<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments for Threat Center - Spyware and Virus Removal</title>
	<atom:link href="http://www.precisesecurity.com/blogs/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.precisesecurity.com/blogs</link>
	<description></description>
	<pubDate>Fri, 20 Nov 2009 22:23:50 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on W32/Vora.worm!p2p by melaku</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/w32vorawormp2p/#comment-65304</link>
		<dc:creator>melaku</dc:creator>
		<pubDate>Fri, 20 Nov 2009 06:45:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/w32vorawormp2p/#comment-65304</guid>
		<description>my computer is infected by ravo_2005 ,what should I do?</description>
		<content:encoded><![CDATA[<p>my computer is infected by ravo_2005 ,what should I do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by Yitayew Birhanu</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65303</link>
		<dc:creator>Yitayew Birhanu</dc:creator>
		<pubDate>Fri, 20 Nov 2009 06:01:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65303</guid>
		<description>Infacted by RAVO</description>
		<content:encoded><![CDATA[<p>Infacted by RAVO</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by ketlareng gale</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65302</link>
		<dc:creator>ketlareng gale</dc:creator>
		<pubDate>Wed, 18 Nov 2009 11:46:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65302</guid>
		<description>people like playing around with my pc, so i want the virus (fullhouse drive)</description>
		<content:encoded><![CDATA[<p>people like playing around with my pc, so i want the virus (fullhouse drive)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by soulless</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65299</link>
		<dc:creator>soulless</dc:creator>
		<pubDate>Tue, 17 Nov 2009 11:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65299</guid>
		<description>ive found that using hirens 10 both in windows and minixp and using the following apps - Kasperky, Malwarebyte, Superantipyware and smitfraudfx manages to get rid of the virus and then just going through the harddrive like c:, temp dirs, Windows, System32, Fonts, system volume information, recycler, Documents and Settings folders and deleting the weired files i find there such as Restorer_32a.exe and Reader_s.exe (Found a new one recently photo_id.exe) and also scanning the reg for them and removing them. This seems to be able to get rid of the virus but ive found a few times there are still bits and peices of it flying around so a few more scans and checking the folders and reg again pretty much cleared it up but Kaspersky can disinect the files but you will proably have to do a repair on you windows again. 

In one of the earlier posts someone mentioned that he used a irc prog to connect to his computer and managed to ulter the options of the virus. Im curious to know if this is true.</description>
		<content:encoded><![CDATA[<p>ive found that using hirens 10 both in windows and minixp and using the following apps - Kasperky, Malwarebyte, Superantipyware and smitfraudfx manages to get rid of the virus and then just going through the harddrive like c:, temp dirs, Windows, System32, Fonts, system volume information, recycler, Documents and Settings folders and deleting the weired files i find there such as Restorer_32a.exe and Reader_s.exe (Found a new one recently photo_id.exe) and also scanning the reg for them and removing them. This seems to be able to get rid of the virus but ive found a few times there are still bits and peices of it flying around so a few more scans and checking the folders and reg again pretty much cleared it up but Kaspersky can disinect the files but you will proably have to do a repair on you windows again. </p>
<p>In one of the earlier posts someone mentioned that he used a irc prog to connect to his computer and managed to ulter the options of the virus. Im curious to know if this is true.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TR/Crypt.XPACK.Gen by aleksi</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/17/tr-crypt-xpack-gen/#comment-65298</link>
		<dc:creator>aleksi</dc:creator>
		<pubDate>Tue, 17 Nov 2009 07:09:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2568#comment-65298</guid>
		<description>I have similar problems with trojan Crypt.XPACK.Gen
I have tried Avira, Malwarebytes and Avast, all of which have not removed the virus. It is in my temp folder and every time I delete it, it pops up under a different file name. Please help.</description>
		<content:encoded><![CDATA[<p>I have similar problems with trojan Crypt.XPACK.Gen<br />
I have tried Avira, Malwarebytes and Avast, all of which have not removed the virus. It is in my temp folder and every time I delete it, it pops up under a different file name. Please help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Internet Antivirus Pro by Naomi McMillan</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/10/internet-antivirus-pro/#comment-65295</link>
		<dc:creator>Naomi McMillan</dc:creator>
		<pubDate>Sun, 15 Nov 2009 19:27:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/10/internet-antivirus-pro/#comment-65295</guid>
		<description>I also purchased a 3 year subscription to antivirus pro. How do you get in touch with these people.  I paid 89.00 for 3 years.  There should be a way to get refunded for this.  Where are these people.  On their website it only tell you how to uninstall it.  I want my money back.</description>
		<content:encoded><![CDATA[<p>I also purchased a 3 year subscription to antivirus pro. How do you get in touch with these people.  I paid 89.00 for 3 years.  There should be a way to get refunded for this.  Where are these people.  On their website it only tell you how to uninstall it.  I want my money back.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security Tool Virus and Internet Search Redirection by John</title>
		<link>http://www.precisesecurity.com/blogs/2009/10/10/security-tool-virus-internet-search-redirection/#comment-65293</link>
		<dc:creator>John</dc:creator>
		<pubDate>Sat, 14 Nov 2009 13:13:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4348#comment-65293</guid>
		<description>I picked up this nasty virus and this is how I got rid of it. I downloaded MalwareBytes Anti-Malware to a thumb drive from another PC and renamed it "baby pictures", then I downloaded it to my infected PC. It installed and scanned and removed the Security Tool virus. I had other ways to get rid of this virus but it blocked all attempts. This method worked for me.</description>
		<content:encoded><![CDATA[<p>I picked up this nasty virus and this is how I got rid of it. I downloaded MalwareBytes Anti-Malware to a thumb drive from another PC and renamed it &#8220;baby pictures&#8221;, then I downloaded it to my infected PC. It installed and scanned and removed the Security Tool virus. I had other ways to get rid of this virus but it blocked all attempts. This method worked for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2009 by I Need Help!</title>
		<link>http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/#comment-65292</link>
		<dc:creator>I Need Help!</dc:creator>
		<pubDate>Thu, 12 Nov 2009 19:27:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/#comment-65292</guid>
		<description>I got duped into buying this Antivirus BS and the numbers given in previous statements aren't doing anything. 1-800-467-1077 is disconnected I'm guessing b/c it's telling me "The service you requested is unavailable from your calling area, SDN98" What is that supposed to mean I thought 800 #s where good to call from anywhere. I don't know about the 1-866-905-5126 they're telling me that my Card number isn't on file. Now that right there is some Bull. I guess I just got scam for my $49.95. I hope somebody catches these punks and take them to court. This is crazy. Some how they pop up on your computer and make you feel like you better buy the product or else your computer will have all kinds of viruses and whatnot. They even kept kicking me off of my home screen. I need a real number with the actual SCAM ARTIST who took my money and on top of things now I'm in the "Dog House" with my girl. Can I get a break??? If anybody can help it would be greatly appreciated. Thanks...</description>
		<content:encoded><![CDATA[<p>I got duped into buying this Antivirus BS and the numbers given in previous statements aren&#8217;t doing anything. 1-800-467-1077 is disconnected I&#8217;m guessing b/c it&#8217;s telling me &#8220;The service you requested is unavailable from your calling area, SDN98&#8243; What is that supposed to mean I thought 800 #s where good to call from anywhere. I don&#8217;t know about the 1-866-905-5126 they&#8217;re telling me that my Card number isn&#8217;t on file. Now that right there is some Bull. I guess I just got scam for my $49.95. I hope somebody catches these punks and take them to court. This is crazy. Some how they pop up on your computer and make you feel like you better buy the product or else your computer will have all kinds of viruses and whatnot. They even kept kicking me off of my home screen. I need a real number with the actual SCAM ARTIST who took my money and on top of things now I&#8217;m in the &#8220;Dog House&#8221; with my girl. Can I get a break??? If anybody can help it would be greatly appreciated. Thanks&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Vbs:malware-gen by FoxconN^^</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/vbsmailware-gen/#comment-65291</link>
		<dc:creator>FoxconN^^</dc:creator>
		<pubDate>Wed, 11 Nov 2009 18:29:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/vbsmailware-gen/#comment-65291</guid>
		<description>you can delete this file with free Avira Antivirus</description>
		<content:encoded><![CDATA[<p>you can delete this file with free Avira Antivirus</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by JB</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65290</link>
		<dc:creator>JB</dc:creator>
		<pubDate>Tue, 10 Nov 2009 18:20:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65290</guid>
		<description>Follow-up to #91

A little later it was obvious the infection was still there.  It seemed clean for a little while but then pop-ups again even without using any software manually invoked.

Malwarebytes found more and removed.  But this did not permanently remove the problem.

Installed PREVX 3.0 which found three more and with the paid version removed them.  There is a coupon available for a 10% discount.

I am not convinced all is gone.  I've had two weird occurrences still: 1) signed on and no sign of PREVX running (but should) and also no sign within IE 7 of it running, so I logged off.  Then, 2) my passwords to accounts did not work.

So I rebooted my PC and then my passwords worked and PREVX is there on logging in and in IE 7.

I guess this is a chapter book.</description>
		<content:encoded><![CDATA[<p>Follow-up to #91</p>
<p>A little later it was obvious the infection was still there.  It seemed clean for a little while but then pop-ups again even without using any software manually invoked.</p>
<p>Malwarebytes found more and removed.  But this did not permanently remove the problem.</p>
<p>Installed PREVX 3.0 which found three more and with the paid version removed them.  There is a coupon available for a 10% discount.</p>
<p>I am not convinced all is gone.  I&#8217;ve had two weird occurrences still: 1) signed on and no sign of PREVX running (but should) and also no sign within IE 7 of it running, so I logged off.  Then, 2) my passwords to accounts did not work.</p>
<p>So I rebooted my PC and then my passwords worked and PREVX is there on logging in and in IE 7.</p>
<p>I guess this is a chapter book.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by overkill</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65288</link>
		<dc:creator>overkill</dc:creator>
		<pubDate>Tue, 10 Nov 2009 14:54:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65288</guid>
		<description>Here's a question for you tech-savvy guys:

What exactly is the danger of the port (65520) that this thing uses ? Assuming you are able to clear the infection from your system (disk &amp; memory), then is there any chance that it can re-enter ? I am assuming not.</description>
		<content:encoded><![CDATA[<p>Here&#8217;s a question for you tech-savvy guys:</p>
<p>What exactly is the danger of the port (65520) that this thing uses ? Assuming you are able to clear the infection from your system (disk &amp; memory), then is there any chance that it can re-enter ? I am assuming not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on W32/Pahati.worm by Rauf</title>
		<link>http://www.precisesecurity.com/blogs/2007/08/20/w32pahatiworm/#comment-65287</link>
		<dc:creator>Rauf</dc:creator>
		<pubDate>Tue, 10 Nov 2009 04:07:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/08/20/w32pahatiworm/#comment-65287</guid>
		<description>Hi
Iam facing problem with virus in my office 150 computers are there.every computer having lot off diffrent typrs of virus
1.word file automaticaly created in computers &amp; pen drive also if i delet again its coming.even i formated.
2.Patah hati.doc this also not going to delet even i format pen drive also.
3.Internet explore auto maticaly disconuted.</description>
		<content:encoded><![CDATA[<p>Hi<br />
Iam facing problem with virus in my office 150 computers are there.every computer having lot off diffrent typrs of virus<br />
1.word file automaticaly created in computers &amp; pen drive also if i delet again its coming.even i formated.<br />
2.Patah hati.doc this also not going to delet even i format pen drive also.<br />
3.Internet explore auto maticaly disconuted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Rebecca</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65286</link>
		<dc:creator>Rebecca</dc:creator>
		<pubDate>Mon, 09 Nov 2009 22:48:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65286</guid>
		<description>I followed the instructions the webmaster gave above follow it... If it's not working it might be because you might not be on the administrator user thingy of the computer!!!! I tried that and worked for me now my computer works!!!</description>
		<content:encoded><![CDATA[<p>I followed the instructions the webmaster gave above follow it&#8230; If it&#8217;s not working it might be because you might not be on the administrator user thingy of the computer!!!! I tried that and worked for me now my computer works!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by JB</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65285</link>
		<dc:creator>JB</dc:creator>
		<pubDate>Mon, 09 Nov 2009 17:09:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65285</guid>
		<description>I followed the steps in #31 and the initial post by webmaster and it appears Cryptor is gone.

Prior to this AVG had found and quarantined win32/Cryptor in an "\temp\Installer.exe".  But when I would sign onto the one account that seems infected pop-ups would occur again and re-infection would occur.  This happens shortly after login without any program being manually started.  Only the one account seems infected, not others, the one being a non-administrative account.  However, I was not able to write to a DVD.

During this AVG found nothing more, MBam found four executables in "\temp" and removed them, and SuperAntiSpyware reported nothing more than tracking files (e.g. cookies).

I have a remaining concern that I don't see what actually removed the cause of re-infection.  There was no report of removing a rootkit or anything else except the four executables in "\temp" and the various tracking files.

What actually removed the re-infection source?</description>
		<content:encoded><![CDATA[<p>I followed the steps in #31 and the initial post by webmaster and it appears Cryptor is gone.</p>
<p>Prior to this AVG had found and quarantined win32/Cryptor in an &#8220;\temp\Installer.exe&#8221;.  But when I would sign onto the one account that seems infected pop-ups would occur again and re-infection would occur.  This happens shortly after login without any program being manually started.  Only the one account seems infected, not others, the one being a non-administrative account.  However, I was not able to write to a DVD.</p>
<p>During this AVG found nothing more, MBam found four executables in &#8220;\temp&#8221; and removed them, and SuperAntiSpyware reported nothing more than tracking files (e.g. cookies).</p>
<p>I have a remaining concern that I don&#8217;t see what actually removed the cause of re-infection.  There was no report of removing a rootkit or anything else except the four executables in &#8220;\temp&#8221; and the various tracking files.</p>
<p>What actually removed the re-infection source?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on W32/YahLover.worm.gen by Ravi Srivastava</title>
		<link>http://www.precisesecurity.com/blogs/2007/09/29/w32yahloverwormgen/#comment-65284</link>
		<dc:creator>Ravi Srivastava</dc:creator>
		<pubDate>Mon, 09 Nov 2009 05:27:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/09/29/w32yahloverwormgen/#comment-65284</guid>
		<description>I am unable to see my hidden files. I tried to unhide the files from tools menu but it is not working. Please send me the solution for this problem.</description>
		<content:encoded><![CDATA[<p>I am unable to see my hidden files. I tried to unhide the files from tools menu but it is not working. Please send me the solution for this problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Sheur2.gnw by Mark</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2-gnw/#comment-65283</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Mon, 09 Nov 2009 04:35:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2gnw/#comment-65283</guid>
		<description>I'm currently working on removing the SHeur2.
took the harddrive out and scanned it on another computer.
finding many infected files.
since I'm not using that hddrives os, I should be able to clean it up.
I'll post my results when I'm finished</description>
		<content:encoded><![CDATA[<p>I&#8217;m currently working on removing the SHeur2.<br />
took the harddrive out and scanned it on another computer.<br />
finding many infected files.<br />
since I&#8217;m not using that hddrives os, I should be able to clean it up.<br />
I&#8217;ll post my results when I&#8217;m finished</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2009 by MslyHrmLess</title>
		<link>http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/#comment-65280</link>
		<dc:creator>MslyHrmLess</dc:creator>
		<pubDate>Sun, 08 Nov 2009 18:56:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/#comment-65280</guid>
		<description>The Losers the Created these Programs live in Brampton, Ontario. Canada, I will Be back With a more precise location and possibly a home address and phone #</description>
		<content:encoded><![CDATA[<p>The Losers the Created these Programs live in Brampton, Ontario. Canada, I will Be back With a more precise location and possibly a home address and phone #</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Zlob.Porn.Ad Adware by Xajeqebk</title>
		<link>http://www.precisesecurity.com/blogs/2008/07/03/zlobpornad-adware/#comment-65279</link>
		<dc:creator>Xajeqebk</dc:creator>
		<pubDate>Sun, 08 Nov 2009 18:50:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/07/03/zlobpornad-adware/#comment-65279</guid>
		<description>comment6</description>
		<content:encoded><![CDATA[<p>comment6</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Arsby</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65278</link>
		<dc:creator>Arsby</dc:creator>
		<pubDate>Sun, 08 Nov 2009 17:13:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65278</guid>
		<description>I had a happy ending, I think.
I got this bug on my Vista laptop on Friday by being stupid.  Kaspersky slows down my downloads, so I turned it off.  I forgot it was off and tried to install an app from the newsgroups.  The first thing Virute did was set my system clock forward to 2049, so Kaspersky thought it had expired 40 years ago!  Then it started eating my executables.
I took the laptop HD out and put it in a SATA USB enclosure attached to a Kaspersky-protected desktop.  I started moving all the files I wanted to save onto the desktop, and ran Kaspersky against the HD in enclosure.  I initially thought I fixed it with Kaspersky and moved it back, but it was still infected.  I then adjusted the Kaspersky setting to Maximum Protection and pointed it explicitly to the USB drive.  It found and deleted a trojan and 216 files (mostly exe's) that were infected.
This morning, Sunday, I put the HD back into the laptop and turned it on, fully expecting to have to recover and wipe the HD.  Signon went well, but it couldn't find two dll's.  Kaspersky was still working on the laptop, and found nothing during its startup procedure.   The internet is working, I'm posting from the laptop now.  Some applications aren't working because the executables are gone, but others, including MS Office, are.     
So it looks like a happy ending.   
So for the previous poster and others...  IF it's a laptop that's infected, it's really easy to pop out a laptop hard drive, then go to Best Buy or something like it and buy a USB enclosure for it.  (Warning, there are two types, SATA and another one.)   Attach it to another PC that's virus protected, and have it run a full maximum check against the drive that's now via USB.  Have it delete anything that's infected.  (Kaspersky does the deletions *after* it finished the full scan.)  Then put it back into the laptop and see if it works.</description>
		<content:encoded><![CDATA[<p>I had a happy ending, I think.<br />
I got this bug on my Vista laptop on Friday by being stupid.  Kaspersky slows down my downloads, so I turned it off.  I forgot it was off and tried to install an app from the newsgroups.  The first thing Virute did was set my system clock forward to 2049, so Kaspersky thought it had expired 40 years ago!  Then it started eating my executables.<br />
I took the laptop HD out and put it in a SATA USB enclosure attached to a Kaspersky-protected desktop.  I started moving all the files I wanted to save onto the desktop, and ran Kaspersky against the HD in enclosure.  I initially thought I fixed it with Kaspersky and moved it back, but it was still infected.  I then adjusted the Kaspersky setting to Maximum Protection and pointed it explicitly to the USB drive.  It found and deleted a trojan and 216 files (mostly exe&#8217;s) that were infected.<br />
This morning, Sunday, I put the HD back into the laptop and turned it on, fully expecting to have to recover and wipe the HD.  Signon went well, but it couldn&#8217;t find two dll&#8217;s.  Kaspersky was still working on the laptop, and found nothing during its startup procedure.   The internet is working, I&#8217;m posting from the laptop now.  Some applications aren&#8217;t working because the executables are gone, but others, including MS Office, are.<br />
So it looks like a happy ending.<br />
So for the previous poster and others&#8230;  IF it&#8217;s a laptop that&#8217;s infected, it&#8217;s really easy to pop out a laptop hard drive, then go to Best Buy or something like it and buy a USB enclosure for it.  (Warning, there are two types, SATA and another one.)   Attach it to another PC that&#8217;s virus protected, and have it run a full maximum check against the drive that&#8217;s now via USB.  Have it delete anything that&#8217;s infected.  (Kaspersky does the deletions *after* it finished the full scan.)  Then put it back into the laptop and see if it works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Cathy</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65276</link>
		<dc:creator>Cathy</dc:creator>
		<pubDate>Sun, 08 Nov 2009 15:25:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65276</guid>
		<description>Sorry last post should read could NOT remove all infected items. ???</description>
		<content:encoded><![CDATA[<p>Sorry last post should read could NOT remove all infected items. ???</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Cathy</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65274</link>
		<dc:creator>Cathy</dc:creator>
		<pubDate>Sun, 08 Nov 2009 15:20:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65274</guid>
		<description>Hi- please help. 
Did step 6 in safe mode, but could remove all infected items. I'm no further forward. Any ideas?</description>
		<content:encoded><![CDATA[<p>Hi- please help.<br />
Did step 6 in safe mode, but could remove all infected items. I&#8217;m no further forward. Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Simon</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65271</link>
		<dc:creator>Simon</dc:creator>
		<pubDate>Fri, 06 Nov 2009 00:54:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65271</guid>
		<description>Ok all you guys,

I couldn't access anything on my computer as it closed automatically (including Task manager, all programs and stuff) except the internet. So I downloaded the software Malwarebytes’ Anti-Malware (mbam-setup.exe)  and restarted my computer in Safe MODE.  Then I searched (while in safe mode) using start - search: "mbam-setup.exe" and installed the software.</description>
		<content:encoded><![CDATA[<p>Ok all you guys,</p>
<p>I couldn&#8217;t access anything on my computer as it closed automatically (including Task manager, all programs and stuff) except the internet. So I downloaded the software Malwarebytes’ Anti-Malware (mbam-setup.exe)  and restarted my computer in Safe MODE.  Then I searched (while in safe mode) using start - search: &#8220;mbam-setup.exe&#8221; and installed the software.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Anti-Virus Number-1 by Judy Kauffmann</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/17/anti-virus-number-1/#comment-65269</link>
		<dc:creator>Judy Kauffmann</dc:creator>
		<pubDate>Wed, 04 Nov 2009 14:54:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3092#comment-65269</guid>
		<description>Hi,
I really need a number to reach you or something. I
am trying to remove you app. for virus proctection 
and I can't get it to remove and I already have protection and I am happy with it. I can't get on
in site now. Please help me get it off.
                   Thanks~!</description>
		<content:encoded><![CDATA[<p>Hi,<br />
I really need a number to reach you or something. I<br />
am trying to remove you app. for virus proctection<br />
and I can&#8217;t get it to remove and I already have protection and I am happy with it. I can&#8217;t get on<br />
in site now. Please help me get it off.<br />
                   Thanks~!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by ASHEBIR LEMMA</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65268</link>
		<dc:creator>ASHEBIR LEMMA</dc:creator>
		<pubDate>Wed, 04 Nov 2009 11:34:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65268</guid>
		<description>My computer has infested by the doomsday ravo_5002.
Pls how can i delete/scan it? please i need your help thanx
my E.mail is   ashitiok@yahoo.com</description>
		<content:encoded><![CDATA[<p>My computer has infested by the doomsday ravo_5002.<br />
Pls how can i delete/scan it? please i need your help thanx<br />
my E.mail is   <a href="mailto:ashitiok@yahoo.com">ashitiok@yahoo.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rootkit.TDSS by tdlwsp.dll &#124; Spyware-Virus Files and Process</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/04/rootkit_tdss/#comment-65267</link>
		<dc:creator>tdlwsp.dll &#124; Spyware-Virus Files and Process</dc:creator>
		<pubDate>Wed, 04 Nov 2009 08:32:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3571#comment-65267</guid>
		<description>[...] Related to: Rootkit.TDSS [...]</description>
		<content:encoded><![CDATA[<p>[...] Related to: Rootkit.TDSS [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Warning! Fatal Error: All media systems on your computer have been crashed! by Daniela</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/05/warning-fatal-error/#comment-65266</link>
		<dc:creator>Daniela</dc:creator>
		<pubDate>Tue, 03 Nov 2009 19:59:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2882#comment-65266</guid>
		<description>I have the same problem with the Warning Fatal Error!!! Wallpaper.  I have Trend Micro Antivirus and didn’t find any infections.  I really don’t know how this wallpaper got into my computer and it was not detected by my antivirus.  I research how to get rid of that problem.  I find a lot of spyware but you have to pay in order to delete the files on your computer.  So I find this page and downloaded the Spyware Doctor and I was really tired with this problem because now my screen looks like and old computer screen.  The colors and images look like you have like dialup internet with poor signal which make them look bad.  I have speed internet with usually all my color and images were great.  So I register and pay for the Spyware Doctor to delete this problem and scan my computer.  It did find 9 threats and a lot of infections so I delete them.  But at the end nothing happened.  I still have the same wallpaper fatal error.  Please help me!!!!  I am tired of this problem.</description>
		<content:encoded><![CDATA[<p>I have the same problem with the Warning Fatal Error!!! Wallpaper.  I have Trend Micro Antivirus and didn’t find any infections.  I really don’t know how this wallpaper got into my computer and it was not detected by my antivirus.  I research how to get rid of that problem.  I find a lot of spyware but you have to pay in order to delete the files on your computer.  So I find this page and downloaded the Spyware Doctor and I was really tired with this problem because now my screen looks like and old computer screen.  The colors and images look like you have like dialup internet with poor signal which make them look bad.  I have speed internet with usually all my color and images were great.  So I register and pay for the Spyware Doctor to delete this problem and scan my computer.  It did find 9 threats and a lot of infections so I delete them.  But at the end nothing happened.  I still have the same wallpaper fatal error.  Please help me!!!!  I am tired of this problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by DonkeyDolck</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65264</link>
		<dc:creator>DonkeyDolck</dc:creator>
		<pubDate>Tue, 03 Nov 2009 00:10:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65264</guid>
		<description>Hey.. I got these virus yeasterday (win32/virut and win32/heur) When i read about it that it infected all the .exe and possibly .jpg files i went nuts, turned of my computer unplugged my other 2 drives (D: and E:)on it and installed windows 7 64bit today. Downloaded avg free 9.0 and searched D: and it had 5 infected .exe files. wich it said that it was removed. So it hadn't have the time to spread that far. Now i wonder if it still might spread into my C: where i have my windows or if it will continue to spread through my D: and E: (havn't plugged E: in yet, so i don't know how badly infected it is.) Or shall i just leave them unplugged until a bulletproof removal program for those viruses are released? Really don't wanna mess up all my pictures and stuff there if it's possible to avoid.. damn.. pics on there since 2002. :/ What to do? Any help would be mostly appreciated</description>
		<content:encoded><![CDATA[<p>Hey.. I got these virus yeasterday (win32/virut and win32/heur) When i read about it that it infected all the .exe and possibly .jpg files i went nuts, turned of my computer unplugged my other 2 drives (D: and E:)on it and installed windows 7 64bit today. Downloaded avg free 9.0 and searched D: and it had 5 infected .exe files. wich it said that it was removed. So it hadn&#8217;t have the time to spread that far. Now i wonder if it still might spread into my C: where i have my windows or if it will continue to spread through my D: and E: (havn&#8217;t plugged E: in yet, so i don&#8217;t know how badly infected it is.) Or shall i just leave them unplugged until a bulletproof removal program for those viruses are released? Really don&#8217;t wanna mess up all my pictures and stuff there if it&#8217;s possible to avoid.. damn.. pics on there since 2002. :/ What to do? Any help would be mostly appreciated</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Szabolcs</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65261</link>
		<dc:creator>Szabolcs</dc:creator>
		<pubDate>Sat, 31 Oct 2009 11:11:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65261</guid>
		<description>Confirmed. I agree with the first poster (and the most of you),  it sneaked through avast's protection, I fought this about a week long, that process let me figure out some important stuff.

This malware is probably added by Win32.Agent along with Win32.Delf and b.exe, just to mention the most critical ones and some others (3-4 more)

 - It hides on your portable devices such as pendrives portable hard disk or other partitions.
 - When you connect to the internet, this will download the whole pack again, causing you more trouble.
 - These malware only works on 32-bit based Windows systems. You should consider updating to 64-bit (there are some drawback) or try Windows 7.
 - Only Win32.Virut will infect files, others should create their own, which you can find in "C:\" and "C:\Windows\system32" or in "Documents and Settings"

Note: A new version has come out in October 2009 and even Kaspersky Labs do not have an update for this infection yet. Although, Kaspersky is able to competely eradicate this virus, thanks to it's more advanced and intelligent being, compered to other virusbusters.

Conclusion: I am now using Windows 7 x64, works quite well that far.</description>
		<content:encoded><![CDATA[<p>Confirmed. I agree with the first poster (and the most of you),  it sneaked through avast&#8217;s protection, I fought this about a week long, that process let me figure out some important stuff.</p>
<p>This malware is probably added by Win32.Agent along with Win32.Delf and b.exe, just to mention the most critical ones and some others (3-4 more)</p>
<p> - It hides on your portable devices such as pendrives portable hard disk or other partitions.<br />
 - When you connect to the internet, this will download the whole pack again, causing you more trouble.<br />
 - These malware only works on 32-bit based Windows systems. You should consider updating to 64-bit (there are some drawback) or try Windows 7.<br />
 - Only Win32.Virut will infect files, others should create their own, which you can find in &#8220;C:\&#8221; and &#8220;C:\Windows\system32&#8243; or in &#8220;Documents and Settings&#8221;</p>
<p>Note: A new version has come out in October 2009 and even Kaspersky Labs do not have an update for this infection yet. Although, Kaspersky is able to competely eradicate this virus, thanks to it&#8217;s more advanced and intelligent being, compered to other virusbusters.</p>
<p>Conclusion: I am now using Windows 7 x64, works quite well that far.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by ephrem</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65257</link>
		<dc:creator>ephrem</dc:creator>
		<pubDate>Thu, 29 Oct 2009 15:55:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65257</guid>
		<description>This is really bad fortune for Ethiopians that hears Dulla virus has been created by Ethiopian distractive guy or Association. You know creating very_low_risk and very ordinary system virus like Dulla is not a work of proud. Most educated Ethiopians suspect strongly who has created this gadium virus. In my belief the current stated antivirus for Dulla-Tsere Dulla creator has created the virus itself before. Because the name of a virus it self is Amharic word, besides the solution itself has found from Ethiopia by the association they called INSA. Don’t forget also most commercial antivirus producers ignore or don’t care about to get a solution for this virus. And do not forget Dulla virus is a kind of very easy and low risk ordinary virus that even a younger student of computer science student with out experience can create this kind of macro type of virus. If I were a creator of this virus, I would rather participate to create a kind problem solving projects for this poor country. Shame on this virus creator. Let me tell him what is he done is reflect he is ordinary, very easy and useless bastard gay. By the way I am not giving this opinion just being hot or affected by the virus. And let me tell him that even I can create such virus. But I wouldn’t be interested to be criminal. I am sorry to use irrational words.</description>
		<content:encoded><![CDATA[<p>This is really bad fortune for Ethiopians that hears Dulla virus has been created by Ethiopian distractive guy or Association. You know creating very_low_risk and very ordinary system virus like Dulla is not a work of proud. Most educated Ethiopians suspect strongly who has created this gadium virus. In my belief the current stated antivirus for Dulla-Tsere Dulla creator has created the virus itself before. Because the name of a virus it self is Amharic word, besides the solution itself has found from Ethiopia by the association they called INSA. Don’t forget also most commercial antivirus producers ignore or don’t care about to get a solution for this virus. And do not forget Dulla virus is a kind of very easy and low risk ordinary virus that even a younger student of computer science student with out experience can create this kind of macro type of virus. If I were a creator of this virus, I would rather participate to create a kind problem solving projects for this poor country. Shame on this virus creator. Let me tell him what is he done is reflect he is ordinary, very easy and useless bastard gay. By the way I am not giving this opinion just being hot or affected by the virus. And let me tell him that even I can create such virus. But I wouldn’t be interested to be criminal. I am sorry to use irrational words.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by tadesse</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65256</link>
		<dc:creator>tadesse</dc:creator>
		<pubDate>Thu, 29 Oct 2009 09:33:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65256</guid>
		<description>Please send Tsere dulla Antivrus. My documents are at riskThe file already corrupted, so how can i recover the excel files?+</description>
		<content:encoded><![CDATA[<p>Please send Tsere dulla Antivrus. My documents are at riskThe file already corrupted, so how can i recover the excel files?+</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Alekaw</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65254</link>
		<dc:creator>Alekaw</dc:creator>
		<pubDate>Tue, 27 Oct 2009 15:16:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65254</guid>
		<description>I appreciate  Dull Virus creator man really !! For future I will expect more that used for our country 'Ethiopia' and pass to Next Generation !!</description>
		<content:encoded><![CDATA[<p>I appreciate  Dull Virus creator man really !! For future I will expect more that used for our country &#8216;Ethiopia&#8217; and pass to Next Generation !!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security Tool Virus and Internet Search Redirection by bev</title>
		<link>http://www.precisesecurity.com/blogs/2009/10/10/security-tool-virus-internet-search-redirection/#comment-65253</link>
		<dc:creator>bev</dc:creator>
		<pubDate>Sun, 25 Oct 2009 21:13:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4348#comment-65253</guid>
		<description>I have had for a few days now the Security Tool Malware virus on my computer with nothing able to remove it. I have had a lot of help from others, and tried doing everything not only manually but automatically. Nothing is working at all for me. Every little pop up from any kind of software on the computer terminates immediately. I tried downloading a few different things people told me to, but it just won't let me retrieve the files, let alone open anything. RUN doesn't work, nor task manager isn't allowed to pop up without terminating automatically. I have tried safe mode, but when I got to it and click on it, I am brought to a blank blue screen and nothing happens for minutes on end, and at one point a half an hour, nothing changed, nor did it start any further than the blue screen.
What do I do now?</description>
		<content:encoded><![CDATA[<p>I have had for a few days now the Security Tool Malware virus on my computer with nothing able to remove it. I have had a lot of help from others, and tried doing everything not only manually but automatically. Nothing is working at all for me. Every little pop up from any kind of software on the computer terminates immediately. I tried downloading a few different things people told me to, but it just won&#8217;t let me retrieve the files, let alone open anything. RUN doesn&#8217;t work, nor task manager isn&#8217;t allowed to pop up without terminating automatically. I have tried safe mode, but when I got to it and click on it, I am brought to a blank blue screen and nothing happens for minutes on end, and at one point a half an hour, nothing changed, nor did it start any further than the blue screen.<br />
What do I do now?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Ian Mac</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65252</link>
		<dc:creator>Ian Mac</dc:creator>
		<pubDate>Sun, 25 Oct 2009 13:06:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65252</guid>
		<description>When you get the choice to save or run the download, click save. You will then get the 'save as' prompt. It's at this point that you can change the name.

System restore won't delete any of your saved files.</description>
		<content:encoded><![CDATA[<p>When you get the choice to save or run the download, click save. You will then get the &#8217;save as&#8217; prompt. It&#8217;s at this point that you can change the name.</p>
<p>System restore won&#8217;t delete any of your saved files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on System Guard 2009 by lilkunta</title>
		<link>http://www.precisesecurity.com/blogs/2009/01/26/system-guard-2009/#comment-65251</link>
		<dc:creator>lilkunta</dc:creator>
		<pubDate>Sun, 25 Oct 2009 00:51:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/01/26/system-guard-2009/#comment-65251</guid>
		<description>I have been infected by this virus. I am on a toshiba L25 with windows xp SP2. I am logged in as the admin. The virus has disabled the internet (ethernet &amp; wifi) and the registry editor &amp; system restore, telling me to contact the admin, which I AM the admin ! The popups I keep getting are a red thing called 'security tool' and a blue screen that looks legit(but I know it is fake) called Windows Security Center. It has disabled the task manager and the registry editor and the system restore.  Both 'safe mode' &amp; 'safe mode with networking' dont work. I have to choose 'directory services restore mode (windows domain controllers only) ' in order for safe mode to load.

How do I get rid of the virus ( or is it a trojan or malware or spyware ?)  I cant get online in order to d/l an avg or norton. I cant get into the registry editor and self delte. I am stuck. Thanks.</description>
		<content:encoded><![CDATA[<p>I have been infected by this virus. I am on a toshiba L25 with windows xp SP2. I am logged in as the admin. The virus has disabled the internet (ethernet &amp; wifi) and the registry editor &amp; system restore, telling me to contact the admin, which I AM the admin ! The popups I keep getting are a red thing called &#8217;security tool&#8217; and a blue screen that looks legit(but I know it is fake) called Windows Security Center. It has disabled the task manager and the registry editor and the system restore.  Both &#8217;safe mode&#8217; &amp; &#8217;safe mode with networking&#8217; dont work. I have to choose &#8216;directory services restore mode (windows domain controllers only) &#8216; in order for safe mode to load.</p>
<p>How do I get rid of the virus ( or is it a trojan or malware or spyware ?)  I cant get online in order to d/l an avg or norton. I cant get into the registry editor and self delte. I am stuck. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pyagcore by rignator</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65248</link>
		<dc:creator>rignator</dc:creator>
		<pubDate>Fri, 23 Oct 2009 22:25:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65248</guid>
		<description>mohamed
  go to my computer&gt;local disc&gt;program files&gt;kiwee toolbar
 not gonna do mauch good though, it protects itself and can't be erased in some cases...</description>
		<content:encoded><![CDATA[<p>mohamed<br />
  go to my computer&gt;local disc&gt;program files&gt;kiwee toolbar<br />
 not gonna do mauch good though, it protects itself and can&#8217;t be erased in some cases&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on XP Antispyware 2009 by hurzwurz</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/07/xp-antispyware-2009/#comment-65247</link>
		<dc:creator>hurzwurz</dc:creator>
		<pubDate>Fri, 23 Oct 2009 08:32:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/07/xp-antispyware-2009/#comment-65247</guid>
		<description>dear exel support,

please stop all tasks that are running under your user.

remove ikowin32.exe from your autostart.

stop tasks like "9129837.exe" and strange names like that
in the end you should have no programm running!
no virus scanner, no game software nothing!°
just windows itself
than you can install Malwarebytes and run a full scan!

if I hadnt killed these taks the scareware program always restartet my computer when it recognized that a antivirus prog was running...

And Warning these Program changes its Name
to me its known as "Security Tool"</description>
		<content:encoded><![CDATA[<p>dear exel support,</p>
<p>please stop all tasks that are running under your user.</p>
<p>remove ikowin32.exe from your autostart.</p>
<p>stop tasks like &#8220;9129837.exe&#8221; and strange names like that<br />
in the end you should have no programm running!<br />
no virus scanner, no game software nothing!°<br />
just windows itself<br />
than you can install Malwarebytes and run a full scan!</p>
<p>if I hadnt killed these taks the scareware program always restartet my computer when it recognized that a antivirus prog was running&#8230;</p>
<p>And Warning these Program changes its Name<br />
to me its known as &#8220;Security Tool&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on errorofbrowser.com by No_limits31</title>
		<link>http://www.precisesecurity.com/blogs/2008/09/04/errorofbrowsercom/#comment-65245</link>
		<dc:creator>No_limits31</dc:creator>
		<pubDate>Thu, 22 Oct 2009 19:47:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/09/04/errorofbrowsercom/#comment-65245</guid>
		<description>Besides the fact that some are only there to fill the politically correct quotas but seem totally incapable of fulfilling their duties. ,</description>
		<content:encoded><![CDATA[<p>Besides the fact that some are only there to fill the politically correct quotas but seem totally incapable of fulfilling their duties. ,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Aaron</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65244</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Thu, 22 Oct 2009 18:51:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65244</guid>
		<description>OR
None of these worked for me, even option 6.  Try a slightly different way though:

I tried to go into safe mode, but it wouldn't let me, so I selected to start up in normal windows.

As it was starting up, I pushed F10, and then maneuvered from back there.  Click the tab that has the date, and change the date per option 6. Click save and continue to restart in normal mode.  Everything was fixed.</description>
		<content:encoded><![CDATA[<p>OR<br />
None of these worked for me, even option 6.  Try a slightly different way though:</p>
<p>I tried to go into safe mode, but it wouldn&#8217;t let me, so I selected to start up in normal windows.</p>
<p>As it was starting up, I pushed F10, and then maneuvered from back there.  Click the tab that has the date, and change the date per option 6. Click save and continue to restart in normal mode.  Everything was fixed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on go.google - go.yahoo by Hyoran</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects/#comment-65242</link>
		<dc:creator>Hyoran</dc:creator>
		<pubDate>Tue, 20 Oct 2009 17:41:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects/#comment-65242</guid>
		<description>I've tried everything to find the TDSSserv.sys including the scan for hardware changes and i still can't find it. Is there any other hardware you can disable that will help?

Also i seem to have problems with serial and npkcrypt. Why have they stopped working?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve tried everything to find the TDSSserv.sys including the scan for hardware changes and i still can&#8217;t find it. Is there any other hardware you can disable that will help?</p>
<p>Also i seem to have problems with serial and npkcrypt. Why have they stopped working?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Caitie</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65240</link>
		<dc:creator>Caitie</dc:creator>
		<pubDate>Mon, 19 Oct 2009 22:50:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65240</guid>
		<description>AVG picked it up but won't let me remove the virus, and my Trend Micro Anti-Virus won't pick it up at all and the virus won't let it update. 
I tired to download Anti-Malware Bytes but I can't rename the file before downloading and afterwards when I try to rename it I can't find any of the .exe files and so it won't open. 
I'm thinking maybe a System Restore would help but I would have to go back about 6 months which would really suck</description>
		<content:encoded><![CDATA[<p>AVG picked it up but won&#8217;t let me remove the virus, and my Trend Micro Anti-Virus won&#8217;t pick it up at all and the virus won&#8217;t let it update.<br />
I tired to download Anti-Malware Bytes but I can&#8217;t rename the file before downloading and afterwards when I try to rename it I can&#8217;t find any of the .exe files and so it won&#8217;t open.<br />
I&#8217;m thinking maybe a System Restore would help but I would have to go back about 6 months which would really suck</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Caitie</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65239</link>
		<dc:creator>Caitie</dc:creator>
		<pubDate>Mon, 19 Oct 2009 22:45:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65239</guid>
		<description>My AVG picked it up but won't let me get rid of it, I tried to install Anti Malware Bytes but I can't rename it before it d/ls and when I go into the folder to rename I can't find any .exe files. I'm thinking I might have to do a full system restore around 5 months back which would really suck.</description>
		<content:encoded><![CDATA[<p>My AVG picked it up but won&#8217;t let me get rid of it, I tried to install Anti Malware Bytes but I can&#8217;t rename it before it d/ls and when I go into the folder to rename I can&#8217;t find any .exe files. I&#8217;m thinking I might have to do a full system restore around 5 months back which would really suck.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by brandon</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65237</link>
		<dc:creator>brandon</dc:creator>
		<pubDate>Mon, 19 Oct 2009 13:28:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65237</guid>
		<description>yyyyaaaay everyone do post six it works and takes under 3 minutes. go under safe mode to do yayayayayay tytyty</description>
		<content:encoded><![CDATA[<p>yyyyaaaay everyone do post six it works and takes under 3 minutes. go under safe mode to do yayayayayay tytyty</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by brandon</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65236</link>
		<dc:creator>brandon</dc:creator>
		<pubDate>Mon, 19 Oct 2009 13:26:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65236</guid>
		<description>i did post six still waiting to see if it worked ;)</description>
		<content:encoded><![CDATA[<p>i did post six still waiting to see if it worked ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TR/Crypt.XPACK.Gen by Mel</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/17/tr-crypt-xpack-gen/#comment-65234</link>
		<dc:creator>Mel</dc:creator>
		<pubDate>Mon, 19 Oct 2009 07:39:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2568#comment-65234</guid>
		<description>I have tried Avira, Malwarebytes and Spybot, all of which have not removed the virus.  It is in my temp folder and every time I delete it, it pops up under a different file name.   Please help.  It's starting to drive me insane</description>
		<content:encoded><![CDATA[<p>I have tried Avira, Malwarebytes and Spybot, all of which have not removed the virus.  It is in my temp folder and every time I delete it, it pops up under a different file name.   Please help.  It&#8217;s starting to drive me insane</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan.Patchep!inf by Andy</title>
		<link>http://www.precisesecurity.com/blogs/2007/09/08/trojanpatchepinf/#comment-65233</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Mon, 19 Oct 2009 02:18:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/09/08/trojanpatchepinf/#comment-65233</guid>
		<description>I have tried this and it found the files but failed to remove them. norton did put them in quarantine.</description>
		<content:encoded><![CDATA[<p>I have tried this and it found the files but failed to remove them. norton did put them in quarantine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan-Downloader.Zlob.Media-Codec by SalesMan</title>
		<link>http://www.precisesecurity.com/blogs/2006/08/27/media-codec/#comment-65232</link>
		<dc:creator>SalesMan</dc:creator>
		<pubDate>Sun, 18 Oct 2009 23:47:05 +0000</pubDate>
		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/08/27/media-codec/#comment-65232</guid>
		<description>??????   ????  ?????? ?? ??????? 2009 
????  ????????? ?? ?????????? ????? ??????? 
????  ????????? ?? ??????? ??????? ??????? 
????  ????????? ?? ???????????? ??????? 
????  ????, 
????  ? ??????????, 
????  ? ????????, 
????  ? ???????????????? ???????????????, 
????  ?????????? ?????????, 
????  ???????? ???????????????? ?????????, 
????  ?????????? ?????; 
????  ??????? ??????, 
????  ??????? ??????????, 
????  ??????????? ??????? 
????  ??????? ??????????? ??????? 
????  09 ???????? ??????? ? ??????????? ??????? 
????  ??? ??????? 
????  ????????? ??????? ?? ????? ? ??????? 
????  ??????? ??????? 
????  ??????? ??????????????? ??????? 
????  ??????????? ??? ??????? 
????  ??????????? ??? ??????? 
????  ?????? -  ?????  - ??????? 
????  ?????? ???????????? ???????????? ??????????? ???????</description>
		<content:encoded><![CDATA[<p>??????   ????  ?????? ?? ??????? 2009<br />
????  ????????? ?? ?????????? ????? ???????<br />
????  ????????? ?? ??????? ??????? ???????<br />
????  ????????? ?? ???????????? ???????<br />
????  ????,<br />
????  ? ??????????,<br />
????  ? ????????,<br />
????  ? ???????????????? ???????????????,<br />
????  ?????????? ?????????,<br />
????  ???????? ???????????????? ?????????,<br />
????  ?????????? ?????;<br />
????  ??????? ??????,<br />
????  ??????? ??????????,<br />
????  ??????????? ???????<br />
????  ??????? ??????????? ???????<br />
????  09 ???????? ??????? ? ??????????? ???????<br />
????  ??? ???????<br />
????  ????????? ??????? ?? ????? ? ???????<br />
????  ??????? ???????<br />
????  ??????? ??????????????? ???????<br />
????  ??????????? ??? ???????<br />
????  ??????????? ??? ???????<br />
????  ?????? -  ?????  - ???????<br />
????  ?????? ???????????? ???????????? ??????????? ???????</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Biny</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65228</link>
		<dc:creator>Biny</dc:creator>
		<pubDate>Thu, 15 Oct 2009 11:12:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65228</guid>
		<description>I'm still wondering who developed dulla virus,i'll b very happy if INSA has something to say abt it.</description>
		<content:encoded><![CDATA[<p>I&#8217;m still wondering who developed dulla virus,i&#8217;ll b very happy if INSA has something to say abt it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2009 by betsy</title>
		<link>http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/#comment-65226</link>
		<dc:creator>betsy</dc:creator>
		<pubDate>Wed, 14 Oct 2009 03:45:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/#comment-65226</guid>
		<description>i downloaded the software like an idiot 2 days ago under my dads credit card. i hope they dont charge ridiculous things to it. i told him to check with his bank and freeze his account. how bad did i screw up? how bad do they charge the cards? how worried should i be?</description>
		<content:encoded><![CDATA[<p>i downloaded the software like an idiot 2 days ago under my dads credit card. i hope they dont charge ridiculous things to it. i told him to check with his bank and freeze his account. how bad did i screw up? how bad do they charge the cards? how worried should i be?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Amaha Fikru</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65225</link>
		<dc:creator>Amaha Fikru</dc:creator>
		<pubDate>Tue, 13 Oct 2009 06:40:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65225</guid>
		<description>The file already corrupted, so how can i recover the excel files?</description>
		<content:encoded><![CDATA[<p>The file already corrupted, so how can i recover the excel files?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Insecure Internet activity. Threat of virus attack! by TrustFighter : Virus Solution and Removal</title>
		<link>http://www.precisesecurity.com/blogs/2009/01/09/insecure-internet-activity-threat-of-virus-attack/#comment-65224</link>
		<dc:creator>TrustFighter : Virus Solution and Removal</dc:creator>
		<pubDate>Tue, 13 Oct 2009 02:39:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/01/09/insecure-internet-activity-threat-of-virus-attack/#comment-65224</guid>
		<description>[...] Internet browser that may block users Internet access and instead be redirected to &#8220;Insecure Internet Activity&#8221; page. It will also run its own virus scanner and alert users on loads of infected file. This [...]</description>
		<content:encoded><![CDATA[<p>[...] Internet browser that may block users Internet access and instead be redirected to &#8220;Insecure Internet Activity&#8221; page. It will also run its own virus scanner and alert users on loads of infected file. This [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Email-Worm.Win32.Myd by nadia</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/06/email-wormwin32myd/#comment-65222</link>
		<dc:creator>nadia</dc:creator>
		<pubDate>Tue, 13 Oct 2009 00:54:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/02/06/email-wormwin32myd/#comment-65222</guid>
		<description>no tengo ni idea de como eliminar virus, pero porfavor ayudenme!!! si puden me lo mandan por paso de cada tipo de virus ok =)</description>
		<content:encoded><![CDATA[<p>no tengo ni idea de como eliminar virus, pero porfavor ayudenme!!! si puden me lo mandan por paso de cada tipo de virus ok =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by rational</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65221</link>
		<dc:creator>rational</dc:creator>
		<pubDate>Mon, 12 Oct 2009 22:57:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65221</guid>
		<description>I WANT TO REMOVE FULL HLUSE VIRUS FROM MY PC. I NEEED HELP</description>
		<content:encoded><![CDATA[<p>I WANT TO REMOVE FULL HLUSE VIRUS FROM MY PC. I NEEED HELP</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by ceri</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65219</link>
		<dc:creator>ceri</dc:creator>
		<pubDate>Mon, 12 Oct 2009 13:02:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65219</guid>
		<description>I went to the microsoft site sorted it straight away</description>
		<content:encoded><![CDATA[<p>I went to the microsoft site sorted it straight away</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pyagcore by mohamed</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65217</link>
		<dc:creator>mohamed</dc:creator>
		<pubDate>Sun, 11 Oct 2009 19:38:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65217</guid>
		<description>hi, after removing it from the task manager, where do you browse the C/:PROGRAM FILES/KIWEE TOOLBAR  ??</description>
		<content:encoded><![CDATA[<p>hi, after removing it from the task manager, where do you browse the C/:PROGRAM FILES/KIWEE TOOLBAR  ??</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Me</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65216</link>
		<dc:creator>Me</dc:creator>
		<pubDate>Sat, 10 Oct 2009 22:30:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65216</guid>
		<description>AVG works</description>
		<content:encoded><![CDATA[<p>AVG works</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by uuzoo</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65215</link>
		<dc:creator>uuzoo</dc:creator>
		<pubDate>Sat, 10 Oct 2009 12:08:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65215</guid>
		<description>This is a nasty virus! I got hit with it a couple of weeks ago from downloading programs. My antivirus at the time ( avast) detected it but couldn't do nothing about it. So, I did some research on the net, and was told to download Kaspersky removal tool. It detected it, and was neutralizing it, but the virus was spreading like a forest fire. It got to about 3,000 files infected, and I said forget it. I ended up reformatting and reinstalling OS. It WORKED! What's really interesting is that I didn't know it at the time but my flashdrive was connected in the back of the tower, and it got infected. After reinstalling everything. I realized that my flashdrive was in too. I'm thinking oh no. I ran avast but nothing came up. I've now installed Vipre and ran scan on the flashdrive and it detected and neutralized the virus. Now I'm using Vipre. Been working well.</description>
		<content:encoded><![CDATA[<p>This is a nasty virus! I got hit with it a couple of weeks ago from downloading programs. My antivirus at the time ( avast) detected it but couldn&#8217;t do nothing about it. So, I did some research on the net, and was told to download Kaspersky removal tool. It detected it, and was neutralizing it, but the virus was spreading like a forest fire. It got to about 3,000 files infected, and I said forget it. I ended up reformatting and reinstalling OS. It WORKED! What&#8217;s really interesting is that I didn&#8217;t know it at the time but my flashdrive was connected in the back of the tower, and it got infected. After reinstalling everything. I realized that my flashdrive was in too. I&#8217;m thinking oh no. I ran avast but nothing came up. I&#8217;ve now installed Vipre and ran scan on the flashdrive and it detected and neutralized the virus. Now I&#8217;m using Vipre. Been working well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by kkkohli</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65212</link>
		<dc:creator>kkkohli</dc:creator>
		<pubDate>Sat, 10 Oct 2009 08:50:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65212</guid>
		<description>i was also cheated by this total security software &amp; i paid them usd 78. They pop message said same thing that your computer is under threat &amp; pop up window was neither closing down nor minimising.There message after pop ups said full money will be refunded within 30 days &amp; now there is no adress of any website. even e-mail is coming make on e-mail id provided on e-mail message by which activation key was sent.Can any tell how to get my money back or to whom to complain againest them</description>
		<content:encoded><![CDATA[<p>i was also cheated by this total security software &amp; i paid them usd 78. They pop message said same thing that your computer is under threat &amp; pop up window was neither closing down nor minimising.There message after pop ups said full money will be refunded within 30 days &amp; now there is no adress of any website. even e-mail is coming make on e-mail id provided on e-mail message by which activation key was sent.Can any tell how to get my money back or to whom to complain againest them</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Generic.dx by webmaster</title>
		<link>http://www.precisesecurity.com/blogs/2007/09/26/genericdx/#comment-65211</link>
		<dc:creator>webmaster</dc:creator>
		<pubDate>Sat, 10 Oct 2009 08:30:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/09/26/genericdx/#comment-65211</guid>
		<description>T2 was right, scanning hard drive via USB or Bootable CD is the best way to clean infected hard drive. Booting on the same infected hard disk makes the virus to load on memory and do his things to hide from antivirus programs.

I have brief tutorial how to scan via USB here. Though it requires a tool that cost about $10.
http://www.precisesecurity.com/tools-resources/threat-removal-procedure/scanning-infected-hard-disk-via-usb/</description>
		<content:encoded><![CDATA[<p>T2 was right, scanning hard drive via USB or Bootable CD is the best way to clean infected hard drive. Booting on the same infected hard disk makes the virus to load on memory and do his things to hide from antivirus programs.</p>
<p>I have brief tutorial how to scan via USB here. Though it requires a tool that cost about $10.<br />
<a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/scanning-infected-hard-disk-via-usb/" rel="nofollow">http://www.precisesecurity.com/tools-resources/threat-removal-procedure/scanning-infected-hard-disk-via-usb/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by RHC</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65210</link>
		<dc:creator>RHC</dc:creator>
		<pubDate>Sat, 10 Oct 2009 03:17:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65210</guid>
		<description>Boris or xXtra or anyone else:

Got cryptor months ago, it fried Malabytes, fried sbybot, fried my restore points, AVG picked it up but wouldn't remove it, and the last few weeks AVG won't even run a scan.

Have downloaded Sophos and run a scan.  It has picked up 250 entries, mostly .tmp files starting with UAC (example: C:\WINDOWS\Temp\UAC68d.tmp), but also about two dozen random letter files like hjgruimxbfhqpx.dll.  Sophos doesn't recommend cleaning up any of them.

Do I delete everything, all 250?  Do  just start with the "hjgru" files?  

Any advice would be appreciated.  I've lived with this virus for months, and my system is getting so threadbare that I have a hard time getting the computer to boot at all.</description>
		<content:encoded><![CDATA[<p>Boris or xXtra or anyone else:</p>
<p>Got cryptor months ago, it fried Malabytes, fried sbybot, fried my restore points, AVG picked it up but wouldn&#8217;t remove it, and the last few weeks AVG won&#8217;t even run a scan.</p>
<p>Have downloaded Sophos and run a scan.  It has picked up 250 entries, mostly .tmp files starting with UAC (example: C:\WINDOWS\Temp\UAC68d.tmp), but also about two dozen random letter files like hjgruimxbfhqpx.dll.  Sophos doesn&#8217;t recommend cleaning up any of them.</p>
<p>Do I delete everything, all 250?  Do  just start with the &#8220;hjgru&#8221; files?  </p>
<p>Any advice would be appreciated.  I&#8217;ve lived with this virus for months, and my system is getting so threadbare that I have a hard time getting the computer to boot at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on anykuy.com by pete burke</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/12/anykuycom/#comment-65209</link>
		<dc:creator>pete burke</dc:creator>
		<pubDate>Fri, 09 Oct 2009 16:40:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2481#comment-65209</guid>
		<description>Marcus, you are a star, I have been trying to get that sorted for 11 hours, loads of people with bright ideas, (which don't work). Shame it took me so long to find your post. Many thanks mate. Pete.</description>
		<content:encoded><![CDATA[<p>Marcus, you are a star, I have been trying to get that sorted for 11 hours, loads of people with bright ideas, (which don&#8217;t work). Shame it took me so long to find your post. Many thanks mate. Pete.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2010 by Jay</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65207</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Thu, 08 Oct 2009 15:58:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65207</guid>
		<description>You were dumb enough to purchase it?   moron....  it is due to morons like you that companies release software like this</description>
		<content:encoded><![CDATA[<p>You were dumb enough to purchase it?   moron&#8230;.  it is due to morons like you that companies release software like this</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Windows Security Alert by gaurav gupta</title>
		<link>http://www.precisesecurity.com/blogs/2007/12/27/windows-security-alert/#comment-65206</link>
		<dc:creator>gaurav gupta</dc:creator>
		<pubDate>Thu, 08 Oct 2009 09:46:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/12/27/windows-security-alert/#comment-65206</guid>
		<description>I have got same virus.thanks for this valuable information.</description>
		<content:encoded><![CDATA[<p>I have got same virus.thanks for this valuable information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Ermias</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65205</link>
		<dc:creator>Ermias</dc:creator>
		<pubDate>Thu, 08 Oct 2009 07:19:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65205</guid>
		<description>Please send Tsere dulla Antivrus. My documents are at risk</description>
		<content:encoded><![CDATA[<p>Please send Tsere dulla Antivrus. My documents are at risk</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by itchy</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65204</link>
		<dc:creator>itchy</dc:creator>
		<pubDate>Wed, 07 Oct 2009 23:06:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65204</guid>
		<description>ow also cleaned my external hard drive no problems there. my friend however who apparently didnt have anti-virus. and who waited to long is completely screwed. he cant even dl the avg removal tool</description>
		<content:encoded><![CDATA[<p>ow also cleaned my external hard drive no problems there. my friend however who apparently didnt have anti-virus. and who waited to long is completely screwed. he cant even dl the avg removal tool</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by itchy</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65203</link>
		<dc:creator>itchy</dc:creator>
		<pubDate>Wed, 07 Oct 2009 23:04:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65203</guid>
		<description>i only used kaspersky 2010 and the avg link that was mentioned hxxp://www.avg.com/us.virus-removal.ndi-67762 
and im done.
took me about 2 hours (because my pc was just rebooted there wasnt mutch to scan)</description>
		<content:encoded><![CDATA[<p>i only used kaspersky 2010 and the avg link that was mentioned hxxp://www.avg.com/us.virus-removal.ndi-67762<br />
and im done.<br />
took me about 2 hours (because my pc was just rebooted there wasnt mutch to scan)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Generic.dx by T2</title>
		<link>http://www.precisesecurity.com/blogs/2007/09/26/genericdx/#comment-65202</link>
		<dc:creator>T2</dc:creator>
		<pubDate>Wed, 07 Oct 2009 10:22:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/09/26/genericdx/#comment-65202</guid>
		<description>The best way to get rid of this trojen is to connect infected hard drive to the secondary connector of another pc and run on demand scanner to perform cleanup. The trojan mostly gets attached to cookies.</description>
		<content:encoded><![CDATA[<p>The best way to get rid of this trojen is to connect infected hard drive to the secondary connector of another pc and run on demand scanner to perform cleanup. The trojan mostly gets attached to cookies.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by Fahad</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65201</link>
		<dc:creator>Fahad</dc:creator>
		<pubDate>Wed, 07 Oct 2009 09:59:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65201</guid>
		<description>This program deleted my san andreas file(not folder only the appication) it alse deleted san andreas multiplayer, downloading them will take a long while so please help me out,i also checked the recycle bin</description>
		<content:encoded><![CDATA[<p>This program deleted my san andreas file(not folder only the appication) it alse deleted san andreas multiplayer, downloading them will take a long while so please help me out,i also checked the recycle bin</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by Nate</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65200</link>
		<dc:creator>Nate</dc:creator>
		<pubDate>Tue, 06 Oct 2009 18:15:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65200</guid>
		<description>I got rid of this yesterday! Go to malware bytes.org. When you try to download the virus will try and block it accompanied by a flashing bar at the top of the window. Simply go to the middle of the page where it  will say " if your having trouble downloading click here" and click there. This should let the download go through. Once you install malwarebytes anitmalware, it should fing the virus and remove it. This worked on my computer, so hopefully it will help you.</description>
		<content:encoded><![CDATA[<p>I got rid of this yesterday! Go to malware bytes.org. When you try to download the virus will try and block it accompanied by a flashing bar at the top of the window. Simply go to the middle of the page where it  will say &#8221; if your having trouble downloading click here&#8221; and click there. This should let the download go through. Once you install malwarebytes anitmalware, it should fing the virus and remove it. This worked on my computer, so hopefully it will help you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Downloader.Agent.OSQ by webmaster</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/28/trojan-downloader-agent-osq/#comment-65199</link>
		<dc:creator>webmaster</dc:creator>
		<pubDate>Mon, 05 Oct 2009 13:32:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4072#comment-65199</guid>
		<description>Hi Taufik, I believed credit card can be used on international transactions. Which particular antivirus do you want to purchase?</description>
		<content:encoded><![CDATA[<p>Hi Taufik, I believed credit card can be used on international transactions. Which particular antivirus do you want to purchase?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Downloader.Agent.OSQ by taufik awarsa kesuma</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/28/trojan-downloader-agent-osq/#comment-65198</link>
		<dc:creator>taufik awarsa kesuma</dc:creator>
		<pubDate>Mon, 05 Oct 2009 01:51:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4072#comment-65198</guid>
		<description>I want to buy your security,if my Pc has inpected by vyrus.but I am new residence in Singapore and I can't apply the credit car. Please give the solution how I bu your anti virus,Thanks</description>
		<content:encoded><![CDATA[<p>I want to buy your security,if my Pc has inpected by vyrus.but I am new residence in Singapore and I can&#8217;t apply the credit car. Please give the solution how I bu your anti virus,Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.TDSS.rtk by Kendo</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65196</link>
		<dc:creator>Kendo</dc:creator>
		<pubDate>Fri, 02 Oct 2009 04:00:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65196</guid>
		<description>Try Malwarebytes   mbma   (free download)

Worked a treat for me</description>
		<content:encoded><![CDATA[<p>Try Malwarebytes   mbma   (free download)</p>
<p>Worked a treat for me</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.TDSS.rtk by Kendo</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65195</link>
		<dc:creator>Kendo</dc:creator>
		<pubDate>Fri, 02 Oct 2009 03:59:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65195</guid>
		<description>Hi all ..at last I found a solid if drastic cure for having TDSS.rtk
it appeared after my daughter downloaded some (as she thought) mp3 files. She had saved to desktop, scanned with Spybot and they were announced as clean...moments later , she yelled to come see...jeez , there was a folder with a number of exe files , all disappearing one by one of their own accord after she had opened the first one !
Thereafter , everything went pearshaped..first of all none of my burning software could even see my DVD RW, and when I checked out "problem devices" in Disk management (in XP) , the first thing I saw in horror was just one huge pink block telling me that there were no physical drives present...no partitions ..NOTHING !!
Weird thing was too that windows still worked after a wobbly fashion, desktop all ok etc 
Scanned whole pc and found 8 instances of TDS.rtk (corresponding to the number of files she had downloaded and let loose )
Spybot elected to fix them, apparently, giving the usual green tick success story .....NOT !!  cuz on the second scan , there they were again, all over the place , in registry etc !!
No matter how many scans I did with various software including AVG, spybot , Adaware etc, they ALWAYS reappeared....PANIC !!!
Got a grip of myself and thought I'd sneak up behind this sucker , by going in XP in Safe Mode ... no way , I couldnt even get there..it just went right on into windows welcome every time !!
In frustration I decided to bite the bullet and go for a full reinstall...and guess what , no matter which way I tried , the install failed , mainly cuz Widows installer couldnt find a drive !!
Trawled loads of sites, looking for help and advice...willing to give anything a go .
Found an article that recommended downloading and installing Malwarebytes  mbam  (freebie)....
Nothing to lose , I gave it a go .....and guess what ? First scan showed up the same 8 instances of our wee friend TDSS.rtk...and mbam offered to do the biz on them.   
Fingers crossed and butt cheeks clenched, I hit the button and sure enough , it apparently did its thing.
Second scan run , and again ..guess what  ?? 
TDSS.rtk had been given the heave ho! Call me a cynic , or just paranoid , but I ran a third scan...still clean...fourth one too.
Went back into Disk Management , and lo and behold , there were all my drives and partitions , and not a hint of pink in sight.
Just to be on the safe side though , and having had a poke around in the registry, I decided to follow on my plan to reinstall, just in case TDSS was hiding with its tail between its legs, preparing an even nastier sting in its tail . Drastic measure, I know , but......
Result  - full clean reinstallation wthout a hitch. !!!
Aye , even though I'm Scottish , I broke out the wallet , bought meself a wee dram or two at the local pub and drank the health of those fine dudes down at Malwarebytes .
Slainte !!!
Hope this helps ...if not , there's always the Samaritans</description>
		<content:encoded><![CDATA[<p>Hi all ..at last I found a solid if drastic cure for having TDSS.rtk<br />
it appeared after my daughter downloaded some (as she thought) mp3 files. She had saved to desktop, scanned with Spybot and they were announced as clean&#8230;moments later , she yelled to come see&#8230;jeez , there was a folder with a number of exe files , all disappearing one by one of their own accord after she had opened the first one !<br />
Thereafter , everything went pearshaped..first of all none of my burning software could even see my DVD RW, and when I checked out &#8220;problem devices&#8221; in Disk management (in XP) , the first thing I saw in horror was just one huge pink block telling me that there were no physical drives present&#8230;no partitions ..NOTHING !!<br />
Weird thing was too that windows still worked after a wobbly fashion, desktop all ok etc<br />
Scanned whole pc and found 8 instances of TDS.rtk (corresponding to the number of files she had downloaded and let loose )<br />
Spybot elected to fix them, apparently, giving the usual green tick success story &#8230;..NOT !!  cuz on the second scan , there they were again, all over the place , in registry etc !!<br />
No matter how many scans I did with various software including AVG, spybot , Adaware etc, they ALWAYS reappeared&#8230;.PANIC !!!<br />
Got a grip of myself and thought I&#8217;d sneak up behind this sucker , by going in XP in Safe Mode &#8230; no way , I couldnt even get there..it just went right on into windows welcome every time !!<br />
In frustration I decided to bite the bullet and go for a full reinstall&#8230;and guess what , no matter which way I tried , the install failed , mainly cuz Widows installer couldnt find a drive !!<br />
Trawled loads of sites, looking for help and advice&#8230;willing to give anything a go .<br />
Found an article that recommended downloading and installing Malwarebytes  mbam  (freebie)&#8230;.<br />
Nothing to lose , I gave it a go &#8230;..and guess what ? First scan showed up the same 8 instances of our wee friend TDSS.rtk&#8230;and mbam offered to do the biz on them.<br />
Fingers crossed and butt cheeks clenched, I hit the button and sure enough , it apparently did its thing.<br />
Second scan run , and again ..guess what  ??<br />
TDSS.rtk had been given the heave ho! Call me a cynic , or just paranoid , but I ran a third scan&#8230;still clean&#8230;fourth one too.<br />
Went back into Disk Management , and lo and behold , there were all my drives and partitions , and not a hint of pink in sight.<br />
Just to be on the safe side though , and having had a poke around in the registry, I decided to follow on my plan to reinstall, just in case TDSS was hiding with its tail between its legs, preparing an even nastier sting in its tail . Drastic measure, I know , but&#8230;&#8230;<br />
Result  - full clean reinstallation wthout a hitch. !!!<br />
Aye , even though I&#8217;m Scottish , I broke out the wallet , bought meself a wee dram or two at the local pub and drank the health of those fine dudes down at Malwarebytes .<br />
Slainte !!!<br />
Hope this helps &#8230;if not , there&#8217;s always the Samaritans</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Kyle</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65194</link>
		<dc:creator>Kyle</dc:creator>
		<pubDate>Fri, 02 Oct 2009 00:46:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65194</guid>
		<description>I got peggle nights and i put it on my flash drive  and when i tried running it it said it had this virus and i was like wtf -.-. now i cant play peggle nights :(</description>
		<content:encoded><![CDATA[<p>I got peggle nights and i put it on my flash drive  and when i tried running it it said it had this virus and i was like wtf -.-. now i cant play peggle nights :(</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by Blueberry</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65193</link>
		<dc:creator>Blueberry</dc:creator>
		<pubDate>Thu, 01 Oct 2009 17:50:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65193</guid>
		<description>thanks Alexander Mc, I have removed it :)</description>
		<content:encoded><![CDATA[<p>thanks Alexander Mc, I have removed it :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by SChalice</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65191</link>
		<dc:creator>SChalice</dc:creator>
		<pubDate>Thu, 01 Oct 2009 02:34:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65191</guid>
		<description>This virus can get on compact flash sticks. You'll need to be sure to wipe all those suckers clean or just throw them away if unsure..</description>
		<content:encoded><![CDATA[<p>This virus can get on compact flash sticks. You&#8217;ll need to be sure to wipe all those suckers clean or just throw them away if unsure..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by Lizzy</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65190</link>
		<dc:creator>Lizzy</dc:creator>
		<pubDate>Wed, 30 Sep 2009 13:49:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65190</guid>
		<description>i want to remove FullHouse drive virus from my PC. please i want something free. i am using AVG antivirus. please help me.</description>
		<content:encoded><![CDATA[<p>i want to remove FullHouse drive virus from my PC. please i want something free. i am using AVG antivirus. please help me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dropper.Bravix.A by TnMike</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/20/dropperbravixa/#comment-65189</link>
		<dc:creator>TnMike</dc:creator>
		<pubDate>Wed, 30 Sep 2009 13:46:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/20/dropperbravixa/#comment-65189</guid>
		<description>MalwareBytes will get rid of the virus</description>
		<content:encoded><![CDATA[<p>MalwareBytes will get rid of the virus</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.TDSS.rtk by Jzone09</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65185</link>
		<dc:creator>Jzone09</dc:creator>
		<pubDate>Mon, 28 Sep 2009 05:03:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65185</guid>
		<description>I have also found Win32.TDSS.rtk using spybot, I tihn kthis is the reason why my computer keeps restarting at startup, I can only run it by booting it from safe mode   with netowrking, what is the fix?</description>
		<content:encoded><![CDATA[<p>I have also found Win32.TDSS.rtk using spybot, I tihn kthis is the reason why my computer keeps restarting at startup, I can only run it by booting it from safe mode   with netowrking, what is the fix?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pyagcore by eithel</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65176</link>
		<dc:creator>eithel</dc:creator>
		<pubDate>Fri, 25 Sep 2009 22:55:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65176</guid>
		<description>tengo problemas con el windows police pro, quiero saber como elominarlo de mi computadora, no me deja entrar a internet. expliquenme bien por favor eithel</description>
		<content:encoded><![CDATA[<p>tengo problemas con el windows police pro, quiero saber como elominarlo de mi computadora, no me deja entrar a internet. expliquenme bien por favor eithel</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by jess m</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65173</link>
		<dc:creator>jess m</dc:creator>
		<pubDate>Thu, 24 Sep 2009 14:14:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65173</guid>
		<description>Ok, so we did everything that was listed and after running all the spyware/virus detection programs we have not found ANY virus on the computer however, it will still not let us access the internet using an ethernet cord.  Anyone else have this issue?  Were you able to resolve it?</description>
		<content:encoded><![CDATA[<p>Ok, so we did everything that was listed and after running all the spyware/virus detection programs we have not found ANY virus on the computer however, it will still not let us access the internet using an ethernet cord.  Anyone else have this issue?  Were you able to resolve it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Dawit</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65172</link>
		<dc:creator>Dawit</dc:creator>
		<pubDate>Thu, 24 Sep 2009 08:43:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65172</guid>
		<description>Amanuel Kenna and AreMoh.

I think you two know how to recover pdf files that have been infected by the dulla virus using hex editor. I tried several times and I didn't succeed. Please help. I am really anxious.</description>
		<content:encoded><![CDATA[<p>Amanuel Kenna and AreMoh.</p>
<p>I think you two know how to recover pdf files that have been infected by the dulla virus using hex editor. I tried several times and I didn&#8217;t succeed. Please help. I am really anxious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by expertanalyzer</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65171</link>
		<dc:creator>expertanalyzer</dc:creator>
		<pubDate>Tue, 22 Sep 2009 23:27:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65171</guid>
		<description>send me the teddy afro virus infected file sample i am expert virus anlayzer and i love to help people in my free time if you have teddy afro virus infected file attach and send it to my email: father@safe-mail.net  i will give you free removal tool for free.
thanks.</description>
		<content:encoded><![CDATA[<p>send me the teddy afro virus infected file sample i am expert virus anlayzer and i love to help people in my free time if you have teddy afro virus infected file attach and send it to my email: <a href="mailto:father@safe-mail.net">father@safe-mail.net</a>  i will give you free removal tool for free.<br />
thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rapid Antivirus Firewall has blocked a program from accessing the Internet by Tolebi</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/17/rapid-antivirus-firewall-has-blocked-a-program-from-accessing-the-internet/#comment-65170</link>
		<dc:creator>Tolebi</dc:creator>
		<pubDate>Tue, 22 Sep 2009 22:24:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3825#comment-65170</guid>
		<description>U menya net antivirusa!Kak mojno udalit total security</description>
		<content:encoded><![CDATA[<p>U menya net antivirusa!Kak mojno udalit total security</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.Tanatos.m by Nasser</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/31/win32tanatosm/#comment-65168</link>
		<dc:creator>Nasser</dc:creator>
		<pubDate>Tue, 22 Sep 2009 18:10:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/31/win32tanatosm/#comment-65168</guid>
		<description>I am suffering the same problem with win32/Tanatos.M It has even disabled the exe of AVG and when I click the AVG icon on desktop. It is showing the 'browse  cancel' dailog box.

From the above discussion I can see a mere discussion about AVG, but no solution. Can anyone please help me with the win32/tanatos.m removal tool?????

Thanks in Advance.
Nasser</description>
		<content:encoded><![CDATA[<p>I am suffering the same problem with win32/Tanatos.M It has even disabled the exe of AVG and when I click the AVG icon on desktop. It is showing the &#8216;browse  cancel&#8217; dailog box.</p>
<p>From the above discussion I can see a mere discussion about AVG, but no solution. Can anyone please help me with the win32/tanatos.m removal tool?????</p>
<p>Thanks in Advance.<br />
Nasser</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by john</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65167</link>
		<dc:creator>john</dc:creator>
		<pubDate>Tue, 22 Sep 2009 16:08:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65167</guid>
		<description>your solution for total security

install revo uninstaller, get it from download.com, run uninstaller in advance mode and follow the prompts, select all files as per screen, uninstall and reboot. Install avira / update,get it from download.com and run full scan, avira will pick up the trojan. Go to program files on your c drive and delete the TS folder, if this folder is locked boot in safe mode F8 and delete the folder.</description>
		<content:encoded><![CDATA[<p>your solution for total security</p>
<p>install revo uninstaller, get it from download.com, run uninstaller in advance mode and follow the prompts, select all files as per screen, uninstall and reboot. Install avira / update,get it from download.com and run full scan, avira will pick up the trojan. Go to program files on your c drive and delete the TS folder, if this folder is locked boot in safe mode F8 and delete the folder.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on W32/Scribble-B by w32 scribble-b</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/23/w32scribble-b/#comment-65165</link>
		<dc:creator>w32 scribble-b</dc:creator>
		<pubDate>Tue, 22 Sep 2009 13:03:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3987#comment-65165</guid>
		<description>how is this virus removed?</description>
		<content:encoded><![CDATA[<p>how is this virus removed?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Joe</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65161</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Sun, 20 Sep 2009 22:01:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65161</guid>
		<description>This virus infected my old HD, so I had no choice but to reinstall WinXP. Then today I accidently clicked an old executable on that HD and the virus is reinfected me. I was in no mood to reinstall so this is how I dealt with it.

DO NOT START ANY PROGRAMS YET, THEY WILL GET INFECTED

1. Pull the plug on your internet connection, because it will try to connect to its website (jL.chura.pl and maybe others) and download more crap to your PC

2. Go to Task Manager and kill ANY program that looks unfamiliar (this can be tricky, if you're a not a computer geek)

3. Run services.msc and you'll see at least 2 services running which have NO description. Stop them and then disable them (by right clicking). Also stop and disable Remote Access Connection Manager, and Background Intelligent Transfer System, if they are running. These are Windows processes, but I think the virus activates them.

4. Repeat step 2 just in case

5. Now you have a choice:
a)You can run restore, but you have to be very sure that the restore is clean
b) run your antivirus. A full scan is preferable, but at least C:\Windows\ and C:\Program Files\. The virus infected only logonui.exe in my case and changed the HOSTS file, and created a temporary file in the WINDOWS\TEMP directory, but nothing else. However, if you ran any program while the virus was loaded, that program will be infected too.

This is the stage on which I am myself. The virus is removed but my system is still a bit screwed up, because everytime I reboot a hidden process iexplore.exe is started, except it's not connecting anywhere. I'm not sure what's starting it, but I dealt with it by killing the process and moving iexplore.exe to a temporary folder.</description>
		<content:encoded><![CDATA[<p>This virus infected my old HD, so I had no choice but to reinstall WinXP. Then today I accidently clicked an old executable on that HD and the virus is reinfected me. I was in no mood to reinstall so this is how I dealt with it.</p>
<p>DO NOT START ANY PROGRAMS YET, THEY WILL GET INFECTED</p>
<p>1. Pull the plug on your internet connection, because it will try to connect to its website (jL.chura.pl and maybe others) and download more crap to your PC</p>
<p>2. Go to Task Manager and kill ANY program that looks unfamiliar (this can be tricky, if you&#8217;re a not a computer geek)</p>
<p>3. Run services.msc and you&#8217;ll see at least 2 services running which have NO description. Stop them and then disable them (by right clicking). Also stop and disable Remote Access Connection Manager, and Background Intelligent Transfer System, if they are running. These are Windows processes, but I think the virus activates them.</p>
<p>4. Repeat step 2 just in case</p>
<p>5. Now you have a choice:<br />
a)You can run restore, but you have to be very sure that the restore is clean<br />
b) run your antivirus. A full scan is preferable, but at least C:\Windows\ and C:\Program Files\. The virus infected only logonui.exe in my case and changed the HOSTS file, and created a temporary file in the WINDOWS\TEMP directory, but nothing else. However, if you ran any program while the virus was loaded, that program will be infected too.</p>
<p>This is the stage on which I am myself. The virus is removed but my system is still a bit screwed up, because everytime I reboot a hidden process iexplore.exe is started, except it&#8217;s not connecting anywhere. I&#8217;m not sure what&#8217;s starting it, but I dealt with it by killing the process and moving iexplore.exe to a temporary folder.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Fennec the sysop</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65160</link>
		<dc:creator>Fennec the sysop</dc:creator>
		<pubDate>Sun, 20 Sep 2009 20:07:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65160</guid>
		<description>This virus is a pain but I have it contained ,my router is a good firewall and I have it set to block all incoming connections on port 65520 and all outgoing connections to Proxima.ircgalaxy.pl so that means the attackers cant use it I have also found that using IRC to connect to my local machine on port 65520 gives you control of this virus so now I am able to change the options and on my machine it only infects explorer.exe too bad it dosent have a disinfect command</description>
		<content:encoded><![CDATA[<p>This virus is a pain but I have it contained ,my router is a good firewall and I have it set to block all incoming connections on port 65520 and all outgoing connections to Proxima.ircgalaxy.pl so that means the attackers cant use it I have also found that using IRC to connect to my local machine on port 65520 gives you control of this virus so now I am able to change the options and on my machine it only infects explorer.exe too bad it dosent have a disinfect command</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by glen</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65159</link>
		<dc:creator>glen</dc:creator>
		<pubDate>Sun, 20 Sep 2009 07:55:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65159</guid>
		<description>Sophos anti-rootkit works magic. all other anti-spyware softwares couldn't solve the problem.</description>
		<content:encoded><![CDATA[<p>Sophos anti-rootkit works magic. all other anti-spyware softwares couldn&#8217;t solve the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by amanuel girma (haramaya university)</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65158</link>
		<dc:creator>amanuel girma (haramaya university)</dc:creator>
		<pubDate>Sat, 19 Sep 2009 22:25:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65158</guid>
		<description>HOW TO PARTIAL REPAIR OFFICE DOCUMENTS INFECTED WIZ “~dulla^@204~” VIRUS
Before you start this tutorial clean your pc wiz anti dulla software I recommend
Emopia® Virus Removal Pack (freeware) from emopia.com
	Tools needed for this tutorial
•	Notepad ++ (absolutely free download and install this software)
•	Office 2007
•	An infected file 
1.	Right click on the infected office document &gt;&gt;click “edit with notepad ++” now the document will be opened in notepad++ window
2.	Click on “search” from the menu &gt;&gt;click on” find” &gt;&gt; click on “replace” tab
3.	Type ‘~dulla^@204~\x00’ (without the quote) on “find what” box&gt;&gt; check the “regular expression” check box &gt;&gt; click on “find next” tab &gt;&gt; click on “replace all” tab &gt;&gt; ok &gt;&gt; done.
4.	Click done &gt;&gt; click on the” save” from menu &gt;&gt; close notepad ++ &gt;&gt; open the infected(corrupted) document when a dialog box appear click yes
any question please email me :amangirma@gmail.com</description>
		<content:encoded><![CDATA[<p>HOW TO PARTIAL REPAIR OFFICE DOCUMENTS INFECTED WIZ “~dulla^@204~” VIRUS<br />
Before you start this tutorial clean your pc wiz anti dulla software I recommend<br />
Emopia® Virus Removal Pack (freeware) from emopia.com<br />
	Tools needed for this tutorial<br />
•	Notepad ++ (absolutely free download and install this software)<br />
•	Office 2007<br />
•	An infected file<br />
1.	Right click on the infected office document &gt;&gt;click “edit with notepad ++” now the document will be opened in notepad++ window<br />
2.	Click on “search” from the menu &gt;&gt;click on” find” &gt;&gt; click on “replace” tab<br />
3.	Type ‘~dulla^@204~\x00’ (without the quote) on “find what” box&gt;&gt; check the “regular expression” check box &gt;&gt; click on “find next” tab &gt;&gt; click on “replace all” tab &gt;&gt; ok &gt;&gt; done.<br />
4.	Click done &gt;&gt; click on the” save” from menu &gt;&gt; close notepad ++ &gt;&gt; open the infected(corrupted) document when a dialog box appear click yes<br />
any question please email me :amangirma@gmail.com</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by endy</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65157</link>
		<dc:creator>endy</dc:creator>
		<pubDate>Sat, 19 Sep 2009 07:15:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65157</guid>
		<description>in reply to ujjawal goel

the whole total security lifetime package is a scam! they got your credit card information, so if i were you, call your bank and let them know what happened.</description>
		<content:encoded><![CDATA[<p>in reply to ujjawal goel</p>
<p>the whole total security lifetime package is a scam! they got your credit card information, so if i were you, call your bank and let them know what happened.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on sc.videofreeforonline.com by Nalaka</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/14/scvideofreeforonlinecom/#comment-65156</link>
		<dc:creator>Nalaka</dc:creator>
		<pubDate>Sat, 19 Sep 2009 06:11:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/14/scvideofreeforonlinecom/#comment-65156</guid>
		<description>It worked with Avast virus scan. It's a Free ware Home package. I am very much relieved after this.</description>
		<content:encoded><![CDATA[<p>It worked with Avast virus scan. It&#8217;s a Free ware Home package. I am very much relieved after this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by Stephanie</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65155</link>
		<dc:creator>Stephanie</dc:creator>
		<pubDate>Fri, 18 Sep 2009 18:25:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65155</guid>
		<description>combofix is the only thing I have seen that removes it. download.com has this file. Malware Bytes is also suppose to remove but it would not on a couple of our computers.</description>
		<content:encoded><![CDATA[<p>combofix is the only thing I have seen that removes it. download.com has this file. Malware Bytes is also suppose to remove but it would not on a couple of our computers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by PHILIP</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65154</link>
		<dc:creator>PHILIP</dc:creator>
		<pubDate>Thu, 17 Sep 2009 11:15:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65154</guid>
		<description>I want to remove FullHouse Drive virus from my PC. please help me.</description>
		<content:encoded><![CDATA[<p>I want to remove FullHouse Drive virus from my PC. please help me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Jiru</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65153</link>
		<dc:creator>Jiru</dc:creator>
		<pubDate>Thu, 17 Sep 2009 10:22:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65153</guid>
		<description>Ther is a virus named Teddy afro which has characterstic feature of hiding your files and disabling ur cd driver...it is even difficult to remove it with command...i have tried avira, kaspersky,macaffe,avg,and NOD..non of them could remove that.You guys do you have any solution for that?EMOPIA ..it is just fake..it cant detect any virus...</description>
		<content:encoded><![CDATA[<p>Ther is a virus named Teddy afro which has characterstic feature of hiding your files and disabling ur cd driver&#8230;it is even difficult to remove it with command&#8230;i have tried avira, kaspersky,macaffe,avg,and NOD..non of them could remove that.You guys do you have any solution for that?EMOPIA ..it is just fake..it cant detect any virus&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by war10ck</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65152</link>
		<dc:creator>war10ck</dc:creator>
		<pubDate>Wed, 16 Sep 2009 07:49:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65152</guid>
		<description>Download ComboFix and run on your pc..
I am sure FullHouse icon on your desktop can be delete.
Tested by me and it's works.

Click above to downlaod ComboFix:-
hxxp://download.bleepingcomputer.com/sUBs/ComboFix.exe</description>
		<content:encoded><![CDATA[<p>Download ComboFix and run on your pc..<br />
I am sure FullHouse icon on your desktop can be delete.<br />
Tested by me and it&#8217;s works.</p>
<p>Click above to downlaod ComboFix:-<br />
hxxp://download.bleepingcomputer.com/sUBs/ComboFix.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pyagcore by ORNELLA</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65151</link>
		<dc:creator>ORNELLA</dc:creator>
		<pubDate>Wed, 16 Sep 2009 07:10:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65151</guid>
		<description>MANY THANKS.. just when I was losing the battle I won the war with this computer .. children are much more easier than technology, haha... but I'm glad I succeded with your help!

This program is great!! it worked!! 

Thanks again.</description>
		<content:encoded><![CDATA[<p>MANY THANKS.. just when I was losing the battle I won the war with this computer .. children are much more easier than technology, haha&#8230; but I&#8217;m glad I succeded with your help!</p>
<p>This program is great!! it worked!! </p>
<p>Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Your computer is infected! by John</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/23/your-computer-is-infected/#comment-65150</link>
		<dc:creator>John</dc:creator>
		<pubDate>Wed, 16 Sep 2009 05:08:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/23/your-computer-is-infected/#comment-65150</guid>
		<description>Hay Garrett
Turn off your restore and dump it then turn it back on this bugger hides in the hidden files like System volume information file. Most of this is your restore files. If you don't want to dump your restore you'll need to make the file accessable so malbytes can get at it.</description>
		<content:encoded><![CDATA[<p>Hay Garrett<br />
Turn off your restore and dump it then turn it back on this bugger hides in the hidden files like System volume information file. Most of this is your restore files. If you don&#8217;t want to dump your restore you&#8217;ll need to make the file accessable so malbytes can get at it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by hoangson dinh</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65148</link>
		<dc:creator>hoangson dinh</dc:creator>
		<pubDate>Tue, 15 Sep 2009 13:52:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65148</guid>
		<description>Response 78 saved my computer.
Thanks to precisesecurity.com, Sophos Anti-Rootkit, Malwarebytes, and Superantispyware.
Thanks to everyone.</description>
		<content:encoded><![CDATA[<p>Response 78 saved my computer.<br />
Thanks to precisesecurity.com, Sophos Anti-Rootkit, Malwarebytes, and Superantispyware.<br />
Thanks to everyone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Abdulkerim</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65147</link>
		<dc:creator>Abdulkerim</dc:creator>
		<pubDate>Tue, 15 Sep 2009 12:02:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65147</guid>
		<description>People! Get over it! There is no method to recover corrupted files, you can see the reason on facebook, just go to emopia.com (they are the one who made emopia virus remover, and are professionals) and join their facebook page and in the discussion board, you can read the reason why dulla corrupted files can't be recovered.</description>
		<content:encoded><![CDATA[<p>People! Get over it! There is no method to recover corrupted files, you can see the reason on facebook, just go to emopia.com (they are the one who made emopia virus remover, and are professionals) and join their facebook page and in the discussion board, you can read the reason why dulla corrupted files can&#8217;t be recovered.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
