Remove Dinoxi. Description and removal instructions

 
Title: Dinoxi
Also known as: Dioxin
Type: Worms
Severity scale:Dinoxi severity is 78  (78 / 100)
 
Dinoxi, also known as Dioxin, is a dangerous worm that spreads through instant messages using the AOL Instant Messenger program. It sends messages containing a certain text and malicious links pointing to infected files to all the users on the AIM contact list. Once a victim clicks on such link, the worm installs itself to the system and displays a message containing swear-words. Then Dinoxi initiates a spreading routine and runs a payload. The worm opens a back door providing the attacker with unauthorized remote access to a compromised computer. The intruder can control the entire system and steal user sensitive information. Dinoxi also disables essential system tools including the Task Manager, the Registry Editor and the Device Manager, cripples the DOS subsystem, modifies Windows Explorer settings, changes the mouse, display and time format settings. Moreover, the parasite hides everything on the desktop and changes the Internet Explorer default home page. It may also install a recent variant of itself. Dinoxi automatically runs on every Windows startup.


Dinoxi properties:
• Allows remote user connection
• Changes browser settings
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Dinoxi removal:

remover for Dinoxi

Dinoxi manual removal:

Kill processes:
dioxin.exe, o.exe, windio778.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ScanRegistry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\SchedulingAgent
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page=[site address]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoDesktop=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsMenu=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetTaskbar=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskmgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDevMgrPage=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\Disabled=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\NoRealMode=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserClose=1
Delete files:
dioxin.exe, o.exe, windio778.exe
Misc:
[site address] is an address of a web site on the ud7swe.t35.com domain.

Exact file location:
windio778.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
dioxin.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32; C:\Documents and Settings\All Users\Start Menu\Programs\Startup; A:

Other programs to remove Dinoxi:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 11/12/05
Information updated: 11/12/05

Additional resources related to Dinoxi:

Attention: If you know or you have a website or page about Dinoxi removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Dinoxi parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: