<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lair360 Blog &#187; Virus Removal</title>
	<atom:link href="http://lair360.co.uk/blog/category/computer-security/virus-removal/feed/" rel="self" type="application/rss+xml" />
	<link>http://lair360.co.uk/blog</link>
	<description></description>
	<lastBuildDate>Sun, 25 Jul 2010 14:35:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>How to remove sdra64.exe from your systems</title>
		<link>http://lair360.co.uk/blog/740/how-to-remove-a-exe-b-exe-and-sdra64-exe-from-your-systems/</link>
		<comments>http://lair360.co.uk/blog/740/how-to-remove-a-exe-b-exe-and-sdra64-exe-from-your-systems/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 12:41:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[a.exe]]></category>
		<category><![CDATA[b.exe]]></category>
		<category><![CDATA[sdra64]]></category>

		<guid isPermaLink="false">http://lair360.co.uk/blog/?p=740</guid>
		<description><![CDATA[Version: 16c Revision: 42 Build 113 How to remove sdra64.exe from your systems Introduction: when I was testing these malware on my crappy computer, I’ve found a slight weakness on these infected malware: “a.exe, b.exe and sdra64.exe”. It seems to download other stuff from the web and installed them into your systems without your permission. [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Version: 16c<br />
Revision: 42 Build 113<br />
<br />
How to remove sdra64.exe from your systems<br />
<br />
Introduction:</strong> when I was testing these malware on my crappy computer, I’ve found a slight weakness on these infected malware: “a.exe, b.exe and sdra64.exe”. It seems to download other stuff from the web and installed them into your systems without your permission. But,  it’s a total nightmare, as I have to spend my five hours to remove these parasites from eating your computer!<br />
<br />
Right, lets get yourself ready and print this document from another machine, if the infected files had removed your Wireless / LAN connections. But, you got to read these instruction carefully and don’t rush yourself! Also, I did all of these works / analysis from scratch, so you don’t have to fiddle about and get yourself frustrated. Just read this article slowly and make sure that you did it correctly…<br />
<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<br />
1.] Remove all P2P sharing software from your computer.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<strong>uTorrent<br />
Azureus<br />
eMule<br />
ect…</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<br />
<strong>Notes:</strong> most of the time the files that you had / have downloaded, they are considered as illegal-wares. They may also be bundled with malware, this could well be how you were infected. Get the point?<br />
<br />
2.] Execute Notepad.exe / Notepad++.exe from your computer and copy these codes. After that, you’ll need to go to: <strong>“File >> Save As >> Type: Fix-XP.bat”</strong>.<br />
You will also need to change the “Save as type to all files” and save it to your desktop.</p>
<pre class="brush: php;">
@echo off
copy C:\WINDOWS\ServicePackFiles\i386\eventlog.dll c:\eventlog.dll
Exit
</pre>
<pre class="brush: php;">
@echo off
copy C:\WINDOWS\system32\dllcache\scecli.dll c:\scecli.dll
Exit
</pre>
<p>3.] Double-click on Fix-XP.bat and let it repair your Eventlog Services.<br />
<br />
4.] At this point, you’ll need to download: “The Avenger” by Swandog46 to your Desktop.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
- Right click on the Zip folder and select &#8220;Extract All&#8230;&#8221;<br />
- Follow the prompts and extract Avenger to your desktop<br />
</p>
<p>http://swandog46.geekstogo.com/avenger2</p>
<p>
5.] Copy these codes and paste these into Avenger – Script Box. However, if you’re using the second script, which is shown in “Step 2”, then, you’ll need to copy the second one. But, please don’t use both, or else, there will be some confusion on your system.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<pre class="brush: php;">
Begin copying here:
Files to move:
c:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll
</pre>
<pre class="brush: php;">
Begin copying here:
Files to move:
c:\scecli.dll | C:\WINDOWS\system32\scecli.dll
</pre>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<br />
6.] Click on Execute<br />
<br />
7.] Answer &#8220;Yes&#8221; twice when prompted.<br />
<br />
<strong>Notes:</strong> just to let you know: The system will restart twice. But, you don’t have to panic… its normal…<br />
<br />
8.] Download ComboFix from these website and rename the application before you download!<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
If you are using Firefox, make sure that your download settings are as follows:<br />
<br />
    * Tools >> Options >> Main tab<br />
    * Set to &#8220;Always ask me where to Save the files&#8221;.<br />
</p>
<p>http://www.forospyware.com/sUBs/ComboFix.exe</p>
<p>http://download.bleepingcomputer.com/sUBs/ComboFix.exe</p>
<p>http://www.combofix.org/download.php</p>
<p>
<strong>Important:</strong> You’ll need to rename ComboFix into Combo-Fix.<br />
Also, It is important that you rename Combofix during the download, but not after.<br />
<br />
<strong>Warning:</strong> Before you continue, please disable your anti-virus, script blocker and any anti-malware (real-time) protection before the scan. These security application may interfere with ComboFix or remove some of its embedded files which may cause &#8220;irregular results&#8221;. Also, please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.<br />
<br />
9.] Double click on combo-Fix.exe &#038; follow the prompts.<br />
<br />
10.] When everything is done, Combofix will generate a Text file that contains your removal.<br />
<br />
11.] Now, you’ll need to copy these scripts and save it to your desktop.<br />
<br />
<strong>File Saved As:</strong> CFScript.txt<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<pre class="brush: php;">
Collect::
c:\windows\svchasts.exe
c:\windows\system32\desote.exe
c:\windows\ucyzy.dat
c:\program files\Common Files\wapibosogi.lib
c:\AutoRun.vbs
c:\windows\Fonts\AcadEref.ttf
c:\windows\Installer\c62d6.msp
c:\windows\system32\drivers\rotscxltmrssww.sys
c:\windows\system32\drivers \_rotscxltmrssww_.sys.zip
c:\windows\system32\rotscxobwwavmy.dll
c:\windows\system32\rotscxoqfqjruf.dat
c:\windows\system32\rotscxqoeniplv.dat
c:\windows\system32\rotscxylltpkql.dll
c:\windows\system32\twain.dll
c:\windows\braviax.exe
c:\windows\cru629.dat
c:\windows\Installer\550c37.msi
c:\windows\oqixovevu.scr
c:\windows\orabuj.inf
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\documents and settings\All Users\Documents\cejik.sys
c:\documents and settings\All Users\Documents\koqely.reg
c:\documents and settings\All Users\Documents\oqijatuzu.exe
c:\documents and settings\All Users\Documents\qyxazemose.exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\minix32.exe
c:\windows\system32\sdra64.exe
c:\windows\system32\sonhelp.htm
c:\windows\system32\sysnet.dat
c:\windows\system32\tapi.nfo
c:\windows\system32\userini.exe

Folder::
c:\program files\Windows Police Pro

DirLook::
c:\program files\awesome
C:\b624c1897f972641605426d99d3538

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
&quot;c:\\Program Files\\Viewpoint\\Common\\ViewpointService.exe&quot;=-
&quot;c:\\Program Files\\uTorrent\\uTorrent.exe&quot;=-

RegNull::
[HKEY_USERS\S-1-5-21-2186207459-4142083742-1883771569-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{AF49AC62-35CC-90AD-1EC3-2AE9C244CBB5}*]
</pre>
<p>12.] Drag CFScript.txt into Combo-Fix.exe<br />
<br />
<strong>Notes:</strong> When Combofix finishes running, there will be a log that pops – up. Please don’t be alarmed! It’s normal for ComboFix…<br />
<br />
13.] Download OTL from these website…<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>http://oldtimer.geekstogo.com/OTL.exe</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<br />
14.] Run the program and paste these codes into the “Custom Scans/Fixes” box.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<pre class="brush: php;">
:OTL
SRV - (RDPRGOSK [Disabled | Stopped]) -- File not found
[2009/08/28 17:01:10 | 00,017,976 | ---- | M] () -- C:\WINDOWS\ugyl.db
[2009/08/28 17:01:10 | 00,014,776 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\okebihyk.db
[2009/08/28 17:01:10 | 00,013,269 | ---- | M] () -- C:\Documents and Settings\tim\Application Data\epujap.db
[2009/08/28 17:01:10 | 00,012,616 | ---- | M] () -- C:\Documents and Settings\tim\Local Settings\Application Data\ybopot.lib

:Services

:Reg

:Files

:Commands
[purity]
[emptytemp]
[Reboot]
</pre>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<br />
15.] Click the Run Fix button which is located at the top – left – corner.<br />
<br />
<strong>Notes:</strong> let the program run; reboot the PC when it is done.<br />
<br />
16.] Download Malwarebytes from these links and follow the prompts.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>http://www.malwarebytes.org/mbam-download.php</p>
<p>http://www.softpedia.com/get/Antivirus/Malwarebytes-Anti-Malware.shtml</p>
<p>
<strong>Notes:</strong> please do a deep scan and make sure that your database is up-to-date!<br />
Also, If it asked you to restart the computer, please do so immediately.<br />
<br />
17.] Last and not least, please copy these codes and save it as: <strong>CFScript.txt</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<pre class="brush: php;">
KillAll::

File::
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\FGQ0JB3M\111_[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\PH0SB3VN\lexus111[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QIS2LMNX\file[1].exe

Reboot::
</pre>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<br />
18.] Drag the scripts into Combo-Fix.exe<br />
<br />
19.] Now, you’ll need to cleanup your computer. But, don’t worry, you’re nearly there!<br />
<br />
-	Click Start >> Run >> Type: Combofix /u<br />
-	Click OK<br />
<br />
20.] Go back and look for OLT. Then, double-click on OTL.exe and run it.<br />
<br />
21.] Click on the <strong>CleanUp!</strong> Button.<br />
<br />
<strong>Notes:</strong> you will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.<br />
<br />
22.] Finish!<br />
<br />
<em>Good Work! You have done a great job!!</em><br />
<br />
<strong>Copyrighted By Lair360</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://lair360.co.uk/blog/740/how-to-remove-a-exe-b-exe-and-sdra64-exe-from-your-systems/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to remove System32.exe and Userinit.exe</title>
		<link>http://lair360.co.uk/blog/739/how-to-remove-system32-exe-and-userinit-exe/</link>
		<comments>http://lair360.co.uk/blog/739/how-to-remove-system32-exe-and-userinit-exe/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 12:33:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[csrss]]></category>
		<category><![CDATA[Explorer.exe]]></category>
		<category><![CDATA[System32]]></category>
		<category><![CDATA[Userinit]]></category>

		<guid isPermaLink="false">http://lair360.co.uk/blog/?p=739</guid>
		<description><![CDATA[Version: 52.8 Revision: 68 Build 16 How to remove System32.exe and Userinit.exe Introduction: This virus was design by a Vietnamese citizen. He is a criminal &#8211; hacker who is trying to distribute fake files to corrupt other user’s computer and your system32 sub &#8211; directories. Part One: remove Userinit.exe and System32.exe &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; 1.] Download Avira [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Version: 52.8<br />
Revision: 68 Build 16<br />
<br />
How to remove System32.exe and Userinit.exe<br />
<br />
Introduction:</strong> This virus was design by a Vietnamese citizen. He is a criminal &#8211; hacker who is trying to distribute fake files to corrupt other user’s computer and your system32 sub &#8211; directories.<br />
<br />
<strong>Part One: remove Userinit.exe and System32.exe</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
1.] Download Avira Anti-Virus [Free Edition].<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>http://avira.com</p>
<p>http://softpedia.com</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<br />
2.] Execute the application and scan your computer.<br />
But, if you want to do it faster, you can go to these directories.<br />
<br />
Right click on these folders and scan it with Avira.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
C:\Windows\<br />
C:\Windows\System32<br />
C:\Windows\System32\System32.exe<br />
C:\windows\system32\dllcache\win32\winlogon.exe<br />
C:\windows\system32\dllcache\win32\csrss.exe<br />
<br />
<strong>Notes:</strong> let the software kill all of the process. But, don’t hit the ignore button!<br />
Also, please don’t forget to hit the delete button when the scan – engine has found the infected file!<br />
<br />
3.] Erase all of these folders in your USB stick with Avira.<br />
However, if you leave it alone, it’s going to regenerate the virus &#8211; that would mean: you’ll need to repeat step five!<br />
<br />
<strong>Part Two: modify windows Shell and Userinit.exe registry</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<br />
<strong>Warning:</strong> once you reboot without userinit.exe and system32.exe, windows cannot access windows successes &#8211; fully!<br />
So, please don’t stop and wonder off at stage three…<br />
<br />
<strong>Notes:</strong> to locate these files, please follow these instructions.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
a.] In “Folder Option,” just hit the “View” tab and un – tick or select these options.<br />
<br />
Hidden files and folders >> select: Show hidden files and folders.<br />
Hidden files and folders >> un – tick: Hide protected operating system files (Recommended).<br />
<br />
Items to be removed from USB memory sticks.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Autorun.inf<br />
Secret.exe<br />
Phimnguoilon.exe / Phim nguoi lon.exe<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<br />
4.] Fix the registry location within these directories…<br />
<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
<br />
a.] Click on Userinit (REG_SZ)<br />
b.] Right click and select “Modify…”<br />
c.] Change the directories.<br />
<br />
<strong>Important:</strong> Please include the trailing comma. But, please be aware that ‘Windows’ was installed in C:\Windows; Userinit.exe file is actually present in the System32 folder. You may want to verify that as well.<br />
<br />
<strong>Wrong: C:\Windows\userinit.exe<br />
Right: C:\Windows\System32\userinit.exe,</strong><br />
<br />
<strong>Important:</strong> You must make sure that the registry location and directory is correct before the initial reboot. But, if you left it UN – changed; the windows logon and access is completely disabled. So, please double check before you hit the “Restart” button!!<br />
<br />
<strong>Advice:</strong> For better performances, you can also put ‘Userinit.exe’ into this registry location. It will boot faster after reboot.<br />
<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Winlogon<br />
<br />
a.] Go to Start >> Run and insert: regedit.<br />
b.] Direct yourself to the correspondent registry location.<br />
c.] At the left panel, just look for ‘Winlogon’ and move your mouse to the right panel.<br />
d.] Right click and Select New >> String Value<br />
e.] Rename it as &#8216;Userinit&#8217; – without the quotes.<br />
f.] Right click on your new registry – strings and select: Modify<br />
g.] Copy the &#8216;value data&#8217; which is shown underneath…<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<strong>C:\Windows\System32\userinit.exe,</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<br />
<strong>Important:</strong> Please include the trailing comma. But, please be aware that ‘Windows’ was installed in C:\Windows; Userinit.exe file is actually present in the System32 folder. You may want to verify that as well.<br />
<br />
h.] Paste the data; click ‘OK’ and exit the registry.<br />
<br />
After reboot, use iobit windows care personal and CCleaner to repair, clean and remove all the junk files.<br />
<br />
5.] Reboot and run Avira again.<br />
<br />
<strong>Warning:</strong> please check your registry entries (again) for any changes and repeat step four to step five. But, you don’t have to run the anti-virus again.<br />
<br />
Part Three: double check your folders for &#8220;system32.exe and csrss.exe&#8221;<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<strong>Problems:</strong> For most users, they also got one of their ‘Shell’ registry infected with a file called: System32.exe. To solve this problem, please continue and clear this hidden virus.<br />
<br />
1.] Since Avira removed this file: System32.exe = &#8220;C:\Windows\System32\system32.exe,&#8221; you have to go to the registry and fix the location. But, don’t you even dare delete the registry entries!!<br />
<br />
a.] Click Start >> Run >> Type: regedit >> Click OK or press Enter.<br />
b.] Navigate through the registry folders and look for this registry location…<br />
<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\<br />
<br />
<strong>Notes:</strong> look for a file called: “Shell” [without the quotes].<br />
<br />
2.] Right click on the value; select modify; delete the entire line from &#8220;Shell&#8221; and copy this to your registry: explorer.exe<br />
<br />
3.] After this process, please reboot your computer ‘again’ and let the new setting take effect!<br />
<br />
4.] Your computer is ready to go!<br />
<br />
<strong>Background history of &#8220;csrss.exe&#8221;</strong><br />
<br />
<strong>Introductions:</strong> firstly, the ‘csrss.exe’ file, it should be in: “C:\Windows\System32\” or “C:\Windows\system32\dllcache.” However, it shouldn’t be in the ‘config’ directory and this directory: “C:\windows\system32\dllcache\win32\csrss.exe” or anywhere else…<br />
<br />
<strong>Notes:</strong> Please change the directories on these registry locations to the correct links….<br />
<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
Userinit = ‘C:\Windows\System32\userinit.exe,’ (REG_SZ)<br />
<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
Shell= “explorer.exe” (REG_SZ)<br />
<br />
<strong>Notes:</strong> If these directories are missing, please re-create them.<br />
<br />
These are the registry to delete…<br />
<br />
1.] Go to this directory: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\&#8230;<br />
<br />
2.] Look under “Image File Execution Options” folders and locate this sub-folder: “explorer.exe” [without the quotes]<br />
<br />
<strong>Notes:</strong> It creates sub-key “explorer.exe” and the value under it:<br />
Debugger=c:\windows\csrss.exe<br />
<br />
3.] Delete it!<br />
<br />
<strong>Optional – Part four: use ComboFix.exe to fix / remove other viruses</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
1.] Download ComboFix from these links…<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
ComboFix: http://www.combofix.org/<br />
Mirror: http://subs.geekstogo.com/ComboFix.exe<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<br />
2.] Make a folder in your C:\ drive.<br />
3.] Drag your ComboFix.exe into that folder.<br />
4.] Disable all anti-virus application, anti-spyware application and all software that has HIPS function.<br />
<br />
<strong>Notes:</strong> if you want to safely disable their system guard for ComboFix.exe to clean your computer, I would recommend you to disable it in: “Computer Management” consol.<br />
<br />
Click Start >> Right click: My Computer >> Select: Manage >> Services and Applications >> Services<br />
<br />
5.] Double check your security guards to see if it’s disabled. After that, just execute ComboFix.<br />
<br />
<strong>Notes:</strong> ComboFix will warn you if you haven&#8217;t disable the security guards. But, click Ok if you already disabled the Shield&#8230;<br />
<br />
6.] The scanner will trigger another box which contains a list of infected files.<br />
<br />
7.] After the scan, it will ask you to reboot your computer. All you need to do is click the &#8220;Ok&#8221; button or hit the &#8220;Enter&#8221; key (on your keyboard).<br />
<br />
8.] After reboot, just don&#8217;t touch anything and let it remove these parasite!<br />
The files which will be remove are shown in combofix.<br />
<br />
9.] When everything is cleared and dusted, you&#8217;ll need to wait for a while.<br />
This is because; the application is generating a &#8216;Log.txt&#8217; file about ComboFix removal process.<br />
<br />
20.] Install CCleaner and clear your Internet Explorer + Firefox temporary files and internet system cache.<br />
<br />
<strong>Part five: remove ComboFix.exe from your computer</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
1.] Click Start >> Run >> Type: Combofix /u<br />
2.] Click Ok or press &#8220;Enter&#8221; on your keyboard<br />
3.] Disable your System Restore and re-enable it&#8230;<br />
4.] Re-activate your ‘System Shield’ and reboot your computer.<br />
5.] Finish!<br />
<br />
<strong>Copyrighted by Lair360</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://lair360.co.uk/blog/739/how-to-remove-system32-exe-and-userinit-exe/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to remove windowsclick infection</title>
		<link>http://lair360.co.uk/blog/738/how-to-remove-windowsclick-infection/</link>
		<comments>http://lair360.co.uk/blog/738/how-to-remove-windowsclick-infection/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 12:23:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[combofix]]></category>
		<category><![CDATA[UAC]]></category>
		<category><![CDATA[UACtnfmndkx.sys]]></category>
		<category><![CDATA[windowsclick infection]]></category>

		<guid isPermaLink="false">http://lair360.co.uk/blog/?p=738</guid>
		<description><![CDATA[Version: 39.2 Revision: 46 Build 154 How to remove windowsclick infection Introduction: this malware had infected my machine and I didn&#8217;t notice it. But, when I was surfing Google website with Firefox, the links had redirected my current website to a nasty website that served fake anti-virus. Right, lets get to work and get this [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Version: 39.2<br />
Revision: 46 Build 154<br />
<br />
How to remove windowsclick infection<br />
<br />
Introduction:</strong> this malware had infected my machine and I didn&#8217;t notice it. But, when I was surfing Google website with Firefox, the links had redirected my current website to a nasty website that served fake anti-virus.<br />
<br />
Right, lets get to work and get this out of your system before it is too late!<br />
<br />
1.] Download these software with &#8220;Firefox&#8221; and save it to your C:/ drive.<br />
<br />
<strong>Important:</strong> please look at ComboFix procedure if everything else fails.<br />
After the repair, please follow this guide, again, for a complete scan and removal.<br />
<br />
<strong>Notes:</strong> if you&#8217;re using Firefox as your main &#8211; browser, you&#8217;ll need to right &#8211; click and open a new tab. If you don&#8217;t, the actual malware will redirect you to a new link.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
<strong>Avira Free Edition:</strong> http://www.avira.com/en/pages/index.php<br />
<strong>Mirror:</strong> http://filehippo.com/download_antivir/<br />
<br />
<strong>ComboFix:</strong> http://www.combofix.org/<br />
<strong>Mirror:</strong> http://subs.geekstogo.com/ComboFix.exe<br />
<strong>Mirror:</strong> http://www.forospyware.com/sUBs/ComboFix.exe<br />
<strong>Mirror:</strong> http://download.bleepingcomputer.com/sUBs/ComboFix.exe<br />
<br />
<strong>SpywareTerminator:</strong> http://spywareterminator.com<br />
<br />
<strong>CCleaner:</strong> http://filehippo.com/download_ccleaner/<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<br />
<strong>Part One: remove Trojan.Agent.RL and RKIT/TDss.eyj.xxx</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
2.] Install SpywareTerminator and Avira.<br />
3.] Update their database.<br />
<br />
<strong>Notes:</strong> if you encounter an error with SpywareTerminator Shield, please ignore it and use the scanner&#8230;<br />
<br />
4.] Do a &#8220;Quick Scan&#8221; (Fast Spyware Scan) with SpywareTerminator.<br />
5.] Remove all infected files and this file: CmdLineExt03.dll<br />
6.] Exit Spywareterminator and click on Avira Anti-Virus. The application is located on your window&#8217;s taskbar (red umbrella icon).<br />
7.] Double click on the application and select: Local Protection >> Scanner >> Rootkit Search<br />
8.] Select all available drive and run the scan&#8230;<br />
<br />
<strong>Notes:</strong> if the application asked you for permission, just select &#8220;Quarantine&#8221; and continue.<br />
<br />
<strong>Similar Infected file&#8230;<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</strong><br />
c:\windows\system32\uacrvkuvdgg.dll<br />
c:\windows\system32\drivers\uaccseutoro.sys<br />
<strong>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</strong><br />
<br />
9.] When Avira finished removing the following &#8220;backdoor-rootkit&#8221; infection, just click no and cancel the reboot operation&#8230;<br />
<br />
10.] Right click on Avira and disable &#8220;AntiVir Guard&#8221;.<br />
<br />
<strong>Advice:</strong> press Crtl + Alt + Del to bring up the process menu. After that, just select the second tab and look this processes: Avguard.exe. But, don&#8217;t worry about the errors&#8230;its only for ComboFix procedure&#8230;<br />
<br />
<strong>Notes:</strong> leave your internet connection as &#8220;Enable&#8221; for ComboFix.exe<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<br />
<strong>Part Two: remove UACcseutoro.sys and acovcnt.exe</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
11.] Make a folder in your C:/ drive.<br />
12.] Drag your ComboFix into that folder and rename it as: FixCombo.exe.<br />
<br />
<strong>Notes:</strong> if it doesn&#8217;t work, please use this method for execution!<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Right click on the actual link and click: &#8220;Save Link As&#8221;. After that, you&#8217;ll need to rename the file into one of these names. However, if that doesn&#8217;t work, just make it up&#8230;<br />
<br />
Renamed files: tool.exe | Fixfile.exe | toolb.exe | FixCombi.exe | FixCombo.exe<br />
<br />
13.] Execute the application.<br />
14.] ComboFix will warn you if you haven&#8217;t disable Avira. But, click Ok if you already disable Avira&#8217;s Shield.<br />
15.] The scanner will trigger another box which contains a list of infected files. The list will look like this&#8230;<br />
<bold>Notes:</bold> I&#8217;ve put two different list. This is because, the malware can change its name with random characters. But, they can be detected by combofix without any problems&#8230;<br />
<br />
c:\windows\system32\acovcnt.exe<br />
c:\windows\system32\drivers\UACcseutoro.sys<br />
c:\windows\system32\UACalwoglkx.dll<br />
c:\windows\system32\UACbdkqyjia.log<br />
c:\windows\system32\UACktlsummn.log<br />
c:\windows\system32\UACndsuqqrv.log<br />
c:\windows\system32\UACplaqlmxs.dat<br />
c:\windows\system32\UACrvkuvdgg.dll<br />
c:\windows\system32\UACtfiwcpqk.dll<br />
c:\windows\system32\UACwkmlpjat.dll<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
c:\windows\system32\drivers\UACtnfmndkx.sys<br />
c:\windows\system32\tmp67.tmp<br />
c:\windows\system32\UACblevabwi.log<br />
c:\windows\system32\UACefnatakr.dll<br />
c:\windows\system32\UACfsaprdmv.dll<br />
c:\windows\system32\UACkjfmxcxi.dll<br />
c:\windows\system32\UAClwnqcbve.dat<br />
c:\windows\system32\UACnfwquyvx.log<br />
c:\windows\system32\UACrjghjnnw.log<br />
c:\windows\system32\UACsdntxukq.dll<br />
c:\windows\temp\uac52f0.tmp<br />
<br />
17.] After the scan, it will ask you to reboot your computer.<br />
All you need to do is click the &#8220;Ok&#8221; button or hit the &#8220;Enter&#8221; key (on your keyboard).<br />
<br />
18.] At the next reboot, just don&#8217;t touch anything and let it remove these pest!<br />
The files which will be remove are shown on combofix&#8230;<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
c:\documents and settings\Userfolder\Application Data\inst.exe<br />
c:\windows\a3kebook.ini<br />
c:\windows\akebook.ini<br />
c:\windows\ANS2000.INI<br />
c:\windows\AutoUpdateWin31.dll<br />
c:\windows\IE4 Error Log.txt<br />
c:\windows\system32\acovcnt.exe<br />
c:\windows\system32\drivers\UACcseutoro.sys<br />
c:\windows\system32\UACalwoglkx.dll<br />
c:\windows\system32\UACbdkqyjia.log<br />
c:\windows\system32\UACktlsummn.log<br />
c:\windows\system32\UACndsuqqrv.log<br />
c:\windows\system32\UACplaqlmxs.dat<br />
c:\windows\system32\UACrvkuvdgg.dll<br />
c:\windows\system32\drivers\UACtnfmndkx.sys<br />
c:\windows\system32\tmp67.tmp<br />
c:\windows\temp\uac52f0.tmp<br />
c:\windows\system32\UACblevabwi.log<br />
c:\windows\system32\UACefnatakr.dll<br />
c:\windows\system32\UACfsaprdmv.dll<br />
c:\windows\system32\UACkjfmxcxi.dll<br />
c:\windows\system32\UAClwnqcbve.dat<br />
c:\windows\system32\UACnfwquyvx.log<br />
c:\windows\system32\UACrjghjnnw.log<br />
c:\windows\system32\UACsdntxukq.dll<br />
c:\windows\system32\UACtfiwcpqk.dll<br />
c:\windows\system32\UACwkmlpjat.dll<br />
K:\Autorun.inf<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<br />
19.] When everything is cleared and dusted, you&#8217;ll need to wait for a while.<br />
This is because; the application is generating a &#8216;Log.txt&#8217; file about ComboFix removal process.<br />
<br />
20.] Install CCleaner and clear your Internet Explorer + Firefox temporary files and internet system cache.<br />
<br />
<strong>Part Three: remove ComboFix.exe from your computer</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
21.] Click Start >> Run >> Type: Combofix /u<br />
22.] Click Ok or press &#8220;Enter&#8221; on your keyboard<br />
23.] Disable your System Restore and re-enable it&#8230;<br />
<br />
<strong>Click Start >> Control Panel >> System >> System Restore</strong><br />
<br />
24.] Exit &#8220;System Properties&#8221; and go to &#8220;Microsoft.com&#8221; for new updates to block these threats from killing your computer&#8230;<br />
<br />
<strong>Alternative method to remove &#8220;windowsclick&#8221; if your PC is seriously infected&#8230;</strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
1.] Insert your Windows XP disk into your CD-ROM drive.<br />
2.] Wait for it to load and press: &#8216;R&#8217; to boot into the recovery console.<br />
3.] When the console is ready, press 1 if you only have one &#8220;Windows XP&#8221; installation on the harddrive, After that, just hit &#8220;Enter&#8221; (without the quotes).<br />
4.] Type in the &#8220;Administrator&#8217;s&#8221; password and hit &#8220;Enter&#8221; (without the quotes).<br />
5.] Now, you&#8217;ll need to type this command: listsvc and press &#8220;Enter&#8221; on your keyboard.<br />
6.] Look for a svc called: UACD.sys / UACd.sys<br />
7.] Press &#8220;ESC&#8221; to stop listing and go back to &#8216;cmd&#8217; prompt.<br />
8.] Now, all you need to do is type this: &#8220;disable UACd.sys&#8221; (without quotes).<br />
9.] Exit recovery console &#8211; don&#8217;t forget to take your XP CD out and reboot the computer.<br />
10.] Go back to stage &#8220;ONE&#8221; and remove this idiot virus!<br />
<br />
<strong>Copyrighted By Lair360</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://lair360.co.uk/blog/738/how-to-remove-windowsclick-infection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove sdra64.exe from your computer</title>
		<link>http://lair360.co.uk/blog/737/how-to-remove-sdra64-exe-from-your-computer/</link>
		<comments>http://lair360.co.uk/blog/737/how-to-remove-sdra64-exe-from-your-computer/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 11:55:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[combofix]]></category>
		<category><![CDATA[local.ds]]></category>
		<category><![CDATA[lowsec]]></category>
		<category><![CDATA[sdra64]]></category>
		<category><![CDATA[user.ds]]></category>

		<guid isPermaLink="false">http://lair360.co.uk/blog/?p=737</guid>
		<description><![CDATA[Version: 14.2b Revision: 15 Build 35 How to remove sdra64.exe from your computer. Introduction: when I was at my friend’s house, his computer is really unhealthy! So, I told him to get off his computer and let me handle his machine. Nevertheless, it took me hours to remove these infected files and directories. 1.] Download [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Version: 14.2b<br />
Revision: 15 Build 35<br />
<br />
How to remove sdra64.exe from your computer.<br />
<br />
Introduction:</strong> when I was at my friend’s house, his computer is really unhealthy! So, I told him to get off his computer and let me handle his machine. Nevertheless, it took me hours to remove these infected files and directories.<br />
<br />
1.] Download ComboFix from these websites and rename it as: Combo-Fix.exe.<br />
However, you don’t need to use it now. If you do, there is a chance that Combo-Fix will be shutdown!<br />
<br />
<strong>http://download.bleepingcomputer.com/sUBs/ComboFix.exe</p>
<p>http://www.forospyware.com/sUBs/ComboFix.exe</strong></p>
<p>
<strong>Warning:</strong> It’s highly recommended that you must disable all anti-virus before you use ComboFix.<br />
<br />
<strong>Notes:</strong> if you want to use ComboFix.exe, you must install Microsoft Recovery Console with your Windows XP CD. However, you must be connected to the internet to download the latest Recovery Console Updates.<br />
<br />
2.] Click on this link and download: Process Explorer &#8211; <strong>http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx</strong><br />
<br />
<strong>Notes:</strong> if the link is broken, please remove “bb896653.aspx” and find “Process Explorer”<br />
<br />
3.] Execute the program and look for this hidden process:  sdra64.exe<br />
<br />
<strong>Notes:</strong> this process hides itself under “Winlogon”.<br />
<br />
4.] Press <em>CTRL+F</em> on your keyboard and type: sdra64.exe.<br />
<br />
5.] Double click on the search results, it should be listed as winlogon. However, don’t end the actual process! You need to highlight “sdra64.exe” on the second box and end the infected process.<br />
<br />
6.] On the toolbar select Handle >> Close Handle. After that, you could delete the file.<br />
<br />
7.] Click Start >> Run >> Type: Regedit<br />
<br />
8.] Expand each folder and look for this registry location…<br />
<br />
<strong>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon</strong><br />
<br />
9.] Look for this registry key and modify with caution.<br />
<br />
<strong>Userinit = C:\WINDOWS\SYSTEM32\\Userinit.exe,C:\WINDOWS\system32\sdra64.exe,</strong><br />
<br />
- You need to delete the second part and accept the changes.<br />
<br />
<strong>Userinit = C:\WINDOWS\SYSTEM32\\Userinit.exe,</strong><br />
<br />
10.] Close the registry and rename sdra64.exe to sdra64.vir. After that, you need to use “Notepad” and make a TXT file for Combo-Fix.exe (renamed version to avoid shutdown).<br />
<br />
<strong>&#8212;&#8212;&#8212;&#8212; Copy Text &#8212;&#8212;&#8212;&#8212;&#8212;</strong></p>
<pre class="brush: plain;">
FileLook::
c:\Program Files\mb.exe

Collect::
c:\windows \system32\lowsec\local.ds
c:\windows \system32\lowsec\user.ds
c:\windows\uyuxexiv.dll
c:\windows\Kqigisucejalafo.dll
c:\windows\system32\sdra64.exe

Folder::
c:\windows\system32\lowsec
</pre>
<p><strong>&#8212;&#8212;&#8212;&#8212; End &#8212;&#8212;&#8212;&#8212;&#8212;</strong></p>
<p>11.] Save this as: “CFScript.txt”.<br />
<br />
12.] Drag the text file to Combo-Fix.exe and let it remove the infected files.<br />
<br />
<strong>Notes:</strong> your desktop may go blank. This is normal and it will return, when ComboFix is done. But, make sure that you are connected to the internet and click OK.<br />
After that, just follow the prompts for any updates.<br />
<br />
<strong>Warning:</strong> do not mouse-click combofix&#8217;s window whilst it&#8217;s running.<br />
That may cause it to stall.<br />
<br />
13.] Let the application remove the threats.<br />
All you need to do is make a cup of tea or coffee and keep an eye on your computer.<br />
<br />
14.] Check your ComboFix log files and take a look at the removal area.<br />
Make sure that the following infection is deleted.<br />
<br />
c:\windows\Kqigisucejalafo.dll<br />
c:\windows\system32\lowsec<br />
c:\windows\system32\lowsec\local.ds<br />
c:\windows\system32\lowsec\user.ds<br />
c:\windows\system32\sdra64.exe<br />
c:\windows\uyuxexiv.dll<br />
<br />
15.] Go back into the registry &#8211; library and check “userinit” for any unwanted modification.<br />
<br />
<strong>Normal:</strong>  Userinit = C:\WINDOWS\SYSTEM32\\Userinit.exe,<br />
<strong>Infected:</strong> Userinit = C:\WINDOWS\SYSTEM32\\Userinit.exe,C:\WINDOWS\system32\sdra64.exe,<br />
<br />
16.] Download CCleaner and delete all your Computer’s temporary files and internet files.<br />
<br />
17.] Reboot your computer and re-enable all of your security settings.<br />
<br />
<strong>Recommended procedure:</strong> I would suggest you to download “MalwareBytes” and do a full system scan. It’s important to keep a backup of another anti-virus. You cannot trust just one… you need 2 just to keep things low!<br />
<br />
<strong>http://www.malwarebytes.org/</strong><br />
<br />
<strong>Notes:</strong> to remove &#8216;ComboFix&#8217; from your computer, please use this command from the Run Box.<br />
<br />
<strong>Type:</strong> combofix /u<br />
<br />
18.] Finish!<br />
<br />
<strong>Copyrighted by Lair360 &#8211; 2009</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://lair360.co.uk/blog/737/how-to-remove-sdra64-exe-from-your-computer/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Kick BlockWatcher out the house!</title>
		<link>http://lair360.co.uk/blog/735/kick-blockwatcher-out-the-house/</link>
		<comments>http://lair360.co.uk/blog/735/kick-blockwatcher-out-the-house/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 10:49:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[blockwatcher]]></category>
		<category><![CDATA[combofix]]></category>
		<category><![CDATA[remove BlockWatcher]]></category>

		<guid isPermaLink="false">http://lair360.co.uk/blog/735/735/</guid>
		<description><![CDATA[Version: 11.1 Revision: 32 Build: 12 Updates: this post was revised to meet the safety &#8211; standards for all users. Kick BlockWatcher out the house! Introduction: last-night, I was analyzing a Rouge Anti-Virus. The name of the anti-virus is &#8220;BlockWatcher&#8221;. According to my research, the fake anti-virus looks exactly identical to &#8220;BlockScanner&#8221;. But, for now, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Version: 11.1<br />
Revision: 32 Build: 12<br />
<br />
Updates: this post was revised to meet the safety &#8211; standards for all users.<br />
<br />
Kick BlockWatcher out the house!<br />
<br />
Introduction:</strong> last-night, I was analyzing a Rouge Anti-Virus. The name of the anti-virus is &#8220;BlockWatcher&#8221;.<br />
<br />
According to my research, the fake anti-virus looks exactly identical to &#8220;BlockScanner&#8221;.<br />
But, for now, here is some background information, about this infection.<br />
<br />
BlockWatcher is a poorly designed security tool, but its real purpose is forcing the user into purchasing fake program. The only way &#8220;Block Scanner&#8221; differs from its ancestors is the name on the logo. If you take a look at SoftBarrier, ShieldSafeness and BlockScanner you will see that they are all identical.<br />
<br />
1.] Download these application and put them on your desktop.<br />
<br />
a.] Right click on these links and Save it As: &#8220;Combo-Fix.exe&#8221;<br />
&#8212;&#8212;&#8212;&#8212;-<br />
<strong>Link#1:</strong> http://download.bleepingcomputer.com/sUBs/ComboFix.exe<br />
<strong>Link#2:</strong> http://www.forospyware.com/sUBs/ComboFix.exe<br />
<br />
b.] Download this Ant-virus and Install it to your computer with the latest updates.<br />
&#8212;&#8212;&#8212;&#8212;-<br />
<strong>Link#1:</strong> http://www.softpedia.com/progDownload/Malwarebytes-Anti-Malware-Download-81598.html<br />
<strong>Link#2:</strong> http://www.malwarebytes.org/mbam-download.php<br />
<br />
2.] Copy this script and Save it As: &#8220;CFScript.txt&#8221;, then drop the file into the application.<br />
However, you must install &#8220;Windows Recovery Consol&#8221; for the application to work.<br />
This can be downloaded with Combofix or installing it with your Windows Disk.<br />
<br />
<strong>Warning:</strong> Before you begin, you must disable all Anti-Virus / Anti-Spyware application.<br />
This is for safety, if you&#8217;re running Combofix.</p>
<pre class="brush: plain;">
File::
c:\Documents and Settings\All Users\Desktop\BlockWatcher.lnk
c:\Program Files\BlockWatcher Software\BlockWatcher\BlockWatcher.exe
c:\WINDOWS\10068tro9zd85.exe
c:\WINDOWS\10258z9amb5t73a.bin
c:\WINDOWS\10518virzs5f9.ocx
c:\WINDOWS\temp\yxh5.tmp.exe
c:\WINDOWS\system32\yxh5.tmp.exe
c:\WINDOWS\system32\19z89s5y663.dll
c:\WINDOWS\system32\1a605tzal32359.dll
c:\WINDOWS\system32\1aa8tzi952064.cpl 

Folder::
c:\Program Files\BlockWatcher Software
c:\Program Files\BlockWatcher Software\BlockWatcher
c:\Documents and Settings\All Users\Start Menu\Programs\BlockWatcher

Registry::
[HKEY_CURRENT_USER\Software\BlockWatcher]
[HKEY_LOCAL_MACHINE\SOFTWARE\BlockWatcher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
&quot;BlockWatcher&quot;=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
&quot;BlockWatcher&quot;=-
&quot;yxh5.tmp.exe&quot;=-
</pre>
<p>3.] Let the application repair / disinfect your computer. Also, when it&#8217;s running, please avoid touching your keyboard or the switch button.<br />
<br />
4.] At this stage, you&#8217;ll need to use MalwareBytes and perform a full system scan.<br />
After that, you&#8217;ll need to download CCleaner and remove all of the junk files.<br />
<br />
<strong>Link:</strong> http://ccleaner.com<br />
<br />
5.] You&#8217;re Done!<br />
<br />
<strong>Copyrighted By Lair360</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://lair360.co.uk/blog/735/kick-blockwatcher-out-the-house/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove W32 &#8211; Explorer.exe</title>
		<link>http://lair360.co.uk/blog/655/how-to-remove-w32-explorer-exe/</link>
		<comments>http://lair360.co.uk/blog/655/how-to-remove-w32-explorer-exe/#comments</comments>
		<pubDate>Sat, 22 Aug 2009 14:51:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[Explorer.exe]]></category>
		<category><![CDATA[ExploreZip.pak]]></category>
		<category><![CDATA[WIN.INI]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[zipped_f]]></category>

		<guid isPermaLink="false">http://lair360.co.uk/blog/?p=655</guid>
		<description><![CDATA[Version: 13.2g Revision: 122 Build 12c How to remove W32 &#8211; Explorer.exe Introduction: recently, my computer was attacked by a bunch of spammers. But, guess what? One of the email had an infected attachment. So, I decided to analyze the source and write an article to revert the infection. Anyway, you don&#8217;t have to worry&#8230; [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Version: 13.2g<br />
Revision: 122 Build 12c<br />
<br />
How to remove W32 &#8211; Explorer.exe<br />
<br />
Introduction:</strong> recently, my computer was attacked by a bunch of spammers. But, guess what? One of the email had an infected attachment. So, I decided to analyze the source and write an article to revert the infection. Anyway, you don&#8217;t have to worry&#8230; I am testing it on my Virtual Server. Its pretty sealed and protected!<br />
<br />
All of my Windows Files and everything else are Fake! These malware are stupid and they are only written by idiots to fool your computer and steal your privacy! Also, there is a warning: take care of your computer! Especially, looking at your emails and downloading attachments. Any of these unknown email, there is a chance that your computer is going to get really Sick!<br />
<br />
Now, if you&#8217;re infected with &#8220;W32/ExploreZip.pak&#8221; virus, then please print this article and disconnect your computer from the internet! After that, you&#8217;ll need to take a deep breath and take it easy&#8230;<br />
<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
<br />
<strong>Warning:</strong> if you&#8217;re on a server, you&#8217;ll need to tell your company to shut down all active computers! If you don&#8217;t, this infection will spread itself into another computer by LAN connections &#8211; mostly, the server&#8217;s &#8220;Shared Documents&#8221;.<br />
<br />
<strong>Overview:</strong> This particular Worm travels, by sending email messages to random users. It drops the file: &#8220;explore.exe&#8221; and modifies either the &#8220;WIN.INI&#8221; or modifies the Registry. However, this malware is still active and I am not sure how it comes into my inbox (Gmail). But, the user who sent the attachment, he / she is a very stupid user!<br />
<br />
<strong><em>What you&#8217;ll need for this procedure&#8230;</em></strong><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
<strong>Notepad++</strong> [http://notepad-plus.sourceforge.net]<br />
<br />
1.] Click Start >> Run >>  Type: REGEDIT<br />
2.] Wait for the registry to appear and navigate yourself to these locations and look for this registry binary. However, you&#8217;ll need to be very careful!<br />
<br />
<strong>HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows</strong><br />
<br />
<strong>Notes:</strong> if the binaries doesn&#8217;t exist, you&#8217;ll need to expand &#8220;Windows&#8221; directories and look into another folder called: Run.<br />
<br />
<strong>Binary to locate and remove:</strong> run=C:\WINNT\System32\Explore.exe<br />
<br />
<strong>Notes:</strong> You&#8217;ll need to do the same to these files, if they exist within the registry library.<br />
<br />
<strong>File Name:</strong> explore, zipped_f, zipped_files or _setup<br />
<br />
3.] Reboot your computer, then remove the following file: <strong>&#8220;C:\WINNT\System32\Explore.exe&#8221; from your &#8220;System32&#8243;</strong> Folders.<br />
<br />
4.] Repeat <em><strong>Step 3</strong></em> for &#8220;_SETUP.EXE and ZIPPED_FILES.EXE&#8221;.<br />
<br />
5.] Find this file: &#8220;WIN.INI&#8221; and remove either of these commands, if they exist.<br />
<br />
<strong>run=c:\winnt\system32\explore.exe<br />
run=c:\winnt\_setup.exe</strong><br />
<br />
6.] Scan your computer with Avira Antivirus or Kaspersky.<br />
After that, just clear computer&#8217;s temporary files with CCleaner.<br />
<br />
7.] Finish!<br />
<br />
<strong>Copyrighted By Lair360</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://lair360.co.uk/blog/655/how-to-remove-w32-explorer-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Win32/Conficker.AA infections</title>
		<link>http://lair360.co.uk/blog/396/how-to-completely-remove-win32confickeraa-infections/</link>
		<comments>http://lair360.co.uk/blog/396/how-to-completely-remove-win32confickeraa-infections/#comments</comments>
		<pubDate>Sun, 15 Feb 2009 15:09:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[Conficker infection]]></category>
		<category><![CDATA[removal tool]]></category>
		<category><![CDATA[remove Conficker]]></category>
		<category><![CDATA[remove Win32/Conficker.AA]]></category>
		<category><![CDATA[W32/Conficker.worm]]></category>

		<guid isPermaLink="false">http://lair360.co.uk/blog/?p=396</guid>
		<description><![CDATA[Version: 32.3 Revision: 65 Build 10 How to remove Win32/Conficker.AA infections Introduction: Win32/Conficker.AA worm is also known as W32/Worm.AHGV, Net-Worm.Win32.Kido.bg, Worm:Win32/Conficker, W32/Conficker.worm.gen, Mal/Conficker. This dangerous infection uses “Microsoft Windows Server Service &#8211; RPC Handling Remote Code Execution Vulnerability (MS08-67)” in order to infect other computers in the local network. This worm also blocks users from [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Version: 32.3<br />
Revision: 65 Build 10<br />
<br />
How to remove Win32/Conficker.AA infections<br />
<br />
Introduction:</strong> Win32/Conficker.AA worm is also known as W32/Worm.AHGV, Net-Worm.Win32.Kido.bg, Worm:Win32/Conficker, W32/Conficker.worm.gen, Mal/Conficker.<br />
This dangerous infection uses “Microsoft Windows Server Service &#8211; RPC Handling Remote Code Execution Vulnerability (MS08-67)” in order to infect other computers in the local network. This worm also blocks users from accessing to other security websites; it deletes all the System Restore points prior to infection, and to protect itself from deletion it!<br />
<br />
<strong>Problems:</strong> If your computer is infected with this worm, you may not experience any symptoms, or you may experience any of the following symptoms:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
-Account lockout and the system policies are being tripped.<br />
-Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender, and Error Reporting Services are disabled.<br />
-Domain controllers respond slowly to client requests.<br />
-The network connection is congested.<br />
-Various security-related Web sites cannot be accessed or shutdown.<br />
<br />
1.] Download one of these tools and remove “Win32/Conficker” infections.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>http://www.bitdefender.com/site/Downloads/downloadFile/1584/FreeRemovalTool</p>
<p>http://www.softpedia.com/get/Antivirus/Anti-Downadup.shtml</p>
<p>ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<br />
2.] After downloading, just extract the contents to a folder.<br />
<br />
3.] Disconnect from the network and unplug your network cable.<br />
If you have wireless connections, please disable your connections and ‘power off’ your router.<br />
<br />
4.] Disable “Windows System Restore” to clean all your infected restore points.<br />
<br />
Click Start >> Control Panel >> System >> System Restore<br />
<br />
5.] Execute the application and choose the best scanning option.<br />
<br />
If it asked you to reboot your system, please deny it (don&#8217;t click ok) and continue…<br />
<br />
6.] After the removal, please go to your registry and check this directory.<br />
This is a safety precaution for all users!<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<strong>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon</strong><br />
<br />
<strong>- Make sure that you have this:</strong> Userinit [REG_SZ] = C:\Windows\System32\userinit.exe,<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
If not, please change it and replace the infected strings with the above or the information which is given below.<br />
<br />
<strong>Value Name:</strong> Userinit<br />
<strong>Value Type:</strong> REG_SZ<br />
<strong>Value Data:</strong> C:\Windows\System32\userinit.exe,<br />
<br />
7.] Reboot your computer when it completes disinfection.<br />
<br />
8.] Plug in your network cable and check your firewall before connecting.<br />
<br />
9.] Now, we will need to enable: “Windows System Restore,” and create a restore point.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
- To enable Windows System Restore, right-click on My Computer >> select Properties >> click on System Restore tab >> Uncheck the option: “Turn off system restore on all drives” >> in the warning box, just select: Yes >> Click: Apply >> OK.<br />
<br />
<strong>Notes:</strong> Once “System Restore” is enabled, it will create a ‘restore point’ for you…<br />
<br />
10.] Download CCleaner and delete all your Internet Temporary files and system caches.<br />
<br />
11.] Done and dusted!<br />
<br />
<strong>Optional:</strong> if you haven&#8217;t got &#8220;Microsoft Security Bulletin MS08-067&#8243; service update, please use this link; download the patch; install the patch and reboot your system.<br />
<br />
<strong>Link:</strong> http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx</p>
]]></content:encoded>
			<wfw:commentRss>http://lair360.co.uk/blog/396/how-to-completely-remove-win32confickeraa-infections/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
