What is TacOnlyOne?

Discussion in 'malware problems & news' started by Escalader, Aug 10, 2008.

Thread Status:
Not open for further replies.
  1. Escalader

    Escalader Registered Member

    Joined:
    Dec 12, 2005
    Posts:
    3,710
    Location:
    Land of the Mooses
    When I ran CCleaner version 618 with the registry scan feature this AM I got the following:

    Unused File Extension TacOnlyOne - HKCR\TacOnlyOne

    This has occurred several days in a row so it regenerates it self.

    SAS and Nod 32 report nothing.

    Has anybody here got a clue as to what this is?
     
  2. emperordarius

    emperordarius Registered Member

    Joined:
    Apr 27, 2008
    Posts:
    1,218
    Location:
    Who cares
    A google search reveals that it could be a rogue.

    See if there are the following processes and if yes terminate them:


    MWLauncher.exe
    Install1.exe

    Find and delete these files:

    MWLauncher.exe
    Install1.exe


    Search for and Remove the following MalWarrior registry keys:
    HKEY_CLASSES_ROOT\TacOnlyOne\MalWarrior
    HKEY_CURRENT_USER\Software\Adsl Software Limited\MalWarrior 2007
    HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TacOnlyOne\MalWarrior
     
  3. Escalader

    Escalader Registered Member

    Joined:
    Dec 12, 2005
    Posts:
    3,710
    Location:
    Land of the Mooses

    Thank you. I have searched for the exe's mentioned and they are not on my set up.

    A search with jv16 PowerTools 2008 for these keys and programs shows they are NOT present.

    I do have Lavasoft's digital lock SW and the registry search showed the entry relates to that SW. Lava must be using their encryption software.

    I will run full Nod32 and SAS scans to be "sure".
     
  4. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    25,669
    Location:
    UK
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.