Remove StripPlayer. Description and removal instructions

 
Title: StripPlayer

Type: Dialers
Severity scale:StripPlayer severity is 40  (40 / 100)
 
StripPlayer is a dialer that connects a compromised computer to the Internet by dialing high-cost phone numbers using a modem. It is designed to provide access to pornographic web resources. StripPlayer can get into the system while visiting a web site on the stripplayer.com domain. The user must agree to the installation. The dialer does not attempt to hide from the user.


StripPlayer properties:
• Changes browser settings
• Connects itself to the internet
• Stays resident in background

Automatic StripPlayer removal:

remover for StripPlayer

StripPlayer manual removal:

Kill processes:
stripsetup.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveStripSetup.EGStripDownload
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveStripSetup.EGStripDownload.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DialerOffline.COMDialer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DialerOffline.COMDialer.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GirlControlCom.GirlCom
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GirlControlCom.GirlCom.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CABD7099-6B04-471D-8371-9FDE9C2E6BEA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CEB29DA4-7AFA-4F24-B3CD-17351D590DF0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1773B696-B019-4FC1-9EED-B1C7F925F56A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{20270406-63AD-4C7E-AE8D-BB632E508ACE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{271D7D74-8E6D-4E6C-86F5-66C064CFB74D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{89161220-A3D9-464F-848C-4EBE0546697D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BC23F736-C5BE-47FB-B459-1757933E5DF3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{357AA41A-B7A8-4632-A27D-5B980B25CF43}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A8882720-E26C-4073-8B8A-981D32882AF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B0ACF771-F0F7-461F-BEF3-5B1A3BA42F51}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E3F7205F-2AE0-4BF0-816B-2D24A5F20EC7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/ActiveStripSetup.dll
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Error Dlg Details Pane Open
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Strip-Player
Unregister DLLs:
activestripsetup.dll, dialeroffline.dll, girlcontrolcom.dll

Delete files:
stripsetup.exe, activestripsetup.dll, cstripvideo.dll, dialeroffline.dll, girlcontrolcom.dll, listgirls.dll
Delete directories:
C:\Program Files\strip-player
Misc:
Exact file location:
cstripvideo.dll, listgirls.dll - C:\Program Files\strip-player
activestripsetup.dll, dialeroffline.dll, girlcontrolcom.dll - C:\Program Files\strip-player, C:\Windows\System, C:\Windows\System32, C:\Winnt\System32

Other programs to remove StripPlayer:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 19/03/04
Information updated: 20/09/05

Additional resources related to StripPlayer:

Attention: If you know or you have a website or page about StripPlayer removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about StripPlayer parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by BigJoe. 2004-03-01 21:46:01
Installed by ActiveX drive-by-download on porn-related pages from strip-player.com (which might be opened by pop-up advertising).

Installation can happen totally automatically on versions of Internet Explorer older than IE6 Service Pack 1, as a security hole is exploited to add the manufacturers, 'Electronic Group', to the list of publishers you trust, allowing them to install any software they like.

The 'StripSetup' ActiveX control can be used on any web page, by any author, to download and run any executable file. There are no security checks whatsoever.


Related news:
Similar parasites:
Related articles: