<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>Antivirus software &#187; Trojan</title>
	<atom:link href="http://www.exterminatelab.com/virus/trojan/feed" rel="self" type="application/rss+xml" />
	<link>http://www.exterminatelab.com</link>
	<description>Free Scan Available</description>
	<pubDate>Fri, 27 Mar 2009 21:04:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Iatd</title>
		<link>http://www.exterminatelab.com/remove-iatd-virus</link>
		<comments>http://www.exterminatelab.com/remove-iatd-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:36:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=9428</guid>
		<description><![CDATA[Aliases of  Iatd
 
There are many names at Iatd. But most known of them are following: [Panda]Trj/Antitrace;[Computer Associates]Iatd
Overview Iatd
Iatd the individual sample Trojan.This malware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Iatd sets in memory unique identifiers.Usually [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  Iatd</h2>
<p> <!-- 1013635 -->
<p>There are many names at Iatd. But most known of them are following: [Panda]Trj/Antitrace;[Computer Associates]Iatd</p>
<h2>Overview Iatd</h2>
<p><strong>Iatd</strong> the individual sample <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>.This malware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Iatd sets in memory unique identifiers.Usually enough is updated and varies.Iatd is unsafe and can lead to loss of the data and make your system infirmity.</p>
<h2>How to Remove Iatd from Your computer?</h2>
<p>In order to completely <b>delete Iatd</b> from your PC it is necessary to remove all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to clear Iatd independently manually.For virus removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear Iatd Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to delete Iatd from the Windows Registry</a>.In sections Files  Iatd and Folders  Iatd complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  Iatd </p>
<h2 id="delete-virus-files">How to clear Iatd Files (.bin .exe, .dll, .com, .sys, etc.).</h2>
<p>All files and directories associated with Iatd are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To remove completely Iatd must remove all the files.</p>
<p>To delete files and folders associated with Iatd execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is unrealizable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To delete locked file, select it and press the right button of the mouse, then select Send To-> remove on Next Reboot on the menu and after removal restart your computer.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for Iatd</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to delete Iatd from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, spyware, adware, and malware (including Iatd) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your pc.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively remove Iatd from your Windows registry, you must delete all the registry keys and values associated with Iatd.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The responsibility for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is needful to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to delete the Iatd registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with Iatd, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To remove the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for Iatd</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>Iatd Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a></p>
<h2>How Did My PC Get Infected with Iatd?</h2>
<p>One of the most common questions found when cleaning Iatd is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get Iatd in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your PC clean and running securely:</p>
<p>If you have an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be Iatd. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you receive an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual PC user, you will almost never receive a valid attachment of this type.</p>
<p>If you get an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>Iatd</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get Iatd on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>adware</b> (including Iatd) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be Iatd too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the evident copyright issues, the downloads from these sites are typically overrun with infections and Iatd is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise adware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your PC from Iatd.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of Iatd</b></p>
<p>If you suspect or confirm that your computer is infected with Iatd, obtain the current antivirus software.The following are some primary indicators that a PC may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The PC stops responding, or it locks up frequently.</li>
<li>The computer crashes, and then it restarts every few minutes, it may be symptom of Iatd.</li>
<li>The PC restarts on its own.</li>
<li>Additionally, the computer does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be Iatd. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the computer even though you did not intentionally clear the program.</li>
</ul>
<p>Note These are common signs of infection by Iatd. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of Iatd in e-mail messages</b></p>
<p>When a PC malware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The Iatd spyware may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The Iatd may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the pc.</li>
<li>The Iatd may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including Iatd) is a program that infects your computer and allows a hacker to run hidden tasks behind your back.</p>
<p>The Iatd can allow total remote access to your computer by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your pc.To remove the trojan and keep others out of your computer you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate Iatd</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>Iatd have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your computer screen flips upside down or invertss.</b></p>
<p>When you are infected with Iatd, hackers can make your computer screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your computer or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your computer browser goes to a strange or unknown web page by itself Trojans, including Iatd, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the Iatd allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your computer.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your computer plays recordings of things recorded in your PC room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by Iatd, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>Iatd can kill or startup programs on your computer.Many times your anti virus is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your PC starts talking or conversing with you.</b></p>
<p>Iatd allow the hacker to type anything that he wants to say to you in a box and then make it appear that your PC is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your PC starts reading the contents of your computer clipboard.</b></p>
<p>The hacker can make your computer speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your PC and you are forced to chat with some stranger.</b></p>
<p>The Iatd will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your PC programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your computer.</b></p>
<p>Your computer generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your PC is IP scanning.</b></p>
<p>The hacker can use your PC to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your pc.</b></p>
<p>With the help of Iatd hackers can find personal information about you by reading documents on your computer such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your computer is infected with Iatd, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your computer room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your computer by itself.</b></p>
<p>Using Iatd the hacker can change the time and date on your computer.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your computer.</p>
<p><b>Your computer speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your PC shuts down by itself.The hacker can cause your computer to shutdown if you are infected by Iatd.</p>
<p><b>Your computer shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using Iatd can make your computer turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your PC you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What Iatd may do?</h2>
<p>Below are possibilities you may experience when you are infected with Iatd. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>Iatd may delete files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from Iatd and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your PC has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with spyware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their malware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be Iatd, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your computer.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-iatd-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>DonaldDick</title>
		<link>http://www.exterminatelab.com/remove-donalddick-2-virus</link>
		<comments>http://www.exterminatelab.com/remove-donalddick-2-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:35:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Backdoor]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=9426</guid>
		<description><![CDATA[Aliases of  DonaldDick
 
DonaldDick also it is known under names [Kaspersky]Backdoor.Win32.DonaldDick.152;[Eset]Win32/DonaldDick.1_52 trojan,Win32/DonaldDick.1_52.02 trojan,Win32/DonaldDick.1_52.B trojan;[McAfee]BackDoor-AQ;[F-Prot]W32/Backdoor.DonaldD.Server.v1;[Panda]Bck/Donald_Dick.152;[Computer Associates]Backdoor/DonaldDick.152.VxD,Backdoor/DonaldDick.A!Server,Win32.Donald.152,Win32.Donald.ldr,Backdoor/DonaldDick.1.5.2.B
Overview DonaldDick
DonaldDick the normal representative Trojan, Backdoor.This malware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system DonaldDick generates in memory unique identifiers.Often enough is [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  DonaldDick</h2>
<p> <!-- 1013632 -->
<p>DonaldDick also it is known under names [Kaspersky]Backdoor.Win32.DonaldDick.152;[Eset]Win32/DonaldDick.1_52 trojan,Win32/DonaldDick.1_52.02 trojan,Win32/DonaldDick.1_52.B trojan;[McAfee]BackDoor-AQ;[F-Prot]W32/Backdoor.DonaldD.Server.v1;[Panda]Bck/Donald_Dick.152;[Computer Associates]Backdoor/DonaldDick.152.VxD,Backdoor/DonaldDick.A!Server,Win32.Donald.152,Win32.Donald.ldr,Backdoor/DonaldDick.1.5.2.B</p>
<h2>Overview DonaldDick</h2>
<p><strong><strong>DonaldDick</strong></strong> the normal representative <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=12"  title="Remove Backdoor">Backdoor</a>.This malware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system DonaldDick generates in memory unique identifiers.Often enough is updated and varies.DonaldDick is dangerous and can lead to loss of the data and make your system unsteadiness.</p>
<h2>How to Delete DonaldDick from Your computer?</h2>
<p>In order to completely <b>remove DonaldDick</b> from your PC it is necessary to remove all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to remove DonaldDick independently manually.For virus removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear DonaldDick Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to remove DonaldDick from the Windows Registry</a>.In sections Files  DonaldDick and Folders  DonaldDick complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  DonaldDick </p>
<h2 id="delete-virus-files">How to remove DonaldDick Files (.com, .exe, .dll, .sys, .bin etc.).</h2>
<p>All files and directories associated with DonaldDick are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To delete completely DonaldDick must clear all the files.</p>
<p>To delete files and folders associated with DonaldDick execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other program), removal is impossible (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To clear locked file, select it and press the right button of the mouse, then select Send To-> delete on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for DonaldDick</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to clear DonaldDick from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, spyware, malware, and adware (including DonaldDick) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively delete DonaldDick from your Windows registry, you must clear all the registry keys and values associated with DonaldDick.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The responsibility for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is requisite to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local computer.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to remove the DonaldDick registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with DonaldDick, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To clear the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for DonaldDick</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>DonaldDick Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=12"  title="Remove Backdoor">Backdoor</a></p>
<h2>How Did My PC Get Infected with DonaldDick?</h2>
<p>One of the most common questions found when cleaning DonaldDick is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your pc&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get DonaldDick in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your PC clean and running securely:</p>
<p>If you have an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be DonaldDick. Opening attachments from people you do not know is a very common method for viruses or worms to infect your pc.</p>
<p>If you acquire an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you acquire an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>DonaldDick</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get DonaldDick on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>malware</b> (including DonaldDick) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be DonaldDick too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the evident copyright issues, the downloads from these sites are typically overrun with infections and DonaldDick is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise adware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your PC from DonaldDick.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of DonaldDick</b></p>
<p>If you suspect or confirm that your PC is infected with DonaldDick, obtain the current antivirus software.The following are some primary indicators that a computer may be infected:
<ul>
<li>The PC runs slower than usual.</li>
<li>The computer stops responding, or it locks up frequently.</li>
<li>The computer crashes, and then it restarts every few minutes, it may be symptom of DonaldDick.</li>
<li>The computer restarts on its own.</li>
<li>Additionally, the computer does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be DonaldDick. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the PC even though you did not intentionally clear the program.</li>
</ul>
<p>Note These are common signs of infection by DonaldDick. However, these signs may also be caused by hardware or software problems that have nothing to do with a computer virus.</p>
<p><b>Symptoms of DonaldDick in e-mail messages</b></p>
<p>When a computer virus infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The DonaldDick spyware may reformat the hard disk.</li>
<li>This behavior will remove files and programs.</li>
<li>The DonaldDick may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the pc.</li>
<li>The DonaldDick may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including DonaldDick) is a program that infects your PC and allows a hacker to run hidden tasks behind your back.</p>
<p>The DonaldDick can allow total remote access to your computer by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your pc.To remove the trojan and keep others out of your computer you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate DonaldDick</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>DonaldDick have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your PC screen flips upside down or invertss.</b></p>
<p>When you are infected with DonaldDick, hackers can make your computer screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your PC or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your PC browser goes to a strange or unknown web page by itself <b>Trojans</b>, including DonaldDick, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the DonaldDick allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your computer.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your PC plays recordings of things recorded in your computer room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by DonaldDick, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>DonaldDick can kill or startup programs on your computer.Many times your anti malware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your computer starts talking or conversing with you.</b></p>
<p>DonaldDick allow the hacker to type anything that he wants to say to you in a box and then make it appear that your computer is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your PC starts reading the contents of your PC clipboard.</b></p>
<p>The hacker can make your computer speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your PC and you are forced to chat with some stranger.</b></p>
<p>The DonaldDick will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your PC programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your computer.</b></p>
<p>Your computer generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your PC is IP scanning.</b></p>
<p>The hacker can use your computer to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your computer.</b></p>
<p>With the help of DonaldDick hackers can find personal information about you by reading documents on your computer such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your PC is infected with DonaldDick, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your computer room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your PC by itself.</b></p>
<p>Using DonaldDick the hacker can change the time and date on your computer.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your pc.</p>
<p><b>Your PC speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your PC shuts down by itself.The hacker can cause your computer to shutdown if you are infected by DonaldDick.</p>
<p><b>Your computer shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using DonaldDick can make your computer turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your computer you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What DonaldDick may do?</h2>
<p>Below are possibilities you may experience when you are infected with DonaldDick. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>DonaldDick may clear files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from DonaldDick and this not happening again it is important that take proper care and precautions when using your computer.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your PC has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with malware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their virus lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be DonaldDick, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your computer.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-donalddick-2-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>Kyjak</title>
		<link>http://www.exterminatelab.com/remove-kyjak-virus</link>
		<comments>http://www.exterminatelab.com/remove-kyjak-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:35:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=9425</guid>
		<description><![CDATA[Overview Kyjak
Kyjak the individual sample Trojan.This malware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Kyjak generates in memory unique identifiers.Usually enough is updated and varies.Kyjak is dangerous and can lead to loss of the data and make your [...]]]></description>
			<content:encoded><![CDATA[<h2>Overview Kyjak</h2>
<p><strong>Kyjak</strong> the individual sample <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>.This malware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Kyjak generates in memory unique identifiers.Usually enough is updated and varies.Kyjak is dangerous and can lead to loss of the data and make your system infirmity.</p>
<h2>How to Delete Kyjak from Your PC?</h2>
<p>In order to completely <b>remove Kyjak</b> from your PC it is necessary to delete all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to clear Kyjak independently manually.For spyware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear Kyjak Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to delete Kyjak from the Windows Registry</a>.In sections Files  Kyjak and Folders  Kyjak complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  Kyjak </p>
<h2 id="delete-virus-files">How to delete Kyjak Files (.bin .exe, .dll, .com, .sys, etc.).</h2>
<p>All files and directories associated with Kyjak are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To delete completely Kyjak must delete all the files.</p>
<p>To delete files and folders associated with Kyjak execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other program), removal is unrealizable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To delete locked file, select it and press the right button of the mouse, then select Send To-> remove on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for Kyjak</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to remove Kyjak from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, spyware, malware, and adware (including Kyjak) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively delete Kyjak from your Windows registry, you must delete all the registry keys and values associated with Kyjak.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The responsibility for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is indispensable to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to clear the Kyjak registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with Kyjak, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To delete the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for Kyjak</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>Kyjak Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a></p>
<h2>How Did My PC Get Infected with Kyjak?</h2>
<p>One of the most common questions found when cleaning Kyjak is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get Kyjak in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your computer clean and running securely:</p>
<p>If you acquire an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be Kyjak. Opening attachments from people you do not know is a very common method for viruses or worms to infect your pc.</p>
<p>If you get an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual PC user, you will almost never receive a valid attachment of this type.</p>
<p>If you have an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>Kyjak</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get Kyjak on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>malware</b> (including Kyjak) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be Kyjak too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and Kyjak is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise spyware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your pc.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your PC from Kyjak.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of Kyjak</b></p>
<p>If you suspect or confirm that your PC is infected with Kyjak, obtain the current antivirus software.The following are some primary indicators that a computer may be infected:
<ul>
<li>The PC runs slower than usual.</li>
<li>The computer stops responding, or it locks up frequently.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of Kyjak.</li>
<li>The PC restarts on its own.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be Kyjak. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the computer even though you did not intentionally clear the program.</li>
</ul>
<p>Note These are common signs of infection by Kyjak. However, these signs may also be caused by hardware or software problems that have nothing to do with a computer virus.</p>
<p><b>Symptoms of Kyjak in e-mail messages</b></p>
<p>When a PC virus infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The Kyjak malware may reformat the hard disk.</li>
<li>This behavior will delete files and programs.</li>
<li>The Kyjak may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The Kyjak may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including Kyjak) is a program that infects your computer and allows a hacker to run hidden tasks behind your back.</p>
<p>The Kyjak can allow total remote access to your computer by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your computer.To delete the trojan and keep others out of your PC you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate Kyjak</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>Kyjak have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your computer screen flips upside down or invertss.</b></p>
<p>When you are infected with Kyjak, hackers can make your computer screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your PC or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your computer browser goes to a strange or unknown web page by itself Trojans, including Kyjak, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the Kyjak allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your computer.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your computer plays recordings of things recorded in your computer room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by Kyjak, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>Kyjak can kill or startup programs on your pc.Many times your anti malware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your PC starts talking or conversing with you.</b></p>
<p>Kyjak allow the hacker to type anything that he wants to say to you in a box and then make it appear that your computer is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your computer starts reading the contents of your computer clipboard.</b></p>
<p>The hacker can make your computer speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your computer and you are forced to chat with some stranger.</b></p>
<p>The Kyjak will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your computer programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your pc.</b></p>
<p>Your PC generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your PC is IP scanning.</b></p>
<p>The hacker can use your computer to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your pc.</b></p>
<p>With the help of Kyjak hackers can find personal information about you by reading documents on your computer such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your computer is infected with Kyjak, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your PC room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your PC by itself.</b></p>
<p>Using Kyjak the hacker can change the time and date on your computer.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your computer.</p>
<p><b>Your computer speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your computer shuts down by itself.The hacker can cause your computer to shutdown if you are infected by Kyjak.</p>
<p><b>Your PC shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using Kyjak can make your computer turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your PC you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What Kyjak may do?</h2>
<p>Below are possibilities you may experience when you are infected with Kyjak. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>Kyjak may clear files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from Kyjak and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with spyware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their adware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be Kyjak, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your pc.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-kyjak-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>CokeCrack</title>
		<link>http://www.exterminatelab.com/remove-cokecrack-virus</link>
		<comments>http://www.exterminatelab.com/remove-cokecrack-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:35:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=9424</guid>
		<description><![CDATA[Overview CokeCrack
CokeCrack the normal representative Trojan.This spyware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system CokeCrack makes in memory unique identifiers.Usually enough is updated and varies.CokeCrack is shifty and can lead to loss of the data and make your [...]]]></description>
			<content:encoded><![CDATA[<h2>Overview CokeCrack</h2>
<p><strong><strong>CokeCrack</strong></strong> the normal representative <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>.This spyware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system CokeCrack makes in memory unique identifiers.Usually enough is updated and varies.CokeCrack is shifty and can lead to loss of the data and make your system unsteadiness.</p>
<h2>How to Delete CokeCrack from Your computer?</h2>
<p>In order to completely <b>remove CokeCrack</b> from your computer it is necessary to remove all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to delete CokeCrack independently manually.For spyware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to delete CokeCrack Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to remove CokeCrack from the Windows Registry</a>.In sections Files  CokeCrack and Folders  CokeCrack complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  CokeCrack </p>
<h2 id="delete-virus-files">How to clear CokeCrack Files (.com, .exe, .dll, .sys, .bin etc.).</h2>
<p>All files and directories associated with CokeCrack are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To clear completely CokeCrack must remove all the files.</p>
<p>To clear files and folders associated with CokeCrack execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is impracticable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To remove locked file, select it and press the right button of the mouse, then select Send To-> clear on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for CokeCrack</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to remove CokeCrack from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, adware, spyware, and malware (including CokeCrack) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively remove CokeCrack from your Windows registry, you must clear all the registry keys and values associated with CokeCrack.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The amenability for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is needful to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local computer.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to clear the CokeCrack registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To remove the keys, associated with CokeCrack, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To delete the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for CokeCrack</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>CokeCrack Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a></p>
<h2>How Did My PC Get Infected with CokeCrack?</h2>
<p>One of the most common questions found when cleaning CokeCrack is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get CokeCrack in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your PC clean and running securely:</p>
<p>If you have an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be CokeCrack. Opening attachments from people you do not know is a very common method for viruses or worms to infect your pc.</p>
<p>If you get an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you receive an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>CokeCrack</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get CokeCrack on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>spyware</b> (including CokeCrack) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be CokeCrack too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the evident copyright issues, the downloads from these sites are typically overrun with infections and CokeCrack is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise adware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from CokeCrack.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of CokeCrack</b></p>
<p>If you suspect or confirm that your computer is infected with CokeCrack, obtain the current antivirus software.The following are some primary indicators that a PC may be infected:
<ul>
<li>The PC runs slower than usual.</li>
<li>The computer stops responding, or it locks up frequently.</li>
<li>The computer crashes, and then it restarts every few minutes, it may be symptom of CokeCrack.</li>
<li>The PC restarts on its own.</li>
<li>Additionally, the computer does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be CokeCrack. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the PC even though you did not intentionally delete the program.</li>
</ul>
<p>Note These are common signs of infection by CokeCrack. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of CokeCrack in e-mail messages</b></p>
<p>When a PC malware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The CokeCrack adware may reformat the hard disk.</li>
<li>This behavior will remove files and programs.</li>
<li>The CokeCrack may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The CokeCrack may reduce security. </li>
<li>This could enable intruders to access remotely the computer or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including CokeCrack) is a program that infects your PC and allows a hacker to run hidden tasks behind your back.</p>
<p>The CokeCrack can allow total remote access to your PC by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your pc.To clear the trojan and keep others out of your PC you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate CokeCrack</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>CokeCrack have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your PC screen flips upside down or invertss.</b></p>
<p>When you are infected with CokeCrack, hackers can make your PC screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your PC or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your PC browser goes to a strange or unknown web page by itself <b>Trojans</b>, including CokeCrack, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the CokeCrack allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your pc.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your PC plays recordings of things recorded in your PC room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by CokeCrack, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>CokeCrack can kill or startup programs on your computer.Many times your anti virus is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your computer starts talking or conversing with you.</b></p>
<p>CokeCrack allow the hacker to type anything that he wants to say to you in a box and then make it appear that your computer is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your PC starts reading the contents of your computer clipboard.</b></p>
<p>The hacker can make your PC speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your PC and you are forced to chat with some stranger.</b></p>
<p>The CokeCrack will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your computer programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your computer.</b></p>
<p>Your computer generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your PC is IP scanning.</b></p>
<p>The hacker can use your PC to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your pc.</b></p>
<p>With the help of CokeCrack hackers can find personal information about you by reading documents on your computer such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your PC is infected with CokeCrack, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your PC room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your computer by itself.</b></p>
<p>Using CokeCrack the hacker can change the time and date on your pc.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your computer.</p>
<p><b>Your computer speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your PC shuts down by itself.The hacker can cause your computer to shutdown if you are infected by CokeCrack.</p>
<p><b>Your PC shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using CokeCrack can make your computer turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your PC you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What CokeCrack may do?</h2>
<p>Below are possibilities you may experience when you are infected with CokeCrack. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>CokeCrack may delete files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from CokeCrack and this not happening again it is important that take proper care and precautions when using your computer.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with spyware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their malware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be CokeCrack, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your pc.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-cokecrack-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>Exploit.Zephyrus</title>
		<link>http://www.exterminatelab.com/remove-exploitzephyrus-virus</link>
		<comments>http://www.exterminatelab.com/remove-exploitzephyrus-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:35:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hacker Tool]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=9423</guid>
		<description><![CDATA[Aliases of  Exploit.Zephyrus
 
There are many names at Exploit.Zephyrus. But most known of them are following: [McAfee]Exploit-Zephyrus;[F-Prot]security risk named W32/Zephyrus.A,security risk or a &#8220;backdoor&#8221; program;[Panda]Trojan Horse;[Computer Associates]Win32/Zephyrus.11Exploit!Trojan
Overview Exploit.Zephyrus
Exploit.Zephyrus the normal representative Trojan, Hacker Tool.This malware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  Exploit.Zephyrus</h2>
<p> <!-- 1013629 -->
<p>There are many names at Exploit.Zephyrus. But most known of them are following: [McAfee]Exploit-Zephyrus;[F-Prot]security risk named W32/Zephyrus.A,security risk or a &#8220;backdoor&#8221; program;[Panda]Trojan Horse;[Computer Associates]Win32/Zephyrus.11Exploit!Trojan</p>
<h2>Overview Exploit.Zephyrus</h2>
<p><strong><strong>Exploit.Zephyrus</strong></strong> the normal representative <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=17"  title="Remove Hacker Tool">Hacker Tool</a>.This malware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Exploit.Zephyrus sets in memory unique identifiers.Often enough is updated and varies.Exploit.Zephyrus is shifty and can lead to loss of the data and make your system instability.</p>
<h2>How to Remove Exploit.Zephyrus from Your PC?</h2>
<p>In order to completely <b>clear Exploit.Zephyrus</b> from your computer it is necessary to clear all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to clear Exploit.Zephyrus independently manually.For malware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to delete Exploit.Zephyrus Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to clear Exploit.Zephyrus from the Windows Registry</a>.In sections Files  Exploit.Zephyrus and Folders  Exploit.Zephyrus complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  Exploit.Zephyrus </p>
<h2 id="delete-virus-files">How to clear Exploit.Zephyrus Files (.dll, .sys, .exe, .com, .bin etc.).</h2>
<p>All files and directories associated with Exploit.Zephyrus are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To delete completely Exploit.Zephyrus must clear all the files.</p>
<p>To delete files and folders associated with Exploit.Zephyrus execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other program), removal is impracticable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To clear locked file, select it and press the right button of the mouse, then select Send To-> clear on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for Exploit.Zephyrus</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to delete Exploit.Zephyrus from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, malware, spyware, and adware (including Exploit.Zephyrus) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively remove Exploit.Zephyrus from your Windows registry, you must delete all the registry keys and values associated with Exploit.Zephyrus.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The responsibility for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is needful to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local computer.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to delete the Exploit.Zephyrus registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To remove the keys, associated with Exploit.Zephyrus, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To delete the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for Exploit.Zephyrus</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>Exploit.Zephyrus Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=17"  title="Remove Hacker Tool">Hacker Tool</a></p>
<h2>How Did My PC Get Infected with Exploit.Zephyrus?</h2>
<p>One of the most common questions found when cleaning Exploit.Zephyrus is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get Exploit.Zephyrus in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your computer clean and running securely:</p>
<p>If you have an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be Exploit.Zephyrus. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you receive an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you get an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>Exploit.Zephyrus</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get Exploit.Zephyrus on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>adware</b> (including Exploit.Zephyrus) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be Exploit.Zephyrus too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and Exploit.Zephyrus is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise spyware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your PC from Exploit.Zephyrus.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of Exploit.Zephyrus</b></p>
<p>If you suspect or confirm that your computer is infected with Exploit.Zephyrus, obtain the current antivirus software.The following are some primary indicators that a computer may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The PC stops responding, or it locks up frequently.</li>
<li>The computer crashes, and then it restarts every few minutes, it may be symptom of Exploit.Zephyrus.</li>
<li>The PC restarts on its own.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be Exploit.Zephyrus. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the computer even though you did not intentionally clear the program.</li>
</ul>
<p>Note These are common signs of infection by Exploit.Zephyrus. However, these signs may also be caused by hardware or software problems that have nothing to do with a computer virus.</p>
<p><b>Symptoms of Exploit.Zephyrus in e-mail messages</b></p>
<p>When a PC virus infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The Exploit.Zephyrus adware may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The Exploit.Zephyrus may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The Exploit.Zephyrus may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including Exploit.Zephyrus) is a program that infects your computer and allows a hacker to run hidden tasks behind your back.</p>
<p>The Exploit.Zephyrus can allow total remote access to your PC by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your pc.To clear the trojan and keep others out of your computer you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate Exploit.Zephyrus</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>Exploit.Zephyrus have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your computer screen flips upside down or invertss.</b></p>
<p>When you are infected with Exploit.Zephyrus, hackers can make your PC screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your PC or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your computer browser goes to a strange or unknown web page by itself Trojans, including Exploit.Zephyrus, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the Exploit.Zephyrus allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your computer.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your PC plays recordings of things recorded in your PC room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by Exploit.Zephyrus, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>Exploit.Zephyrus can kill or startup programs on your pc.Many times your anti adware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your PC starts talking or conversing with you.</b></p>
<p>Exploit.Zephyrus allow the hacker to type anything that he wants to say to you in a box and then make it appear that your PC is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your PC starts reading the contents of your computer clipboard.</b></p>
<p>The hacker can make your PC speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your PC and you are forced to chat with some stranger.</b></p>
<p>The Exploit.Zephyrus will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your PC programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your computer.</b></p>
<p>Your PC generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your computer is IP scanning.</b></p>
<p>The hacker can use your computer to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your pc.</b></p>
<p>With the help of Exploit.Zephyrus hackers can find personal information about you by reading documents on your computer such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your computer is infected with Exploit.Zephyrus, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your computer room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your PC by itself.</b></p>
<p>Using Exploit.Zephyrus the hacker can change the time and date on your computer.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your pc.</p>
<p><b>Your PC speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your PC shuts down by itself.The hacker can cause your computer to shutdown if you are infected by Exploit.Zephyrus.</p>
<p><b>Your computer shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using Exploit.Zephyrus can make your PC turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your PC you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What Exploit.Zephyrus may do?</h2>
<p>Below are possibilities you may experience when you are infected with Exploit.Zephyrus. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>Exploit.Zephyrus may delete files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from Exploit.Zephyrus and this not happening again it is important that take proper care and precautions when using your computer.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with malware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every PC you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their adware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be Exploit.Zephyrus, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your pc.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-exploitzephyrus-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>BO2K.Plugin.Idea</title>
		<link>http://www.exterminatelab.com/remove-bo2kpluginidea-virus</link>
		<comments>http://www.exterminatelab.com/remove-bo2kpluginidea-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:35:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Backdoor]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=9421</guid>
		<description><![CDATA[Aliases of  BO2K.Plugin.Idea
 
There are many names at BO2K.Plugin.Idea. But most known of them are following: [Eset]Win32/BO2K.Plugin.Idea.D trojan;[Panda]BO2K/plugin.Idea.D;[Computer Associates]Backdoor/BO2K_Plugin.Idea.D
Overview BO2K.Plugin.Idea
BO2K.Plugin.Idea the classic sample Trojan, Backdoor.This malware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system BO2K.Plugin.Idea initiates in memory [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  BO2K.Plugin.Idea</h2>
<p> <!-- 1013627 -->
<p>There are many names at BO2K.Plugin.Idea. But most known of them are following: [Eset]Win32/BO2K.Plugin.Idea.D trojan;[Panda]BO2K/plugin.Idea.D;[Computer Associates]Backdoor/BO2K_Plugin.Idea.D</p>
<h2>Overview BO2K.Plugin.Idea</h2>
<p><strong>BO2K.Plugin.Idea</strong> the classic sample <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=12"  title="Remove Backdoor">Backdoor</a>.This malware extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system BO2K.Plugin.Idea initiates in memory unique identifiers.Often enough is updated and varies.BO2K.Plugin.Idea is shifty and can lead to loss of the data and make your system instability.</p>
<h2>How to Clear BO2K.Plugin.Idea from Your computer?</h2>
<p>In order to completely <b>remove BO2K.Plugin.Idea</b> from your PC it is necessary to remove all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to remove BO2K.Plugin.Idea independently manually.For adware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear BO2K.Plugin.Idea Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to clear BO2K.Plugin.Idea from the Windows Registry</a>.In sections Files  BO2K.Plugin.Idea and Folders  BO2K.Plugin.Idea complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  BO2K.Plugin.Idea </p>
<h2 id="delete-virus-files">How to remove BO2K.Plugin.Idea Files (.bin .exe, .dll, .com, .sys, etc.).</h2>
<p>All files and directories associated with BO2K.Plugin.Idea are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To remove completely BO2K.Plugin.Idea must clear all the files.</p>
<p>To remove files and folders associated with BO2K.Plugin.Idea execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is impossible (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To remove locked file, select it and press the right button of the mouse, then select Send To-> remove on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for BO2K.Plugin.Idea</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to clear BO2K.Plugin.Idea from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, adware, spyware, and malware (including BO2K.Plugin.Idea) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your pc.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively clear BO2K.Plugin.Idea from your Windows registry, you must remove all the registry keys and values associated with BO2K.Plugin.Idea.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The amenability for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is requisite to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local computer.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to clear the BO2K.Plugin.Idea registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To clear the keys, associated with BO2K.Plugin.Idea, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To remove the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for BO2K.Plugin.Idea</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>BO2K.Plugin.Idea Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=12"  title="Remove Backdoor">Backdoor</a></p>
<h2>How Did My PC Get Infected with BO2K.Plugin.Idea?</h2>
<p>One of the most common questions found when cleaning BO2K.Plugin.Idea is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get BO2K.Plugin.Idea in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your PC clean and running securely:</p>
<p>If you receive an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be BO2K.Plugin.Idea. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you acquire an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual PC user, you will almost never receive a valid attachment of this type.</p>
<p>If you get an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>BO2K.Plugin.Idea</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get BO2K.Plugin.Idea on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to porn sites.The fact is that a large amount of <b>malware</b> (including BO2K.Plugin.Idea) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be BO2K.Plugin.Idea too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and BO2K.Plugin.Idea is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise spyware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from BO2K.Plugin.Idea.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of BO2K.Plugin.Idea</b></p>
<p>If you suspect or confirm that your PC is infected with BO2K.Plugin.Idea, obtain the current antivirus software.The following are some primary indicators that a computer may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The computer stops responding, or it locks up frequently.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of BO2K.Plugin.Idea.</li>
<li>The computer restarts on its own.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be BO2K.Plugin.Idea. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the PC even though you did not intentionally clear the program.</li>
</ul>
<p>Note These are common signs of infection by BO2K.Plugin.Idea. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of BO2K.Plugin.Idea in e-mail messages</b></p>
<p>When a computer malware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The BO2K.Plugin.Idea adware may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The BO2K.Plugin.Idea may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the pc.</li>
<li>The BO2K.Plugin.Idea may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including BO2K.Plugin.Idea) is a program that infects your PC and allows a hacker to run hidden tasks behind your back.</p>
<p>The BO2K.Plugin.Idea can allow total remote access to your PC by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your computer.To remove the trojan and keep others out of your PC you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate BO2K.Plugin.Idea</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>BO2K.Plugin.Idea have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your computer screen flips upside down or invertss.</b></p>
<p>When you are infected with BO2K.Plugin.Idea, hackers can make your PC screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your computer or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your computer browser goes to a strange or unknown web page by itself Trojans, including BO2K.Plugin.Idea, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the BO2K.Plugin.Idea allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your computer.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your computer plays recordings of things recorded in your PC room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by BO2K.Plugin.Idea, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>BO2K.Plugin.Idea can kill or startup programs on your pc.Many times your anti spyware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your computer starts talking or conversing with you.</b></p>
<p>BO2K.Plugin.Idea allow the hacker to type anything that he wants to say to you in a box and then make it appear that your computer is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your PC starts reading the contents of your computer clipboard.</b></p>
<p>The hacker can make your PC speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your computer and you are forced to chat with some stranger.</b></p>
<p>The BO2K.Plugin.Idea will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your PC programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your pc.</b></p>
<p>Your computer generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your PC is IP scanning.</b></p>
<p>The hacker can use your PC to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your pc.</b></p>
<p>With the help of BO2K.Plugin.Idea hackers can find personal information about you by reading documents on your computer such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your PC is infected with BO2K.Plugin.Idea, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your computer room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your PC by itself.</b></p>
<p>Using BO2K.Plugin.Idea the hacker can change the time and date on your computer.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your pc.</p>
<p><b>Your PC speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your computer shuts down by itself.The hacker can cause your PC to shutdown if you are infected by BO2K.Plugin.Idea.</p>
<p><b>Your PC shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using BO2K.Plugin.Idea can make your PC turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your PC you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What BO2K.Plugin.Idea may do?</h2>
<p>Below are possibilities you may experience when you are infected with BO2K.Plugin.Idea. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>BO2K.Plugin.Idea may remove files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from BO2K.Plugin.Idea and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your PC has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with adware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their spyware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be BO2K.Plugin.Idea, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your computer.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-bo2kpluginidea-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>Copier</title>
		<link>http://www.exterminatelab.com/remove-copier-virus</link>
		<comments>http://www.exterminatelab.com/remove-copier-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:35:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=9420</guid>
		<description><![CDATA[Aliases of  Copier
 
Copier also it is known under names [Panda]Trj/Copier
Overview Copier
Copier the typical sample Trojan.This spyware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Copier sets in memory unique identifiers.Usually enough is updated and varies.Copier is shifty [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  Copier</h2>
<p> <!-- 1013626 -->
<p>Copier also it is known under names [Panda]Trj/Copier</p>
<h2>Overview Copier</h2>
<p><strong>Copier</strong> the typical sample <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>.This spyware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system Copier sets in memory unique identifiers.Usually enough is updated and varies.Copier is shifty and can lead to loss of the data and make your system infirmity.</p>
<h2>How to Delete Copier from Your PC?</h2>
<p>In order to completely <b>delete Copier</b> from your PC it is necessary to delete all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to clear Copier independently manually.For malware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear Copier Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to clear Copier from the Windows Registry</a>.In sections Files  Copier and Folders  Copier complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  Copier </p>
<h2 id="delete-virus-files">How to remove Copier Files (.sys, .exe, .dll, .com, .bin etc.).</h2>
<p>All files and directories associated with Copier are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To clear completely Copier must delete all the files.</p>
<p>To remove files and folders associated with Copier execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other program), removal is impracticable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To clear locked file, select it and press the right button of the mouse, then select Send To-> remove on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for Copier</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to remove Copier from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, malware, spyware, and adware (including Copier) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively remove Copier from your Windows registry, you must delete all the registry keys and values associated with Copier.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The responsibility for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is requisite to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local computer.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to clear the Copier registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To clear the keys, associated with Copier, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To remove the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for Copier</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>Copier Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a></p>
<h2>How Did My PC Get Infected with Copier?</h2>
<p>One of the most common questions found when cleaning Copier is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get Copier in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your computer clean and running securely:</p>
<p>If you receive an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be Copier. Opening attachments from people you do not know is a very common method for viruses or worms to infect your pc.</p>
<p>If you receive an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual PC user, you will almost never receive a valid attachment of this type.</p>
<p>If you receive an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>Copier</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get Copier on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to porn sites.The fact is that a large amount of <b>spyware</b> (including Copier) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be Copier too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and Copier is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise spyware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from Copier.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of Copier</b></p>
<p>If you suspect or confirm that your computer is infected with Copier, obtain the current antivirus software.The following are some primary indicators that a PC may be infected:
<ul>
<li>The PC runs slower than usual.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of Copier.</li>
<li>The computer restarts on its own.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be Copier. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the PC even though you did not intentionally remove the program.</li>
</ul>
<p>Note These are common signs of infection by Copier. However, these signs may also be caused by hardware or software problems that have nothing to do with a computer virus.</p>
<p><b>Symptoms of Copier in e-mail messages</b></p>
<p>When a computer virus infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The Copier malware may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The Copier may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The Copier may reduce security. </li>
<li>This could enable intruders to access remotely the computer or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including Copier) is a program that infects your computer and allows a hacker to run hidden tasks behind your back.</p>
<p>The Copier can allow total remote access to your computer by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your computer.To remove the trojan and keep others out of your computer you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate Copier</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>Copier have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your computer screen flips upside down or invertss.</b></p>
<p>When you are infected with Copier, hackers can make your PC screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your PC or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your PC browser goes to a strange or unknown web page by itself <b>Trojans</b>, including Copier, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the Copier allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your computer.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your PC plays recordings of things recorded in your computer room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by Copier, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>Copier can kill or startup programs on your computer.Many times your anti malware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your computer starts talking or conversing with you.</b></p>
<p>Copier allow the hacker to type anything that he wants to say to you in a box and then make it appear that your computer is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your computer starts reading the contents of your computer clipboard.</b></p>
<p>The hacker can make your computer speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your PC and you are forced to chat with some stranger.</b></p>
<p>The Copier will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your PC programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your pc.</b></p>
<p>Your PC generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your PC is IP scanning.</b></p>
<p>The hacker can use your PC to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your computer.</b></p>
<p>With the help of Copier hackers can find personal information about you by reading documents on your computer such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your PC is infected with Copier, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your PC room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your computer by itself.</b></p>
<p>Using Copier the hacker can change the time and date on your pc.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your pc.</p>
<p><b>Your computer speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your computer shuts down by itself.The hacker can cause your PC to shutdown if you are infected by Copier.</p>
<p><b>Your computer shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using Copier can make your computer turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your PC you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What Copier may do?</h2>
<p>Below are possibilities you may experience when you are infected with Copier. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>Copier may remove files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from Copier and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your PC safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with malware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their spyware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be Copier, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your pc.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-copier-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>MSN.Faker</title>
		<link>http://www.exterminatelab.com/remove-msnfaker-2-virus</link>
		<comments>http://www.exterminatelab.com/remove-msnfaker-2-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:35:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Hacker Tool]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=9418</guid>
		<description><![CDATA[Aliases of  MSN.Faker
 
MSN.Faker also it is known under names [Panda]Trj/PSW.MSN.FAKER.G;[Computer Associates]Win32/MSN.Faker.g!PWS!Trojan
Overview MSN.Faker
MSN.Faker the classic specimen Trojan, Hacker Tool.This virus extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system MSN.Faker initiates in memory unique identifiers.Often enough is updated and [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  MSN.Faker</h2>
<p> <!-- 1013624 -->
<p>MSN.Faker also it is known under names [Panda]Trj/PSW.MSN.FAKER.G;[Computer Associates]Win32/MSN.Faker.g!PWS!Trojan</p>
<h2>Overview MSN.Faker</h2>
<p><strong>MSN.Faker</strong> the classic specimen <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=17"  title="Remove Hacker Tool">Hacker Tool</a>.This virus extends basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system MSN.Faker initiates in memory unique identifiers.Often enough is updated and varies.MSN.Faker is perilous and can lead to loss of the data and make your system instability.</p>
<h2>How to Clear MSN.Faker from Your computer?</h2>
<p>In order to completely <b>delete MSN.Faker</b> from your computer it is necessary to delete all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to delete MSN.Faker independently manually.For spyware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear MSN.Faker Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to clear MSN.Faker from the Windows Registry</a>.In sections Files  MSN.Faker and Folders  MSN.Faker complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  MSN.Faker </p>
<h2 id="delete-virus-files">How to delete MSN.Faker Files (.dll, .sys, .exe, .com, .bin etc.).</h2>
<p>All files and directories associated with MSN.Faker are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To clear completely MSN.Faker must remove all the files.</p>
<p>To clear files and folders associated with MSN.Faker execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is impracticable (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To delete locked file, select it and press the right button of the mouse, then select Send To-> clear on Next Reboot on the menu and after removal restart your computer.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for MSN.Faker</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to delete MSN.Faker from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, adware, malware, and spyware (including MSN.Faker) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your pc.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively remove MSN.Faker from your Windows registry, you must remove all the registry keys and values associated with MSN.Faker.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The amenability for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is indispensable to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to clear the MSN.Faker registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with MSN.Faker, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To delete the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for MSN.Faker</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>MSN.Faker Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=17"  title="Remove Hacker Tool">Hacker Tool</a></p>
<h2>How Did My PC Get Infected with MSN.Faker?</h2>
<p>One of the most common questions found when cleaning MSN.Faker is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your pc&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get MSN.Faker in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your computer clean and running securely:</p>
<p>If you acquire an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be MSN.Faker. Opening attachments from people you do not know is a very common method for viruses or worms to infect your pc.</p>
<p>If you get an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual PC user, you will almost never receive a valid attachment of this type.</p>
<p>If you get an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>MSN.Faker</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get MSN.Faker on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>adware</b> (including MSN.Faker) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be MSN.Faker too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and MSN.Faker is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise spyware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your PC from MSN.Faker.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of MSN.Faker</b></p>
<p>If you suspect or confirm that your PC is infected with MSN.Faker, obtain the current antivirus software.The following are some primary indicators that a PC may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The PC stops responding, or it locks up frequently.</li>
<li>The computer crashes, and then it restarts every few minutes, it may be symptom of MSN.Faker.</li>
<li>The PC restarts on its own.</li>
<li>Additionally, the PC does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be MSN.Faker. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the PC even though you did not intentionally remove the program.</li>
</ul>
<p>Note These are common signs of infection by MSN.Faker. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of MSN.Faker in e-mail messages</b></p>
<p>When a computer malware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The MSN.Faker adware may reformat the hard disk.</li>
<li>This behavior will delete files and programs.</li>
<li>The MSN.Faker may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the computer.</li>
<li>The MSN.Faker may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including MSN.Faker) is a program that infects your computer and allows a hacker to run hidden tasks behind your back.</p>
<p>The MSN.Faker can allow total remote access to your computer by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your pc.To delete the trojan and keep others out of your computer you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate MSN.Faker</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>MSN.Faker have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your PC screen flips upside down or invertss.</b></p>
<p>When you are infected with MSN.Faker, hackers can make your computer screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your PC or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your computer browser goes to a strange or unknown web page by itself Trojans, including MSN.Faker, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the MSN.Faker allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your computer.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your PC plays recordings of things recorded in your computer room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by MSN.Faker, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>MSN.Faker can kill or startup programs on your pc.Many times your anti malware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your computer starts talking or conversing with you.</b></p>
<p>MSN.Faker allow the hacker to type anything that he wants to say to you in a box and then make it appear that your PC is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your computer starts reading the contents of your computer clipboard.</b></p>
<p>The hacker can make your computer speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your PC and you are forced to chat with some stranger.</b></p>
<p>The MSN.Faker will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your computer programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your computer.</b></p>
<p>Your PC generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your computer is IP scanning.</b></p>
<p>The hacker can use your computer to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your computer.</b></p>
<p>With the help of MSN.Faker hackers can find personal information about you by reading documents on your PC such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your computer is infected with MSN.Faker, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your PC room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your PC by itself.</b></p>
<p>Using MSN.Faker the hacker can change the time and date on your pc.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your pc.</p>
<p><b>Your computer speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your PC shuts down by itself.The hacker can cause your computer to shutdown if you are infected by MSN.Faker.</p>
<p><b>Your PC shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using MSN.Faker can make your computer turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your computer you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What MSN.Faker may do?</h2>
<p>Below are possibilities you may experience when you are infected with MSN.Faker. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>MSN.Faker may clear files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from MSN.Faker and this not happening again it is important that take proper care and precautions when using your computer.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your PC has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with malware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every PC you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their spyware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be MSN.Faker, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your pc.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-msnfaker-2-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>BO2K.Plugin</title>
		<link>http://www.exterminatelab.com/remove-bo2kplugin-virus</link>
		<comments>http://www.exterminatelab.com/remove-bo2kplugin-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:35:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Backdoor]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=9417</guid>
		<description><![CDATA[Aliases of  BO2K.Plugin
 
There are many names at BO2K.Plugin. But most known of them are following: [Eset]Win32/BO2K.13.plugin trojan,Win32/BO2K.Plugin.Cast.M trojan;[Computer Associates]Backdoor/BO2K.13.C.Plugin,Win32.BO2K.plugin
Overview BO2K.Plugin
BO2K.Plugin the typical representative Trojan, Backdoor.This spyware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system BO2K.Plugin generates in [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  BO2K.Plugin</h2>
<p> <!-- 1013623 -->
<p>There are many names at BO2K.Plugin. But most known of them are following: [Eset]Win32/BO2K.13.plugin trojan,Win32/BO2K.Plugin.Cast.M trojan;[Computer Associates]Backdoor/BO2K.13.C.Plugin,Win32.BO2K.plugin</p>
<h2>Overview BO2K.Plugin</h2>
<p><strong>BO2K.Plugin</strong> the typical representative <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=12"  title="Remove Backdoor">Backdoor</a>.This spyware spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system BO2K.Plugin generates in memory unique identifiers.Usually enough is updated and varies.BO2K.Plugin is unsafe and can lead to loss of the data and make your system infirmity.</p>
<h2>How to Remove BO2K.Plugin from Your computer?</h2>
<p>In order to completely <b>delete BO2K.Plugin</b> from your PC it is necessary to remove all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to remove BO2K.Plugin independently manually.For adware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to clear BO2K.Plugin Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to delete BO2K.Plugin from the Windows Registry</a>.In sections Files  BO2K.Plugin and Folders  BO2K.Plugin complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  BO2K.Plugin </p>
<h2 id="delete-virus-files">How to clear BO2K.Plugin Files (.dll, .sys, .exe, .com, .bin etc.).</h2>
<p>All files and directories associated with BO2K.Plugin are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To clear completely BO2K.Plugin must delete all the files.</p>
<p>To remove files and folders associated with BO2K.Plugin execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is impossible (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To clear locked file, select it and press the right button of the mouse, then select Send To-> delete on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for BO2K.Plugin</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to remove BO2K.Plugin from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, malware, adware, and spyware (including BO2K.Plugin) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively remove BO2K.Plugin from your Windows registry, you must delete all the registry keys and values associated with BO2K.Plugin.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The amenability for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is necessary to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to delete the BO2K.Plugin registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To delete the keys, associated with BO2K.Plugin, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To remove the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for BO2K.Plugin</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>BO2K.Plugin Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=12"  title="Remove Backdoor">Backdoor</a></p>
<h2>How Did My PC Get Infected with BO2K.Plugin?</h2>
<p>One of the most common questions found when cleaning BO2K.Plugin is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get BO2K.Plugin in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your PC clean and running securely:</p>
<p>If you acquire an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be BO2K.Plugin. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you acquire an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual PC user, you will almost never receive a valid attachment of this type.</p>
<p>If you receive an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>BO2K.Plugin</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get BO2K.Plugin on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to adult sites.The fact is that a large amount of <b>malware</b> (including BO2K.Plugin) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be BO2K.Plugin too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections and BO2K.Plugin is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your PC from BO2K.Plugin.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of BO2K.Plugin</b></p>
<p>If you suspect or confirm that your PC is infected with BO2K.Plugin, obtain the current antivirus software.The following are some primary indicators that a PC may be infected:
<ul>
<li>The computer runs slower than usual.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of BO2K.Plugin.</li>
<li>Additionally, the computer does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be BO2K.Plugin. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the computer even though you did not intentionally remove the program.</li>
</ul>
<p>Note These are common signs of infection by BO2K.Plugin. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of BO2K.Plugin in e-mail messages</b></p>
<p>When a computer adware infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The BO2K.Plugin adware may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The BO2K.Plugin may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the pc.</li>
<li>The BO2K.Plugin may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including BO2K.Plugin) is a program that infects your computer and allows a hacker to run hidden tasks behind your back.</p>
<p>The BO2K.Plugin can allow total remote access to your computer by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your pc.To delete the trojan and keep others out of your computer you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate BO2K.Plugin</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>BO2K.Plugin have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your PC screen flips upside down or invertss.</b></p>
<p>When you are infected with BO2K.Plugin, hackers can make your computer screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your computer or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your PC browser goes to a strange or unknown web page by itself <b>Trojans</b>, including BO2K.Plugin, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the BO2K.Plugin allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your pc.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your PC plays recordings of things recorded in your computer room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by BO2K.Plugin, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>BO2K.Plugin can kill or startup programs on your pc.Many times your anti malware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your computer starts talking or conversing with you.</b></p>
<p>BO2K.Plugin allow the hacker to type anything that he wants to say to you in a box and then make it appear that your computer is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your PC starts reading the contents of your PC clipboard.</b></p>
<p>The hacker can make your PC speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your PC and you are forced to chat with some stranger.</b></p>
<p>The BO2K.Plugin will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your computer programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your pc.</b></p>
<p>Your computer generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your PC is IP scanning.</b></p>
<p>The hacker can use your PC to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your pc.</b></p>
<p>With the help of BO2K.Plugin hackers can find personal information about you by reading documents on your computer such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your PC is infected with BO2K.Plugin, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your computer room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your PC by itself.</b></p>
<p>Using BO2K.Plugin the hacker can change the time and date on your computer.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your computer.</p>
<p><b>Your computer speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your PC shuts down by itself.The hacker can cause your computer to shutdown if you are infected by BO2K.Plugin.</p>
<p><b>Your computer shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using BO2K.Plugin can make your computer turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your computer you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What BO2K.Plugin may do?</h2>
<p>Below are possibilities you may experience when you are infected with BO2K.Plugin. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>BO2K.Plugin may clear files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from BO2K.Plugin and this not happening again it is important that take proper care and precautions when using your computer.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your PC safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your PC has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with malware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every computer you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their malware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be BO2K.Plugin, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your computer.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-bo2kplugin-virus/feed</wfw:commentRss>
		</item>
		<item>
		<title>BO2K.plugin.Cast</title>
		<link>http://www.exterminatelab.com/remove-bo2kplugincast-virus</link>
		<comments>http://www.exterminatelab.com/remove-bo2kplugincast-virus#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:35:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Backdoor]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://antivirus/?p=9416</guid>
		<description><![CDATA[Aliases of  BO2K.plugin.Cast
 
BO2K.plugin.Cast also it is known under names [Eset]Win32/BO2K.Plugin.Cast.G trojan;[Computer Associates]Backdoor/BO2K.plugin.Cast.g1
Overview BO2K.plugin.Cast
BO2K.plugin.Cast the classical specimen Trojan, Backdoor.This virus spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system BO2K.plugin.Cast makes in memory unique identifiers.Usually enough is updated and [...]]]></description>
			<content:encoded><![CDATA[<h2>Aliases of  BO2K.plugin.Cast</h2>
<p> <!-- 1013622 -->
<p>BO2K.plugin.Cast also it is known under names [Eset]Win32/BO2K.Plugin.Cast.G trojan;[Computer Associates]Backdoor/BO2K.plugin.Cast.g1</p>
<h2>Overview BO2K.plugin.Cast</h2>
<p><strong>BO2K.plugin.Cast</strong> the classical specimen <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=12"  title="Remove Backdoor">Backdoor</a>.This virus spreads basically on wide-area networks using for infection and reproduction of vulnerability of the operating system of Windows.For definition of the presence at system BO2K.plugin.Cast makes in memory unique identifiers.Usually enough is updated and varies.BO2K.plugin.Cast is shifty and can lead to loss of the data and make your system unsteadiness.</p>
<h2>How to Remove BO2K.plugin.Cast from Your computer?</h2>
<p>In order to completely <b>remove BO2K.plugin.Cast</b> from your PC it is necessary to clear all files, folders, keys of the register of Windows and their value.For this purpose you can use <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> or try to delete BO2K.plugin.Cast independently manually.For adware removal independently you need to follow the steps described below in the sections - <a href="#delete-virus-files">How to remove BO2K.plugin.Cast Files</a> (.exe, .dll, .com, .sys, .bin etc.)and <a href="#delete-virus-registry">How to delete BO2K.plugin.Cast from the Windows Registry</a>.In sections Files  BO2K.plugin.Cast and Folders  BO2K.plugin.Cast complete lists for removal are resulted. Also you can take advantage of sections of Windows Registry Keys and Windows Registry Values for removal  BO2K.plugin.Cast </p>
<h2 id="delete-virus-files">How to delete BO2K.plugin.Cast Files (.dll, .exe, .com, .sys, .bin etc.).</h2>
<p>All files and directories associated with BO2K.plugin.Cast are below the relevant sections <a href="#files">Files</a> and <a href="#folders">Folders</a> on this page.To clear completely BO2K.plugin.Cast must remove all the files.</p>
<p>To delete files and folders associated with BO2K.plugin.Cast execute following steps:</p>
<p>Using the file explorer or file manager display all from mentioned below files and folders. Note: The paths use certain conventions such as [ %PROGRAM_FILES%]. These conventions are explained <a href="javascript:window.open('/mapping')">here</a>.Select the file or folder and press SHIFT+Delete on the keyboard. Click Yes in the confirm dialog box.</p>
<p>
<blockquote>
<p>IMPORTANT: If a file is locked (the file can be used by other application), removal is impossible (the Windows will notify you the corresponding message).</p>
</blockquote>
<p>For removal locked files take advantage RemoveOnReboot utility.To clear locked file, select it and press the right button of the mouse, then select Send To-> delete on Next Reboot on the menu and after removal restart your pc.</p>
<p>You could download RemoveOnReboot utility now <a href="/RemoveOnRebootSetup.exe">RemoveOnReboot</a></p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Files for BO2K.plugin.Cast</a></noindex></p>
<p><!-- %DELETE_VIRUS_FILES% --><br />
<h2 id="delete-virus-registry">How to clear BO2K.plugin.Cast from the Windows Registry?</h2>
<p>The Windows registry is important directory which stores system information, settings and options for Microsoft Windows operating systems. Also information about installed programs details as well as the information about the applications that are automatically run at start-up.Because this, malware, adware, and spyware (including BO2K.plugin.Cast) often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.The registry also provides a window into the operation of the kernel, exposing runtime information such as performance counters and currently active hardware.</p>
<p>If you want effectively clear BO2K.plugin.Cast from your Windows registry, you must delete all the registry keys and values associated with BO2K.plugin.Cast.They are listed in the additional sections - Registry Keys and Registry Values on this page.</p>
<blockquote><p>IMPORTANT: it should be remembered that Windows registry is a core component of your operation system, therefore we urgently recommend to make back up of registry before the removal beginning keys and values. The warning. Wrong change of parameters of the registry using the editor of the register or any different way can lead to serious problems. For their elimination operating system reinstallation can be demanded. The corporation Microsoft does not guarantee that these problems can be eliminated.</p>
</blockquote>
<p>The responsibility for changing the registry at your own risk.Back up the registry.</p>
<p>Before register editing is indispensable to export sections to which changes will be made, or to create a backup copy of all register.At occurrence of a problem it will allow to restore a former state of the register. To create a backup copy of all register, take advantage of the program of archiving for a backup of a state of system. The system state includes the register, a database of registration of classes COM + and load files.</p>
<p>Registry Editor it is possible to use for performance of following tasks: search of the subteen, section, subsection or parameter; subsection or parameter addition; change of value of parameter; subsection or parameter removal; subsection or parameter renaming. Transition Registry Editor displays the set of folders. Each folder represents a key local pc.When you view the remote computer&#8217;s registry will be visible only two standard sections: HKEY_USERS and HKEY_LOCAL_MACHINE.</p>
<p>Follow the steps below to clear the BO2K.plugin.Cast registry keys and values:</p>
<p>On the Windows Start menu, click Run. In the Open box, type regedit and click OK. Open the Registry Editor. The application consists of two panels.</p>
<p>In the left pane, presented folders that represent the registry keys, arranged in a hierarchical order. The right side shows the value selected key. To remove the keys, associated with BO2K.plugin.Cast, do the following:Locate the key in the left pane windows Registry Editor, opening folders ways described in the section Registry Keys. By selecting the correct key, click the right mouse button and in the dialog box, select Delete. Click Yes in the dialog box Confirm Key Delete. To remove the key value contained in the section Registry Values, do the following:In the right pane of Registry Editor window, click the key, highlight it and click the right mouse button. In the pop-up menu, select Delete. Click Yes in the dialog box Confirm Value Delete.</p>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >Scan your Windows Registry for BO2K.plugin.Cast</a></noindex></p>
<p><!-- %DELETE_VIRUS_REGISTRY% -->
<p>BO2K.plugin.Cast Categorized as <a target="_blank" href="http://www.exterminatelab.com/?cat=3"  title="Remove Trojan">Trojan</a>, <a target="_blank" href="http://www.exterminatelab.com/?cat=12"  title="Remove Backdoor">Backdoor</a></p>
<h2>How Did My PC Get Infected with BO2K.plugin.Cast?</h2>
<p>One of the most common questions found when cleaning BO2K.plugin.Cast is &#8220;how did my machine get infected&#8221;? There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your pc&#8217;s security settings are set too low.</p>
<h3>Practice Safe Internet</h3>
<p>One of the main reasons people get BO2K.plugin.Cast in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to use properly the Internet using security tools and good practice. Whether these things are files or sites it doesn&#8217;t really matter. If something is out to get you, and you click on it, it most likely will. </p>
<p>Below are a list of simple precautions to take to keep your computer clean and running securely:</p>
<p>If you get an attachment from someone you do not know, <b>DO NOT OPEN IT!</b>It may be BO2K.plugin.Cast. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.</p>
<p>If you receive an attachment and it ends with a .exe, .com, .bat, or .pif <b>DO NOT OPEN</b> the attachment unless you know for a fact that it is clean.For the casual computer user, you will almost never receive a valid attachment of this type.</p>
<p>If you receive an attachment from someone you know, and it looks suspicious, then it probably is.The email could be from someone you know infected with <b>BO2K.plugin.Cast</b> that is trying to infect everyone in their address book.</p>
<p>If you are browsing the Internet and a popup appears saying that you are infected, ignore it!  <b>DO NOT INSTALL</b> any software that will require to download.</p>
<p>Another tactic to get BO2K.plugin.Cast on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you.</p>
<p>Do not go to porn sites.The fact is that a large amount of <b>adware</b> (including BO2K.plugin.Cast) is pushed through these types of sites.</p>
<p>When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person&#8217;s contact list that contains a link to an infection (it may be BO2K.plugin.Cast too). Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.</p>
<p>Stay away from Warez and Crack sites! In addition to the evident copyright issues, the downloads from these sites are typically overrun with infections and BO2K.plugin.Cast is not exception.</p>
<p>Be careful of what you download off web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it.If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.</p>
<p>Visit Microsoft&#8217;s Windows Update Site Frequently</p>
<p>It is important that you visit http://www.windowsupdate.com regularly. This will ensure your PC has always the latest security updates available installed on your computer.If there are new updates to install, install them immediately, then reboot your computer, and revisit the site until there are no more critical updates.  This also protect your computer from BO2K.plugin.Cast.</p>
<h2>Symptoms of Infection</h2>
<p><b>Symptoms of BO2K.plugin.Cast</b></p>
<p>If you suspect or confirm that your PC is infected with BO2K.plugin.Cast, obtain the current antivirus software.The following are some primary indicators that a PC may be infected:
<ul>
<li>The PC runs slower than usual.</li>
<li>The PC crashes, and then it restarts every few minutes, it may be symptom of BO2K.plugin.Cast.</li>
<li>The computer restarts on its own.</li>
<li>Additionally, the computer does not run as usual.</li>
<li>Disks or disk drives are inaccessible.</li>
<li>You cannot print items correctly. </li>
<li>You see unusual error messages. </li>
<li>You see distorted menus and dialog boxes. </li>
<li>There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension, it&#8217;s may be BO2K.plugin.Cast. </li>
<li>An antivirus program is disabled for no reason. Additionally, the antivirus program cannot be restarted. </li>
<li>An antivirus program cannot be installed on the computer, or the antivirus program will not run. </li>
<li>New icons appear on the desktop that you did not put there, or the icons are not associated with any recently installed programs. </li>
<li>Strange sounds or music plays from the speakers unexpectedly.</li>
<li>A program disappears from the PC even though you did not intentionally delete the program.</li>
</ul>
<p>Note These are common signs of infection by BO2K.plugin.Cast. However, these signs may also be caused by hardware or software problems that have nothing to do with a PC virus.</p>
<p><b>Symptoms of BO2K.plugin.Cast in e-mail messages</b></p>
<p>When a PC virus infects e-mail messages or infects other files on a computer, you may notice the following symptoms:
<ul>
<li>The infected file may make copies of itself. This behavior may use up all the free space on the hard disk.</li>
<li>A copy of the infected file may be sent to all the addresses in an e-mail address list.</li>
<li>The BO2K.plugin.Cast spyware may reformat the hard disk.</li>
<li>This behavior will clear files and programs.</li>
<li>The BO2K.plugin.Cast may install hidden programs, such as pirated software. </li>
<li>This pirated software may then be distributed and sold from the pc.</li>
<li>The BO2K.plugin.Cast may reduce security. </li>
<li>This could enable intruders to access remotely the PC or the network.</li>
<li>You receive an e-mail message that has a strange attachment. When you open the attachment, dialog boxes appear, or a sudden degradation in system performance occurs. </li>
<li>Someone tells you that they have recently received e-mail messages from you that contained attached files that you did not send. The files that are attached to the e-mail messages have extensions such as .exe, .bat, .scr, and .vbs extensions.  </li>
</ul>
<p><!--IF TROJAN --><br />
<h3>Trojan Infection Symptoms</h3>
<p>A trojan horse (including BO2K.plugin.Cast) is a program that infects your PC and allows a hacker to run hidden tasks behind your back.</p>
<p>The BO2K.plugin.Cast can allow total remote access to your PC by a third party.</p>
<p>If you have experienced any of the following symptoms, you are infected with an Internet Trojan and hackers have invaded your computer.To delete the trojan and keep others out of your computer you could purchase the <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>.</p>
<h3>Symptoms That Indicate BO2K.plugin.Cast</h3>
<p>If you experience any of the following symptoms, you have been infected by one of the most dangerous type of individuals. These non-stealth hackers are known to destroy data and crash computers when they grow tired of playing their games.</p>
<p><b>Your CD-ROM drawer opens and closes by itself</b></p>
<p>BO2K.plugin.Cast have the ability to open and close your CD-ROM drawer.</p>
<p><b>Your PC screen flips upside down or invertss.</b></p>
<p>When you are infected with BO2K.plugin.Cast, hackers can make your computer screen blink, flip upside down or invert it so that everything is displayed backwards.</p>
<p><b>Your wall paper or background settings change by themselves </b></p>
<p>The non-stealth type of hacker may change your default background or wall paper settings. Many times this will be done by using a picture found on your computer or one uploaded by the hacker.</p>
<p><b>Documents or messages print on your printer by themselves</b></p>
<p>Since the hacker has total access to your computer, he can access your printer and print personal messages to you or print documents found in your folders.</p>
<p><b>Problems with your browser</b></p>
<p>Your PC browser goes to a strange or unknown web page by itself <b>Trojans</b>, including BO2K.plugin.Cast, allow the hacker to launch your web browser and go to any web page that they preselected.</p>
<p><b>Your windows color settings change by themselves</b></p>
<p>When infected, the BO2K.plugin.Cast allows the hacker to change your Windows color settings to any colors of their choice.</p>
<p><b>Your screen saver settings change by themselves</b></p>
<p>Often, the non-stealth hacker will set your screen saver with a personal scrolling message to you.</p>
<p><b>Your right and left mouse buttons reverse their functions</b></p>
<p>Often, the hacker makes your mouse buttons switch around. The right click now does what the left click did and the left click takes on the functions that the right click used to have.</p>
<p><b>Your mouse pointer disappears</b></p>
<p>Sometimes the hacker will completely turn off your mouse. Then, your mouse pointing arrow completely disappears.</p>
<p><b>Your mouse moves by itself</b></p>
<p>The hacker can take control of your mouse pointer and click on icons and start programs as if he were sitting in your chair in front of your pc.</p>
<p><b>Your mouse starts leaving trails</b></p>
<p>The hacker can change your mouse configuration to make it leave mouse trails as you move it.</p>
<p><b>Your computer plays recordings of things recorded in your PC room.</b></p>
<p>If you have a microphone connected to your computer, the hacker can record and listen to what is going on in the room. Sometimes the non-stealth hacker will play the sound file back when he knows you are in the room.</p>
<p><b>Your sound volume changes by itself</b></p>
<p>Sometimes the hacker will turn your sound volume all the way up or down to attract your attention.</p>
<p><b>Your Windows Start button disappears</b></p>
<p>Once infected by BO2K.plugin.Cast, the hacker can make your Windows start button hidden from your view.</p>
<p><b>Programs load or unload by themselves</b></p>
<p>BO2K.plugin.Cast can kill or startup programs on your pc.Many times your anti malware is unloaded and then parts of it are altered or deleted.</p>
<p><b>Your computer starts talking or conversing with you.</b></p>
<p>BO2K.plugin.Cast allow the hacker to type anything that he wants to say to you in a box and then make it appear that your PC is talking to you.Many times this feature is used along with the web cam and sound option so that the hacker can see and hear you as he converses.</p>
<p><b>Your computer starts reading the contents of your PC clipboard.</b></p>
<p>The hacker can make your computer speak the text contained in your clipboard and insert new text into your windows clipboard.</p>
<p><b>Strange chat boxes appear on your computer and you are forced to chat with some stranger.</b></p>
<p>The BO2K.plugin.Cast will allow the hacker to bring up a square black chat box when you can not do anything else but type into this box. The hacker may talk back to you, or just leave this box up to block you from accessing your PC programs while he undermines what you are doing.</p>
<p><b>Strange Windows Warning, Info, error, or question boxes appear on your computer.</b></p>
<p>Your PC generates strange warning or question boxes.Many times these are personal messages directed directly to you and asking you a question with Yes or No or Ok buttons for you to click.</p>
<p><b>You get complaints from your ISP that your computer is IP scanning.</b></p>
<p>The hacker can use your computer to attack, send email or scan for other infected computers.You could then even get an email from your Internet service provider warning you that your account will be terminated if the activity continues.</p>
<p><b>People that you are chatting with know too much personal information about you or your pc.</b></p>
<p>With the help of BO2K.plugin.Cast hackers can find personal information about you by reading documents on your PC such as a resume, financial records, personal letters, etc.</p>
<p><b>Other people can read your private IRC or ICQ messages</b></p>
<p>While your PC is infected with BO2K.plugin.Cast, the hacker can not only see everything that you type, but every message sent to you via programs such as ICQ, IRC, AIM and yahoo pager.If someone that you are talking to seems to know what others are talking to you about in private while using one of the chat programs above you may have been infected.</p>
<p><b>People that you are talking to can see you or know what is inside your computer room.</b></p>
<p>If you have a webcam, the hacker can turn it on without your knowledge and watch you as well as see things in the background of the webcam.</p>
<p><b>Your time and date change on your computer by itself.</b></p>
<p>Using BO2K.plugin.Cast the hacker can change the time and date on your computer.Often this is done it is to catch your attention and changed to the extreme.You can then expect the hacker to ask you what time or date it is on your computer.</p>
<p><b>Your PC speaker starts and stops working by itself.</b></p>
<p>The hacker can turn your PC speaker on and off.  Your PC shuts down by itself.The hacker can cause your PC to shutdown if you are infected by BO2K.plugin.Cast.</p>
<p><b>Your PC shuts down and powers off by itself.</b></p>
<p>Once infected, the hacker using BO2K.plugin.Cast can make your computer turn itself off.</p>
<p><b>Your Task bar disappears </b></p>
<p>The hacker can hide your taskbar from your view.</p>
<p><b>Ctrl + Alt + Del stops working</b></p>
<p>The hacker or Trojan may disable this function so that you can not view your task list or be able to end the task on a given program or process.</p>
<p><b>When you reboot your computer you get a message telling you that there are other users still connected.</b></p>
<p>If you get a message when you reboot telling you that other users are still connected, it means that you have open file shares and someone is accessing your files. You need to put a password on your drives and shares or stop sharing files.</p>
<h2>What BO2K.plugin.Cast may do?</h2>
<p>Below are possibilities you may experience when you are infected with BO2K.plugin.Cast. Remember that you also may be experiencing any of the below issues and not have a virus.
<ul>
<li>BO2K.plugin.Cast may remove files.</li>
<li>Various messages in files or on programs.</li>
<li>Changes volume label.</li>
<li>Marks clusters as bad in the FAT.</li>
<li>Randomly overwrites sectors on the hard disk.</li>
<li>Replaces the MBR with own code.</li>
<li>Create more than one partition.</li>
<li>Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.</li>
<li>Causes cross-linked files.</li>
<li>Causes a &#8220;sector not found&#8221; error.</li>
<li>Cause the system to run slow.</li>
<li>Logical partitions created, partitions decrease in size.</li>
<li>A directory may be displayed as garbage.</li>
<li>Directory order may be modified so files, such as COM files, will start at the beginning of the directory.</li>
<li>Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.</li>
<li>Disable ports such as LPT or COM ports.</li>
<li>Caused keyboard keys to be remapped.</li>
<li>Alter the system time / date.</li>
<li>Cause system to hang or freeze randomly.</li>
<li>Cause activity on HDD or FDD randomly.</li>
<li>Increase file size.</li>
<li>Increase or decrease memory size.</li>
<li>Randomly change file or memory size.</li>
<li>Extended boot times.</li>
<li>Increase disk access times.</li>
</ul>
<h2>How to protect yourself in the future?</h2>
<p>In order to protect yourself from BO2K.plugin.Cast and this not happening again it is important that take proper care and precautions when using your pc.Make sure you have updated  ExterminateIt  running, all the latest updates to your operating system, a firewall, and only open attachments or click on popups that you know are safe. These precautions can be a tutorial unto itself, and luckily, we have one created already: </p>
<p>Simple and easy ways to keep your computer safe and secure on the Internet.</p>
<p><b>Make your Internet Explorer 6 and below more secure.</b>From within Internet Explorer click on the Tools menu and then click on Options. </p>
<ul>
<li>Click once on the Security tab.</li>
<li>Click once on the Internet icon so it becomes highlighted.</li>
<li>Click once on the Custom Level button.</li>
<li>Change the Download signed ActiveX controls to Prompt.</li>
<li>Change the Download unsigned ActiveX controls to Disable.</li>
<li>Change the Initialize and script ActiveX controls not marked as safe to Disable.</li>
<li>Change the Installation of desktop items to Prompt.</li>
<li>Change the Launching programs and files in an IFRAME to Prompt.</li>
<li>Change the Navigate sub-frames across different domains to Prompt.</li>
<li>When all these settings have been made, click on the OK button.</li>
<li>If it prompts you as to whether or not you want to save the settings, click on  Yes button.</li>
<li>Next press the Apply button and then the OK to exit the Internet Properties page.</li>
</ul>
<p><noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/softsell/nph-softsell.cgi?item=16843-2&#038;affiliate=349259" >Buy ExterminateIt Now</a></noindex>
<p>It is very important that your computer has an anti-virus software running on your machine (you could free download <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex>).This alone can save you a lot of trouble with spyware in the future.</p>
<p>We can&#8217;t stress strongly enough how important it is for you to do five things for every PC you own:Secure your e-mail client against running unwanted scripts. If you use Outlook or Outlook Express and have not secured them.</p>
<p>Scan your computers by <noindex><a target="_blank" rel="nofollow" href="http://www.exterminatelab.com/goto/http://www.regnow.com/trialware/download/Download_ExterminateItSetup-swpl.exe?item=16843-2&#038;affiliate=349259" >ExterminateIt</a></noindex> at least weekly to make sure they aren&#8217;t harboring viruses or worms.</p>
<p>Keep your  ExterminateIt  software up-to-date. AntiVirus software vendors update their adware lists on a regular basis.Make sure you visit your vendor&#8217;s Web site at least once a week to download the update.</p>
<p>Avoid running attachments (especially .EXE files) that come in your e-mail it may be BO2K.plugin.Cast, even if they come from your friends, relatives or colleagues. The warped minds now writing e-mail viruses will do their best to lure you into running their viruses and worms by making them look like love letters, jokes or pornography. Once you or one of your friend succumbs to this temptation, the script will mail itself to everyone on that computer&#8217;s address list.</p>
<p>Make frequent backups of your data files, and keep some of your backups out of your computer.We like to burn CD-R backup discs on a regular schedule; CD-RW and Zip discs also work well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exterminatelab.com/remove-bo2kplugincast-virus/feed</wfw:commentRss>
		</item>
	</channel>
</rss>

