<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>Antivirus software &#187; Hostile Code</title>
	<atom:link href="http://www.exterminatelab.com/virus/hostile-code/feed" rel="self" type="application/rss+xml" />
	<link>http://www.exterminatelab.com</link>
	<description>Free Scan Available</description>
	<pubDate>Fri, 27 Mar 2009 21:04:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>BAT.Noshare</title>
		<link>http://www.exterminatelab.com/remove-batnoshare-virus</link>
		<comments>http://www.exterminatelab.com/remove-batnoshare-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 20:12:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Backdoor]]></category>

		<category><![CDATA[DoS]]></category>

		<category><![CDATA[Hacker Tool]]></category>

		<category><![CDATA[Hostile Code]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://antivirus/?p=6376</guid>
		<description><![CDATA[Aliases of  BAT.Noshare
 
There are many names at BAT.Noshare. But most known of them are following: [Kaspersky]Worm.Win32.Muma,Worm.Win32.Randon.n;[Eset]Win32/Tkbot.A trojan;[Panda]Application/Serv-U-Based.A,Trojan Horse,Trojan Horse.LC,W32/Randon,Backdoor Program,Bck/Ratsou.B,HackTool/NTRootkit.C,W32/Randon.N;[Computer Associates]BAT.Noshare.AN,Bat/ServU-based!Trojan,BAT.Noshare.K,BAT.Noshare.B,Bat/Noshare.B!Trojan,BAT.Noshare.V,IRC.Flood,Bat/IRC.Flood.55NN2!Trojan,Bat/NoShare.S!Trojan,BAT.Noshare.AB;[Other]BAT/Noshare
Overview BAT.Noshare
BAT.Noshare the specific representative Trojan, Worm, Backdoor, Hacker Tool, DoS, Hostile Code.This virus spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  BAT.Noshare</h2>
<p> <!-- 1010024 -->
<p>There are many names at BAT.Noshare. But most known of them are following: [Kaspersky]Worm.Win32.Muma,Worm.Win32.Randon.n;[Eset]Win32/Tkbot.A trojan;[Panda]Application/Serv-U-Based.A,Trojan Horse,Trojan Horse.LC,W32/Randon,Backdoor Program,Bck/Ratsou.B,HackTool/NTRootkit.C,W32/Randon.N;[Computer Associates]BAT.Noshare.AN,Bat/ServU-based!Trojan,BAT.Noshare.K,BAT.Noshare.B,Bat/Noshare.B!Trojan,BAT.Noshare.V,IRC.Flood,Bat/IRC.Flood.55NN2!Trojan,Bat/NoShare.S!Trojan,BAT.Noshare.AB;[Other]BAT/Noshare</p>
<h2>Overview BAT.Noshare</h2>
<p><strong>BAT.Noshare</strong> the specific representative <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=20"  title="Remove Worm">Worm</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=12"  title="Remove Backdoor">Backdoor</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=17"  title="Remove Hacker Tool">Hacker Tool</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=4"  title="Remove DoS">DoS</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a>.This virus spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system BAT.Noshare generates in memory unique identifiers.Usually enough is updated and varies.BAT.Noshare is perilous and can lead to loss of the data and make your system instability.</p>
<h2>How to Delete BAT.Noshare from Your computer?</h2>
<p>In order to completely <b>delete BAT.Noshare</b> from your computer it is necessary to remove all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to delete BAT.Noshare independently manually.For adware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to delete BAT.Noshare Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to clear BAT.Noshare from the Windows Registry</a>.In sections Files  BAT.Noshare and Folders  BAT.Noshare complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  BAT.Noshare </p>
<h2 id="delete-virus-files">How to clear BAT.Noshare Files (.dll, .exe, .com, .sys, .bin etc.).</h2>
<p>All files and directories associated with BAT.Noshare are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To remove completely BAT.Noshare must clear all the files.</p>
<p>To delete files and folders associated with BAT.Noshare execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other program), removal is unrealizable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To clear locked file, select it and press the right button of the mouse, then select Send To-> delete on Next Reboot on the menu and after removal restart your computer.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for BAT.Noshare</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to delete BAT.Noshare from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, spyware, adware, and malware (including BAT.Noshare) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your pc.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively clear BAT.Noshare from your Windows registry, you must remove all the registry keys and values associated with BAT.Noshare.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The responsibility for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is necessary to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local computer.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to remove the BAT.Noshare registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To clear the keys, associated with BAT.Noshare, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To clear the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for BAT.Noshare</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>BAT.Noshare Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=20"  title="Remove Worm">Worm</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=12"  title="Remove Backdoor">Backdoor</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=17"  title="Remove Hacker Tool">Hacker Tool</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=4"  title="Remove DoS">DoS</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a></p>
<h2>How Did My PC Get Infected with BAT.Noshare?</h2>
<p>One of the most common questions found when cleaning BAT.Noshare is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get BAT.Noshare in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your computer clean and running securely:</p>
<p>If you receive an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be BAT.Noshare. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you acquire an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you have an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>BAT.Noshare</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get BAT.Noshare on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to porn sites.The fact is that a large amount of <b>adware</b> (including BAT.Noshare) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be BAT.Noshare too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and BAT.Noshare is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise adware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your pc.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from BAT.Noshare.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of BAT.Noshare</b></p>
<p>If you suspect or confirm that your computer is infected with BAT.Noshare, obtain the current antivirus software.The following are some primary indicators that a PC may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The computer stops responding, or it locks up frequently.</li>
<li>The computer crashes, and then it restarts every few minutes, it may be symptom of BAT.Noshare.</li>
<li>The PC restarts on its own.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be BAT.Noshare. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the PC even though you did not intentionally delete the program.</li>
</ul>
<p>Note These are common signs of infection by BAT.Noshare. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of BAT.Noshare in e-mail messages</b></p>
<p>When a PC virus infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The BAT.Noshare virus may reformat the hard disk.</li>
<li>This behavior will remove files and programs.</li>
<li>The BAT.Noshare may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The BAT.Noshare may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including BAT.Noshare) is a program that infects your computer and allows a hacker to run hidden tasks behind your back.</p>
<p>The BAT.Noshare can allow total remote access to your computer by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your pc.To delete the trojan and keep others out of your computer you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate BAT.Noshare</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>BAT.Noshare have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your computer screen flips upside down or invertss.</b></p>
<p>When you are infected with BAT.Noshare, hackers can make your PC screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your computer or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your computer browser goes to a strange or unknown web page by itself Trojans, including BAT.Noshare, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the BAT.Noshare allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your pc.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your PC plays recordings of things recorded in your PC room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by BAT.Noshare, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>BAT.Noshare can kill or startup programs on your computer.Many times your anti adware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your computer starts talking or conversing with you.</b></p>
<p>BAT.Noshare allow the hacker to type anything that he wants to say to you in a box and then make it appear that your PC is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your computer starts reading the contents of your computer clipboard.</b></p>
<p>The hacker can make your computer speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your computer and you are forced to chat with some stranger.</b></p>
<p>The BAT.Noshare will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your PC programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your pc.</b></p>
<p>Your PC generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your computer is IP scanning.</b></p>
<p>The hacker can use your PC to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your computer.</b></p>
<p>With the help of BAT.Noshare hackers can find personal information about you by reading documents on your computer such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your computer is infected with BAT.Noshare, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your PC room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your computer by itself.</b></p>
<p>Using BAT.Noshare the hacker can change the time and date on your computer.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your computer.</p>
<p><b>Your computer speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your PC shuts down by itself.The hacker can cause your PC to shutdown if you are infected by BAT.Noshare.</p>
<p><b>Your PC shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using BAT.Noshare can make your PC turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your PC you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What BAT.Noshare may do?</h2>
<p>Below are possibilities you may experience when you are infected with BAT.Noshare. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>BAT.Noshare may clear files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from BAT.Noshare and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your PC has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with spyware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every PC you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their adware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be BAT.Noshare, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your computer.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-batnoshare-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>Abraham</title>
		<link>http://www.exterminatelab.com/remove-abraham-virus</link>
		<comments>http://www.exterminatelab.com/remove-abraham-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 18:56:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hostile Code]]></category>

		<guid isPermaLink="false">http://antivirus/?p=2891</guid>
		<description><![CDATA[Overview Abraham
Abraham the typical sample Hostile Code.This virus extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Abraham initiates in memory unique identifiers.Usually enough is updated and varies.Abraham is parlous and can lead to loss of the data and make [...]]]></description>
			<content:encoded><![CDATA[<h2>Overview Abraham</h2>
<p><strong>Abraham</strong> the typical sample <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a>.This virus extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Abraham initiates in memory unique identifiers.Usually enough is updated and varies.Abraham is parlous and can lead to loss of the data and make your system infirmity.</p>
<h2>How to Remove Abraham from Your computer?</h2>
<p>In order to completely <b>clear Abraham</b> from your computer it is necessary to clear all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to remove Abraham independently manually.For virus removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to remove Abraham Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to delete Abraham from the Windows Registry</a>.In sections Files  Abraham and Folders  Abraham complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  Abraham </p>
<h2 id="delete-virus-files">How to delete Abraham Files (.dll, .bin .sys, .exe, .com, etc.).</h2>
<p>All files and directories associated with Abraham are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To clear completely Abraham must clear all the files.</p>
<p>To remove files and folders associated with Abraham execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other program), removal is impossible (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To remove locked file, select it and press the right button of the mouse, then select Send To-> remove on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for Abraham</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to delete Abraham from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, malware, spyware, and adware (including Abraham) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively delete Abraham from your Windows registry, you must clear all the registry keys and values associated with Abraham.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The amenability for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is necessary to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to clear the Abraham registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To clear the keys, associated with Abraham, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To clear the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for Abraham</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>Abraham Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a></p>
<h2>How Did My PC Get Infected with Abraham?</h2>
<p>One of the most common questions found when cleaning Abraham is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your pc&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get Abraham in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your PC clean and running securely:</p>
<p>If you get an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be Abraham. Opening attachments from people you do not know is a very common method for viruses or worms to infect your pc.</p>
<p>If you receive an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you have an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>Abraham</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get Abraham on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to porn sites.The fact is that a large amount of <b>spyware</b> (including Abraham) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be Abraham too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the evident copyright issues, the downloads from these sites are typically overrun with infections and Abraham is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your pc.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from Abraham.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of Abraham</b></p>
<p>If you suspect or confirm that your PC is infected with Abraham, obtain the current antivirus software.The following are some primary indicators that a computer may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The PC stops responding, or it locks up frequently.</li>
<li>The computer crashes, and then it restarts every few minutes, it may be symptom of Abraham.</li>
<li>The computer restarts on its own.</li>
<li>Additionally, the computer does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be Abraham. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the computer even though you did not intentionally delete the program.</li>
</ul>
<p>Note These are common signs of infection by Abraham. However, these signs may also be caused by hardware or software problems that have nothing to do with a computer virus.</p>
<p><b>Symptoms of Abraham in e-mail messages</b></p>
<p>When a computer spyware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The Abraham adware may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The Abraham may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the pc.</li>
<li>The Abraham may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<h2>What Abraham may do?</h2>
<p>Below are possibilities you may experience when you are infected with Abraham. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>Abraham may clear files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from Abraham and this not happening again it is important that take proper care and precautions when using your computer.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with spyware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every PC you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their virus lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be Abraham, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your pc.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-abraham-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>AxNTService</title>
		<link>http://www.exterminatelab.com/remove-axntservice-virus</link>
		<comments>http://www.exterminatelab.com/remove-axntservice-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 18:53:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hostile Code]]></category>

		<guid isPermaLink="false">http://antivirus/?p=2689</guid>
		<description><![CDATA[Overview AxNTService
AxNTService the classic representative Hostile Code.This malware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system AxNTService generates in memory unique identifiers.Usually enough is updated and varies.AxNTService is parlous and can lead to loss of the data and make [...]]]></description>
			<content:encoded><![CDATA[<h2>Overview AxNTService</h2>
<p><strong>AxNTService</strong> the classic representative <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a>.This malware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system AxNTService generates in memory unique identifiers.Usually enough is updated and varies.AxNTService is parlous and can lead to loss of the data and make your system unsteadiness.</p>
<h2>How to Clear AxNTService from Your PC?</h2>
<p>In order to completely <b>delete AxNTService</b> from your PC it is necessary to remove all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to delete AxNTService independently manually.For malware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear AxNTService Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to delete AxNTService from the Windows Registry</a>.In sections Files  AxNTService and Folders  AxNTService complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  AxNTService </p>
<h2 id="delete-virus-files">How to clear AxNTService Files (.com, .exe, .dll, .sys, .bin etc.).</h2>
<p>All files and directories associated with AxNTService are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To clear completely AxNTService must delete all the files.</p>
<p>To remove files and folders associated with AxNTService execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is impossible (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To remove locked file, select it and press the right button of the mouse, then select Send To-> clear on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for AxNTService</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to remove AxNTService from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, spyware, adware, and malware (including AxNTService) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your pc.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively delete AxNTService from your Windows registry, you must remove all the registry keys and values associated with AxNTService.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The amenability for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is necessary to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to delete the AxNTService registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with AxNTService, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To clear the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for AxNTService</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>AxNTService Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a></p>
<h2>How Did My PC Get Infected with AxNTService?</h2>
<p>One of the most common questions found when cleaning AxNTService is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get AxNTService in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your computer clean and running securely:</p>
<p>If you have an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be AxNTService. Opening attachments from people you do not know is a very common method for viruses or worms to infect your pc.</p>
<p>If you have an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you acquire an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>AxNTService</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get AxNTService on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>adware</b> (including AxNTService) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be AxNTService too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and AxNTService is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise adware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from AxNTService.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of AxNTService</b></p>
<p>If you suspect or confirm that your computer is infected with AxNTService, obtain the current antivirus software.The following are some primary indicators that a PC may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The PC stops responding, or it locks up frequently.</li>
<li>The computer crashes, and then it restarts every few minutes, it may be symptom of AxNTService.</li>
<li>Additionally, the computer does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be AxNTService. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the computer even though you did not intentionally clear the program.</li>
</ul>
<p>Note These are common signs of infection by AxNTService. However, these signs may also be caused by hardware or software problems that have nothing to do with a computer virus.</p>
<p><b>Symptoms of AxNTService in e-mail messages</b></p>
<p>When a PC spyware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The AxNTService malware may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The AxNTService may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the pc.</li>
<li>The AxNTService may reduce security. </li>
<li>This could enable intruders to access remotely the computer or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<h2>What AxNTService may do?</h2>
<p>Below are possibilities you may experience when you are infected with AxNTService. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>AxNTService may clear files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from AxNTService and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your PC safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your PC has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with spyware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their malware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be AxNTService, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your computer.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-axntservice-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>AxNTRegSecurity</title>
		<link>http://www.exterminatelab.com/remove-axntregsecurity-virus</link>
		<comments>http://www.exterminatelab.com/remove-axntregsecurity-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 18:53:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hostile Code]]></category>

		<guid isPermaLink="false">http://antivirus/?p=2690</guid>
		<description><![CDATA[Overview AxNTRegSecurity
AxNTRegSecurity the typical representative Hostile Code.This adware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system AxNTRegSecurity makes in memory unique identifiers.Usually enough is updated and varies.AxNTRegSecurity is parlous and can lead to loss of the data and make [...]]]></description>
			<content:encoded><![CDATA[<h2>Overview AxNTRegSecurity</h2>
<p><strong>AxNTRegSecurity</strong> the typical representative <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a>.This adware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system AxNTRegSecurity makes in memory unique identifiers.Usually enough is updated and varies.AxNTRegSecurity is parlous and can lead to loss of the data and make your system instability.</p>
<h2>How to Remove AxNTRegSecurity from Your computer?</h2>
<p>In order to completely <b>remove AxNTRegSecurity</b> from your computer it is necessary to delete all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to delete AxNTRegSecurity independently manually.For spyware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to delete AxNTRegSecurity Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to delete AxNTRegSecurity from the Windows Registry</a>.In sections Files  AxNTRegSecurity and Folders  AxNTRegSecurity complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  AxNTRegSecurity </p>
<h2 id="delete-virus-files">How to clear AxNTRegSecurity Files (.dll, .com, .sys, .exe, .bin etc.).</h2>
<p>All files and directories associated with AxNTRegSecurity are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To delete completely AxNTRegSecurity must remove all the files.</p>
<p>To remove files and folders associated with AxNTRegSecurity execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is impracticable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To clear locked file, select it and press the right button of the mouse, then select Send To-> remove on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for AxNTRegSecurity</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to clear AxNTRegSecurity from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, malware, adware, and spyware (including AxNTRegSecurity) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your pc.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively clear AxNTRegSecurity from your Windows registry, you must delete all the registry keys and values associated with AxNTRegSecurity.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The amenability for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is necessary to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to clear the AxNTRegSecurity registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with AxNTRegSecurity, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To delete the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for AxNTRegSecurity</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>AxNTRegSecurity Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a></p>
<h2>How Did My PC Get Infected with AxNTRegSecurity?</h2>
<p>One of the most common questions found when cleaning AxNTRegSecurity is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get AxNTRegSecurity in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your PC clean and running securely:</p>
<p>If you have an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be AxNTRegSecurity. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you acquire an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you receive an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>AxNTRegSecurity</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get AxNTRegSecurity on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>malware</b> (including AxNTRegSecurity) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be AxNTRegSecurity too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and AxNTRegSecurity is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from AxNTRegSecurity.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of AxNTRegSecurity</b></p>
<p>If you suspect or confirm that your computer is infected with AxNTRegSecurity, obtain the current antivirus software.The following are some primary indicators that a computer may be infected:
<ul>
<li>The PC runs slower than usual.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of AxNTRegSecurity.</li>
<li>The PC restarts on its own.</li>
<li>Additionally, the computer does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be AxNTRegSecurity. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the computer even though you did not intentionally delete the program.</li>
</ul>
<p>Note These are common signs of infection by AxNTRegSecurity. However, these signs may also be caused by hardware or software problems that have nothing to do with a computer virus.</p>
<p><b>Symptoms of AxNTRegSecurity in e-mail messages</b></p>
<p>When a computer virus infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The AxNTRegSecurity spyware may reformat the hard disk.</li>
<li>This behavior will remove files and programs.</li>
<li>The AxNTRegSecurity may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The AxNTRegSecurity may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<h2>What AxNTRegSecurity may do?</h2>
<p>Below are possibilities you may experience when you are infected with AxNTRegSecurity. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>AxNTRegSecurity may remove files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from AxNTRegSecurity and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with spyware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their malware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be AxNTRegSecurity, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your computer.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-axntregsecurity-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>AxNTFileSecurity</title>
		<link>http://www.exterminatelab.com/remove-axntfilesecurity-virus</link>
		<comments>http://www.exterminatelab.com/remove-axntfilesecurity-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 18:53:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hostile Code]]></category>

		<guid isPermaLink="false">http://antivirus/?p=2688</guid>
		<description><![CDATA[Overview AxNTFileSecurity
AxNTFileSecurity the typical representative Hostile Code.This virus extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system AxNTFileSecurity generates in memory unique identifiers.Usually enough is updated and varies.AxNTFileSecurity is dangerous and can lead to loss of the data and make [...]]]></description>
			<content:encoded><![CDATA[<h2>Overview AxNTFileSecurity</h2>
<p><strong>AxNTFileSecurity</strong> the typical representative <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a>.This virus extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system AxNTFileSecurity generates in memory unique identifiers.Usually enough is updated and varies.AxNTFileSecurity is dangerous and can lead to loss of the data and make your system unsteadiness.</p>
<h2>How to Delete AxNTFileSecurity from Your computer?</h2>
<p>In order to completely <b>delete AxNTFileSecurity</b> from your computer it is necessary to delete all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to clear AxNTFileSecurity independently manually.For virus removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to delete AxNTFileSecurity Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to remove AxNTFileSecurity from the Windows Registry</a>.In sections Files  AxNTFileSecurity and Folders  AxNTFileSecurity complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  AxNTFileSecurity </p>
<h2 id="delete-virus-files">How to delete AxNTFileSecurity Files (.dll, .exe, .com, .sys, .bin etc.).</h2>
<p>All files and directories associated with AxNTFileSecurity are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To delete completely AxNTFileSecurity must remove all the files.</p>
<p>To remove files and folders associated with AxNTFileSecurity execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other program), removal is impossible (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To delete locked file, select it and press the right button of the mouse, then select Send To-> remove on Next Reboot on the menu and after removal restart your computer.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for AxNTFileSecurity</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to delete AxNTFileSecurity from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, adware, spyware, and malware (including AxNTFileSecurity) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively remove AxNTFileSecurity from your Windows registry, you must remove all the registry keys and values associated with AxNTFileSecurity.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The responsibility for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is needful to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local computer.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to delete the AxNTFileSecurity registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with AxNTFileSecurity, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To clear the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for AxNTFileSecurity</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>AxNTFileSecurity Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a></p>
<h2>How Did My PC Get Infected with AxNTFileSecurity?</h2>
<p>One of the most common questions found when cleaning AxNTFileSecurity is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your pc&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get AxNTFileSecurity in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your computer clean and running securely:</p>
<p>If you acquire an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be AxNTFileSecurity. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you have an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual PC user, you will almost never receive a valid attachment of this type.</p>
<p>If you have an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>AxNTFileSecurity</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get AxNTFileSecurity on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to porn sites.The fact is that a large amount of <b>spyware</b> (including AxNTFileSecurity) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be AxNTFileSecurity too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and AxNTFileSecurity is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise adware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your pc.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from AxNTFileSecurity.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of AxNTFileSecurity</b></p>
<p>If you suspect or confirm that your computer is infected with AxNTFileSecurity, obtain the current antivirus software.The following are some primary indicators that a PC may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The PC stops responding, or it locks up frequently.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of AxNTFileSecurity.</li>
<li>The computer restarts on its own.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be AxNTFileSecurity. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the PC even though you did not intentionally clear the program.</li>
</ul>
<p>Note These are common signs of infection by AxNTFileSecurity. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of AxNTFileSecurity in e-mail messages</b></p>
<p>When a PC spyware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The AxNTFileSecurity spyware may reformat the hard disk.</li>
<li>This behavior will remove files and programs.</li>
<li>The AxNTFileSecurity may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The AxNTFileSecurity may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<h2>What AxNTFileSecurity may do?</h2>
<p>Below are possibilities you may experience when you are infected with AxNTFileSecurity. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>AxNTFileSecurity may delete files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from AxNTFileSecurity and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your PC safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with malware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every PC you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their virus lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be AxNTFileSecurity, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your computer.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-axntfilesecurity-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>Hostile.Java</title>
		<link>http://www.exterminatelab.com/remove-hostilejava-virus</link>
		<comments>http://www.exterminatelab.com/remove-hostilejava-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 18:52:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hostile Code]]></category>

		<guid isPermaLink="false">http://antivirus/?p=2565</guid>
		<description><![CDATA[Overview Hostile.Java
Hostile.Java the classical sample Hostile Code.This malware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Hostile.Java makes in memory unique identifiers.Usually enough is updated and varies.Hostile.Java is unsafe and can lead to loss of the data and make [...]]]></description>
			<content:encoded><![CDATA[<h2>Overview Hostile.Java</h2>
<p><strong>Hostile.Java</strong> the classical sample <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a>.This malware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Hostile.Java makes in memory unique identifiers.Usually enough is updated and varies.Hostile.Java is unsafe and can lead to loss of the data and make your system instability.</p>
<h2>How to Remove Hostile.Java from Your PC?</h2>
<p>In order to completely <b>clear Hostile.Java</b> from your computer it is necessary to delete all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to clear Hostile.Java independently manually.For malware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear Hostile.Java Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to delete Hostile.Java from the Windows Registry</a>.In sections Files  Hostile.Java and Folders  Hostile.Java complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  Hostile.Java </p>
<h2 id="delete-virus-files">How to remove Hostile.Java Files (.dll, .bin .sys, .exe, .com, etc.).</h2>
<p>All files and directories associated with Hostile.Java are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To delete completely Hostile.Java must clear all the files.</p>
<p>To delete files and folders associated with Hostile.Java execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is impossible (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To delete locked file, select it and press the right button of the mouse, then select Send To-> remove on Next Reboot on the menu and after removal restart your computer.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for Hostile.Java</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to remove Hostile.Java from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, adware, spyware, and malware (including Hostile.Java) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your pc.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively clear Hostile.Java from your Windows registry, you must remove all the registry keys and values associated with Hostile.Java.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The responsibility for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is necessary to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to delete the Hostile.Java registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with Hostile.Java, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To clear the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for Hostile.Java</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>Hostile.Java Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a></p>
<h2>How Did My PC Get Infected with Hostile.Java?</h2>
<p>One of the most common questions found when cleaning Hostile.Java is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your pc&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get Hostile.Java in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your PC clean and running securely:</p>
<p>If you receive an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be Hostile.Java. Opening attachments from people you do not know is a very common method for viruses or worms to infect your pc.</p>
<p>If you receive an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you acquire an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>Hostile.Java</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get Hostile.Java on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to porn sites.The fact is that a large amount of <b>adware</b> (including Hostile.Java) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be Hostile.Java too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and Hostile.Java is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your PC from Hostile.Java.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of Hostile.Java</b></p>
<p>If you suspect or confirm that your computer is infected with Hostile.Java, obtain the current antivirus software.The following are some primary indicators that a computer may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The PC stops responding, or it locks up frequently.</li>
<li>The computer crashes, and then it restarts every few minutes, it may be symptom of Hostile.Java.</li>
<li>The PC restarts on its own.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be Hostile.Java. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the PC even though you did not intentionally remove the program.</li>
</ul>
<p>Note These are common signs of infection by Hostile.Java. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of Hostile.Java in e-mail messages</b></p>
<p>When a PC malware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The Hostile.Java spyware may reformat the hard disk.</li>
<li>This behavior will delete files and programs.</li>
<li>The Hostile.Java may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The Hostile.Java may reduce security. </li>
<li>This could enable intruders to access remotely the computer or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<h2>What Hostile.Java may do?</h2>
<p>Below are possibilities you may experience when you are infected with Hostile.Java. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>Hostile.Java may remove files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from Hostile.Java and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with malware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their adware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be Hostile.Java, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your pc.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-hostilejava-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>ActiveX.Exploder</title>
		<link>http://www.exterminatelab.com/remove-activexexploder-virus</link>
		<comments>http://www.exterminatelab.com/remove-activexexploder-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 18:48:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hostile Code]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=2230</guid>
		<description><![CDATA[Aliases of  ActiveX.Exploder
 
There are many names at ActiveX.Exploder. But most known of them are following: [Kaspersky]Trojan.ActiveX.Exploder;[Panda]AX/Exploder;[Computer Associates]ActiveX/Exploder
Overview ActiveX.Exploder
ActiveX.Exploder the normal sample Trojan, Hostile Code.This adware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system ActiveX.Exploder makes in memory [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  ActiveX.Exploder</h2>
<p> <!-- 1004864 -->
<p>There are many names at ActiveX.Exploder. But most known of them are following: [Kaspersky]Trojan.ActiveX.Exploder;[Panda]AX/Exploder;[Computer Associates]ActiveX/Exploder</p>
<h2>Overview ActiveX.Exploder</h2>
<p><strong>ActiveX.Exploder</strong> the normal sample <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a>.This adware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system ActiveX.Exploder makes in memory unique identifiers.Often enough is updated and varies.ActiveX.Exploder is dangerous and can lead to loss of the data and make your system instability.</p>
<h2>How to Clear ActiveX.Exploder from Your PC?</h2>
<p>In order to completely <b>clear ActiveX.Exploder</b> from your computer it is necessary to remove all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to remove ActiveX.Exploder independently manually.For spyware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear ActiveX.Exploder Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to clear ActiveX.Exploder from the Windows Registry</a>.In sections Files  ActiveX.Exploder and Folders  ActiveX.Exploder complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  ActiveX.Exploder </p>
<h2 id="delete-virus-files">How to clear ActiveX.Exploder Files (.bin .exe, .dll, .com, .sys, etc.).</h2>
<p>All files and directories associated with ActiveX.Exploder are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To clear completely ActiveX.Exploder must delete all the files.</p>
<p>To clear files and folders associated with ActiveX.Exploder execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is impracticable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To clear locked file, select it and press the right button of the mouse, then select Send To-> delete on Next Reboot on the menu and after removal restart your computer.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for ActiveX.Exploder</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to delete ActiveX.Exploder from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, spyware, adware, and malware (including ActiveX.Exploder) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your pc.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively delete ActiveX.Exploder from your Windows registry, you must clear all the registry keys and values associated with ActiveX.Exploder.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The amenability for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is requisite to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local computer.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to delete the ActiveX.Exploder registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To remove the keys, associated with ActiveX.Exploder, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To clear the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for ActiveX.Exploder</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>ActiveX.Exploder Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a></p>
<h2>How Did My PC Get Infected with ActiveX.Exploder?</h2>
<p>One of the most common questions found when cleaning ActiveX.Exploder is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get ActiveX.Exploder in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your computer clean and running securely:</p>
<p>If you acquire an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be ActiveX.Exploder. Opening attachments from people you do not know is a very common method for viruses or worms to infect your pc.</p>
<p>If you have an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual PC user, you will almost never receive a valid attachment of this type.</p>
<p>If you have an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>ActiveX.Exploder</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get ActiveX.Exploder on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>adware</b> (including ActiveX.Exploder) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be ActiveX.Exploder too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and ActiveX.Exploder is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise adware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your pc.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your PC from ActiveX.Exploder.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of ActiveX.Exploder</b></p>
<p>If you suspect or confirm that your PC is infected with ActiveX.Exploder, obtain the current antivirus software.The following are some primary indicators that a computer may be infected:
<ul>
<li>The PC runs slower than usual.</li>
<li>The PC stops responding, or it locks up frequently.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of ActiveX.Exploder.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be ActiveX.Exploder. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the PC even though you did not intentionally delete the program.</li>
</ul>
<p>Note These are common signs of infection by ActiveX.Exploder. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of ActiveX.Exploder in e-mail messages</b></p>
<p>When a computer spyware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The ActiveX.Exploder virus may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The ActiveX.Exploder may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the pc.</li>
<li>The ActiveX.Exploder may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including ActiveX.Exploder) is a program that infects your PC and allows a hacker to run hidden tasks behind your back.</p>
<p>The ActiveX.Exploder can allow total remote access to your PC by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your pc.To remove the trojan and keep others out of your PC you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate ActiveX.Exploder</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>ActiveX.Exploder have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your computer screen flips upside down or invertss.</b></p>
<p>When you are infected with ActiveX.Exploder, hackers can make your PC screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your PC or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your computer browser goes to a strange or unknown web page by itself Trojans, including ActiveX.Exploder, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the ActiveX.Exploder allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your computer.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your computer plays recordings of things recorded in your computer room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by ActiveX.Exploder, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>ActiveX.Exploder can kill or startup programs on your pc.Many times your anti adware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your computer starts talking or conversing with you.</b></p>
<p>ActiveX.Exploder allow the hacker to type anything that he wants to say to you in a box and then make it appear that your PC is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your PC starts reading the contents of your PC clipboard.</b></p>
<p>The hacker can make your computer speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your PC and you are forced to chat with some stranger.</b></p>
<p>The ActiveX.Exploder will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your PC programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your pc.</b></p>
<p>Your PC generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your computer is IP scanning.</b></p>
<p>The hacker can use your computer to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your pc.</b></p>
<p>With the help of ActiveX.Exploder hackers can find personal information about you by reading documents on your PC such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your PC is infected with ActiveX.Exploder, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your PC room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your PC by itself.</b></p>
<p>Using ActiveX.Exploder the hacker can change the time and date on your computer.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your pc.</p>
<p><b>Your PC speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your computer shuts down by itself.The hacker can cause your PC to shutdown if you are infected by ActiveX.Exploder.</p>
<p><b>Your computer shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using ActiveX.Exploder can make your computer turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your PC you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What ActiveX.Exploder may do?</h2>
<p>Below are possibilities you may experience when you are infected with ActiveX.Exploder. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>ActiveX.Exploder may clear files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from ActiveX.Exploder and this not happening again it is important that take proper care and precautions when using your computer.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with malware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their malware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be ActiveX.Exploder, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your pc.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-activexexploder-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>Queen.Hitman.Virus</title>
		<link>http://www.exterminatelab.com/remove-queenhitmanvirus-virus</link>
		<comments>http://www.exterminatelab.com/remove-queenhitmanvirus-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 18:45:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hostile Code]]></category>

		<guid isPermaLink="false">http://antivirus/?p=1875</guid>
		<description><![CDATA[Overview Queen.Hitman.Virus
Queen.Hitman.Virus the specific sample Hostile Code.This virus spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Queen.Hitman.Virus creates in memory unique identifiers.Usually enough is updated and varies.Queen.Hitman.Virus is shifty and can lead to loss of the data and make [...]]]></description>
			<content:encoded><![CDATA[<h2>Overview Queen.Hitman.Virus</h2>
<p><strong>Queen.Hitman.Virus</strong> the specific sample <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a>.This virus spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Queen.Hitman.Virus creates in memory unique identifiers.Usually enough is updated and varies.Queen.Hitman.Virus is shifty and can lead to loss of the data and make your system unsteadiness.</p>
<h2>How to Delete Queen.Hitman.Virus from Your PC?</h2>
<p>In order to completely <b>clear Queen.Hitman.Virus</b> from your PC it is necessary to delete all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to clear Queen.Hitman.Virus independently manually.For malware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear Queen.Hitman.Virus Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to delete Queen.Hitman.Virus from the Windows Registry</a>.In sections Files  Queen.Hitman.Virus and Folders  Queen.Hitman.Virus complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  Queen.Hitman.Virus </p>
<h2 id="delete-virus-files">How to clear Queen.Hitman.Virus Files (.sys, .exe, .dll, .com, .bin etc.).</h2>
<p>All files and directories associated with Queen.Hitman.Virus are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To clear completely Queen.Hitman.Virus must clear all the files.</p>
<p>To remove files and folders associated with Queen.Hitman.Virus execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other program), removal is impracticable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To remove locked file, select it and press the right button of the mouse, then select Send To-> clear on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for Queen.Hitman.Virus</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to clear Queen.Hitman.Virus from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, malware, adware, and spyware (including Queen.Hitman.Virus) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively delete Queen.Hitman.Virus from your Windows registry, you must clear all the registry keys and values associated with Queen.Hitman.Virus.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The responsibility for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is necessary to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local computer.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to delete the Queen.Hitman.Virus registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with Queen.Hitman.Virus, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To delete the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for Queen.Hitman.Virus</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>Queen.Hitman.Virus Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a></p>
<h2>How Did My PC Get Infected with Queen.Hitman.Virus?</h2>
<p>One of the most common questions found when cleaning Queen.Hitman.Virus is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get Queen.Hitman.Virus in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your PC clean and running securely:</p>
<p>If you get an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be Queen.Hitman.Virus. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you have an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you get an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>Queen.Hitman.Virus</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get Queen.Hitman.Virus on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to porn sites.The fact is that a large amount of <b>spyware</b> (including Queen.Hitman.Virus) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be Queen.Hitman.Virus too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the evident copyright issues, the downloads from these sites are typically overrun with infections and Queen.Hitman.Virus is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from Queen.Hitman.Virus.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of Queen.Hitman.Virus</b></p>
<p>If you suspect or confirm that your computer is infected with Queen.Hitman.Virus, obtain the current antivirus software.The following are some primary indicators that a PC may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The computer stops responding, or it locks up frequently.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of Queen.Hitman.Virus.</li>
<li>The computer restarts on its own.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be Queen.Hitman.Virus. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the computer even though you did not intentionally clear the program.</li>
</ul>
<p>Note These are common signs of infection by Queen.Hitman.Virus. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of Queen.Hitman.Virus in e-mail messages</b></p>
<p>When a computer spyware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The Queen.Hitman.Virus spyware may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The Queen.Hitman.Virus may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The Queen.Hitman.Virus may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<h2>What Queen.Hitman.Virus may do?</h2>
<p>Below are possibilities you may experience when you are infected with Queen.Hitman.Virus. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>Queen.Hitman.Virus may delete files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from Queen.Hitman.Virus and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your PC safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with spyware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every PC you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their adware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be Queen.Hitman.Virus, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your pc.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-queenhitmanvirus-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>Nasty.JavaScript.Tricks</title>
		<link>http://www.exterminatelab.com/remove-nastyjavascripttricks-virus</link>
		<comments>http://www.exterminatelab.com/remove-nastyjavascripttricks-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 18:45:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hostile Code]]></category>

		<guid isPermaLink="false">http://antivirus/?p=1869</guid>
		<description><![CDATA[Overview Nasty.JavaScript.Tricks
Nasty.JavaScript.Tricks the specific sample Hostile Code.This malware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Nasty.JavaScript.Tricks sets in memory unique identifiers.Often enough is updated and varies.Nasty.JavaScript.Tricks is unsafe and can lead to loss of the data and make [...]]]></description>
			<content:encoded><![CDATA[<h2>Overview Nasty.JavaScript.Tricks</h2>
<p><strong>Nasty.JavaScript.Tricks</strong> the specific sample <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a>.This malware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Nasty.JavaScript.Tricks sets in memory unique identifiers.Often enough is updated and varies.Nasty.JavaScript.Tricks is unsafe and can lead to loss of the data and make your system unsteadiness.</p>
<h2>How to Delete Nasty.JavaScript.Tricks from Your computer?</h2>
<p>In order to completely <b>delete Nasty.JavaScript.Tricks</b> from your computer it is necessary to clear all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to delete Nasty.JavaScript.Tricks independently manually.For adware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to remove Nasty.JavaScript.Tricks Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to delete Nasty.JavaScript.Tricks from the Windows Registry</a>.In sections Files  Nasty.JavaScript.Tricks and Folders  Nasty.JavaScript.Tricks complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  Nasty.JavaScript.Tricks </p>
<h2 id="delete-virus-files">How to delete Nasty.JavaScript.Tricks Files (.dll, .exe, .com, .sys, .bin etc.).</h2>
<p>All files and directories associated with Nasty.JavaScript.Tricks are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To delete completely Nasty.JavaScript.Tricks must clear all the files.</p>
<p>To delete files and folders associated with Nasty.JavaScript.Tricks execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is impracticable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To delete locked file, select it and press the right button of the mouse, then select Send To-> clear on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for Nasty.JavaScript.Tricks</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to delete Nasty.JavaScript.Tricks from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, adware, malware, and spyware (including Nasty.JavaScript.Tricks) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your pc.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively clear Nasty.JavaScript.Tricks from your Windows registry, you must remove all the registry keys and values associated with Nasty.JavaScript.Tricks.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The amenability for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is indispensable to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to remove the Nasty.JavaScript.Tricks registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with Nasty.JavaScript.Tricks, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To remove the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for Nasty.JavaScript.Tricks</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>Nasty.JavaScript.Tricks Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a></p>
<h2>How Did My PC Get Infected with Nasty.JavaScript.Tricks?</h2>
<p>One of the most common questions found when cleaning Nasty.JavaScript.Tricks is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your pc&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get Nasty.JavaScript.Tricks in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your PC clean and running securely:</p>
<p>If you get an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be Nasty.JavaScript.Tricks. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you get an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual PC user, you will almost never receive a valid attachment of this type.</p>
<p>If you receive an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>Nasty.JavaScript.Tricks</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get Nasty.JavaScript.Tricks on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>spyware</b> (including Nasty.JavaScript.Tricks) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be Nasty.JavaScript.Tricks too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the evident copyright issues, the downloads from these sites are typically overrun with infections and Nasty.JavaScript.Tricks is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise spyware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your pc.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from Nasty.JavaScript.Tricks.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of Nasty.JavaScript.Tricks</b></p>
<p>If you suspect or confirm that your computer is infected with Nasty.JavaScript.Tricks, obtain the current antivirus software.The following are some primary indicators that a computer may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of Nasty.JavaScript.Tricks.</li>
<li>The computer restarts on its own.</li>
<li>Additionally, the computer does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be Nasty.JavaScript.Tricks. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the computer even though you did not intentionally clear the program.</li>
</ul>
<p>Note These are common signs of infection by Nasty.JavaScript.Tricks. However, these signs may also be caused by hardware or software problems that have nothing to do with a computer virus.</p>
<p><b>Symptoms of Nasty.JavaScript.Tricks in e-mail messages</b></p>
<p>When a computer spyware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The Nasty.JavaScript.Tricks spyware may reformat the hard disk.</li>
<li>This behavior will delete files and programs.</li>
<li>The Nasty.JavaScript.Tricks may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The Nasty.JavaScript.Tricks may reduce security. </li>
<li>This could enable intruders to access remotely the computer or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<h2>What Nasty.JavaScript.Tricks may do?</h2>
<p>Below are possibilities you may experience when you are infected with Nasty.JavaScript.Tricks. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>Nasty.JavaScript.Tricks may remove files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from Nasty.JavaScript.Tricks and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your PC safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your PC has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with adware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every PC you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their spyware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be Nasty.JavaScript.Tricks, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your pc.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-nastyjavascripttricks-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>Appkiller.src</title>
		<link>http://www.exterminatelab.com/remove-appkillersrc-virus</link>
		<comments>http://www.exterminatelab.com/remove-appkillersrc-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 18:44:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hostile Code]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=1788</guid>
		<description><![CDATA[Aliases of  Appkiller.src
 
There are many names at Appkiller.src. But most known of them are following: [Kaspersky]Trojan.Java.AppletKiller;[McAfee]Appkiller.src;[F-Prot]destructive program;[Panda]JV/AppletKiller
Overview Appkiller.src
Appkiller.src the classical representative Trojan, Hostile Code.This adware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Appkiller.src makes in memory [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  Appkiller.src</h2>
<p> <!-- 1004298 -->
<p>There are many names at Appkiller.src. But most known of them are following: [Kaspersky]Trojan.Java.AppletKiller;[McAfee]Appkiller.src;[F-Prot]destructive program;[Panda]JV/AppletKiller</p>
<h2>Overview Appkiller.src</h2>
<p><strong>Appkiller.src</strong> the classical representative <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a>.This adware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Appkiller.src makes in memory unique identifiers.Often enough is updated and varies.Appkiller.src is parlous and can lead to loss of the data and make your system infirmity.</p>
<h2>How to Remove Appkiller.src from Your computer?</h2>
<p>In order to completely <b>clear Appkiller.src</b> from your PC it is necessary to remove all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to remove Appkiller.src independently manually.For spyware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear Appkiller.src Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to clear Appkiller.src from the Windows Registry</a>.In sections Files  Appkiller.src and Folders  Appkiller.src complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  Appkiller.src </p>
<h2 id="delete-virus-files">How to clear Appkiller.src Files (.sys, .exe, .dll, .com, .bin etc.).</h2>
<p>All files and directories associated with Appkiller.src are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To remove completely Appkiller.src must clear all the files.</p>
<p>To delete files and folders associated with Appkiller.src execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other program), removal is impracticable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To clear locked file, select it and press the right button of the mouse, then select Send To-> remove on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for Appkiller.src</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to delete Appkiller.src from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, malware, adware, and spyware (including Appkiller.src) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively clear Appkiller.src from your Windows registry, you must remove all the registry keys and values associated with Appkiller.src.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The amenability for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is needful to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to delete the Appkiller.src registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To remove the keys, associated with Appkiller.src, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To delete the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for Appkiller.src</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>Appkiller.src Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=15"  title="Remove Hostile Code">Hostile Code</a></p>
<h2>How Did My PC Get Infected with Appkiller.src?</h2>
<p>One of the most common questions found when cleaning Appkiller.src is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your pc&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get Appkiller.src in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your computer clean and running securely:</p>
<p>If you receive an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be Appkiller.src. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you get an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you have an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>Appkiller.src</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get Appkiller.src on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to porn sites.The fact is that a large amount of <b>spyware</b> (including Appkiller.src) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be Appkiller.src too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and Appkiller.src is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your pc.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your PC from Appkiller.src.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of Appkiller.src</b></p>
<p>If you suspect or confirm that your PC is infected with Appkiller.src, obtain the current antivirus software.The following are some primary indicators that a computer may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The PC stops responding, or it locks up frequently.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of Appkiller.src.</li>
<li>The computer restarts on its own.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be Appkiller.src. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the computer even though you did not intentionally clear the program.</li>
</ul>
<p>Note These are common signs of infection by Appkiller.src. However, these signs may also be caused by hardware or software problems that have nothing to do with a computer virus.</p>
<p><b>Symptoms of Appkiller.src in e-mail messages</b></p>
<p>When a PC spyware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The Appkiller.src adware may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The Appkiller.src may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the pc.</li>
<li>The Appkiller.src may reduce security. </li>
<li>This could enable intruders to access remotely the computer or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including Appkiller.src) is a program that infects your computer and allows a hacker to run hidden tasks behind your back.</p>
<p>The Appkiller.src can allow total remote access to your computer by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your pc.To remove the trojan and keep others out of your PC you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate Appkiller.src</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>Appkiller.src have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your computer screen flips upside down or invertss.</b></p>
<p>When you are infected with Appkiller.src, hackers can make your computer screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your PC or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your PC browser goes to a strange or unknown web page by itself <b>Trojans</b>, including Appkiller.src, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the Appkiller.src allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your pc.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your computer plays recordings of things recorded in your computer room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by Appkiller.src, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>Appkiller.src can kill or startup programs on your computer.Many times your anti spyware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your PC starts talking or conversing with you.</b></p>
<p>Appkiller.src allow the hacker to type anything that he wants to say to you in a box and then make it appear that your PC is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your PC starts reading the contents of your PC clipboard.</b></p>
<p>The hacker can make your PC speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your PC and you are forced to chat with some stranger.</b></p>
<p>The Appkiller.src will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your PC programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your computer.</b></p>
<p>Your computer generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your computer is IP scanning.</b></p>
<p>The hacker can use your PC to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your computer.</b></p>
<p>With the help of Appkiller.src hackers can find personal information about you by reading documents on your PC such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your computer is infected with Appkiller.src, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your PC room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your PC by itself.</b></p>
<p>Using Appkiller.src the hacker can change the time and date on your computer.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your pc.</p>
<p><b>Your PC speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your PC shuts down by itself.The hacker can cause your PC to shutdown if you are infected by Appkiller.src.</p>
<p><b>Your PC shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using Appkiller.src can make your computer turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your PC you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What Appkiller.src may do?</h2>
<p>Below are possibilities you may experience when you are infected with Appkiller.src. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>Appkiller.src may clear files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from Appkiller.src and this not happening again it is important that take proper care and precautions when using your computer.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with adware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their spyware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be Appkiller.src, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your computer.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-appkillersrc-virus/feed</wfw:commentRss>
		</item>
	</channel>
</rss>

