|
free virus removal tool for bldk (@bldk@.htm,smss.exe,svchost.exe)
|
|
Written by Administrator |
Friday, 18 September 2009 08:58
|
A virus which disturb by posting a Web page with each time Windows starts.
Is propagated in network and via removable media regularly. Beware of applications that have the same name as the file system but that is not in the system directory.
Creates four files :
- <User>\Application Data\svchost.exe
- <System>\Sexy Girls.scr
- <Windows>\inf\smss.exe
- <Root>\@bldk@.htm
Registry entries created :
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer DisallowRun 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer NoFolderOptions 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer NoFind 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer NoRun 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun 1 cmd.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun 2 mmc.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun 3 rstrui.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun 4 regedit.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun 5 regedt32.exe
This virus launches out automatically each time you open or explore a partition or a removable disk, it is thus preferable to download this patch and to decompress it on the desktop, to start your machine in safe mode and launch the patch, always in safe mode.

|