Remove IEAccess. Description and removal instructions

 
Title: IEAccess

Type: Dialers
Severity scale:IEAccess severity is 57  (57 / 100)
 
IEAccess is a specific ActiveX control that secretly downloads from the Internet and installs one or more dialers without asking for user permission. Such dialers are designed to provide paid access to pornographic web resources. They connect a compromised computer to the Internet by dialing premium rate phone numbers using a modem. IEAccess may also execute arbitrary potentially dangerous code. The threat can silently get into the system while visiting some insecure web sites. It is able to run on every Windows startup.


IEAccess properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic IEAccess removal:

remover for IEAccess

IEAccess manual removal:

Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\livesrv
HKEY_CLASSES_ROOT\CLSID\{3CD945A2-E413-4956-B9D8-A67FB6A7CB66}
HKEY_CLASSES_ROOT\CLSID\{9D6ADDBF-8227-4D36-AE46-116AFBDAFCA0}
HKEY_CLASSES_ROOT\CLSID\{D24A1963-9951-4153-A340-6648759EB77D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieaccess2.iedial
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieaccess2.iedial.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3CD945A2-e413-4956-b9D8-a67FB6A7CB66}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D24A1963-9951-4153-A340-6648759EB77D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Typelib\{9D6ADDBF-8227-4D36-AE46-116AFBDAFCA0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\%System%\liveservice_5.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\%System%/ieaccess2.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\%System%/liveservice_5.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D2DCA0D-B30F-40AD-9690-087105F214EC}
HKEY_USERS\.DEFAULT\Software\eGroup
HKEY_CURRENT_USER\Software\eGroup
Delete files:
dhtmlaccess.dll, eghtmldialer.dll, eghtmldialer_[XVS].dll, ieaccess2.dll, liveservice_[XVS].dll
Delete directories:
C:\Windows\eGroup
C:\Winnt\eGroup
Misc:
[XVS] is the version number.

Listed IEAccess files can be found in the default system folder, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.

Other programs to remove IEAccess:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 19/03/04
Information updated: 01/10/05

Additional resources related to IEAccess:

Attention: If you know or you have a website or page about IEAccess removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about IEAccess parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by Arthur. 2004-03-04 21:16:59
Installed by ActiveX drive-by-download by porn-related pages from nocreditcard.net and sex-explorer.com, which may be opened or redirected to by pop-up advertising.


Latest spyware news:
Similar parasites: