<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Threat Center - Spyware and Virus Removal</title>
	<atom:link href="http://www.precisesecurity.com/blogs/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.precisesecurity.com/blogs</link>
	<description></description>
	<lastBuildDate>Sun, 21 Mar 2010 02:52:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Lsas.Blaster.Keyloger by Sandra</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65546</link>
		<dc:creator>Sandra</dc:creator>
		<pubDate>Sun, 21 Mar 2010 02:52:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65546</guid>
		<description>I have Windows 7 and don&#039;t know how to start it in Safe Mode.  It is infested with this virus and I have had no success in downloading malaware either from the internet or from a CD. I would like to try to restore to an earlier date, but it won&#039;t let me change the date either.  Help please!</description>
		<content:encoded><![CDATA[<p>I have Windows 7 and don&#8217;t know how to start it in Safe Mode.  It is infested with this virus and I have had no success in downloading malaware either from the internet or from a CD. I would like to try to restore to an earlier date, but it won&#8217;t let me change the date either.  Help please!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by Hagos</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65544</link>
		<dc:creator>Hagos</dc:creator>
		<pubDate>Thu, 18 Mar 2010 09:30:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65544</guid>
		<description>Please kindly help my computer in removing “Doomsday Has Come: You are infected by Ravo-5002?</description>
		<content:encoded><![CDATA[<p>Please kindly help my computer in removing “Doomsday Has Come: You are infected by Ravo-5002?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by joecobra1968</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65543</link>
		<dc:creator>joecobra1968</dc:creator>
		<pubDate>Thu, 18 Mar 2010 08:50:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65543</guid>
		<description>malwarebytes does indeed bite,,bites  the big one! i had this virus and had to use trusty avast 4.8 NOT 5.0 &lt;that one sucks! worse then s h i t t y avg, anyhow dont use s h i t warebytes is suck knobs! use avast you&#039;ll thank me !</description>
		<content:encoded><![CDATA[<p>malwarebytes does indeed bite,,bites  the big one! i had this virus and had to use trusty avast 4.8 NOT 5.0 &lt;that one sucks! worse then s h i t t y avg, anyhow dont use s h i t warebytes is suck knobs! use avast you&#039;ll thank me !</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by Megersa Beyene</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65541</link>
		<dc:creator>Megersa Beyene</dc:creator>
		<pubDate>Wed, 17 Mar 2010 06:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65541</guid>
		<description>How can remove ravo-5002 in my desktop computer</description>
		<content:encoded><![CDATA[<p>How can remove ravo-5002 in my desktop computer</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on W32/Vora.worm!p2p by Megersa Beyene</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/w32vorawormp2p/#comment-65540</link>
		<dc:creator>Megersa Beyene</dc:creator>
		<pubDate>Wed, 17 Mar 2010 06:04:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/w32vorawormp2p/#comment-65540</guid>
		<description>My computer is infected by Ravo_5002, What should i do ?</description>
		<content:encoded><![CDATA[<p>My computer is infected by Ravo_5002, What should i do ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Infiltration Alert! by UMD</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/18/infiltration-alert/#comment-65539</link>
		<dc:creator>UMD</dc:creator>
		<pubDate>Mon, 15 Mar 2010 17:15:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3848#comment-65539</guid>
		<description>I am facing the same problem. Malwarebytes can not be run and nor th task manager. I think the rouge software disables it. I also found the file containing the virus but can not delete it!
Please help!</description>
		<content:encoded><![CDATA[<p>I am facing the same problem. Malwarebytes can not be run and nor th task manager. I think the rouge software disables it. I also found the file containing the virus but can not delete it!<br />
Please help!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by Awoke Aknaw</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65538</link>
		<dc:creator>Awoke Aknaw</dc:creator>
		<pubDate>Mon, 15 Mar 2010 06:07:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65538</guid>
		<description>Please kindly help my computer in removing &quot;Doomsday Has Come: You are infected by Ravo-5002&quot;</description>
		<content:encoded><![CDATA[<p>Please kindly help my computer in removing &#8220;Doomsday Has Come: You are infected by Ravo-5002&#8243;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on free-viruscan.com by Max</title>
		<link>http://www.precisesecurity.com/blogs/2008/06/26/free-viruscancom/#comment-65537</link>
		<dc:creator>Max</dc:creator>
		<pubDate>Mon, 15 Mar 2010 01:32:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/06/26/free-viruscancom/#comment-65537</guid>
		<description>I keep getting the pop-ups even while running the scan and the scan was unable to detect it.</description>
		<content:encoded><![CDATA[<p>I keep getting the pop-ups even while running the scan and the scan was unable to detect it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse IRC/Backdoor.SDBot4.gsi by Chachacha</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/12/trojan-horse-ircbackdoorsdbot4gsi/#comment-65536</link>
		<dc:creator>Chachacha</dc:creator>
		<pubDate>Sun, 14 Mar 2010 11:17:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/12/trojan-horse-ircbackdoorsdbot4gsi/#comment-65536</guid>
		<description>I&#039;m seeing an alert from AVG on this now (only not .gsi but .QGB)

Trojan Horse IRC/Backdoor.SdBot4.QGB

And in this case the warning is for 

C:\Program Files\Logitech\SetPoint\Connect.exe

The ODD thing is that AVG doesn&#039;t seem to know anything more about the virus and will give 0 results if I search for it</description>
		<content:encoded><![CDATA[<p>I&#8217;m seeing an alert from AVG on this now (only not .gsi but .QGB)</p>
<p>Trojan Horse IRC/Backdoor.SdBot4.QGB</p>
<p>And in this case the warning is for </p>
<p>C:\Program Files\Logitech\SetPoint\Connect.exe</p>
<p>The ODD thing is that AVG doesn&#8217;t seem to know anything more about the virus and will give 0 results if I search for it</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by gump</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65534</link>
		<dc:creator>gump</dc:creator>
		<pubDate>Sat, 13 Mar 2010 16:31:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65534</guid>
		<description>thanks alot peaple you helped me out a shitload...
i could do shit even lost my background tryed to use avg but it wouldn&#039;t let me. after comeing here i realized i had to start in safe mode do a sys. restore from there then use my avg but it&#039;s done and up in running agen so thanks

hey dude you find him i&#039;ll hold him down while you kick him in the balls a few times as long as i in black both his eyes. and may break a finger or 2     lol</description>
		<content:encoded><![CDATA[<p>thanks alot peaple you helped me out a shitload&#8230;<br />
i could do shit even lost my background tryed to use avg but it wouldn&#8217;t let me. after comeing here i realized i had to start in safe mode do a sys. restore from there then use my avg but it&#8217;s done and up in running agen so thanks</p>
<p>hey dude you find him i&#8217;ll hold him down while you kick him in the balls a few times as long as i in black both his eyes. and may break a finger or 2     lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2010 by Louis Cedeno</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65532</link>
		<dc:creator>Louis Cedeno</dc:creator>
		<pubDate>Thu, 11 Mar 2010 21:13:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65532</guid>
		<description>Sally, I hope your connectivity issue has been resolved. If not, make sure you go into your network adaptor and under tcp/ip ensure that dhcp is selected. if you have an ip there,it&#039;s wrong. Try this.</description>
		<content:encoded><![CDATA[<p>Sally, I hope your connectivity issue has been resolved. If not, make sure you go into your network adaptor and under tcp/ip ensure that dhcp is selected. if you have an ip there,it&#8217;s wrong. Try this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2010 by Louis Cedeno</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65530</link>
		<dc:creator>Louis Cedeno</dc:creator>
		<pubDate>Thu, 11 Mar 2010 20:55:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65530</guid>
		<description>Not everyone gets the same type infection. Remember that viruses now come in packets(blender viruses) releasing bad code depending on the network and o/s weakness.</description>
		<content:encoded><![CDATA[<p>Not everyone gets the same type infection. Remember that viruses now come in packets(blender viruses) releasing bad code depending on the network and o/s weakness.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2010 by Louis Cedeno</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65529</link>
		<dc:creator>Louis Cedeno</dc:creator>
		<pubDate>Thu, 11 Mar 2010 20:52:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65529</guid>
		<description>I had a virus (Anti-virus 2010) that was in completely different locations and aliases. Be careful, i think this virus has been updated. It took me 4 hours to get rid of it as i combed the registry.</description>
		<content:encoded><![CDATA[<p>I had a virus (Anti-virus 2010) that was in completely different locations and aliases. Be careful, i think this virus has been updated. It took me 4 hours to get rid of it as i combed the registry.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Infiltration Alert! by Rick ELder</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/18/infiltration-alert/#comment-65528</link>
		<dc:creator>Rick ELder</dc:creator>
		<pubDate>Thu, 11 Mar 2010 19:32:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3848#comment-65528</guid>
		<description>I have the virus explained above, but I cannot run any programs to rid my computer of it. They all lead me to &quot; do you want to purchase anti virus software now?&quot;. Any suggestions to rid this virus are welcome. I have the MalwareBytes software installed previosly but cannot run it!!...Thanks in advance!</description>
		<content:encoded><![CDATA[<p>I have the virus explained above, but I cannot run any programs to rid my computer of it. They all lead me to &#8221; do you want to purchase anti virus software now?&#8221;. Any suggestions to rid this virus are welcome. I have the MalwareBytes software installed previosly but cannot run it!!&#8230;Thanks in advance!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win.MSSQL.Worm.Helkern by dahne</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/04/winmssqlwormhelkern/#comment-65525</link>
		<dc:creator>dahne</dc:creator>
		<pubDate>Tue, 09 Mar 2010 21:52:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/04/winmssqlwormhelkern/#comment-65525</guid>
		<description>how to block intrusion of win.mssql.worm.helkern 61.175.243.101</description>
		<content:encoded><![CDATA[<p>how to block intrusion of win.mssql.worm.helkern 61.175.243.101</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse IRC/Backdoor.SDBot4.gsi by k0ba1t</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/12/trojan-horse-ircbackdoorsdbot4gsi/#comment-65523</link>
		<dc:creator>k0ba1t</dc:creator>
		<pubDate>Mon, 08 Mar 2010 21:13:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/12/trojan-horse-ircbackdoorsdbot4gsi/#comment-65523</guid>
		<description>So, it seems that only AVG antivirus detects this threat. Might it be that this is a fake alarm???</description>
		<content:encoded><![CDATA[<p>So, it seems that only AVG antivirus detects this threat. Might it be that this is a fake alarm???</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.TDSS.rtk by DAVO</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65522</link>
		<dc:creator>DAVO</dc:creator>
		<pubDate>Mon, 08 Mar 2010 10:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/13/win32tdssrtk/#comment-65522</guid>
		<description>so basically that whole story just to say we should download malwarebytes</description>
		<content:encoded><![CDATA[<p>so basically that whole story just to say we should download malwarebytes</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2009 by Jose</title>
		<link>http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/#comment-65521</link>
		<dc:creator>Jose</dc:creator>
		<pubDate>Sun, 07 Mar 2010 23:04:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/#comment-65521</guid>
		<description>ok someone help me...i got hit by the antivirus xo 2010 which im guessing id the same as &#039;09....well everytime i try to open the web or any kind of application it opens a window saying &quot;Open With:&quot; and i click on Internet explorer but it does not do anything...i tried downloading malwarebytes and saved in on the desktop but even when i try to run it, it opens the &quot;Open With:&quot; window not allowing me to open it..i even went another step further and downloaded it from another computer intoa CD and tried to open it in the infected computer but the same damn thing...so far i have the spyware doctor keeping it quarantined and keeping it from poppin up but the computer is still not responding...SO BASICALLY the computer is taken over...anyway to help?? ive tried the &quot;end process&quot; thing also..didnt work...any ideas?? please email me at my email jgoku_3418@yahoo.com if you dont see it up top..thanks</description>
		<content:encoded><![CDATA[<p>ok someone help me&#8230;i got hit by the antivirus xo 2010 which im guessing id the same as &#8216;09&#8230;.well everytime i try to open the web or any kind of application it opens a window saying &#8220;Open With:&#8221; and i click on Internet explorer but it does not do anything&#8230;i tried downloading malwarebytes and saved in on the desktop but even when i try to run it, it opens the &#8220;Open With:&#8221; window not allowing me to open it..i even went another step further and downloaded it from another computer intoa CD and tried to open it in the infected computer but the same damn thing&#8230;so far i have the spyware doctor keeping it quarantined and keeping it from poppin up but the computer is still not responding&#8230;SO BASICALLY the computer is taken over&#8230;anyway to help?? ive tried the &#8220;end process&#8221; thing also..didnt work&#8230;any ideas?? please email me at my email <a href="mailto:jgoku_3418@yahoo.com">jgoku_3418@yahoo.com</a> if you dont see it up top..thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Surabaya by pankaj</title>
		<link>http://www.precisesecurity.com/blogs/2008/09/27/surabaya-startup/#comment-65520</link>
		<dc:creator>pankaj</dc:creator>
		<pubDate>Sun, 07 Mar 2010 11:13:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/09/27/surabaya-startup/#comment-65520</guid>
		<description>how to removed surabaya birthday virus for regedit with edit solution &amp; removal tools.</description>
		<content:encoded><![CDATA[<p>how to removed surabaya birthday virus for regedit with edit solution &amp; removal tools.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2010 by JASON</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65519</link>
		<dc:creator>JASON</dc:creator>
		<pubDate>Sat, 06 Mar 2010 22:24:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65519</guid>
		<description>did a restore and then got rid of the restore file</description>
		<content:encoded><![CDATA[<p>did a restore and then got rid of the restore file</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse IRC/Backdoor.SdBot4.FRV by Harpz</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/28/irc-backdoor-sdbot4-frv/#comment-65517</link>
		<dc:creator>Harpz</dc:creator>
		<pubDate>Fri, 05 Mar 2010 21:44:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3388#comment-65517</guid>
		<description>I got avg and on resident  shield there is 2 trojans what shall i do? it say you can remove all threats what happens if i click that 


help will be appricated 

thank you</description>
		<content:encoded><![CDATA[<p>I got avg and on resident  shield there is 2 trojans what shall i do? it say you can remove all threats what happens if i click that </p>
<p>help will be appricated </p>
<p>thank you</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by Easyrider</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65516</link>
		<dc:creator>Easyrider</dc:creator>
		<pubDate>Fri, 05 Mar 2010 15:59:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65516</guid>
		<description>I had this little blighter today - tried to virsu scan AVG9, got part way but was taking ages, cpu 100%, each object was taking several seconds to scan, so after about 8hours of scanning I aborted and rolled back with system restore - updated AVG, scanned clean, CPU back to normal.

System Restore is such a useful tool - I&#039;d recommend setting it up on every new computer before connecting it to a router and setting it up to automatically set restore points - it&#039;s got me out of a load of holes over the years - do it now!!</description>
		<content:encoded><![CDATA[<p>I had this little blighter today &#8211; tried to virsu scan AVG9, got part way but was taking ages, cpu 100%, each object was taking several seconds to scan, so after about 8hours of scanning I aborted and rolled back with system restore &#8211; updated AVG, scanned clean, CPU back to normal.</p>
<p>System Restore is such a useful tool &#8211; I&#8217;d recommend setting it up on every new computer before connecting it to a router and setting it up to automatically set restore points &#8211; it&#8217;s got me out of a load of holes over the years &#8211; do it now!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.DOS.Uruguay.poly by natale de risi</title>
		<link>http://www.precisesecurity.com/blogs/2009/01/05/virusdosuruguaypoly/#comment-65515</link>
		<dc:creator>natale de risi</dc:creator>
		<pubDate>Thu, 04 Mar 2010 18:59:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/01/05/virusdosuruguaypoly/#comment-65515</guid>
		<description>windows 7 home edition</description>
		<content:encoded><![CDATA[<p>windows 7 home edition</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.DOS.Uruguay.poly by natale de risi</title>
		<link>http://www.precisesecurity.com/blogs/2009/01/05/virusdosuruguaypoly/#comment-65514</link>
		<dc:creator>natale de risi</dc:creator>
		<pubDate>Thu, 04 Mar 2010 18:57:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/01/05/virusdosuruguaypoly/#comment-65514</guid>
		<description>just now my kaspersky antivirus. 2010 find this malicius virus-help -. kaspersky not removal .thanks for any help.</description>
		<content:encoded><![CDATA[<p>just now my kaspersky antivirus. 2010 find this malicius virus-help -. kaspersky not removal .thanks for any help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan.Win32.Genome by ESO</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/26/trojan_win32genome/#comment-65513</link>
		<dc:creator>ESO</dc:creator>
		<pubDate>Wed, 03 Mar 2010 23:02:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3346#comment-65513</guid>
		<description>I&#039;m not sure why it&#039;s labeled &quot;LOW RISK&quot; - when I quarantined this last night it took important drivers with it, and crashed my machine.</description>
		<content:encoded><![CDATA[<p>I&#8217;m not sure why it&#8217;s labeled &#8220;LOW RISK&#8221; &#8211; when I quarantined this last night it took important drivers with it, and crashed my machine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Steve</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65512</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Mon, 01 Mar 2010 00:31:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65512</guid>
		<description>I was browsing online and then was suddenly hit with the worm.... First time with a virus. on a new laptop to.  
I have no virus block at the moment Ill try to   Download Malwarebytes’ Anti-Malware.. (any suggestions) ... Thanks....
 It said it is eating it&#039;s way through my computer trying to send credit card info. lookin for passwords
pop ups kept on appearing with security tool.  tried to deleate security tool but  just came back so I turned  off the computer.  

would someone please find the person
that started this worm and kick him in the balls.  
greatly appreaciated.</description>
		<content:encoded><![CDATA[<p>I was browsing online and then was suddenly hit with the worm&#8230;. First time with a virus. on a new laptop to.<br />
I have no virus block at the moment Ill try to   Download Malwarebytes’ Anti-Malware.. (any suggestions) &#8230; Thanks&#8230;.<br />
 It said it is eating it&#8217;s way through my computer trying to send credit card info. lookin for passwords<br />
pop ups kept on appearing with security tool.  tried to deleate security tool but  just came back so I turned  off the computer.  </p>
<p>would someone please find the person<br />
that started this worm and kick him in the balls.<br />
greatly appreaciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by cryptor-virus-be-gone</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65511</link>
		<dc:creator>cryptor-virus-be-gone</dc:creator>
		<pubDate>Fri, 26 Feb 2010 15:50:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65511</guid>
		<description>I got infected by the Cryptor virus the other day. It significantly deteriorated the performance of my pc- to the point it was maxing my CPU useage to 100% and taking 10 minutes to load any program. This virus really is very destructive and dangerous.

AVG spotted the virus after a manual deep scan (rather than a quick daily scan), removed 141 infected files, but couldn&#039;t clean/remove or quarantine a further 4 infected files. I rebooted my machine and sure enough, the virus was back in all its glory.

I tried running Spyware Search and Destroy, but the virus wouldn&#039;t let the program load or update. I read the above posts and downloaded malwarebytes for free.

The virus prevented me from downloading and running malwarebytes on my machine directly, so I downloaded it from an uninfected machine, saved the .exe file to a memory stick and attempted to run it on my machine.

Again, the virus was clever and wouldn&#039;t let me run the install file on my machine. After reading some more on here, I renamed the .exe file to mbamm.exe and it still wouldn&#039;t run!

I&#039;m guessing the version of the virus I received was a more updated version than others received above. I completely renamed the install file to installme.exe and booted the computer in safe mode.

After I booted in safe mode, the install file managed to install onto my machine without any probs. I did the updates as suggested and ran the program. It found all my infected files, removed them and solved the problem.

I&#039;m now Cryptor virus free! Thanks for all your help and a special gratitude goes to the makers of malwarebytes!</description>
		<content:encoded><![CDATA[<p>I got infected by the Cryptor virus the other day. It significantly deteriorated the performance of my pc- to the point it was maxing my CPU useage to 100% and taking 10 minutes to load any program. This virus really is very destructive and dangerous.</p>
<p>AVG spotted the virus after a manual deep scan (rather than a quick daily scan), removed 141 infected files, but couldn&#8217;t clean/remove or quarantine a further 4 infected files. I rebooted my machine and sure enough, the virus was back in all its glory.</p>
<p>I tried running Spyware Search and Destroy, but the virus wouldn&#8217;t let the program load or update. I read the above posts and downloaded malwarebytes for free.</p>
<p>The virus prevented me from downloading and running malwarebytes on my machine directly, so I downloaded it from an uninfected machine, saved the .exe file to a memory stick and attempted to run it on my machine.</p>
<p>Again, the virus was clever and wouldn&#8217;t let me run the install file on my machine. After reading some more on here, I renamed the .exe file to mbamm.exe and it still wouldn&#8217;t run!</p>
<p>I&#8217;m guessing the version of the virus I received was a more updated version than others received above. I completely renamed the install file to installme.exe and booted the computer in safe mode.</p>
<p>After I booted in safe mode, the install file managed to install onto my machine without any probs. I did the updates as suggested and ran the program. It found all my infected files, removed them and solved the problem.</p>
<p>I&#8217;m now Cryptor virus free! Thanks for all your help and a special gratitude goes to the makers of malwarebytes!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by Leblizy Tondex</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65510</link>
		<dc:creator>Leblizy Tondex</dc:creator>
		<pubDate>Fri, 26 Feb 2010 13:09:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65510</guid>
		<description>fullhouz had attacked mi pc, help mi with a strong antivirus e.g AVAST antivirus</description>
		<content:encoded><![CDATA[<p>fullhouz had attacked mi pc, help mi with a strong antivirus e.g AVAST antivirus</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by JoeAdmin</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65508</link>
		<dc:creator>JoeAdmin</dc:creator>
		<pubDate>Tue, 23 Feb 2010 15:25:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65508</guid>
		<description>A VERY important note is included at the end of this article:
1) Download mabm-setup.exe from a non-affected computer.  Save the file to the desktop.

2) Re-Name mbam-setup.exe to something else with the .exe extension (like JoeAdmin.exe)

3) Copy the re-named .exe file to a memory stick, or write it to a CD/DVD

4) Restore it to the desktop of your infected PC
and execute it (Scan entire disk).

5) If you have any problems doin this with your current login (which should be a administrator) try creating a new login with administrator privs, loging in as that new login and follow the same instructions.</description>
		<content:encoded><![CDATA[<p>A VERY important note is included at the end of this article:<br />
1) Download mabm-setup.exe from a non-affected computer.  Save the file to the desktop.</p>
<p>2) Re-Name mbam-setup.exe to something else with the .exe extension (like JoeAdmin.exe)</p>
<p>3) Copy the re-named .exe file to a memory stick, or write it to a CD/DVD</p>
<p>4) Restore it to the desktop of your infected PC<br />
and execute it (Scan entire disk).</p>
<p>5) If you have any problems doin this with your current login (which should be a administrator) try creating a new login with administrator privs, loging in as that new login and follow the same instructions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Sheur2.gnw by Joe</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2-gnw/#comment-65507</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Tue, 23 Feb 2010 02:19:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2gnw/#comment-65507</guid>
		<description>Removed hard drive from laptop and running both AVG and Malwarebytes from a healthy machine. This seems to be taking care of it but only time will tell</description>
		<content:encoded><![CDATA[<p>Removed hard drive from laptop and running both AVG and Malwarebytes from a healthy machine. This seems to be taking care of it but only time will tell</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PrivacyProtector Free (Red BioHazard Desktop Screen) by DainXC</title>
		<link>http://www.precisesecurity.com/blogs/2007/06/29/privacyprotector-free-red-bio-hazard-desktop/#comment-65506</link>
		<dc:creator>DainXC</dc:creator>
		<pubDate>Mon, 22 Feb 2010 23:43:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/06/29/privacyprotector-free-red-bio-hazard-desktop/#comment-65506</guid>
		<description>My Pc was hit with this a few years back. Btw it was not from porn, it was from a infected download from freewareshare.com</description>
		<content:encoded><![CDATA[<p>My Pc was hit with this a few years back. Btw it was not from porn, it was from a infected download from freewareshare.com</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by SolGabrien</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65505</link>
		<dc:creator>SolGabrien</dc:creator>
		<pubDate>Mon, 22 Feb 2010 21:44:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65505</guid>
		<description>I re-installed my operating system (xp) and it&#039;s fine now - tried everything else beforehand.</description>
		<content:encoded><![CDATA[<p>I re-installed my operating system (xp) and it&#8217;s fine now &#8211; tried everything else beforehand.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on System Security by Rdb</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/system-security/#comment-65504</link>
		<dc:creator>Rdb</dc:creator>
		<pubDate>Mon, 22 Feb 2010 01:53:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/system-secuirty/#comment-65504</guid>
		<description>Sorry 4 the typo- the word ..... on ..... should not be in my message</description>
		<content:encoded><![CDATA[<p>Sorry 4 the typo- the word &#8230;.. on &#8230;.. should not be in my message</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on System Security by Rdb</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/system-security/#comment-65503</link>
		<dc:creator>Rdb</dc:creator>
		<pubDate>Mon, 22 Feb 2010 01:51:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/system-secuirty/#comment-65503</guid>
		<description>The best thing to to is not to get the virus.... When the fake virus message pops up on DO NOT touch it..... simply go to the start menu and turn off your computer and restart it..... YOU WILL NOT GET THE VIRUS AT ALL!

Works every time!</description>
		<content:encoded><![CDATA[<p>The best thing to to is not to get the virus&#8230;. When the fake virus message pops up on DO NOT touch it&#8230;.. simply go to the start menu and turn off your computer and restart it&#8230;.. YOU WILL NOT GET THE VIRUS AT ALL!</p>
<p>Works every time!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by simon</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65502</link>
		<dc:creator>simon</dc:creator>
		<pubDate>Mon, 22 Feb 2010 01:47:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65502</guid>
		<description>I very very sorry by the dulla virus plz give me the solution b/c I do any thing with the virus dulla help me how can i remove from my PC  . We can&#039;t do with messanger and an other documents please send me a solution</description>
		<content:encoded><![CDATA[<p>I very very sorry by the dulla virus plz give me the solution b/c I do any thing with the virus dulla help me how can i remove from my PC  . We can&#8217;t do with messanger and an other documents please send me a solution</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Email-Worm.Win32.Net by greg</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/06/email-wormwin32net/#comment-65501</link>
		<dc:creator>greg</dc:creator>
		<pubDate>Sun, 21 Feb 2010 16:22:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2009/02/06/email-wormwin32net/#comment-65501</guid>
		<description>I only get it on a yahoo message board. If its not a real scam, why can&#039;t I shut the virus warning windows down? I can only restart my pc to get the warning pages  to quit. Thanks</description>
		<content:encoded><![CDATA[<p>I only get it on a yahoo message board. If its not a real scam, why can&#8217;t I shut the virus warning windows down? I can only restart my pc to get the warning pages  to quit. Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by gazza</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65500</link>
		<dc:creator>gazza</dc:creator>
		<pubDate>Sun, 21 Feb 2010 11:18:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65500</guid>
		<description>i have this virus....its terrible.  i first up did a system recovery....big mistake, i wiped everything thinkin it would rid me of this thing...it didnt!  Now i can&#039;t do a system restore point (which i should have done first up) because as far as the computers concerned, it had this virus from the start!  ahhhhhh  its drivin me nuts.</description>
		<content:encoded><![CDATA[<p>i have this virus&#8230;.its terrible.  i first up did a system recovery&#8230;.big mistake, i wiped everything thinkin it would rid me of this thing&#8230;it didnt!  Now i can&#8217;t do a system restore point (which i should have done first up) because as far as the computers concerned, it had this virus from the start!  ahhhhhh  its drivin me nuts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2010 by MWRadio</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65497</link>
		<dc:creator>MWRadio</dc:creator>
		<pubDate>Fri, 19 Feb 2010 09:26:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65497</guid>
		<description>As of 2/19/2010 this malware was killing IE and .exe files in XP.

Problems with IE: Go START &gt; RUN (type in regedit and hit enter)  look for:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Right click on Default, click Modify. Remove:
&quot;C:\\Documents and Settings\\\\Local Settings\\Application Data\\av.exe\&quot; /START \
Leave:
&quot;C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\&quot;

If you can&#039;t start any programs from desk top links or start menu the .exe shell open command may be broken. Download and run FixExe.reg: hxxp://download.bleepingcomputer.com/reg/FixExe.reg</description>
		<content:encoded><![CDATA[<p>As of 2/19/2010 this malware was killing IE and .exe files in XP.</p>
<p>Problems with IE: Go START &gt; RUN (type in regedit and hit enter)  look for:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command<br />
Right click on Default, click Modify. Remove:<br />
&#8220;C:\\Documents and Settings\\\\Local Settings\\Application Data\\av.exe\&#8221; /START \<br />
Leave:<br />
&#8220;C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\&#8221;</p>
<p>If you can&#8217;t start any programs from desk top links or start menu the .exe shell open command may be broken. Download and run FixExe.reg: hxxp://download.bleepingcomputer.com/reg/FixExe.reg</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by Hiwot</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65496</link>
		<dc:creator>Hiwot</dc:creator>
		<pubDate>Fri, 19 Feb 2010 07:03:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65496</guid>
		<description>How to Remove Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002:</description>
		<content:encoded><![CDATA[<p>How to Remove Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002:</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cutie Monkey Virus by Jan Joseph "pacman" P. Hernandez</title>
		<link>http://www.precisesecurity.com/blogs/2008/02/23/cutie-monkey-virus/#comment-65494</link>
		<dc:creator>Jan Joseph "pacman" P. Hernandez</dc:creator>
		<pubDate>Wed, 17 Feb 2010 10:05:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/02/23/cutie-monkey-virus/#comment-65494</guid>
		<description>where can i get cutie monkey virus?</description>
		<content:encoded><![CDATA[<p>where can i get cutie monkey virus?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Sheur2.gnw by steve</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2-gnw/#comment-65492</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Wed, 17 Feb 2010 09:57:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2gnw/#comment-65492</guid>
		<description>havin same problem, been trying to kill it for three days now.  mine&#039;s SHeur.CLUO.</description>
		<content:encoded><![CDATA[<p>havin same problem, been trying to kill it for three days now.  mine&#8217;s SHeur.CLUO.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Bingo</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65491</link>
		<dc:creator>Bingo</dc:creator>
		<pubDate>Tue, 16 Feb 2010 12:04:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65491</guid>
		<description>Hello All.
I see this little bugger is still doing the rounds. Vicious little sod!
This is a repost of my messages from July 2009 detailing how I got rid of the problem. It is possible that new victims may not read that far back and I hope my experiences are helpful. Good luck! By the way, still free from this virus.



Bingo
July 22nd, 2009 at 1:28 pm 56 

Hello everybody. Only became aware of this thing about 5 days ago when the computer started shutting down and various programs became unworkable. Also, all files on my key drive disappeared and the drive had to be reformatted. Can’t swear that the virus did this but I cnn’t think of anything else to explain it. Windows Firewall (I’m running XP Pro) reported that I had a Virtob infection but AVG, Zone Alarm, and Ad-aware reported nothing. So after a bit of researching, I found the Kaspersky online scanner. This revealed that quite a lot of files were infected with win32.virut.ce but these could not be deleted by the online scanner. However, Kaspersky are doing a Full 30 day trial of Kaspersky Internet Security 2010 and I installed this. On checking drives C, D, and External Drive F, Kaspersky found and disinfected, or deleted, about 700 infected files. Reran the program and a few more files were found and treated. I am completed my third scan and the infection seems to have gone. Can’t say this will work for everyone but it seems to have worked for me. Worth a try and good luck to you. This is one awkward sob. I will report back if the infection recreates itself in the next few days, but so far it’s looking good



Bingo
July 22nd, 2009 at 10:48 pm 57 

Following on from earlier post, I found that a few vrt.tmp files were appearing in C:\Documents and Settings\LocalService\Local Settings\Temp but Kaspersky was preventing them loading or connecting to the net. I ran the scan next in Safe Mode and this disinfected the few files which could not be done in normal mode. As of this moment, this machine is now completely free, as far as I can see, of Virut and anything else. All programs and files seem to be working normally and the Kaspersky Network Monitor is showing that there are no suspect connections. Just for information, my operating system is XP Pro SP3. Kaspersky seems to have given me the complete solution to this pest. Well worth giving it a try. Free 30 day trial could rid you of this problem.



Bingo
July 31st, 2009 at 8:35 am 59 

Well, just to tie up the story on my experiences, I am now a week on from installing Kaspersky and ridding myself of Virut and it has not reappeared. That about says it all. Would highly recommend Kaspersky for ridding yourself of Virut</description>
		<content:encoded><![CDATA[<p>Hello All.<br />
I see this little bugger is still doing the rounds. Vicious little sod!<br />
This is a repost of my messages from July 2009 detailing how I got rid of the problem. It is possible that new victims may not read that far back and I hope my experiences are helpful. Good luck! By the way, still free from this virus.</p>
<p>Bingo<br />
July 22nd, 2009 at 1:28 pm 56 </p>
<p>Hello everybody. Only became aware of this thing about 5 days ago when the computer started shutting down and various programs became unworkable. Also, all files on my key drive disappeared and the drive had to be reformatted. Can’t swear that the virus did this but I cnn’t think of anything else to explain it. Windows Firewall (I’m running XP Pro) reported that I had a Virtob infection but AVG, Zone Alarm, and Ad-aware reported nothing. So after a bit of researching, I found the Kaspersky online scanner. This revealed that quite a lot of files were infected with win32.virut.ce but these could not be deleted by the online scanner. However, Kaspersky are doing a Full 30 day trial of Kaspersky Internet Security 2010 and I installed this. On checking drives C, D, and External Drive F, Kaspersky found and disinfected, or deleted, about 700 infected files. Reran the program and a few more files were found and treated. I am completed my third scan and the infection seems to have gone. Can’t say this will work for everyone but it seems to have worked for me. Worth a try and good luck to you. This is one awkward sob. I will report back if the infection recreates itself in the next few days, but so far it’s looking good</p>
<p>Bingo<br />
July 22nd, 2009 at 10:48 pm 57 </p>
<p>Following on from earlier post, I found that a few vrt.tmp files were appearing in C:\Documents and Settings\LocalService\Local Settings\Temp but Kaspersky was preventing them loading or connecting to the net. I ran the scan next in Safe Mode and this disinfected the few files which could not be done in normal mode. As of this moment, this machine is now completely free, as far as I can see, of Virut and anything else. All programs and files seem to be working normally and the Kaspersky Network Monitor is showing that there are no suspect connections. Just for information, my operating system is XP Pro SP3. Kaspersky seems to have given me the complete solution to this pest. Well worth giving it a try. Free 30 day trial could rid you of this problem.</p>
<p>Bingo<br />
July 31st, 2009 at 8:35 am 59 </p>
<p>Well, just to tie up the story on my experiences, I am now a week on from installing Kaspersky and ridding myself of Virut and it has not reappeared. That about says it all. Would highly recommend Kaspersky for ridding yourself of Virut</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FullHouse Drive by mongwe motho</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/18/fullhouse-drive/#comment-65489</link>
		<dc:creator>mongwe motho</dc:creator>
		<pubDate>Tue, 16 Feb 2010 06:53:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3124#comment-65489</guid>
		<description>I want to remove fullhouse drive from my computer...what are the steps to follow???i need help fast......</description>
		<content:encoded><![CDATA[<p>I want to remove fullhouse drive from my computer&#8230;what are the steps to follow???i need help fast&#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2010 by David</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65488</link>
		<dc:creator>David</dc:creator>
		<pubDate>Tue, 16 Feb 2010 04:54:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65488</guid>
		<description>try the super anti spyware thats how i got mine out with</description>
		<content:encoded><![CDATA[<p>try the super anti spyware thats how i got mine out with</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by Herbert</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65487</link>
		<dc:creator>Herbert</dc:creator>
		<pubDate>Tue, 16 Feb 2010 00:09:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65487</guid>
		<description>Thanks! The information on this blog helped me recover from the LSAS virus.....</description>
		<content:encoded><![CDATA[<p>Thanks! The information on this blog helped me recover from the LSAS virus&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Kiwee Toolbar by Kit</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/kiwee-toolbar/#comment-65486</link>
		<dc:creator>Kit</dc:creator>
		<pubDate>Sun, 14 Feb 2010 14:39:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/kiwee-toolbar/#comment-65486</guid>
		<description>Nortons has blocked the &quot;Unlocker&quot; file. It says that it contains  the Heuristic vrus</description>
		<content:encoded><![CDATA[<p>Nortons has blocked the &#8220;Unlocker&#8221; file. It says that it contains  the Heuristic vrus</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by pat</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65485</link>
		<dc:creator>pat</dc:creator>
		<pubDate>Sun, 14 Feb 2010 13:45:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65485</guid>
		<description>do system restore it works even if restor says not completed</description>
		<content:encoded><![CDATA[<p>do system restore it works even if restor says not completed</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on P2P-Worm.Win32.Palevo!IK by alioune</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/27/p2p-worm-win32-palevo-ik/#comment-65483</link>
		<dc:creator>alioune</dc:creator>
		<pubDate>Sat, 13 Feb 2010 21:42:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4061#comment-65483</guid>
		<description>i wanted to ger music from a friends laptop and my phone contacts P2P-Worm.win32.palevo.lbt
i have active KAPERSKY but my kerperky was not able to remove it
what am i to do???
contact me please with my email
sarr_6@hotmail.com</description>
		<content:encoded><![CDATA[<p>i wanted to ger music from a friends laptop and my phone contacts P2P-Worm.win32.palevo.lbt<br />
i have active KAPERSKY but my kerperky was not able to remove it<br />
what am i to do???<br />
contact me please with my email<br />
<a href="mailto:sarr_6@hotmail.com">sarr_6@hotmail.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by ken.absolute</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65482</link>
		<dc:creator>ken.absolute</dc:creator>
		<pubDate>Fri, 12 Feb 2010 21:34:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65482</guid>
		<description>I slaved a SATA drive via USB adapter to copy some data off of it...This som&#039;bitch was on it and it jumped to the hosting PC!

It must get deep into all drives that it finds to make them autorun.  Anyway - Sunbelts Vipre anti-malware caught it on the hosting computer and kept it from spreading.  

The lesson anyway: be sure and hold down the shift key as you insert a USB drive (even if it&#039;s a adapter for IDE/serial/SCSI) to keep it from auto-running.

wow - this thing... it gets deep into sysvol and even maintenance partitions.  

I used Darik&#039;s Boot and Nuke (http://sourceforge.net/projects/dban/) for the guest drive (inc maint partition) after reading about the issues here and I&#039;ve not heard from it again.

My guess is people keep on getting reinfected by using their infected-auto-running USB drives or accessing infected .exe&#039;s that they backed up - unless their is some bios component it can load into that I&#039;ve been luckily enough not to have encountered.</description>
		<content:encoded><![CDATA[<p>I slaved a SATA drive via USB adapter to copy some data off of it&#8230;This som&#8217;bitch was on it and it jumped to the hosting PC!</p>
<p>It must get deep into all drives that it finds to make them autorun.  Anyway &#8211; Sunbelts Vipre anti-malware caught it on the hosting computer and kept it from spreading.  </p>
<p>The lesson anyway: be sure and hold down the shift key as you insert a USB drive (even if it&#8217;s a adapter for IDE/serial/SCSI) to keep it from auto-running.</p>
<p>wow &#8211; this thing&#8230; it gets deep into sysvol and even maintenance partitions.  </p>
<p>I used Darik&#8217;s Boot and Nuke (<a href="http://sourceforge.net/projects/dban/" rel="nofollow">http://sourceforge.net/projects/dban/</a>) for the guest drive (inc maint partition) after reading about the issues here and I&#8217;ve not heard from it again.</p>
<p>My guess is people keep on getting reinfected by using their infected-auto-running USB drives or accessing infected .exe&#8217;s that they backed up &#8211; unless their is some bios component it can load into that I&#8217;ve been luckily enough not to have encountered.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Sheur2.gnw by Tech guru</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2-gnw/#comment-65481</link>
		<dc:creator>Tech guru</dc:creator>
		<pubDate>Wed, 10 Feb 2010 16:50:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2gnw/#comment-65481</guid>
		<description>I have found a easy wayto remove this, well. i think it is this, (i realy dont know if they are linked, but i think they are) if you go to the task manager (XP: CTRL+ALT+Delete  vista: CTRL+SHIFT+Esc  7: unknown, try ctrl alt delete)

anyway
in the task manger, go to prosese&#039;s, and look for a prosses called &quot;YLq&quot;, if its there, rightclick it and click on &quot;open file location&quot;. 
if the file location is locat/temp then just ctrl A and press delete

if its not temp, highlight the file and any other things that start with YL (or there and round abouts) and press delete, if it says try again, go back to the task manger and press stop proses.. your welcom, i just made your computer a little safer</description>
		<content:encoded><![CDATA[<p>I have found a easy wayto remove this, well. i think it is this, (i realy dont know if they are linked, but i think they are) if you go to the task manager (XP: CTRL+ALT+Delete  vista: CTRL+SHIFT+Esc  7: unknown, try ctrl alt delete)</p>
<p>anyway<br />
in the task manger, go to prosese&#8217;s, and look for a prosses called &#8220;YLq&#8221;, if its there, rightclick it and click on &#8220;open file location&#8221;.<br />
if the file location is locat/temp then just ctrl A and press delete</p>
<p>if its not temp, highlight the file and any other things that start with YL (or there and round abouts) and press delete, if it says try again, go back to the task manger and press stop proses.. your welcom, i just made your computer a little safer</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dialer.Win32.cutygirls by wail elawoor</title>
		<link>http://www.precisesecurity.com/blogs/2008/08/22/dialerwin32cutygirls/#comment-65479</link>
		<dc:creator>wail elawoor</dc:creator>
		<pubDate>Wed, 10 Feb 2010 09:12:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/08/22/dialerwin32cutygirls/#comment-65479</guid>
		<description>hi roland
i need your e mail</description>
		<content:encoded><![CDATA[<p>hi roland<br />
i need your e mail</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dropper.Bravix.A by Butch</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/20/dropperbravixa/#comment-65476</link>
		<dc:creator>Butch</dc:creator>
		<pubDate>Tue, 09 Feb 2010 23:31:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/20/dropperbravixa/#comment-65476</guid>
		<description>run AVG in windows safe mode and it&#039;ll do the tricj just fine</description>
		<content:encoded><![CDATA[<p>run AVG in windows safe mode and it&#8217;ll do the tricj just fine</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Sheur2.gnw by AHOY</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2-gnw/#comment-65475</link>
		<dc:creator>AHOY</dc:creator>
		<pubDate>Tue, 09 Feb 2010 23:06:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2gnw/#comment-65475</guid>
		<description>SHeur2 CKNB and SHeur2 CKLX I just tried to open the site with those sweet pics on the FB&#039;s friends for sale...stupid I know... Do you know how to remove that?</description>
		<content:encoded><![CDATA[<p>SHeur2 CKNB and SHeur2 CKLX I just tried to open the site with those sweet pics on the FB&#8217;s friends for sale&#8230;stupid I know&#8230; Do you know how to remove that?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by tit</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65474</link>
		<dc:creator>tit</dc:creator>
		<pubDate>Tue, 09 Feb 2010 13:29:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65474</guid>
		<description>how can remove ravo-5002 in my laptop</description>
		<content:encoded><![CDATA[<p>how can remove ravo-5002 in my laptop</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by tit</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65473</link>
		<dc:creator>tit</dc:creator>
		<pubDate>Tue, 09 Feb 2010 13:28:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65473</guid>
		<description>my laptop is infefcted by ravo-5002. how can I remove this virus</description>
		<content:encoded><![CDATA[<p>my laptop is infefcted by ravo-5002. how can I remove this virus</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on W32.Svich &#8211; 0catch.com by bich ngoc</title>
		<link>http://www.precisesecurity.com/blogs/2007/07/02/w32svich-0catchcom/#comment-65472</link>
		<dc:creator>bich ngoc</dc:creator>
		<pubDate>Mon, 08 Feb 2010 11:01:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/07/02/w32svich-0catchcom/#comment-65472</guid>
		<description>Tha nguoi dung noi se yeu minh toi mai thoi thi gio day toi se vui hon. Gio nguoi lac loi buoc chan ve noi xa xoi, cay dang chi rieng minh toi…</description>
		<content:encoded><![CDATA[<p>Tha nguoi dung noi se yeu minh toi mai thoi thi gio day toi se vui hon. Gio nguoi lac loi buoc chan ve noi xa xoi, cay dang chi rieng minh toi…</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on antivirus-live-scan.com by madhar</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/05/antivirus-live-scan-com/#comment-65470</link>
		<dc:creator>madhar</dc:creator>
		<pubDate>Sat, 06 Feb 2010 18:50:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/05/antivirus-live-scancom/#comment-65470</guid>
		<description>help me</description>
		<content:encoded><![CDATA[<p>help me</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pyagcore by Jess</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65469</link>
		<dc:creator>Jess</dc:creator>
		<pubDate>Fri, 05 Feb 2010 19:18:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/25/pyagcore/#comment-65469</guid>
		<description>I&#039;ve tried uninstalling the kiwee toolbar but it wont let me! I clicked continue then you see a the outline of a box flash up and go away again. Kiwee toolbar just wont uninstall!! I installed Kiwee ages ago...why is it causing a problem for me now? The same message comes up every time... Pyagcore.search.detection...then loads of other writing i dont understand lol. It stops me from going on MSN and internet explorer so im having to use AOL at the moment. Please can someone help!</description>
		<content:encoded><![CDATA[<p>I&#8217;ve tried uninstalling the kiwee toolbar but it wont let me! I clicked continue then you see a the outline of a box flash up and go away again. Kiwee toolbar just wont uninstall!! I installed Kiwee ages ago&#8230;why is it causing a problem for me now? The same message comes up every time&#8230; Pyagcore.search.detection&#8230;then loads of other writing i dont understand lol. It stops me from going on MSN and internet explorer so im having to use AOL at the moment. Please can someone help!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Surabaya by panu</title>
		<link>http://www.precisesecurity.com/blogs/2008/09/27/surabaya-startup/#comment-65468</link>
		<dc:creator>panu</dc:creator>
		<pubDate>Fri, 05 Feb 2010 08:03:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/09/27/surabaya-startup/#comment-65468</guid>
		<description>do the above for all ur drives</description>
		<content:encoded><![CDATA[<p>do the above for all ur drives</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Surabaya by suraj</title>
		<link>http://www.precisesecurity.com/blogs/2008/09/27/surabaya-startup/#comment-65467</link>
		<dc:creator>suraj</dc:creator>
		<pubDate>Fri, 05 Feb 2010 08:02:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/09/27/surabaya-startup/#comment-65467</guid>
		<description>Press Start -&gt; Run -&gt; cmd (or command) -&gt; press Enter
Type in command box- cd\
Type again in command box- c:
Type again in command box- attrib -s -h -r /d /s -&gt; press Enter
Type again in command box- del autorun.inf -&gt; press Enter
Type again in command box- del thumb*.* -&gt; press Enter</description>
		<content:encoded><![CDATA[<p>Press Start -&gt; Run -&gt; cmd (or command) -&gt; press Enter<br />
Type in command box- cd\<br />
Type again in command box- c:<br />
Type again in command box- attrib -s -h -r /d /s -&gt; press Enter<br />
Type again in command box- del autorun.inf -&gt; press Enter<br />
Type again in command box- del thumb*.* -&gt; press Enter</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by Ismail</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65466</link>
		<dc:creator>Ismail</dc:creator>
		<pubDate>Fri, 05 Feb 2010 06:00:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65466</guid>
		<description>Plse, help me in removing the &quot;Dooms day Has come&quot; which is dameging my computer.</description>
		<content:encoded><![CDATA[<p>Plse, help me in removing the &#8220;Dooms day Has come&#8221; which is dameging my computer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doomsday Has Come: YOU ARE iNFECTED BY RAVO_5002 by fishi @ ethiopian</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65464</link>
		<dc:creator>fishi @ ethiopian</dc:creator>
		<pubDate>Thu, 04 Feb 2010 20:25:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/17/doomsday-has-come-you-are-infected-by-ravo_5002/#comment-65464</guid>
		<description>please help my laptop our WEBMASTER? I INFECTED TO</description>
		<content:encoded><![CDATA[<p>please help my laptop our WEBMASTER? I INFECTED TO</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Sheur2.gnw by Anti Spam</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2-gnw/#comment-65463</link>
		<dc:creator>Anti Spam</dc:creator>
		<pubDate>Thu, 04 Feb 2010 13:42:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/22/trojan-horse-sheur2gnw/#comment-65463</guid>
		<description>Another SHeur2 file is send trough MSN! The file is called Picture2525.exe and is found on IP 74.86.216.78. I allready contacted the hoster to remove that file and disconnect the user from internet. The infection found with AVG is : Trojan horse SHeur2.CIDT

It was catched and locked by AVG the minute the file was written on my &quot;safedisk&quot;. Best thing you always must do is only download and safe it. DO NOT DOWNLOAD AND EXECUTE! When you safe the file first, you can scan it with a scanner. If it is infected, it will be locked and can&#039;t infect your computer.</description>
		<content:encoded><![CDATA[<p>Another SHeur2 file is send trough MSN! The file is called Picture2525.exe and is found on IP 74.86.216.78. I allready contacted the hoster to remove that file and disconnect the user from internet. The infection found with AVG is : Trojan horse SHeur2.CIDT</p>
<p>It was catched and locked by AVG the minute the file was written on my &#8220;safedisk&#8221;. Best thing you always must do is only download and safe it. DO NOT DOWNLOAD AND EXECUTE! When you safe the file first, you can scan it with a scanner. If it is infected, it will be locked and can&#8217;t infect your computer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2010 by George</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65462</link>
		<dc:creator>George</dc:creator>
		<pubDate>Wed, 03 Feb 2010 21:22:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65462</guid>
		<description>For Sally:

It has a habit of adding or changing the default gateway for the network adapter. Go to the tcp/ip properties if the adapter and click on advanced. remove the gateway entry if there is one.</description>
		<content:encoded><![CDATA[<p>For Sally:</p>
<p>It has a habit of adding or changing the default gateway for the network adapter. Go to the tcp/ip properties if the adapter and click on advanced. remove the gateway entry if there is one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by maggiekittie</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65461</link>
		<dc:creator>maggiekittie</dc:creator>
		<pubDate>Tue, 02 Feb 2010 14:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65461</guid>
		<description>I got the virus aswell i just ran avg twice it found some virus and removed them but the main virus was still there ran malwarebytes which i already had on my computer and it found 100 more on top of it and fixed it all the virus is gone as far as i tell, surprised it did way better then avg free:0</description>
		<content:encoded><![CDATA[<p>I got the virus aswell i just ran avg twice it found some virus and removed them but the main virus was still there ran malwarebytes which i already had on my computer and it found 100 more on top of it and fixed it all the virus is gone as far as i tell, surprised it did way better then avg free:0</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TR/Crypt.XPACK.Gen by s.b</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/17/tr-crypt-xpack-gen/#comment-65460</link>
		<dc:creator>s.b</dc:creator>
		<pubDate>Tue, 02 Feb 2010 09:07:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2568#comment-65460</guid>
		<description>it also infect the file svchosts file. in the process list in Task Manager in some cases. remove tre proces and then run AV program. ceck again in task manager
hope it works</description>
		<content:encoded><![CDATA[<p>it also infect the file svchosts file. in the process list in Task Manager in some cases. remove tre proces and then run AV program. ceck again in task manager<br />
hope it works</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TR/Crypt.XPACK.Gen by CJ</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/17/tr-crypt-xpack-gen/#comment-65458</link>
		<dc:creator>CJ</dc:creator>
		<pubDate>Sat, 30 Jan 2010 01:45:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2568#comment-65458</guid>
		<description>Down load (free) AntiVir Personal software...run the defaul settings.  It will remove this virus...I&#039;ve done my ProBono for today. :)  Let me know the outcome.</description>
		<content:encoded><![CDATA[<p>Down load (free) AntiVir Personal software&#8230;run the defaul settings.  It will remove this virus&#8230;I&#8217;ve done my ProBono for today. :)  Let me know the outcome.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on resycled/boot.com by rickster723</title>
		<link>http://www.precisesecurity.com/blogs/2008/09/20/resycledbootcom/#comment-65457</link>
		<dc:creator>rickster723</dc:creator>
		<pubDate>Fri, 29 Jan 2010 16:44:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/09/24/resycledbootcom/#comment-65457</guid>
		<description>Spyware terminiator eliminates it</description>
		<content:encoded><![CDATA[<p>Spyware terminiator eliminates it</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by D Mulyana</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65456</link>
		<dc:creator>D Mulyana</dc:creator>
		<pubDate>Thu, 28 Jan 2010 15:52:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65456</guid>
		<description>i have tried the save mode way n run the mbam-setup exe (i renamed it first). Yup the mwalbytes can fixed the lsas blaster. Thanx to you all, especially webmaster, now my laptop run normally again</description>
		<content:encoded><![CDATA[<p>i have tried the save mode way n run the mbam-setup exe (i renamed it first). Yup the mwalbytes can fixed the lsas blaster. Thanx to you all, especially webmaster, now my laptop run normally again</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OSX/Tored.worm by saleem</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/23/osxtoredworm/#comment-65454</link>
		<dc:creator>saleem</dc:creator>
		<pubDate>Mon, 25 Jan 2010 15:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4002#comment-65454</guid>
		<description>hey wassup dude findi out web file</description>
		<content:encoded><![CDATA[<p>hey wassup dude findi out web file</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by AZ</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65453</link>
		<dc:creator>AZ</dc:creator>
		<pubDate>Mon, 25 Jan 2010 08:19:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65453</guid>
		<description>THIS IS THE NASTIEST VIRUS HUMANS HAVE EVER FACED!!!!!!!!! 12 YEARS PC PROFICIENT HAS GIVEN UP AFTER REINSTALLING 64BIT VISTA, WIN 7 XP PRO 10 TIMES.....will completely format now. Installing new OS doesn&#039;t help either, it infects the new OS as well..ANY SUGGESTIONS??????????</description>
		<content:encoded><![CDATA[<p>THIS IS THE NASTIEST VIRUS HUMANS HAVE EVER FACED!!!!!!!!! 12 YEARS PC PROFICIENT HAS GIVEN UP AFTER REINSTALLING 64BIT VISTA, WIN 7 XP PRO 10 TIMES&#8230;..will completely format now. Installing new OS doesn&#8217;t help either, it infects the new OS as well..ANY SUGGESTIONS??????????</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32.Tanatos.m by jacob</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/31/win32tanatosm/#comment-65452</link>
		<dc:creator>jacob</dc:creator>
		<pubDate>Sat, 23 Jan 2010 08:06:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/31/win32tanatosm/#comment-65452</guid>
		<description>AVG can do some extent....one can try even the  free version</description>
		<content:encoded><![CDATA[<p>AVG can do some extent&#8230;.one can try even the  free version</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Assi</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65451</link>
		<dc:creator>Assi</dc:creator>
		<pubDate>Fri, 22 Jan 2010 12:09:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65451</guid>
		<description>In one hand it is good to see ethiopians to create this things!!
Don&#039;t to be stupid to loss somebodies file? create antivirus for dulla ! to be prised by 8000000 peoples of ethiopia</description>
		<content:encoded><![CDATA[<p>In one hand it is good to see ethiopians to create this things!!<br />
Don&#8217;t to be stupid to loss somebodies file? create antivirus for dulla ! to be prised by 8000000 peoples of ethiopia</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Spy Guard 2008 by Stacy</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/28/spy-guard-2008/#comment-65449</link>
		<dc:creator>Stacy</dc:creator>
		<pubDate>Wed, 20 Jan 2010 03:54:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/28/spy-guard-2008/#comment-65449</guid>
		<description>Great program...thank you from the bottom of my heart! It found over 91 infections on a computer that had been rendered useless and removed them. Can&#039;t boost enough...definite go!!!</description>
		<content:encoded><![CDATA[<p>Great program&#8230;thank you from the bottom of my heart! It found over 91 infections on a computer that had been rendered useless and removed them. Can&#8217;t boost enough&#8230;definite go!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on &#8220;Aurora&#8221; Hit Google Services and Others by Roarur.dr : Virus Solution and Removal</title>
		<link>http://www.precisesecurity.com/blogs/2010/01/20/aurora-hit-google-services-and-others/#comment-65448</link>
		<dc:creator>Roarur.dr : Virus Solution and Removal</dc:creator>
		<pubDate>Wed, 20 Jan 2010 01:25:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=4443#comment-65448</guid>
		<description>[...] drop multiple malicious files on the computer. Roarur.dr is associated with stage two of the &#8220;Aurora&#8221; [...]</description>
		<content:encoded><![CDATA[<p>[...] drop multiple malicious files on the computer. Roarur.dr is associated with stage two of the &#8220;Aurora&#8221; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by Liane</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65447</link>
		<dc:creator>Liane</dc:creator>
		<pubDate>Mon, 18 Jan 2010 00:48:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65447</guid>
		<description>I found out I had this virus last night.
Kaspersky just detected backdoor.win32.papras.t
It&#039;s go time. *-*</description>
		<content:encoded><![CDATA[<p>I found out I had this virus last night.<br />
Kaspersky just detected backdoor.win32.papras.t<br />
It&#8217;s go time. *-*</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by chuck</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65446</link>
		<dc:creator>chuck</dc:creator>
		<pubDate>Sat, 16 Jan 2010 20:31:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65446</guid>
		<description>I had the same problem re lsas virus.  I shut the system down, reopened in &quot;safe&quot; mode, then did a &quot;systems restore&quot; dated 2 weeks ago.  This is in Windows XP. Took me about 2 minutes and so far it is working.</description>
		<content:encoded><![CDATA[<p>I had the same problem re lsas virus.  I shut the system down, reopened in &#8220;safe&#8221; mode, then did a &#8220;systems restore&#8221; dated 2 weeks ago.  This is in Windows XP. Took me about 2 minutes and so far it is working.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Cyber Dan</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65445</link>
		<dc:creator>Cyber Dan</dc:creator>
		<pubDate>Fri, 15 Jan 2010 09:52:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65445</guid>
		<description>Dear Persons

i want to express my deep concern on this virus from a technical point of view and becuse i have related profession ..but not virsus making lolz! i have made few virus but not like dulla and i have not released them becuse they are for educational purpose only. What i have understood from ~dulla204 is it insert the string ~dulla204 in each file that have extensions like .xlsx .vbp.asp.aspx. and so on...and it strats using a service application(as a windows helpfull application) but.it&#039;s not i have seen some of the prtion of code by opening it in a notpad i have come to undrrstood that it is written in delphi programing language....</description>
		<content:encoded><![CDATA[<p>Dear Persons</p>
<p>i want to express my deep concern on this virus from a technical point of view and becuse i have related profession ..but not virsus making lolz! i have made few virus but not like dulla and i have not released them becuse they are for educational purpose only. What i have understood from ~dulla204 is it insert the string ~dulla204 in each file that have extensions like .xlsx .vbp.asp.aspx. and so on&#8230;and it strats using a service application(as a windows helpfull application) but.it&#8217;s not i have seen some of the prtion of code by opening it in a notpad i have come to undrrstood that it is written in delphi programing language&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Surabaya by Gopi</title>
		<link>http://www.precisesecurity.com/blogs/2008/09/27/surabaya-startup/#comment-65444</link>
		<dc:creator>Gopi</dc:creator>
		<pubDate>Wed, 13 Jan 2010 22:26:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/09/27/surabaya-startup/#comment-65444</guid>
		<description>Thank you guys so much, i was able to remove the virus.  Thank you once again.</description>
		<content:encoded><![CDATA[<p>Thank you guys so much, i was able to remove the virus.  Thank you once again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus.Win32.Virut.ce by psog_choudai</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/#comment-65442</link>
		<dc:creator>psog_choudai</dc:creator>
		<pubDate>Tue, 12 Jan 2010 23:27:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439#comment-65442</guid>
		<description>This stupid bugger&#039;s put me a week of hard work into this computer.

I can&#039;t say that I&#039;m 100% free of the stupidity this thing does, but... I might have easy tips for getting rid of the virus, and some pointers to note for people who might be having issues:

1. The virus indiscriminantly infects all .exe and .scr files (even inside .zip, .rar, .7z, or any other kind of archive.) It also infects mostly system .dll files.

2. It does NOT infect any other &quot;media&quot; file. These include .mp3, .ogg, .wav, .avi, .mpg extensions and the like.

3. It doesn&#039;t matter if you have more than one internal or external HDD or Flash drive (or any media that is rewritable), anything that meets the infection criteria WILL get infected.

4. Even if one file is already infected, the virus and any instances running WILL re-infect the same file in a different section of the coding.  Thus, multiple scans are necessary to make sure the file is ABSOLUTELY clean.

So... I have a LOT of music and videos that I&#039;m a little too attached to and that I don&#039;t want to lose. When I noticed that this stupid thing targets executables, I realized that I needed to reformat the HDD carrying the OS.  I did, and the virus came back.

I then noticed some strange occurrences.  Obviously, port 65520 was being accessed by winlogon.exe and explorer.exe. Even though this was a fresh install, I needed to reformat again already.

So, I took up the task of arming myself to clear out this virus from my system with the following tools:

1. Windows XP CD
2. Hiren&#039;s Boot CD v. 10.0
3. Ubuntu v. 8.04 Live CD

Here&#039;s how that worked.

1. I turned off my computer and unplugged the power cord and the Ethernet cable. Left off for 30 min, then plugged the power cord (not ethernet) back in, then booted to Hiren&#039;s Boot CD.
2. I used Hiren&#039;s Boot CD&#039;s partition tools to delete all partitions and destroy the data in the HDD carrying Windows XP.
3. I used the HDD Regenerator in the Hard Disk tools section to check for corrupted sectors. Usually this only applies to physical errors and not so much to data, but if a section has been damaged it&#039;s good to know.  Everything came back clean.
4. Went back to Partition Tools and formatted out an NTFS partition for Windows XP.

5. Rebooted and used the Ubuntu Live CD. Using this I was able to get the drivers for anything that I needed on the computer, and clean virus free copies of them because Linux doesn&#039;t have these kinds of virus issues. I also downloaded Virut Removal Tools and Comodo Internet Security and Dr. Web Cure It!. This is good for people that have lost their recovery CDs or their motherboard or display drivers. I placed all these into a clean USB Flash drive. When I copied everything in, I ejected and disconnected the drive.

6. I rebooted into the Windows XP CD. When asked for the desired partition, I performed yet another Format (not quick) on the blank NTFS partition. Proceeded with installing Windows.

7. When Windows loaded, I connected the USB Flash drive and placed its contents on the desktop. Proceeded with installing everything, starting with the basic motherboard drivers all the way to the AV tools and Security software. Ethernet cable is STILL disconnected.

8. Here I noticed none of the system files were behaving erratically. When Comodo Internet Security asked me to update the Virus DB, I then connected the Ethernet cable. Connections were safe, and port 65520 was not being accessed by any program. Definitions were updated, and port 65520 was eventually blocked.

9. Used Dr. Web Cure It! and performed a complete scan of the computer and all disks connected (USB Flash disconnected) overnight. Found a ridiculous amount of instances of Win32.Virut.56. Also found a few miscellaneous backdoors and other trojans.

10. Removed all files mentioned by the Dr. Web scan. Proceeded to scan computer again with Comodo Internet Security AV scan. Few more infections came up, proceeded to remove those as well.

11. Noticed that none of the removed content was on C:\. Proceeded with a deep scan of both HDDs&#039; &quot;System Volume Information&quot; folder. Found another ridiculous set of instances of Win32.Virut.Ce. Removed them all.

12. This is where I find myself.

Every time I idle my computer and it accesses the screen saver, I notice that my computer has found yet another instance of Virut in the non-Windows HDD&#039;s &quot;System Volume Information&quot; folder. I did just scan again and found more instances, so I removed those.

I just can&#039;t seem to tell whether the virus is still active, or if it&#039;s just remnants. When I use the system, Comodo does not alert me of anything. Also, websites are not blocked, and media files from that HDD do not further aggravate the system as I use them.

Though, I think I&#039;m pretty clear! Hope this helps as another guide and alternative to clear out Virut.</description>
		<content:encoded><![CDATA[<p>This stupid bugger&#8217;s put me a week of hard work into this computer.</p>
<p>I can&#8217;t say that I&#8217;m 100% free of the stupidity this thing does, but&#8230; I might have easy tips for getting rid of the virus, and some pointers to note for people who might be having issues:</p>
<p>1. The virus indiscriminantly infects all .exe and .scr files (even inside .zip, .rar, .7z, or any other kind of archive.) It also infects mostly system .dll files.</p>
<p>2. It does NOT infect any other &#8220;media&#8221; file. These include .mp3, .ogg, .wav, .avi, .mpg extensions and the like.</p>
<p>3. It doesn&#8217;t matter if you have more than one internal or external HDD or Flash drive (or any media that is rewritable), anything that meets the infection criteria WILL get infected.</p>
<p>4. Even if one file is already infected, the virus and any instances running WILL re-infect the same file in a different section of the coding.  Thus, multiple scans are necessary to make sure the file is ABSOLUTELY clean.</p>
<p>So&#8230; I have a LOT of music and videos that I&#8217;m a little too attached to and that I don&#8217;t want to lose. When I noticed that this stupid thing targets executables, I realized that I needed to reformat the HDD carrying the OS.  I did, and the virus came back.</p>
<p>I then noticed some strange occurrences.  Obviously, port 65520 was being accessed by winlogon.exe and explorer.exe. Even though this was a fresh install, I needed to reformat again already.</p>
<p>So, I took up the task of arming myself to clear out this virus from my system with the following tools:</p>
<p>1. Windows XP CD<br />
2. Hiren&#8217;s Boot CD v. 10.0<br />
3. Ubuntu v. 8.04 Live CD</p>
<p>Here&#8217;s how that worked.</p>
<p>1. I turned off my computer and unplugged the power cord and the Ethernet cable. Left off for 30 min, then plugged the power cord (not ethernet) back in, then booted to Hiren&#8217;s Boot CD.<br />
2. I used Hiren&#8217;s Boot CD&#8217;s partition tools to delete all partitions and destroy the data in the HDD carrying Windows XP.<br />
3. I used the HDD Regenerator in the Hard Disk tools section to check for corrupted sectors. Usually this only applies to physical errors and not so much to data, but if a section has been damaged it&#8217;s good to know.  Everything came back clean.<br />
4. Went back to Partition Tools and formatted out an NTFS partition for Windows XP.</p>
<p>5. Rebooted and used the Ubuntu Live CD. Using this I was able to get the drivers for anything that I needed on the computer, and clean virus free copies of them because Linux doesn&#8217;t have these kinds of virus issues. I also downloaded Virut Removal Tools and Comodo Internet Security and Dr. Web Cure It!. This is good for people that have lost their recovery CDs or their motherboard or display drivers. I placed all these into a clean USB Flash drive. When I copied everything in, I ejected and disconnected the drive.</p>
<p>6. I rebooted into the Windows XP CD. When asked for the desired partition, I performed yet another Format (not quick) on the blank NTFS partition. Proceeded with installing Windows.</p>
<p>7. When Windows loaded, I connected the USB Flash drive and placed its contents on the desktop. Proceeded with installing everything, starting with the basic motherboard drivers all the way to the AV tools and Security software. Ethernet cable is STILL disconnected.</p>
<p>8. Here I noticed none of the system files were behaving erratically. When Comodo Internet Security asked me to update the Virus DB, I then connected the Ethernet cable. Connections were safe, and port 65520 was not being accessed by any program. Definitions were updated, and port 65520 was eventually blocked.</p>
<p>9. Used Dr. Web Cure It! and performed a complete scan of the computer and all disks connected (USB Flash disconnected) overnight. Found a ridiculous amount of instances of Win32.Virut.56. Also found a few miscellaneous backdoors and other trojans.</p>
<p>10. Removed all files mentioned by the Dr. Web scan. Proceeded to scan computer again with Comodo Internet Security AV scan. Few more infections came up, proceeded to remove those as well.</p>
<p>11. Noticed that none of the removed content was on C:\. Proceeded with a deep scan of both HDDs&#8217; &#8220;System Volume Information&#8221; folder. Found another ridiculous set of instances of Win32.Virut.Ce. Removed them all.</p>
<p>12. This is where I find myself.</p>
<p>Every time I idle my computer and it accesses the screen saver, I notice that my computer has found yet another instance of Virut in the non-Windows HDD&#8217;s &#8220;System Volume Information&#8221; folder. I did just scan again and found more instances, so I removed those.</p>
<p>I just can&#8217;t seem to tell whether the virus is still active, or if it&#8217;s just remnants. When I use the system, Comodo does not alert me of anything. Also, websites are not blocked, and media files from that HDD do not further aggravate the system as I use them.</p>
<p>Though, I think I&#8217;m pretty clear! Hope this helps as another guide and alternative to clear out Virut.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Windows Security Alert by Mitchell</title>
		<link>http://www.precisesecurity.com/blogs/2007/12/27/windows-security-alert/#comment-65441</link>
		<dc:creator>Mitchell</dc:creator>
		<pubDate>Tue, 12 Jan 2010 11:54:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/12/27/windows-security-alert/#comment-65441</guid>
		<description>brad i had same issue my friend told me to run it in safe mode and so far so good.</description>
		<content:encoded><![CDATA[<p>brad i had same issue my friend told me to run it in safe mode and so far so good.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan-Downloader.Zlob.Media-Codec by jesegeary</title>
		<link>http://www.precisesecurity.com/blogs/2006/08/27/media-codec/#comment-65440</link>
		<dc:creator>jesegeary</dc:creator>
		<pubDate>Sun, 10 Jan 2010 17:11:40 +0000</pubDate>
		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/08/27/media-codec/#comment-65440</guid>
		<description>&#1061;&#1086;&#1088;&#1086;&#1096;&#1080;&#1081; &#1089;&#1072;&#1081;&#1090;. &#1058;&#1072;&#1082; &#1076;&#1077;&#1088;&#1078;&#1072;&#1090;&#1100;!!!</description>
		<content:encoded><![CDATA[<p>&#1061;&#1086;&#1088;&#1086;&#1096;&#1080;&#1081; &#1089;&#1072;&#1081;&#1090;. &#1058;&#1072;&#1082; &#1076;&#1077;&#1088;&#1078;&#1072;&#1090;&#1100;!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus:Win32/Virut.BM by Mike</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutbm/#comment-65439</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sun, 10 Jan 2010 00:28:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2447#comment-65439</guid>
		<description>try clearing your CMOS / Flash memory directly after removal takes place. be sure to perform a complete shutdown. Then follow what ever steps there are for clearing the CMOS on your system. I&#039;ve read that it worked for others. Apparently if your machine just reboots and doesn&#039;t do a complete shutdown, the virus will reside in RAM and wait for Win to come back up and infect it again. Nasty bug for sure.</description>
		<content:encoded><![CDATA[<p>try clearing your CMOS / Flash memory directly after removal takes place. be sure to perform a complete shutdown. Then follow what ever steps there are for clearing the CMOS on your system. I&#8217;ve read that it worked for others. Apparently if your machine just reboots and doesn&#8217;t do a complete shutdown, the virus will reside in RAM and wait for Win to come back up and infect it again. Nasty bug for sure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan-Downloader.Zlob.Media-Codec by jesegeary</title>
		<link>http://www.precisesecurity.com/blogs/2006/08/27/media-codec/#comment-65438</link>
		<dc:creator>jesegeary</dc:creator>
		<pubDate>Sat, 09 Jan 2010 14:02:05 +0000</pubDate>
		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/08/27/media-codec/#comment-65438</guid>
		<description>&#1059;&#1074;&#1072;&#1078;&#1072;&#1077;&#1084;&#1099;&#1077; &#1095;&#1080;&#1090;&#1072;&#1090;&#1077;&#1083;&#1080;. &#1057; &#1056;&#1086;&#1078;&#1076;&#1077;&#1089;&#1090;&#1074;&#1086;&#1084; &#1093;&#1088;&#1080;&#1089;&#1090;&#1086;&#1074;&#1099;&#1084; &#1093;&#1086;&#1095;&#1077;&#1090;&#1089;&#1103; &#1074;&#1072;&#1089; &#1087;&#1086;&#1079;&#1076;&#1088;&#1072;&#1074;&#1080;&#1090;&#1100;. &#1040;&#1076;&#1084;&#1080;&#1085;&#1091; &#1089;&#1072;&#1081;&#1090;&#1072; &#1086;&#1090;&#1076;&#1077;&#1083;&#1100;&#1085;&#1086;&#1077; &#1087;&#1086;&#1078;&#1077;&#1083;&#1072;&#1085;&#1080;&#1077;-&#1087;&#1086;&#1073;&#1086;&#1083;&#1100;&#1096;&#1077; &#1095;&#1080;&#1090;&#1072;&#1090;&#1077;&#1083;&#1077;&#1081; &#1085;&#1072; &#1073;&#1083;&#1086;&#1075;&#1077;, &#1082;&#1088;&#1077;&#1072;&#1090;&#1080;&#1074;&#1085;&#1099;&#1093; &#1080;&#1085;&#1090;&#1077;&#1088;&#1077;&#1089;&#1085;&#1099;&#1093; &#1089;&#1090;&#1072;&#1090;&#1077;&#1081; &#1080; &#1074;&#1089;&#1077;&#1075;&#1086; &#1074;&#1089;&#1077;&#1075;&#1086; &#1074;&#1089;&#1077;&#1075;&#1086; :)</description>
		<content:encoded><![CDATA[<p>&#1059;&#1074;&#1072;&#1078;&#1072;&#1077;&#1084;&#1099;&#1077; &#1095;&#1080;&#1090;&#1072;&#1090;&#1077;&#1083;&#1080;. &#1057; &#1056;&#1086;&#1078;&#1076;&#1077;&#1089;&#1090;&#1074;&#1086;&#1084; &#1093;&#1088;&#1080;&#1089;&#1090;&#1086;&#1074;&#1099;&#1084; &#1093;&#1086;&#1095;&#1077;&#1090;&#1089;&#1103; &#1074;&#1072;&#1089; &#1087;&#1086;&#1079;&#1076;&#1088;&#1072;&#1074;&#1080;&#1090;&#1100;. &#1040;&#1076;&#1084;&#1080;&#1085;&#1091; &#1089;&#1072;&#1081;&#1090;&#1072; &#1086;&#1090;&#1076;&#1077;&#1083;&#1100;&#1085;&#1086;&#1077; &#1087;&#1086;&#1078;&#1077;&#1083;&#1072;&#1085;&#1080;&#1077;-&#1087;&#1086;&#1073;&#1086;&#1083;&#1100;&#1096;&#1077; &#1095;&#1080;&#1090;&#1072;&#1090;&#1077;&#1083;&#1077;&#1081; &#1085;&#1072; &#1073;&#1083;&#1086;&#1075;&#1077;, &#1082;&#1088;&#1077;&#1072;&#1090;&#1080;&#1074;&#1085;&#1099;&#1093; &#1080;&#1085;&#1090;&#1077;&#1088;&#1077;&#1089;&#1085;&#1099;&#1093; &#1089;&#1090;&#1072;&#1090;&#1077;&#1081; &#1080; &#1074;&#1089;&#1077;&#1075;&#1086; &#1074;&#1089;&#1077;&#1075;&#1086; &#1074;&#1089;&#1077;&#1075;&#1086; :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TR/Crypt.XPACK.Gen by Abe</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/17/tr-crypt-xpack-gen/#comment-65436</link>
		<dc:creator>Abe</dc:creator>
		<pubDate>Thu, 07 Jan 2010 03:52:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2568#comment-65436</guid>
		<description>Hi. I have the following:
TR/Crypt.XPACK.Gen
 
I&#039;m not sure if it&#039;s still in my system but i have the proof!! My laptop is so slow, everytime i open the laptop, Avira Gaurd is disabled, and sometimes my firewall turns of everytime i open the laptop.

Please help me!!!! I&#039;m not sure if it&#039;s in my laptop but i&#039;m very sure it&#039;s infected!! thanks</description>
		<content:encoded><![CDATA[<p>Hi. I have the following:<br />
TR/Crypt.XPACK.Gen</p>
<p>I&#8217;m not sure if it&#8217;s still in my system but i have the proof!! My laptop is so slow, everytime i open the laptop, Avira Gaurd is disabled, and sometimes my firewall turns of everytime i open the laptop.</p>
<p>Please help me!!!! I&#8217;m not sure if it&#8217;s in my laptop but i&#8217;m very sure it&#8217;s infected!! thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Antivirus 2010 by sally</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65435</link>
		<dc:creator>sally</dc:creator>
		<pubDate>Wed, 06 Jan 2010 18:53:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/08/antivirus-2010/#comment-65435</guid>
		<description>Hi I had this virus recently and have managed to remove it, but now my p.c wont connect to the internet, hubby seems to thiink it has something to with the firewall settings, he said there are 3 ports that are conncted to the firewall settings that appear to have been changed and we cant work out how to change them back , almost like the virus has changed something!! Can anyone help !!</description>
		<content:encoded><![CDATA[<p>Hi I had this virus recently and have managed to remove it, but now my p.c wont connect to the internet, hubby seems to thiink it has something to with the firewall settings, he said there are 3 ports that are conncted to the firewall settings that appear to have been changed and we cant work out how to change them back , almost like the virus has changed something!! Can anyone help !!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Zlob.Porn.Ad Adware by Greg</title>
		<link>http://www.precisesecurity.com/blogs/2008/07/03/zlobpornad-adware/#comment-65434</link>
		<dc:creator>Greg</dc:creator>
		<pubDate>Tue, 05 Jan 2010 22:56:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/07/03/zlobpornad-adware/#comment-65434</guid>
		<description>What a intresting story
When reading could it be the same of related storys in 
&lt;a href=&quot;www.avg-free-download.org&quot; rel=&quot;nofollow&quot;&gt;avg free download&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>What a intresting story<br />
When reading could it be the same of related storys in<br />
<a href="www.avg-free-download.org" rel="nofollow">avg free download</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by MEEEE</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65433</link>
		<dc:creator>MEEEE</dc:creator>
		<pubDate>Tue, 05 Jan 2010 17:44:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65433</guid>
		<description>change the file extension to something else, like readme.pdf ==&gt; readme.pdf.SSS
tHIS WILL FOOL THE VIRUS, i HOPE.....GOOD LUCK!</description>
		<content:encoded><![CDATA[<p>change the file extension to something else, like readme.pdf ==&gt; readme.pdf.SSS<br />
tHIS WILL FOOL THE VIRUS, i HOPE&#8230;..GOOD LUCK!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SmitfraudFixTool by jmcisaac@seascape.ns.ca</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/13/smitfraudfixtool/#comment-65432</link>
		<dc:creator>jmcisaac@seascape.ns.ca</dc:creator>
		<pubDate>Tue, 05 Jan 2010 17:32:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2502#comment-65432</guid>
		<description>I bought a subscription to your product(Smitfraudfix) and when I got my conputer reformatted, it disappeared.  Could you reinstate this subscription for me please?

                              John McIsaac</description>
		<content:encoded><![CDATA[<p>I bought a subscription to your product(Smitfraudfix) and when I got my conputer reformatted, it disappeared.  Could you reinstate this subscription for me please?</p>
<p>                              John McIsaac</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by How to remove Lsas.Blaster.Keyloger &#124; Jon Murphy Dot Net</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65431</link>
		<dc:creator>How to remove Lsas.Blaster.Keyloger &#124; Jon Murphy Dot Net</dc:creator>
		<pubDate>Tue, 05 Jan 2010 12:55:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65431</guid>
		<description>[...] Tags: how to remove Lsas.Blaster.Keyloger, Lsas Blaster Keyloger, Lsas.Blaster.Keyloger, Lsas.Blaster.Keyloger removal tool, Lsas.Blaster.Keyloger virus    via precisesecurity.com [...]</description>
		<content:encoded><![CDATA[<p>[...] Tags: how to remove Lsas.Blaster.Keyloger, Lsas Blaster Keyloger, Lsas.Blaster.Keyloger, Lsas.Blaster.Keyloger removal tool, Lsas.Blaster.Keyloger virus    via precisesecurity.com [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on System Security by How to remove Lsas.Blaster.Keyloger &#124; Jon Murphy Dot Net</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/system-security/#comment-65430</link>
		<dc:creator>How to remove Lsas.Blaster.Keyloger &#124; Jon Murphy Dot Net</dc:creator>
		<pubDate>Tue, 05 Jan 2010 12:55:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/system-secuirty/#comment-65430</guid>
		<description>[...] is part of the rogue program System Security which display it as a threat detected. It will then prompt users to download and install the said [...]</description>
		<content:encoded><![CDATA[<p>[...] is part of the rogue program System Security which display it as a threat detected. It will then prompt users to download and install the said [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse IRC/Backdoor.SDBot4.gsi by Fernando</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/12/trojan-horse-ircbackdoorsdbot4gsi/#comment-65429</link>
		<dc:creator>Fernando</dc:creator>
		<pubDate>Tue, 05 Jan 2010 03:53:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/12/trojan-horse-ircbackdoorsdbot4gsi/#comment-65429</guid>
		<description>This trojan popped up when i did a virus scan with AVG, it was linked to my Internet Download Manager...I suppose i have to delete IDM now. Oh well, it was great while it lasted.</description>
		<content:encoded><![CDATA[<p>This trojan popped up when i did a virus scan with AVG, it was linked to my Internet Download Manager&#8230;I suppose i have to delete IDM now. Oh well, it was great while it lasted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Win32/Cryptor by YDB</title>
		<link>http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65425</link>
		<dc:creator>YDB</dc:creator>
		<pubDate>Sat, 02 Jan 2010 22:22:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/10/28/win32cryptor/#comment-65425</guid>
		<description>The issue for me is finally resolved!
After following all that was written here AVG kept popping up with virus alerts even though the scans came up clean.
I could not do a system restore since the virus infected to restore files. 
Windows update was also not working.
This is what I did:

1. Download the latest Windows Malicious Software Removal Tool at hxxp://www.microsoft.com/downloads/en/default.aspx
run the tool. restart computer.

2. Since windows update wasn&#039;t working I opened up a support ticket at hxxp://support.microsoft.com/ph/6527/en-us/#tab0
click contact a support professional by email. They helped me through the process until I was able to download all the critical security updates I missed.

3. Run a full free PC scan at hxxp://onecare.live.com/site/en-us/default.htm
follow instuctions after scan.

4. Download Microsoft Security Essentials from same website.

5. Disable all anti-virus/spyware programs and run Microsoft Security Essentials complete scan. 

6. Repeat steps 3 and 5 until all infections are removed.</description>
		<content:encoded><![CDATA[<p>The issue for me is finally resolved!<br />
After following all that was written here AVG kept popping up with virus alerts even though the scans came up clean.<br />
I could not do a system restore since the virus infected to restore files.<br />
Windows update was also not working.<br />
This is what I did:</p>
<p>1. Download the latest Windows Malicious Software Removal Tool at hxxp://www.microsoft.com/downloads/en/default.aspx<br />
run the tool. restart computer.</p>
<p>2. Since windows update wasn&#8217;t working I opened up a support ticket at hxxp://support.microsoft.com/ph/6527/en-us/#tab0<br />
click contact a support professional by email. They helped me through the process until I was able to download all the critical security updates I missed.</p>
<p>3. Run a full free PC scan at hxxp://onecare.live.com/site/en-us/default.htm<br />
follow instuctions after scan.</p>
<p>4. Download Microsoft Security Essentials from same website.</p>
<p>5. Disable all anti-virus/spyware programs and run Microsoft Security Essentials complete scan. </p>
<p>6. Repeat steps 3 and 5 until all infections are removed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by shebaw</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65424</link>
		<dc:creator>shebaw</dc:creator>
		<pubDate>Sat, 02 Jan 2010 16:32:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65424</guid>
		<description>@Jaffer, why is my comment not costructive? Is that because it pointed out the truth, im confused here! 

&quot;We have a number of IT solution providers who are solving a number of problems&quot;... what problems, do you call a stupid straight froward database to calculate some stupid calculations real programming? Where were they when dulla struck? Any real programmer can program a remover for dulla but it took them ages before they can manage that, that shows how inexperienced and dumb they are.

If you have evidences, why don&#039;t you post it here. You make it sound like some type of mesterious mission. And if programming a PE infector is that easy, then why did it take them so long. And how many of the CS graduates here can program a remover for it, how many? I bet 99.99% of the graduates don&#039;t even know the difference between PE infector and some other script &quot;viruses&quot;, let alone knowing the structure of PE and programming a remover for a PE infector virus!!!</description>
		<content:encoded><![CDATA[<p>@Jaffer, why is my comment not costructive? Is that because it pointed out the truth, im confused here! </p>
<p>&#8220;We have a number of IT solution providers who are solving a number of problems&#8221;&#8230; what problems, do you call a stupid straight froward database to calculate some stupid calculations real programming? Where were they when dulla struck? Any real programmer can program a remover for dulla but it took them ages before they can manage that, that shows how inexperienced and dumb they are.</p>
<p>If you have evidences, why don&#8217;t you post it here. You make it sound like some type of mesterious mission. And if programming a PE infector is that easy, then why did it take them so long. And how many of the CS graduates here can program a remover for it, how many? I bet 99.99% of the graduates don&#8217;t even know the difference between PE infector and some other script &#8220;viruses&#8221;, let alone knowing the structure of PE and programming a remover for a PE infector virus!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TR/Crypt.XPACK.Gen by me</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/17/tr-crypt-xpack-gen/#comment-65421</link>
		<dc:creator>me</dc:creator>
		<pubDate>Thu, 31 Dec 2009 18:36:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2568#comment-65421</guid>
		<description>http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FSELEX%2EA&amp;VSect=Sn

do exactly as it says, good luck</description>
		<content:encoded><![CDATA[<p><a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FSELEX%2EA&amp;VSect=Sn" rel="nofollow">http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FSELEX%2EA&amp;VSect=Sn</a></p>
<p>do exactly as it says, good luck</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by KENNY</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65418</link>
		<dc:creator>KENNY</dc:creator>
		<pubDate>Tue, 29 Dec 2009 16:57:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65418</guid>
		<description>By the way... once my computer was restored, I installed the &quot;Malwarebytes Anti-Malware&quot; software via the Malwarebytes Anti-Malware Instillation Wizard generated from the mbam-setup link on betanews.com/malwarebytes/mbam-setup.exe</description>
		<content:encoded><![CDATA[<p>By the way&#8230; once my computer was restored, I installed the &#8220;Malwarebytes Anti-Malware&#8221; software via the Malwarebytes Anti-Malware Instillation Wizard generated from the mbam-setup link on betanews.com/malwarebytes/mbam-setup.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lsas.Blaster.Keyloger by KENNY</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65417</link>
		<dc:creator>KENNY</dc:creator>
		<pubDate>Tue, 29 Dec 2009 16:37:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/#comment-65417</guid>
		<description>I was having &quot;fits&quot; trying to get rid of the Lsas.Blaster.keyloger worm virus that kept popping up and preventing me from accessing anything that would assist, or, give me a clue as to what was going on. Finally after two and a half hours of several failed repeated attempts to download and run various softwware and clean up tools and devices. I shut off my computer and restarted it. While it was re-booting I pushed the F8 key before the &quot;Windows&quot; started. The computer entered the &quot;safe mode&quot;. I pushed the &quot;enter&quot; key, this allowed me the option to &quot;click-on&quot; as &quot;the administrator&quot;. Once I did this I was given the window option &quot;to,or, not to&quot; enter the safe mode. Choosing &quot;not to&quot; allowed me finally... the option to restore my computer. I clicked &quot;not to&quot; and was then given the option to restore my computer to a previous setting. Since I had been going at the failed attempts to get rid of the Lsas.Blaster.Keyloger worm virus for several hours, I just restored my computer to the previous day. Everything restored perfectly! It worked. This is a slight variation of the suggestion that I recieved in this comment section, except that I didn&#039;t try to run the embam-setup.exe from the &quot;safe mode&quot;.  Basically, I made the right decisions by following the instruction options that I was presented with. And as each suceeding window opened during this navigation process I took a breath of reliefe because I could see as I was going in the right direction. Try it! WHATEVER WORKS, RIGHT!!!   THANKS</description>
		<content:encoded><![CDATA[<p>I was having &#8220;fits&#8221; trying to get rid of the Lsas.Blaster.keyloger worm virus that kept popping up and preventing me from accessing anything that would assist, or, give me a clue as to what was going on. Finally after two and a half hours of several failed repeated attempts to download and run various softwware and clean up tools and devices. I shut off my computer and restarted it. While it was re-booting I pushed the F8 key before the &#8220;Windows&#8221; started. The computer entered the &#8220;safe mode&#8221;. I pushed the &#8220;enter&#8221; key, this allowed me the option to &#8220;click-on&#8221; as &#8220;the administrator&#8221;. Once I did this I was given the window option &#8220;to,or, not to&#8221; enter the safe mode. Choosing &#8220;not to&#8221; allowed me finally&#8230; the option to restore my computer. I clicked &#8220;not to&#8221; and was then given the option to restore my computer to a previous setting. Since I had been going at the failed attempts to get rid of the Lsas.Blaster.Keyloger worm virus for several hours, I just restored my computer to the previous day. Everything restored perfectly! It worked. This is a slight variation of the suggestion that I recieved in this comment section, except that I didn&#8217;t try to run the embam-setup.exe from the &#8220;safe mode&#8221;.  Basically, I made the right decisions by following the instruction options that I was presented with. And as each suceeding window opened during this navigation process I took a breath of reliefe because I could see as I was going in the right direction. Try it! WHATEVER WORKS, RIGHT!!!   THANKS</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Anti-Virus Number-1 by jackass</title>
		<link>http://www.precisesecurity.com/blogs/2009/03/17/anti-virus-number-1/#comment-65416</link>
		<dc:creator>jackass</dc:creator>
		<pubDate>Tue, 29 Dec 2009 15:09:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3092#comment-65416</guid>
		<description>this is a new spesies threat, warning to you, dont used</description>
		<content:encoded><![CDATA[<p>this is a new spesies threat, warning to you, dont used</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on BOO/Sinowal.C by bla</title>
		<link>http://www.precisesecurity.com/blogs/2009/04/07/boo-sinowal-c/#comment-65415</link>
		<dc:creator>bla</dc:creator>
		<pubDate>Tue, 29 Dec 2009 07:35:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=3593#comment-65415</guid>
		<description>Tried using Avira for the virus and still doesn&#039;t work. the boot repair thing I mean</description>
		<content:encoded><![CDATA[<p>Tried using Avira for the virus and still doesn&#8217;t work. the boot repair thing I mean</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ~dulla@204 Virus by Jaffer</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65413</link>
		<dc:creator>Jaffer</dc:creator>
		<pubDate>Mon, 28 Dec 2009 19:57:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/#comment-65413</guid>
		<description>Dear Shebaw, ur comment is not constructive. Are sure about what u wrote, i don&#039;t think. We have a number of IT solution providers who are solving a number of problems. anyway u can email me for real evidences.

there r a number of C++ virus scripts on hackers and P2P site anyone with little programming skill specially in C++ can modify and increase the risk of the virus. Its is not a big deal nowadays.

for those who r suffering from ~dulla^@204~ u files could be recovered partially, if u uses Easy Recovery Professional or Advanced Word repair programs. If can&#039;t find the Software emailme at jaffermohATyahooDOTcom
wishing u all including ephrem, all  the best.</description>
		<content:encoded><![CDATA[<p>Dear Shebaw, ur comment is not constructive. Are sure about what u wrote, i don&#8217;t think. We have a number of IT solution providers who are solving a number of problems. anyway u can email me for real evidences.</p>
<p>there r a number of C++ virus scripts on hackers and P2P site anyone with little programming skill specially in C++ can modify and increase the risk of the virus. Its is not a big deal nowadays.</p>
<p>for those who r suffering from ~dulla^@204~ u files could be recovered partially, if u uses Easy Recovery Professional or Advanced Word repair programs. If can&#8217;t find the Software emailme at jaffermohATyahooDOTcom<br />
wishing u all including ephrem, all  the best.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
