Remove Blurax. Description and removal instructions

 
Title: Blurax

Type: Backdoors
Severity scale:Blurax severity is 65  (65 / 100)
 
Blurax is a backdoor that provides the attacker with unauthorized remote access to the compromised computer. It allows the intruder to download arbitrary files, create and delete folders, search for specific files and execute system commands. Furthermore, the intruder can record user keystrokes and retrieve all information gathered. Blurax uses an integrated rootkit to hide its active services. The backdoor secretly runs as a service on every Windows startup. It also starts in Safe Mode.


Related files: blueo.exe, svvhost.exe, svvhosti.exe, bluedrv.sys

Blurax properties:
• Allows remote user connection
• Logs keystrokes
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Blurax removal:

remover for Blurax

Blurax manual removal:

Kill processes:
blueo.exe, svvhost.exe, svvhosti.exe, bluedrv.sys
Delete registry values:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\blueo
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BLUEO
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\blueodrv
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BLUEODRV
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svvhost
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SVVHOST
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\blueo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BLUEO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\blueodrv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BLUEODRV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\svvhost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SVVHOST
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\blueo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_BLUEO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\blueodrv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_BLUEODRV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\svvhost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SVVHOST
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\blueo
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\blueo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{78265AA7-CE86-A82E-2852-F9CAE8A97158}
Delete files:
blueo.exe, svvhost.exe, svvhosti.exe, bluedrv.sys
Misc:
Blurax files can be found in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.

Other programs to remove Blurax:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 03/10/06
Information updated: 03/10/06

Additional resources related to Blurax:

Attention: If you know or you have a website or page about Blurax removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Blurax parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: