<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments for Threat Center - Spyware and Virus Removal</title>
	<atom:link href="http://www.precisesecurity.com/blogs/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.precisesecurity.com/blogs</link>
	<description></description>
	<pubDate>Thu, 05 Nov 2009 01:57:12 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Anti-Virus Number-1 by Judy Kauffmann</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/17/anti-virus-number-1/#comment-65269</link>
		<dc:creator>Judy Kauffmann</dc:creator>
		<pubDate>Wed, 04 Nov 2009 14:54:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3092#comment-65269</guid>
		<description>Hi,
I really need a number to reach you or something. I
am trying to remove you app. for virus proctection 
and I can't get it to remove and I already have protection and I am happy with it. I can't get on
in site now. Please help me get it off.
                   Thanks~!</description>
		<content:encoded><![CDATA[<p>Hi,<br />
I really need a number to reach you or something. I<br />
am trying to remove you app. for virus proctection<br />
and I can&#8217;t get it to remove and I already have protection and I am happy with it. I can&#8217;t get on<br />
in site now. Please help me get it off.<br />
                   Thanks~!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rootkit.TDSS by tdlwsp.dll &#124; Spyware-Virus Files and Process</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/04/rootkit_tdss/#comment-65267</link>
		<dc:creator>tdlwsp.dll &#124; Spyware-Virus Files and Process</dc:creator>
		<pubDate>Wed, 04 Nov 2009 08:32:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3571#comment-65267</guid>
		<description>[...] Related to: Rootkit.TDSS [...]</description>
		<content:encoded><![CDATA[<p>[...] Related to: Rootkit.TDSS [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Warning! Fatal Error: All media systems on your computer have been crashed! by Daniela</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/05/warning-fatal-error/#comment-65266</link>
		<dc:creator>Daniela</dc:creator>
		<pubDate>Tue, 03 Nov 2009 19:59:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2882#comment-65266</guid>
		<description>I have the same problem with the Warning Fatal Error!!! Wallpaper.  I have Trend Micro Antivirus and didn’t find any infections.  I really don’t know how this wallpaper got into my computer and it was not detected by my antivirus.  I research how to get rid of that problem.  I find a lot of spyware but you have to pay in order to delete the files on your computer.  So I find this page and downloaded the Spyware Doctor and I was really tired with this problem because now my screen looks like and old computer screen.  The colors and images look like you have like dialup internet with poor signal which make them look bad.  I have speed internet with usually all my color and images were great.  So I register and pay for the Spyware Doctor to delete this problem and scan my computer.  It did find 9 threats and a lot of infections so I delete them.  But at the end nothing happened.  I still have the same wallpaper fatal error.  Please help me!!!!  I am tired of this problem.</description>
		<content:encoded><![CDATA[<p>I have the same problem with the Warning Fatal Error!!! Wallpaper.  I have Trend Micro Antivirus and didn’t find any infections.  I really don’t know how this wallpaper got into my computer and it was not detected by my antivirus.  I research how to get rid of that problem.  I find a lot of spyware but you have to pay in order to delete the files on your computer.  So I find this page and downloaded the Spyware Doctor and I was really tired with this problem because now my screen looks like and old computer screen.  The colors and images look like you have like dialup internet with poor signal which make them look bad.  I have speed internet with usually all my color and images were great.  So I register and pay for the Spyware Doctor to delete this problem and scan my computer.  It did find 9 threats and a lot of infections so I delete them.  But at the end nothing happened.  I still have the same wallpaper fatal error.  Please help me!!!!  I am tired of this problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by DonkeyDolck</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65264</link>
		<dc:creator>DonkeyDolck</dc:creator>
		<pubDate>Tue, 03 Nov 2009 00:10:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65264</guid>
		<description>Hey.. I got these virus yeasterday (win32/virut and win32/heur) When i read about it that it infected all the .exe and possibly .jpg files i went nuts, turned of my computer unplugged my other 2 drives (D: and E:)on it and installed windows 7 64bit today. Downloaded avg free 9.0 and searched D: and it had 5 infected .exe files. wich it said that it was removed. So it hadn't have the time to spread that far. Now i wonder if it still might spread into my C: where i have my windows or if it will continue to spread through my D: and E: (havn't plugged E: in yet, so i don't know how badly infected it is.) Or shall i just leave them unplugged until a bulletproof removal program for those viruses are released? Really don't wanna mess up all my pictures and stuff there if it's possible to avoid.. damn.. pics on there since 2002. :/ What to do? Any help would be mostly appreciated</description>
		<content:encoded><![CDATA[<p>Hey.. I got these virus yeasterday (win32/virut and win32/heur) When i read about it that it infected all the .exe and possibly .jpg files i went nuts, turned of my computer unplugged my other 2 drives (D: and E:)on it and installed windows 7 64bit today. Downloaded avg free 9.0 and searched D: and it had 5 infected .exe files. wich it said that it was removed. So it hadn&#8217;t have the time to spread that far. Now i wonder if it still might spread into my C: where i have my windows or if it will continue to spread through my D: and E: (havn&#8217;t plugged E: in yet, so i don&#8217;t know how badly infected it is.) Or shall i just leave them unplugged until a bulletproof removal program for those viruses are released? Really don&#8217;t wanna mess up all my pictures and stuff there if it&#8217;s possible to avoid.. damn.. pics on there since 2002. :/ What to do? Any help would be mostly appreciated</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Szabolcs</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65261</link>
		<dc:creator>Szabolcs</dc:creator>
		<pubDate>Sat, 31 Oct 2009 11:11:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65261</guid>
		<description>Confirmed. I agree with the first poster (and the most of you),  it sneaked through avast's protection, I fought this about a week long, that process let me figure out some important stuff.

This malware is probably added by Win32.Agent along with Win32.Delf and b.exe, just to mention the most critical ones and some others (3-4 more)

 - It hides on your portable devices such as pendrives portable hard disk or other partitions.
 - When you connect to the internet, this will download the whole pack again, causing you more trouble.
 - These malware only works on 32-bit based Windows systems. You should consider updating to 64-bit (there are some drawback) or try Windows 7.
 - Only Win32.Virut will infect files, others should create their own, which you can find in "C:\" and "C:\Windows\system32" or in "Documents and Settings"

Note: A new version has come out in October 2009 and even Kaspersky Labs do not have an update for this infection yet. Although, Kaspersky is able to competely eradicate this virus, thanks to it's more advanced and intelligent being, compered to other virusbusters.

Conclusion: I am now using Windows 7 x64, works quite well that far.</description>
		<content:encoded><![CDATA[<p>Confirmed. I agree with the first poster (and the most of you),  it sneaked through avast&#8217;s protection, I fought this about a week long, that process let me figure out some important stuff.</p>
<p>This malware is probably added by Win32.Agent along with Win32.Delf and b.exe, just to mention the most critical ones and some others (3-4 more)</p>
<p> - It hides on your portable devices such as pendrives portable hard disk or other partitions.<br />
 - When you connect to the internet, this will download the whole pack again, causing you more trouble.<br />
 - These malware only works on 32-bit based Windows systems. You should consider updating to 64-bit (there are some drawback) or try Windows 7.<br />
 - Only Win32.Virut will infect files, others should create their own, which you can find in &#8220;C:\&#8221; and &#8220;C:\Windows\system32&#8243; or in &#8220;Documents and Settings&#8221;</p>
<p>Note: A new version has come out in October 2009 and even Kaspersky Labs do not have an update for this infection yet. Although, Kaspersky is able to competely eradicate this virus, thanks to it&#8217;s more advanced and intelligent being, compered to other virusbusters.</p>
<p>Conclusion: I am now using Windows 7 x64, works quite well that far.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by ephrem</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65257</link>
		<dc:creator>ephrem</dc:creator>
		<pubDate>Thu, 29 Oct 2009 15:55:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65257</guid>
		<description>This is really bad fortune for Ethiopians that hears Dulla virus has been created by Ethiopian distractive guy or Association. You know creating very_low_risk and very ordinary system virus like Dulla is not a work of proud. Most educated Ethiopians suspect strongly who has created this gadium virus. In my belief the current stated antivirus for Dulla-Tsere Dulla creator has created the virus itself before. Because the name of a virus it self is Amharic word, besides the solution itself has found from Ethiopia by the association they called INSA. Don’t forget also most commercial antivirus producers ignore or don’t care about to get a solution for this virus. And do not forget Dulla virus is a kind of very easy and low risk ordinary virus that even a younger student of computer science student with out experience can create this kind of macro type of virus. If I were a creator of this virus, I would rather participate to create a kind problem solving projects for this poor country. Shame on this virus creator. Let me tell him what is he done is reflect he is ordinary, very easy and useless bastard gay. By the way I am not giving this opinion just being hot or affected by the virus. And let me tell him that even I can create such virus. But I wouldn’t be interested to be criminal. I am sorry to use irrational words.</description>
		<content:encoded><![CDATA[<p>This is really bad fortune for Ethiopians that hears Dulla virus has been created by Ethiopian distractive guy or Association. You know creating very_low_risk and very ordinary system virus like Dulla is not a work of proud. Most educated Ethiopians suspect strongly who has created this gadium virus. In my belief the current stated antivirus for Dulla-Tsere Dulla creator has created the virus itself before. Because the name of a virus it self is Amharic word, besides the solution itself has found from Ethiopia by the association they called INSA. Don’t forget also most commercial antivirus producers ignore or don’t care about to get a solution for this virus. And do not forget Dulla virus is a kind of very easy and low risk ordinary virus that even a younger student of computer science student with out experience can create this kind of macro type of virus. If I were a creator of this virus, I would rather participate to create a kind problem solving projects for this poor country. Shame on this virus creator. Let me tell him what is he done is reflect he is ordinary, very easy and useless bastard gay. By the way I am not giving this opinion just being hot or affected by the virus. And let me tell him that even I can create such virus. But I wouldn’t be interested to be criminal. I am sorry to use irrational words.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by tadesse</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65256</link>
		<dc:creator>tadesse</dc:creator>
		<pubDate>Thu, 29 Oct 2009 09:33:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65256</guid>
		<description>Please send Tsere dulla Antivrus. My documents are at riskThe file already corrupted, so how can i recover the excel files?+</description>
		<content:encoded><![CDATA[<p>Please send Tsere dulla Antivrus. My documents are at riskThe file already corrupted, so how can i recover the excel files?+</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Alekaw</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65254</link>
		<dc:creator>Alekaw</dc:creator>
		<pubDate>Tue, 27 Oct 2009 15:16:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65254</guid>
		<description>I appreciate  Dull Virus creator man really !! For future I will expect more that used for our country 'Ethiopia' and pass to Next Generation !!</description>
		<content:encoded><![CDATA[<p>I appreciate  Dull Virus creator man really !! For future I will expect more that used for our country &#8216;Ethiopia&#8217; and pass to Next Generation !!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security Tool Virus and Internet Search Redirection by bev</title>
		<link>http://www.precisesecurity.com/blogs/2009/10/10/security-tool-virus-internet-search-redirection/#comment-65253</link>
		<dc:creator>bev</dc:creator>
		<pubDate>Sun, 25 Oct 2009 21:13:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4348#comment-65253</guid>
		<description>I have had for a few days now the Security Tool Malware virus on my computer with nothing able to remove it. I have had a lot of help from others, and tried doing everything not only manually but automatically. Nothing is working at all for me. Every little pop up from any kind of software on the computer terminates immediately. I tried downloading a few different things people told me to, but it just won't let me retrieve the files, let alone open anything. RUN doesn't work, nor task manager isn't allowed to pop up without terminating automatically. I have tried safe mode, but when I got to it and click on it, I am brought to a blank blue screen and nothing happens for minutes on end, and at one point a half an hour, nothing changed, nor did it start any further than the blue screen.
What do I do now?</description>
		<content:encoded><![CDATA[<p>I have had for a few days now the Security Tool Malware virus on my computer with nothing able to remove it. I have had a lot of help from others, and tried doing everything not only manually but automatically. Nothing is working at all for me. Every little pop up from any kind of software on the computer terminates immediately. I tried downloading a few different things people told me to, but it just won&#8217;t let me retrieve the files, let alone open anything. RUN doesn&#8217;t work, nor task manager isn&#8217;t allowed to pop up without terminating automatically. I have tried safe mode, but when I got to it and click on it, I am brought to a blank blue screen and nothing happens for minutes on end, and at one point a half an hour, nothing changed, nor did it start any further than the blue screen.<br />
What do I do now?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Ian Mac</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65252</link>
		<dc:creator>Ian Mac</dc:creator>
		<pubDate>Sun, 25 Oct 2009 13:06:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65252</guid>
		<description>When you get the choice to save or run the download, click save. You will then get the 'save as' prompt. It's at this point that you can change the name.

System restore won't delete any of your saved files.</description>
		<content:encoded><![CDATA[<p>When you get the choice to save or run the download, click save. You will then get the &#8217;save as&#8217; prompt. It&#8217;s at this point that you can change the name.</p>
<p>System restore won&#8217;t delete any of your saved files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on System Guard 2009 by lilkunta</title>
		<link>http://www.precisesecurity.com/blogs/2009/01/26/system-guard-2009/#comment-65251</link>
		<dc:creator>lilkunta</dc:creator>
		<pubDate>Sun, 25 Oct 2009 00:51:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/01/26/system-guard-2009/#comment-65251</guid>
		<description>I have been infected by this virus. I am on a toshiba L25 with windows xp SP2. I am logged in as the admin. The virus has disabled the internet (ethernet &amp; wifi) and the registry editor &amp; system restore, telling me to contact the admin, which I AM the admin ! The popups I keep getting are a red thing called 'security tool' and a blue screen that looks legit(but I know it is fake) called Windows Security Center. It has disabled the task manager and the registry editor and the system restore.  Both 'safe mode' &amp; 'safe mode with networking' dont work. I have to choose 'directory services restore mode (windows domain controllers only) ' in order for safe mode to load.

How do I get rid of the virus ( or is it a trojan or malware or spyware ?)  I cant get online in order to d/l an avg or norton. I cant get into the registry editor and self delte. I am stuck. Thanks.</description>
		<content:encoded><![CDATA[<p>I have been infected by this virus. I am on a toshiba L25 with windows xp SP2. I am logged in as the admin. The virus has disabled the internet (ethernet &amp; wifi) and the registry editor &amp; system restore, telling me to contact the admin, which I AM the admin ! The popups I keep getting are a red thing called &#8217;security tool&#8217; and a blue screen that looks legit(but I know it is fake) called Windows Security Center. It has disabled the task manager and the registry editor and the system restore.  Both &#8217;safe mode&#8217; &amp; &#8217;safe mode with networking&#8217; dont work. I have to choose &#8216;directory services restore mode (windows domain controllers only) &#8216; in order for safe mode to load.</p>
<p>How do I get rid of the virus ( or is it a trojan or malware or spyware ?)  I cant get online in order to d/l an avg or norton. I cant get into the registry editor and self delte. I am stuck. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pyagcore by rignator</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65248</link>
		<dc:creator>rignator</dc:creator>
		<pubDate>Fri, 23 Oct 2009 22:25:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65248</guid>
		<description>mohamed
  go to my computer&gt;local disc&gt;program files&gt;kiwee toolbar
 not gonna do mauch good though, it protects itself and can't be erased in some cases...</description>
		<content:encoded><![CDATA[<p>mohamed<br />
  go to my computer&gt;local disc&gt;program files&gt;kiwee toolbar<br />
 not gonna do mauch good though, it protects itself and can&#8217;t be erased in some cases&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on XP Antispyware 2009 by hurzwurz</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/07/xp-antispyware-2009/#comment-65247</link>
		<dc:creator>hurzwurz</dc:creator>
		<pubDate>Fri, 23 Oct 2009 08:32:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/07/xp-antispyware-2009/#comment-65247</guid>
		<description>dear exel support,

please stop all tasks that are running under your user.

remove ikowin32.exe from your autostart.

stop tasks like "9129837.exe" and strange names like that
in the end you should have no programm running!
no virus scanner, no game software nothing!°
just windows itself
than you can install Malwarebytes and run a full scan!

if I hadnt killed these taks the scareware program always restartet my computer when it recognized that a antivirus prog was running...

And Warning these Program changes its Name
to me its known as "Security Tool"</description>
		<content:encoded><![CDATA[<p>dear exel support,</p>
<p>please stop all tasks that are running under your user.</p>
<p>remove ikowin32.exe from your autostart.</p>
<p>stop tasks like &#8220;9129837.exe&#8221; and strange names like that<br />
in the end you should have no programm running!<br />
no virus scanner, no game software nothing!°<br />
just windows itself<br />
than you can install Malwarebytes and run a full scan!</p>
<p>if I hadnt killed these taks the scareware program always restartet my computer when it recognized that a antivirus prog was running&#8230;</p>
<p>And Warning these Program changes its Name<br />
to me its known as &#8220;Security Tool&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on errorofbrowser.com by No_limits31</title>
		<link>http://www.precisesecurity.com/blogs/2008/09/04/errorofbrowsercom/#comment-65245</link>
		<dc:creator>No_limits31</dc:creator>
		<pubDate>Thu, 22 Oct 2009 19:47:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/09/04/errorofbrowsercom/#comment-65245</guid>
		<description>Besides the fact that some are only there to fill the politically correct quotas but seem totally incapable of fulfilling their duties. ,</description>
		<content:encoded><![CDATA[<p>Besides the fact that some are only there to fill the politically correct quotas but seem totally incapable of fulfilling their duties. ,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Aaron</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65244</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Thu, 22 Oct 2009 18:51:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65244</guid>
		<description>OR
None of these worked for me, even option 6.  Try a slightly different way though:

I tried to go into safe mode, but it wouldn't let me, so I selected to start up in normal windows.

As it was starting up, I pushed F10, and then maneuvered from back there.  Click the tab that has the date, and change the date per option 6. Click save and continue to restart in normal mode.  Everything was fixed.</description>
		<content:encoded><![CDATA[<p>OR<br />
None of these worked for me, even option 6.  Try a slightly different way though:</p>
<p>I tried to go into safe mode, but it wouldn&#8217;t let me, so I selected to start up in normal windows.</p>
<p>As it was starting up, I pushed F10, and then maneuvered from back there.  Click the tab that has the date, and change the date per option 6. Click save and continue to restart in normal mode.  Everything was fixed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on go.google - go.yahoo by Hyoran</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects/#comment-65242</link>
		<dc:creator>Hyoran</dc:creator>
		<pubDate>Tue, 20 Oct 2009 17:41:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects/#comment-65242</guid>
		<description>I've tried everything to find the TDSSserv.sys including the scan for hardware changes and i still can't find it. Is there any other hardware you can disable that will help?

Also i seem to have problems with serial and npkcrypt. Why have they stopped working?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve tried everything to find the TDSSserv.sys including the scan for hardware changes and i still can&#8217;t find it. Is there any other hardware you can disable that will help?</p>
<p>Also i seem to have problems with serial and npkcrypt. Why have they stopped working?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Caitie</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65240</link>
		<dc:creator>Caitie</dc:creator>
		<pubDate>Mon, 19 Oct 2009 22:50:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65240</guid>
		<description>AVG picked it up but won't let me remove the virus, and my Trend Micro Anti-Virus won't pick it up at all and the virus won't let it update. 
I tired to download Anti-Malware Bytes but I can't rename the file before downloading and afterwards when I try to rename it I can't find any of the .exe files and so it won't open. 
I'm thinking maybe a System Restore would help but I would have to go back about 6 months which would really suck</description>
		<content:encoded><![CDATA[<p>AVG picked it up but won&#8217;t let me remove the virus, and my Trend Micro Anti-Virus won&#8217;t pick it up at all and the virus won&#8217;t let it update.<br />
I tired to download Anti-Malware Bytes but I can&#8217;t rename the file before downloading and afterwards when I try to rename it I can&#8217;t find any of the .exe files and so it won&#8217;t open.<br />
I&#8217;m thinking maybe a System Restore would help but I would have to go back about 6 months which would really suck</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Caitie</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65239</link>
		<dc:creator>Caitie</dc:creator>
		<pubDate>Mon, 19 Oct 2009 22:45:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65239</guid>
		<description>My AVG picked it up but won't let me get rid of it, I tried to install Anti Malware Bytes but I can't rename it before it d/ls and when I go into the folder to rename I can't find any .exe files. I'm thinking I might have to do a full system restore around 5 months back which would really suck.</description>
		<content:encoded><![CDATA[<p>My AVG picked it up but won&#8217;t let me get rid of it, I tried to install Anti Malware Bytes but I can&#8217;t rename it before it d/ls and when I go into the folder to rename I can&#8217;t find any .exe files. I&#8217;m thinking I might have to do a full system restore around 5 months back which would really suck.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by brandon</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65237</link>
		<dc:creator>brandon</dc:creator>
		<pubDate>Mon, 19 Oct 2009 13:28:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65237</guid>
		<description>yyyyaaaay everyone do post six it works and takes under 3 minutes. go under safe mode to do yayayayayay tytyty</description>
		<content:encoded><![CDATA[<p>yyyyaaaay everyone do post six it works and takes under 3 minutes. go under safe mode to do yayayayayay tytyty</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by brandon</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65236</link>
		<dc:creator>brandon</dc:creator>
		<pubDate>Mon, 19 Oct 2009 13:26:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65236</guid>
		<description>i did post six still waiting to see if it worked ;)</description>
		<content:encoded><![CDATA[<p>i did post six still waiting to see if it worked ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TR/Crypt.XPACK.Gen by Mel</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/17/tr-crypt-xpack-gen/#comment-65234</link>
		<dc:creator>Mel</dc:creator>
		<pubDate>Mon, 19 Oct 2009 07:39:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2568#comment-65234</guid>
		<description>I have tried Avira, Malwarebytes and Spybot, all of which have not removed the virus.  It is in my temp folder and every time I delete it, it pops up under a different file name.   Please help.  It's starting to drive me insane</description>
		<content:encoded><![CDATA[<p>I have tried Avira, Malwarebytes and Spybot, all of which have not removed the virus.  It is in my temp folder and every time I delete it, it pops up under a different file name.   Please help.  It&#8217;s starting to drive me insane</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan.Patchep!inf by Andy</title>
		<link>http://www.precisesecurity.com/blogs/2007/09/08/trojanpatchepinf/#comment-65233</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Mon, 19 Oct 2009 02:18:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/09/08/trojanpatchepinf/#comment-65233</guid>
		<description>I have tried this and it found the files but failed to remove them. norton did put them in quarantine.</description>
		<content:encoded><![CDATA[<p>I have tried this and it found the files but failed to remove them. norton did put them in quarantine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan-Downloader.Zlob.Media-Codec by SalesMan</title>
		<link>http://www.precisesecurity.com/blogs/2006/08/27/media-codec/#comment-65232</link>
		<dc:creator>SalesMan</dc:creator>
		<pubDate>Sun, 18 Oct 2009 23:47:05 +0000</pubDate>
		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/08/27/media-codec/#comment-65232</guid>
		<description>??????   ????  ?????? ?? ??????? 2009 
????  ????????? ?? ?????????? ????? ??????? 
????  ????????? ?? ??????? ??????? ??????? 
????  ????????? ?? ???????????? ??????? 
????  ????, 
????  ? ??????????, 
????  ? ????????, 
????  ? ???????????????? ???????????????, 
????  ?????????? ?????????, 
????  ???????? ???????????????? ?????????, 
????  ?????????? ?????; 
????  ??????? ??????, 
????  ??????? ??????????, 
????  ??????????? ??????? 
????  ??????? ??????????? ??????? 
????  09 ???????? ??????? ? ??????????? ??????? 
????  ??? ??????? 
????  ????????? ??????? ?? ????? ? ??????? 
????  ??????? ??????? 
????  ??????? ??????????????? ??????? 
????  ??????????? ??? ??????? 
????  ??????????? ??? ??????? 
????  ?????? -  ?????  - ??????? 
????  ?????? ???????????? ???????????? ??????????? ???????</description>
		<content:encoded><![CDATA[<p>??????   ????  ?????? ?? ??????? 2009<br />
????  ????????? ?? ?????????? ????? ???????<br />
????  ????????? ?? ??????? ??????? ???????<br />
????  ????????? ?? ???????????? ???????<br />
????  ????,<br />
????  ? ??????????,<br />
????  ? ????????,<br />
????  ? ???????????????? ???????????????,<br />
????  ?????????? ?????????,<br />
????  ???????? ???????????????? ?????????,<br />
????  ?????????? ?????;<br />
????  ??????? ??????,<br />
????  ??????? ??????????,<br />
????  ??????????? ???????<br />
????  ??????? ??????????? ???????<br />
????  09 ???????? ??????? ? ??????????? ???????<br />
????  ??? ???????<br />
????  ????????? ??????? ?? ????? ? ???????<br />
????  ??????? ???????<br />
????  ??????? ??????????????? ???????<br />
????  ??????????? ??? ???????<br />
????  ??????????? ??? ???????<br />
????  ?????? -  ?????  - ???????<br />
????  ?????? ???????????? ???????????? ??????????? ???????</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Biny</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65228</link>
		<dc:creator>Biny</dc:creator>
		<pubDate>Thu, 15 Oct 2009 11:12:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65228</guid>
		<description>I'm still wondering who developed dulla virus,i'll b very happy if INSA has something to say abt it.</description>
		<content:encoded><![CDATA[<p>I&#8217;m still wondering who developed dulla virus,i&#8217;ll b very happy if INSA has something to say abt it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2009 by betsy</title>
		<link>http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/#comment-65226</link>
		<dc:creator>betsy</dc:creator>
		<pubDate>Wed, 14 Oct 2009 03:45:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/#comment-65226</guid>
		<description>i downloaded the software like an idiot 2 days ago under my dads credit card. i hope they dont charge ridiculous things to it. i told him to check with his bank and freeze his account. how bad did i screw up? how bad do they charge the cards? how worried should i be?</description>
		<content:encoded><![CDATA[<p>i downloaded the software like an idiot 2 days ago under my dads credit card. i hope they dont charge ridiculous things to it. i told him to check with his bank and freeze his account. how bad did i screw up? how bad do they charge the cards? how worried should i be?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Amaha Fikru</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65225</link>
		<dc:creator>Amaha Fikru</dc:creator>
		<pubDate>Tue, 13 Oct 2009 06:40:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65225</guid>
		<description>The file already corrupted, so how can i recover the excel files?</description>
		<content:encoded><![CDATA[<p>The file already corrupted, so how can i recover the excel files?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Insecure Internet activity. Threat of virus attack! by TrustFighter : Virus Solution and Removal</title>
		<link>http://www.precisesecurity.com/blogs/2009/01/09/insecure-internet-activity-threat-of-virus-attack/#comment-65224</link>
		<dc:creator>TrustFighter : Virus Solution and Removal</dc:creator>
		<pubDate>Tue, 13 Oct 2009 02:39:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/01/09/insecure-internet-activity-threat-of-virus-attack/#comment-65224</guid>
		<description>[...] Internet browser that may block users Internet access and instead be redirected to &#8220;Insecure Internet Activity&#8221; page. It will also run its own virus scanner and alert users on loads of infected file. This [...]</description>
		<content:encoded><![CDATA[<p>[...] Internet browser that may block users Internet access and instead be redirected to &#8220;Insecure Internet Activity&#8221; page. It will also run its own virus scanner and alert users on loads of infected file. This [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Email-Worm.Win32.Myd by nadia</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/06/email-wormwin32myd/#comment-65222</link>
		<dc:creator>nadia</dc:creator>
		<pubDate>Tue, 13 Oct 2009 00:54:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/02/06/email-wormwin32myd/#comment-65222</guid>
		<description>no tengo ni idea de como eliminar virus, pero porfavor ayudenme!!! si puden me lo mandan por paso de cada tipo de virus ok =)</description>
		<content:encoded><![CDATA[<p>no tengo ni idea de como eliminar virus, pero porfavor ayudenme!!! si puden me lo mandan por paso de cada tipo de virus ok =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by rational</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65221</link>
		<dc:creator>rational</dc:creator>
		<pubDate>Mon, 12 Oct 2009 22:57:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65221</guid>
		<description>I WANT TO REMOVE FULL HLUSE VIRUS FROM MY PC. I NEEED HELP</description>
		<content:encoded><![CDATA[<p>I WANT TO REMOVE FULL HLUSE VIRUS FROM MY PC. I NEEED HELP</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by ceri</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65219</link>
		<dc:creator>ceri</dc:creator>
		<pubDate>Mon, 12 Oct 2009 13:02:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65219</guid>
		<description>I went to the microsoft site sorted it straight away</description>
		<content:encoded><![CDATA[<p>I went to the microsoft site sorted it straight away</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pyagcore by mohamed</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65217</link>
		<dc:creator>mohamed</dc:creator>
		<pubDate>Sun, 11 Oct 2009 19:38:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65217</guid>
		<description>hi, after removing it from the task manager, where do you browse the C/:PROGRAM FILES/KIWEE TOOLBAR  ??</description>
		<content:encoded><![CDATA[<p>hi, after removing it from the task manager, where do you browse the C/:PROGRAM FILES/KIWEE TOOLBAR  ??</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Me</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65216</link>
		<dc:creator>Me</dc:creator>
		<pubDate>Sat, 10 Oct 2009 22:30:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65216</guid>
		<description>AVG works</description>
		<content:encoded><![CDATA[<p>AVG works</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by uuzoo</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65215</link>
		<dc:creator>uuzoo</dc:creator>
		<pubDate>Sat, 10 Oct 2009 12:08:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65215</guid>
		<description>This is a nasty virus! I got hit with it a couple of weeks ago from downloading programs. My antivirus at the time ( avast) detected it but couldn't do nothing about it. So, I did some research on the net, and was told to download Kaspersky removal tool. It detected it, and was neutralizing it, but the virus was spreading like a forest fire. It got to about 3,000 files infected, and I said forget it. I ended up reformatting and reinstalling OS. It WORKED! What's really interesting is that I didn't know it at the time but my flashdrive was connected in the back of the tower, and it got infected. After reinstalling everything. I realized that my flashdrive was in too. I'm thinking oh no. I ran avast but nothing came up. I've now installed Vipre and ran scan on the flashdrive and it detected and neutralized the virus. Now I'm using Vipre. Been working well.</description>
		<content:encoded><![CDATA[<p>This is a nasty virus! I got hit with it a couple of weeks ago from downloading programs. My antivirus at the time ( avast) detected it but couldn&#8217;t do nothing about it. So, I did some research on the net, and was told to download Kaspersky removal tool. It detected it, and was neutralizing it, but the virus was spreading like a forest fire. It got to about 3,000 files infected, and I said forget it. I ended up reformatting and reinstalling OS. It WORKED! What&#8217;s really interesting is that I didn&#8217;t know it at the time but my flashdrive was connected in the back of the tower, and it got infected. After reinstalling everything. I realized that my flashdrive was in too. I&#8217;m thinking oh no. I ran avast but nothing came up. I&#8217;ve now installed Vipre and ran scan on the flashdrive and it detected and neutralized the virus. Now I&#8217;m using Vipre. Been working well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by kkkohli</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65212</link>
		<dc:creator>kkkohli</dc:creator>
		<pubDate>Sat, 10 Oct 2009 08:50:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65212</guid>
		<description>i was also cheated by this total security software &amp; i paid them usd 78. They pop message said same thing that your computer is under threat &amp; pop up window was neither closing down nor minimising.There message after pop ups said full money will be refunded within 30 days &amp; now there is no adress of any website. even e-mail is coming make on e-mail id provided on e-mail message by which activation key was sent.Can any tell how to get my money back or to whom to complain againest them</description>
		<content:encoded><![CDATA[<p>i was also cheated by this total security software &amp; i paid them usd 78. They pop message said same thing that your computer is under threat &amp; pop up window was neither closing down nor minimising.There message after pop ups said full money will be refunded within 30 days &amp; now there is no adress of any website. even e-mail is coming make on e-mail id provided on e-mail message by which activation key was sent.Can any tell how to get my money back or to whom to complain againest them</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Generic.dx by webmaster</title>
		<link>http://www.precisesecurity.com/blogs/2007/09/26/genericdx/#comment-65211</link>
		<dc:creator>webmaster</dc:creator>
		<pubDate>Sat, 10 Oct 2009 08:30:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/09/26/genericdx/#comment-65211</guid>
		<description>T2 was right, scanning hard drive via USB or Bootable CD is the best way to clean infected hard drive. Booting on the same infected hard disk makes the virus to load on memory and do his things to hide from antivirus programs.

I have brief tutorial how to scan via USB here. Though it requires a tool that cost about $10.
http://www.precisesecurity.com/tools-resources/threat-removal-procedure/scanning-infected-hard-disk-via-usb/</description>
		<content:encoded><![CDATA[<p>T2 was right, scanning hard drive via USB or Bootable CD is the best way to clean infected hard drive. Booting on the same infected hard disk makes the virus to load on memory and do his things to hide from antivirus programs.</p>
<p>I have brief tutorial how to scan via USB here. Though it requires a tool that cost about $10.<br />
<a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/scanning-infected-hard-disk-via-usb/" rel="nofollow">http://www.precisesecurity.com/tools-resources/threat-removal-procedure/scanning-infected-hard-disk-via-usb/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by RHC</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65210</link>
		<dc:creator>RHC</dc:creator>
		<pubDate>Sat, 10 Oct 2009 03:17:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65210</guid>
		<description>Boris or xXtra or anyone else:

Got cryptor months ago, it fried Malabytes, fried sbybot, fried my restore points, AVG picked it up but wouldn't remove it, and the last few weeks AVG won't even run a scan.

Have downloaded Sophos and run a scan.  It has picked up 250 entries, mostly .tmp files starting with UAC (example: C:\WINDOWS\Temp\UAC68d.tmp), but also about two dozen random letter files like hjgruimxbfhqpx.dll.  Sophos doesn't recommend cleaning up any of them.

Do I delete everything, all 250?  Do  just start with the "hjgru" files?  

Any advice would be appreciated.  I've lived with this virus for months, and my system is getting so threadbare that I have a hard time getting the computer to boot at all.</description>
		<content:encoded><![CDATA[<p>Boris or xXtra or anyone else:</p>
<p>Got cryptor months ago, it fried Malabytes, fried sbybot, fried my restore points, AVG picked it up but wouldn&#8217;t remove it, and the last few weeks AVG won&#8217;t even run a scan.</p>
<p>Have downloaded Sophos and run a scan.  It has picked up 250 entries, mostly .tmp files starting with UAC (example: C:\WINDOWS\Temp\UAC68d.tmp), but also about two dozen random letter files like hjgruimxbfhqpx.dll.  Sophos doesn&#8217;t recommend cleaning up any of them.</p>
<p>Do I delete everything, all 250?  Do  just start with the &#8220;hjgru&#8221; files?  </p>
<p>Any advice would be appreciated.  I&#8217;ve lived with this virus for months, and my system is getting so threadbare that I have a hard time getting the computer to boot at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on anykuy.com by pete burke</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/12/anykuycom/#comment-65209</link>
		<dc:creator>pete burke</dc:creator>
		<pubDate>Fri, 09 Oct 2009 16:40:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2481#comment-65209</guid>
		<description>Marcus, you are a star, I have been trying to get that sorted for 11 hours, loads of people with bright ideas, (which don't work). Shame it took me so long to find your post. Many thanks mate. Pete.</description>
		<content:encoded><![CDATA[<p>Marcus, you are a star, I have been trying to get that sorted for 11 hours, loads of people with bright ideas, (which don&#8217;t work). Shame it took me so long to find your post. Many thanks mate. Pete.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2010 by Jay</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65207</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Thu, 08 Oct 2009 15:58:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65207</guid>
		<description>You were dumb enough to purchase it?   moron....  it is due to morons like you that companies release software like this</description>
		<content:encoded><![CDATA[<p>You were dumb enough to purchase it?   moron&#8230;.  it is due to morons like you that companies release software like this</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Windows Security Alert by gaurav gupta</title>
		<link>http://www.precisesecurity.com/blogs/2007/12/27/windows-security-alert/#comment-65206</link>
		<dc:creator>gaurav gupta</dc:creator>
		<pubDate>Thu, 08 Oct 2009 09:46:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/12/27/windows-security-alert/#comment-65206</guid>
		<description>I have got same virus.thanks for this valuable information.</description>
		<content:encoded><![CDATA[<p>I have got same virus.thanks for this valuable information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Ermias</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65205</link>
		<dc:creator>Ermias</dc:creator>
		<pubDate>Thu, 08 Oct 2009 07:19:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65205</guid>
		<description>Please send Tsere dulla Antivrus. My documents are at risk</description>
		<content:encoded><![CDATA[<p>Please send Tsere dulla Antivrus. My documents are at risk</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by itchy</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65204</link>
		<dc:creator>itchy</dc:creator>
		<pubDate>Wed, 07 Oct 2009 23:06:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65204</guid>
		<description>ow also cleaned my external hard drive no problems there. my friend however who apparently didnt have anti-virus. and who waited to long is completely screwed. he cant even dl the avg removal tool</description>
		<content:encoded><![CDATA[<p>ow also cleaned my external hard drive no problems there. my friend however who apparently didnt have anti-virus. and who waited to long is completely screwed. he cant even dl the avg removal tool</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by itchy</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65203</link>
		<dc:creator>itchy</dc:creator>
		<pubDate>Wed, 07 Oct 2009 23:04:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65203</guid>
		<description>i only used kaspersky 2010 and the avg link that was mentioned hxxp://www.avg.com/us.virus-removal.ndi-67762 
and im done.
took me about 2 hours (because my pc was just rebooted there wasnt mutch to scan)</description>
		<content:encoded><![CDATA[<p>i only used kaspersky 2010 and the avg link that was mentioned hxxp://www.avg.com/us.virus-removal.ndi-67762<br />
and im done.<br />
took me about 2 hours (because my pc was just rebooted there wasnt mutch to scan)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Generic.dx by T2</title>
		<link>http://www.precisesecurity.com/blogs/2007/09/26/genericdx/#comment-65202</link>
		<dc:creator>T2</dc:creator>
		<pubDate>Wed, 07 Oct 2009 10:22:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/09/26/genericdx/#comment-65202</guid>
		<description>The best way to get rid of this trojen is to connect infected hard drive to the secondary connector of another pc and run on demand scanner to perform cleanup. The trojan mostly gets attached to cookies.</description>
		<content:encoded><![CDATA[<p>The best way to get rid of this trojen is to connect infected hard drive to the secondary connector of another pc and run on demand scanner to perform cleanup. The trojan mostly gets attached to cookies.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by Fahad</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65201</link>
		<dc:creator>Fahad</dc:creator>
		<pubDate>Wed, 07 Oct 2009 09:59:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65201</guid>
		<description>This program deleted my san andreas file(not folder only the appication) it alse deleted san andreas multiplayer, downloading them will take a long while so please help me out,i also checked the recycle bin</description>
		<content:encoded><![CDATA[<p>This program deleted my san andreas file(not folder only the appication) it alse deleted san andreas multiplayer, downloading them will take a long while so please help me out,i also checked the recycle bin</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by Nate</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65200</link>
		<dc:creator>Nate</dc:creator>
		<pubDate>Tue, 06 Oct 2009 18:15:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65200</guid>
		<description>I got rid of this yesterday! Go to malware bytes.org. When you try to download the virus will try and block it accompanied by a flashing bar at the top of the window. Simply go to the middle of the page where it  will say " if your having trouble downloading click here" and click there. This should let the download go through. Once you install malwarebytes anitmalware, it should fing the virus and remove it. This worked on my computer, so hopefully it will help you.</description>
		<content:encoded><![CDATA[<p>I got rid of this yesterday! Go to malware bytes.org. When you try to download the virus will try and block it accompanied by a flashing bar at the top of the window. Simply go to the middle of the page where it  will say &#8221; if your having trouble downloading click here&#8221; and click there. This should let the download go through. Once you install malwarebytes anitmalware, it should fing the virus and remove it. This worked on my computer, so hopefully it will help you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Downloader.Agent.OSQ by webmaster</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/28/trojan-downloader-agent-osq/#comment-65199</link>
		<dc:creator>webmaster</dc:creator>
		<pubDate>Mon, 05 Oct 2009 13:32:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4072#comment-65199</guid>
		<description>Hi Taufik, I believed credit card can be used on international transactions. Which particular antivirus do you want to purchase?</description>
		<content:encoded><![CDATA[<p>Hi Taufik, I believed credit card can be used on international transactions. Which particular antivirus do you want to purchase?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Downloader.Agent.OSQ by taufik awarsa kesuma</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/28/trojan-downloader-agent-osq/#comment-65198</link>
		<dc:creator>taufik awarsa kesuma</dc:creator>
		<pubDate>Mon, 05 Oct 2009 01:51:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4072#comment-65198</guid>
		<description>I want to buy your security,if my Pc has inpected by vyrus.but I am new residence in Singapore and I can't apply the credit car. Please give the solution how I bu your anti virus,Thanks</description>
		<content:encoded><![CDATA[<p>I want to buy your security,if my Pc has inpected by vyrus.but I am new residence in Singapore and I can&#8217;t apply the credit car. Please give the solution how I bu your anti virus,Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.TDSS.rtk by Kendo</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65196</link>
		<dc:creator>Kendo</dc:creator>
		<pubDate>Fri, 02 Oct 2009 04:00:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65196</guid>
		<description>Try Malwarebytes   mbma   (free download)

Worked a treat for me</description>
		<content:encoded><![CDATA[<p>Try Malwarebytes   mbma   (free download)</p>
<p>Worked a treat for me</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.TDSS.rtk by Kendo</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65195</link>
		<dc:creator>Kendo</dc:creator>
		<pubDate>Fri, 02 Oct 2009 03:59:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65195</guid>
		<description>Hi all ..at last I found a solid if drastic cure for having TDSS.rtk
it appeared after my daughter downloaded some (as she thought) mp3 files. She had saved to desktop, scanned with Spybot and they were announced as clean...moments later , she yelled to come see...jeez , there was a folder with a number of exe files , all disappearing one by one of their own accord after she had opened the first one !
Thereafter , everything went pearshaped..first of all none of my burning software could even see my DVD RW, and when I checked out "problem devices" in Disk management (in XP) , the first thing I saw in horror was just one huge pink block telling me that there were no physical drives present...no partitions ..NOTHING !!
Weird thing was too that windows still worked after a wobbly fashion, desktop all ok etc 
Scanned whole pc and found 8 instances of TDS.rtk (corresponding to the number of files she had downloaded and let loose )
Spybot elected to fix them, apparently, giving the usual green tick success story .....NOT !!  cuz on the second scan , there they were again, all over the place , in registry etc !!
No matter how many scans I did with various software including AVG, spybot , Adaware etc, they ALWAYS reappeared....PANIC !!!
Got a grip of myself and thought I'd sneak up behind this sucker , by going in XP in Safe Mode ... no way , I couldnt even get there..it just went right on into windows welcome every time !!
In frustration I decided to bite the bullet and go for a full reinstall...and guess what , no matter which way I tried , the install failed , mainly cuz Widows installer couldnt find a drive !!
Trawled loads of sites, looking for help and advice...willing to give anything a go .
Found an article that recommended downloading and installing Malwarebytes  mbam  (freebie)....
Nothing to lose , I gave it a go .....and guess what ? First scan showed up the same 8 instances of our wee friend TDSS.rtk...and mbam offered to do the biz on them.   
Fingers crossed and butt cheeks clenched, I hit the button and sure enough , it apparently did its thing.
Second scan run , and again ..guess what  ?? 
TDSS.rtk had been given the heave ho! Call me a cynic , or just paranoid , but I ran a third scan...still clean...fourth one too.
Went back into Disk Management , and lo and behold , there were all my drives and partitions , and not a hint of pink in sight.
Just to be on the safe side though , and having had a poke around in the registry, I decided to follow on my plan to reinstall, just in case TDSS was hiding with its tail between its legs, preparing an even nastier sting in its tail . Drastic measure, I know , but......
Result  - full clean reinstallation wthout a hitch. !!!
Aye , even though I'm Scottish , I broke out the wallet , bought meself a wee dram or two at the local pub and drank the health of those fine dudes down at Malwarebytes .
Slainte !!!
Hope this helps ...if not , there's always the Samaritans</description>
		<content:encoded><![CDATA[<p>Hi all ..at last I found a solid if drastic cure for having TDSS.rtk<br />
it appeared after my daughter downloaded some (as she thought) mp3 files. She had saved to desktop, scanned with Spybot and they were announced as clean&#8230;moments later , she yelled to come see&#8230;jeez , there was a folder with a number of exe files , all disappearing one by one of their own accord after she had opened the first one !<br />
Thereafter , everything went pearshaped..first of all none of my burning software could even see my DVD RW, and when I checked out &#8220;problem devices&#8221; in Disk management (in XP) , the first thing I saw in horror was just one huge pink block telling me that there were no physical drives present&#8230;no partitions ..NOTHING !!<br />
Weird thing was too that windows still worked after a wobbly fashion, desktop all ok etc<br />
Scanned whole pc and found 8 instances of TDS.rtk (corresponding to the number of files she had downloaded and let loose )<br />
Spybot elected to fix them, apparently, giving the usual green tick success story &#8230;..NOT !!  cuz on the second scan , there they were again, all over the place , in registry etc !!<br />
No matter how many scans I did with various software including AVG, spybot , Adaware etc, they ALWAYS reappeared&#8230;.PANIC !!!<br />
Got a grip of myself and thought I&#8217;d sneak up behind this sucker , by going in XP in Safe Mode &#8230; no way , I couldnt even get there..it just went right on into windows welcome every time !!<br />
In frustration I decided to bite the bullet and go for a full reinstall&#8230;and guess what , no matter which way I tried , the install failed , mainly cuz Widows installer couldnt find a drive !!<br />
Trawled loads of sites, looking for help and advice&#8230;willing to give anything a go .<br />
Found an article that recommended downloading and installing Malwarebytes  mbam  (freebie)&#8230;.<br />
Nothing to lose , I gave it a go &#8230;..and guess what ? First scan showed up the same 8 instances of our wee friend TDSS.rtk&#8230;and mbam offered to do the biz on them.<br />
Fingers crossed and butt cheeks clenched, I hit the button and sure enough , it apparently did its thing.<br />
Second scan run , and again ..guess what  ??<br />
TDSS.rtk had been given the heave ho! Call me a cynic , or just paranoid , but I ran a third scan&#8230;still clean&#8230;fourth one too.<br />
Went back into Disk Management , and lo and behold , there were all my drives and partitions , and not a hint of pink in sight.<br />
Just to be on the safe side though , and having had a poke around in the registry, I decided to follow on my plan to reinstall, just in case TDSS was hiding with its tail between its legs, preparing an even nastier sting in its tail . Drastic measure, I know , but&#8230;&#8230;<br />
Result  - full clean reinstallation wthout a hitch. !!!<br />
Aye , even though I&#8217;m Scottish , I broke out the wallet , bought meself a wee dram or two at the local pub and drank the health of those fine dudes down at Malwarebytes .<br />
Slainte !!!<br />
Hope this helps &#8230;if not , there&#8217;s always the Samaritans</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Kyle</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65194</link>
		<dc:creator>Kyle</dc:creator>
		<pubDate>Fri, 02 Oct 2009 00:46:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65194</guid>
		<description>I got peggle nights and i put it on my flash drive  and when i tried running it it said it had this virus and i was like wtf -.-. now i cant play peggle nights :(</description>
		<content:encoded><![CDATA[<p>I got peggle nights and i put it on my flash drive  and when i tried running it it said it had this virus and i was like wtf -.-. now i cant play peggle nights :(</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by Blueberry</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65193</link>
		<dc:creator>Blueberry</dc:creator>
		<pubDate>Thu, 01 Oct 2009 17:50:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65193</guid>
		<description>thanks Alexander Mc, I have removed it :)</description>
		<content:encoded><![CDATA[<p>thanks Alexander Mc, I have removed it :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by SChalice</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65191</link>
		<dc:creator>SChalice</dc:creator>
		<pubDate>Thu, 01 Oct 2009 02:34:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65191</guid>
		<description>This virus can get on compact flash sticks. You'll need to be sure to wipe all those suckers clean or just throw them away if unsure..</description>
		<content:encoded><![CDATA[<p>This virus can get on compact flash sticks. You&#8217;ll need to be sure to wipe all those suckers clean or just throw them away if unsure..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by Lizzy</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65190</link>
		<dc:creator>Lizzy</dc:creator>
		<pubDate>Wed, 30 Sep 2009 13:49:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65190</guid>
		<description>i want to remove FullHouse drive virus from my PC. please i want something free. i am using AVG antivirus. please help me.</description>
		<content:encoded><![CDATA[<p>i want to remove FullHouse drive virus from my PC. please i want something free. i am using AVG antivirus. please help me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dropper.Bravix.A by TnMike</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/20/dropperbravixa/#comment-65189</link>
		<dc:creator>TnMike</dc:creator>
		<pubDate>Wed, 30 Sep 2009 13:46:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/20/dropperbravixa/#comment-65189</guid>
		<description>MalwareBytes will get rid of the virus</description>
		<content:encoded><![CDATA[<p>MalwareBytes will get rid of the virus</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.TDSS.rtk by Jzone09</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65185</link>
		<dc:creator>Jzone09</dc:creator>
		<pubDate>Mon, 28 Sep 2009 05:03:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65185</guid>
		<description>I have also found Win32.TDSS.rtk using spybot, I tihn kthis is the reason why my computer keeps restarting at startup, I can only run it by booting it from safe mode   with netowrking, what is the fix?</description>
		<content:encoded><![CDATA[<p>I have also found Win32.TDSS.rtk using spybot, I tihn kthis is the reason why my computer keeps restarting at startup, I can only run it by booting it from safe mode   with netowrking, what is the fix?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pyagcore by eithel</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65176</link>
		<dc:creator>eithel</dc:creator>
		<pubDate>Fri, 25 Sep 2009 22:55:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65176</guid>
		<description>tengo problemas con el windows police pro, quiero saber como elominarlo de mi computadora, no me deja entrar a internet. expliquenme bien por favor eithel</description>
		<content:encoded><![CDATA[<p>tengo problemas con el windows police pro, quiero saber como elominarlo de mi computadora, no me deja entrar a internet. expliquenme bien por favor eithel</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by jess m</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65173</link>
		<dc:creator>jess m</dc:creator>
		<pubDate>Thu, 24 Sep 2009 14:14:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65173</guid>
		<description>Ok, so we did everything that was listed and after running all the spyware/virus detection programs we have not found ANY virus on the computer however, it will still not let us access the internet using an ethernet cord.  Anyone else have this issue?  Were you able to resolve it?</description>
		<content:encoded><![CDATA[<p>Ok, so we did everything that was listed and after running all the spyware/virus detection programs we have not found ANY virus on the computer however, it will still not let us access the internet using an ethernet cord.  Anyone else have this issue?  Were you able to resolve it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Dawit</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65172</link>
		<dc:creator>Dawit</dc:creator>
		<pubDate>Thu, 24 Sep 2009 08:43:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65172</guid>
		<description>Amanuel Kenna and AreMoh.

I think you two know how to recover pdf files that have been infected by the dulla virus using hex editor. I tried several times and I didn't succeed. Please help. I am really anxious.</description>
		<content:encoded><![CDATA[<p>Amanuel Kenna and AreMoh.</p>
<p>I think you two know how to recover pdf files that have been infected by the dulla virus using hex editor. I tried several times and I didn&#8217;t succeed. Please help. I am really anxious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by expertanalyzer</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65171</link>
		<dc:creator>expertanalyzer</dc:creator>
		<pubDate>Tue, 22 Sep 2009 23:27:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65171</guid>
		<description>send me the teddy afro virus infected file sample i am expert virus anlayzer and i love to help people in my free time if you have teddy afro virus infected file attach and send it to my email: father@safe-mail.net  i will give you free removal tool for free.
thanks.</description>
		<content:encoded><![CDATA[<p>send me the teddy afro virus infected file sample i am expert virus anlayzer and i love to help people in my free time if you have teddy afro virus infected file attach and send it to my email: <a href="mailto:father@safe-mail.net">father@safe-mail.net</a>  i will give you free removal tool for free.<br />
thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rapid Antivirus Firewall has blocked a program from accessing the Internet by Tolebi</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/17/rapid-antivirus-firewall-has-blocked-a-program-from-accessing-the-internet/#comment-65170</link>
		<dc:creator>Tolebi</dc:creator>
		<pubDate>Tue, 22 Sep 2009 22:24:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3825#comment-65170</guid>
		<description>U menya net antivirusa!Kak mojno udalit total security</description>
		<content:encoded><![CDATA[<p>U menya net antivirusa!Kak mojno udalit total security</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.Tanatos.m by Nasser</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/31/win32tanatosm/#comment-65168</link>
		<dc:creator>Nasser</dc:creator>
		<pubDate>Tue, 22 Sep 2009 18:10:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/31/win32tanatosm/#comment-65168</guid>
		<description>I am suffering the same problem with win32/Tanatos.M It has even disabled the exe of AVG and when I click the AVG icon on desktop. It is showing the 'browse  cancel' dailog box.

From the above discussion I can see a mere discussion about AVG, but no solution. Can anyone please help me with the win32/tanatos.m removal tool?????

Thanks in Advance.
Nasser</description>
		<content:encoded><![CDATA[<p>I am suffering the same problem with win32/Tanatos.M It has even disabled the exe of AVG and when I click the AVG icon on desktop. It is showing the &#8216;browse  cancel&#8217; dailog box.</p>
<p>From the above discussion I can see a mere discussion about AVG, but no solution. Can anyone please help me with the win32/tanatos.m removal tool?????</p>
<p>Thanks in Advance.<br />
Nasser</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by john</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65167</link>
		<dc:creator>john</dc:creator>
		<pubDate>Tue, 22 Sep 2009 16:08:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65167</guid>
		<description>your solution for total security

install revo uninstaller, get it from download.com, run uninstaller in advance mode and follow the prompts, select all files as per screen, uninstall and reboot. Install avira / update,get it from download.com and run full scan, avira will pick up the trojan. Go to program files on your c drive and delete the TS folder, if this folder is locked boot in safe mode F8 and delete the folder.</description>
		<content:encoded><![CDATA[<p>your solution for total security</p>
<p>install revo uninstaller, get it from download.com, run uninstaller in advance mode and follow the prompts, select all files as per screen, uninstall and reboot. Install avira / update,get it from download.com and run full scan, avira will pick up the trojan. Go to program files on your c drive and delete the TS folder, if this folder is locked boot in safe mode F8 and delete the folder.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on W32/Scribble-B by w32 scribble-b</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/23/w32scribble-b/#comment-65165</link>
		<dc:creator>w32 scribble-b</dc:creator>
		<pubDate>Tue, 22 Sep 2009 13:03:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3987#comment-65165</guid>
		<description>how is this virus removed?</description>
		<content:encoded><![CDATA[<p>how is this virus removed?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Joe</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65161</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Sun, 20 Sep 2009 22:01:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65161</guid>
		<description>This virus infected my old HD, so I had no choice but to reinstall WinXP. Then today I accidently clicked an old executable on that HD and the virus is reinfected me. I was in no mood to reinstall so this is how I dealt with it.

DO NOT START ANY PROGRAMS YET, THEY WILL GET INFECTED

1. Pull the plug on your internet connection, because it will try to connect to its website (jL.chura.pl and maybe others) and download more crap to your PC

2. Go to Task Manager and kill ANY program that looks unfamiliar (this can be tricky, if you're a not a computer geek)

3. Run services.msc and you'll see at least 2 services running which have NO description. Stop them and then disable them (by right clicking). Also stop and disable Remote Access Connection Manager, and Background Intelligent Transfer System, if they are running. These are Windows processes, but I think the virus activates them.

4. Repeat step 2 just in case

5. Now you have a choice:
a)You can run restore, but you have to be very sure that the restore is clean
b) run your antivirus. A full scan is preferable, but at least C:\Windows\ and C:\Program Files\. The virus infected only logonui.exe in my case and changed the HOSTS file, and created a temporary file in the WINDOWS\TEMP directory, but nothing else. However, if you ran any program while the virus was loaded, that program will be infected too.

This is the stage on which I am myself. The virus is removed but my system is still a bit screwed up, because everytime I reboot a hidden process iexplore.exe is started, except it's not connecting anywhere. I'm not sure what's starting it, but I dealt with it by killing the process and moving iexplore.exe to a temporary folder.</description>
		<content:encoded><![CDATA[<p>This virus infected my old HD, so I had no choice but to reinstall WinXP. Then today I accidently clicked an old executable on that HD and the virus is reinfected me. I was in no mood to reinstall so this is how I dealt with it.</p>
<p>DO NOT START ANY PROGRAMS YET, THEY WILL GET INFECTED</p>
<p>1. Pull the plug on your internet connection, because it will try to connect to its website (jL.chura.pl and maybe others) and download more crap to your PC</p>
<p>2. Go to Task Manager and kill ANY program that looks unfamiliar (this can be tricky, if you&#8217;re a not a computer geek)</p>
<p>3. Run services.msc and you&#8217;ll see at least 2 services running which have NO description. Stop them and then disable them (by right clicking). Also stop and disable Remote Access Connection Manager, and Background Intelligent Transfer System, if they are running. These are Windows processes, but I think the virus activates them.</p>
<p>4. Repeat step 2 just in case</p>
<p>5. Now you have a choice:<br />
a)You can run restore, but you have to be very sure that the restore is clean<br />
b) run your antivirus. A full scan is preferable, but at least C:\Windows\ and C:\Program Files\. The virus infected only logonui.exe in my case and changed the HOSTS file, and created a temporary file in the WINDOWS\TEMP directory, but nothing else. However, if you ran any program while the virus was loaded, that program will be infected too.</p>
<p>This is the stage on which I am myself. The virus is removed but my system is still a bit screwed up, because everytime I reboot a hidden process iexplore.exe is started, except it&#8217;s not connecting anywhere. I&#8217;m not sure what&#8217;s starting it, but I dealt with it by killing the process and moving iexplore.exe to a temporary folder.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Fennec the sysop</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65160</link>
		<dc:creator>Fennec the sysop</dc:creator>
		<pubDate>Sun, 20 Sep 2009 20:07:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65160</guid>
		<description>This virus is a pain but I have it contained ,my router is a good firewall and I have it set to block all incoming connections on port 65520 and all outgoing connections to Proxima.ircgalaxy.pl so that means the attackers cant use it I have also found that using IRC to connect to my local machine on port 65520 gives you control of this virus so now I am able to change the options and on my machine it only infects explorer.exe too bad it dosent have a disinfect command</description>
		<content:encoded><![CDATA[<p>This virus is a pain but I have it contained ,my router is a good firewall and I have it set to block all incoming connections on port 65520 and all outgoing connections to Proxima.ircgalaxy.pl so that means the attackers cant use it I have also found that using IRC to connect to my local machine on port 65520 gives you control of this virus so now I am able to change the options and on my machine it only infects explorer.exe too bad it dosent have a disinfect command</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by glen</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65159</link>
		<dc:creator>glen</dc:creator>
		<pubDate>Sun, 20 Sep 2009 07:55:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65159</guid>
		<description>Sophos anti-rootkit works magic. all other anti-spyware softwares couldn't solve the problem.</description>
		<content:encoded><![CDATA[<p>Sophos anti-rootkit works magic. all other anti-spyware softwares couldn&#8217;t solve the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by amanuel girma (haramaya university)</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65158</link>
		<dc:creator>amanuel girma (haramaya university)</dc:creator>
		<pubDate>Sat, 19 Sep 2009 22:25:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65158</guid>
		<description>HOW TO PARTIAL REPAIR OFFICE DOCUMENTS INFECTED WIZ “~dulla^@204~” VIRUS
Before you start this tutorial clean your pc wiz anti dulla software I recommend
Emopia® Virus Removal Pack (freeware) from emopia.com
	Tools needed for this tutorial
•	Notepad ++ (absolutely free download and install this software)
•	Office 2007
•	An infected file 
1.	Right click on the infected office document &gt;&gt;click “edit with notepad ++” now the document will be opened in notepad++ window
2.	Click on “search” from the menu &gt;&gt;click on” find” &gt;&gt; click on “replace” tab
3.	Type ‘~dulla^@204~\x00’ (without the quote) on “find what” box&gt;&gt; check the “regular expression” check box &gt;&gt; click on “find next” tab &gt;&gt; click on “replace all” tab &gt;&gt; ok &gt;&gt; done.
4.	Click done &gt;&gt; click on the” save” from menu &gt;&gt; close notepad ++ &gt;&gt; open the infected(corrupted) document when a dialog box appear click yes
any question please email me :amangirma@gmail.com</description>
		<content:encoded><![CDATA[<p>HOW TO PARTIAL REPAIR OFFICE DOCUMENTS INFECTED WIZ “~dulla^@204~” VIRUS<br />
Before you start this tutorial clean your pc wiz anti dulla software I recommend<br />
Emopia® Virus Removal Pack (freeware) from emopia.com<br />
	Tools needed for this tutorial<br />
•	Notepad ++ (absolutely free download and install this software)<br />
•	Office 2007<br />
•	An infected file<br />
1.	Right click on the infected office document &gt;&gt;click “edit with notepad ++” now the document will be opened in notepad++ window<br />
2.	Click on “search” from the menu &gt;&gt;click on” find” &gt;&gt; click on “replace” tab<br />
3.	Type ‘~dulla^@204~\x00’ (without the quote) on “find what” box&gt;&gt; check the “regular expression” check box &gt;&gt; click on “find next” tab &gt;&gt; click on “replace all” tab &gt;&gt; ok &gt;&gt; done.<br />
4.	Click done &gt;&gt; click on the” save” from menu &gt;&gt; close notepad ++ &gt;&gt; open the infected(corrupted) document when a dialog box appear click yes<br />
any question please email me :amangirma@gmail.com</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by endy</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65157</link>
		<dc:creator>endy</dc:creator>
		<pubDate>Sat, 19 Sep 2009 07:15:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65157</guid>
		<description>in reply to ujjawal goel

the whole total security lifetime package is a scam! they got your credit card information, so if i were you, call your bank and let them know what happened.</description>
		<content:encoded><![CDATA[<p>in reply to ujjawal goel</p>
<p>the whole total security lifetime package is a scam! they got your credit card information, so if i were you, call your bank and let them know what happened.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on sc.videofreeforonline.com by Nalaka</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/14/scvideofreeforonlinecom/#comment-65156</link>
		<dc:creator>Nalaka</dc:creator>
		<pubDate>Sat, 19 Sep 2009 06:11:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/14/scvideofreeforonlinecom/#comment-65156</guid>
		<description>It worked with Avast virus scan. It's a Free ware Home package. I am very much relieved after this.</description>
		<content:encoded><![CDATA[<p>It worked with Avast virus scan. It&#8217;s a Free ware Home package. I am very much relieved after this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by Stephanie</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65155</link>
		<dc:creator>Stephanie</dc:creator>
		<pubDate>Fri, 18 Sep 2009 18:25:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65155</guid>
		<description>combofix is the only thing I have seen that removes it. download.com has this file. Malware Bytes is also suppose to remove but it would not on a couple of our computers.</description>
		<content:encoded><![CDATA[<p>combofix is the only thing I have seen that removes it. download.com has this file. Malware Bytes is also suppose to remove but it would not on a couple of our computers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by PHILIP</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65154</link>
		<dc:creator>PHILIP</dc:creator>
		<pubDate>Thu, 17 Sep 2009 11:15:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65154</guid>
		<description>I want to remove FullHouse Drive virus from my PC. please help me.</description>
		<content:encoded><![CDATA[<p>I want to remove FullHouse Drive virus from my PC. please help me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Jiru</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65153</link>
		<dc:creator>Jiru</dc:creator>
		<pubDate>Thu, 17 Sep 2009 10:22:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65153</guid>
		<description>Ther is a virus named Teddy afro which has characterstic feature of hiding your files and disabling ur cd driver...it is even difficult to remove it with command...i have tried avira, kaspersky,macaffe,avg,and NOD..non of them could remove that.You guys do you have any solution for that?EMOPIA ..it is just fake..it cant detect any virus...</description>
		<content:encoded><![CDATA[<p>Ther is a virus named Teddy afro which has characterstic feature of hiding your files and disabling ur cd driver&#8230;it is even difficult to remove it with command&#8230;i have tried avira, kaspersky,macaffe,avg,and NOD..non of them could remove that.You guys do you have any solution for that?EMOPIA ..it is just fake..it cant detect any virus&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by war10ck</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65152</link>
		<dc:creator>war10ck</dc:creator>
		<pubDate>Wed, 16 Sep 2009 07:49:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65152</guid>
		<description>Download ComboFix and run on your pc..
I am sure FullHouse icon on your desktop can be delete.
Tested by me and it's works.

Click above to downlaod ComboFix:-
hxxp://download.bleepingcomputer.com/sUBs/ComboFix.exe</description>
		<content:encoded><![CDATA[<p>Download ComboFix and run on your pc..<br />
I am sure FullHouse icon on your desktop can be delete.<br />
Tested by me and it&#8217;s works.</p>
<p>Click above to downlaod ComboFix:-<br />
hxxp://download.bleepingcomputer.com/sUBs/ComboFix.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pyagcore by ORNELLA</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65151</link>
		<dc:creator>ORNELLA</dc:creator>
		<pubDate>Wed, 16 Sep 2009 07:10:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65151</guid>
		<description>MANY THANKS.. just when I was losing the battle I won the war with this computer .. children are much more easier than technology, haha... but I'm glad I succeded with your help!

This program is great!! it worked!! 

Thanks again.</description>
		<content:encoded><![CDATA[<p>MANY THANKS.. just when I was losing the battle I won the war with this computer .. children are much more easier than technology, haha&#8230; but I&#8217;m glad I succeded with your help!</p>
<p>This program is great!! it worked!! </p>
<p>Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Your computer is infected! by John</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/23/your-computer-is-infected/#comment-65150</link>
		<dc:creator>John</dc:creator>
		<pubDate>Wed, 16 Sep 2009 05:08:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/23/your-computer-is-infected/#comment-65150</guid>
		<description>Hay Garrett
Turn off your restore and dump it then turn it back on this bugger hides in the hidden files like System volume information file. Most of this is your restore files. If you don't want to dump your restore you'll need to make the file accessable so malbytes can get at it.</description>
		<content:encoded><![CDATA[<p>Hay Garrett<br />
Turn off your restore and dump it then turn it back on this bugger hides in the hidden files like System volume information file. Most of this is your restore files. If you don&#8217;t want to dump your restore you&#8217;ll need to make the file accessable so malbytes can get at it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by hoangson dinh</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65148</link>
		<dc:creator>hoangson dinh</dc:creator>
		<pubDate>Tue, 15 Sep 2009 13:52:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65148</guid>
		<description>Response 78 saved my computer.
Thanks to precisesecurity.com, Sophos Anti-Rootkit, Malwarebytes, and Superantispyware.
Thanks to everyone.</description>
		<content:encoded><![CDATA[<p>Response 78 saved my computer.<br />
Thanks to precisesecurity.com, Sophos Anti-Rootkit, Malwarebytes, and Superantispyware.<br />
Thanks to everyone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Abdulkerim</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65147</link>
		<dc:creator>Abdulkerim</dc:creator>
		<pubDate>Tue, 15 Sep 2009 12:02:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65147</guid>
		<description>People! Get over it! There is no method to recover corrupted files, you can see the reason on facebook, just go to emopia.com (they are the one who made emopia virus remover, and are professionals) and join their facebook page and in the discussion board, you can read the reason why dulla corrupted files can't be recovered.</description>
		<content:encoded><![CDATA[<p>People! Get over it! There is no method to recover corrupted files, you can see the reason on facebook, just go to emopia.com (they are the one who made emopia virus remover, and are professionals) and join their facebook page and in the discussion board, you can read the reason why dulla corrupted files can&#8217;t be recovered.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on [Site] is BANNED you fool, The adminstrators didn&#8217;t write this program guess who did??&#8221; by emily</title>
		<link>http://www.precisesecurity.com/blogs/2007/10/20/site-is-banned-you-fool-the-adminstrators-didnt-write-this-program-guess-who-did/#comment-65146</link>
		<dc:creator>emily</dc:creator>
		<pubDate>Tue, 15 Sep 2009 08:33:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/10/20/site-is-banned-you-fool-the-adminstrators-didnt-write-this-program-guess-who-did/#comment-65146</guid>
		<description>thx ps i tried c:\heap41a and it really works!!!</description>
		<content:encoded><![CDATA[<p>thx ps i tried c:\heap41a and it really works!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by ujjawal goel</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65145</link>
		<dc:creator>ujjawal goel</dc:creator>
		<pubDate>Tue, 15 Sep 2009 04:13:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65145</guid>
		<description>i had purchased the total security lifetime package, but they have cheated me. they charged USD 99.00 and i did not recieve any code to activate. please inform me what can be done. 
i am very unhappy.</description>
		<content:encoded><![CDATA[<p>i had purchased the total security lifetime package, but they have cheated me. they charged USD 99.00 and i did not recieve any code to activate. please inform me what can be done.<br />
i am very unhappy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pyagcore by alfredo</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65144</link>
		<dc:creator>alfredo</dc:creator>
		<pubDate>Sun, 13 Sep 2009 20:49:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65144</guid>
		<description>hola
espero que me ayuden con este problema que tengo con mi computadora este es el problema:
es que cada que intento abrir el windos Live Messenger
NO se puede por que dice:

pyagscore.searchdetection
['Traceback (most recent call last):/n',' File"c://pyagcore//pyagcore/_init_.py", line 3, in /n',ImportError: NO module named shell/n']

nesesito que me digan que significa y por que causa sucedio esto y tambien como solucionar este problema por que ya me quiero conectar en windows live messenger si me puden ayudar?

ESPERARE SU RESPUESTA SII!

¡muchas GRACIAS por atenderme!</description>
		<content:encoded><![CDATA[<p>hola<br />
espero que me ayuden con este problema que tengo con mi computadora este es el problema:<br />
es que cada que intento abrir el windos Live Messenger<br />
NO se puede por que dice:</p>
<p>pyagscore.searchdetection<br />
['Traceback (most recent call last):/n',' File"c://pyagcore//pyagcore/_init_.py", line 3, in /n',ImportError: NO module named shell/n']</p>
<p>nesesito que me digan que significa y por que causa sucedio esto y tambien como solucionar este problema por que ya me quiero conectar en windows live messenger si me puden ayudar?</p>
<p>ESPERARE SU RESPUESTA SII!</p>
<p>¡muchas GRACIAS por atenderme!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Anti-Virus Number-1 by Megan</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/17/anti-virus-number-1/#comment-65142</link>
		<dc:creator>Megan</dc:creator>
		<pubDate>Fri, 11 Sep 2009 22:41:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3092#comment-65142</guid>
		<description>is there a way to get my money back?</description>
		<content:encoded><![CDATA[<p>is there a way to get my money back?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Kiwee Toolbar by Kelley</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/kiwee-toolbar/#comment-65141</link>
		<dc:creator>Kelley</dc:creator>
		<pubDate>Fri, 11 Sep 2009 20:24:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/kiwee-toolbar/#comment-65141</guid>
		<description>I have a vista 64 bit and had this problem awhile ago. the unlocker thing doesnt really work for vista 64 bit. You have to put your comp in safe mode and delete the file while your in safe mode. best of luck!</description>
		<content:encoded><![CDATA[<p>I have a vista 64 bit and had this problem awhile ago. the unlocker thing doesnt really work for vista 64 bit. You have to put your comp in safe mode and delete the file while your in safe mode. best of luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on STOP! Adware Detected by megan fox</title>
		<link>http://www.precisesecurity.com/blogs/2008/07/03/stop-adware-detected/#comment-65140</link>
		<dc:creator>megan fox</dc:creator>
		<pubDate>Fri, 11 Sep 2009 15:41:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/07/03/stop-adware-detected/#comment-65140</guid>
		<description>Sign: umsun Hello!!! rcuwwymhyw and 48ssgfhphzye and 1462I love your site.  :) Love design!!! I just came across your blog and wanted to say that Ive really enjoyed browsing your blog posts.</description>
		<content:encoded><![CDATA[<p>Sign: umsun Hello!!! rcuwwymhyw and 48ssgfhphzye and 1462I love your site.  :) Love design!!! I just came across your blog and wanted to say that Ive really enjoyed browsing your blog posts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dropper.Bravix.A by Jeroen</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/20/dropperbravixa/#comment-65138</link>
		<dc:creator>Jeroen</dc:creator>
		<pubDate>Fri, 11 Sep 2009 15:25:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/20/dropperbravixa/#comment-65138</guid>
		<description>Yes, correct, AVG 8 detects it, but does not remove it. Does anybody have a trusted removal tool on how to get rid of this trojan? I got rid of AVG and used the latest Norton A.V., but that is not abel to completely erase the trojan either. True, it blocks all the outgoing spam, but that's it. It does not completely erase the Dropper. Bravix.

HELP!!</description>
		<content:encoded><![CDATA[<p>Yes, correct, AVG 8 detects it, but does not remove it. Does anybody have a trusted removal tool on how to get rid of this trojan? I got rid of AVG and used the latest Norton A.V., but that is not abel to completely erase the trojan either. True, it blocks all the outgoing spam, but that&#8217;s it. It does not completely erase the Dropper. Bravix.</p>
<p>HELP!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Boris</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65137</link>
		<dc:creator>Boris</dc:creator>
		<pubDate>Fri, 11 Sep 2009 14:26:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65137</guid>
		<description>Im glad that someone have found quicker help with my recommendation (#73), cause the fighf with virus took me over 90 hours before i found the Sophos Anti-rootkit.</description>
		<content:encoded><![CDATA[<p>Im glad that someone have found quicker help with my recommendation (#73), cause the fighf with virus took me over 90 hours before i found the Sophos Anti-rootkit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Agent.ODG by Pipo</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/22/win32agentodg/#comment-65136</link>
		<dc:creator>Pipo</dc:creator>
		<pubDate>Fri, 11 Sep 2009 08:16:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3278#comment-65136</guid>
		<description>Use GMR or Dr Web-CureIt
;)</description>
		<content:encoded><![CDATA[<p>Use GMR or Dr Web-CureIt<br />
;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Total Security by Ian Heisel</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/21/total-security/#comment-65135</link>
		<dc:creator>Ian Heisel</dc:creator>
		<pubDate>Thu, 10 Sep 2009 18:17:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3166#comment-65135</guid>
		<description>I need a customer service number to get my money back, anyone who has a number would be appreciated</description>
		<content:encoded><![CDATA[<p>I need a customer service number to get my money back, anyone who has a number would be appreciated</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Malware Activity Rises in August 2009 by mike</title>
		<link>http://www.precisesecurity.com/blogs/2009/09/04/malware-activity-rises-in-august-2009/#comment-65133</link>
		<dc:creator>mike</dc:creator>
		<pubDate>Thu, 10 Sep 2009 16:48:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4329#comment-65133</guid>
		<description>I recently got the cryptor virus and shuer2 trojan. I've tried system restore but i get message that it has been disabled through group user policy. Does anybody have an suggestions as to how to get around this and where to look in my registry to remove these problems. My antivirus isn't removing them. Thanks</description>
		<content:encoded><![CDATA[<p>I recently got the cryptor virus and shuer2 trojan. I&#8217;ve tried system restore but i get message that it has been disabled through group user policy. Does anybody have an suggestions as to how to get around this and where to look in my registry to remove these problems. My antivirus isn&#8217;t removing them. Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on STOP! Adware Detected by angelina jolie</title>
		<link>http://www.precisesecurity.com/blogs/2008/07/03/stop-adware-detected/#comment-65132</link>
		<dc:creator>angelina jolie</dc:creator>
		<pubDate>Thu, 10 Sep 2009 16:13:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/07/03/stop-adware-detected/#comment-65132</guid>
		<description>I love your site.  :) Love design!!! I just came across your blog and wanted to say that I?ve really enjoyed browsing your blog posts. Sign: ndsam</description>
		<content:encoded><![CDATA[<p>I love your site.  :) Love design!!! I just came across your blog and wanted to say that I?ve really enjoyed browsing your blog posts. Sign: ndsam</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on AntivirusPro 2009 by angelina jolie</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/01/antiviruspro-2009/#comment-65131</link>
		<dc:creator>angelina jolie</dc:creator>
		<pubDate>Thu, 10 Sep 2009 16:12:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/01/antiviruspro-2009/#comment-65131</guid>
		<description>I love your site.  :) Love design!!! I just came across your blog and wanted to say that I?ve really enjoyed browsing your blog posts. Sign: ndsam</description>
		<content:encoded><![CDATA[<p>I love your site.  :) Love design!!! I just came across your blog and wanted to say that I?ve really enjoyed browsing your blog posts. Sign: ndsam</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on STOP! Adware Detected by sandrar</title>
		<link>http://www.precisesecurity.com/blogs/2008/07/03/stop-adware-detected/#comment-65130</link>
		<dc:creator>sandrar</dc:creator>
		<pubDate>Thu, 10 Sep 2009 12:55:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/07/03/stop-adware-detected/#comment-65130</guid>
		<description>Hi! I was surfing and found your blog post... nice! I love your blog.  :) Cheers! Sandra. R.</description>
		<content:encoded><![CDATA[<p>Hi! I was surfing and found your blog post&#8230; nice! I love your blog.  :) Cheers! Sandra. R.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Sheur2.gnw by jagdish</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2-gnw/#comment-65129</link>
		<dc:creator>jagdish</dc:creator>
		<pubDate>Thu, 10 Sep 2009 07:08:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2gnw/#comment-65129</guid>
		<description>i have a trojan horse SHeur2.BCBT on my pc....need help to remove it...anyone kind enough?</description>
		<content:encoded><![CDATA[<p>i have a trojan horse SHeur2.BCBT on my pc&#8230;.need help to remove it&#8230;anyone kind enough?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.TDSS.rtk by Spetto</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65128</link>
		<dc:creator>Spetto</dc:creator>
		<pubDate>Wed, 09 Sep 2009 19:01:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65128</guid>
		<description>I found TDSS using Spybot but it couldn't remove vsfoce files from system32.
So I run Windows Recovery Console and deleted them manually.
After that I used regedit to delete most of its entries but I had to change the permissions first.
I also couldn't delete one of the entries. Any ideas?</description>
		<content:encoded><![CDATA[<p>I found TDSS using Spybot but it couldn&#8217;t remove vsfoce files from system32.<br />
So I run Windows Recovery Console and deleted them manually.<br />
After that I used regedit to delete most of its entries but I had to change the permissions first.<br />
I also couldn&#8217;t delete one of the entries. Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on AntivirusPro 2009 by Sandra R</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/01/antiviruspro-2009/#comment-65127</link>
		<dc:creator>Sandra R</dc:creator>
		<pubDate>Wed, 09 Sep 2009 17:01:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/01/antiviruspro-2009/#comment-65127</guid>
		<description>Hi! I was surfing and found your blog post... nice! I love your blog.  :) Cheers! Sandra. R.</description>
		<content:encoded><![CDATA[<p>Hi! I was surfing and found your blog post&#8230; nice! I love your blog.  :) Cheers! Sandra. R.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by Aimar Eric</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65126</link>
		<dc:creator>Aimar Eric</dc:creator>
		<pubDate>Wed, 09 Sep 2009 11:43:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65126</guid>
		<description>I want to remove FullHouse Drive virus from my PC but I want something free.</description>
		<content:encoded><![CDATA[<p>I want to remove FullHouse Drive virus from my PC but I want something free.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on XP Police Antivirus by kendidit7</title>
		<link>http://www.precisesecurity.com/blogs/2009/01/27/xp-police-antivirus/#comment-65125</link>
		<dc:creator>kendidit7</dc:creator>
		<pubDate>Tue, 08 Sep 2009 20:24:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/01/27/xp-police-antivirus/#comment-65125</guid>
		<description>Thank goodness malwarebyte fixed my problem 59 objects. We are so blessed to be able to communicate with each other in order to resolve things like this. Thanks everyone be careful and take care.</description>
		<content:encoded><![CDATA[<p>Thank goodness malwarebyte fixed my problem 59 objects. We are so blessed to be able to communicate with each other in order to resolve things like this. Thanks everyone be careful and take care.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Email-Worm.Win32.Net by jakecue</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/06/email-wormwin32net/#comment-65124</link>
		<dc:creator>jakecue</dc:creator>
		<pubDate>Tue, 08 Sep 2009 01:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/02/06/email-wormwin32net/#comment-65124</guid>
		<description>Well, you can use MBAM for this one. Make sure that you can computer while in SafeMode.
http://www.precisesecurity.com/tools-resources/adware-tools/malwarebytes-anti-malware/</description>
		<content:encoded><![CDATA[<p>Well, you can use MBAM for this one. Make sure that you can computer while in SafeMode.<br />
<a href="http://www.precisesecurity.com/tools-resources/adware-tools/malwarebytes-anti-malware/" rel="nofollow">http://www.precisesecurity.com/tools-resources/adware-tools/malwarebytes-anti-malware/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Lee</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65122</link>
		<dc:creator>Lee</dc:creator>
		<pubDate>Mon, 07 Sep 2009 23:07:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65122</guid>
		<description>Hi all. I've had this bug for about a week now, and nothing seems to work. I have AVG and Malwarebytes installed, but neither will scan or run. I downloaded Sophos minutes ago, but it won't install. I'm so out of ideas... any help is appreciated. And thanks to everyone sharing their knowledge.</description>
		<content:encoded><![CDATA[<p>Hi all. I&#8217;ve had this bug for about a week now, and nothing seems to work. I have AVG and Malwarebytes installed, but neither will scan or run. I downloaded Sophos minutes ago, but it won&#8217;t install. I&#8217;m so out of ideas&#8230; any help is appreciated. And thanks to everyone sharing their knowledge.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Steven</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65121</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Mon, 07 Sep 2009 22:25:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65121</guid>
		<description>response 31 worked for me and i did not even have to go in safe mode( my safe mode wont work lol i get blue screen of death.....but thats a whole nother problem) i also unplugged my internet and the adds stopped coming while i was fixing the problem( I alrdy had malewarebytes and avg downloaded)</description>
		<content:encoded><![CDATA[<p>response 31 worked for me and i did not even have to go in safe mode( my safe mode wont work lol i get blue screen of death&#8230;..but thats a whole nother problem) i also unplugged my internet and the adds stopped coming while i was fixing the problem( I alrdy had malewarebytes and avg downloaded)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by AreMoh</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65117</link>
		<dc:creator>AreMoh</dc:creator>
		<pubDate>Mon, 07 Sep 2009 19:55:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65117</guid>
		<description>for Solution For Every Thing(160) what about *.xls or *.xlsx files? I need help.</description>
		<content:encoded><![CDATA[<p>for Solution For Every Thing(160) what about *.xls or *.xlsx files? I need help.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
