8e25c53-9508-4f5c-9249-d98d438891d5}
  Value: @

• Key: typelib\{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
  Value: @

• Key: unidist.unidistctrl.1

• Key: software\fci
  Value: @

• Key: software\classes\clsid\{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
  Value: @

• Key: software\microsoft\code store database\distribution units\{e8edb60c-951e-4130-93dc-faf1ad25f8e7}

• Key: Software\Microsoft\Code Store Database\Distribution Units\{FC87A650-207D-4392-A6A1-82ADBC56FA64}
  Value: SystemComponent

• Key: Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MulDist.ocx
  Value: .Owner

• Key: software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/unidist.ocx

• Key: software\microsoft\windows\currentversion\run\monitor
  Value: @

• Key: software\microsoft\windows\currentversion\shareddlls\c:\windows\downloaded program files\muldist.ocx
  Value: @

• Key: software\microsoft\windows\currentversion\shareddlls\c:\windows\downloaded program files\unidist.ocx
  Value: @

• Key: CLSID\{405fd721-04ef-4ef2-ab96-fb31d32d4643}

• Key: TypeLib\{11B6F65D-7B8D-43CB-9AAE-17234A1DB33A}\1.0

• Key: TypeLib\{11B6F65D-7B8D-43CB-9AAE-17234A1DB33A}\1.0\FLAGS

• Key: TypeLib\{11B6F65D-7B8D-43CB-9AAE-17234A1DB33A}\1.0\0\win32

• Key: TypeLib\{11B6F65D-7B8D-43CB-9AAE-17234A1DB33A}\1.0\HELPDIR

• Key: Interface\{F332D106-2EF3-45C4-BAF2-0F739D76B26A}\ProxyStubClsid

• Key: Interface\{F332D106-2EF3-45C4-BAF2-0F739D76B26A}\ProxyStubClsid32

• Key: Interface\{F332D106-2EF3-45C4-BAF2-0F739D76B26A}\TypeLib
  Value: Version

• Key: Interface\{563E5DF0-2C1C-4513-BBF5-D380536BB8FC}\ProxyStubClsid

• Key: Interface\{563E5DF0-2C1C-4513-BBF5-D380536BB8FC}\ProxyStubClsid32

• Key: Interface\{563E5DF0-2C1C-4513-BBF5-D380536BB8FC}\TypeLib
  Value: Version

• Key: CLSID\{BF279130-3F58-4E26-8043-CD5688A4D4C9}\InprocServer32

• Key: MULTIDIST.MultiDistCtrl.1\CLSID

• Key: CLSID\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\ProgID

• Key: CLSID\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\InprocServer32
  Value: ThreadingModel

• Key: CLSID\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\ToolboxBitmap32

• Key: CLSID\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\MiscStatus

• Key: CLSID\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\MiscStatus\1

• Key: CLSID\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\Control

• Key: CLSID\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\TypeLib

• Key: CLSID\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\Version

• Key: Software\Microsoft\Code Store Database\Distribution Units\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\InstalledVersion
  Value: LastModified

• Key: software\microsoft\windows\currentversion\shareddlls
  Value: C:\Windows\downloaded program files\muldist.ocx

• Key: software\microsoft\windows\currentversion\shareddlls
  Value: C:\Windows\downloaded program files\unidist.ocx

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{622CC208-B014-4FE0-801B-874A5E5E403A}\iexplore
  Value: Type

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{622CC208-B014-4FE0-801B-874A5E5E403A}\iexplore
  Value: Count

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{622CC208-B014-4FE0-801B-874A5E5E403A}\iexplore
  Value: Time

• Key: Software\Microsoft\Internet Explorer\URLSearchHooks
  Value: {15651C7C-E812-44a2-A9AC-B467A2233E7D}

• Key: Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0
  Value: ppcimdnnnjbeahepfabjipfginloedkg enodaj

• Key: Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0
  Value: ppcimdnnnjbeahepfabjipfginloedkg cfcaak

• Key: Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0
  Value: goicfboogidikkejccmclpieicihhlpo ejfebp

• Key: Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0
  Value: goicfboogidikkejccmclpieicihhlpo imfado

• Key: Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0
  Value: goicfboogidikkejccmclpieicihhlpo igcdca

• Key: Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MulDist.ocx
  Value: {FC87A650-207D-4392-A6A1-82ADBC56FA64}

• Key: Software\Microsoft\Code Store Database\Distribution Units\{FC87A650-207D-4392-A6A1-82ADBC56FA64}
  Value: Installer

• Key: Software\Microsoft\Code Store Database\Distribution Units\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\DownloadInformation
  Value: CODEBASE

• Key: Software\Microsoft\Code Store Database\Distribution Units\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\DownloadInformation
  Value: INF

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\iexplore
  Value: Type

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\iexplore
  Value: Count

• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC87A650-207D-4392-A6A1-82ADBC56FA64}\iexplore
  Value: Time

• Key: Software\Microsoft\Internet Explorer\Search
  Value: SearchAssistant

Warning: If value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use True Sword for safe problem solution.

 

 

Here are the descriptions of problems connected with MoneyTree and 5bc2a0cc5720bf5f1b1c54bbbfc7f612.exe we received earlier:

Next threat: Morpheus »

« Back to catalog

 
Products
Active Shield
Active Shield icon
True Sword
True Sword icon
Security Suite
Security Suite icon
Registry Cleaner
Registry Cleaner icon

Online update

Date: May 11, 2008

Threats: 316 214


News
May 15, 2008
We are proud to present you our new program - Registry Cleaner! Free windows registry from errors and garbage and increase its performance up to 250% with help of Registry Cleaner! Download it now.
June 03, 2007
There was a huge update of our spyware and adware encyclopedia today! Enjoy new structute of encyclopedia and ability to search within database.
March 04, 2007
Active Shield and True Sword now fully support Windows Vista.
January 06, 2007
Active Shield 4 has just been released! New features include dynamic rapid scanning of hard disk and registry for known malicious programs and tracking cookies guarding.
December 20, 2006
True Sword 4 has just been released! New features include deep reverse scanning algorithm, more than 40 000 new spyware database definitions, increased speed and reliability. It is urgently recommended for all existing True Sword users to install True Sword 4.

Our partners