<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>Solving bad experience with Computer &#187; Viruses</title>
	<atom:link href="http://www.badxp.com/category/security/viruses/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.badxp.com</link>
	<description>Computer repair, computer troubleshooting and computer diagnosing tips</description>
	<pubDate>Thu, 11 Dec 2008 09:10:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<image>
<link>http://www.badxp.com</link>
<url>http://www.badxp.com/wp-content/plugins/maxblogpress-favicon/icons/favicon-66.ico</url>
<title>Solving bad experience with Computer</title>
</image>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>AVG 8 destroyed Windows XP</title>
		<link>http://www.badxp.com/308/avg-8-destroyed-windows-xp/</link>
		<comments>http://www.badxp.com/308/avg-8-destroyed-windows-xp/#comments</comments>
		<pubDate>Sun, 16 Nov 2008 05:24:11 +0000</pubDate>
		<dc:creator>Faizi</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[AVG 8]]></category>

		<category><![CDATA[AVG destroy Windows XP]]></category>

		<category><![CDATA[AVG kill Windows XP]]></category>

		<category><![CDATA[user32.dll virus]]></category>

		<guid isPermaLink="false">http://www.badxp.com/?p=308</guid>
		<description><![CDATA[What happen when your security software detected a Microsoft Windows Operating System file as a virus and deleted it forever from your Microsoft Windows? The answer is simple, your Microsoft Windows will not be able to boot, or the Operating System might restart itself in a continous cycle.



That what will happen if you happen to [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;">What happen when your security software detected a Microsoft Windows Operating System file as a <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> and deleted it forever from your Microsoft Windows? The answer is simple, your Microsoft Windows will not be able to boot, or the Operating System might restart itself in a continous cycle.</p>
<div id="attachment_309" class="wp-caption alignnone" style="width: 369px"><img class="size-full wp-image-309" title="avg 8 destroyed Windows XP" src="http://www.badxp.com/wp-content/uploads/2008/11/avg8.jpg" alt="AVG 8 Security Suite Software" width="359" height="364" /><p class="wp-caption-text"><a href="http://www.badxp.com/tag/avg-8/" class="st_tag internal_tag" rel="tag" title="Posts tagged with AVG 8">AVG 8</a> Security Suite Software</p></div>
<p><script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>That what will happen if you happen to use Dutch, French, Italian, Portuguese or Spanish version of Microsoft Windows XP and AVG8 as your <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> program, with recent <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> definition file update.</p>
<p>AVG8 with the latest update file detected user32.dll, which is a crucial system file in Microsoft Windows XP as a <a href="http://www.badxp.com/tag/trojan/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trojan">trojan</a>. Fortunately, AVG have fixed the problem immediately and casualty have been kept to a minimum</p>
<p>This is quite a shocking news considering the glitch came from a well know Security Product Manufacturer such as AVG.</p>

	Tags: <a href="http://www.badxp.com/tag/avg-8/" title="AVG 8" rel="tag">AVG 8</a>, <a href="http://www.badxp.com/tag/avg-destroy-windows-xp/" title="AVG destroy Windows XP" rel="tag">AVG destroy Windows XP</a>, <a href="http://www.badxp.com/tag/avg-kill-windows-xp/" title="AVG kill Windows XP" rel="tag">AVG kill Windows XP</a>, <a href="http://www.badxp.com/tag/user32dll-virus/" title="user32.dll virus" rel="tag">user32.dll virus</a><br />

	<h4>See also:</h4>
	<ul class="st-related-posts">
	<li>No related posts.</li>
	</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.badxp.com/308/avg-8-destroyed-windows-xp/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Yongyut Aunkaen in Internet Explorer title bar</title>
		<link>http://www.badxp.com/91/remove-yongyut-aunkaen-in-internet-explorer-title-bar/</link>
		<comments>http://www.badxp.com/91/remove-yongyut-aunkaen-in-internet-explorer-title-bar/#comments</comments>
		<pubDate>Wed, 11 Jun 2008 04:22:22 +0000</pubDate>
		<dc:creator>Faizi</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[MS32DLL.dll.vbs]]></category>

		<category><![CDATA[Yongyut Aunkaen]]></category>

		<category><![CDATA[Yongyut Aunkaen internet explorer]]></category>

		<category><![CDATA[Yongyut Aunkaen virus]]></category>

		<category><![CDATA[Yongyut Aunkaen worm]]></category>

		<guid isPermaLink="false">http://www.badxp.com/91/remove-yongyut-aunkaen-in-internet-explorer-title-bar/</guid>
		<description><![CDATA[I received a system today with a message Yongyut Aunkaen appear in the Internet Explorer title bar. Without no doubt this Yongyut Aunkaen text is some kind of worm that hijacked the Internet Explorer.  After doing some googling, I found out that this Yongyut Aunkaen is indeed a worm.  This worm will display [...]]]></description>
			<content:encoded><![CDATA[<p><!--noadsense-->I received a system today with a message <strong><a href="http://www.badxp.com/tag/yongyut-aunkaen/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Yongyut Aunkaen">Yongyut Aunkaen</a></strong> appear in the Internet Explorer title bar. Without no doubt this <a href="http://www.badxp.com/tag/yongyut-aunkaen/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Yongyut Aunkaen">Yongyut Aunkaen</a> text is some kind of <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a> that hijacked the Internet Explorer.  After doing some googling, I found out that this <a href="http://www.badxp.com/tag/yongyut-aunkaen/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Yongyut Aunkaen">Yongyut Aunkaen</a> is indeed a <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a>.  This <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a> will display <a href="http://www.badxp.com/tag/yongyut-aunkaen/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Yongyut Aunkaen">Yongyut Aunkaen</a> in Internet Explorer title bar, will duplicate itself, and will disable user from double clicking the computer drives.</p>
<p>This <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a> will create the files <strong><a href="http://www.badxp.com/tag/ms32dlldllvbs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with MS32DLL.dll.vbs">MS32DLL.dll.vbs</a></strong>  and <strong><a href="http://www.badxp.com/tag/autoruninf/" class="st_tag internal_tag" rel="tag" title="Posts tagged with autorun.inf">autorun.inf</a> </strong>in every computer drives on the system. This will enable the<strong> </strong><strong><a href="http://www.badxp.com/tag/yongyut-aunkaen/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Yongyut Aunkaen">Yongyut Aunkaen</a> </strong><a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a> to autorun every time the drive are double clicked.</p>
<p>To remove the <a href="http://www.badxp.com/tag/yongyut-aunkaen/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Yongyut Aunkaen">Yongyut Aunkaen</a> <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a>, follow steps below:</p>
<ol>
<li> Download the vb script fix <a href="http://www.badxp.com/wp-content/uploads/2008/06/fix-ms32.vbs" title="Yongyut Aunkaen fix">here</a>.</li>
<li>Run the  vb script fix.</li>
<li>Run the Task Manager (ctrl+alt+del) or (ctrl+shift+esc), kill the process &#8220;wscript.exe&#8221;.</li>
<li>Run My Computer &gt; Control Panel &gt; Folder Option.</li>
<li>Select view tab, choose &#8220;Show hidden files and folder&#8221; , uncheck &#8220;Hide protected operating system files&#8221;.<br />
<img src="http://www.badxp.com/wp-content/uploads/2008/06/show_hidden_folder.JPG" alt="Yongyut Aunkaen show hidden files and folder" /><br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</li>
<li>Go to C:\ drive , search and delete <a href="http://www.badxp.com/tag/autoruninf/" class="st_tag internal_tag" rel="tag" title="Posts tagged with autorun.inf">autorun.inf</a> and <a href="http://www.badxp.com/tag/ms32dlldllvbs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with MS32DLL.dll.vbs">MS32DLL.dll.vbs</a></li>
<li>Run registry editor.  Start menu &gt; run &gt; regedit</li>
<li>Go to HKEY_LOCAL_MACHINE -&gt; Software -&gt;Microsoft -&gt;Windows -&gt; Current Version -&gt; Run</li>
<li>Delete MS32DLL</li>
<li>Go to HKEY_CURRENT_USER -&gt; Software -&gt; Microsoft -&gt; Internet Explorer -&gt; Main</li>
<li>Delete <a href="http://www.badxp.com/tag/yongyut-aunkaen/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Yongyut Aunkaen">Yongyut Aunkaen</a></li>
<li>Run Microsoft Configuration Utility. Start menu &gt; run &gt; msconfig</li>
<li>Go to startup tab &gt; uncheck MS32DLL entry.</li>
<li>Restart your computer.</li>
</ol>
<p>This will remove the <a href="http://www.badxp.com/tag/yongyut-aunkaen/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Yongyut Aunkaen">Yongyut Aunkaen</a> title from Internet Explorer bar, and remove the files <a href="http://www.badxp.com/tag/autoruninf/" class="st_tag internal_tag" rel="tag" title="Posts tagged with autorun.inf">autorun.inf</a> and <a href="http://www.badxp.com/tag/ms32dlldllvbs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with MS32DLL.dll.vbs">MS32DLL.dll.vbs</a> that the <a href="http://www.badxp.com/tag/yongyut-aunkaen/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Yongyut Aunkaen">Yongyut Aunkaen</a> have created.</p>

	Tags: <a href="http://www.badxp.com/tag/ms32dlldllvbs/" title="MS32DLL.dll.vbs" rel="tag">MS32DLL.dll.vbs</a>, <a href="http://www.badxp.com/tag/yongyut-aunkaen/" title="Yongyut Aunkaen" rel="tag">Yongyut Aunkaen</a>, <a href="http://www.badxp.com/tag/yongyut-aunkaen-internet-explorer/" title="Yongyut Aunkaen internet explorer" rel="tag">Yongyut Aunkaen internet explorer</a>, <a href="http://www.badxp.com/tag/yongyut-aunkaen-virus/" title="Yongyut Aunkaen virus" rel="tag">Yongyut Aunkaen virus</a>, <a href="http://www.badxp.com/tag/yongyut-aunkaen-worm/" title="Yongyut Aunkaen worm" rel="tag">Yongyut Aunkaen worm</a><br />

	<h4>See also:</h4>
	<ul class="st-related-posts">
	<li>No related posts.</li>
	</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.badxp.com/91/remove-yongyut-aunkaen-in-internet-explorer-title-bar/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Kyrent virus information and remover</title>
		<link>http://www.badxp.com/70/kyrent-virus-information-and-remover/</link>
		<comments>http://www.badxp.com/70/kyrent-virus-information-and-remover/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 12:35:49 +0000</pubDate>
		<dc:creator>Faizi</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[antivirus]]></category>

		<category><![CDATA[kyrent]]></category>

		<category><![CDATA[kyrent virus]]></category>

		<category><![CDATA[kyrent virus remover]]></category>

		<category><![CDATA[pcmav]]></category>

		<category><![CDATA[pcmav download]]></category>

		<category><![CDATA[virus remover]]></category>

		<guid isPermaLink="false">http://www.badxp.com/70/kyrent-virus-information-and-remover/</guid>
		<description><![CDATA[Not much is know about the KyrEnt Virus , except that most of its source code are similar to previous Brontox variant viruses, which originated from Indonesia. Even the executables that this KyrEnt Virus created use &#8220;My Documents&#8221; icons, similar to Brontox variant viruses. The KyrEnt Virus is known as KyRent due to fact that [...]]]></description>
			<content:encoded><![CDATA[<p><!--noadsense-->Not much is know about the <a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyrEnt</a> <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a> , except that most of its source code are similar to previous Brontox variant viruses, which originated from Indonesia. Even the executables that this <a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyrEnt</a> <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a> created use &#8220;My Documents&#8221; icons, similar to Brontox variant viruses. The <a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyrEnt</a> <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a> is known as <a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyRent</a> due to fact that they are various &#8220;<a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyRent</a>&#8221;string inside the <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a>.</p>
<p>The <a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyrEnt</a> <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a> will copy these files into the following directories:</p>
<blockquote><p> c:\text.exe<br />
c:\windows\windows.exe<br />
c:\windows\WinSystem.exe<br />
c:\windows\Win System.exe<br />
c:\windows\windows.exe<br />
c:\windows\WinSys32.exe<br />
c:\windows\runrunrun.exe<br />
c:\windows\SystemMonitor64.exe<br />
c:\windows\MonitorSetup.exe<br />
c:\windows\MonitorMission.run<br />
c:\bootex.exe<br />
d:\bootex.exe<br />
c:\windows\system32\WindowsProtection.exe<br />
c:\log.exe<br />
c:\windows\winsystem.exe<br />
c:\windows\explorer.exe<br />
c:\windows\sysa.exe<br />
c:\windows\sysb.exe</p></blockquote>
<p>And will create the following registry entries:</p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SuperHidden<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\HideFileExt<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\AlternateShell<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell<br />
HKEY_CLASSES_ROOT\folder\defaulticon<br />
HKEY_CLASSES_ROOT\.run<br />
HKEY_CLASSES_ROOT\*\shell\Run As\Command<br />
HKEY_CLASSES_ROOT\Folder\shell\Scan for <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a>\Command<br />
HKEY_CLASSES_ROOT\Folder\shell\Search\Command<br />
HKEY_CLASSES_ROOT\*\shell\Scan for <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a>\Command<br />
HKEY_CLASSES_ROOT\.doc\shell\new\command<br />
HKEY_CLASSES_ROOT\.dot<br />
HKEY_CLASSES_ROOT\.exed<br />
HKEY_CLASSES_ROOT\exedfile<br />
HKEY_CLASSES_ROOT\exedfile\DefaultIcon<br />
HKEY_CLASSES_ROOT\exedfile\Shell\Open\Command<br />
HKEY_CLASSES_ROOT\exedfile\Shell\Open<br />
HKEY_CLASSES_ROOT\.ppa<br />
HKEY_CLASSES_ROOT\.xlt<br />
HKEY_CLASSES_ROOT\.mdb<br />
HKEY_CLASSES_ROOT\.ldb<br />
HKEY_CLASSES_ROOT\.db<br />
HKEY_CLASSES_ROOT\.dbf<br />
HKEY_CLASSES_ROOT\.dbl<br />
HKEY_CLASSES_ROOT\.ttf<br />
HKEY_CLASSES_ROOT\.fon<br />
HKEY_CLASSES_ROOT\.cfg<br />
HKEY_CLASSES_ROOT\cfgfile\shell\Open\command<br />
HKEY_CLASSES_ROOT\cfgfile<br />
HKEY_CLASSES_ROOT\cfgfile\shell\open\command<br />
HKEY_CLASSES_ROOT\.bin<br />
HKEY_CLASSES_ROOT\.cvd<br />
HKEY_CLASSES_ROOT\.dat<br />
HKEY_CLASSES_ROOT\.com<br />
HKEY_CLASSES_ROOT\.exc<br />
HKEY_CLASSES_ROOT\excfile\shell\open\command<br />
HKEY_CLASSES_ROOT\excfile<br />
HKEY_CLASSES_ROOT\exefile\shell\open\command<br />
HKEY_CLASSES_ROOT\excfile\DefaultIcon<br />
HKEY_CLASSES_ROOT\htmlfile</p></blockquote>
<p>The <a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyrEnt</a> <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a> will also modified your Microsoft Windows OEM informations, sound familliar? You guessed right, another Brontox <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a> copycat.</p>
<p>The <a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyrEnt</a> <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a> will block programs or processes containing these texts:</p>
<blockquote><p>Updatex, Updatingx, upgradex, <a href="http://www.badxp.com/tag/pcmav/" class="st_tag internal_tag" rel="tag" title="Posts tagged with pcmav">pcmav</a>, system restore, registry, Task Manager, System Configuration, Process Manager, hijack, process xp, Process View, Process Control, Process Explorer, Process Patrol, cmd xxxx, raypc, ntfs4dos, ntfs for dos, ntfs 4 dos, Confirm File Delete, Confirm Key Delete, Registry, Edit String, cleaner, Confirm Value Delete, Folder Option, control panel error, antivir, avast, clamav, nod32, norton, norman, mcafee, kaspersky, remover, curr proces, defender.</p></blockquote>
<p>Whenever active, this <a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyrEnt</a> <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a> will display this text:</p>
<blockquote><p>&#8220;<em>Gita, gimana kabarmu?, kemana kamu pergi ?, aku merindukanmu, aku mohon kembalilah. By: Ir. Pluto</em>&#8220;</p></blockquote>
<p>With a black background on your screen. The text &#8220;<em>Gita, gimana kabarmu?, kemana kamu pergi ?, aku merindukanmu, aku mohon kembalilah. By: Ir. Pluto</em>&#8221; have been set to be always on top of your screen.</p>
<p><strong> <a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyrEnt</a> Remover</strong></p>
<p>You can remove <a href="http://www.badxp.com/tag/kyrent/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kyrent">KyrEnt</a> <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">Virus</a> using <a href="http://www.badxp.com/tag/pcmav/" class="st_tag internal_tag" rel="tag" title="Posts tagged with pcmav">PCMAV</a> <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> developed by PC Media Indonesia. The current version is 1.1.<a href="http://www.badxp.com/wp-content/uploads/2008/03/pcmav-11-package.zip" title="PCMAV 1.1 package"></a></p>
<p><a href="http://www.badxp.com/wp-content/uploads/2008/03/pcmav-11-package.zip" title="PCMAV 1.1 package">Download PCMAV 1.1 package</a></p>
<p>The password for the zip file is &#8220;badxp.com&#8221;<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>

	Tags: <a href="http://www.badxp.com/tag/antivirus/" title="antivirus" rel="tag">antivirus</a>, <a href="http://www.badxp.com/tag/kyrent/" title="kyrent" rel="tag">kyrent</a>, <a href="http://www.badxp.com/tag/kyrent-virus/" title="kyrent virus" rel="tag">kyrent virus</a>, <a href="http://www.badxp.com/tag/kyrent-virus-remover/" title="kyrent virus remover" rel="tag">kyrent virus remover</a>, <a href="http://www.badxp.com/tag/pcmav/" title="pcmav" rel="tag">pcmav</a>, <a href="http://www.badxp.com/tag/pcmav-download/" title="pcmav download" rel="tag">pcmav download</a>, <a href="http://www.badxp.com/tag/virus-remover/" title="virus remover" rel="tag">virus remover</a><br />

	<h4>See also:</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.badxp.com/416/how-to-remove-anti-virus-2009/" title="How To Remove Anti-Virus 2009 (December 9, 2008)">How To Remove Anti-Virus 2009</a> (25)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.badxp.com/70/kyrent-virus-information-and-remover/feed/</wfw:commentRss>
		</item>
		<item>
		<title>RoMeO A.K.A ILLS [CIXENT] cleaner and remover</title>
		<link>http://www.badxp.com/63/romeo-aka-ills-cixent-cleaner-and-remover/</link>
		<comments>http://www.badxp.com/63/romeo-aka-ills-cixent-cleaner-and-remover/#comments</comments>
		<pubDate>Thu, 06 Mar 2008 18:49:36 +0000</pubDate>
		<dc:creator>Faizi</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[CIXENT Corp]]></category>

		<category><![CDATA[RoMeO A.K.A ILLS]]></category>

		<category><![CDATA[virus disinfection]]></category>

		<category><![CDATA[virus fix]]></category>

		<guid isPermaLink="false">http://www.badxp.com/63/romeo-aka-ills-cixent-cleaner-and-remover/</guid>
		<description><![CDATA[Referring to my previous post regarding RoMeO A.K.A ILLS [CIXENT] or CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb virus , a blogger have created a solution cleaner and remover for this RoMeO A.K.A ILLS [CIXENT] or CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb virus



This RoMeO A.K.A ILLS [CIXENT] remover is design to remove entirely the RoMeO A.K.A ILLS [CIXENT] virus including the registry [...]]]></description>
			<content:encoded><![CDATA[<p><!--noadsense-->Referring to my <a href="http://www.badxp.com/45/romeo-aka-ills-cixent/" title="RoMeO A.K.A ILLS [CIXENT]" target="_blank">previous post regarding RoMeO A.K.A ILLS [CIXENT] or CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb virus</a> , a <a href="http://maniack.co.nr/" title="Maniack" target="_blank">blogger</a> have created a solution cleaner and remover for this <a href="http://www.badxp.com/tag/romeo-aka-ills/" class="st_tag internal_tag" rel="tag" title="Posts tagged with RoMeO A.K.A ILLS">RoMeO A.K.A ILLS</a> [CIXENT] or <a href="http://www.badxp.com/tag/cixent-corp/" class="st_tag internal_tag" rel="tag" title="Posts tagged with CIXENT Corp">CIXENT Corp</a> [CIXENT.V3.Force.LovePart.Small.vb <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a><br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
This <a href="http://www.badxp.com/tag/romeo-aka-ills/" class="st_tag internal_tag" rel="tag" title="Posts tagged with RoMeO A.K.A ILLS">RoMeO A.K.A ILLS</a> [CIXENT] remover is design to remove entirely the <a href="http://www.badxp.com/tag/romeo-aka-ills/" class="st_tag internal_tag" rel="tag" title="Posts tagged with RoMeO A.K.A ILLS">RoMeO A.K.A ILLS</a> [CIXENT] <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> including the registry entries.</p>
<p><img src="http://www.badxp.com/wp-content/uploads/2008/03/cixent_remover.jpg" alt="Cixent remover" /><br />
<br />
<a href="http://www.badxp.com/wp-content/uploads/2008/03/cixent_v3-force_remover.rar" title="Cixent remover">Download RoMeO A.K.A ILLS [CIXENT] or CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb virus remover here</a></p>
<p>* Credit to maniack.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>

	Tags: <a href="http://www.badxp.com/tag/cixent-corp/" title="CIXENT Corp" rel="tag">CIXENT Corp</a>, <a href="http://www.badxp.com/tag/romeo-aka-ills/" title="RoMeO A.K.A ILLS" rel="tag">RoMeO A.K.A ILLS</a>, <a href="http://www.badxp.com/tag/virus-disinfection/" title="virus disinfection" rel="tag">virus disinfection</a>, <a href="http://www.badxp.com/tag/virus-fix/" title="virus fix" rel="tag">virus fix</a><br />

	<h4>See also:</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.badxp.com/45/romeo-aka-ills-cixent/" title="RoMeO A.K.A ILLS [CIXENT] (March 1, 2008)">RoMeO A.K.A ILLS [CIXENT]</a> (5)</li>
	<li><a href="http://www.badxp.com/52/remove-vbsbutsur-a-or-bhadllvbs-fix/" title="Remove VBS/ButSur-A or BHA.DLL.VBS fix (March 4, 2008)">Remove VBS/ButSur-A or BHA.DLL.VBS fix</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.badxp.com/63/romeo-aka-ills-cixent-cleaner-and-remover/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Remove VBS/ButSur-A or BHA.DLL.VBS fix</title>
		<link>http://www.badxp.com/52/remove-vbsbutsur-a-or-bhadllvbs-fix/</link>
		<comments>http://www.badxp.com/52/remove-vbsbutsur-a-or-bhadllvbs-fix/#comments</comments>
		<pubDate>Tue, 04 Mar 2008 08:35:55 +0000</pubDate>
		<dc:creator>Faizi</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[adware]]></category>

		<category><![CDATA[autorun.inf]]></category>

		<category><![CDATA[Bha.dll.vbs]]></category>

		<category><![CDATA[spyware]]></category>

		<category><![CDATA[VBS/ButSur-A]]></category>

		<category><![CDATA[VBS/Butsur.B]]></category>

		<category><![CDATA[VBS_BUTSUR.B]]></category>

		<category><![CDATA[virus]]></category>

		<category><![CDATA[virus disinfection]]></category>

		<category><![CDATA[virus fix]]></category>

		<category><![CDATA[virus removal]]></category>

		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.badxp.com/52/remove-vbsbutsur-a-or-bhadllvbs-fix/</guid>
		<description><![CDATA[Ever try to open a drive with double click and this error message pop up?
WINDOWS SCRIPT HOST, CANNOT FIND SCRIPT FILE &#8220;C:/Bha.dll.vbs
This &#8220;WINDOWS SCRIPT HOST, CANNOT FIND SCRIPT FILE &#8220;C:/Bha.dll.vbs&#8221; occur due to a worm infection known as VBS/ButSur-A . VBS/ButSur-A is a Visual Basic script worm for Microsoft Windows platform, and also known as

VBS_BUTSUR.B
VBS/Butsur.B




When [...]]]></description>
			<content:encoded><![CDATA[<p><!--noadsense-->Ever try to open a drive with double click and this error message pop up?</p>
<blockquote><p>WINDOWS SCRIPT HOST, CANNOT FIND SCRIPT FILE &#8220;C:/<a href="http://www.badxp.com/tag/bhadllvbs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Bha.dll.vbs">Bha.dll.vbs</a></p></blockquote>
<p>This &#8220;WINDOWS SCRIPT HOST, CANNOT FIND SCRIPT FILE &#8220;C:/<a href="http://www.badxp.com/tag/bhadllvbs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Bha.dll.vbs">Bha.dll.vbs</a>&#8221; occur due to a <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a> infection known as <strong><a href="http://www.badxp.com/tag/vbsbutsur-a/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS/ButSur-A">VBS/ButSur-A</a> </strong>. <a href="http://www.badxp.com/tag/vbsbutsur-a/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS/ButSur-A">VBS/ButSur-A</a> is a Visual Basic script <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a> for Microsoft Windows platform, and also known as</p>
<ul>
<li><strong><a href="http://www.badxp.com/tag/vbs_butsurb/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS_BUTSUR.B">VBS_BUTSUR.B</a></strong></li>
<li><strong><a href="http://www.badxp.com/tag/vbsbutsurb/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS/Butsur.B">VBS/Butsur.B</a></strong></li>
</ul>
<p><script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
When active, <a href="http://www.badxp.com/tag/vbsbutsur-a/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS/ButSur-A">VBS/ButSur-A</a>:</p>
<ol>
<li>Copies itself to C:\Windows\<strong><a href="http://www.badxp.com/tag/bhadllvbs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Bha.dll.vbs">Bha.dll.vbs</a></strong></li>
<li>Create the following registry entry:<br />
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<br />
MS32DLL<br />
C:\Windows\<a href="http://www.badxp.com/tag/bhadllvbs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Bha.dll.vbs">Bha.dll.vbs</a></li>
<li>Add the following registry entry:<br />
HKCU\Software\Microsoft\Internet Explorer\Main\Window Title\</li>
<li>Copies itself to all removeable and shared drives as <strong><a href="http://www.badxp.com/tag/bhadllvbs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Bha.dll.vbs">Bha.dll.vbs</a></strong> and creates the file <a href="http://www.badxp.com/tag/autoruninf/" class="st_tag internal_tag" rel="tag" title="Posts tagged with autorun.inf">autorun.inf</a>.</li>
</ol>
<p>This <a href="http://www.badxp.com/tag/autoruninf/" class="st_tag internal_tag" rel="tag" title="Posts tagged with autorun.inf">autorun.inf</a> files will run the script <strong><a href="http://www.badxp.com/tag/bhadllvbs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Bha.dll.vbs">Bha.dll.vbs</a> </strong>everytime the removeable drive are open with double click. This <a href="http://www.badxp.com/tag/vbsbutsur-a/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS/ButSur-A">VBS/ButSur-A</a>, <a href="http://www.badxp.com/tag/vbs_butsurb/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS_BUTSUR.B">VBS_BUTSUR.B</a>, <a href="http://www.badxp.com/tag/vbsbutsurb/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS/Butsur.B">VBS/Butsur.B</a> can be easily remove by deleting the files and the registry entries that this <a href="http://www.badxp.com/tag/vbsbutsur-a/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS/ButSur-A">VBS/ButSur-A</a>, <a href="http://www.badxp.com/tag/vbs_butsurb/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS_BUTSUR.B">VBS_BUTSUR.B</a>, <a href="http://www.badxp.com/tag/vbsbutsurb/" class="st_tag internal_tag" rel="tag" title="Posts tagged with VBS/Butsur.B">VBS/Butsur.B</a> <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a> created.</p>
<p>Alternatively you can download this nifty utility called the Flash Disinfector to enable you to disinfect and open your removable drive with double click.</p>
<p><a href="http://www.badxp.com/wp-content/uploads/2008/03/flash_disinfector.exe" title="Flash Disinfector">Download Flash Disinfector</a></p>
<p><img src="http://www.badxp.com/wp-content/uploads/2008/03/flash_disinfector.JPG" alt="Flash Disinfector" /><br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
A popup message will appear, click &#8220;OK&#8221; to start the disinfection process. That&#8217;s all to it.</p>

	Tags: <a href="http://www.badxp.com/tag/adware/" title="adware" rel="tag">adware</a>, <a href="http://www.badxp.com/tag/autoruninf/" title="autorun.inf" rel="tag">autorun.inf</a>, <a href="http://www.badxp.com/tag/bhadllvbs/" title="Bha.dll.vbs" rel="tag">Bha.dll.vbs</a>, <a href="http://www.badxp.com/tag/spyware/" title="spyware" rel="tag">spyware</a>, <a href="http://www.badxp.com/tag/vbsbutsur-a/" title="VBS/ButSur-A" rel="tag">VBS/ButSur-A</a>, <a href="http://www.badxp.com/tag/vbsbutsurb/" title="VBS/Butsur.B" rel="tag">VBS/Butsur.B</a>, <a href="http://www.badxp.com/tag/vbs_butsurb/" title="VBS_BUTSUR.B" rel="tag">VBS_BUTSUR.B</a>, <a href="http://www.badxp.com/tag/virus/" title="virus" rel="tag">virus</a>, <a href="http://www.badxp.com/tag/virus-disinfection/" title="virus disinfection" rel="tag">virus disinfection</a>, <a href="http://www.badxp.com/tag/virus-fix/" title="virus fix" rel="tag">virus fix</a>, <a href="http://www.badxp.com/tag/virus-removal/" title="virus removal" rel="tag">virus removal</a>, <a href="http://www.badxp.com/tag/worm/" title="worm" rel="tag">worm</a><br />

	<h4>See also:</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.badxp.com/45/romeo-aka-ills-cixent/" title="RoMeO A.K.A ILLS [CIXENT] (March 1, 2008)">RoMeO A.K.A ILLS [CIXENT]</a> (5)</li>
	<li><a href="http://www.badxp.com/4/trixcua-worm/" title="Trixcu.A worm (November 20, 2007)">Trixcu.A worm</a> (1)</li>
	<li><a href="http://www.badxp.com/1/the-genealogy-of-virus/" title="The Genealogy of Virus (November 19, 2007)">The Genealogy of Virus</a> (9)</li>
	<li><a href="http://www.badxp.com/20/the-best-antivirus-program/" title="The best antivirus program (February 15, 2008)">The best antivirus program</a> (2)</li>
	<li><a href="http://www.badxp.com/63/romeo-aka-ills-cixent-cleaner-and-remover/" title="RoMeO A.K.A ILLS [CIXENT] cleaner and remover (March 7, 2008)">RoMeO A.K.A ILLS [CIXENT] cleaner and remover</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.badxp.com/52/remove-vbsbutsur-a-or-bhadllvbs-fix/feed/</wfw:commentRss>
		</item>
		<item>
		<title>RoMeO A.K.A ILLS [CIXENT]</title>
		<link>http://www.badxp.com/45/romeo-aka-ills-cixent/</link>
		<comments>http://www.badxp.com/45/romeo-aka-ills-cixent/#comments</comments>
		<pubDate>Sat, 01 Mar 2008 13:19:27 +0000</pubDate>
		<dc:creator>Faizi</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[adware]]></category>

		<category><![CDATA[CIXENT Corp]]></category>

		<category><![CDATA[remove virus]]></category>

		<category><![CDATA[RoMeO A.K.A ILLS]]></category>

		<category><![CDATA[spyware]]></category>

		<category><![CDATA[virus]]></category>

		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.badxp.com/45/romeo-aka-ills-cixent/</guid>
		<description><![CDATA[
This is virus is known as CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb] . This  RoMeO A.K.A ILLS [CIXENT] copied these files to C:\WINDOWS\system32 folder:



C:\WINDOWS\system32\V3-Force.exe
C:\WINDOWS\system32\cipaplu.exe
C:\WINDOWS\system32\mycaption.reg
C:\WINDOWS\system32\butuhlu.bat
C:\WINDOWS\system32\forattrib.bat
C:\WINDOWS\system32\makedir.bat
and will change your C drive name to:
(C:) jadi RoMeO A.K.A ILLS [CIXENT]
RoMeO A.K.A ILLS [CIXENT] or CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb] will display a popup title:
Jeng!!!Jeng!!!Jeng!!!Jeng!!!Jeng!!!Jeng!!!Jeng!!! x100 words
And will display a &#8220;51&#8243; icon on the [...]]]></description>
			<content:encoded><![CDATA[<p><!--noadsense--><br />
This is <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> is known as <strong>CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb]</strong> . This  <strong>RoMeO A.K.A ILLS [CIXENT]</strong> copied these files to C:\WINDOWS\system32 folder:<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<blockquote><p>C:\WINDOWS\system32\V3-Force.exe<br />
C:\WINDOWS\system32\cipaplu.exe<br />
C:\WINDOWS\system32\mycaption.reg<br />
C:\WINDOWS\system32\butuhlu.bat<br />
C:\WINDOWS\system32\forattrib.bat<br />
C:\WINDOWS\system32\makedir.bat</p></blockquote>
<p>and will change your C drive name to:</p>
<blockquote><p>(C:) jadi RoMeO A.K.A ILLS [CIXENT]</p></blockquote>
<p>RoMeO A.K.A ILLS [CIXENT] or CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb] will display a popup title:</p>
<blockquote><p>Jeng!!!Jeng!!!Jeng!!!Jeng!!!Jeng!!!Jeng!!!Jeng!!! x100 words</p></blockquote>
<p>And will display a <strong>&#8220;51&#8243; icon</strong> on the system tray.</p>
<p>The solutions to  RoMeO A.K.A ILLS [CIXENT] or CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> is to delete all the files that it have copied, and delete all the registry entries containing the name of those files.  To delete those registry entries:</p>
<ol>
<li>Run regedit.</li>
<li>Click on the menu  "Edit".</li>
<li>Choose "Find".</li>
<li>Type in the name of the files that the RoMeO A.K.A ILLS [CIXENT] or CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> have copied, and delete them.</li>
</ol>
<p>Make sure to update your Antivirus or any other Malicious scanner program such as adware scanner or <a href="http://www.badxp.com/tag/spyware/" class="st_tag internal_tag" rel="tag" title="Posts tagged with spyware">spyware</a> scanner, and run a full scan using these Software after cleaning and removing this RoMeO A.K.A ILLS [CIXENT] or CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> manually.</p>
<p><a title="RoMeO A.K.A ILLS [CIXENT] cleaner and remover&#8221; href=&#8221;http://www.badxp.com/63/romeo-aka-ills-cixent-cleaner-and-remover/&#8221;>Update on  RoMeO A.K.A ILLS [CIXENT] or CIXENT Corp [CIXENT.V3.Force.LovePart.Small.vb <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> cleaner and remover here.</a></p>

	Tags: <a href="http://www.badxp.com/tag/adware/" title="adware" rel="tag">adware</a>, <a href="http://www.badxp.com/tag/cixent-corp/" title="CIXENT Corp" rel="tag">CIXENT Corp</a>, <a href="http://www.badxp.com/tag/remove-virus/" title="remove virus" rel="tag">remove virus</a>, <a href="http://www.badxp.com/tag/romeo-aka-ills/" title="RoMeO A.K.A ILLS" rel="tag">RoMeO A.K.A ILLS</a>, <a href="http://www.badxp.com/tag/spyware/" title="spyware" rel="tag">spyware</a>, <a href="http://www.badxp.com/tag/virus/" title="virus" rel="tag">virus</a>, <a href="http://www.badxp.com/tag/virus-removal/" title="virus removal" rel="tag">virus removal</a><br />

	<h4>See also:</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.badxp.com/52/remove-vbsbutsur-a-or-bhadllvbs-fix/" title="Remove VBS/ButSur-A or BHA.DLL.VBS fix (March 4, 2008)">Remove VBS/ButSur-A or BHA.DLL.VBS fix</a> (6)</li>
	<li><a href="http://www.badxp.com/4/trixcua-worm/" title="Trixcu.A worm (November 20, 2007)">Trixcu.A worm</a> (1)</li>
	<li><a href="http://www.badxp.com/1/the-genealogy-of-virus/" title="The Genealogy of Virus (November 19, 2007)">The Genealogy of Virus</a> (9)</li>
	<li><a href="http://www.badxp.com/20/the-best-antivirus-program/" title="The best antivirus program (February 15, 2008)">The best antivirus program</a> (2)</li>
	<li><a href="http://www.badxp.com/63/romeo-aka-ills-cixent-cleaner-and-remover/" title="RoMeO A.K.A ILLS [CIXENT] cleaner and remover (March 7, 2008)">RoMeO A.K.A ILLS [CIXENT] cleaner and remover</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.badxp.com/45/romeo-aka-ills-cixent/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Trixcu.a fix, Flash.10.exe fix, Macromedia.10.exe fix</title>
		<link>http://www.badxp.com/37/trixcua-fix-flash10exe-fix-macromedia10exe-fix/</link>
		<comments>http://www.badxp.com/37/trixcua-fix-flash10exe-fix-macromedia10exe-fix/#comments</comments>
		<pubDate>Tue, 26 Feb 2008 19:03:38 +0000</pubDate>
		<dc:creator>Faizi</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Software]]></category>

		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[flash.10.exe]]></category>

		<category><![CDATA[JambanMu.com]]></category>

		<category><![CDATA[macromedia.10.exe]]></category>

		<category><![CDATA[trixcu]]></category>

		<category><![CDATA[trixcu.a]]></category>

		<category><![CDATA[trixcu.a worm]]></category>

		<guid isPermaLink="false">http://www.badxp.com/37/trixcua-fix-flash10exe-fix-macromedia10exe-fix/</guid>
		<description><![CDATA[There are still some of my customer who are infected with  Trixcu.A worm, also known as Flash.10.exe, Macromedia.10.exe or JambanMu.com.



I&#8217;ve written the details about this Trixcu.A worm in previous entry.
Since then, a lot of Trixcu.A worm have been released on the Internet. A search on google with the keywords such as Trixcu.A, Trixcu worm, [...]]]></description>
			<content:encoded><![CDATA[<p><!--noadsense-->There are still some of my customer who are infected with  <a href="http://www.badxp.com/tag/trixcua-worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a worm">Trixcu.A worm</a>, also known as <a href="http://www.badxp.com/tag/flash10exe/" class="st_tag internal_tag" rel="tag" title="Posts tagged with flash.10.exe">Flash.10.exe</a>, <a href="http://www.badxp.com/tag/macromedia10exe/" class="st_tag internal_tag" rel="tag" title="Posts tagged with macromedia.10.exe">Macromedia.10.exe</a> or <a href="http://www.badxp.com/tag/jambanmucom/" class="st_tag internal_tag" rel="tag" title="Posts tagged with JambanMu.com">JambanMu.com</a>.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
I&#8217;ve written the details about this <a href="http://www.badxp.com/tag/trixcua-worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a worm">Trixcu.A worm</a> in <a href="http://www.badxp.com/4/trixcua-worm/" target="_blank">previous entry</a>.</p>
<p>Since then, a lot of <a href="http://www.badxp.com/tag/trixcua-worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a worm">Trixcu.A worm</a> have been released on the Internet. A search on google with the keywords such as <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a>, <a href="http://www.badxp.com/tag/trixcu/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu">Trixcu</a> <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a>, Cmd.com, dxdiag.com, Ping.com, Msconfig.com, Regedit.com, <a href="http://www.badxp.com/tag/flash10exe/" class="st_tag internal_tag" rel="tag" title="Posts tagged with flash.10.exe">Flash.10.exe</a>, <a href="http://www.badxp.com/tag/macromedia10exe/" class="st_tag internal_tag" rel="tag" title="Posts tagged with macromedia.10.exe">Macromedia.10.exe</a>, <a href="http://www.badxp.com/tag/jambanmucom/" class="st_tag internal_tag" rel="tag" title="Posts tagged with JambanMu.com">JambanMu.com</a>, Msn.msn, MY.SECRET.FOLD, NEW SONG.LAGU, NEW VIDEO.VIDZ, AWEKS.PIKZ, SERAM.PIKZ will bring you a lot of informations regarding this <a href="http://www.badxp.com/tag/trixcua-worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a worm">Trixcu.A worm</a>.</p>
<p>I have been using this <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> fix which I have downloaded from some Forum (which I have forgotten which Forum it is). So far this <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> fix have been reliable and have done its job well. You can download the <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> fix below:</p>
<p><a href="http://www.badxp.com/wp-content/uploads/2008/02/trixcu-a-fix.exe" title="Trixcu.A fix">Download Trixcu.A fix, Flash.10.exe fix, Macromedia.10.exe fix here.</a><br />
<br />
Run the <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> fix executable file, then reboot for the fix to take effect. Hopefully this <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> fix will provide a solutions to all your problems regarding this troublesome <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a>, including registry fixes.</p>

	Tags: <a href="http://www.badxp.com/tag/flash10exe/" title="flash.10.exe" rel="tag">flash.10.exe</a>, <a href="http://www.badxp.com/tag/jambanmucom/" title="JambanMu.com" rel="tag">JambanMu.com</a>, <a href="http://www.badxp.com/tag/macromedia10exe/" title="macromedia.10.exe" rel="tag">macromedia.10.exe</a>, <a href="http://www.badxp.com/tag/trixcu/" title="trixcu" rel="tag">trixcu</a>, <a href="http://www.badxp.com/tag/trixcua/" title="trixcu.a" rel="tag">trixcu.a</a>, <a href="http://www.badxp.com/tag/trixcua-worm/" title="trixcu.a worm" rel="tag">trixcu.a worm</a><br />

	<h4>See also:</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.badxp.com/4/trixcua-worm/" title="Trixcu.A worm (November 20, 2007)">Trixcu.A worm</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.badxp.com/37/trixcua-fix-flash10exe-fix-macromedia10exe-fix/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The best antivirus program</title>
		<link>http://www.badxp.com/20/the-best-antivirus-program/</link>
		<comments>http://www.badxp.com/20/the-best-antivirus-program/#comments</comments>
		<pubDate>Thu, 14 Feb 2008 21:26:32 +0000</pubDate>
		<dc:creator>Faizi</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Tips and Guides]]></category>

		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[adware]]></category>

		<category><![CDATA[antivirus program]]></category>

		<category><![CDATA[antivirus protection]]></category>

		<category><![CDATA[best antivirus]]></category>

		<category><![CDATA[best antivirus software]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[spyware]]></category>

		<category><![CDATA[trojan]]></category>

		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.badxp.com/20/the-best-antivirus-program/</guid>
		<description><![CDATA[What is the best antivirus software in the market nowadays? That is one of the most often ask question by my clients after their system have undergo an attack by malware, viruses, spyware, adware and trojans. Which so much antivirus programs to choose, which are the best for giving the most comprehensive virus protection?



Most IT [...]]]></description>
			<content:encoded><![CDATA[<p>What is the best <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> software in the market nowadays? That is one of the most often ask question by my clients after their system have undergo an attack by <a href="http://www.badxp.com/tag/malware/" class="st_tag internal_tag" rel="tag" title="Posts tagged with malware">malware</a>, viruses, <a href="http://www.badxp.com/tag/spyware/" class="st_tag internal_tag" rel="tag" title="Posts tagged with spyware">spyware</a>, <a href="http://www.badxp.com/tag/adware/" class="st_tag internal_tag" rel="tag" title="Posts tagged with adware">adware</a> and trojans. Which so much <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> programs to choose, which are the best for giving the most comprehensive <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> protection?<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
Most IT Professional will recommend some Commercial <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">Antivirus</a> program from established companies, while others will recommend the free alternative for <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">Antivirus</a> program.  For me, my answer will be fairly simple and straightforward, the <strong>best <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> program is the one that is regularly updated and upgraded</strong>. It is true, whether you are using the commercial <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> program, or the free <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> programs out there, those <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> programs will be useless if those <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> programs are not regularly updated and upgraded.</p>
<p>So make sure you update your <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">Antivirus</a> programs regularly, if not daily, and don&#8217;t forget to install any upgrades available from the <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">Antivirus</a> manufacturer as soon as they are stable in their releases, for you to have the best <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">Antivirus</a> program protection.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>

<p>Tags: <a href="http://technorati.com/tag/" rel="tag"></a></p>

	Tags: <a href="http://www.badxp.com/tag/adware/" title="adware" rel="tag">adware</a>, <a href="http://www.badxp.com/tag/antivirus-program/" title="antivirus program" rel="tag">antivirus program</a>, <a href="http://www.badxp.com/tag/antivirus-protection/" title="antivirus protection" rel="tag">antivirus protection</a>, <a href="http://www.badxp.com/tag/best-antivirus/" title="best antivirus" rel="tag">best antivirus</a>, <a href="http://www.badxp.com/tag/best-antivirus-software/" title="best antivirus software" rel="tag">best antivirus software</a>, <a href="http://www.badxp.com/tag/malware/" title="malware" rel="tag">malware</a>, <a href="http://www.badxp.com/tag/spyware/" title="spyware" rel="tag">spyware</a>, <a href="http://www.badxp.com/tag/trojan/" title="trojan" rel="tag">trojan</a>, <a href="http://www.badxp.com/tag/virus/" title="virus" rel="tag">virus</a><br />

	<h4>See also:</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.badxp.com/4/trixcua-worm/" title="Trixcu.A worm (November 20, 2007)">Trixcu.A worm</a> (1)</li>
	<li><a href="http://www.badxp.com/1/the-genealogy-of-virus/" title="The Genealogy of Virus (November 19, 2007)">The Genealogy of Virus</a> (9)</li>
	<li><a href="http://www.badxp.com/13/descriptions-of-malicious-programs/" title="Descriptions of Malicious Programs (January 22, 2008)">Descriptions of Malicious Programs</a> (1)</li>
	<li><a href="http://www.badxp.com/45/romeo-aka-ills-cixent/" title="RoMeO A.K.A ILLS [CIXENT] (March 1, 2008)">RoMeO A.K.A ILLS [CIXENT]</a> (5)</li>
	<li><a href="http://www.badxp.com/52/remove-vbsbutsur-a-or-bhadllvbs-fix/" title="Remove VBS/ButSur-A or BHA.DLL.VBS fix (March 4, 2008)">Remove VBS/ButSur-A or BHA.DLL.VBS fix</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.badxp.com/20/the-best-antivirus-program/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Descriptions of Malicious Programs</title>
		<link>http://www.badxp.com/13/descriptions-of-malicious-programs/</link>
		<comments>http://www.badxp.com/13/descriptions-of-malicious-programs/#comments</comments>
		<pubDate>Tue, 22 Jan 2008 14:37:34 +0000</pubDate>
		<dc:creator>Faizi</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[hacker]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[spyware]]></category>

		<category><![CDATA[trojan]]></category>

		<category><![CDATA[virus]]></category>

		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.badxp.com/2008/01/22/descriptions-of-malicious-programs/</guid>
		<description><![CDATA[ This is a nice informations on the descriptions of several malicious program I got from Kaspersky website. You can view the original article here.



