Remove Cutwail. Description and removal instructions

 
Title: Cutwail

Type: Trojans
Severity scale:Cutwail severity is 94  (94 / 100)
 
Cutwail trojan usually gets on a computer as part of other program, i.e. illegal software installs, movies and similar files. It also spreads as fake video codec. Cutwail infection is difficult to prevent because people voluntarily download infected files without knowing about additional features included in them.

Cutwail downloads and executes malwares with user’s permission. Computer’s owner may even doesn’t notice any malicious activity because Cutwail works in a background. The trojan is able to install various malicious programs. It usually downloads adware, corrupt security tools and fraudulent browser toolbars.


Related files: rs32net.ex1, outpuk24[1].exe, setupapi.dll, 943327918.exe

Cutwail properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Cutwail removal:

remover for Cutwail

Cutwail manual removal:

Kill processes:
outpuk24[1].exe 943327918.exe
Delete registry values:
HKEY_CLASSES_ROOT\clsid\{36b0a261-ea24-6be5-6027-7fc4035dd69b}
HKEY_CLASSES_ROOT\clsid\{7b5a24ee-1a07-53ab-eb60-eb908c88e935}
HKEY_CLASSES_ROOT\clsid\{51704c8a-007a-8362-32d7-c2ee36ce9214}
HKEY_CLASSES_ROOT\clsid\{97b59ad2-1228-70b8-ca0b-b7594efcbe07}
HKEY_CLASSES_ROOT\clsid\{f7405b81-92e2-ba64-ee73-933738d57403}
HKEY_CURRENT_USER\software\wget
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9b71d88c-c598-4935-c5d1-43aa4db90836}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\xvid
HKEY_LOCAL_MACHINE\software\wget
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ndnet1
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_runtime
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_runtime2
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ndnet1
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\runtime
HKEY_CURRENT_USER\software\dimaware
HKEY_LOCAL_MACHINE\software\dimaware
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c4de5b15-4ffe-4c02-8cb3-cad24a33562b}
HKEY_LOCAL_MACHINE\system\currentcontrolset001\control\safeboot\minimal\ctl_w32.sys
HKEY_LOCAL_MACHINE\system\currentcontrolset001\control\safeboot\network\ctl_w32.sys
HKEY_LOCAL_MACHINE\system\currentcontrolset001\services\ctl_w32
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ctl_w32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, startkey=[%SYSTEM%]\setup.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, startkey=[%SYSTEM%]\winlog.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, startkey=[%WINDOWS%]\winnows.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, startdrv=[%WINDOWS%]\Temp\startdrv.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run, startdrv=
Unregister DLLs:
setupapi.dll

Delete files:
outpuk24[1].exe setupapi.dll rs32net.ex1 943327918.exe

Other programs to remove Cutwail:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 15/10/08
Information updated: 10/11/08

Additional resources related to Cutwail:

Attention: If you know or you have a website or page about Cutwail removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Cutwail parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: