Re: How to remove PWS-Bluedit

Re: How to remove PWS-Bluedit

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: How to remove PWS-Bluedit - 781 08-16-2006
Posted by - 781 on August 16, 2006, 3:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options
2.exe and IExplorer.dll were the viruse files of PWS-Bluedit together with
some registry edits which are here:
http://vil.nai.com//vil/content/v_132935.htm
IExplorer.dll was a dbt filetype and when I looked at File Types in Folder
Options, I noticed it was referring to a file called NOTEDAD.exe
I have deleted a NOTEDAD.exe file that .dbt file was directed to.
I haven't noticed that it was in fact not notePAD, but it was noteDAD.exe.
Inside my registry, I had deleted .ini, .bat, .txt registry locations that
had NOTEDAD.exe

bat registry location that I deleted was in registry located at:
HKCR\batfile\shell\edit\comman (Default) REG_SZ "C:\Windows\NOTEDAD.EXE"
Later I edited the Default value to "%1"%*
I thought that it needed some sort of value in it and copied it from
OPEN\COMMAND's Default value.

I did the same for ini, txt, reg locations that NOTEDAD.exe was found.

Now I think this is the reason that I am unable to edit batfiles, txt files,
ini files since upon right clicking and choosing EDIT, it opens the file.

How can I get my registry back and fix it in regards to editing txt, ini,
bat, reg files.
Thank you.
Hope this was as clear to fix my problem.
Gino.


>I somehow infected my pc with the PWS-Bluedit virus.
> Norton Antivirus 2006 with updated virus definitions was unable to remove
> the virus as it keeps coming back.
> Here is the website from McAfee
> http://vil.nai.com//vil/content/v_132935.htm
>
> Can someone tell me whether I can get a removal tool or do I have to buy
> McAfee?
> Thanks.
> Running WinXP Pro SP2.
>
>



Posted by David H. Lipman on August 16, 2006, 7:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| 2.exe and IExplorer.dll were the viruse files of PWS-Bluedit together with
| some registry edits which are here:
| http://vil.nai.com//vil/content/v_132935.htm
| IExplorer.dll was a dbt filetype and when I looked at File Types in Folder
| Options, I noticed it was referring to a file called NOTEDAD.exe
| I have deleted a NOTEDAD.exe file that .dbt file was directed to.
| I haven't noticed that it was in fact not notePAD, but it was noteDAD.exe.
| Inside my registry, I had deleted .ini, .bat, .txt registry locations that
| had NOTEDAD.exe

| bat registry location that I deleted was in registry located at:
| HKCR\batfile\shell\edit\comman (Default) REG_SZ "C:\Windows\NOTEDAD.EXE"
| Later I edited the Default value to "%1"%*
| I thought that it needed some sort of value in it and copied it from
| OPEN\COMMAND's Default value.

| I did the same for ini, txt, reg locations that NOTEDAD.exe was found.

| Now I think this is the reason that I am unable to edit batfiles, txt files,
| ini files since upon right clicking and choosing EDIT, it opens the file.

| How can I get my registry back and fix it in regards to editing txt, ini,
| bat, reg files.
| Thank you.
| Hope this was as clear to fix my problem.
| Gino.


>>I somehow infected my pc with the PWS-Bluedit virus.
>> Norton Antivirus 2006 with updated virus definitions was unable to remove
>> the virus as it keeps coming back.
>> Here is the website from McAfee
>> http://vil.nai.com//vil/content/v_132935.htm

>> Can someone tell me whether I can get a removal tool or do I have to buy
>> McAfee?
>> Thanks.
>> Running WinXP Pro SP2.


There was NO reason to Cross-Post this to;
microsoft.public.windows.inetexplorer.ie6.browser &
microsoft.public.windowsxp.help_and_support once you posted to;
microsoft.public.security.virus

Follow-ups set to; microsoft.public.security.virus


The Multi AV Scanning Tool corrects the Registry enties you posted. You were
asked to run
the Multi AV Scanning Tool and post your results.

I don't see the requested HTML Log files.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by - 781 on August 16, 2006, 5:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
RESULTS:

08/16/2006 13:53:18

Options:
"C:\" /UNZIP /WINMEM /SUB /ANALYZE /PANALYZE /STREAMS /CLEAN /ALL /DEL /MIME
/PROGRAM /EXCLUDE C:\AV-CLS\EXCLIST.TXT /HTML
"C:\AV-CLS\MCAFEE\SCANREPORT.HTML"

Scanning C: [MAIN]
Scanning C:\*.*
C:\Documents and Settings\Chaxkal\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-5f22f99-372d5264.zip\NEWSECURITYCLASSLOADER.CLASS
... Found the Generic Downloader.v trojan !!!
C:\Documents and Settings\Chaxkal\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-5f22f99-372d5264.zip\NEWURLCLASSLOADER.CLASS
... Found the Exploit-ByteVerify trojan !!!
C:\Documents and Settings\Chaxkal\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-1ab62644-2c7b60a3.zip\DUMMY.CLASS
... Found the Exploit-ByteVerify trojan !!!

Summary report on C:\*.*
File(s)
Total files: ........... 140090
Clean: ................. 139890
Possibly Infected: ..... 3
Cleaned: ............... 0
Non-critical Error(s): 2


Time: 00:38.25

>
> | 2.exe and IExplorer.dll were the viruse files of PWS-Bluedit together
> with
> | some registry edits which are here:
> | http://vil.nai.com//vil/content/v_132935.htm
> | IExplorer.dll was a dbt filetype and when I looked at File Types in
> Folder
> | Options, I noticed it was referring to a file called NOTEDAD.exe
> | I have deleted a NOTEDAD.exe file that .dbt file was directed to.
> | I haven't noticed that it was in fact not notePAD, but it was
> noteDAD.exe.
> | Inside my registry, I had deleted .ini, .bat, .txt registry locations
> that
> | had NOTEDAD.exe
>
> | bat registry location that I deleted was in registry located at:
> | HKCR\batfile\shell\edit\comman (Default) REG_SZ
> "C:\Windows\NOTEDAD.EXE"
> | Later I edited the Default value to "%1"%*
> | I thought that it needed some sort of value in it and copied it from
> | OPEN\COMMAND's Default value.
>
> | I did the same for ini, txt, reg locations that NOTEDAD.exe was found.
>
> | Now I think this is the reason that I am unable to edit batfiles, txt
> files,
> | ini files since upon right clicking and choosing EDIT, it opens the
> file.
>
> | How can I get my registry back and fix it in regards to editing txt,
> ini,
> | bat, reg files.
> | Thank you.
> | Hope this was as clear to fix my problem.
> | Gino.
>
>
>>>I somehow infected my pc with the PWS-Bluedit virus.
>>> Norton Antivirus 2006 with updated virus definitions was unable to
>>> remove
>>> the virus as it keeps coming back.
>>> Here is the website from McAfee
>>> http://vil.nai.com//vil/content/v_132935.htm
>
>>> Can someone tell me whether I can get a removal tool or do I have to buy
>>> McAfee?
>>> Thanks.
>>> Running WinXP Pro SP2.
>
>
> There was NO reason to Cross-Post this to;
> microsoft.public.windows.inetexplorer.ie6.browser &
> microsoft.public.windowsxp.help_and_support once you posted to;
> microsoft.public.security.virus
>
> Follow-ups set to; microsoft.public.security.virus
>
>
> The Multi AV Scanning Tool corrects the Registry enties you posted. You
> were asked to run
> the Multi AV Scanning Tool and post your results.
>
> I don't see the requested HTML Log files.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Posted by David H. Lipman on August 16, 2006, 6:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| RESULTS:
|
| 08/16/2006 13:53:18
|
| Options:
| "C:\" /UNZIP /WINMEM /SUB /ANALYZE /PANALYZE /STREAMS /CLEAN /ALL /DEL /MIME
| /PROGRAM /EXCLUDE C:\AV-CLS\EXCLIST.TXT /HTML
| "C:\AV-CLS\MCAFEE\SCANREPORT.HTML"
|
| Scanning C: [MAIN]
| Scanning C:\*.*
| C:\Documents and Settings\Chaxkal\Application
|
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-5f22f99-372d5264.zip\NEWSECURITYCL
| ASSLOADER.CLASS
| ... Found the Generic Downloader.v trojan !!!
| C:\Documents and Settings\Chaxkal\Application
|
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-5f22f99-372d5264.zip\NEWURLCLASSLO
| ADER.CLASS
| ... Found the Exploit-ByteVerify trojan !!!
| C:\Documents and Settings\Chaxkal\Application
|
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-1ab62644-2c7b60a3.zip\DUMM
| Y.CLASS
| ... Found the Exploit-ByteVerify trojan !!!
|




If you are using any version of Sun Java that is prior to JRE Version 5.0 update
5,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0 update 5. There are vulnerabilities in them and they are actively
being
exploited. It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun
Java
to Version 5 on the PC that they be removed ASAP.

The latest version is Sun Java JRE/JSE Version 5.0 Update 8

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version.

Such as...
C:\Program Files\Java\jre1.5.0_08

http://www.java.com/en/download/manual.jsp

or

http://java.sun.com/javase/downloads/index.jsp

1) Dump the contents of your IE cache -
Start --> settings --> control panel --> Internet options --> delete
files

2) Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
Tools --> Options --> Privacy --> Cache --> Clear

3) Dump the contents of your Sun Java cache -
Start --> settings --> control panel --> Java applet --> cache --> clear
or
Start --> settings --> control panel --> Java applet --> general -->
settings -->
delete files

4) Re-scan your system using the Sophos module of the Multi AV Scanning Tool.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?UGFuZGFfbWFu?= on August 17, 2006, 6:00 am
If you were  Registered and logged in, you could reply and use other advanced thread options
"David H. Lipman" wrote:


> The Multi AV Scanning Tool corrects the Registry enties you posted.
>


Hi Dave , which module/scanner fixes corrupted or infected registry entries ?
Thanks in advance ! :)


--
Panda_man
Bronze level Contributor


Similar ThreadsPosted
Remove FCS SSA information July 15, 2008, 7:19 am
i can't remove BACKDOOR.SDBOT HELP! July 5, 2005, 9:12 am
How do I remove Purstiu Virus July 15, 2005, 3:51 pm
Help Remove Trojan.KillReg August 7, 2005, 3:57 pm
how to remove "windows onecare"? September 21, 2005, 6:55 am
stuck can't remove NIS2005 February 5, 2006, 9:35 pm
WD fails to remove WinTools February 17, 2006, 6:48 pm
How to Remove Adware.TargetSaver ? March 31, 2006, 6:22 pm
How do I remove Downloader virus??? Help! July 13, 2006, 9:29 pm
Can't remove image in desktop October 6, 2006, 11:00 pm

The site map in XML format XML site map

Contact Us | Privacy Policy