PerMedia manual removal:
Kill processes:
otms.exe, otupdate.exe, winsrvc.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PMedia
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\IEEvtCatcher.IEEvtCatcherObj
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\IEEvtCatcher.IEEvtCatcherObj.1
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\IEMsgSvr.IEMsgSvrObj
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\IEMsgSvr.IEMsgSvrObj.1
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{7011471D-3F74-498E-88E1-C0491200312D}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{7677C920-9CC3-4621-AF8C-AD45402DC2FD}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\Interface\{059D8C85-A00F-40AF-8078-7692A0A79F19}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TypeLib\{3972ADCE-8737-45DE-A6E2-A253348E5A1E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7011471D-3F74-498E-88E1-C0491200312D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinSrv Reg
Unregister DLLs:otdock.dll, otglove.dll
Delete files:otms.exe, otupdate.exe, winsrvc.exe, otdock.dll, otglove.dll
Delete directories:C:\Program Files\Common Files\Media
Their greeting card worm uses a site called:
http://www.friendgreetings.com/
When you visit it, it looks like a low end flower shopping site, by 'Floral Inspirations by nancy - Phoenix, Arizona'.
Looking closer, you see that the content is absolutely fake, none of the links work.
Doing a whois on the site reveals that the creator is:
'Alfaro, Ricardo
admin@permissionedmedia.com
Permissioned Media Inc.
Apartado 5956
Panama City, El Dorado Zona 6
PA 571-628-5535 '
Post Comment: