Emsisoft Malware-Info

Name: Adware.Win32.LiaoTian

Risklevel: Low Risk

Description:

This application contains Trojan, and it also will modify IE default start page.

Removal instructions for Adware LiaoTian:

To delete this malware infection, buy Emsisoft Anti-Malware.
Guaranteed removal of Adware LiaoTian.

Run a full scan on all drives and move all detected items to the quarantine.

More details about this danger:

Installation: Installed through EXE

Process: FGYEC.exe

Screenshots:

LiaoTianLiaoTian

Used folders:

  • C:\Program Files\LiaoTian\
  • C:\Program Files\LiaoTian\plugin\
  • C:\Documents and Settings\[USER]\Cookies\
  • C:\Documents and Settings\[USER]\Desktop\
  • C:\Documents and Settings\[USER]\Local Settings\Application Data\Microsoft\Internet Explorer\
  • C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\
  • C:\Documents and Settings\[USER]\Start Menu\Programs\cs??????????????? V1.0\

Used files:

  • C:\Program Files\LiaoTian\aynchw.dll
    [45056 Bytes] DLL File
  • C:\Program Files\LiaoTian\BException.dll
    [9728 Bytes] DLL File
  • C:\Program Files\LiaoTian\camer.dll
    [27648 Bytes] DLL File
  • C:\Program Files\LiaoTian\cfgdll.dll
    [45056 Bytes] DLL File
  • C:\Program Files\LiaoTian\FGYEC.exe
    [150016 Bytes] EXE File
  • C:\Program Files\LiaoTian\helper.dll
    [20480 Bytes] DLL File
  • C:\Program Files\LiaoTian\iext2.fne
    [471040 Bytes] FNE File
  • C:\Program Files\LiaoTian\krnln.fnr
    [1105920 Bytes] FNR File
  • C:\Program Files\LiaoTian\lan.dll
    [294912 Bytes] DLL File
  • C:\Program Files\LiaoTian\offline.dll
    [109456 Bytes] DLL File
  • C:\Program Files\LiaoTian\syetim.exe
    [314626 Bytes] EXE File
  • C:\Program Files\LiaoTian\Uninstall.exe
    [64355 Bytes] EXE File
  • C:\Program Files\LiaoTian\Uninstall.ini
    [2575 Bytes] INI File
  • C:\Program Files\LiaoTian\WinIo.sys
    [4944 Bytes] SYS File
  • C:\Program Files\LiaoTian\WINIO.VXD
    [5174 Bytes] VXD File
  • C:\Program Files\LiaoTian\???.txt
    [67 Bytes] TXT File
  • C:\Program Files\LiaoTian\?????.reg
    [178 Bytes] REG File
  • C:\Program Files\LiaoTian\plugin\BkgndColor.dll
    [31232 Bytes] DLL File
  • C:\Program Files\LiaoTian\plugin\Console.dll
    [17920 Bytes] DLL File
  • C:\Program Files\LiaoTian\plugin\File.dll
    [19456 Bytes] DLL File
  • C:\Program Files\LiaoTian\plugin\GetSysInfo.dll
    [23040 Bytes] DLL File
  • C:\Program Files\LiaoTian\plugin\Memory.dll
    [28672 Bytes] DLL File
  • C:\Program Files\LiaoTian\plugin\Window.dll
    [5632 Bytes] DLL File
  • C:\Documents and Settings\[USER]\Cookies\index.dat
    [32768 Bytes] DAT File
  • C:\Documents and Settings\[USER]\Cookies\virus demo@www.5mqxmq[2].txt
    [161 Bytes] TXT File
  • C:\Documents and Settings\[USER]\Desktop\cs???????????????.lnk
    [671 Bytes] LNK File
  • C:\Documents and Settings\[USER]\Desktop\?????.lnk
    [688 Bytes] LNK File
  • C:\Documents and Settings\[USER]\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
    [16384 Bytes] DAT File
  • C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\index.dat
    [32768 Bytes] DAT File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    [81920 Bytes] DAT File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\dir01[1].gif
    [596 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\search[1].js
    [4370 Bytes] JS File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\srh_1[1].gif
    [1691 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\title[1].js
    [565 Bytes] JS File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\top_cen2[1].gif
    [287 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\dir02[1].gif
    [690 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\pubfun[1].js
    [16177 Bytes] JS File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\tb_link[1].gif
    [413 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\topbg01[1].gif
    [46 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\toplogo[1].gif
    [2064 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\1281803[1].js
    [1840 Bytes] JS File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\dangdang[1].gif
    [2121 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\funb[1].js
    [14772 Bytes] JS File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\gl_1[1].gif
    [1437 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\index[1].css
    [6681 Bytes] CSS File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\tb_bg[1].gif
    [1561 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\120_60[1].gif
    [2961 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\1332061[1].js
    [1211 Bytes] JS File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\5mqxmq[1].htm
    [49912 Bytes] HTM File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\index[1].js
    [13713 Bytes] JS File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\joyo3[1].gif
    [1540 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\top_cen1[1].gif
    [69 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Start Menu\Programs\cs??????????????? V1.0\cs???????????????.lnk
    [683 Bytes] LNK File
  • C:\Documents and Settings\[USER]\Start Menu\Programs\cs??????????????? V1.0\???.lnk
    [779 Bytes] LNK File

Additional information might be found here:

Search at Google for Adware LiaoTian Search at Google for Adware LiaoTian
Search at Bing for Adware LiaoTian Search at Bing for Adware LiaoTian
Search at Yahoo for Adware LiaoTian Search at Yahoo for Adware LiaoTian

How can I protect myself from Adware LiaoTian?

Important!
You essentially need an antivirus product, that is not only able to clean infections, but also protect your PC permanently from new dangers. This is the only way to prevent data loss and unnecessary hassle and costs of new installations of your operating system.

Take your chance and buy the multiple awarded protection software Emsisoft Anti-Malware today!

Only $40 for the security of your computer.

Buy Emsisoft Anti-Malware online:

Buy Emsisoft Anti-Malware now

Trust only on the best protection software!

Spring Offer!

Don't miss this: To your bought 1-year license of Emsisoft Anti-Malware or Emsisoft Internet Security Pack or higher you can now get a free license of the CyberGhost Anonymizer for free.
Your advantage: Surf anonymously and visit websites that are restricted in your country.

Only a few days left! Order here

Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - Q1-Q3 2011
More independent reviews of anti-malware software