<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Free Spyware Adware Worm and Virus Trojan Horse Download Removal Tools &#187; backdoor</title>
	<atom:link href="http://www.softe.org/tag/backdoor/feed" rel="self" type="application/rss+xml" />
	<link>http://www.softe.org</link>
	<description>FREE Computer Repair</description>
	<lastBuildDate>Sun, 04 Dec 2011 21:36:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>BackDoor-EVC!8F7F8F47​013F Network Trojan and how to remove</title>
		<link>http://www.softe.org/backdoor-evc8f7f8f47%e2%80%8b013f-network-trojan-and-how-to-remove.html</link>
		<comments>http://www.softe.org/backdoor-evc8f7f8f47%e2%80%8b013f-network-trojan-and-how-to-remove.html#comments</comments>
		<pubDate>Fri, 30 Sep 2011 04:39:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[BackDoor-EVC!8F7F8F47​013F Network Trojan and how to remove]]></category>
		<category><![CDATA[back door]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[network virus]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=166</guid>
		<description><![CDATA[This backdoor Trojan  infects  files, registry, and network communication. The following registry elements have been created: HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\ HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\ HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\ HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\ HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\INPROCSERVER32\ HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\ This virus can be removed with microsoft security essentials. If your PC gets locked you are getting a black screen, you might want to run scan in safe mode. Other names to reffer [...]]]></description>
			<content:encoded><![CDATA[<p>This <strong>backdoor Trojan</strong>  infects  files, registry, and network communication.</p>
<p><strong>The following registry elements have been created:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\INPROCSERVER32\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\</li>
</ul>
<div>This virus can be removed with <strong>microsoft security essentials</strong>. If your PC gets locked you are getting a black screen, you might want to run scan in safe mode.</div>
<div>Other names to reffer to.</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/backdoor-evc8f7f8f47%e2%80%8b013f-network-trojan-and-how-to-remove.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>So how do you Remove Koobface the facebook worm virus</title>
		<link>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html</link>
		<comments>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html#comments</comments>
		<pubDate>Thu, 08 Sep 2011 18:50:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[So how do you Remove Koobface the facebook worm virus]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[google redirect spyware]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[windows xp]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=159</guid>
		<description><![CDATA[Koobface Virus threat is one that is taking by storm, specially because it uses a host such as facebook social network to spread the virus.  This Koobface virus finds methods to seek into the users PC and spread malware into the computer so its considered as a worm which replicates itself within your computer.  So [...]]]></description>
			<content:encoded><![CDATA[<p>Koobface Virus threat is one that is taking by storm, specially because it uses a host such as facebook social network to spread the virus.  This Koobface virus finds methods to seek into the users PC and spread malware into the computer so its considered as a worm which replicates itself within your computer.  So how does KoobFace infect your PC, well its simple really, if you use facebook, and you receive a strange email, stating something along the lines of &#8221; click here to see your face look stupid&#8221; which attracts you to click the link,  once clicked, a virus code will be downloaded to your PC which will then spread the worm to your PC and start to redirect your search results from google to malicious software and websites. Simple huh?</p>
<div>
<div id="mod_2169282">
<div id="txtd_2169282">
<div>
<div id="mod_2169300">
<h2>So how do you Remove Koobface worm virus?</h2>
<div id="txtd_2169300">With  anti-malware software such as melwarebytes and spybot, you might be able to remove this worm, but sometimes this is not possible and you need to manually remove it.</p>
<div>
<div id="mod_2169358">
<div id="txtd_2169358">
<p><strong>Using The Add Remove Program in control panel:</strong></p>
<ul>
<li>Go to Add\Remove in control panel</li>
<li>Look up for the Koobface malware to remove and uninstall it.</li>
</ul>
<p>if you do not see the koobface there, go to registry and search for: ( <span style="color: #ff0000;">if you do not know how to use your registry, you might really screw up your PC for good, so take note, this step is for advanced users who have messed around with the registry and know their way around</span>.)</p>
<ul>
<li>Search for &#8220;koobface&#8221; in Mycomputer using find utility.</li>
<li>Note down Koobface file path some where.</li>
<li>Press Ctrl+Alt+Del to open &#8216;Task Manager&#8217;</li>
<li>End the &#8220;Koobface&#8221; processes.</li>
</ul>
<p><strong>End the following processes</strong></p>
<ol>
<li>%SYSTEMROOT%\bolivar28.exe</li>
<li>che07.exe</li>
<li>bolivar28.exe</li>
<li>%WinDir%\system32\nScan\ekrn.exe</li>
<li>%WinDir%\system32\nScan\ecls.exe</li>
<li>%WinDir%\system32\splm\ncsjapi32.exe</li>
<li>%WinDir%\bolivar28.exe</li>
<li>C:\Windows\fbtre6.exe</li>
</ol>
<p><strong>now change Registry Files</strong></p>
<ul>
<li>Type &#8216;regedit&#8217; in Run and press Enter.</li>
<li>The Registry Editor will appear, locate the above mentioned process files and delete them.</li>
<li>Locate &#8220;Koobface&#8221; registry entries and delete them, they are as the follows:</li>
</ul>
<ol>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Intelli Mouse Pro Version 2.0B\StubPath: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Intelli Mouse Pro Version 2.0B: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden: &#8220;2&#8243;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\nScan32\ExecuteDate: &#8220;14\8\2008&#8243;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\&#8221;systray&#8221; = &#8220;c:\windows\mstre6.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\&#8221;systray&#8221; = &#8220;C:\Windows\fbtre6.exe&#8221;</li>
<li>HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating</li>
</ol>
</div>
</div>
</div>
<div id="mod_2169659">
<div id="txtd_2169659">
<p><strong>Now you have to unregister the dll files</strong></p>
<ul>
<li>Go to start and type in &#8216;cmd&#8217; to open comman prompt.</li>
<li>First locate the following dll files using &#8216;dir&#8217; command.</li>
</ul>
<ol>
<li>%WinDir%\system32\nScan\ekrnEmon.dll</li>
<li>%WinDir%\system32\nScan\ekrnScan.dll</li>
<li>%WinDir%\system32\nScan\ekrnEpfw.dll</li>
<li>%WinDir%\system32\nScan\ekrnAmon.dll</li>
<li>%WinDir%\system32\splm\lmfunit32.dll</li>
<li>%WinDir%\system32\splm\mcaserv32.dll</li>
<li>%WinDir%\system32\splm\kbdsapi.dll</li>
</ol>
<ul>
<li>Now change the current directory using &#8216;cd&#8217; command leave a space after &#8216;cd&#8217; and then the path of dll file, which you have located above. Press enter after this.</li>
<li>Now unregister dll file by typing &#8220;directory path+&#8217;regsvr32/u&#8217;+dll file name&#8221;. Press enter, the file will be unregistered.</li>
</ul>
<p>&nbsp;</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic BackDoor!djf!5D41C80E​A0DA malware Trojan Virus</title>
		<link>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html</link>
		<comments>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html#comments</comments>
		<pubDate>Wed, 20 Jul 2011 22:58:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic BackDoor!djf!5D41C80E​A0DA malware Trojan Virus]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[IRC virus]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[virus removal]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[W32/Autorun]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=154</guid>
		<description><![CDATA[These files were added to the system: %APPDATA%\services.exe %TEMP%\e3c1c08557a0d0feee33b9c9d18b4e6c129b553f.exe This Trojan will attempt to fiddle with your network conection, e.g hxxp://www.maxmind.com/app/*** Virus app&#8217;s Detection Names EMSI Software Trojan.Backdoor.Ircbot!IK avast Win32:Ruskill-F Kaspersky Backdoor.Win32.IRCBot.tjd BitDefender Backdoor.Bot.138642 Microsoft VirTool:Win32/CeeInject.gen!EI Symantec Backdoor.IRC.Bot Eset a variant of Win32/Injector.GLN trojan norman W32/Suspicious_Gen3.TYCW Sophos Mal/Generic-L Trend Micro PAK_Generic.001 vba32 Backdoor.IRCBot.tjd How to [...]]]></description>
			<content:encoded><![CDATA[<p>These files were added to the system:</p>
<ul>
<li>%APPDATA%\services.exe</li>
</ul>
<ul>
<li>%TEMP%\e3c1c08557a0d0feee33b9c9d18b4e6c129b553f.exe</li>
</ul>
<p>This Trojan will attempt to fiddle with your network conection, e.g hxxp://www.maxmind.com/app/***</p>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr bgcolor="silver">
<th align="left" bgcolor="silver"><strong>Virus app&#8217;s<br />
</strong></th>
<th align="right" bgcolor="silver"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">EMSI Software</td>
<td align="right">Trojan.Backdoor.Ircbot!IK</td>
</tr>
<tr>
<td align="left">avast</td>
<td align="right">Win32:Ruskill-F</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Backdoor.Win32.IRCBot.tjd</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Backdoor.Bot.138642</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">VirTool:Win32/CeeInject.gen!EI</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">Backdoor.IRC.Bot</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">a variant of Win32/Injector.GLN trojan</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Suspicious_Gen3.TYCW</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Mal/Generic-L</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">PAK_Generic.001</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">Backdoor.IRCBot.tjd</td>
</tr>
</tbody>
</table>
<p>How to remove <strong>Generic BackDoor!djf!5D41C80E​A0DA</strong></p>
<p>Removal should be easy given the fact that you are able to follow directions <img src='http://www.softe.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>First thing to do is disconnect your network or internet. Now you will need to reboot your PC and enter safe mode, if you do not know how to enter safe mode, please search above for &#8221; how to enter safe mode&#8221;</p>
<p>Now you will need to do a system scan using these apps below:</p>
<p>1. your favorite virus app, i suggest AVG or Microsoft security essentials<br />
2. do a system scan using Malwarebytes<br />
3. do a system scan using spybot<br />
4. do a system scan using hijackthis</p>
<p>if the virus  is not letting you do these scans, you must :</p>
<p>1.Disable System Restore on Windows ME and windows XP only.<br />
2.Update to current engine and DAT files for detection and removal.<br />
3.Run a complete system scan.</p>
<p>This should remove the threat, this threat is a low security threat but never the less it should always be cleaned before using the world wide web.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Profile: BackDoor-CEP.gen how to clean</title>
		<link>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html</link>
		<comments>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html#comments</comments>
		<pubDate>Fri, 20 May 2011 06:16:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Profile: BackDoor-CEP.gen how to clean]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=140</guid>
		<description><![CDATA[Virus Profile: BackDoor-CEP.gen.cq!CF151229CE1E avast Win32:Caxnet [Trj] AVG (GriSoft) Rootkit-Pakes.BG (Trojan horse) avira TR/Koutodoor.psa Kaspersky HEUR:Trojan.Win32.Generic BitDefender Gen:Variant.Koutodoor.18 clamav Trojan.Dropper-27717 Dr.Web Trojan.MulDrop.origin F-Prot W32/Koutodoor.N.gen!Eldorado FortiNet W32/Koutodoor.KWD!tr.bdr Microsoft Trojan:Win32/Koutodoor.E Symantec Trojan.Koutodoor Eset Win32/Koutodoor.HM trojan (variant) norman W32/Suspicious_Gen2.LZIQS (trojan) panda Trj/Genetic.gen rising Trojan.Win32.Generic.1282E422 Sophos Troj/Kouto-D Trend Micro TROJ_DLOADR.SMOM vba32 Trojan.Downloader.gen.h (suspected) The following files have been added to [...]]]></description>
			<content:encoded><![CDATA[<p>Virus Profile: BackDoor-CEP.gen.cq!CF151229CE1E</p>
<p>avast	Win32:Caxnet [Trj]<br />
AVG (GriSoft)	Rootkit-Pakes.BG (Trojan horse)<br />
avira	TR/Koutodoor.psa<br />
Kaspersky	HEUR:Trojan.Win32.Generic<br />
BitDefender	Gen:Variant.Koutodoor.18<br />
clamav	Trojan.Dropper-27717<br />
Dr.Web	Trojan.MulDrop.origin<br />
F-Prot	W32/Koutodoor.N.gen!Eldorado<br />
FortiNet	W32/Koutodoor.KWD!tr.bdr<br />
Microsoft	Trojan:Win32/Koutodoor.E<br />
Symantec	Trojan.Koutodoor<br />
Eset	Win32/Koutodoor.HM trojan (variant)<br />
norman	W32/Suspicious_Gen2.LZIQS (trojan)<br />
panda	Trj/Genetic.gen<br />
rising	Trojan.Win32.Generic.1282E422<br />
Sophos	Troj/Kouto-D<br />
Trend Micro	TROJ_DLOADR.SMOM<br />
vba32	Trojan.Downloader.gen.h (suspected)</p>
<p>The following files have been added to the system:<br />
%WINDIR%\SYSTEM32\szccw.dll<br />
%TEMP%\nsd12.tmp<br />
%PROGRAMFILES%\Microsoft\ie13\Internat Explorer\target.lnk<br />
%ALLUSERSPROFILE%\Desktop\Internat Explorer.jgp<br />
%WINDIR%\SYSTEM32\drivers\fmsde.sys<br />
%PROGRAMFILES%\Microsoft\ie13\Internat Explorer\Desktop.ini<br />
	The following files were temporarily written to disk then later removed:<br />
%TEMP%\hmufctw.bat<br />
%TEMP%\nsq13.tmp<br />
%TEMP%\ygnpyvce.bat<br />
%TEMP%\nsi11.tmp<br />
%WINDIR%\SYSTEM32\mhzscp.bat<br />
%TEMP%\faxjdr.exe<br />
%TEMP%\tmp.bat<br />
%TEMP%\yxcdiz.exe<br />
%TEMP%\nsq13.tmp\System.dll<br />
%TEMP%\wcyolgo.bat<br />
%TEMP%\ftrnkqxw.bat</p>
<p>This is a Trojan detection Unlike viruses Trojans do not self replicate they are spread manually under the premise that they are beneficial. The most common installation methods involve system security exploitation unsuspecting users manually executing unknown programs. Distribution channels include email malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks and what have  you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic Trojan BackDoor!cyh!E437DACF​F88B Virus Threat Removal</title>
		<link>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html</link>
		<comments>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html#comments</comments>
		<pubDate>Wed, 09 Mar 2011 05:22:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic BackDoor!cyh!E437DACF​F88B Virus Threat Removal]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[generic]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=128</guid>
		<description><![CDATA[Download Malwarebytes' Anti-Malware if you do now have this free software, from  here and save it to your computer.]]></description>
			<content:encoded><![CDATA[<p><strong>ystem Changes</strong></p>
<p>Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</p>
<p><strong>The following registry elements have been created:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\29AEB4A0365755F6-B862CAE984EA4D0E\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\29AEB4A0365755F6-B862CAE984EA4D0E\02F01F553A112DCE-00C9DB38C18D5FD1\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMADEVELOPERS\</li>
</ul>
<p><strong>The following files have been added to the system:</strong></p>
<p>* %WINDIR%\SYSTEM32\svhest.dll</p>
<p>* %WINDIR%\SYSTEM32\svhest.exe</p>
<p>To remove <strong>Generic Trojan BackDoor!cyh!E437DACF​F88B Virus</strong></p>
<p>Download Malwarebytes&#8217; Anti-Malware if you do now have this free software, from  <a href="http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html" target="_blank"><strong><span style="color: red;">here</span></strong></a> and save it to your computer.</p>
<ul>
<li>Double click <strong>mbam-setup.exe</strong> and install</li>
<li>At the end of the installation be sure a checkmark
<ul>
<li><strong>Update Malwarebytes&#8217; Anti-Malware</strong></li>
<li>and <strong>Launch Malwarebytes&#8217; Anti-Malware</strong></li>
<li><strong>do a full scan and allow your computer to fix your virus.<br />
</strong></li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove BackDoor.SmallX.VX virus trojan</title>
		<link>http://www.softe.org/how-to-remove-backdoor-smallx-vx-virus-trojan.html</link>
		<comments>http://www.softe.org/how-to-remove-backdoor-smallx-vx-virus-trojan.html#comments</comments>
		<pubDate>Tue, 13 Jul 2010 20:02:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[how to remove BackDoor.SmallX.VX virus trojan]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=75</guid>
		<description><![CDATA[Backdoor.smallX.VX is a nasty virus that enters the PC adn opens system back doors in Windows XP and Vista and could enter windows 7, once in your computer, the virus starts to download countless packed malware threats and gives distant hackers access to the infected machine via open ports. Stopzilla says to use their app [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.softe.org/wp-content/uploads/2010/07/computer-virus-bugs-clip-art7674.jpg"><img class="alignleft  size-full wp-image-76" title="computer-virus-bugs-clip-art7674" src="http://www.softe.org/wp-content/uploads/2010/07/computer-virus-bugs-clip-art7674.jpg" alt="" width="300" height="300" /></a><span style="font-family: Verdana,Arial,Helvetica,sans-serif; color: #333333; font-size: x-small;"><strong>Backdoor.smallX.VX</strong> is a nasty virus that enters the PC adn opens system back doors in Windows XP and Vista and could enter windows 7, once in your computer, the virus starts to download countless packed malware threats and gives distant hackers  access to the infected machine via open ports.</span></p>
<p><span style="font-family: Verdana,Arial,Helvetica,sans-serif; color: #333333; font-size: x-small;">Stopzilla says to use their app to remove this threat, but you can simply use </span>http://www.malwarebytes.org to remove this threat. Make sure you first download this app, update it, disconnect your PC from the internet, then run malwarebytes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-backdoor-smallx-vx-virus-trojan.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

