Remove Blaxe. Description and removal instructions

 
Title: Blaxe

Type: Worms
Severity scale:Blaxe severity is 62  (62 / 100)
 
Blaxe is an Internet worm that spreads through file sharing networks using popular peer-to-peer applications. Once executed, the parasite registers itself in the system, creates a hidden folder and drops infected files with meaningful names in it. Then it shares this folder with other Internet users through Kazaa, iMesh or Grokster programs. Blaxe also silently downloads from a predetermined FTP server arbitrary potentially harmful files and runs them. One of them is the installation file of another dangerous worm called Spybot. Blaxe has the ability to infect executables located on a floppy disk. The worm runs on every Windows startup.


Blaxe properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Blaxe removal:

remover for Blaxe

Blaxe manual removal:

Kill processes:
directx.exe, messenger plus! - setup.exe, update.exe, winbat.exe, wzextract.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\DirectX=%Windir%\directx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\DirectX=%Windir%\directx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip\Shell\Open\Command\(Default)=[path to wzextract.exe]
HKEY_CURRENT_USER\Software\Grokster\LocalContent\dir0=012345:%Windir%\kernell
HKEY_CURRENT_USER\Software\Grokster\LocalContent\dir1=012345:%Windir%\kernell
HKEY_CURRENT_USER\Software\Grokster\LocalContent\dir2=012345:%Windir%\kernell
HKEY_CURRENT_USER\Software\iMesh\Client\LocalContent\dir0=012345:%Windir%\kernell
HKEY_CURRENT_USER\Software\iMesh\Client\LocalContent\dir1=012345:%Windir%\kernell
HKEY_CURRENT_USER\Software\iMesh\Client\LocalContent\dir2=012345:%Windir%\kernell
HKEY_CURRENT_USER\Software\KaZaA\LocalContent\dir0=012345:%Windir%\kernell
HKEY_CURRENT_USER\Software\KaZaA\LocalContent\dir1=012345:%Windir%\kernell
HKEY_CURRENT_USER\Software\KaZaA\LocalContent\dir2=012345:%Windir%\kernell
Delete files:
directx.exe, messenger plus! - setup.exe, update.exe, winbat.exe, wzextract.exe, ftp.bat, windll32.dll
Delete directories:
C:\Windows\kernell
C:\Winnt\kernell
Misc:
The update.exe executable usually installs the Spybot worm.

Exact file location:
directx.exe, winbat.exe - C:\Windows or C:\Winnt
messenger plus! - setup.exe - C:\Windows\Temp or C:\Winnt\Temp
wzextract.exe - WinZip installation directory
ftp.bat, windll32.dll - C:

Other programs to remove Blaxe:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 19/03/04
Information updated: 30/09/05

Additional resources related to Blaxe:

Attention: If you know or you have a website or page about Blaxe removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Blaxe parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: