Exterminate It! Antimalware

malpedia

Known threats:700,086 Last Update:March 16, 12:51

Testimonials

exterminate it remove the agent.nbo files without restart. i let it scan again, nothing found! great job!

now i surf since 5 minutes, no popups, it looks like the problem is solved!

big thanks to you and your team, you are the only company that give me response and realy help to remove this bad worm/malware!

i will place now links to our network to your homepage and email my friends and business partners that they know that there is a realy good company with a great tool and good programmers.

thanks.

regards,

m. s.

Family.Cyber.Alert- Registry Values List

This is a complete list of Family.Cyber.Alert registry values collected by Exterminate It!. If you find any of these registry values on your PC, your computer is very likely to be infected with the Family.Cyber.Alert - spyware.

IMPORTANT: Because the registry is a core component of your Windows system, it is strongly recommended that you back up the registry before you begin deleting keys and values. For information about backing up the Windows registry, refer to the Registry Editor online help.
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%PROGRAM_FILES_COMMON%]\FCyberAlert\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%SYSTEM%]\FCA\syslogin.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%SYSTEM%]\FCA\FCACheck.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%SYSTEM%]\cdi\syslogin.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%SYSTEM%]\cdi\FCACheck.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%SYSTEMX86%]\FCA\FCACheck.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%SYSTEMX86%]\FCA\syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%PROGRAM_FILES%]\FCA\syslogin.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%PROGRAM_FILES%]\FCA\FCACheck.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]deletesnapshots=30
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chkadvancedisable=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chkdisableadvance=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chkdisablefeature=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chkfilesrecordingdisable=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chkmessengerrecordingdisable=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chkrecordingdisable=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chksnapshotstimedisable=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]cmdrecoveruninstallinformation=Pressed
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]cmdremoveuninstallinformation=UnPressed
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]optcaptureallkeys=False
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]optcaptureasciikeys=True
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]optshowtipoftheday=True
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtarchivelocation=[%SYSTEM%]\FCyberAlert\Recorded
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtbufferoutputinfile=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtdiskspaced=500
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtupdatesnapshots=15
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\wizardsetting]runnedwizard=True
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%SYSTEM%]\FCyberAlert\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmshutdownspyware]optionvalue=2
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]hotkeyoption=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]sldjpegsaveoption=4
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]snapshotstime=30
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert="[%PROGRAM_FILES_COMMON%]\FCyberAlert\Syslogin.exe"
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%SYSTEM%]\ABC\syslogin.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%SYSTEM%]\ABC\FCACheck.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chksnapshotstimedisable=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]deletesnapshots=7
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]snapshotstime=180
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]sldjpegsaveoption=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmshutdownspyware]optionvalue=3
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%WINDOWS%]\FCA\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]sldjpegsaveoption=7
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]optshowtipoftheday=False
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%SYSTEM%]\FCyberAlert\FCACheck.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmshutdownspyware]optionvalue=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtdiskspaced=600
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]deletesnapshots=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtbufferoutputinfile=5
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]deletesnapshots=10
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtarchivelocation=[%PROGRAM_FILES_COMMON%]\FCyberAlert\Recorded
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtdiskspaced=1000
  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]FamilyCyberAlert=[%DESKTOP%]\usefull component\FCA\Syslogin.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%DESKTOP%]\usefull component\FCA\FCACheck.exe
  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]FamilyCyberAlert=[%ANY_FOLDER%]\Crack\Syslogin.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%PROGRAM_FILES_COMMON%]\FCyberAlert\FCACheck.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%ANY_FOLDER%]\FCA\FCACheck.exe
  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]FamilyCyberAlert=[%ANY_DRIVE%]\FCA\Syslogin.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%ANY_DRIVE%]\FCA\FCACheck.exe
  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]FamilyCyberAlert=[%SYSTEM%]\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]deletesnapshots=6
  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]FamilyCyberAlert=[%SYSTEM%]\FCA2\Syslogin.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%SYSTEM%]\FCA2\FCACheck.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chkrecordingdisable=1
  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]FamilyCyberAlert=[%SYSTEM%]\FCA\FCA\Syslogin.exe
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]FCACheck=[%SYSTEM%]\FCA\FCA\Fcacheck.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]optcaptureallkeys=Falso
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]optcaptureasciikeys=Verdadero
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]optshowtipoftheday=Verdadero
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]deletesnapshots=20
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]sldjpegsaveoption=3
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]snapshotstime=40
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtdiskspaced=9999
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]optcaptureallkeys=True
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]optcaptureasciikeys=False
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]deletesnapshots=90
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%ANY_FOLDER%]\Antidoto\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtarchivelocation=[%DESKTOP%]\Crack_Family Cyber Alert v3.99\Recorded
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%DESKTOP%]\Crack_Family Cyber Alert v3.99\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]snapshotstime=60
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chkadvancedisable=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chkfilesrecordingdisable=1
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%WINDOWS%]\FCyberAlert\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]chkmessengerrecordingdisable=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]sldjpegsaveoption=10
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]snapshotstime=90
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]txtdiskspaced=807
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%SYSTEM_DRIVE%]\!KillBox\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%PROFILE_TEMP%]\Rar$EX[%NUM%].[%NUM%]\Family.Cyber.Alert.v4.16.WinAll.Cracked-HS\Crack\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%DESKTOP%]\Family Cyber Alert v4.26\Crack\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]sldjpegsaveoption=2
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%SYSTEM_DRIVE%]\fgk\FCA\syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%WINDOWS%]\panther\unattend\FCA\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%PROGRAM_FILES%]\Folder Lock\Locker\High Park\Family Cyber Alert 4.26\Crack\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]familycyberalert=[%DESKTOP%]\Syslogin.exe
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]deletesnapshots=4
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions]optshowtipoftheday=Falso
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkadvancedisable=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkdisableadvance=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkdisablefeature=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkfilesrecordingdisable=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkmessengerrecordingdisable=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkrecordingdisable=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chksnapshotstimedisable=0
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] cmdrecoveruninstallinformation=Pressed
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] cmdremoveuninstallinformation=UnPressed
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] deletesnapshots=7
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] hotkeyoption=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] optcaptureallkeys=False
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] optcaptureasciikeys=True
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] optshowtipoftheday=True
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] sldjpegsaveoption=7
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] snapshotstime=180
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] txtarchivelocation=[%SYSTEM%]\FCyberAlert\Recorded
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] txtbufferoutputinfile=1
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] txtdiskspaced=500
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] txtupdatesnapshots=15
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmshutdownspyware] optionvalue=2
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\wizardsetting] runnedwizard=True
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkadvancedisable=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkdisableadvance=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkdisablefeature=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkfilesrecordingdisable=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkmessengerrecordingdisable=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chkrecordingdisable=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] chksnapshotstimedisable=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] cmdrecoveruninstallinformation=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] cmdremoveuninstallinformation=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] deletesnapshots=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] hotkeyoption=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] optcaptureallkeys=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] optcaptureasciikeys=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] optshowtipoftheday=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] sldjpegsaveoption=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] snapshotstime=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] txtarchivelocation=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] txtbufferoutputinfile=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] txtdiskspaced=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmoptions] txtupdatesnapshots=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\frmshutdownspyware] optionvalue=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\infoworks technology\family cyber alert\wizardsetting] runnedwizard=(EMPTY)
  • [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] familycyberalert=(EMPTY)