Malicious programs can be divided into the following groups: worms, viruses, Trojans, hacker utilities and other malware. All of these are designed to damage the infected machine or other networked machines.
Network [...]]]></description>
			<content:encoded><![CDATA[<p> This is a nice informations on the descriptions of several malicious program I got from Kaspersky website. You can view the original article <a href="http://www.viruslist.com/en/virusesdescribed" target="_blank">here.</a><br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
Malicious programs can be divided into the following groups: <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a>, viruses, Trojans, <a href="http://www.badxp.com/tag/hacker/" class="st_tag internal_tag" rel="tag" title="Posts tagged with hacker">hacker</a> utilities and other <a href="http://www.badxp.com/tag/malware/" class="st_tag internal_tag" rel="tag" title="Posts tagged with malware">malware</a>. All of these are designed to damage the infected machine or other networked machines.</p>
<p><u><strong>Network <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">Worms</a></strong></u><br />
This category includes programs that propagate via LANs or the Internet with the following objectives:</p>
<ul>
<li>Penetrating remote machines</li>
<li>Launching copies on victim machines</li>
<li>Spreading further to new machines</li>
</ul>
<p><a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">Worms</a> use different networking systems to propagate: email, instant messaging, file-sharing (P2P), IRC channels, LANs, WANs and so forth.</p>
<p>Most existing <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a> spread as files in one form or another - email attachments, in ICQ or IRC messages, links to files stored on infected websites or FTP servers, files accessible via P2P networks and so on.</p>
<p>There are a small number of so-called fileless or packet <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a>; these spread as network packets and directly penetrate the RAM of the victim machine, where the code is then executed.</p>
<p><a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">Worms</a> use a variety of methods for penetrating victim machines and subsequently executing code, including:</p>
<ul>
<li>Social engineering; emails that encourage recipients to open the attachment</li>
<li>Poorly configured networks; networks that leave local machines open to access from outside the network</li>
<li>Vulnerabilities in operating systems and applications</li>
</ul>
<p>Today&#8217;s <a href="http://www.badxp.com/tag/malware/" class="st_tag internal_tag" rel="tag" title="Posts tagged with malware">malware</a> is often a composite creation: <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a> now often include <a href="http://www.badxp.com/tag/trojan/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trojan">Trojan</a> functions or are able to infect exe files on the victim machine. They are no longer pure <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a>, but blended threats.</p>
<p><u><strong>Classic Viruses</strong></u><br />
This class of malicious programs covers programs that spread copies of themselves throughout a single machine in order to:</p>
<ul>
<li>Launch and/or execute this code once a user fulfills a designated action</li>
<li>Penetrate other resources within the victim machine</li>
</ul>
<p>Unlike <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a>, viruses do not use network resources to penetrate other machines. Copies of viruses can penetrate other machines only if an infected object is accessed and the code is launched by a user on an uninfected machine. This can happen in the following ways:</p>
<ul>
<li>The <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> infects files on a network resource that other users can access</li>
<li>The <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> infects removable storage media which are then attached to a clean machine</li>
<li>The user attaches an infected file to an email and sends it to a &#8216;healthy&#8217; recipient</li>
</ul>
<p>Viruses are sometimes carried by <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a> as additional payloads or they can themselves include backdoor or <a href="http://www.badxp.com/tag/trojan/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trojan">Trojan</a> functionality which destroy data on an infected machine.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
<u><strong><a href="http://www.badxp.com/tag/trojan/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trojan">Trojan</a> Programs</strong></u><br />
This class of <a href="http://www.badxp.com/tag/malware/" class="st_tag internal_tag" rel="tag" title="Posts tagged with malware">malware</a> includes a wide variety of programs that perform actions without the user&#8217;s knowledge or consent: collecting data and sending it to a cyber criminal, destroying or altering data with malicious intent, causing the computer to malfunction, or using a machine&#8217;s capabilities for malicious or criminal purposes, such as sending spam.</p>
<p>A subset of Trojans damage remote machines or networks without compromising infected machines; these are Trojans that utilize victim machines to participate in a DoS attack on a designated web site.</p>
<p><u><strong><a href="http://www.badxp.com/tag/hacker/" class="st_tag internal_tag" rel="tag" title="Posts tagged with hacker">Hacker</a> Utilities and other malicious programs</strong></u><br />
This diverse class includes:</p>
<ul>
<li>Utilities such as constructors that can be used to create viruses, <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a> and Trojans</li>
<li>Program libraries specially developed to be used in creating <a href="http://www.badxp.com/tag/malware/" class="st_tag internal_tag" rel="tag" title="Posts tagged with malware">malware</a></li>
<li><a href="http://www.badxp.com/tag/hacker/" class="st_tag internal_tag" rel="tag" title="Posts tagged with hacker">Hacker</a> utilities that encrypt infected files to hide them from <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> software</li>
<li>Jokes that interfere with normal computer function</li>
<li>Programs that deliberately misinform users about their actions in the system</li>
<li>Other programs that are designed to directly or indirectly damage local or networked machines</li>
</ul>

	Tags: <a href="http://www.badxp.com/tag/hacker/" title="hacker" rel="tag">hacker</a>, <a href="http://www.badxp.com/tag/malware/" title="malware" rel="tag">malware</a>, <a href="http://www.badxp.com/tag/spyware/" title="spyware" rel="tag">spyware</a>, <a href="http://www.badxp.com/tag/trojan/" title="trojan" rel="tag">trojan</a>, <a href="http://www.badxp.com/tag/virus/" title="virus" rel="tag">virus</a>, <a href="http://www.badxp.com/tag/worms/" title="worms" rel="tag">worms</a><br />

	<h4>See also:</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.badxp.com/20/the-best-antivirus-program/" title="The best antivirus program (February 15, 2008)">The best antivirus program</a> (2)</li>
	<li><a href="http://www.badxp.com/4/trixcua-worm/" title="Trixcu.A worm (November 20, 2007)">Trixcu.A worm</a> (1)</li>
	<li><a href="http://www.badxp.com/1/the-genealogy-of-virus/" title="The Genealogy of Virus (November 19, 2007)">The Genealogy of Virus</a> (9)</li>
	<li><a href="http://www.badxp.com/45/romeo-aka-ills-cixent/" title="RoMeO A.K.A ILLS [CIXENT] (March 1, 2008)">RoMeO A.K.A ILLS [CIXENT]</a> (5)</li>
	<li><a href="http://www.badxp.com/52/remove-vbsbutsur-a-or-bhadllvbs-fix/" title="Remove VBS/ButSur-A or BHA.DLL.VBS fix (March 4, 2008)">Remove VBS/ButSur-A or BHA.DLL.VBS fix</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.badxp.com/13/descriptions-of-malicious-programs/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Trixcu.A worm</title>
		<link>http://www.badxp.com/4/trixcua-worm/</link>
		<comments>http://www.badxp.com/4/trixcua-worm/#comments</comments>
		<pubDate>Tue, 20 Nov 2007 14:31:27 +0000</pubDate>
		<dc:creator>Faizi</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Viruses]]></category>

		<category><![CDATA[adware]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[spyware]]></category>

		<category><![CDATA[trixcu.a]]></category>

		<category><![CDATA[trixcu.a worm]]></category>

		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.badxp.com/2007/11/20/trixcua-worm/</guid>
		<description><![CDATA[Trixcu.A worm have been spreading through removable drives and I have been receiving a lot of queries regarding this worms.



Trixcu.A creates the following files, which copies itself when it&#8217;s run by opening the removable drives infected with the worm.

Trixcu.A creates the following files in the Windows system directory (C:\Windows\System32),:
- Cmd.com
- Dxdiag.com
- Flash.10.exe
- JambanMu.com
- Msconfig.com
- Ping.com
- [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a></strong> <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a> have been spreading through removable drives and I have been receiving a lot of queries regarding this <a href="http://www.badxp.com/tag/worms/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worms">worms</a>.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
<strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a></strong> creates the following files, which copies itself when it&#8217;s run by opening the removable drives infected with the <a href="http://www.badxp.com/tag/worm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with worm">worm</a>.</p>
<ol>
<li><strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a></strong> creates the following files in the Windows system directory (C:\Windows\System32),:<br />
- Cmd.com<br />
- Dxdiag.com<br />
- <strong><a href="http://www.badxp.com/tag/flash10exe/" class="st_tag internal_tag" rel="tag" title="Posts tagged with flash.10.exe">Flash.10.exe</a></strong><br />
- <strong><a href="http://www.badxp.com/tag/jambanmucom/" class="st_tag internal_tag" rel="tag" title="Posts tagged with JambanMu.com">JambanMu.com</a></strong><br />
- Msconfig.com<br />
- Ping.com<br />
- Regedit.com</li>
<li><strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a></strong> create the following file in C:\Program Files\Common Files\Microsoft Shared<br />
- <a href="http://www.badxp.com/tag/macromedia10exe/" class="st_tag internal_tag" rel="tag" title="Posts tagged with macromedia.10.exe">Macromedia.10.exe</a></li>
<li><strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a></strong> create the following file in C:\Program Files\Common Files\Microsoft Shared\DAO<br />
- Msn.msn</li>
<li><strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a></strong> create the following file in C:\Documents and Settings\(User)\Start Menu\Programs\Startup<br />
- (Empty).empty</li>
<li><strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a></strong> will delete all the programs in the Startup directory to disable those programs to run whenever Windows is started.</li>
<li><strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a></strong> create the following Folder:<br />
- MY.SECRET.FOLD in My Documents<br />
- NEW SONG.LAGU and NEW VIDEO.VIDZ in My Document\My Music<br />
- AWEKS.PIKZ and SERAM.PIKZ in My Documents\My Pictures</li>
</ol>
<p><strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a></strong> create the following entries in the Windows Registry:</p>
<ol>
<li><em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Run<br />
Windows MSN = C:\Program Files\Common Files\Microsoft Shared\DAO\MSN.msn</em><br />
By creating this entry, <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> ensures that it is run whenever Windows is started.</li>
<li><em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Policies\ Explorer</em><br />
NoFind = 01, 00, 00, 00<br />
It disables the option Find of the Start menu.</li>
<li><em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Policies\ Explorer</em><br />
NoFolderOptions = 01, 00, 00, 00<br />
It disables the option Folder Options of the Start menu.</li>
<li><em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Policies\ System\</em> DisableRegistryTools = 01, 00, 00, 00<br />
It doesn&#8217;t allow the Windows Registry Editor to be run.</li>
<li><em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Policies\ System</em> DisableCMD = 01, 00, 00, 00<br />
It doesn&#8217;t allow the CMD shell to be run.</li>
<li><em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Policies\ System</em><br />
DisableTaskMgr = 01, 00, 00, 00<br />
It prevents the Task Manager from being run.</li>
<li><em>HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ JambanMuV2\ Date</em><br />
(Default) = 070617</li>
<li><em>HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ JambanMuV2\ MsgDate</em><br />
(Default) = 070701</li>
<li><em>HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ JambanMuV2\ MsgMkr</em><br />
(Default) = 0</li>
<li><em>HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ JambanMuV2\ FUCK AZAM</em><br />
(Default) = THIS GUY SHIT HEAD!!BIG LIER!!FUCKING GAY!!</li>
<li><em>HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ JambanMuV2\ FUCK DZULKIFLI</em><br />
(Default) = THIS GUY PIG HEAD!!!!U FUCKED EVERYBODY!!</li>
<li><em>HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ JambanMuV2\ FUCK ZAWAWI</em><br />
(Default) = THIS GUY DICK HEAD!!!NOBODY LIKES U!!!</li>
</ol>
<p><strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a></strong> modifies the following registry entries</p>
<ol>
<li><em>HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon</em><br />
Shell = Explorer.exe<br />
It changes this entry to:<br />
<em>HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon</em><br />
Shell = Explorer.exe %sysdir%\<a href="http://www.badxp.com/tag/jambanmucom/" class="st_tag internal_tag" rel="tag" title="Posts tagged with JambanMu.com">JambanMu.com</a><br />
where %sysdir% is the Windows system directory.</li>
<li><em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows NT\ CurrentVersion\ Windows</em><br />
load<br />
It changes this entry to:<br />
<em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows NT\ CurrentVersion\ Windows</em><br />
load = <a href="http://www.badxp.com/tag/flash10exe/" class="st_tag internal_tag" rel="tag" title="Posts tagged with flash.10.exe">Flash.10.exe</a><br />
By modifying these entries, <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> ensures that it is run whenever Windows is started.</li>
<li><em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced</em><br />
Hidden = 01, 00, 00, 00<br />
It changes this entry to:<br />
<em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced</em><br />
Hidden = 00, 00, 00, 00<br />
By modifying this entry, <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> hides the files and subfolders that have the attribute hidden.</li>
<li><em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced</em><br />
HideFileExt = 00, 00, 00, 00<br />
It changes this entry to:<br />
<em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced</em><br />
HideFileExt = 01, 00, 00, 00<br />
By modifying this entry, <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> hides the extensions of the files.</li>
<li><em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced</em><br />
ShowSuperHidden = 01, 00, 00, 00<br />
It changes this entry to:<br />
<em>HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced</em><br />
ShowSuperHidden = 00, 00, 00, 00</li>
<li><em>HKEY_LOCAL_MACHINE\ Software\ Microsoft\ Windows NT\ CurrentVersion</em><br />
RegisteredOwner = %name with which the system is registered%<br />
It changes this entry to:<br />
<em>HKEY_LOCAL_MACHINE\ Software\ Microsoft\ Windows NT\ CurrentVersion</em><br />
RegisteredOwner = JambanMuV2</li>
<li><em>HKEY_LOCAL_MACHINE\ Software\ Microsoft\ Windows NT\ CurrentVersion</em><br />
RegisteredOrganization = %name of the organization with which the system is registered%<br />
It changes this entry to:<br />
<em>HKEY_LOCAL_MACHINE\ Software\ Microsoft\ Windows NT\ CurrentVersion</em><br />
RegisteredOrganization = HELP ME!!.html<br />
By modifying these entries, <a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> changes the names with which the operating system and the organization are registered.</li>
</ol>
<p><strong><a href="http://www.badxp.com/tag/trixcua/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trixcu.a">Trixcu.A</a> </strong>created files can be remove manually or automatically by most of <a href="http://www.badxp.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">Antivirus</a>, just make sure you update your <a href="http://www.badxp.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> definition files. The registry entry have to be remove manually though.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4963985439908056";
google_ad_channel = "7303333523";
google_ui_features = "rc:0";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "376699";
google_color_text = "3c3c3c";
google_color_url = "b1b515";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>

	Tags: <a href="http://www.badxp.com/tag/adware/" title="adware" rel="tag">adware</a>, <a href="http://www.badxp.com/tag/malware/" title="malware" rel="tag">malware</a>, <a href="http://www.badxp.com/tag/spyware/" title="spyware" rel="tag">spyware</a>, <a href="http://www.badxp.com/tag/trixcua/" title="trixcu.a" rel="tag">trixcu.a</a>, <a href="http://www.badxp.com/tag/trixcua-worm/" title="trixcu.a worm" rel="tag">trixcu.a worm</a>, <a href="http://www.badxp.com/tag/virus/" title="virus" rel="tag">virus</a><br />

	<h4>See also:</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.badxp.com/1/the-genealogy-of-virus/" title="The Genealogy of Virus (November 19, 2007)">The Genealogy of Virus</a> (9)</li>
	<li><a href="http://www.badxp.com/20/the-best-antivirus-program/" title="The best antivirus program (February 15, 2008)">The best antivirus program</a> (2)</li>
	<li><a href="http://www.badxp.com/45/romeo-aka-ills-cixent/" title="RoMeO A.K.A ILLS [CIXENT] (March 1, 2008)">RoMeO A.K.A ILLS [CIXENT]</a> (5)</li>
	<li><a href="http://www.badxp.com/52/remove-vbsbutsur-a-or-bhadllvbs-fix/" title="Remove VBS/ButSur-A or BHA.DLL.VBS fix (March 4, 2008)">Remove VBS/ButSur-A or BHA.DLL.VBS fix</a> (6)</li>
	<li><a href="http://www.badxp.com/13/descriptions-of-malicious-programs/" title="Descriptions of Malicious Programs (January 22, 2008)">Descriptions of Malicious Programs</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.badxp.com/4/trixcua-worm/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
