Alibaba Toolbar manual removal:
Kill processes:
update.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Alibaba\Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AlibabaIEToolBar.AlibabaButton
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AlibabaIEToolBar.AlibabaButton.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AlibabaIEToolBar.AlibabaSearchBar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AlibabaIEToolBar.AlibabaSearchBar.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AlibabaIEToolBar.ShowBarObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AlibabaIEToolBar.ShowBarObject.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0C588F7D-A2B3-4001-B59B-D856C1BF3AD7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{850B69E4-90DB-4F45-8621-891BF35A5B53}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{09F59435-7814-48ED-A73A-96FF861A91EB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{42CB709C-A1D6-4C3A-9F9C-B077FF86A760}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{63C8AF31-AD6E-417C-BF8B-48B96E95DC25}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB44756F-FCE0-454D-AF29-930B89BB44D2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{448F1BD5-C41A-4551-83CF-8CD2309ABC66}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{09F59435-7814-48ED-A73A-96FF861A91EB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{13B0C05C-EF05-4BF6-B0EA-F6111AF25544}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{09F59435-7814-48ED-A73A-96FF861A91EB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Alibaba Toolbar
Unregister DLLs:bar.dll
Delete files:update.exe, bar.dll
Misc:The threat is related to Chinese web site china.alibaba.com.
Post Comment: