<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3724943210192394558</id><updated>2011-11-27T15:33:24.068-08:00</updated><title type='text'>Orilogbon Taiwo's Blog - Life &amp; Computer Issues</title><subtitle type='html'>Believe me, a Virus or Worm is just another application, with evil intents added, it needs your operating system to survive, so... just get in touch with me when you need virus solutions!</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://tlogbon.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://tlogbon.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>tlogbon</name><uri>http://www.blogger.com/profile/13741132541773900116</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://bp2.blogger.com/_l9ll1t96LYA/SH23cO03osI/AAAAAAAAAAM/8mvIKJ-V6eQ/S220/Moi.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3724943210192394558.post-1441778109556304150</id><published>2009-04-28T01:23:00.000-07:00</published><updated>2009-04-28T01:30:51.420-07:00</updated><title type='text'>Long Time No Write</title><content type='html'>It's been a very long long time since i last wrote on this blog, it's not my fault, it is school work that has been so demanding.&lt;br /&gt;Aside that I felt the blog was so boring that noboidy cared to view it.&lt;br /&gt;But again, I was wrong. i am presently working on some mind blowing articles about my Final Year Project, Bart PE &amp; Sality.aa, and lots more...&lt;br /&gt;Just hold on.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3724943210192394558-1441778109556304150?l=tlogbon.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tlogbon.blogspot.com/feeds/1441778109556304150/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3724943210192394558&amp;postID=1441778109556304150' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/1441778109556304150'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/1441778109556304150'/><link rel='alternate' type='text/html' href='http://tlogbon.blogspot.com/2009/04/long-time-no-write.html' title='Long Time No Write'/><author><name>tlogbon</name><uri>http://www.blogger.com/profile/13741132541773900116</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://bp2.blogger.com/_l9ll1t96LYA/SH23cO03osI/AAAAAAAAAAM/8mvIKJ-V6eQ/S220/Moi.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3724943210192394558.post-6036409262597243212</id><published>2008-11-10T07:08:00.000-08:00</published><updated>2008-11-10T07:25:11.961-08:00</updated><title type='text'>Red Alert: Microsoft Office Documents could be dangerous Pt 2</title><content type='html'>&lt;span style="color: rgb(255, 102, 102); font-weight: bold;"&gt;NOTE: As at the time of writing this post, I have seen a system attacked by this worm, but I believe this worm does not load with userinit or shell [explorer], so this method shoul work for it.&lt;/span&gt;  &lt;p class="MsoNormal"&gt;I just discovered that the Trojan that replicates file names as .exe is called ‘raila odinga’ though antiviruses call it by different names.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The worm which keeps displaying the picture Raila Odinga.gif has put many project students in OAU, ile-Ife into tears as many of them have mistakenly copied the worm in place of their original files.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The Worm which I talked about sometime ago replicates the name of all the files in a removable disk as a .exe.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;A solution to the virus, which I can propose for now, is to use, Tune Up Utilities, process manager or any other process managing software.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The virus usually runs from %systemroot%/systsem32/drivers/~.exe&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The file size is usually about 160Kb, please ensure that the extension of your known documents is always revealed by using Folder Options&lt;/p&gt;  &lt;p class="MsoNormal"&gt;To stop the virus, simply do the following:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Restart your system, keep pressing F8 when it comes on, select “safe mode with command prompt”&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Then choose your default OS.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Log in as an Administrator, Command Prompt starts&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast"&gt;Then follow these commands:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;TASKLIST&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt; &lt;/span&gt;REM this displays the list of all running processes&lt;/p&gt;  &lt;p class="MsoNormal"&gt;TASKKILL /im [unusual_process_name] /f&lt;/p&gt;  &lt;p class="MsoNormal"&gt;REM this stops the process specified. Say ‘Raila Odinga.exe’, that is if it is pasrt of the processes listed.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;CD %systemroot%\system32\drivers&lt;/p&gt;  &lt;p class="MsoNormal"&gt;REM this changes to the directory where the virus is mainly running from&lt;/p&gt;  &lt;p class="MsoNormal"&gt;DEL *.exe /f /q /ah &lt;/p&gt;  &lt;p class="MsoNormal"&gt;REM as no .exe is supposed to be in the drivers’ folder, this will delete all viruses&lt;/p&gt;  &lt;p class="MsoNormal"&gt;REM If it says file not found, try &lt;/p&gt;  &lt;p class="MsoNormal"&gt;DEL *.exe&lt;/p&gt;  &lt;p class="MsoNormal"&gt;REM This must delete the viruses if present.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;cd &lt;span style=""&gt; &lt;/span&gt;"\Documents and Settings\All Users\Start Menu\Programs\Startup"&lt;/p&gt;  &lt;p class="MsoNormal"&gt;DEL *.lnk *.exe&lt;/p&gt;  &lt;p class="MsoNormal"&gt;DEL *.lnk *.exe /f/q/ah&lt;/p&gt;  &lt;p class="MsoNormal"&gt;REM Restart ur system and verify if the virus is still running.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3724943210192394558-6036409262597243212?l=tlogbon.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tlogbon.blogspot.com/feeds/6036409262597243212/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3724943210192394558&amp;postID=6036409262597243212' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/6036409262597243212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/6036409262597243212'/><link rel='alternate' type='text/html' href='http://tlogbon.blogspot.com/2008/11/red-alert-microsoft-office-documents.html' title='Red Alert: Microsoft Office Documents could be dangerous Pt 2'/><author><name>tlogbon</name><uri>http://www.blogger.com/profile/13741132541773900116</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://bp2.blogger.com/_l9ll1t96LYA/SH23cO03osI/AAAAAAAAAAM/8mvIKJ-V6eQ/S220/Moi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3724943210192394558.post-2649193248980157825</id><published>2008-10-22T05:46:00.000-07:00</published><updated>2008-10-22T05:49:50.277-07:00</updated><title type='text'>Red Alert: Microsoft Office Documents could be dangerous!</title><content type='html'>&lt;p class="MsoNormal"&gt;Protect your System! &lt;/p&gt;  &lt;p class="MsoNormal"&gt;I just saw a new form of virus which copies the name of all the types of documents in your removable device, then replaces them with a .exe.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;It also uses a Microsoft word 2007 icon to represent its .exe.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Please be careful in clicking on any form of ‘MS Word like’ document.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Before clicking on any of these MS Word Document, please do the following, place your cursor on the MS Document and be sure that the side bar shows ‘Microsoft Word Document’ or&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;‘Microsoft Word 1997-2003 Document’ .&lt;/p&gt;  &lt;p class="MsoNormal"&gt;If on placing your cursor on the document, you see anything like ‘Version…’ then the file is an exe, which is most likely a virus.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The size is about 160kb; it imitates all .doc, .zip, .rar and form of file you may think of!&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Another alternative is to visit folder options and under view, uncheck ‘Hide extension for known file types’ click on OK.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;This will ensure that the extension of all your files is revealed.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;So before clicking on anything that looks like a Microsoft Office Document, be sure that the file is not an Executable.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I am yet to catch this virus.&lt;/p&gt;&lt;p class="MsoNormal"&gt;BEWARE&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3724943210192394558-2649193248980157825?l=tlogbon.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tlogbon.blogspot.com/feeds/2649193248980157825/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3724943210192394558&amp;postID=2649193248980157825' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/2649193248980157825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/2649193248980157825'/><link rel='alternate' type='text/html' href='http://tlogbon.blogspot.com/2008/10/red-alert-microsoft-office-documents.html' title='Red Alert: Microsoft Office Documents could be dangerous!'/><author><name>tlogbon</name><uri>http://www.blogger.com/profile/13741132541773900116</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://bp2.blogger.com/_l9ll1t96LYA/SH23cO03osI/AAAAAAAAAAM/8mvIKJ-V6eQ/S220/Moi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3724943210192394558.post-6500239767999844965</id><published>2008-10-08T09:54:00.000-07:00</published><updated>2008-10-22T06:55:09.827-07:00</updated><title type='text'>Reduce the Risk of Attacks by 90% - Part 1</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Having used Microsoft windows for quite some time, I can tell that the greatest source of infections is usually from external storage devices.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;From the era of diskette viruses, to the era of flash drive viruses, one cannot overlook the fact that most infections are from external devices.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Initially, Viruses do not run themselves from external devices but with the use of autorun.inf files, viruses found way of running themselves from external devices.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;As time went on, people discovered way of disabling ‘AUTORUNing’ viruses from external storage devices. But this was not enough as most people still had to double click on flash drives and double clicking on a flash drive reduces the risk of infection.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;As time went on, writers of malwares discovered that by replacing the shell (right click) options of external drives with their virus options, they could still infect systems easily and this they did.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;At a point, all you needed to do was just to right click on a flash drive and you will see options like ‘auto’, ‘autorun’ or some other options, by seeing any of these, you could easily tell that a virus was present on an external storage device.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;With time, writers of malwares saw that people were easily detecting the presence of viruses. I can remember well that the first worm I saw that used a normal window shell, i.e. &lt;i style="mso-bidi-font-style:normal"&gt;Open, Search &amp;amp; Explore &lt;/i&gt;was avpo.exe, and this was a very surprising event for me as a person.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;So I discovered that the best way to avoid run a virus by clicking on a flash drive is either by using Run (i.e. Start Menu&gt;Run), then typing in the name of the drive. Alternatively, you can use windows explorer, press f4 and the address bar drops down the list of available drives. Choose the drive you want to open and that’s it. As shown below&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_l9ll1t96LYA/SP8wTCzmLCI/AAAAAAAAAA8/M4973WfH7xk/s1600-h/winexplorer.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_l9ll1t96LYA/SP8wTCzmLCI/AAAAAAAAAA8/M4973WfH7xk/s320/winexplorer.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5259975993520958498" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;What about malwares that disguise as normal applications or folders or even documents.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Funny UST Scandal &amp;amp; Ahsan’ss Virus both disguise as Video Files&lt;/p&gt;  &lt;p class="MsoNormal"&gt;SVSCHOSTS disguises as an Offices Document.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;BRONTOK and DETNAT both disguise using folder ICONS and there are any more disguises and one can only know this by revealing the extension of known files from folder options.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Be sure that the extensions of files are revealed, that will help you a lot.&lt;/p&gt;&lt;p class="MsoNormal"&gt;My next article will be on using PATH RULES to prevent infections from all executables (.exe, .bat, .reg, .cmd, .vbs, .com)&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3724943210192394558-6500239767999844965?l=tlogbon.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tlogbon.blogspot.com/feeds/6500239767999844965/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3724943210192394558&amp;postID=6500239767999844965' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/6500239767999844965'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/6500239767999844965'/><link rel='alternate' type='text/html' href='http://tlogbon.blogspot.com/2008/10/reduce-risk-of-attacks-by-90-part-1.html' title='Reduce the Risk of Attacks by 90% - Part 1'/><author><name>tlogbon</name><uri>http://www.blogger.com/profile/13741132541773900116</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://bp2.blogger.com/_l9ll1t96LYA/SH23cO03osI/AAAAAAAAAAM/8mvIKJ-V6eQ/S220/Moi.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_l9ll1t96LYA/SP8wTCzmLCI/AAAAAAAAAA8/M4973WfH7xk/s72-c/winexplorer.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3724943210192394558.post-2324935394244873221</id><published>2008-10-07T08:42:00.000-07:00</published><updated>2008-10-08T09:26:01.841-07:00</updated><title type='text'>Ahsan's Virus</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Solution to Ahsan's Virus:&lt;/span&gt;&lt;br /&gt;One big solution to Ahsan's virus is to use the new CPE Anti-Autorun Killer,&lt;br /&gt;This little application works like magic to stop the Ahsan's virus.&lt;br /&gt;Double click on the application, then it appears in your taskbar&lt;br /&gt;Right click on the task bar icon and then choose kill in computer,&lt;br /&gt;this will stop the virus for the time being.&lt;br /&gt;Download this application from www.cpe17.com&lt;br /&gt;If you don't have access to this application, then try to install tune up utilities, the process manager that comes with it can help you out!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-style: italic;"&gt; About Ahsan's Virus&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;This virus is one of the most interstin viruses I have ever seen. it changes My Computer to Ahsan's computer&lt;br /&gt;My Documents to Ahsan's Document, My Network places to Ahsan's places and finally, it changes Recycle Bin to G.W.Bush, i guess Ahsan hates America so much.&lt;br /&gt;That's not all, all .com, .cmd, .bat are changed to regfile, all .reg &amp;amp; .vbs are changed to exefile.&lt;br /&gt;All these is so as to prevent you from running some internal commands.&lt;br /&gt;The command prompt is disabled, access to task manager and regedit is prevented.&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(255, 102, 102);"&gt;This Ahsan guy must be very good.&lt;/span&gt;&lt;br /&gt;The title of your internet explorer has something to do with Ahsan and so on.&lt;br /&gt;This virus runs with a process name: csrss.exe which is one of windows' critical processes.&lt;br /&gt;but this is located in %systemroot% instead of &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;%systemroot% \system32 which the original file is located, Ahsan's virus also comes as system.exe and 'home video.exe' all in &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;%systemroot%.&lt;br /&gt;The major component that starts up the virus is located in&lt;br /&gt;\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe&lt;br /&gt;you can do well to delete this file.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-style: italic;"&gt;Enough about Ahsan.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;Once you have succeeded in killing the process, just do well to do the folllowing:&lt;br /&gt;Run Regedit then go to:&lt;br /&gt;HKCU\Software\Policies\Microsoft\System\&lt;br /&gt;Delete DisableCMD command, then continue.&lt;br /&gt;Now you can run CMD.&lt;br /&gt;From running CMD, run the follwing command&lt;br /&gt;:&lt;br /&gt;del &lt;span&gt;&lt;span&gt;\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe /f/q/ah&lt;br /&gt;del %systemroot%\system.exe &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;%systemroot%\csrss.exe "&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;%systemroot%\Home Video.exe"&lt;br /&gt;From here, Go to start menu, rename&lt;br /&gt;Ahsan's Computer to My Computer, apply the same for documents and network places.&lt;br /&gt;For Recycle Bin, go to registry, and browse to the following location&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}&lt;br /&gt;delete the default value which should be on G.W.Bush&lt;br /&gt;The last thing to consider&lt;br /&gt;Goto HKCR (Root), look for .com, .cmd, .bat from regfile to comfile, cmdfile, and batfile respectively.&lt;br /&gt;Go to .reg, change from exefile to regfile&lt;br /&gt;Go to .vbs, change from exe to vbs&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3724943210192394558-2324935394244873221?l=tlogbon.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tlogbon.blogspot.com/feeds/2324935394244873221/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3724943210192394558&amp;postID=2324935394244873221' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/2324935394244873221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/2324935394244873221'/><link rel='alternate' type='text/html' href='http://tlogbon.blogspot.com/2008/10/ahsans-virus.html' title='Ahsan&apos;s Virus'/><author><name>tlogbon</name><uri>http://www.blogger.com/profile/13741132541773900116</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://bp2.blogger.com/_l9ll1t96LYA/SH23cO03osI/AAAAAAAAAAM/8mvIKJ-V6eQ/S220/Moi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3724943210192394558.post-5975638540993427923</id><published>2008-07-16T02:10:00.000-07:00</published><updated>2008-07-16T02:14:51.155-07:00</updated><title type='text'>Who's heard anything about Ahsan's Virus!!!</title><content type='html'>I saw a new virus of recent, the Virus chaged everything on the desktop.&lt;br /&gt;Tho' i was able to overcome the problem, but it took quite a lot of time trying to restore the system's state!&lt;br /&gt;u need tuneUp process manager to easily remove this virus!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3724943210192394558-5975638540993427923?l=tlogbon.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tlogbon.blogspot.com/feeds/5975638540993427923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3724943210192394558&amp;postID=5975638540993427923' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/5975638540993427923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/5975638540993427923'/><link rel='alternate' type='text/html' href='http://tlogbon.blogspot.com/2008/07/whos-heard-anything-about-ahsans-virus.html' title='Who&apos;s heard anything about Ahsan&apos;s Virus!!!'/><author><name>tlogbon</name><uri>http://www.blogger.com/profile/13741132541773900116</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://bp2.blogger.com/_l9ll1t96LYA/SH23cO03osI/AAAAAAAAAAM/8mvIKJ-V6eQ/S220/Moi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3724943210192394558.post-3455050149946283580</id><published>2008-03-30T07:28:00.000-07:00</published><updated>2008-03-30T07:32:23.976-07:00</updated><title type='text'>Virus Geek</title><content type='html'>I'm working on my first post CatchYai&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3724943210192394558-3455050149946283580?l=tlogbon.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tlogbon.blogspot.com/feeds/3455050149946283580/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3724943210192394558&amp;postID=3455050149946283580' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/3455050149946283580'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3724943210192394558/posts/default/3455050149946283580'/><link rel='alternate' type='text/html' href='http://tlogbon.blogspot.com/2008/03/virus-geek.html' title='Virus Geek'/><author><name>tlogbon</name><uri>http://www.blogger.com/profile/13741132541773900116</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://bp2.blogger.com/_l9ll1t96LYA/SH23cO03osI/AAAAAAAAAAM/8mvIKJ-V6eQ/S220/Moi.jpg'/></author><thr:total>0</thr:total></entry></feed>
