ShopAtHomeSelect Removal: Remove ShopAtHomeSelect Forever
Let our support team solve your problem with ShopAtHomeSelect and repair ShopAtHomeSelect right now!
Leave the detailed description of your ShopAtHomeSelect problem in the form below. Our support team will contact you in several minutes and give a step-by-step instruction on how to fix ShopAtHomeSelect problem. Please be specific. Do your best describing the problem. This will help us recommend right and complete ShopAtHomeSelect problem removal solution.
Describe your problem here and we'll contact you in several minutes:
Warning:
1) We hate spam as much as you do. We will not share your email with any third party or publish it anywhere. Your email is used only to contact you and give you ShopAtHomeSelect removal solution.
2) All fields of this form are obligatory.
Threat's profile
|
Name of the threat: ShopAtHomeSelect |
| Command or file name: 795l62j4.exe |
| Threat type: Spyware |
| Affected OS: Win32 (Windows 9x, Windows XP, Windows Vista) |
ShopAtHomeSelect intrusion method
ShopAtHomeSelect copies its file(s) to your hard disk. Its typical file name is 795l62j4.exe. Then it creates new startup key with name ShopAtHomeSelect and value 795l62j4.exe. You can also find it in your processes list with name 795l62j4.exe or ShopAtHomeSelect.
If you have further questions about ShopAtHomeSelect, please fill in the form above and we'll contact you shortly.
» Download program to remove ShopAtHomeSelect (ShopAtHomeSelect Removal Tool)
Recommended Solution
If you are not sure what to delete, use our award winning program - ShopAtHomeSelect Removal Tool.
ShopAtHomeSelect Removal Tool will find and fully remove ShopAtHomeSelect and all problems associated with ShopAtHomeSelect virus.
Fast, easy, and handy, ShopAtHomeSelect Removal Tool protects your computer against ShopAtHomeSelect that does harm to your computer and breaks your privacy. ShopAtHomeSelect Removal Tool scans your hard disks and registry and destroys any manifestation of ShopAtHomeSelect. Standard anti-virus software can do nothing against malicious programs like ShopAtHomeSelect. Remove ShopAtHomeSelect straight away!
» Download ShopAtHomeSelect Removal Tool now for free
How to fix ShopAtHomeSelect
This problem can be solved manually by deleting all registry keys and files connected with ShopAtHomeSelect, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by ShopAtHomeSelect.
To get rid of ShopAtHomeSelect, you should:
1. Kill the following processes and delete the appropriate files:
• 7gdu0b7c.exe
• abasa5jrp_.exe
• abasa5jrp_.ini
• ap2nqrd4.dat
• binsttmp.tmp
• bundlelite.exe
• bundlep.exe
• bundle_cdt1006.exe
• cc6p7pug.exe
• cc6p7pug.ini
• dupcount.tmp
• e0jh5h77.exe
• e3c9nerc.html
• EulaUpgrade.exe
• fraja2fs.exe
• fraja2fs.ini
• gn0obd84.dll
• GRInstall.inf
• GRInstall6.dll
• grinstall7.dll
• gr_1reg.gif
• gr_2shop.gif
• gr_3cash.gif
• gr_reg_header.gif
• gr_sahs_logo2.gif
• h5u8nl7u.dat
• ibecdbv8.ini
• iteicpm3.dat
• k818begl.dll
• mcm3.exe
• nc3dmmkb.html
• oipi9a7v.dll
• papsfi9h.exe
• pde0m3r9.dat
• pifhgldt.exe
• qap2nqrd4.dat
• r4t00otj.exe
• ra62gm8h.dll
• relatedsetup.exe
• ritsacnk.dat
• s9205ge4.dll
• sah.exe
• sahagent-fellymedia1001.exe
• selectrebates.dll
• selectrebates.exe
• selectrebates.ini
• selectrebatesa.dat
• selectrebatesapi.exe
• selectrebatesapi.ini
• selectrebatesb.dat
• selectrebatesbt.dat
• selectrebatesuninstall.exe
• selectrebatesuninstall.ini
• selectrebatesuninstall_.exe
• SelectRebates_FreeGifts.exe
• SelectRebates_SiteInstall.exe
• shop1004.exe
• sporder_.dll
• ssippcbl.dat
• submit_pop.gif
• t6c8p6hd.dat
• vcmjsls1.dat
• zsysuz.exe
• zxinst12.exe
Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use ShopAtHomeSelect Removal Tool for safe problem solution.
2. Delete the following malicious folders:
• C:\Windows\mcm\
• C:\Windows\System\sahimages\
• C:\Documents and Settings\User\Desktop\bundle_cdt1006\
• C:\Documents and Settings\User\Desktop\sure leads\
• C:\Program Files\selectrebates\
• C:\Documents and Settings\User\Desktop\geturl4todo\205.240.15.19\axinstall\
3. Delete the following malicious registry entries and\or values:
• Key: clsid\{30402ff4-3e71-4a1c-9b4b-1cd3486a9fb2}
• Key: interface\{4828c95f-c5db-4ab6-a945-8d8ec44b98a8}
• Key: interface\{4e570f74-deee-4fcf-b960-feefa4b8c6fc}
• Key: WEBInstaller.execute
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SAHBundle
• Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\a95kfrhe
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopAtHomeSelect Agent
• Key: software\vgroup
• Key: SOFTWARE\VGroup\SAHAgent Value: DllName
• Key: CLSID\{5F3B3060-09E0-44C6-86F7-BC7B02B57BEE}
• Key: SOFTWARE\Group\SAHAgent
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\AppManagement\ARPCache\ShopAtHomeSelect Agent
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/aj8sml3fo_.exe
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/aj8sml3fo_.exe
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/h63v2629j_.exe
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/h63v2629j_.ini
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/lcp4q80t9_.dll
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/uu1en13ec_.exe
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/uu1en13ec_.ini
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/WEBInstaller.dll
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/websetup.ini
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/h63v2629j_.exe
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/h63v2629j_.ini
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/lcp4q80t9_.dll
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/uu1en13ec_.exe
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/uu1en13ec_.ini
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/WEBInstaller.dll
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/websetup.ini
• Key: software\microsoft\windows\currentversion\uninstall\70tovmto
• Key: software\winsock2\layered provider sample
• Key: WEBInstaller.execute.1
• Key: GRInstall7.Installer.1
• Key: GRInstall7.Installer.1\CLSID
• Key: GRInstall7.Installer
• Key: GRInstall7.Installer\CLSID
• Key: GRInstall7.Installer\CurVer
• Key: CLSID\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}
• Key: CLSID\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\ProgID
• Key: CLSID\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\VersionIndependentProgID
• Key: CLSID\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\InprocServer32 Value: ThreadingModel
• Key: CLSID\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\TypeLib
• Key: TypeLib\{759C257C-F750-4F52-AB58-FB8A7B8770FE}\1.0
• Key: TypeLib\{759C257C-F750-4F52-AB58-FB8A7B8770FE}\1.0\FLAGS
• Key: TypeLib\{759C257C-F750-4F52-AB58-FB8A7B8770FE}\1.0\0\win32
• Key: TypeLib\{759C257C-F750-4F52-AB58-FB8A7B8770FE}\1.0\HELPDIR
• Key: Interface\{DE92B583-BA06-495B-8438-85591194521B}
• Key: Interface\{DE92B583-BA06-495B-8438-85591194521B}\ProxyStubClsid
• Key: Interface\{DE92B583-BA06-495B-8438-85591194521B}\ProxyStubClsid32
• Key: Interface\{DE92B583-BA06-495B-8438-85591194521B}\TypeLib Value: Version
• Key: Software\Microsoft\Code Store Database\Distribution Units\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\InstalledVersion
• Key: SOFTWARE\Microsoft\Windows\ShellNoRoam\MUICache Value: C:\Windows\System\SahAgent.exe
• Key: SOFTWARE\VGroup\SAHAgent Value: HtmlName
• Key: SOFTWARE\VGroup\SAHAgent Value: BundleKey
• Key: SOFTWARE\VGroup\SAHAgent Value: BundlePackage
• Key: SOFTWARE\VGroup\SAHAgent Value: iniName
• Key: SOFTWARE\VGroup\SAHAgent Value: PackageLocation
• Key: SOFTWARE\VGroup\SAHAgent Value: PackageName
• Key: SOFTWARE\VGroup\SAHAgent Value: PrefsServer
• Key: SOFTWARE\VGroup\SAHAgent Value: PrefsPath
• Key: SOFTWARE\VGroup\SAHAgent Value: PrefsXML
• Key: SOFTWARE\VGroup\SAHAgent Value: CookieUserAgent
• Key: SOFTWARE\VGroup\SAHAgent Value: BrowserType
• Key: SOFTWARE\VGroup\SAHAgent Value: BundleProgress
• Key: SOFTWARE\VGroup\SAHAgent Value: BundleInstall
• Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\papsfi9h Value: DisplayName
• Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\papsfi9h Value: UninstallString
• Key: SOFTWARE\VGroup\SAHAgent Value: HowdyPartner
• Key: software\microsoft\windows\currentversion\uninstall\papsfi9h Value: uninstallstring
• Key: SOFTWARE\VGroup\SAHAgent Value: KeyExistNai
• Key: SOFTWARE\VGroup\SAHPopup Value: LastIS
• Key: SOFTWARE\VGroup\SAHAgent Value: DllName
• Key: SOFTWARE\VGroup\SAHAgent Value: HtmlName
• Key: SOFTWARE\VGroup\SAHAgent Value: CountKey
• Key: SOFTWARE\VGroup\SAHAgent Value: BundleInstall
• Key: SOFTWARE\VGroup\SAHAgent Value: AgentVersion
• Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\r4t00otj Value: DisplayName
• Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\r4t00otj Value: UninstallString
• Key: SOFTWARE\VGroup\SAHPopup Value: LastInstall
• Key: SOFTWARE\ShopAtHome\SelectRebates Value: SelectRebatesLocation
• Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SelectRebatesUninstall Value: DisplayName
• Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SelectRebatesUninstall Value: UninstallString
• Key: Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/BundleLite.exe Value: .Owner
• Key: Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/BundleLite.exe Value: {E9670165-86FE-4C34-8C4B-D3158DDC5D92}
• Key: Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/GRInstall7.dll Value: .Owner
• Key: Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/GRInstall7.dll Value: {E9670165-86FE-4C34-8C4B-D3158DDC5D92}
• Key: Software\Microsoft\Code Store Database\Distribution Units\{E9670165-86FE-4C34-8C4B-D3158DDC5D92} Value: SystemComponent
• Key: Software\Microsoft\Code Store Database\Distribution Units\{E9670165-86FE-4C34-8C4B-D3158DDC5D92} Value: Installer
• Key: Software\Microsoft\Code Store Database\Distribution Units\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\DownloadInformation Value: CODEBASE
• Key: Software\Microsoft\Code Store Database\Distribution Units\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\DownloadInformation Value: INF
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\iexplore Value: Type
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\iexplore Value: Count
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\iexplore Value: Time
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}\iexplore Value: Count
• Key: SOFTWARE\VGroup\SAHAgent Value: DllName
• Key: SOFTWARE\VGroup\SAHAgent Value: HtmlName
• Key: SOFTWARE\VGroup\SAHAgent Value: UniqueBundleKey
• Key: SOFTWARE\VGroup\SAHAgent Value: UniqueBundleID
• Key: SOFTWARE\VGroup\SAHAgent Value: InstallLocation
• Key: SOFTWARE\VGroup\SAHAgent Value: InstPath
• Key: SOFTWARE\VGroup\SAHAgent Value: BundleKey
• Key: SOFTWARE\VGroup\SAHAgent Value: BundlePackage
• Key: SOFTWARE\VGroup\SAHAgent Value: PackageLocation
• Key: SOFTWARE\VGroup\SAHAgent Value: PackageName
• Key: SOFTWARE\VGroup\SAHAgent Value: PrefsPath
• Key: SOFTWARE\VGroup\SAHAgent Value: PrefsXML
Warning: If value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use ShopAtHomeSelect Removal Tool for safe problem solution.
Next threat: shopathomeselect cookie »
Learn more about ShopAtHomeSelect and 795l62j4.exe »
« Back to catalog
Solution: 2913
|