<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Security and Tech Blogs</title>
	<atom:link href="http://www.precisesecurity.com/blogs/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://www.precisesecurity.com/blogs</link>
	<description></description>
	<lastBuildDate>Mon, 23 Jan 2012 08:19:19 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>Comment on defender-review.com by Perfect Defender 2009 - Threat Center</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/16/defender-reviewcom#comment-66498</link>
		<dc:creator>Perfect Defender 2009 - Threat Center</dc:creator>
		<pubDate>Mon, 23 Jan 2012 08:13:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/16/defender-reviewcom/#comment-66498</guid>
		<description>[...] defender-review.com [...]</description>
		<content:encoded><![CDATA[<p>[...] defender-review.com [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by mo</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65959</link>
		<dc:creator>mo</dc:creator>
		<pubDate>Wed, 28 Dec 2011 13:53:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65959</guid>
		<description>I am sorry but this virus replaces the original file even the dulla programmer can not recover the data but removing the virus is pz of cake</description>
		<content:encoded><![CDATA[<p>I am sorry but this virus replaces the original file even the dulla programmer can not recover the data but removing the virus is pz of cake</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by pakcik</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65898</link>
		<dc:creator>pakcik</dc:creator>
		<pubDate>Wed, 11 May 2011 14:19:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65898</guid>
		<description>Only one thing I have in my mind right now.....kill those son of a @&amp;%**.......
I have 3 hd in my pc.....one of them is my system....others...all my works....and im already too late...everything must be reformat again.....include my works...cos, everything already infected..... in really crazy mad grrrrrr.......</description>
		<content:encoded><![CDATA[<p>Only one thing I have in my mind right now&#8230;..kill those son of a @&amp;%**&#8230;&#8230;.<br />
I have 3 hd in my pc&#8230;..one of them is my system&#8230;.others&#8230;all my works&#8230;.and im already too late&#8230;everything must be reformat again&#8230;..include my works&#8230;cos, everything already infected&#8230;.. in really crazy mad grrrrrr&#8230;&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by chank</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65894</link>
		<dc:creator>chank</dc:creator>
		<pubDate>Sun, 08 May 2011 09:13:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65894</guid>
		<description>well i think it is good tutorial thanks aman</description>
		<content:encoded><![CDATA[<p>well i think it is good tutorial thanks aman</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Bipul</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65874</link>
		<dc:creator>Bipul</dc:creator>
		<pubDate>Tue, 26 Apr 2011 14:29:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65874</guid>
		<description>Hello my pc infected with win32 virut.ce i have kaspersky antivirus. its detected the virus but results shows that postponed. please guide me how to clean the virus.</description>
		<content:encoded><![CDATA[<p>Hello my pc infected with win32 virut.ce i have kaspersky antivirus. its detected the virus but results shows that postponed. please guide me how to clean the virus.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Dula's nemesis</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65863</link>
		<dc:creator>Dula's nemesis</dc:creator>
		<pubDate>Thu, 21 Apr 2011 20:00:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65863</guid>
		<description>Zis dula aint nothin comared  with the new upcoming virus called &#039;abadula&#039; No antivirus could stop it. Dula wont be a virus after this. u will miss ur desktop interface after u r infected and z best thing is u cant even format ur PC!!! (It wont work on win98 and mac) but  unfortunetly about 91% of z ethiopian ppl use xp and newer versons of windows. Then ur pc would a piece of junk that wo uld throwen to z garbage.</description>
		<content:encoded><![CDATA[<p>Zis dula aint nothin comared  with the new upcoming virus called &#8216;abadula&#8217; No antivirus could stop it. Dula wont be a virus after this. u will miss ur desktop interface after u r infected and z best thing is u cant even format ur PC!!! (It wont work on win98 and mac) but  unfortunetly about 91% of z ethiopian ppl use xp and newer versons of windows. Then ur pc would a piece of junk that wo uld throwen to z garbage.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by stephen</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65853</link>
		<dc:creator>stephen</dc:creator>
		<pubDate>Mon, 11 Apr 2011 18:59:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65853</guid>
		<description>read number 6,...it really does work,but put your pc in safe mode first....and im runnin windows xp....</description>
		<content:encoded><![CDATA[<p>read number 6,&#8230;it really does work,but put your pc in safe mode first&#8230;.and im runnin windows xp&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Binyam Letarge</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65819</link>
		<dc:creator>Binyam Letarge</dc:creator>
		<pubDate>Sun, 30 Jan 2011 12:07:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65819</guid>
		<description>Tell me, how can i get z antivirus for dulla?</description>
		<content:encoded><![CDATA[<p>Tell me, how can i get z antivirus for dulla?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by theodros</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65815</link>
		<dc:creator>theodros</dc:creator>
		<pubDate>Mon, 17 Jan 2011 07:30:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65815</guid>
		<description>Please, tell me how I can load this anti virus. My computer was affected by virus and not properly operated.</description>
		<content:encoded><![CDATA[<p>Please, tell me how I can load this anti virus. My computer was affected by virus and not properly operated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Bob</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65800</link>
		<dc:creator>Bob</dc:creator>
		<pubDate>Thu, 16 Dec 2010 12:02:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65800</guid>
		<description>12/15/10 -  I too was infected.  Thanks for all of your comments,but especially to Kenny (#29 &amp; 30).  Starting in Safe Mode in Windows 7 worked for me.  I did not get the option to be &#039;Administrator&#039;, but I was able to access System Restore.  I picked a point a couple of days prior to the incident and that solved the problem.</description>
		<content:encoded><![CDATA[<p>12/15/10 &#8211;  I too was infected.  Thanks for all of your comments,but especially to Kenny (#29 &amp; 30).  Starting in Safe Mode in Windows 7 worked for me.  I did not get the option to be &#8216;Administrator&#8217;, but I was able to access System Restore.  I picked a point a couple of days prior to the incident and that solved the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by afe</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65789</link>
		<dc:creator>afe</dc:creator>
		<pubDate>Thu, 11 Nov 2010 11:39:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65789</guid>
		<description>10Q it creats business to me b/c i have got the solution for the courapted file,so any one can send mail to have got the solution.</description>
		<content:encoded><![CDATA[<p>10Q it creats business to me b/c i have got the solution for the courapted file,so any one can send mail to have got the solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by thon</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65781</link>
		<dc:creator>thon</dc:creator>
		<pubDate>Tue, 26 Oct 2010 20:50:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65781</guid>
		<description>the best solution is to format and re install os,and try avira free anti virus,the virus will gone in 2 hours,</description>
		<content:encoded><![CDATA[<p>the best solution is to format and re install os,and try avira free anti virus,the virus will gone in 2 hours,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on go.google &#8211; go.yahoo by Michael</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects#comment-65700</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Sat, 04 Sep 2010 04:29:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects/#comment-65700</guid>
		<description>If you can&#039;t find TDSSserv.sys in DEVICE MANAGER (as Mike described above);  then click START &gt; RUN &gt; Open: regedit &gt; EDIT &gt; FIND &gt; TDSSserv  --- delete (if you also see go.yahoo delete that too) --- then click FIND NEXT --- delete any others found then FIND for go.yahoo --- delete any found.  Exit Registry Editor.</description>
		<content:encoded><![CDATA[<p>If you can&#8217;t find TDSSserv.sys in DEVICE MANAGER (as Mike described above);  then click START &gt; RUN &gt; Open: regedit &gt; EDIT &gt; FIND &gt; TDSSserv  &#8212; delete (if you also see go.yahoo delete that too) &#8212; then click FIND NEXT &#8212; delete any others found then FIND for go.yahoo &#8212; delete any found.  Exit Registry Editor.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Spyware Protect 2009 by Joe UPS</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/30/spyware-protect-2009#comment-65657</link>
		<dc:creator>Joe UPS</dc:creator>
		<pubDate>Sat, 10 Jul 2010 16:13:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/30/spyware-protect-2009/#comment-65657</guid>
		<description>After uninstalling the virus i lost HTTP internet browsing capabilities. Service was restored by unchecking &quot;use proxy&quot; under LAN settings in IE8 &gt; tools &gt; internet options &gt; connections &gt; LAN setiings</description>
		<content:encoded><![CDATA[<p>After uninstalling the virus i lost HTTP internet browsing capabilities. Service was restored by unchecking &#8220;use proxy&#8221; under LAN settings in IE8 &gt; tools &gt; internet options &gt; connections &gt; LAN setiings</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by mesfin Adugna</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65656</link>
		<dc:creator>mesfin Adugna</dc:creator>
		<pubDate>Wed, 07 Jul 2010 12:22:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65656</guid>
		<description>how i am gone to fix the virus dulla</description>
		<content:encoded><![CDATA[<p>how i am gone to fix the virus dulla</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by mesfin</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65647</link>
		<dc:creator>mesfin</dc:creator>
		<pubDate>Sun, 27 Jun 2010 06:28:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65647</guid>
		<description>Please send Tsere dulla Antivrus. My documents are at riskThe file already corrupted, so how can i recover the excel files?</description>
		<content:encoded><![CDATA[<p>Please send Tsere dulla Antivrus. My documents are at riskThe file already corrupted, so how can i recover the excel files?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by mesfin</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65646</link>
		<dc:creator>mesfin</dc:creator>
		<pubDate>Sun, 27 Jun 2010 06:27:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65646</guid>
		<description>Please send Tsere dulla Antivrus. My documents are at riskThe file already corrupted, so how can i recover the excel files? help me now!!</description>
		<content:encoded><![CDATA[<p>Please send Tsere dulla Antivrus. My documents are at riskThe file already corrupted, so how can i recover the excel files? help me now!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by kabiand</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65638</link>
		<dc:creator>kabiand</dc:creator>
		<pubDate>Wed, 16 Jun 2010 17:50:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65638</guid>
		<description>i really appriciate your innvention but could you give me your offer please to get out of this mess. thank y0u</description>
		<content:encoded><![CDATA[<p>i really appriciate your innvention but could you give me your offer please to get out of this mess. thank y0u</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by kabiand</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65637</link>
		<dc:creator>kabiand</dc:creator>
		<pubDate>Wed, 16 Jun 2010 14:39:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65637</guid>
		<description>i am really angry that my laptop is highley affected please a little solution</description>
		<content:encoded><![CDATA[<p>i am really angry that my laptop is highley affected please a little solution</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by oh noes</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65630</link>
		<dc:creator>oh noes</dc:creator>
		<pubDate>Wed, 09 Jun 2010 06:08:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65630</guid>
		<description>Captured new virut.ce variant; infected userinit.exe , control.exe and cmd.exe from /system32.. confirmed infected by jotti- AVG&#039;s Win32/Virut tool does not detect these infected files. Malwarebytes doesn&#039;t see them either. ~.~</description>
		<content:encoded><![CDATA[<p>Captured new virut.ce variant; infected userinit.exe , control.exe and cmd.exe from /system32.. confirmed infected by jotti- AVG&#8217;s Win32/Virut tool does not detect these infected files. Malwarebytes doesn&#8217;t see them either. ~.~</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by seena seena</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65620</link>
		<dc:creator>seena seena</dc:creator>
		<pubDate>Tue, 18 May 2010 04:23:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65620</guid>
		<description>Blogs are always a main source of getting accurate information and provide you the handy results; you can get instant and reliable information which surely helps you in any field of your concern. I am post graduate in IT and HR. These days I am doing preparation of different online certifications and I found &lt;a href=&quot;http://www.mcdbatoday.com&quot; rel=&quot;nofollow&quot;&gt;mcdba&lt;/a&gt; is the best helping source which is providing 100% authentic material. I also spend my extra time in surfing internet, listening music and playing games. After my exams I would like to join your group.</description>
		<content:encoded><![CDATA[<p>Blogs are always a main source of getting accurate information and provide you the handy results; you can get instant and reliable information which surely helps you in any field of your concern. I am post graduate in IT and HR. These days I am doing preparation of different online certifications and I found <a href="http://www.mcdbatoday.com" rel="nofollow">mcdba</a> is the best helping source which is providing 100% authentic material. I also spend my extra time in surfing internet, listening music and playing games. After my exams I would like to join your group.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by debb</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65590</link>
		<dc:creator>debb</dc:creator>
		<pubDate>Mon, 12 Apr 2010 13:49:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65590</guid>
		<description>I can not do step 6. I&#039;ve tried numerous times and nothing happens. I&#039;ve tried downloading different virus removers, (spybot, Malware etc) it says it&#039;s downloaded buy it&#039;s not showing up on my computer. I&#039;ve ran a search and nothing is there. I restarted in Safe Mode and ran a Rogers virus scan and it&#039;s still not going away... I&#039;m so frustrated. Please help!</description>
		<content:encoded><![CDATA[<p>I can not do step 6. I&#8217;ve tried numerous times and nothing happens. I&#8217;ve tried downloading different virus removers, (spybot, Malware etc) it says it&#8217;s downloaded buy it&#8217;s not showing up on my computer. I&#8217;ve ran a search and nothing is there. I restarted in Safe Mode and ran a Rogers virus scan and it&#8217;s still not going away&#8230; I&#8217;m so frustrated. Please help!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Jennifer</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65586</link>
		<dc:creator>Jennifer</dc:creator>
		<pubDate>Sat, 10 Apr 2010 22:46:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65586</guid>
		<description>I have had all the same problems that everyone has spoken about here! I am currently in safe mode and waiting for the malware to finish as I chose to do all users rather than just mine. I unfortunately am waiting a bit longer than 5 min but that&#039;s okay if it gets rid of the stupid virus! :( In addition I got the worm while being on facebook!!!</description>
		<content:encoded><![CDATA[<p>I have had all the same problems that everyone has spoken about here! I am currently in safe mode and waiting for the malware to finish as I chose to do all users rather than just mine. I unfortunately am waiting a bit longer than 5 min but that&#8217;s okay if it gets rid of the stupid virus! :( In addition I got the worm while being on facebook!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by bradley</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65581</link>
		<dc:creator>bradley</dc:creator>
		<pubDate>Tue, 06 Apr 2010 18:31:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65581</guid>
		<description>m8 just rang me he had this was driving him mad just told him to do system restore took it back to march 8th worked a treat thanks for the info</description>
		<content:encoded><![CDATA[<p>m8 just rang me he had this was driving him mad just told him to do system restore took it back to march 8th worked a treat thanks for the info</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Musik Anima</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65576</link>
		<dc:creator>Musik Anima</dc:creator>
		<pubDate>Sat, 03 Apr 2010 08:11:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65576</guid>
		<description>this shity i got it from a crack ...

yesterday i ran Kaspersky full scan and i got 12 infection of this virus.

And I think all is good now..

Kaspersky maybe has erased all the infections..


I have put the scan to &quot;high&quot;, and it took 12hrs to scan all..

i have no problem actually..but dunno if in future i will get problems..

I will do another scan, to stay assured that there is none of these infections...

this virus is owesome.. :) pc slows a lot during scan also..

pc started to lag...

1st thing to do: update Kaspersky
2nd: disconect from net
3rd: deep very deep scan
4th: restart pc
5th: again a deep deep scan..

then good.. I think problem solved..</description>
		<content:encoded><![CDATA[<p>this shity i got it from a crack &#8230;</p>
<p>yesterday i ran Kaspersky full scan and i got 12 infection of this virus.</p>
<p>And I think all is good now..</p>
<p>Kaspersky maybe has erased all the infections..</p>
<p>I have put the scan to &#8220;high&#8221;, and it took 12hrs to scan all..</p>
<p>i have no problem actually..but dunno if in future i will get problems..</p>
<p>I will do another scan, to stay assured that there is none of these infections&#8230;</p>
<p>this virus is owesome.. :) pc slows a lot during scan also..</p>
<p>pc started to lag&#8230;</p>
<p>1st thing to do: update Kaspersky<br />
2nd: disconect from net<br />
3rd: deep very deep scan<br />
4th: restart pc<br />
5th: again a deep deep scan..</p>
<p>then good.. I think problem solved..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by million tsegaye</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65575</link>
		<dc:creator>million tsegaye</dc:creator>
		<pubDate>Fri, 02 Apr 2010 11:34:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65575</guid>
		<description>ohhhhh the best solution .i have lost a lots of data so this one might be solution.anyways thnx
guys</description>
		<content:encoded><![CDATA[<p>ohhhhh the best solution .i have lost a lots of data so this one might be solution.anyways thnx<br />
guys</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by martyn</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65572</link>
		<dc:creator>martyn</dc:creator>
		<pubDate>Thu, 01 Apr 2010 13:33:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65572</guid>
		<description>i should also have said i got no option to run in safe mode either</description>
		<content:encoded><![CDATA[<p>i should also have said i got no option to run in safe mode either</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by martyn</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65571</link>
		<dc:creator>martyn</dc:creator>
		<pubDate>Thu, 01 Apr 2010 13:32:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65571</guid>
		<description>i&#039;ve got this on my laptop it sneaked in through facebook. i have tried everything suggested here and on other sites to no avail. i can&#039;t restore as it&#039;s removed that option. i can&#039;t run any new files as it&#039;s says it got a virus and refuses to play. can anyone help?  and reading thought others coments if we find the one responsible i&#039;ll cut his balls off</description>
		<content:encoded><![CDATA[<p>i&#8217;ve got this on my laptop it sneaked in through facebook. i have tried everything suggested here and on other sites to no avail. i can&#8217;t restore as it&#8217;s removed that option. i can&#8217;t run any new files as it&#8217;s says it got a virus and refuses to play. can anyone help?  and reading thought others coments if we find the one responsible i&#8217;ll cut his balls off</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Drewski</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65569</link>
		<dc:creator>Drewski</dc:creator>
		<pubDate>Wed, 31 Mar 2010 17:59:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65569</guid>
		<description>Well, I did instructions on step 6 and it worked for me. I spent 3 hours trying to find online instructions and after doing step 6 it was back to nornal in 5 mins. Computer place wanted to charge me $130.00 to fix. Thank you.</description>
		<content:encoded><![CDATA[<p>Well, I did instructions on step 6 and it worked for me. I spent 3 hours trying to find online instructions and after doing step 6 it was back to nornal in 5 mins. Computer place wanted to charge me $130.00 to fix. Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Get</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65551</link>
		<dc:creator>Get</dc:creator>
		<pubDate>Tue, 23 Mar 2010 06:35:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65551</guid>
		<description>I have seen that your virus software, but what differs you from the civilized one your anti-virus never recover every corrupted data/file please learn more do once.</description>
		<content:encoded><![CDATA[<p>I have seen that your virus software, but what differs you from the civilized one your anti-virus never recover every corrupted data/file please learn more do once.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Tammy</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65548</link>
		<dc:creator>Tammy</dc:creator>
		<pubDate>Mon, 22 Mar 2010 00:08:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65548</guid>
		<description>im having the same problem as everyoe else. except i cant go on safe mode. when i hit enter to enter safe mode a whole bunch of writing like file names comes up &amp; its there forever unless i turn it off. i need help so bad!! ive tried everything!!!!! what should i do?</description>
		<content:encoded><![CDATA[<p>im having the same problem as everyoe else. except i cant go on safe mode. when i hit enter to enter safe mode a whole bunch of writing like file names comes up &amp; its there forever unless i turn it off. i need help so bad!! ive tried everything!!!!! what should i do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Sandra</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65546</link>
		<dc:creator>Sandra</dc:creator>
		<pubDate>Sun, 21 Mar 2010 02:52:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65546</guid>
		<description>I have Windows 7 and don&#039;t know how to start it in Safe Mode.  It is infested with this virus and I have had no success in downloading malaware either from the internet or from a CD. I would like to try to restore to an earlier date, but it won&#039;t let me change the date either.  Help please!</description>
		<content:encoded><![CDATA[<p>I have Windows 7 and don&#8217;t know how to start it in Safe Mode.  It is infested with this virus and I have had no success in downloading malaware either from the internet or from a CD. I would like to try to restore to an earlier date, but it won&#8217;t let me change the date either.  Help please!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by gump</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65534</link>
		<dc:creator>gump</dc:creator>
		<pubDate>Sat, 13 Mar 2010 16:31:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65534</guid>
		<description>thanks alot peaple you helped me out a shitload...
i could do shit even lost my background tryed to use avg but it wouldn&#039;t let me. after comeing here i realized i had to start in safe mode do a sys. restore from there then use my avg but it&#039;s done and up in running agen so thanks

hey dude you find him i&#039;ll hold him down while you kick him in the balls a few times as long as i in black both his eyes. and may break a finger or 2     lol</description>
		<content:encoded><![CDATA[<p>thanks alot peaple you helped me out a shitload&#8230;<br />
i could do shit even lost my background tryed to use avg but it wouldn&#8217;t let me. after comeing here i realized i had to start in safe mode do a sys. restore from there then use my avg but it&#8217;s done and up in running agen so thanks</p>
<p>hey dude you find him i&#8217;ll hold him down while you kick him in the balls a few times as long as i in black both his eyes. and may break a finger or 2     lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Steve</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65512</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Mon, 01 Mar 2010 00:31:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65512</guid>
		<description>I was browsing online and then was suddenly hit with the worm.... First time with a virus. on a new laptop to.  
I have no virus block at the moment Ill try to   Download Malwarebytes’ Anti-Malware.. (any suggestions) ... Thanks....
 It said it is eating it&#039;s way through my computer trying to send credit card info. lookin for passwords
pop ups kept on appearing with security tool.  tried to deleate security tool but  just came back so I turned  off the computer.  

would someone please find the person
that started this worm and kick him in the balls.  
greatly appreaciated.</description>
		<content:encoded><![CDATA[<p>I was browsing online and then was suddenly hit with the worm&#8230;. First time with a virus. on a new laptop to.<br />
I have no virus block at the moment Ill try to   Download Malwarebytes’ Anti-Malware.. (any suggestions) &#8230; Thanks&#8230;.<br />
 It said it is eating it&#8217;s way through my computer trying to send credit card info. lookin for passwords<br />
pop ups kept on appearing with security tool.  tried to deleate security tool but  just came back so I turned  off the computer.  </p>
<p>would someone please find the person<br />
that started this worm and kick him in the balls.<br />
greatly appreaciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by JoeAdmin</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65508</link>
		<dc:creator>JoeAdmin</dc:creator>
		<pubDate>Tue, 23 Feb 2010 15:25:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65508</guid>
		<description>A VERY important note is included at the end of this article:
1) Download mabm-setup.exe from a non-affected computer.  Save the file to the desktop.

2) Re-Name mbam-setup.exe to something else with the .exe extension (like JoeAdmin.exe)

3) Copy the re-named .exe file to a memory stick, or write it to a CD/DVD

4) Restore it to the desktop of your infected PC
and execute it (Scan entire disk).

5) If you have any problems doin this with your current login (which should be a administrator) try creating a new login with administrator privs, loging in as that new login and follow the same instructions.</description>
		<content:encoded><![CDATA[<p>A VERY important note is included at the end of this article:<br />
1) Download mabm-setup.exe from a non-affected computer.  Save the file to the desktop.</p>
<p>2) Re-Name mbam-setup.exe to something else with the .exe extension (like JoeAdmin.exe)</p>
<p>3) Copy the re-named .exe file to a memory stick, or write it to a CD/DVD</p>
<p>4) Restore it to the desktop of your infected PC<br />
and execute it (Scan entire disk).</p>
<p>5) If you have any problems doin this with your current login (which should be a administrator) try creating a new login with administrator privs, loging in as that new login and follow the same instructions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by simon</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65502</link>
		<dc:creator>simon</dc:creator>
		<pubDate>Mon, 22 Feb 2010 01:47:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65502</guid>
		<description>I very very sorry by the dulla virus plz give me the solution b/c I do any thing with the virus dulla help me how can i remove from my PC  . We can&#039;t do with messanger and an other documents please send me a solution</description>
		<content:encoded><![CDATA[<p>I very very sorry by the dulla virus plz give me the solution b/c I do any thing with the virus dulla help me how can i remove from my PC  . We can&#8217;t do with messanger and an other documents please send me a solution</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by gazza</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65500</link>
		<dc:creator>gazza</dc:creator>
		<pubDate>Sun, 21 Feb 2010 11:18:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65500</guid>
		<description>i have this virus....its terrible.  i first up did a system recovery....big mistake, i wiped everything thinkin it would rid me of this thing...it didnt!  Now i can&#039;t do a system restore point (which i should have done first up) because as far as the computers concerned, it had this virus from the start!  ahhhhhh  its drivin me nuts.</description>
		<content:encoded><![CDATA[<p>i have this virus&#8230;.its terrible.  i first up did a system recovery&#8230;.big mistake, i wiped everything thinkin it would rid me of this thing&#8230;it didnt!  Now i can&#8217;t do a system restore point (which i should have done first up) because as far as the computers concerned, it had this virus from the start!  ahhhhhh  its drivin me nuts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Bingo</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65491</link>
		<dc:creator>Bingo</dc:creator>
		<pubDate>Tue, 16 Feb 2010 12:04:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65491</guid>
		<description>Hello All.
I see this little bugger is still doing the rounds. Vicious little sod!
This is a repost of my messages from July 2009 detailing how I got rid of the problem. It is possible that new victims may not read that far back and I hope my experiences are helpful. Good luck! By the way, still free from this virus.



Bingo
July 22nd, 2009 at 1:28 pm 56 

Hello everybody. Only became aware of this thing about 5 days ago when the computer started shutting down and various programs became unworkable. Also, all files on my key drive disappeared and the drive had to be reformatted. Can’t swear that the virus did this but I cnn’t think of anything else to explain it. Windows Firewall (I’m running XP Pro) reported that I had a Virtob infection but AVG, Zone Alarm, and Ad-aware reported nothing. So after a bit of researching, I found the Kaspersky online scanner. This revealed that quite a lot of files were infected with win32.virut.ce but these could not be deleted by the online scanner. However, Kaspersky are doing a Full 30 day trial of Kaspersky Internet Security 2010 and I installed this. On checking drives C, D, and External Drive F, Kaspersky found and disinfected, or deleted, about 700 infected files. Reran the program and a few more files were found and treated. I am completed my third scan and the infection seems to have gone. Can’t say this will work for everyone but it seems to have worked for me. Worth a try and good luck to you. This is one awkward sob. I will report back if the infection recreates itself in the next few days, but so far it’s looking good



Bingo
July 22nd, 2009 at 10:48 pm 57 

Following on from earlier post, I found that a few vrt.tmp files were appearing in C:\Documents and Settings\LocalService\Local Settings\Temp but Kaspersky was preventing them loading or connecting to the net. I ran the scan next in Safe Mode and this disinfected the few files which could not be done in normal mode. As of this moment, this machine is now completely free, as far as I can see, of Virut and anything else. All programs and files seem to be working normally and the Kaspersky Network Monitor is showing that there are no suspect connections. Just for information, my operating system is XP Pro SP3. Kaspersky seems to have given me the complete solution to this pest. Well worth giving it a try. Free 30 day trial could rid you of this problem.



Bingo
July 31st, 2009 at 8:35 am 59 

Well, just to tie up the story on my experiences, I am now a week on from installing Kaspersky and ridding myself of Virut and it has not reappeared. That about says it all. Would highly recommend Kaspersky for ridding yourself of Virut</description>
		<content:encoded><![CDATA[<p>Hello All.<br />
I see this little bugger is still doing the rounds. Vicious little sod!<br />
This is a repost of my messages from July 2009 detailing how I got rid of the problem. It is possible that new victims may not read that far back and I hope my experiences are helpful. Good luck! By the way, still free from this virus.</p>
<p>Bingo<br />
July 22nd, 2009 at 1:28 pm 56 </p>
<p>Hello everybody. Only became aware of this thing about 5 days ago when the computer started shutting down and various programs became unworkable. Also, all files on my key drive disappeared and the drive had to be reformatted. Can’t swear that the virus did this but I cnn’t think of anything else to explain it. Windows Firewall (I’m running XP Pro) reported that I had a Virtob infection but AVG, Zone Alarm, and Ad-aware reported nothing. So after a bit of researching, I found the Kaspersky online scanner. This revealed that quite a lot of files were infected with win32.virut.ce but these could not be deleted by the online scanner. However, Kaspersky are doing a Full 30 day trial of Kaspersky Internet Security 2010 and I installed this. On checking drives C, D, and External Drive F, Kaspersky found and disinfected, or deleted, about 700 infected files. Reran the program and a few more files were found and treated. I am completed my third scan and the infection seems to have gone. Can’t say this will work for everyone but it seems to have worked for me. Worth a try and good luck to you. This is one awkward sob. I will report back if the infection recreates itself in the next few days, but so far it’s looking good</p>
<p>Bingo<br />
July 22nd, 2009 at 10:48 pm 57 </p>
<p>Following on from earlier post, I found that a few vrt.tmp files were appearing in C:\Documents and Settings\LocalService\Local Settings\Temp but Kaspersky was preventing them loading or connecting to the net. I ran the scan next in Safe Mode and this disinfected the few files which could not be done in normal mode. As of this moment, this machine is now completely free, as far as I can see, of Virut and anything else. All programs and files seem to be working normally and the Kaspersky Network Monitor is showing that there are no suspect connections. Just for information, my operating system is XP Pro SP3. Kaspersky seems to have given me the complete solution to this pest. Well worth giving it a try. Free 30 day trial could rid you of this problem.</p>
<p>Bingo<br />
July 31st, 2009 at 8:35 am 59 </p>
<p>Well, just to tie up the story on my experiences, I am now a week on from installing Kaspersky and ridding myself of Virut and it has not reappeared. That about says it all. Would highly recommend Kaspersky for ridding yourself of Virut</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Herbert</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65487</link>
		<dc:creator>Herbert</dc:creator>
		<pubDate>Tue, 16 Feb 2010 00:09:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65487</guid>
		<description>Thanks! The information on this blog helped me recover from the LSAS virus.....</description>
		<content:encoded><![CDATA[<p>Thanks! The information on this blog helped me recover from the LSAS virus&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by pat</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65485</link>
		<dc:creator>pat</dc:creator>
		<pubDate>Sun, 14 Feb 2010 13:45:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65485</guid>
		<description>do system restore it works even if restor says not completed</description>
		<content:encoded><![CDATA[<p>do system restore it works even if restor says not completed</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by ken.absolute</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65482</link>
		<dc:creator>ken.absolute</dc:creator>
		<pubDate>Fri, 12 Feb 2010 21:34:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65482</guid>
		<description>I slaved a SATA drive via USB adapter to copy some data off of it...This som&#039;bitch was on it and it jumped to the hosting PC!

It must get deep into all drives that it finds to make them autorun.  Anyway - Sunbelts Vipre anti-malware caught it on the hosting computer and kept it from spreading.  

The lesson anyway: be sure and hold down the shift key as you insert a USB drive (even if it&#039;s a adapter for IDE/serial/SCSI) to keep it from auto-running.

wow - this thing... it gets deep into sysvol and even maintenance partitions.  

I used Darik&#039;s Boot and Nuke (http://sourceforge.net/projects/dban/) for the guest drive (inc maint partition) after reading about the issues here and I&#039;ve not heard from it again.

My guess is people keep on getting reinfected by using their infected-auto-running USB drives or accessing infected .exe&#039;s that they backed up - unless their is some bios component it can load into that I&#039;ve been luckily enough not to have encountered.</description>
		<content:encoded><![CDATA[<p>I slaved a SATA drive via USB adapter to copy some data off of it&#8230;This som&#8217;bitch was on it and it jumped to the hosting PC!</p>
<p>It must get deep into all drives that it finds to make them autorun.  Anyway &#8211; Sunbelts Vipre anti-malware caught it on the hosting computer and kept it from spreading.  </p>
<p>The lesson anyway: be sure and hold down the shift key as you insert a USB drive (even if it&#8217;s a adapter for IDE/serial/SCSI) to keep it from auto-running.</p>
<p>wow &#8211; this thing&#8230; it gets deep into sysvol and even maintenance partitions.  </p>
<p>I used Darik&#8217;s Boot and Nuke (<a href="http://sourceforge.net/projects/dban/" rel="nofollow">http://sourceforge.net/projects/dban/</a>) for the guest drive (inc maint partition) after reading about the issues here and I&#8217;ve not heard from it again.</p>
<p>My guess is people keep on getting reinfected by using their infected-auto-running USB drives or accessing infected .exe&#8217;s that they backed up &#8211; unless their is some bios component it can load into that I&#8217;ve been luckily enough not to have encountered.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by D Mulyana</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65456</link>
		<dc:creator>D Mulyana</dc:creator>
		<pubDate>Thu, 28 Jan 2010 15:52:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65456</guid>
		<description>i have tried the save mode way n run the mbam-setup exe (i renamed it first). Yup the mwalbytes can fixed the lsas blaster. Thanx to you all, especially webmaster, now my laptop run normally again</description>
		<content:encoded><![CDATA[<p>i have tried the save mode way n run the mbam-setup exe (i renamed it first). Yup the mwalbytes can fixed the lsas blaster. Thanx to you all, especially webmaster, now my laptop run normally again</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by AZ</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65453</link>
		<dc:creator>AZ</dc:creator>
		<pubDate>Mon, 25 Jan 2010 08:19:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65453</guid>
		<description>THIS IS THE NASTIEST VIRUS HUMANS HAVE EVER FACED!!!!!!!!! 12 YEARS PC PROFICIENT HAS GIVEN UP AFTER REINSTALLING 64BIT VISTA, WIN 7 XP PRO 10 TIMES.....will completely format now. Installing new OS doesn&#039;t help either, it infects the new OS as well..ANY SUGGESTIONS??????????</description>
		<content:encoded><![CDATA[<p>THIS IS THE NASTIEST VIRUS HUMANS HAVE EVER FACED!!!!!!!!! 12 YEARS PC PROFICIENT HAS GIVEN UP AFTER REINSTALLING 64BIT VISTA, WIN 7 XP PRO 10 TIMES&#8230;..will completely format now. Installing new OS doesn&#8217;t help either, it infects the new OS as well..ANY SUGGESTIONS??????????</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Assi</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65451</link>
		<dc:creator>Assi</dc:creator>
		<pubDate>Fri, 22 Jan 2010 12:09:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65451</guid>
		<description>In one hand it is good to see ethiopians to create this things!!
Don&#039;t to be stupid to loss somebodies file? create antivirus for dulla ! to be prised by 8000000 peoples of ethiopia</description>
		<content:encoded><![CDATA[<p>In one hand it is good to see ethiopians to create this things!!<br />
Don&#8217;t to be stupid to loss somebodies file? create antivirus for dulla ! to be prised by 8000000 peoples of ethiopia</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Spy Guard 2008 by Stacy</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/28/spy-guard-2008#comment-65449</link>
		<dc:creator>Stacy</dc:creator>
		<pubDate>Wed, 20 Jan 2010 03:54:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/28/spy-guard-2008/#comment-65449</guid>
		<description>Great program...thank you from the bottom of my heart! It found over 91 infections on a computer that had been rendered useless and removed them. Can&#039;t boost enough...definite go!!!</description>
		<content:encoded><![CDATA[<p>Great program&#8230;thank you from the bottom of my heart! It found over 91 infections on a computer that had been rendered useless and removed them. Can&#8217;t boost enough&#8230;definite go!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Liane</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65447</link>
		<dc:creator>Liane</dc:creator>
		<pubDate>Mon, 18 Jan 2010 00:48:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65447</guid>
		<description>I found out I had this virus last night.
Kaspersky just detected backdoor.win32.papras.t
It&#039;s go time. *-*</description>
		<content:encoded><![CDATA[<p>I found out I had this virus last night.<br />
Kaspersky just detected backdoor.win32.papras.t<br />
It&#8217;s go time. *-*</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by chuck</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65446</link>
		<dc:creator>chuck</dc:creator>
		<pubDate>Sat, 16 Jan 2010 20:31:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65446</guid>
		<description>I had the same problem re lsas virus.  I shut the system down, reopened in &quot;safe&quot; mode, then did a &quot;systems restore&quot; dated 2 weeks ago.  This is in Windows XP. Took me about 2 minutes and so far it is working.</description>
		<content:encoded><![CDATA[<p>I had the same problem re lsas virus.  I shut the system down, reopened in &#8220;safe&#8221; mode, then did a &#8220;systems restore&#8221; dated 2 weeks ago.  This is in Windows XP. Took me about 2 minutes and so far it is working.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Cyber Dan</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65445</link>
		<dc:creator>Cyber Dan</dc:creator>
		<pubDate>Fri, 15 Jan 2010 09:52:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65445</guid>
		<description>Dear Persons

i want to express my deep concern on this virus from a technical point of view and becuse i have related profession ..but not virsus making lolz! i have made few virus but not like dulla and i have not released them becuse they are for educational purpose only. What i have understood from ~dulla204 is it insert the string ~dulla204 in each file that have extensions like .xlsx .vbp.asp.aspx. and so on...and it strats using a service application(as a windows helpfull application) but.it&#039;s not i have seen some of the prtion of code by opening it in a notpad i have come to undrrstood that it is written in delphi programing language....</description>
		<content:encoded><![CDATA[<p>Dear Persons</p>
<p>i want to express my deep concern on this virus from a technical point of view and becuse i have related profession ..but not virsus making lolz! i have made few virus but not like dulla and i have not released them becuse they are for educational purpose only. What i have understood from ~dulla204 is it insert the string ~dulla204 in each file that have extensions like .xlsx .vbp.asp.aspx. and so on&#8230;and it strats using a service application(as a windows helpfull application) but.it&#8217;s not i have seen some of the prtion of code by opening it in a notpad i have come to undrrstood that it is written in delphi programing language&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by psog_choudai</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65442</link>
		<dc:creator>psog_choudai</dc:creator>
		<pubDate>Tue, 12 Jan 2010 23:27:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65442</guid>
		<description>This stupid bugger&#039;s put me a week of hard work into this computer.

I can&#039;t say that I&#039;m 100% free of the stupidity this thing does, but... I might have easy tips for getting rid of the virus, and some pointers to note for people who might be having issues:

1. The virus indiscriminantly infects all .exe and .scr files (even inside .zip, .rar, .7z, or any other kind of archive.) It also infects mostly system .dll files.

2. It does NOT infect any other &quot;media&quot; file. These include .mp3, .ogg, .wav, .avi, .mpg extensions and the like.

3. It doesn&#039;t matter if you have more than one internal or external HDD or Flash drive (or any media that is rewritable), anything that meets the infection criteria WILL get infected.

4. Even if one file is already infected, the virus and any instances running WILL re-infect the same file in a different section of the coding.  Thus, multiple scans are necessary to make sure the file is ABSOLUTELY clean.

So... I have a LOT of music and videos that I&#039;m a little too attached to and that I don&#039;t want to lose. When I noticed that this stupid thing targets executables, I realized that I needed to reformat the HDD carrying the OS.  I did, and the virus came back.

I then noticed some strange occurrences.  Obviously, port 65520 was being accessed by winlogon.exe and explorer.exe. Even though this was a fresh install, I needed to reformat again already.

So, I took up the task of arming myself to clear out this virus from my system with the following tools:

1. Windows XP CD
2. Hiren&#039;s Boot CD v. 10.0
3. Ubuntu v. 8.04 Live CD

Here&#039;s how that worked.

1. I turned off my computer and unplugged the power cord and the Ethernet cable. Left off for 30 min, then plugged the power cord (not ethernet) back in, then booted to Hiren&#039;s Boot CD.
2. I used Hiren&#039;s Boot CD&#039;s partition tools to delete all partitions and destroy the data in the HDD carrying Windows XP.
3. I used the HDD Regenerator in the Hard Disk tools section to check for corrupted sectors. Usually this only applies to physical errors and not so much to data, but if a section has been damaged it&#039;s good to know.  Everything came back clean.
4. Went back to Partition Tools and formatted out an NTFS partition for Windows XP.

5. Rebooted and used the Ubuntu Live CD. Using this I was able to get the drivers for anything that I needed on the computer, and clean virus free copies of them because Linux doesn&#039;t have these kinds of virus issues. I also downloaded Virut Removal Tools and Comodo Internet Security and Dr. Web Cure It!. This is good for people that have lost their recovery CDs or their motherboard or display drivers. I placed all these into a clean USB Flash drive. When I copied everything in, I ejected and disconnected the drive.

6. I rebooted into the Windows XP CD. When asked for the desired partition, I performed yet another Format (not quick) on the blank NTFS partition. Proceeded with installing Windows.

7. When Windows loaded, I connected the USB Flash drive and placed its contents on the desktop. Proceeded with installing everything, starting with the basic motherboard drivers all the way to the AV tools and Security software. Ethernet cable is STILL disconnected.

8. Here I noticed none of the system files were behaving erratically. When Comodo Internet Security asked me to update the Virus DB, I then connected the Ethernet cable. Connections were safe, and port 65520 was not being accessed by any program. Definitions were updated, and port 65520 was eventually blocked.

9. Used Dr. Web Cure It! and performed a complete scan of the computer and all disks connected (USB Flash disconnected) overnight. Found a ridiculous amount of instances of Win32.Virut.56. Also found a few miscellaneous backdoors and other trojans.

10. Removed all files mentioned by the Dr. Web scan. Proceeded to scan computer again with Comodo Internet Security AV scan. Few more infections came up, proceeded to remove those as well.

11. Noticed that none of the removed content was on C:\. Proceeded with a deep scan of both HDDs&#039; &quot;System Volume Information&quot; folder. Found another ridiculous set of instances of Win32.Virut.Ce. Removed them all.

12. This is where I find myself.

Every time I idle my computer and it accesses the screen saver, I notice that my computer has found yet another instance of Virut in the non-Windows HDD&#039;s &quot;System Volume Information&quot; folder. I did just scan again and found more instances, so I removed those.

I just can&#039;t seem to tell whether the virus is still active, or if it&#039;s just remnants. When I use the system, Comodo does not alert me of anything. Also, websites are not blocked, and media files from that HDD do not further aggravate the system as I use them.

Though, I think I&#039;m pretty clear! Hope this helps as another guide and alternative to clear out Virut.</description>
		<content:encoded><![CDATA[<p>This stupid bugger&#8217;s put me a week of hard work into this computer.</p>
<p>I can&#8217;t say that I&#8217;m 100% free of the stupidity this thing does, but&#8230; I might have easy tips for getting rid of the virus, and some pointers to note for people who might be having issues:</p>
<p>1. The virus indiscriminantly infects all .exe and .scr files (even inside .zip, .rar, .7z, or any other kind of archive.) It also infects mostly system .dll files.</p>
<p>2. It does NOT infect any other &#8220;media&#8221; file. These include .mp3, .ogg, .wav, .avi, .mpg extensions and the like.</p>
<p>3. It doesn&#8217;t matter if you have more than one internal or external HDD or Flash drive (or any media that is rewritable), anything that meets the infection criteria WILL get infected.</p>
<p>4. Even if one file is already infected, the virus and any instances running WILL re-infect the same file in a different section of the coding.  Thus, multiple scans are necessary to make sure the file is ABSOLUTELY clean.</p>
<p>So&#8230; I have a LOT of music and videos that I&#8217;m a little too attached to and that I don&#8217;t want to lose. When I noticed that this stupid thing targets executables, I realized that I needed to reformat the HDD carrying the OS.  I did, and the virus came back.</p>
<p>I then noticed some strange occurrences.  Obviously, port 65520 was being accessed by winlogon.exe and explorer.exe. Even though this was a fresh install, I needed to reformat again already.</p>
<p>So, I took up the task of arming myself to clear out this virus from my system with the following tools:</p>
<p>1. Windows XP CD<br />
2. Hiren&#8217;s Boot CD v. 10.0<br />
3. Ubuntu v. 8.04 Live CD</p>
<p>Here&#8217;s how that worked.</p>
<p>1. I turned off my computer and unplugged the power cord and the Ethernet cable. Left off for 30 min, then plugged the power cord (not ethernet) back in, then booted to Hiren&#8217;s Boot CD.<br />
2. I used Hiren&#8217;s Boot CD&#8217;s partition tools to delete all partitions and destroy the data in the HDD carrying Windows XP.<br />
3. I used the HDD Regenerator in the Hard Disk tools section to check for corrupted sectors. Usually this only applies to physical errors and not so much to data, but if a section has been damaged it&#8217;s good to know.  Everything came back clean.<br />
4. Went back to Partition Tools and formatted out an NTFS partition for Windows XP.</p>
<p>5. Rebooted and used the Ubuntu Live CD. Using this I was able to get the drivers for anything that I needed on the computer, and clean virus free copies of them because Linux doesn&#8217;t have these kinds of virus issues. I also downloaded Virut Removal Tools and Comodo Internet Security and Dr. Web Cure It!. This is good for people that have lost their recovery CDs or their motherboard or display drivers. I placed all these into a clean USB Flash drive. When I copied everything in, I ejected and disconnected the drive.</p>
<p>6. I rebooted into the Windows XP CD. When asked for the desired partition, I performed yet another Format (not quick) on the blank NTFS partition. Proceeded with installing Windows.</p>
<p>7. When Windows loaded, I connected the USB Flash drive and placed its contents on the desktop. Proceeded with installing everything, starting with the basic motherboard drivers all the way to the AV tools and Security software. Ethernet cable is STILL disconnected.</p>
<p>8. Here I noticed none of the system files were behaving erratically. When Comodo Internet Security asked me to update the Virus DB, I then connected the Ethernet cable. Connections were safe, and port 65520 was not being accessed by any program. Definitions were updated, and port 65520 was eventually blocked.</p>
<p>9. Used Dr. Web Cure It! and performed a complete scan of the computer and all disks connected (USB Flash disconnected) overnight. Found a ridiculous amount of instances of Win32.Virut.56. Also found a few miscellaneous backdoors and other trojans.</p>
<p>10. Removed all files mentioned by the Dr. Web scan. Proceeded to scan computer again with Comodo Internet Security AV scan. Few more infections came up, proceeded to remove those as well.</p>
<p>11. Noticed that none of the removed content was on C:\. Proceeded with a deep scan of both HDDs&#8217; &#8220;System Volume Information&#8221; folder. Found another ridiculous set of instances of Win32.Virut.Ce. Removed them all.</p>
<p>12. This is where I find myself.</p>
<p>Every time I idle my computer and it accesses the screen saver, I notice that my computer has found yet another instance of Virut in the non-Windows HDD&#8217;s &#8220;System Volume Information&#8221; folder. I did just scan again and found more instances, so I removed those.</p>
<p>I just can&#8217;t seem to tell whether the virus is still active, or if it&#8217;s just remnants. When I use the system, Comodo does not alert me of anything. Also, websites are not blocked, and media files from that HDD do not further aggravate the system as I use them.</p>
<p>Though, I think I&#8217;m pretty clear! Hope this helps as another guide and alternative to clear out Virut.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by MEEEE</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65433</link>
		<dc:creator>MEEEE</dc:creator>
		<pubDate>Tue, 05 Jan 2010 17:44:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65433</guid>
		<description>change the file extension to something else, like readme.pdf ==&gt; readme.pdf.SSS
tHIS WILL FOOL THE VIRUS, i HOPE.....GOOD LUCK!</description>
		<content:encoded><![CDATA[<p>change the file extension to something else, like readme.pdf ==&gt; readme.pdf.SSS<br />
tHIS WILL FOOL THE VIRUS, i HOPE&#8230;..GOOD LUCK!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by How to remove Lsas.Blaster.Keyloger &#124; Jon Murphy Dot Net</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65431</link>
		<dc:creator>How to remove Lsas.Blaster.Keyloger &#124; Jon Murphy Dot Net</dc:creator>
		<pubDate>Tue, 05 Jan 2010 12:55:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65431</guid>
		<description>[...] Tags: how to remove Lsas.Blaster.Keyloger, Lsas Blaster Keyloger, Lsas.Blaster.Keyloger, Lsas.Blaster.Keyloger removal tool, Lsas.Blaster.Keyloger virus    via precisesecurity.com [...]</description>
		<content:encoded><![CDATA[<p>[...] Tags: how to remove Lsas.Blaster.Keyloger, Lsas Blaster Keyloger, Lsas.Blaster.Keyloger, Lsas.Blaster.Keyloger removal tool, Lsas.Blaster.Keyloger virus    via precisesecurity.com [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by shebaw</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65424</link>
		<dc:creator>shebaw</dc:creator>
		<pubDate>Sat, 02 Jan 2010 16:32:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65424</guid>
		<description>@Jaffer, why is my comment not costructive? Is that because it pointed out the truth, im confused here! 

&quot;We have a number of IT solution providers who are solving a number of problems&quot;... what problems, do you call a stupid straight froward database to calculate some stupid calculations real programming? Where were they when dulla struck? Any real programmer can program a remover for dulla but it took them ages before they can manage that, that shows how inexperienced and dumb they are.

If you have evidences, why don&#039;t you post it here. You make it sound like some type of mesterious mission. And if programming a PE infector is that easy, then why did it take them so long. And how many of the CS graduates here can program a remover for it, how many? I bet 99.99% of the graduates don&#039;t even know the difference between PE infector and some other script &quot;viruses&quot;, let alone knowing the structure of PE and programming a remover for a PE infector virus!!!</description>
		<content:encoded><![CDATA[<p>@Jaffer, why is my comment not costructive? Is that because it pointed out the truth, im confused here! </p>
<p>&#8220;We have a number of IT solution providers who are solving a number of problems&#8221;&#8230; what problems, do you call a stupid straight froward database to calculate some stupid calculations real programming? Where were they when dulla struck? Any real programmer can program a remover for dulla but it took them ages before they can manage that, that shows how inexperienced and dumb they are.</p>
<p>If you have evidences, why don&#8217;t you post it here. You make it sound like some type of mesterious mission. And if programming a PE infector is that easy, then why did it take them so long. And how many of the CS graduates here can program a remover for it, how many? I bet 99.99% of the graduates don&#8217;t even know the difference between PE infector and some other script &#8220;viruses&#8221;, let alone knowing the structure of PE and programming a remover for a PE infector virus!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by KENNY</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65418</link>
		<dc:creator>KENNY</dc:creator>
		<pubDate>Tue, 29 Dec 2009 16:57:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65418</guid>
		<description>By the way... once my computer was restored, I installed the &quot;Malwarebytes Anti-Malware&quot; software via the Malwarebytes Anti-Malware Instillation Wizard generated from the mbam-setup link on betanews.com/malwarebytes/mbam-setup.exe</description>
		<content:encoded><![CDATA[<p>By the way&#8230; once my computer was restored, I installed the &#8220;Malwarebytes Anti-Malware&#8221; software via the Malwarebytes Anti-Malware Instillation Wizard generated from the mbam-setup link on betanews.com/malwarebytes/mbam-setup.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by KENNY</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65417</link>
		<dc:creator>KENNY</dc:creator>
		<pubDate>Tue, 29 Dec 2009 16:37:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65417</guid>
		<description>I was having &quot;fits&quot; trying to get rid of the Lsas.Blaster.keyloger worm virus that kept popping up and preventing me from accessing anything that would assist, or, give me a clue as to what was going on. Finally after two and a half hours of several failed repeated attempts to download and run various softwware and clean up tools and devices. I shut off my computer and restarted it. While it was re-booting I pushed the F8 key before the &quot;Windows&quot; started. The computer entered the &quot;safe mode&quot;. I pushed the &quot;enter&quot; key, this allowed me the option to &quot;click-on&quot; as &quot;the administrator&quot;. Once I did this I was given the window option &quot;to,or, not to&quot; enter the safe mode. Choosing &quot;not to&quot; allowed me finally... the option to restore my computer. I clicked &quot;not to&quot; and was then given the option to restore my computer to a previous setting. Since I had been going at the failed attempts to get rid of the Lsas.Blaster.Keyloger worm virus for several hours, I just restored my computer to the previous day. Everything restored perfectly! It worked. This is a slight variation of the suggestion that I recieved in this comment section, except that I didn&#039;t try to run the embam-setup.exe from the &quot;safe mode&quot;.  Basically, I made the right decisions by following the instruction options that I was presented with. And as each suceeding window opened during this navigation process I took a breath of reliefe because I could see as I was going in the right direction. Try it! WHATEVER WORKS, RIGHT!!!   THANKS</description>
		<content:encoded><![CDATA[<p>I was having &#8220;fits&#8221; trying to get rid of the Lsas.Blaster.keyloger worm virus that kept popping up and preventing me from accessing anything that would assist, or, give me a clue as to what was going on. Finally after two and a half hours of several failed repeated attempts to download and run various softwware and clean up tools and devices. I shut off my computer and restarted it. While it was re-booting I pushed the F8 key before the &#8220;Windows&#8221; started. The computer entered the &#8220;safe mode&#8221;. I pushed the &#8220;enter&#8221; key, this allowed me the option to &#8220;click-on&#8221; as &#8220;the administrator&#8221;. Once I did this I was given the window option &#8220;to,or, not to&#8221; enter the safe mode. Choosing &#8220;not to&#8221; allowed me finally&#8230; the option to restore my computer. I clicked &#8220;not to&#8221; and was then given the option to restore my computer to a previous setting. Since I had been going at the failed attempts to get rid of the Lsas.Blaster.Keyloger worm virus for several hours, I just restored my computer to the previous day. Everything restored perfectly! It worked. This is a slight variation of the suggestion that I recieved in this comment section, except that I didn&#8217;t try to run the embam-setup.exe from the &#8220;safe mode&#8221;.  Basically, I made the right decisions by following the instruction options that I was presented with. And as each suceeding window opened during this navigation process I took a breath of reliefe because I could see as I was going in the right direction. Try it! WHATEVER WORKS, RIGHT!!!   THANKS</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Jaffer</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65413</link>
		<dc:creator>Jaffer</dc:creator>
		<pubDate>Mon, 28 Dec 2009 19:57:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65413</guid>
		<description>Dear Shebaw, ur comment is not constructive. Are sure about what u wrote, i don&#039;t think. We have a number of IT solution providers who are solving a number of problems. anyway u can email me for real evidences.

there r a number of C++ virus scripts on hackers and P2P site anyone with little programming skill specially in C++ can modify and increase the risk of the virus. Its is not a big deal nowadays.

for those who r suffering from ~dulla^@204~ u files could be recovered partially, if u uses Easy Recovery Professional or Advanced Word repair programs. If can&#039;t find the Software emailme at jaffermohATyahooDOTcom
wishing u all including ephrem, all  the best.</description>
		<content:encoded><![CDATA[<p>Dear Shebaw, ur comment is not constructive. Are sure about what u wrote, i don&#8217;t think. We have a number of IT solution providers who are solving a number of problems. anyway u can email me for real evidences.</p>
<p>there r a number of C++ virus scripts on hackers and P2P site anyone with little programming skill specially in C++ can modify and increase the risk of the virus. Its is not a big deal nowadays.</p>
<p>for those who r suffering from ~dulla^@204~ u files could be recovered partially, if u uses Easy Recovery Professional or Advanced Word repair programs. If can&#8217;t find the Software emailme at jaffermohATyahooDOTcom<br />
wishing u all including ephrem, all  the best.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by zizo</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65404</link>
		<dc:creator>zizo</dc:creator>
		<pubDate>Tue, 22 Dec 2009 08:28:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65404</guid>
		<description>helooooooooooooooooooooooooo</description>
		<content:encoded><![CDATA[<p>helooooooooooooooooooooooooo</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Maybe</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65388</link>
		<dc:creator>Maybe</dc:creator>
		<pubDate>Tue, 15 Dec 2009 23:37:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65388</guid>
		<description>Hiya all.  I don&#039;t recommend this unless you are positive that you have the right firmware.  Flash you BIOS.  clean computer up, flash again, then clean again.  Hope it helps a bit</description>
		<content:encoded><![CDATA[<p>Hiya all.  I don&#8217;t recommend this unless you are positive that you have the right firmware.  Flash you BIOS.  clean computer up, flash again, then clean again.  Hope it helps a bit</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by shebaw</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65368</link>
		<dc:creator>shebaw</dc:creator>
		<pubDate>Tue, 08 Dec 2009 20:32:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65368</guid>
		<description>@ephrem you are very stupid, you can&#039;t even differentiate between Macro virus and PE infecter VIRUS!!!  First of all, do you even know the definition of Macro Virus, i guess you don&#039;t. Even though the creator of Dulla used his knowledge for destructive ends, the coding of Dulla isn&#039;t stupid! Infact its brilliant coz almost none of the CS &quot;graduates&quot; can code innovative stuff coz the only thing they know is VB and JAVA and they consider themselves to be knowledgable!!! Ephrem, you are the perfect example!! CS is one of the hardest subjects to master, and even takes decades to be a good programmer. There will be almost none in Ethiopia because no one chooses what he likes to study on the University Level, almost all of the CS students here in Ethio got to CS schools because of their LOW results! Thats why its hard to find Ethiopians who love their Job, almost all of the high school students want to join Medical School on the hope of relatively high salary! How would you expect anyone to be good at anything if he joined it without interest! The CS graduates in Ethiopian are stupids without any knowledge in programming, and Ephrem if you claim that making the virus is easy, then why wouldn&#039;t you make the antivirus coz its easier than making the Virus!! Everyone here reading this post, if you joined something only by considering the salary, you won&#039;t ever be good at it and for all of the CS &quot;graduates&quot; in ethiopia, you don&#039;t know anything and you will never know anything if you continue like this!!! Check out rohitab.com, its filled with genius highschool students that make programs that even the Professor in Ethiopia will never know how to make them!</description>
		<content:encoded><![CDATA[<p>@ephrem you are very stupid, you can&#8217;t even differentiate between Macro virus and PE infecter VIRUS!!!  First of all, do you even know the definition of Macro Virus, i guess you don&#8217;t. Even though the creator of Dulla used his knowledge for destructive ends, the coding of Dulla isn&#8217;t stupid! Infact its brilliant coz almost none of the CS &#8220;graduates&#8221; can code innovative stuff coz the only thing they know is VB and JAVA and they consider themselves to be knowledgable!!! Ephrem, you are the perfect example!! CS is one of the hardest subjects to master, and even takes decades to be a good programmer. There will be almost none in Ethiopia because no one chooses what he likes to study on the University Level, almost all of the CS students here in Ethio got to CS schools because of their LOW results! Thats why its hard to find Ethiopians who love their Job, almost all of the high school students want to join Medical School on the hope of relatively high salary! How would you expect anyone to be good at anything if he joined it without interest! The CS graduates in Ethiopian are stupids without any knowledge in programming, and Ephrem if you claim that making the virus is easy, then why wouldn&#8217;t you make the antivirus coz its easier than making the Virus!! Everyone here reading this post, if you joined something only by considering the salary, you won&#8217;t ever be good at it and for all of the CS &#8220;graduates&#8221; in ethiopia, you don&#8217;t know anything and you will never know anything if you continue like this!!! Check out rohitab.com, its filled with genius highschool students that make programs that even the Professor in Ethiopia will never know how to make them!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Netwolf</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65367</link>
		<dc:creator>Netwolf</dc:creator>
		<pubDate>Tue, 08 Dec 2009 10:29:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65367</guid>
		<description>look ephrem or bla bla.The creator Dulla virus is not s----d or b-----d rather you are the b-----d he did what he can do or he wants to do may be you are the one who make it.u said  it can be made by a junior CS student. plz show me what you can code the biggest and main problem of ethiopians are we know a lil bit and we talk million times that&#039;s why we are not changing you might know vb.net(it is for dummies and kids) then you will laugh at c codders  dont be stupid and as you aid you can make a virus like that so post something you programmed ideot!!!!</description>
		<content:encoded><![CDATA[<p>look ephrem or bla bla.The creator Dulla virus is not s&#8212;-d or b&#8212;&#8211;d rather you are the b&#8212;&#8211;d he did what he can do or he wants to do may be you are the one who make it.u said  it can be made by a junior CS student. plz show me what you can code the biggest and main problem of ethiopians are we know a lil bit and we talk million times that&#8217;s why we are not changing you might know vb.net(it is for dummies and kids) then you will laugh at c codders  dont be stupid and as you aid you can make a virus like that so post something you programmed ideot!!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Tadele</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65359</link>
		<dc:creator>Tadele</dc:creator>
		<pubDate>Mon, 07 Dec 2009 08:48:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65359</guid>
		<description>Please make visible you loading option. How can I get this option?</description>
		<content:encoded><![CDATA[<p>Please make visible you loading option. How can I get this option?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Muller Digital</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65335</link>
		<dc:creator>Muller Digital</dc:creator>
		<pubDate>Mon, 30 Nov 2009 08:07:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65335</guid>
		<description>it&#039;s good but it can&#039;t protect z new worm, INSA-Worm, can u tell me about famous INSA?</description>
		<content:encoded><![CDATA[<p>it&#8217;s good but it can&#8217;t protect z new worm, INSA-Worm, can u tell me about famous INSA?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by dawit</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65324</link>
		<dc:creator>dawit</dc:creator>
		<pubDate>Wed, 25 Nov 2009 12:57:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65324</guid>
		<description>good but how con i recovered my  corrupted file
tell me what can i do</description>
		<content:encoded><![CDATA[<p>good but how con i recovered my  corrupted file<br />
tell me what can i do</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by eparico</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65307</link>
		<dc:creator>eparico</dc:creator>
		<pubDate>Sat, 21 Nov 2009 16:23:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65307</guid>
		<description>I&#039;ve been lucky so far but I&#039;m working on a friends laptop, a mini with no CD ROM drive, that was/is infected with Virut &amp; Delf...the bastards. I didn&#039;t know much about this virus and was unaware it attached itself to flash drives. Lesson learned! My AV program picked up this virus on a flash drive I was moving between my comp and the laptop. I created a bootable USB XP installation, reinstalled the OS on the mini only to find out the flash drive I used was infected. Now, I have to go back and reinstall a second time. 

After several scans using McAfee and Kaspersky online scanner (so far), luckily, my computer has not been infected. After doing a bit of research and reading a bunch of message boards, a lot of them say that the best resolution is to format and reinstall the OS. From what I&#039;ve read (check out Spybot S &amp; D message boards and search for Virut), this virus is said to attach itself to exe, scr, htm, html, asp, php, pdf, doc and even jpg files. There might be more that I&#039;m unaware of but to say the least, this has to be one of the nastiest viruses I&#039;ve ever run into. 

Some people have said that this virus can be eliminated but I&#039;m not willing to take this risk giving I transport some of my data between home and work with a flash drive. Good luck to anyone who spends days on end trying to fix instead of reinstalling their OS. Computers 101....ALWAYS back up your data in the event something like this should occur. You may spend several hours reinstalling all of your software but it beats spending days on end trying to fix a virus that might come back. 

Microsoft has released a security bulletin (967940) with a patch (KB971029) that will disable the AutoRun feature for flash drives to prevent automatic installation of software included (U3, etc) and will help prevent the running of an infected exe file. Best of luck everyone...</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been lucky so far but I&#8217;m working on a friends laptop, a mini with no CD ROM drive, that was/is infected with Virut &amp; Delf&#8230;the bastards. I didn&#8217;t know much about this virus and was unaware it attached itself to flash drives. Lesson learned! My AV program picked up this virus on a flash drive I was moving between my comp and the laptop. I created a bootable USB XP installation, reinstalled the OS on the mini only to find out the flash drive I used was infected. Now, I have to go back and reinstall a second time. </p>
<p>After several scans using McAfee and Kaspersky online scanner (so far), luckily, my computer has not been infected. After doing a bit of research and reading a bunch of message boards, a lot of them say that the best resolution is to format and reinstall the OS. From what I&#8217;ve read (check out Spybot S &amp; D message boards and search for Virut), this virus is said to attach itself to exe, scr, htm, html, asp, php, pdf, doc and even jpg files. There might be more that I&#8217;m unaware of but to say the least, this has to be one of the nastiest viruses I&#8217;ve ever run into. </p>
<p>Some people have said that this virus can be eliminated but I&#8217;m not willing to take this risk giving I transport some of my data between home and work with a flash drive. Good luck to anyone who spends days on end trying to fix instead of reinstalling their OS. Computers 101&#8230;.ALWAYS back up your data in the event something like this should occur. You may spend several hours reinstalling all of your software but it beats spending days on end trying to fix a virus that might come back. </p>
<p>Microsoft has released a security bulletin (967940) with a patch (KB971029) that will disable the AutoRun feature for flash drives to prevent automatic installation of software included (U3, etc) and will help prevent the running of an infected exe file. Best of luck everyone&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by soulless</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65299</link>
		<dc:creator>soulless</dc:creator>
		<pubDate>Tue, 17 Nov 2009 11:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65299</guid>
		<description>ive found that using hirens 10 both in windows and minixp and using the following apps - Kasperky, Malwarebyte, Superantipyware and smitfraudfx manages to get rid of the virus and then just going through the harddrive like c:, temp dirs, Windows, System32, Fonts, system volume information, recycler, Documents and Settings folders and deleting the weired files i find there such as Restorer_32a.exe and Reader_s.exe (Found a new one recently photo_id.exe) and also scanning the reg for them and removing them. This seems to be able to get rid of the virus but ive found a few times there are still bits and peices of it flying around so a few more scans and checking the folders and reg again pretty much cleared it up but Kaspersky can disinect the files but you will proably have to do a repair on you windows again. 

In one of the earlier posts someone mentioned that he used a irc prog to connect to his computer and managed to ulter the options of the virus. Im curious to know if this is true.</description>
		<content:encoded><![CDATA[<p>ive found that using hirens 10 both in windows and minixp and using the following apps &#8211; Kasperky, Malwarebyte, Superantipyware and smitfraudfx manages to get rid of the virus and then just going through the harddrive like c:, temp dirs, Windows, System32, Fonts, system volume information, recycler, Documents and Settings folders and deleting the weired files i find there such as Restorer_32a.exe and Reader_s.exe (Found a new one recently photo_id.exe) and also scanning the reg for them and removing them. This seems to be able to get rid of the virus but ive found a few times there are still bits and peices of it flying around so a few more scans and checking the folders and reg again pretty much cleared it up but Kaspersky can disinect the files but you will proably have to do a repair on you windows again. </p>
<p>In one of the earlier posts someone mentioned that he used a irc prog to connect to his computer and managed to ulter the options of the virus. Im curious to know if this is true.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by overkill</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65288</link>
		<dc:creator>overkill</dc:creator>
		<pubDate>Tue, 10 Nov 2009 14:54:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65288</guid>
		<description>Here&#039;s a question for you tech-savvy guys:

What exactly is the danger of the port (65520) that this thing uses ? Assuming you are able to clear the infection from your system (disk &amp; memory), then is there any chance that it can re-enter ? I am assuming not.</description>
		<content:encoded><![CDATA[<p>Here&#8217;s a question for you tech-savvy guys:</p>
<p>What exactly is the danger of the port (65520) that this thing uses ? Assuming you are able to clear the infection from your system (disk &amp; memory), then is there any chance that it can re-enter ? I am assuming not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Rebecca</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65286</link>
		<dc:creator>Rebecca</dc:creator>
		<pubDate>Mon, 09 Nov 2009 22:48:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65286</guid>
		<description>I followed the instructions the webmaster gave above follow it... If it&#039;s not working it might be because you might not be on the administrator user thingy of the computer!!!! I tried that and worked for me now my computer works!!!</description>
		<content:encoded><![CDATA[<p>I followed the instructions the webmaster gave above follow it&#8230; If it&#8217;s not working it might be because you might not be on the administrator user thingy of the computer!!!! I tried that and worked for me now my computer works!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Arsby</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65278</link>
		<dc:creator>Arsby</dc:creator>
		<pubDate>Sun, 08 Nov 2009 17:13:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65278</guid>
		<description>I had a happy ending, I think.
I got this bug on my Vista laptop on Friday by being stupid.  Kaspersky slows down my downloads, so I turned it off.  I forgot it was off and tried to install an app from the newsgroups.  The first thing Virute did was set my system clock forward to 2049, so Kaspersky thought it had expired 40 years ago!  Then it started eating my executables.
I took the laptop HD out and put it in a SATA USB enclosure attached to a Kaspersky-protected desktop.  I started moving all the files I wanted to save onto the desktop, and ran Kaspersky against the HD in enclosure.  I initially thought I fixed it with Kaspersky and moved it back, but it was still infected.  I then adjusted the Kaspersky setting to Maximum Protection and pointed it explicitly to the USB drive.  It found and deleted a trojan and 216 files (mostly exe&#039;s) that were infected.
This morning, Sunday, I put the HD back into the laptop and turned it on, fully expecting to have to recover and wipe the HD.  Signon went well, but it couldn&#039;t find two dll&#039;s.  Kaspersky was still working on the laptop, and found nothing during its startup procedure.   The internet is working, I&#039;m posting from the laptop now.  Some applications aren&#039;t working because the executables are gone, but others, including MS Office, are.     
So it looks like a happy ending.   
So for the previous poster and others...  IF it&#039;s a laptop that&#039;s infected, it&#039;s really easy to pop out a laptop hard drive, then go to Best Buy or something like it and buy a USB enclosure for it.  (Warning, there are two types, SATA and another one.)   Attach it to another PC that&#039;s virus protected, and have it run a full maximum check against the drive that&#039;s now via USB.  Have it delete anything that&#039;s infected.  (Kaspersky does the deletions *after* it finished the full scan.)  Then put it back into the laptop and see if it works.</description>
		<content:encoded><![CDATA[<p>I had a happy ending, I think.<br />
I got this bug on my Vista laptop on Friday by being stupid.  Kaspersky slows down my downloads, so I turned it off.  I forgot it was off and tried to install an app from the newsgroups.  The first thing Virute did was set my system clock forward to 2049, so Kaspersky thought it had expired 40 years ago!  Then it started eating my executables.<br />
I took the laptop HD out and put it in a SATA USB enclosure attached to a Kaspersky-protected desktop.  I started moving all the files I wanted to save onto the desktop, and ran Kaspersky against the HD in enclosure.  I initially thought I fixed it with Kaspersky and moved it back, but it was still infected.  I then adjusted the Kaspersky setting to Maximum Protection and pointed it explicitly to the USB drive.  It found and deleted a trojan and 216 files (mostly exe&#8217;s) that were infected.<br />
This morning, Sunday, I put the HD back into the laptop and turned it on, fully expecting to have to recover and wipe the HD.  Signon went well, but it couldn&#8217;t find two dll&#8217;s.  Kaspersky was still working on the laptop, and found nothing during its startup procedure.   The internet is working, I&#8217;m posting from the laptop now.  Some applications aren&#8217;t working because the executables are gone, but others, including MS Office, are.<br />
So it looks like a happy ending.<br />
So for the previous poster and others&#8230;  IF it&#8217;s a laptop that&#8217;s infected, it&#8217;s really easy to pop out a laptop hard drive, then go to Best Buy or something like it and buy a USB enclosure for it.  (Warning, there are two types, SATA and another one.)   Attach it to another PC that&#8217;s virus protected, and have it run a full maximum check against the drive that&#8217;s now via USB.  Have it delete anything that&#8217;s infected.  (Kaspersky does the deletions *after* it finished the full scan.)  Then put it back into the laptop and see if it works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Cathy</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65276</link>
		<dc:creator>Cathy</dc:creator>
		<pubDate>Sun, 08 Nov 2009 15:25:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65276</guid>
		<description>Sorry last post should read could NOT remove all infected items. ???</description>
		<content:encoded><![CDATA[<p>Sorry last post should read could NOT remove all infected items. ???</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Cathy</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65274</link>
		<dc:creator>Cathy</dc:creator>
		<pubDate>Sun, 08 Nov 2009 15:20:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65274</guid>
		<description>Hi- please help. 
Did step 6 in safe mode, but could remove all infected items. I&#039;m no further forward. Any ideas?</description>
		<content:encoded><![CDATA[<p>Hi- please help.<br />
Did step 6 in safe mode, but could remove all infected items. I&#8217;m no further forward. Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Simon</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65271</link>
		<dc:creator>Simon</dc:creator>
		<pubDate>Fri, 06 Nov 2009 00:54:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65271</guid>
		<description>Ok all you guys,

I couldn&#039;t access anything on my computer as it closed automatically (including Task manager, all programs and stuff) except the internet. So I downloaded the software Malwarebytes’ Anti-Malware (mbam-setup.exe)  and restarted my computer in Safe MODE.  Then I searched (while in safe mode) using start - search: &quot;mbam-setup.exe&quot; and installed the software.</description>
		<content:encoded><![CDATA[<p>Ok all you guys,</p>
<p>I couldn&#8217;t access anything on my computer as it closed automatically (including Task manager, all programs and stuff) except the internet. So I downloaded the software Malwarebytes’ Anti-Malware (mbam-setup.exe)  and restarted my computer in Safe MODE.  Then I searched (while in safe mode) using start &#8211; search: &#8220;mbam-setup.exe&#8221; and installed the software.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by DonkeyDolck</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65264</link>
		<dc:creator>DonkeyDolck</dc:creator>
		<pubDate>Tue, 03 Nov 2009 00:10:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65264</guid>
		<description>Hey.. I got these virus yeasterday (win32/virut and win32/heur) When i read about it that it infected all the .exe and possibly .jpg files i went nuts, turned of my computer unplugged my other 2 drives (D: and E:)on it and installed windows 7 64bit today. Downloaded avg free 9.0 and searched D: and it had 5 infected .exe files. wich it said that it was removed. So it hadn&#039;t have the time to spread that far. Now i wonder if it still might spread into my C: where i have my windows or if it will continue to spread through my D: and E: (havn&#039;t plugged E: in yet, so i don&#039;t know how badly infected it is.) Or shall i just leave them unplugged until a bulletproof removal program for those viruses are released? Really don&#039;t wanna mess up all my pictures and stuff there if it&#039;s possible to avoid.. damn.. pics on there since 2002. :/ What to do? Any help would be mostly appreciated</description>
		<content:encoded><![CDATA[<p>Hey.. I got these virus yeasterday (win32/virut and win32/heur) When i read about it that it infected all the .exe and possibly .jpg files i went nuts, turned of my computer unplugged my other 2 drives (D: and E:)on it and installed windows 7 64bit today. Downloaded avg free 9.0 and searched D: and it had 5 infected .exe files. wich it said that it was removed. So it hadn&#8217;t have the time to spread that far. Now i wonder if it still might spread into my C: where i have my windows or if it will continue to spread through my D: and E: (havn&#8217;t plugged E: in yet, so i don&#8217;t know how badly infected it is.) Or shall i just leave them unplugged until a bulletproof removal program for those viruses are released? Really don&#8217;t wanna mess up all my pictures and stuff there if it&#8217;s possible to avoid.. damn.. pics on there since 2002. :/ What to do? Any help would be mostly appreciated</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Szabolcs</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65261</link>
		<dc:creator>Szabolcs</dc:creator>
		<pubDate>Sat, 31 Oct 2009 11:11:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65261</guid>
		<description>Confirmed. I agree with the first poster (and the most of you),  it sneaked through avast&#039;s protection, I fought this about a week long, that process let me figure out some important stuff.

This malware is probably added by Win32.Agent along with Win32.Delf and b.exe, just to mention the most critical ones and some others (3-4 more)

 - It hides on your portable devices such as pendrives portable hard disk or other partitions.
 - When you connect to the internet, this will download the whole pack again, causing you more trouble.
 - These malware only works on 32-bit based Windows systems. You should consider updating to 64-bit (there are some drawback) or try Windows 7.
 - Only Win32.Virut will infect files, others should create their own, which you can find in &quot;C:\&quot; and &quot;C:\Windows\system32&quot; or in &quot;Documents and Settings&quot;

Note: A new version has come out in October 2009 and even Kaspersky Labs do not have an update for this infection yet. Although, Kaspersky is able to competely eradicate this virus, thanks to it&#039;s more advanced and intelligent being, compered to other virusbusters.

Conclusion: I am now using Windows 7 x64, works quite well that far.</description>
		<content:encoded><![CDATA[<p>Confirmed. I agree with the first poster (and the most of you),  it sneaked through avast&#8217;s protection, I fought this about a week long, that process let me figure out some important stuff.</p>
<p>This malware is probably added by Win32.Agent along with Win32.Delf and b.exe, just to mention the most critical ones and some others (3-4 more)</p>
<p> &#8211; It hides on your portable devices such as pendrives portable hard disk or other partitions.<br />
 &#8211; When you connect to the internet, this will download the whole pack again, causing you more trouble.<br />
 &#8211; These malware only works on 32-bit based Windows systems. You should consider updating to 64-bit (there are some drawback) or try Windows 7.<br />
 &#8211; Only Win32.Virut will infect files, others should create their own, which you can find in &#8220;C:\&#8221; and &#8220;C:\Windows\system32&#8243; or in &#8220;Documents and Settings&#8221;</p>
<p>Note: A new version has come out in October 2009 and even Kaspersky Labs do not have an update for this infection yet. Although, Kaspersky is able to competely eradicate this virus, thanks to it&#8217;s more advanced and intelligent being, compered to other virusbusters.</p>
<p>Conclusion: I am now using Windows 7 x64, works quite well that far.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by ephrem</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65257</link>
		<dc:creator>ephrem</dc:creator>
		<pubDate>Thu, 29 Oct 2009 15:55:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65257</guid>
		<description>This is really bad fortune for Ethiopians that hears Dulla virus has been created by Ethiopian distractive guy or Association. You know creating very_low_risk and very ordinary system virus like Dulla is not a work of proud. Most educated Ethiopians suspect strongly who has created this gadium virus. In my belief the current stated antivirus for Dulla-Tsere Dulla creator has created the virus itself before. Because the name of a virus it self is Amharic word, besides the solution itself has found from Ethiopia by the association they called INSA. Don’t forget also most commercial antivirus producers ignore or don’t care about to get a solution for this virus. And do not forget Dulla virus is a kind of very easy and low risk ordinary virus that even a younger student of computer science student with out experience can create this kind of macro type of virus. If I were a creator of this virus, I would rather participate to create a kind problem solving projects for this poor country. Shame on this virus creator. Let me tell him what is he done is reflect he is ordinary, very easy and useless bastard gay. By the way I am not giving this opinion just being hot or affected by the virus. And let me tell him that even I can create such virus. But I wouldn’t be interested to be criminal. I am sorry to use irrational words.</description>
		<content:encoded><![CDATA[<p>This is really bad fortune for Ethiopians that hears Dulla virus has been created by Ethiopian distractive guy or Association. You know creating very_low_risk and very ordinary system virus like Dulla is not a work of proud. Most educated Ethiopians suspect strongly who has created this gadium virus. In my belief the current stated antivirus for Dulla-Tsere Dulla creator has created the virus itself before. Because the name of a virus it self is Amharic word, besides the solution itself has found from Ethiopia by the association they called INSA. Don’t forget also most commercial antivirus producers ignore or don’t care about to get a solution for this virus. And do not forget Dulla virus is a kind of very easy and low risk ordinary virus that even a younger student of computer science student with out experience can create this kind of macro type of virus. If I were a creator of this virus, I would rather participate to create a kind problem solving projects for this poor country. Shame on this virus creator. Let me tell him what is he done is reflect he is ordinary, very easy and useless bastard gay. By the way I am not giving this opinion just being hot or affected by the virus. And let me tell him that even I can create such virus. But I wouldn’t be interested to be criminal. I am sorry to use irrational words.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by tadesse</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65256</link>
		<dc:creator>tadesse</dc:creator>
		<pubDate>Thu, 29 Oct 2009 09:33:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65256</guid>
		<description>Please send Tsere dulla Antivrus. My documents are at riskThe file already corrupted, so how can i recover the excel files?+</description>
		<content:encoded><![CDATA[<p>Please send Tsere dulla Antivrus. My documents are at riskThe file already corrupted, so how can i recover the excel files?+</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Alekaw</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65254</link>
		<dc:creator>Alekaw</dc:creator>
		<pubDate>Tue, 27 Oct 2009 15:16:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65254</guid>
		<description>I appreciate  Dull Virus creator man really !! For future I will expect more that used for our country &#039;Ethiopia&#039; and pass to Next Generation !!</description>
		<content:encoded><![CDATA[<p>I appreciate  Dull Virus creator man really !! For future I will expect more that used for our country &#8216;Ethiopia&#8217; and pass to Next Generation !!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Aaron</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65244</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Thu, 22 Oct 2009 18:51:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65244</guid>
		<description>OR
None of these worked for me, even option 6.  Try a slightly different way though:

I tried to go into safe mode, but it wouldn&#039;t let me, so I selected to start up in normal windows.

As it was starting up, I pushed F10, and then maneuvered from back there.  Click the tab that has the date, and change the date per option 6. Click save and continue to restart in normal mode.  Everything was fixed.</description>
		<content:encoded><![CDATA[<p>OR<br />
None of these worked for me, even option 6.  Try a slightly different way though:</p>
<p>I tried to go into safe mode, but it wouldn&#8217;t let me, so I selected to start up in normal windows.</p>
<p>As it was starting up, I pushed F10, and then maneuvered from back there.  Click the tab that has the date, and change the date per option 6. Click save and continue to restart in normal mode.  Everything was fixed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on go.google &#8211; go.yahoo by Hyoran</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects#comment-65242</link>
		<dc:creator>Hyoran</dc:creator>
		<pubDate>Tue, 20 Oct 2009 17:41:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects/#comment-65242</guid>
		<description>I&#039;ve tried everything to find the TDSSserv.sys including the scan for hardware changes and i still can&#039;t find it. Is there any other hardware you can disable that will help?

Also i seem to have problems with serial and npkcrypt. Why have they stopped working?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve tried everything to find the TDSSserv.sys including the scan for hardware changes and i still can&#8217;t find it. Is there any other hardware you can disable that will help?</p>
<p>Also i seem to have problems with serial and npkcrypt. Why have they stopped working?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by brandon</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65237</link>
		<dc:creator>brandon</dc:creator>
		<pubDate>Mon, 19 Oct 2009 13:28:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65237</guid>
		<description>yyyyaaaay everyone do post six it works and takes under 3 minutes. go under safe mode to do yayayayayay tytyty</description>
		<content:encoded><![CDATA[<p>yyyyaaaay everyone do post six it works and takes under 3 minutes. go under safe mode to do yayayayayay tytyty</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by brandon</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65236</link>
		<dc:creator>brandon</dc:creator>
		<pubDate>Mon, 19 Oct 2009 13:26:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65236</guid>
		<description>i did post six still waiting to see if it worked ;)</description>
		<content:encoded><![CDATA[<p>i did post six still waiting to see if it worked ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Biny</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65228</link>
		<dc:creator>Biny</dc:creator>
		<pubDate>Thu, 15 Oct 2009 11:12:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65228</guid>
		<description>I&#039;m still wondering who developed dulla virus,i&#039;ll b very happy if INSA has something to say abt it.</description>
		<content:encoded><![CDATA[<p>I&#8217;m still wondering who developed dulla virus,i&#8217;ll b very happy if INSA has something to say abt it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Amaha Fikru</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65225</link>
		<dc:creator>Amaha Fikru</dc:creator>
		<pubDate>Tue, 13 Oct 2009 06:40:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65225</guid>
		<description>The file already corrupted, so how can i recover the excel files?</description>
		<content:encoded><![CDATA[<p>The file already corrupted, so how can i recover the excel files?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by ceri</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comment-65219</link>
		<dc:creator>ceri</dc:creator>
		<pubDate>Mon, 12 Oct 2009 13:02:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65219</guid>
		<description>I went to the microsoft site sorted it straight away</description>
		<content:encoded><![CDATA[<p>I went to the microsoft site sorted it straight away</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by uuzoo</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65215</link>
		<dc:creator>uuzoo</dc:creator>
		<pubDate>Sat, 10 Oct 2009 12:08:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65215</guid>
		<description>This is a nasty virus! I got hit with it a couple of weeks ago from downloading programs. My antivirus at the time ( avast) detected it but couldn&#039;t do nothing about it. So, I did some research on the net, and was told to download Kaspersky removal tool. It detected it, and was neutralizing it, but the virus was spreading like a forest fire. It got to about 3,000 files infected, and I said forget it. I ended up reformatting and reinstalling OS. It WORKED! What&#039;s really interesting is that I didn&#039;t know it at the time but my flashdrive was connected in the back of the tower, and it got infected. After reinstalling everything. I realized that my flashdrive was in too. I&#039;m thinking oh no. I ran avast but nothing came up. I&#039;ve now installed Vipre and ran scan on the flashdrive and it detected and neutralized the virus. Now I&#039;m using Vipre. Been working well.</description>
		<content:encoded><![CDATA[<p>This is a nasty virus! I got hit with it a couple of weeks ago from downloading programs. My antivirus at the time ( avast) detected it but couldn&#8217;t do nothing about it. So, I did some research on the net, and was told to download Kaspersky removal tool. It detected it, and was neutralizing it, but the virus was spreading like a forest fire. It got to about 3,000 files infected, and I said forget it. I ended up reformatting and reinstalling OS. It WORKED! What&#8217;s really interesting is that I didn&#8217;t know it at the time but my flashdrive was connected in the back of the tower, and it got infected. After reinstalling everything. I realized that my flashdrive was in too. I&#8217;m thinking oh no. I ran avast but nothing came up. I&#8217;ve now installed Vipre and ran scan on the flashdrive and it detected and neutralized the virus. Now I&#8217;m using Vipre. Been working well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Ermias</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65205</link>
		<dc:creator>Ermias</dc:creator>
		<pubDate>Thu, 08 Oct 2009 07:19:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65205</guid>
		<description>Please send Tsere dulla Antivrus. My documents are at risk</description>
		<content:encoded><![CDATA[<p>Please send Tsere dulla Antivrus. My documents are at risk</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by itchy</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65204</link>
		<dc:creator>itchy</dc:creator>
		<pubDate>Wed, 07 Oct 2009 23:06:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65204</guid>
		<description>ow also cleaned my external hard drive no problems there. my friend however who apparently didnt have anti-virus. and who waited to long is completely screwed. he cant even dl the avg removal tool</description>
		<content:encoded><![CDATA[<p>ow also cleaned my external hard drive no problems there. my friend however who apparently didnt have anti-virus. and who waited to long is completely screwed. he cant even dl the avg removal tool</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by itchy</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65203</link>
		<dc:creator>itchy</dc:creator>
		<pubDate>Wed, 07 Oct 2009 23:04:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65203</guid>
		<description>i only used kaspersky 2010 and the avg link that was mentioned hxxp://www.avg.com/us.virus-removal.ndi-67762 
and im done.
took me about 2 hours (because my pc was just rebooted there wasnt mutch to scan)</description>
		<content:encoded><![CDATA[<p>i only used kaspersky 2010 and the avg link that was mentioned hxxp://www.avg.com/us.virus-removal.ndi-67762<br />
and im done.<br />
took me about 2 hours (because my pc was just rebooted there wasnt mutch to scan)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by SChalice</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65191</link>
		<dc:creator>SChalice</dc:creator>
		<pubDate>Thu, 01 Oct 2009 02:34:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65191</guid>
		<description>This virus can get on compact flash sticks. You&#039;ll need to be sure to wipe all those suckers clean or just throw them away if unsure..</description>
		<content:encoded><![CDATA[<p>This virus can get on compact flash sticks. You&#8217;ll need to be sure to wipe all those suckers clean or just throw them away if unsure..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Dawit</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65172</link>
		<dc:creator>Dawit</dc:creator>
		<pubDate>Thu, 24 Sep 2009 08:43:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65172</guid>
		<description>Amanuel Kenna and AreMoh.

I think you two know how to recover pdf files that have been infected by the dulla virus using hex editor. I tried several times and I didn&#039;t succeed. Please help. I am really anxious.</description>
		<content:encoded><![CDATA[<p>Amanuel Kenna and AreMoh.</p>
<p>I think you two know how to recover pdf files that have been infected by the dulla virus using hex editor. I tried several times and I didn&#8217;t succeed. Please help. I am really anxious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by expertanalyzer</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65171</link>
		<dc:creator>expertanalyzer</dc:creator>
		<pubDate>Tue, 22 Sep 2009 23:27:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65171</guid>
		<description>send me the teddy afro virus infected file sample i am expert virus anlayzer and i love to help people in my free time if you have teddy afro virus infected file attach and send it to my email: father@safe-mail.net  i will give you free removal tool for free.
thanks.</description>
		<content:encoded><![CDATA[<p>send me the teddy afro virus infected file sample i am expert virus anlayzer and i love to help people in my free time if you have teddy afro virus infected file attach and send it to my email: <a href="mailto:father@safe-mail.net">father@safe-mail.net</a>  i will give you free removal tool for free.<br />
thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Joe</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65161</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Sun, 20 Sep 2009 22:01:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65161</guid>
		<description>This virus infected my old HD, so I had no choice but to reinstall WinXP. Then today I accidently clicked an old executable on that HD and the virus is reinfected me. I was in no mood to reinstall so this is how I dealt with it.

DO NOT START ANY PROGRAMS YET, THEY WILL GET INFECTED

1. Pull the plug on your internet connection, because it will try to connect to its website (jL.chura.pl and maybe others) and download more crap to your PC

2. Go to Task Manager and kill ANY program that looks unfamiliar (this can be tricky, if you&#039;re a not a computer geek)

3. Run services.msc and you&#039;ll see at least 2 services running which have NO description. Stop them and then disable them (by right clicking). Also stop and disable Remote Access Connection Manager, and Background Intelligent Transfer System, if they are running. These are Windows processes, but I think the virus activates them.

4. Repeat step 2 just in case

5. Now you have a choice:
a)You can run restore, but you have to be very sure that the restore is clean
b) run your antivirus. A full scan is preferable, but at least C:\Windows\ and C:\Program Files\. The virus infected only logonui.exe in my case and changed the HOSTS file, and created a temporary file in the WINDOWS\TEMP directory, but nothing else. However, if you ran any program while the virus was loaded, that program will be infected too.

This is the stage on which I am myself. The virus is removed but my system is still a bit screwed up, because everytime I reboot a hidden process iexplore.exe is started, except it&#039;s not connecting anywhere. I&#039;m not sure what&#039;s starting it, but I dealt with it by killing the process and moving iexplore.exe to a temporary folder.</description>
		<content:encoded><![CDATA[<p>This virus infected my old HD, so I had no choice but to reinstall WinXP. Then today I accidently clicked an old executable on that HD and the virus is reinfected me. I was in no mood to reinstall so this is how I dealt with it.</p>
<p>DO NOT START ANY PROGRAMS YET, THEY WILL GET INFECTED</p>
<p>1. Pull the plug on your internet connection, because it will try to connect to its website (jL.chura.pl and maybe others) and download more crap to your PC</p>
<p>2. Go to Task Manager and kill ANY program that looks unfamiliar (this can be tricky, if you&#8217;re a not a computer geek)</p>
<p>3. Run services.msc and you&#8217;ll see at least 2 services running which have NO description. Stop them and then disable them (by right clicking). Also stop and disable Remote Access Connection Manager, and Background Intelligent Transfer System, if they are running. These are Windows processes, but I think the virus activates them.</p>
<p>4. Repeat step 2 just in case</p>
<p>5. Now you have a choice:<br />
a)You can run restore, but you have to be very sure that the restore is clean<br />
b) run your antivirus. A full scan is preferable, but at least C:\Windows\ and C:\Program Files\. The virus infected only logonui.exe in my case and changed the HOSTS file, and created a temporary file in the WINDOWS\TEMP directory, but nothing else. However, if you ran any program while the virus was loaded, that program will be infected too.</p>
<p>This is the stage on which I am myself. The virus is removed but my system is still a bit screwed up, because everytime I reboot a hidden process iexplore.exe is started, except it&#8217;s not connecting anywhere. I&#8217;m not sure what&#8217;s starting it, but I dealt with it by killing the process and moving iexplore.exe to a temporary folder.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Fennec the sysop</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65160</link>
		<dc:creator>Fennec the sysop</dc:creator>
		<pubDate>Sun, 20 Sep 2009 20:07:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65160</guid>
		<description>This virus is a pain but I have it contained ,my router is a good firewall and I have it set to block all incoming connections on port 65520 and all outgoing connections to Proxima.ircgalaxy.pl so that means the attackers cant use it I have also found that using IRC to connect to my local machine on port 65520 gives you control of this virus so now I am able to change the options and on my machine it only infects explorer.exe too bad it dosent have a disinfect command</description>
		<content:encoded><![CDATA[<p>This virus is a pain but I have it contained ,my router is a good firewall and I have it set to block all incoming connections on port 65520 and all outgoing connections to Proxima.ircgalaxy.pl so that means the attackers cant use it I have also found that using IRC to connect to my local machine on port 65520 gives you control of this virus so now I am able to change the options and on my machine it only infects explorer.exe too bad it dosent have a disinfect command</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by amanuel girma (haramaya university)</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65158</link>
		<dc:creator>amanuel girma (haramaya university)</dc:creator>
		<pubDate>Sat, 19 Sep 2009 22:25:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65158</guid>
		<description>HOW TO PARTIAL REPAIR OFFICE DOCUMENTS INFECTED WIZ “~dulla^@204~” VIRUS
Before you start this tutorial clean your pc wiz anti dulla software I recommend
Emopia® Virus Removal Pack (freeware) from emopia.com
	Tools needed for this tutorial
•	Notepad ++ (absolutely free download and install this software)
•	Office 2007
•	An infected file 
1.	Right click on the infected office document &gt;&gt;click “edit with notepad ++” now the document will be opened in notepad++ window
2.	Click on “search” from the menu &gt;&gt;click on” find” &gt;&gt; click on “replace” tab
3.	Type ‘~dulla^@204~\x00’ (without the quote) on “find what” box&gt;&gt; check the “regular expression” check box &gt;&gt; click on “find next” tab &gt;&gt; click on “replace all” tab &gt;&gt; ok &gt;&gt; done.
4.	Click done &gt;&gt; click on the” save” from menu &gt;&gt; close notepad ++ &gt;&gt; open the infected(corrupted) document when a dialog box appear click yes
any question please email me :amangirma@gmail.com</description>
		<content:encoded><![CDATA[<p>HOW TO PARTIAL REPAIR OFFICE DOCUMENTS INFECTED WIZ “~dulla^@204~” VIRUS<br />
Before you start this tutorial clean your pc wiz anti dulla software I recommend<br />
Emopia® Virus Removal Pack (freeware) from emopia.com<br />
	Tools needed for this tutorial<br />
•	Notepad ++ (absolutely free download and install this software)<br />
•	Office 2007<br />
•	An infected file<br />
1.	Right click on the infected office document &gt;&gt;click “edit with notepad ++” now the document will be opened in notepad++ window<br />
2.	Click on “search” from the menu &gt;&gt;click on” find” &gt;&gt; click on “replace” tab<br />
3.	Type ‘~dulla^@204~\x00’ (without the quote) on “find what” box&gt;&gt; check the “regular expression” check box &gt;&gt; click on “find next” tab &gt;&gt; click on “replace all” tab &gt;&gt; ok &gt;&gt; done.<br />
4.	Click done &gt;&gt; click on the” save” from menu &gt;&gt; close notepad ++ &gt;&gt; open the infected(corrupted) document when a dialog box appear click yes<br />
any question please email me :amangirma@gmail.com</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Jiru</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65153</link>
		<dc:creator>Jiru</dc:creator>
		<pubDate>Thu, 17 Sep 2009 10:22:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65153</guid>
		<description>Ther is a virus named Teddy afro which has characterstic feature of hiding your files and disabling ur cd driver...it is even difficult to remove it with command...i have tried avira, kaspersky,macaffe,avg,and NOD..non of them could remove that.You guys do you have any solution for that?EMOPIA ..it is just fake..it cant detect any virus...</description>
		<content:encoded><![CDATA[<p>Ther is a virus named Teddy afro which has characterstic feature of hiding your files and disabling ur cd driver&#8230;it is even difficult to remove it with command&#8230;i have tried avira, kaspersky,macaffe,avg,and NOD..non of them could remove that.You guys do you have any solution for that?EMOPIA ..it is just fake..it cant detect any virus&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Abdulkerim</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65147</link>
		<dc:creator>Abdulkerim</dc:creator>
		<pubDate>Tue, 15 Sep 2009 12:02:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65147</guid>
		<description>People! Get over it! There is no method to recover corrupted files, you can see the reason on facebook, just go to emopia.com (they are the one who made emopia virus remover, and are professionals) and join their facebook page and in the discussion board, you can read the reason why dulla corrupted files can&#039;t be recovered.</description>
		<content:encoded><![CDATA[<p>People! Get over it! There is no method to recover corrupted files, you can see the reason on facebook, just go to emopia.com (they are the one who made emopia virus remover, and are professionals) and join their facebook page and in the discussion board, you can read the reason why dulla corrupted files can&#8217;t be recovered.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by AreMoh</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65117</link>
		<dc:creator>AreMoh</dc:creator>
		<pubDate>Mon, 07 Sep 2009 19:55:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65117</guid>
		<description>for Solution For Every Thing(160) what about *.xls or *.xlsx files? I need help.</description>
		<content:encoded><![CDATA[<p>for Solution For Every Thing(160) what about *.xls or *.xlsx files? I need help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by AreMoh</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65116</link>
		<dc:creator>AreMoh</dc:creator>
		<pubDate>Mon, 07 Sep 2009 19:52:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65116</guid>
		<description>for Amanuel Kenna(162) how can I recover dulla infected files with hex editor? I need additional information or the steps of recovering!</description>
		<content:encoded><![CDATA[<p>for Amanuel Kenna(162) how can I recover dulla infected files with hex editor? I need additional information or the steps of recovering!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by AreMoh</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65115</link>
		<dc:creator>AreMoh</dc:creator>
		<pubDate>Mon, 07 Sep 2009 19:14:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65115</guid>
		<description>O! people, Is there any recovery methode or software for dulla infected MicroSoft Office files?</description>
		<content:encoded><![CDATA[<p>O! people, Is there any recovery methode or software for dulla infected MicroSoft Office files?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Rob Cullum</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65060</link>
		<dc:creator>Rob Cullum</dc:creator>
		<pubDate>Sun, 23 Aug 2009 13:30:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65060</guid>
		<description>Hi there, my desktop has been infected with this virus and it is creating havoc . Casn&#039;t even get online (I&#039;m on my laptop atm!) 
Please help!
Kind regards
Rob</description>
		<content:encoded><![CDATA[<p>Hi there, my desktop has been infected with this virus and it is creating havoc . Casn&#8217;t even get online (I&#8217;m on my laptop atm!)<br />
Please help!<br />
Kind regards<br />
Rob</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by The Tech Guy Tom</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comment-65051</link>
		<dc:creator>The Tech Guy Tom</dc:creator>
		<pubDate>Fri, 21 Aug 2009 23:54:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65051</guid>
		<description>I&#039;ve removed this virus successfully without formatting.  Email me thetechguytom@gmail.com for details, it&#039;s a long hairy process but can be done.  We had an outbreak within our internal network at my support office where a win2k3 server w/exchange and AD, tech machine, all computers that were on the bench etc. were infected by thumbdrives plugged in to machines when the virus first struck.  Apparently it&#039;s really really easy to spread it.  Hit me up and I&#039;ll paste my epic essay.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve removed this virus successfully without formatting.  Email me <a href="mailto:thetechguytom@gmail.com">thetechguytom@gmail.com</a> for details, it&#8217;s a long hairy process but can be done.  We had an outbreak within our internal network at my support office where a win2k3 server w/exchange and AD, tech machine, all computers that were on the bench etc. were infected by thumbdrives plugged in to machines when the virus first struck.  Apparently it&#8217;s really really easy to spread it.  Hit me up and I&#8217;ll paste my epic essay.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by aman</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comment-65049</link>
		<dc:creator>aman</dc:creator>
		<pubDate>Fri, 21 Aug 2009 11:15:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65049</guid>
		<description>anti dulla is the stupidest anti virus i ever see it only uncheck the service file from &quot;msconfig&quot; it has no auto detect options 
the virus some time even attack the anti dulla excutable files
the anti virus should have auto detect options 
how   ever i wrote the code for dulla.  u had enough destroying our files please give us the solution.</description>
		<content:encoded><![CDATA[<p>anti dulla is the stupidest anti virus i ever see it only uncheck the service file from &#8220;msconfig&#8221; it has no auto detect options<br />
the virus some time even attack the anti dulla excutable files<br />
the anti virus should have auto detect options<br />
how   ever i wrote the code for dulla.  u had enough destroying our files please give us the solution.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

