<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments for Spyware-Virus Files and Process</title>
	<atom:link href="http://www.precisesecurity.com/files-process/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.precisesecurity.com/files-process</link>
	<description></description>
	<pubDate>Fri, 20 Nov 2009 23:10:36 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Ramal Jodoh.pif by devy putri pratama</title>
		<link>http://www.precisesecurity.com/files-process/2007/11/01/ramal-jodohpif/#comment-4145</link>
		<dc:creator>devy putri pratama</dc:creator>
		<pubDate>Mon, 16 Nov 2009 09:42:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2007/11/01/ramal-jodohpif/#comment-4145</guid>
		<description>ramalkan saya ttgjodoh saya...dan apa saya bs menikah</description>
		<content:encoded><![CDATA[<p>ramalkan saya ttgjodoh saya&#8230;dan apa saya bs menikah</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ramal Jodoh.pif by devy putri pratama</title>
		<link>http://www.precisesecurity.com/files-process/2007/11/01/ramal-jodohpif/#comment-4144</link>
		<dc:creator>devy putri pratama</dc:creator>
		<pubDate>Mon, 16 Nov 2009 09:41:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2007/11/01/ramal-jodohpif/#comment-4144</guid>
		<description>ramalkan ttg jodoh saya..</description>
		<content:encoded><![CDATA[<p>ramalkan ttg jodoh saya..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by bekyo</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4143</link>
		<dc:creator>bekyo</dc:creator>
		<pubDate>Mon, 16 Nov 2009 05:28:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4143</guid>
		<description>me too.. 

i coudn't delete also.</description>
		<content:encoded><![CDATA[<p>me too.. </p>
<p>i coudn&#8217;t delete also.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on regsvr.exe by harish</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/21/regsvrexe/#comment-4142</link>
		<dc:creator>harish</dc:creator>
		<pubDate>Sat, 14 Nov 2009 06:47:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/21/regsvrexe/#comment-4142</guid>
		<description>The procedure solves issue to an extent.

It only disable the regsvr virus but kill all the related registry stting.  If you open you Regedit in the startup option, you will still see the Regsvr option which can be enabled or disbaled....Any way to remove it from here??

harry_g1979@rediffmail.com</description>
		<content:encoded><![CDATA[<p>The procedure solves issue to an extent.</p>
<p>It only disable the regsvr virus but kill all the related registry stting.  If you open you Regedit in the startup option, you will still see the Regsvr option which can be enabled or disbaled&#8230;.Any way to remove it from here??</p>
<p><a href="mailto:harry_g1979@rediffmail.com">harry_g1979@rediffmail.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FUvirus.exe by ega</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/11/fuvirusexe/#comment-4141</link>
		<dc:creator>ega</dc:creator>
		<pubDate>Thu, 12 Nov 2009 01:21:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1373#comment-4141</guid>
		<description>i'm also having the same problem....malwarebytes is effecitve in removing fuvirus....but all the files converted to .exe files were gone...</description>
		<content:encoded><![CDATA[<p>i&#8217;m also having the same problem&#8230;.malwarebytes is effecitve in removing fuvirus&#8230;.but all the files converted to .exe files were gone&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by gan</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4138</link>
		<dc:creator>gan</dc:creator>
		<pubDate>Tue, 03 Nov 2009 07:19:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4138</guid>
		<description>hi..

i have finished doing steps 1 to 4..

but i couldn't delete the ff files in step5:

%System%\hlpsvc1.exe
%System%\hlpsvc2.exe
%SystemDrive%\Read1st!.exe
%SystemDrive%\goats.exe
%UserProfile%\My Documents\Classified.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Keyboard\kbdsys.exe
C:\Documents and Settings\All Users\Application Data\PolariSys\dirlock.exe

i need help please... thank you.

God Bless. :D</description>
		<content:encoded><![CDATA[<p>hi..</p>
<p>i have finished doing steps 1 to 4..</p>
<p>but i couldn&#8217;t delete the ff files in step5:</p>
<p>%System%\hlpsvc1.exe<br />
%System%\hlpsvc2.exe<br />
%SystemDrive%\Read1st!.exe<br />
%SystemDrive%\goats.exe<br />
%UserProfile%\My Documents\Classified.exe<br />
C:\Documents and Settings\All Users\Application Data\Microsoft\Keyboard\kbdsys.exe<br />
C:\Documents and Settings\All Users\Application Data\PolariSys\dirlock.exe</p>
<p>i need help please&#8230; thank you.</p>
<p>God Bless. <img src='http://www.precisesecurity.com/files-process/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winupgro.exe by Flon Klar</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/28/winupgro/#comment-4137</link>
		<dc:creator>Flon Klar</dc:creator>
		<pubDate>Mon, 02 Nov 2009 14:06:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1408#comment-4137</guid>
		<description>Why is it that when I run the batch file, the DOS window runs a constant stream of "md5deep" is not a valid program, command, or batch file?"  The "out" file is also blank at the end of the scan.  Am I doing something wrong?</description>
		<content:encoded><![CDATA[<p>Why is it that when I run the batch file, the DOS window runs a constant stream of &#8220;md5deep&#8221; is not a valid program, command, or batch file?&#8221;  The &#8220;out&#8221; file is also blank at the end of the scan.  Am I doing something wrong?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winupgro.exe by Piotr</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/28/winupgro/#comment-4136</link>
		<dc:creator>Piotr</dc:creator>
		<pubDate>Sat, 31 Oct 2009 14:42:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1408#comment-4136</guid>
		<description>Thank you, Yasser. Thanks to your post I was able to remove the winupgro.exe. My antivirus, NOD32, as well as Windows Defender got their arses kicked by it. Luckily my PC is now clean.</description>
		<content:encoded><![CDATA[<p>Thank you, Yasser. Thanks to your post I was able to remove the winupgro.exe. My antivirus, NOD32, as well as Windows Defender got their arses kicked by it. Luckily my PC is now clean.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by Zac</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4134</link>
		<dc:creator>Zac</dc:creator>
		<pubDate>Fri, 23 Oct 2009 03:06:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4134</guid>
		<description>Avast can detect and remove TRUE_LOVE.EXE. But the thing is it wont automatically detect unless you scan the folder that has the virus.</description>
		<content:encoded><![CDATA[<p>Avast can detect and remove TRUE_LOVE.EXE. But the thing is it wont automatically detect unless you scan the folder that has the virus.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ogard.exe by CCCP</title>
		<link>http://www.precisesecurity.com/files-process/2009/02/17/ogard-exe/#comment-4130</link>
		<dc:creator>CCCP</dc:creator>
		<pubDate>Sun, 18 Oct 2009 21:40:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1535#comment-4130</guid>
		<description>Try to boot in safe mode then find it and try to delete or u can try vista cause im hearing ti doesnt work on vista</description>
		<content:encoded><![CDATA[<p>Try to boot in safe mode then find it and try to delete or u can try vista cause im hearing ti doesnt work on vista</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by Jefferson</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4129</link>
		<dc:creator>Jefferson</dc:creator>
		<pubDate>Fri, 16 Oct 2009 04:45:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4129</guid>
		<description>How to remove this virus... 



1.  Boot in safe mode with command prompt. Do NOT boot on safe mode with networking. the virus will be active. 
 &gt;to boot in safe mode&gt;&gt;&gt;start your computer&gt;&gt; while restarting press F8&gt;&gt; then choose safe mode

2.  Run regedit (Start &gt;&gt; Run &gt;&gt; cmd) 
3.  Delete the following registry entries: 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"WinSys" = "%Windir%\system.exe" 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"LSAShell" = "%Windir%\lsass.exe" 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"SessionMngr" = "C:\Documents and Settings\All Users\Application Data\PolariSys\dirlock.exe" 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe \"C:\Documents and Settings\All Users\Application Data\Microsoft\Keyboard\kbdsys.exe\"

4. Edit the following entries too: 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\"DisableSR" = "1" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"Hidden" = "2" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"HideFileExt" = "1" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"ShowSuperHidden" = "1" 
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"Hidden" = "2" 
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"HideFileExt" = "1" 
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"ShowSuperHidden" = "0" 
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"SuperHidden" = "1" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoFolderOptions" = "1"


Note: "0" is to disable, "1" is to enable. 

Very Important Note: 
Use Attribute Changer first to fix regular folders' attribute BEFORE fixing the registry. 
________________________________________

here's my regentry for the above: 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\"DisableSR" = "1" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"Hidden" = "2" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"HideFileExt" = "1" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"ShowSuperHidden" = "0" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"SuperHidden" = "0" 

________________________________________


5. Manually delete the following files 
%System%\hlpsvc1.exe 
%System%\hlpsvc2.exe 
%SystemDrive%\Read1st!.exe 
%SystemDrive%\goats.exe 
%Windir%\Classified.exe 
%Windir%\system.exe 
%Windir%\lsass.exe 
%Windir%\shutdown.dll 
%UserProfile%\My Documents\Classified.exe 
C:\Documents and Settings\All Users\Application Data\Microsoft\Keyboard\kbdsys.exe 
C:\Documents and Settings\All Users\Application Data\PolariSys\dirlock.exe 

Also clear your startup folder

%Windir%\ is usually Windows (unless you specified a diff one upon OS installation) 
%system% and %systemDrive%\ is the drive where your OS is (usually C: drive)</description>
		<content:encoded><![CDATA[<p>How to remove this virus&#8230; </p>
<p>1.  Boot in safe mode with command prompt. Do NOT boot on safe mode with networking. the virus will be active.<br />
 &gt;to boot in safe mode&gt;&gt;&gt;start your computer&gt;&gt; while restarting press F8&gt;&gt; then choose safe mode</p>
<p>2.  Run regedit (Start &gt;&gt; Run &gt;&gt; cmd)<br />
3.  Delete the following registry entries:<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\&#8221;WinSys&#8221; = &#8220;%Windir%\system.exe&#8221;<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;LSAShell&#8221; = &#8220;%Windir%\lsass.exe&#8221;<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;SessionMngr&#8221; = &#8220;C:\Documents and Settings\All Users\Application Data\PolariSys\dirlock.exe&#8221;<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&#8221;Shell&#8221; = &#8220;Explorer.exe \&#8221;C:\Documents and Settings\All Users\Application Data\Microsoft\Keyboard\kbdsys.exe\&#8221;</p>
<p>4. Edit the following entries too:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\&#8221;DisableSR&#8221; = &#8220;1&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;Hidden&#8221; = &#8220;2&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;HideFileExt&#8221; = &#8220;1&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;ShowSuperHidden&#8221; = &#8220;1&#8243;<br />
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;Hidden&#8221; = &#8220;2&#8243;<br />
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;HideFileExt&#8221; = &#8220;1&#8243;<br />
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;ShowSuperHidden&#8221; = &#8220;0&#8243;<br />
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;SuperHidden&#8221; = &#8220;1&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\&#8221;NoFolderOptions&#8221; = &#8220;1&#8243;</p>
<p>Note: &#8220;0&#8243; is to disable, &#8220;1&#8243; is to enable. </p>
<p>Very Important Note:<br />
Use Attribute Changer first to fix regular folders&#8217; attribute BEFORE fixing the registry.<br />
________________________________________</p>
<p>here&#8217;s my regentry for the above:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\&#8221;DisableSR&#8221; = &#8220;1&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;Hidden&#8221; = &#8220;2&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;HideFileExt&#8221; = &#8220;1&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;ShowSuperHidden&#8221; = &#8220;0&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;SuperHidden&#8221; = &#8220;0&#8243; </p>
<p>________________________________________</p>
<p>5. Manually delete the following files<br />
%System%\hlpsvc1.exe<br />
%System%\hlpsvc2.exe<br />
%SystemDrive%\Read1st!.exe<br />
%SystemDrive%\goats.exe<br />
%Windir%\Classified.exe<br />
%Windir%\system.exe<br />
%Windir%\lsass.exe<br />
%Windir%\shutdown.dll<br />
%UserProfile%\My Documents\Classified.exe<br />
C:\Documents and Settings\All Users\Application Data\Microsoft\Keyboard\kbdsys.exe<br />
C:\Documents and Settings\All Users\Application Data\PolariSys\dirlock.exe </p>
<p>Also clear your startup folder</p>
<p>%Windir%\ is usually Windows (unless you specified a diff one upon OS installation)<br />
%system% and %systemDrive%\ is the drive where your OS is (usually C: drive)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by kirby</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4128</link>
		<dc:creator>kirby</dc:creator>
		<pubDate>Fri, 16 Oct 2009 03:16:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4128</guid>
		<description>how do i show all the folders????</description>
		<content:encoded><![CDATA[<p>how do i show all the folders????</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by kirby</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4127</link>
		<dc:creator>kirby</dc:creator>
		<pubDate>Fri, 16 Oct 2009 03:15:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4127</guid>
		<description>all my foldera are gone. there is no folder options. how do i get it back? pls help jeff</description>
		<content:encoded><![CDATA[<p>all my foldera are gone. there is no folder options. how do i get it back? pls help jeff</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by kirby</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4126</link>
		<dc:creator>kirby</dc:creator>
		<pubDate>Fri, 16 Oct 2009 00:11:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4126</guid>
		<description>thanks jeff!</description>
		<content:encoded><![CDATA[<p>thanks jeff!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by weirdzal</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4125</link>
		<dc:creator>weirdzal</dc:creator>
		<pubDate>Thu, 15 Oct 2009 03:29:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4125</guid>
		<description>can i just copy the "Advanced" folder from another pc and paste it on the directory on my pc?</description>
		<content:encoded><![CDATA[<p>can i just copy the &#8220;Advanced&#8221; folder from another pc and paste it on the directory on my pc?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by weirdzal</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4124</link>
		<dc:creator>weirdzal</dc:creator>
		<pubDate>Wed, 14 Oct 2009 01:49:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4124</guid>
		<description>Hi Jeff...what if in the part below where the "Advanced" folder is missing in my case...how do i go around with this?

HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\”Hidden” = “2?
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer
Advanced\”HideFileExt” = “1?
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\”ShowSuperHidden” = “0?
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\”SuperHidden” = “1?


Thanks for all the help i could get =)</description>
		<content:encoded><![CDATA[<p>Hi Jeff&#8230;what if in the part below where the &#8220;Advanced&#8221; folder is missing in my case&#8230;how do i go around with this?</p>
<p>HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\<br />
Advanced\”Hidden” = “2?<br />
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer<br />
Advanced\”HideFileExt” = “1?<br />
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\<br />
Advanced\”ShowSuperHidden” = “0?<br />
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\<br />
Advanced\”SuperHidden” = “1?</p>
<p>Thanks for all the help i could get =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on zxx by bgeo</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/15/zxx/#comment-4123</link>
		<dc:creator>bgeo</dc:creator>
		<pubDate>Mon, 12 Oct 2009 17:54:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2061#comment-4123</guid>
		<description>Just ran a scan with STOPzilla and removed 81 threats - however, there was one with a high threat quotiant, Zxx, which Stopzilla could not remove - what is it?  how dangerous?  I can't find it in any component/program list - how do I get rid of it?</description>
		<content:encoded><![CDATA[<p>Just ran a scan with STOPzilla and removed 81 threats - however, there was one with a high threat quotiant, Zxx, which Stopzilla could not remove - what is it?  how dangerous?  I can&#8217;t find it in any component/program list - how do I get rid of it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by loganathan</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4122</link>
		<dc:creator>loganathan</dc:creator>
		<pubDate>Sun, 04 Oct 2009 09:32:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4122</guid>
		<description>i have avast antivirus.but true love.exe virus cant able to remove by avast .its permanently in my pendrive. icant able to format my pen drive.</description>
		<content:encoded><![CDATA[<p>i have avast antivirus.but true love.exe virus cant able to remove by avast .its permanently in my pendrive. icant able to format my pen drive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MarioForever.exe by cisso</title>
		<link>http://www.precisesecurity.com/files-process/2008/05/10/marioforeverexe/#comment-4121</link>
		<dc:creator>cisso</dc:creator>
		<pubDate>Tue, 29 Sep 2009 18:19:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1136#comment-4121</guid>
		<description>je demande le jeu marioforever.zip 18 Mo
ou marioforever.exe 16 Mo</description>
		<content:encoded><![CDATA[<p>je demande le jeu marioforever.zip 18 Mo<br />
ou marioforever.exe 16 Mo</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winupgro.exe by Alex</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/28/winupgro/#comment-4119</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Sun, 27 Sep 2009 02:50:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1408#comment-4119</guid>
		<description>Thanks Yasser. Worked for me. Similar file I found was NtuneCmd.exe in Nvidia Ntune folder. Deleted both NtuneCmd.exe and winupgro.exe and their registry entries, and it worked.
Creating checksum lasted about 10 hours, so thanks 
to Anish for his workaround tip too.</description>
		<content:encoded><![CDATA[<p>Thanks Yasser. Worked for me. Similar file I found was NtuneCmd.exe in Nvidia Ntune folder. Deleted both NtuneCmd.exe and winupgro.exe and their registry entries, and it worked.<br />
Creating checksum lasted about 10 hours, so thanks<br />
to Anish for his workaround tip too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by ragend</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4118</link>
		<dc:creator>ragend</dc:creator>
		<pubDate>Fri, 25 Sep 2009 13:24:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4118</guid>
		<description>i have true-love.exe on my computer.....................</description>
		<content:encoded><![CDATA[<p>i have true-love.exe on my computer&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winupgro.exe by Anish</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/28/winupgro/#comment-4117</link>
		<dc:creator>Anish</dc:creator>
		<pubDate>Wed, 23 Sep 2009 06:04:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1408#comment-4117</guid>
		<description>Thanks Yasser and everyone. Your tip was a great help.
My C drive contains huge amount of data and it took more than 3 hours to create checksum for half of the files in hard disk.
I tried a tricky workaround. It worked for me, I hope it might help u guys too.

I looked at the property of [%appdata%\drivers\winupgro.exe] which were following
size:=856064B date:=5/6/2006

I did a search of this specific file using windows search including hidden files.
To my surprise I got the other file withing minutes.
In my case it was [%appdata%\..\Local\Google\Update\GoogleUpdate.exe] which got overwritten.
"GoogleUpdate.exe" uses windows scheduler and calls itself pretty often like when system is idel or when it restarts...

Also one another observation:
Look at these place where the winupgro.exe points to.
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
or
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
the hidden overwritten exe might be one of the exe listed in these locations.

Regards
Anish</description>
		<content:encoded><![CDATA[<p>Thanks Yasser and everyone. Your tip was a great help.<br />
My C drive contains huge amount of data and it took more than 3 hours to create checksum for half of the files in hard disk.<br />
I tried a tricky workaround. It worked for me, I hope it might help u guys too.</p>
<p>I looked at the property of [%appdata%\drivers\winupgro.exe] which were following<br />
size:=856064B date:=5/6/2006</p>
<p>I did a search of this specific file using windows search including hidden files.<br />
To my surprise I got the other file withing minutes.<br />
In my case it was [%appdata%\..\Local\Google\Update\GoogleUpdate.exe] which got overwritten.<br />
&#8220;GoogleUpdate.exe&#8221; uses windows scheduler and calls itself pretty often like when system is idel or when it restarts&#8230;</p>
<p>Also one another observation:<br />
Look at these place where the winupgro.exe points to.<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
or<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
the hidden overwritten exe might be one of the exe listed in these locations.</p>
<p>Regards<br />
Anish</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Data Administrator.exe by ashkan</title>
		<link>http://www.precisesecurity.com/files-process/2008/01/25/data-administratorexe/#comment-4116</link>
		<dc:creator>ashkan</dc:creator>
		<pubDate>Mon, 21 Sep 2009 03:08:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/01/25/data-administratorexe/#comment-4116</guid>
		<description>anti adminstrator.exe</description>
		<content:encoded><![CDATA[<p>anti adminstrator.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by Dinesh Babu</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4114</link>
		<dc:creator>Dinesh Babu</dc:creator>
		<pubDate>Fri, 18 Sep 2009 11:22:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4114</guid>
		<description>Easy Way To Remove True_love.exe is stop  Msrun32 services by ending it in taskmanger and find msrun32 and remove the file . 


at last delete true_love in drive. then virus problem will be over</description>
		<content:encoded><![CDATA[<p>Easy Way To Remove True_love.exe is stop  Msrun32 services by ending it in taskmanger and find msrun32 and remove the file . </p>
<p>at last delete true_love in drive. then virus problem will be over</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on My SeXy.exe by tj</title>
		<link>http://www.precisesecurity.com/files-process/2006/11/24/my-sexyexe/#comment-4113</link>
		<dc:creator>tj</dc:creator>
		<pubDate>Fri, 18 Sep 2009 10:21:13 +0000</pubDate>
		<guid isPermaLink="false">http://precisesecurity.com/files-process/2006/11/24/my-sexyexe/#comment-4113</guid>
		<description>plz i have a problem wit this virus
i need a removal tool that can help me remove it frm my system.</description>
		<content:encoded><![CDATA[<p>plz i have a problem wit this virus<br />
i need a removal tool that can help me remove it frm my system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by Roberto</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4112</link>
		<dc:creator>Roberto</dc:creator>
		<pubDate>Fri, 18 Sep 2009 10:03:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4112</guid>
		<description>Thanks a lot jeff.  It worked.</description>
		<content:encoded><![CDATA[<p>Thanks a lot jeff.  It worked.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by Rem</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4110</link>
		<dc:creator>Rem</dc:creator>
		<pubDate>Tue, 15 Sep 2009 02:06:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4110</guid>
		<description>thanks jeff !</description>
		<content:encoded><![CDATA[<p>thanks jeff !</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ikowin32.exe by Andrew</title>
		<link>http://www.precisesecurity.com/files-process/2009/08/20/ikowin32exe/#comment-4109</link>
		<dc:creator>Andrew</dc:creator>
		<pubDate>Mon, 14 Sep 2009 21:33:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2480#comment-4109</guid>
		<description>Jason you douche there are people in the world who speak other languages who may not know how to speak English perfectly.</description>
		<content:encoded><![CDATA[<p>Jason you douche there are people in the world who speak other languages who may not know how to speak English perfectly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winupgro.exe by Amundo</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/28/winupgro/#comment-4108</link>
		<dc:creator>Amundo</dc:creator>
		<pubDate>Sat, 12 Sep 2009 10:01:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1408#comment-4108</guid>
		<description>Thanks to this forum and "ComboFix", I was able to delete the infected files (unfortunately, I still have some suspicious entries in my registry). On my machine, this is what I found: it behaves like a rootkit and hooks several important system processes. It keeps watch for AV products (including "ComboFix" - when downloading, rename it to something else, like "Combo-Fix", else you'll get "invalid Win32 application") and will corrupt? or intercept? attempts at running them. It will then check your registry and find a program that starts when Windows starts - it will replace it with the Winupgro.exe, renamed as the applications original filename (in my case, I had KeePass password keeper in my startup - it was only by accident I was wondering why it was not autostarting anymore - it had the same icon as the infecting program!! - that's why I noticed it!!!). So if you know what you're doing, as has been mentioned previously, use MSCONFIG or AUTORUNS to see what gets executed at startup, and target these for the MD5 checksum, rather that checking the whole of the C: drive. ("ComboFix" does seem to work, though, I just lost track of all the things I did).</description>
		<content:encoded><![CDATA[<p>Thanks to this forum and &#8220;ComboFix&#8221;, I was able to delete the infected files (unfortunately, I still have some suspicious entries in my registry). On my machine, this is what I found: it behaves like a rootkit and hooks several important system processes. It keeps watch for AV products (including &#8220;ComboFix&#8221; - when downloading, rename it to something else, like &#8220;Combo-Fix&#8221;, else you&#8217;ll get &#8220;invalid Win32 application&#8221;) and will corrupt? or intercept? attempts at running them. It will then check your registry and find a program that starts when Windows starts - it will replace it with the Winupgro.exe, renamed as the applications original filename (in my case, I had KeePass password keeper in my startup - it was only by accident I was wondering why it was not autostarting anymore - it had the same icon as the infecting program!! - that&#8217;s why I noticed it!!!). So if you know what you&#8217;re doing, as has been mentioned previously, use MSCONFIG or AUTORUNS to see what gets executed at startup, and target these for the MD5 checksum, rather that checking the whole of the C: drive. (&#8221;ComboFix&#8221; does seem to work, though, I just lost track of all the things I did).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ProtectFile.vbs by Siddharth</title>
		<link>http://www.precisesecurity.com/files-process/2008/11/26/protectfile-vbs/#comment-4099</link>
		<dc:creator>Siddharth</dc:creator>
		<pubDate>Mon, 07 Sep 2009 06:05:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1362#comment-4099</guid>
		<description>When i tried the Move ON boot tool to rename first of all the it says New Name should contain a valid relative local file system path and if oi dont specify the path it says the source file doesnt exist.What to do please help</description>
		<content:encoded><![CDATA[<p>When i tried the Move ON boot tool to rename first of all the it says New Name should contain a valid relative local file system path and if oi dont specify the path it says the source file doesnt exist.What to do please help</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on braviax.exe by ty</title>
		<link>http://www.precisesecurity.com/files-process/2008/05/10/braviaxexe/#comment-4095</link>
		<dc:creator>ty</dc:creator>
		<pubDate>Sat, 05 Sep 2009 19:57:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1137#comment-4095</guid>
		<description>to kill braviax.exe :

1-shut down internet.
2-open task manager
3-end braviax.exe and its creator sys32_nov.exe
4-than open windows/system32/
5-search find and delete with unlocker these found files sys32_nov.exe and braviax.exe in system32 folder..it means you survived braviax.exe))</description>
		<content:encoded><![CDATA[<p>to kill braviax.exe :</p>
<p>1-shut down internet.<br />
2-open task manager<br />
3-end braviax.exe and its creator sys32_nov.exe<br />
4-than open windows/system32/<br />
5-search find and delete with unlocker these found files sys32_nov.exe and braviax.exe in system32 folder..it means you survived braviax.exe))</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by Mike</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4093</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sat, 05 Sep 2009 09:29:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4093</guid>
		<description>Oct 10 2007, 09:24 AM

Here's a Tip on USB Devices on protecting them..  Hope you want this... Enjoy  

1. Check first the Auto Insert Notification setttings. Set it to "prompt user...".
2. Insert your USB device
3. Open "My Computer" after the USB loads
4. DON'T left-click, but right-click on the USB drive
5. Check: (very important)

if it displays:
QUOTE
Open
Explore
Search
Autoplay


then it's safe.

if it displays:
QUOTE
Autoplay
Open
Explore
Search


or:
QUOTE
Auto
Autoplay
Open
Explore
Search


or:
QUOTE
0pen
Autoplay
Open
Explore
Search


or:
QUOTE
Open
Autoplay Folder Options. If Folder Options isn't displayed, then proceed to step 7**
2. Go to the View tab, then enable "Show hidden files and folders", and uncheck "Hide extensions for known file types" and "Hide protected operating files" (click yes on this part)
3. Apply and Ok
4. Click the address bar
5. Type the drive letter of your USB device (example - F:\)
6. Look for suspicious files... like EXE files that has the icon of a folder, and named after the folder it is in... or VBS files in the root folder... or krag.exe and other unnecessary executables, or the folder RECYCLER. Delete those.
7. Run Notepad
8. Go to File&gt;Save As, go to any folder you want to save.
9. Name it as "autorun.inf", then save.
10. Copy autorun.inf
11. Paste it on the root folder of the USB drive (example - F:\)
12.Confirm file overwrite.
13. Reconnect your USB device.
14. Finished. No more Autoplay.

**if there is no Folder Options, then it might have been disabled by the administrator, or your system also has already been infected.

===================================

Also dont Reboot PC (pressing restart button.) while your USB Device is inserted. it can corrupt data...</description>
		<content:encoded><![CDATA[<p>Oct 10 2007, 09:24 AM</p>
<p>Here&#8217;s a Tip on USB Devices on protecting them..  Hope you want this&#8230; Enjoy  </p>
<p>1. Check first the Auto Insert Notification setttings. Set it to &#8220;prompt user&#8230;&#8221;.<br />
2. Insert your USB device<br />
3. Open &#8220;My Computer&#8221; after the USB loads<br />
4. DON&#8217;T left-click, but right-click on the USB drive<br />
5. Check: (very important)</p>
<p>if it displays:<br />
QUOTE<br />
Open<br />
Explore<br />
Search<br />
Autoplay</p>
<p>then it&#8217;s safe.</p>
<p>if it displays:<br />
QUOTE<br />
Autoplay<br />
Open<br />
Explore<br />
Search</p>
<p>or:<br />
QUOTE<br />
Auto<br />
Autoplay<br />
Open<br />
Explore<br />
Search</p>
<p>or:<br />
QUOTE<br />
0pen<br />
Autoplay<br />
Open<br />
Explore<br />
Search</p>
<p>or:<br />
QUOTE<br />
Open<br />
Autoplay Folder Options. If Folder Options isn&#8217;t displayed, then proceed to step 7**<br />
2. Go to the View tab, then enable &#8220;Show hidden files and folders&#8221;, and uncheck &#8220;Hide extensions for known file types&#8221; and &#8220;Hide protected operating files&#8221; (click yes on this part)<br />
3. Apply and Ok<br />
4. Click the address bar<br />
5. Type the drive letter of your USB device (example - F:\)<br />
6. Look for suspicious files&#8230; like EXE files that has the icon of a folder, and named after the folder it is in&#8230; or VBS files in the root folder&#8230; or krag.exe and other unnecessary executables, or the folder RECYCLER. Delete those.<br />
7. Run Notepad<br />
8. Go to File&gt;Save As, go to any folder you want to save.<br />
9. Name it as &#8220;autorun.inf&#8221;, then save.<br />
10. Copy autorun.inf<br />
11. Paste it on the root folder of the USB drive (example - F:\)<br />
12.Confirm file overwrite.<br />
13. Reconnect your USB device.<br />
14. Finished. No more Autoplay.</p>
<p>**if there is no Folder Options, then it might have been disabled by the administrator, or your system also has already been infected.</p>
<p>===================================</p>
<p>Also dont Reboot PC (pressing restart button.) while your USB Device is inserted. it can corrupt data&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ikowin32.exe by Jason</title>
		<link>http://www.precisesecurity.com/files-process/2009/08/20/ikowin32exe/#comment-4088</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Thu, 03 Sep 2009 23:49:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2480#comment-4088</guid>
		<description>"is still a threat?"

"just hide in usb and moved in my files in startup and avg catched"

"Should I must install an anti-spyware?"

WHAT ARE YOU TRYING TO SAY???

Before you expect someone to fix your issue, learn how to use proper grammar.  It goes a long way in being able to understand what someone is trying to say, not to mention it's just plain lazy and dumb.</description>
		<content:encoded><![CDATA[<p>&#8220;is still a threat?&#8221;</p>
<p>&#8220;just hide in usb and moved in my files in startup and avg catched&#8221;</p>
<p>&#8220;Should I must install an anti-spyware?&#8221;</p>
<p>WHAT ARE YOU TRYING TO SAY???</p>
<p>Before you expect someone to fix your issue, learn how to use proper grammar.  It goes a long way in being able to understand what someone is trying to say, not to mention it&#8217;s just plain lazy and dumb.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winjpg.jpg by Aman</title>
		<link>http://www.precisesecurity.com/files-process/2009/05/20/winjpgjpg/#comment-4087</link>
		<dc:creator>Aman</dc:creator>
		<pubDate>Thu, 03 Sep 2009 20:39:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1925#comment-4087</guid>
		<description>Dear 
Ven i enter the system password at login it hangs for somtime then enter can u help me out.</description>
		<content:encoded><![CDATA[<p>Dear<br />
Ven i enter the system password at login it hangs for somtime then enter can u help me out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winupgro.exe by francesco</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/28/winupgro/#comment-4078</link>
		<dc:creator>francesco</dc:creator>
		<pubDate>Tue, 01 Sep 2009 07:56:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1408#comment-4078</guid>
		<description>Hi Yasser, i tried your procedure, it' ok the OUT.txt file, i found the others files were the winupgro was hidden but the problem is that these file togheter with the winupgro.exe file are not deletable....when i try to delete thme i get the messase "access denied" disk could be full or write protected or the file is currently in use....and it's true because the winupgro is running as virus gettin the 99% of the cpu resources! 
How can i get out of this trick!??
thanks for your help!
francesco</description>
		<content:encoded><![CDATA[<p>Hi Yasser, i tried your procedure, it&#8217; ok the OUT.txt file, i found the others files were the winupgro was hidden but the problem is that these file togheter with the winupgro.exe file are not deletable&#8230;.when i try to delete thme i get the messase &#8220;access denied&#8221; disk could be full or write protected or the file is currently in use&#8230;.and it&#8217;s true because the winupgro is running as virus gettin the 99% of the cpu resources!<br />
How can i get out of this trick!??<br />
thanks for your help!<br />
francesco</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winupgro.exe by Ozgur</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/28/winupgro/#comment-4063</link>
		<dc:creator>Ozgur</dc:creator>
		<pubDate>Fri, 28 Aug 2009 23:45:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1408#comment-4063</guid>
		<description>It is working 100%. Thanks again.</description>
		<content:encoded><![CDATA[<p>It is working 100%. Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by Mohan.S</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4055</link>
		<dc:creator>Mohan.S</dc:creator>
		<pubDate>Thu, 27 Aug 2009 12:36:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4055</guid>
		<description>I am alos effected that the same virus, so please help me.</description>
		<content:encoded><![CDATA[<p>I am alos effected that the same virus, so please help me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on vshost.exe by razvan</title>
		<link>http://www.precisesecurity.com/files-process/2009/03/06/vshost-exe/#comment-4054</link>
		<dc:creator>razvan</dc:creator>
		<pubDate>Thu, 27 Aug 2009 12:03:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1578#comment-4054</guid>
		<description>hi,guys i have a problem with vshost.exe...when i try to entire in D: partitio i receive a vshost message like zgb..please help me:((</description>
		<content:encoded><![CDATA[<p>hi,guys i have a problem with vshost.exe&#8230;when i try to entire in D: partitio i receive a vshost message like zgb..please help me:((</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FUvirus.exe by Sheena Shroff</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/11/fuvirusexe/#comment-4053</link>
		<dc:creator>Sheena Shroff</dc:creator>
		<pubDate>Wed, 26 Aug 2009 01:09:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1373#comment-4053</guid>
		<description>Hi there I got hit by the FU virus and I was wondering if ISRESET works with AVG. Please help all my important office files got hit.</description>
		<content:encoded><![CDATA[<p>Hi there I got hit by the FU virus and I was wondering if ISRESET works with AVG. Please help all my important office files got hit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on rncsys32.exe by rqqt</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/08/rncsys32-exe/#comment-4049</link>
		<dc:creator>rqqt</dc:creator>
		<pubDate>Mon, 24 Aug 2009 11:21:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2018#comment-4049</guid>
		<description>this malware can hijack server files ... piggys back to your other network machines.

I has got infected by this pairup:
rncsys32.exe
kovin32.exe</description>
		<content:encoded><![CDATA[<p>this malware can hijack server files &#8230; piggys back to your other network machines.</p>
<p>I has got infected by this pairup:<br />
rncsys32.exe<br />
kovin32.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ikowin32.exe by FND</title>
		<link>http://www.precisesecurity.com/files-process/2009/08/20/ikowin32exe/#comment-4048</link>
		<dc:creator>FND</dc:creator>
		<pubDate>Sat, 22 Aug 2009 11:43:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2480#comment-4048</guid>
		<description>yes but if moved by usb and was deleted by the avg, is still a threat?
the program virus is not installed on my pc, just hide in usb and moved in my files in startup and avg catched
Should i must install an anti-spyware?</description>
		<content:encoded><![CDATA[<p>yes but if moved by usb and was deleted by the avg, is still a threat?<br />
the program virus is not installed on my pc, just hide in usb and moved in my files in startup and avg catched<br />
Should i must install an anti-spyware?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on vshost.exe by mihai</title>
		<link>http://www.precisesecurity.com/files-process/2009/03/06/vshost-exe/#comment-4047</link>
		<dc:creator>mihai</dc:creator>
		<pubDate>Fri, 21 Aug 2009 14:00:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1578#comment-4047</guid>
		<description>Hi, my PC does the same thing. I saw that nobody answered at your post for a long time, why is site for anyway?</description>
		<content:encoded><![CDATA[<p>Hi, my PC does the same thing. I saw that nobody answered at your post for a long time, why is site for anyway?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by Jeff</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4046</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Thu, 20 Aug 2009 17:43:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4046</guid>
		<description>Guys try this to remove Classified.exe worm

1. Download Hitman Pro 3.5 and run it to your computer
* This will remove threats in windows. Restart your computer

2. Download Kaspersk removal tool and run this in your computer. 
* Run this tool after hitman. Remove all the threats that were found

3. Open regedit and do the following
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\
SystemRestore\"DisableSR" = "1" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\A
dvanced\"Hidden" = "2" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\"HideFileExt" = "1" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\"ShowSuperHidden" = "1" 

HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\"Hidden" = "2" 
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer
Advanced\"HideFileExt" = "1" 
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\"ShowSuperHidden" = "0" 
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\"SuperHidden" = "1" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
\"NoFolderOptions" = "1"

4. Show all the folders. Open run command and type this to the terminal: 

attrib -h -s /s /d

*At this point the folders were back and your computer is now free from Classified.exe

5. Rescan again just to make sure your computer is safe from any threats</description>
		<content:encoded><![CDATA[<p>Guys try this to remove Classified.exe worm</p>
<p>1. Download Hitman Pro 3.5 and run it to your computer<br />
* This will remove threats in windows. Restart your computer</p>
<p>2. Download Kaspersk removal tool and run this in your computer.<br />
* Run this tool after hitman. Remove all the threats that were found</p>
<p>3. Open regedit and do the following<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\<br />
SystemRestore\&#8221;DisableSR&#8221; = &#8220;1&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\A<br />
dvanced\&#8221;Hidden&#8221; = &#8220;2&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\<br />
Advanced\&#8221;HideFileExt&#8221; = &#8220;1&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\<br />
Advanced\&#8221;ShowSuperHidden&#8221; = &#8220;1&#8243; </p>
<p>HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\<br />
Advanced\&#8221;Hidden&#8221; = &#8220;2&#8243;<br />
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer<br />
Advanced\&#8221;HideFileExt&#8221; = &#8220;1&#8243;<br />
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\<br />
Advanced\&#8221;ShowSuperHidden&#8221; = &#8220;0&#8243;<br />
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\<br />
Advanced\&#8221;SuperHidden&#8221; = &#8220;1&#8243;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer<br />
\&#8221;NoFolderOptions&#8221; = &#8220;1&#8243;</p>
<p>4. Show all the folders. Open run command and type this to the terminal: </p>
<p>attrib -h -s /s /d</p>
<p>*At this point the folders were back and your computer is now free from Classified.exe</p>
<p>5. Rescan again just to make sure your computer is safe from any threats</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by noelskie</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4043</link>
		<dc:creator>noelskie</dc:creator>
		<pubDate>Mon, 17 Aug 2009 06:52:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4043</guid>
		<description>I may say, once your pc is infected with this worm, it disable or blocked your antivirus, making it useless...It replace folders with an application with the same name and icon...original folders are set by this wom as super hidden so it appears to be deleted though it is really not.

My solution scan your infected hardrive to another pc with a removal tool...i have use an updated removal tool from kaspersky and it works... here's the links:
Download 1 (http://downloads1.kaspersky-labs.com/devbuilds/AVPTool/)
Download 2 (http://downloads2.kaspersky-labs.com/devbuilds/AVPTool/)
Download 3 (http://downloads5.kaspersky-labs.com/devbuilds/AVPTool/)
install this on a clean virus free pc then scan your infected hard drive or usb...It will detect and delete the worms...

As to restore the hidden folders, you have to set folder options to show all files and uncheck the hide protected operating system...to be able to view the hidden folders...then you may manually change its folelder attributes by right click the properties... or you may download a software called Attribute Manager 2.6 to ease the work of setting attributes...

Be sure to reset folder options for protections...when done...you may rescan to be sure worms are gone...then test the hard drive on your pc...

Its kinda long process but it works for me...

Hope It helps...God Bless!!!</description>
		<content:encoded><![CDATA[<p>I may say, once your pc is infected with this worm, it disable or blocked your antivirus, making it useless&#8230;It replace folders with an application with the same name and icon&#8230;original folders are set by this wom as super hidden so it appears to be deleted though it is really not.</p>
<p>My solution scan your infected hardrive to another pc with a removal tool&#8230;i have use an updated removal tool from kaspersky and it works&#8230; here&#8217;s the links:<br />
Download 1 (http://downloads1.kaspersky-labs.com/devbuilds/AVPTool/)<br />
Download 2 (http://downloads2.kaspersky-labs.com/devbuilds/AVPTool/)<br />
Download 3 (http://downloads5.kaspersky-labs.com/devbuilds/AVPTool/)<br />
install this on a clean virus free pc then scan your infected hard drive or usb&#8230;It will detect and delete the worms&#8230;</p>
<p>As to restore the hidden folders, you have to set folder options to show all files and uncheck the hide protected operating system&#8230;to be able to view the hidden folders&#8230;then you may manually change its folelder attributes by right click the properties&#8230; or you may download a software called Attribute Manager 2.6 to ease the work of setting attributes&#8230;</p>
<p>Be sure to reset folder options for protections&#8230;when done&#8230;you may rescan to be sure worms are gone&#8230;then test the hard drive on your pc&#8230;</p>
<p>Its kinda long process but it works for me&#8230;</p>
<p>Hope It helps&#8230;God Bless!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winupgro.exe by Ozgur</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/28/winupgro/#comment-4042</link>
		<dc:creator>Ozgur</dc:creator>
		<pubDate>Sun, 16 Aug 2009 12:58:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1408#comment-4042</guid>
		<description>Or you can try the easy duplicate finder to find the duplicate. The program has a min. and max. file size to search. If you make it look between 820-840 kbs it would find the trojan. Then clean the registry and uninstall the affected program as Yasser says. For me it was the AI Roboform.
One more thing , I have security task manager and it shows the icons for programs working in the background. Roboform is a program working in the background and its icon was the same as winupgro's. Maybe that can also help.

Thanks for the solution. I will check my system and will post here if this alternative way works 100%.</description>
		<content:encoded><![CDATA[<p>Or you can try the easy duplicate finder to find the duplicate. The program has a min. and max. file size to search. If you make it look between 820-840 kbs it would find the trojan. Then clean the registry and uninstall the affected program as Yasser says. For me it was the AI Roboform.<br />
One more thing , I have security task manager and it shows the icons for programs working in the background. Roboform is a program working in the background and its icon was the same as winupgro&#8217;s. Maybe that can also help.</p>
<p>Thanks for the solution. I will check my system and will post here if this alternative way works 100%.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on vshost.exe by zgb</title>
		<link>http://www.precisesecurity.com/files-process/2009/03/06/vshost-exe/#comment-4040</link>
		<dc:creator>zgb</dc:creator>
		<pubDate>Wed, 12 Aug 2009 07:46:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1578#comment-4040</guid>
		<description>My avast cannot delete this "vshost.exe",even if i choose to delete that file it is still on ... and i got 1 more problem..that svhost.exe won't let me see files on my HDD. When I try to open C:/ message is : "Windows cannot find 'vshost.exe'. Make sure you typed the name correctly, and try again. To search for a file, click the Start button, and then click Search." Pls any help or i need to format my HDD?</description>
		<content:encoded><![CDATA[<p>My avast cannot delete this &#8220;vshost.exe&#8221;,even if i choose to delete that file it is still on &#8230; and i got 1 more problem..that svhost.exe won&#8217;t let me see files on my HDD. When I try to open C:/ message is : &#8220;Windows cannot find &#8216;vshost.exe&#8217;. Make sure you typed the name correctly, and try again. To search for a file, click the Start button, and then click Search.&#8221; Pls any help or i need to format my HDD?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by Fernando</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4039</link>
		<dc:creator>Fernando</dc:creator>
		<pubDate>Tue, 11 Aug 2009 21:13:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4039</guid>
		<description>"try downloading usb disk security…

then make your HD as a flash disk by using a IDE/SATA USB cable to scan it in another computer with the disk security…

that would work i already tried it…"

Nah..It won't!</description>
		<content:encoded><![CDATA[<p>&#8220;try downloading usb disk security…</p>
<p>then make your HD as a flash disk by using a IDE/SATA USB cable to scan it in another computer with the disk security…</p>
<p>that would work i already tried it…&#8221;</p>
<p>Nah..It won&#8217;t!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by ian</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4038</link>
		<dc:creator>ian</dc:creator>
		<pubDate>Tue, 11 Aug 2009 06:02:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4038</guid>
		<description>my laptop is insfected my classified.exe then i tried to delete using task manager, later on my whole screen invert... what should i do?please help!...</description>
		<content:encoded><![CDATA[<p>my laptop is insfected my classified.exe then i tried to delete using task manager, later on my whole screen invert&#8230; what should i do?please help!&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by webmaster</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4034</link>
		<dc:creator>webmaster</dc:creator>
		<pubDate>Sat, 08 Aug 2009 10:28:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4034</guid>
		<description>If it is on memory stick you can use Flash Disinfector.
http://www.precisesecurity.com/tools-resources/adware-tools/flash-disinfector/</description>
		<content:encoded><![CDATA[<p>If it is on memory stick you can use Flash Disinfector.<br />
<a href="http://www.precisesecurity.com/tools-resources/adware-tools/flash-disinfector/" rel="nofollow">http://www.precisesecurity.com/tools-resources/adware-tools/flash-disinfector/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FUvirus.exe by jaymark</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/11/fuvirusexe/#comment-4033</link>
		<dc:creator>jaymark</dc:creator>
		<pubDate>Wed, 05 Aug 2009 03:13:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1373#comment-4033</guid>
		<description>..uhmmmmmm

..webmaster

..are you sure it can delete the FUvirus

..bcoz my pc is very affected by that virus

..i hope that this Malwarebytes’ Anti-Malware 

..is working tnx</description>
		<content:encoded><![CDATA[<p>..uhmmmmmm</p>
<p>..webmaster</p>
<p>..are you sure it can delete the FUvirus</p>
<p>..bcoz my pc is very affected by that virus</p>
<p>..i hope that this Malwarebytes’ Anti-Malware </p>
<p>..is working tnx</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by mani</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4032</link>
		<dc:creator>mani</dc:creator>
		<pubDate>Mon, 03 Aug 2009 08:19:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4032</guid>
		<description>i also have the same...
true_love.exe virus
in my memory stick 

help me how to remove...</description>
		<content:encoded><![CDATA[<p>i also have the same&#8230;<br />
true_love.exe virus<br />
in my memory stick </p>
<p>help me how to remove&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by Rodel</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4021</link>
		<dc:creator>Rodel</dc:creator>
		<pubDate>Wed, 29 Jul 2009 14:07:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4021</guid>
		<description>try downloading usb disk security...

then make your HD as a flash disk by using a IDE/SATA USB cable to scan it in another computer with the disk security...

that would work i already tried it...</description>
		<content:encoded><![CDATA[<p>try downloading usb disk security&#8230;</p>
<p>then make your HD as a flash disk by using a IDE/SATA USB cable to scan it in another computer with the disk security&#8230;</p>
<p>that would work i already tried it&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by mamun reza</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4020</link>
		<dc:creator>mamun reza</dc:creator>
		<pubDate>Wed, 29 Jul 2009 08:12:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4020</guid>
		<description>i have two viruses
true_love.exe

in my pen drive and computer if delete after close and open they are reappeared 

help me to remove viruses
i cant open my taskmanager</description>
		<content:encoded><![CDATA[<p>i have two viruses<br />
true_love.exe</p>
<p>in my pen drive and computer if delete after close and open they are reappeared </p>
<p>help me to remove viruses<br />
i cant open my taskmanager</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Patah Hati.doc .exe by ratheesh</title>
		<link>http://www.precisesecurity.com/files-process/2007/08/20/patah-hatidoc-exe/#comment-4019</link>
		<dc:creator>ratheesh</dc:creator>
		<pubDate>Wed, 29 Jul 2009 07:17:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2007/08/20/patah-hatidoc-exe/#comment-4019</guid>
		<description>i want removal tool of pathahati.doc</description>
		<content:encoded><![CDATA[<p>i want removal tool of pathahati.doc</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by hahabelat</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4018</link>
		<dc:creator>hahabelat</dc:creator>
		<pubDate>Sun, 26 Jul 2009 13:12:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4018</guid>
		<description>i had the same problem too.. my first anti virus was avira.. and also i have malwarebytes.. but it only inactivate my antivirus. then i tried to download kaspersky but it can't delete the classified.exe.. this folder is locked.. and all the sites of antivirus, malware, spyware and others are also blocked.</description>
		<content:encoded><![CDATA[<p>i had the same problem too.. my first anti virus was avira.. and also i have malwarebytes.. but it only inactivate my antivirus. then i tried to download kaspersky but it can&#8217;t delete the classified.exe.. this folder is locked.. and all the sites of antivirus, malware, spyware and others are also blocked.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on solution.vbs by Ody</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/28/solutionvbs/#comment-4017</link>
		<dc:creator>Ody</dc:creator>
		<pubDate>Sat, 25 Jul 2009 08:56:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2152#comment-4017</guid>
		<description>My AVG alerted me that solution.vbs in my usb was potentially harmful.  So I moved the file in to the vault.

Now whenever I try to access my usb, the Windows Script Host buble says "Can not find script file "G:\solution.vbs".

What does this mean and how can I access my USB again?</description>
		<content:encoded><![CDATA[<p>My AVG alerted me that solution.vbs in my usb was potentially harmful.  So I moved the file in to the vault.</p>
<p>Now whenever I try to access my usb, the Windows Script Host buble says &#8220;Can not find script file &#8220;G:\solution.vbs&#8221;.</p>
<p>What does this mean and how can I access my USB again?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on chrome.exe by abrar</title>
		<link>http://www.precisesecurity.com/files-process/2008/11/09/chrome-exe/#comment-4015</link>
		<dc:creator>abrar</dc:creator>
		<pubDate>Wed, 22 Jul 2009 07:08:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1328#comment-4015</guid>
		<description>i hve got a virus with .exe extensions it creates a folder.exe folder in every pre-existing folder.please advice what to do</description>
		<content:encoded><![CDATA[<p>i hve got a virus with .exe extensions it creates a folder.exe folder in every pre-existing folder.please advice what to do</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on rncsys32.exe by fernanda</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/08/rncsys32-exe/#comment-4014</link>
		<dc:creator>fernanda</dc:creator>
		<pubDate>Wed, 22 Jul 2009 05:23:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2018#comment-4014</guid>
		<description>It happened to me. The site of a client started to going wrong, showing blank pages. When I was searching the code, I saw that it had been mysteriously added a  that directs to a site called "q1n.in" in all of my index and default pages. I contacted my host's support and they said I was hacked. Not understand, because the files were all on the server and the password remains the same. Turning the antivirus on my machine I saw that I was more a victim of this trojan ...</description>
		<content:encoded><![CDATA[<p>It happened to me. The site of a client started to going wrong, showing blank pages. When I was searching the code, I saw that it had been mysteriously added a  that directs to a site called &#8220;q1n.in&#8221; in all of my index and default pages. I contacted my host&#8217;s support and they said I was hacked. Not understand, because the files were all on the server and the password remains the same. Turning the antivirus on my machine I saw that I was more a victim of this trojan &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PAV.exe by KeV</title>
		<link>http://www.precisesecurity.com/files-process/2009/04/22/pav-exe/#comment-4013</link>
		<dc:creator>KeV</dc:creator>
		<pubDate>Mon, 20 Jul 2009 22:27:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1771#comment-4013</guid>
		<description>I have a variant on my mates system in a PersonalAV folder and no winexplorer.dll and so I'm not sure if it will still operate quietly. Also, Does it need javascript, activex or something to install as prevention is better than a cure?</description>
		<content:encoded><![CDATA[<p>I have a variant on my mates system in a PersonalAV folder and no winexplorer.dll and so I&#8217;m not sure if it will still operate quietly. Also, Does it need javascript, activex or something to install as prevention is better than a cure?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by anand</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4012</link>
		<dc:creator>anand</dc:creator>
		<pubDate>Sun, 19 Jul 2009 05:53:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-4012</guid>
		<description>hi i also have same virues true love on my pendrive please help me how to remove this. the PC is getting stuck once i plug this in.</description>
		<content:encoded><![CDATA[<p>hi i also have same virues true love on my pendrive please help me how to remove this. the PC is getting stuck once i plug this in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on wiawow32.sys by Kimi</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/26/wiawow32sys/#comment-4011</link>
		<dc:creator>Kimi</dc:creator>
		<pubDate>Sat, 18 Jul 2009 19:22:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2149#comment-4011</guid>
		<description>I have the same problem. But currently I created a new admin account on my computer, and it seems to not be affected yet, so I'm able to get online and do many things that the other computer account can't. I'm using Avast! (the free version) antivirus software, I did a thorough scan, and it came acrossed this virus. It moved it to the chest. Is that going to be sufficient enough or should it be deleted?</description>
		<content:encoded><![CDATA[<p>I have the same problem. But currently I created a new admin account on my computer, and it seems to not be affected yet, so I&#8217;m able to get online and do many things that the other computer account can&#8217;t. I&#8217;m using Avast! (the free version) antivirus software, I did a thorough scan, and it came acrossed this virus. It moved it to the chest. Is that going to be sufficient enough or should it be deleted?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classified.exe by Elis</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/16/classifiedexe/#comment-4010</link>
		<dc:creator>Elis</dc:creator>
		<pubDate>Sat, 18 Jul 2009 06:58:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2293#comment-4010</guid>
		<description>i had tested out almost all of the known antivirus to remove the virus but they doesn't solve the removal of the classified.exe.

any help will be much appreciated</description>
		<content:encoded><![CDATA[<p>i had tested out almost all of the known antivirus to remove the virus but they doesn&#8217;t solve the removal of the classified.exe.</p>
<p>any help will be much appreciated</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on wiawow32.sys by Jeffrey</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/26/wiawow32sys/#comment-4003</link>
		<dc:creator>Jeffrey</dc:creator>
		<pubDate>Thu, 16 Jul 2009 05:07:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2149#comment-4003</guid>
		<description>oh and by the way, that last post and this post are coming from a different computer. I cant open up IE explorer or Firefox on the other computer.</description>
		<content:encoded><![CDATA[<p>oh and by the way, that last post and this post are coming from a different computer. I cant open up IE explorer or Firefox on the other computer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on wiawow32.sys by Jeffrey</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/26/wiawow32sys/#comment-4002</link>
		<dc:creator>Jeffrey</dc:creator>
		<pubDate>Thu, 16 Jul 2009 05:06:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2149#comment-4002</guid>
		<description>Hey help me out...I have this virus and I can't open any programs, but I can open up folders and whatnot (My Computer, Recycle Bin, etc.)</description>
		<content:encoded><![CDATA[<p>Hey help me out&#8230;I have this virus and I can&#8217;t open any programs, but I can open up folders and whatnot (My Computer, Recycle Bin, etc.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on regsvr.exe by chaitu</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/21/regsvrexe/#comment-4001</link>
		<dc:creator>chaitu</dc:creator>
		<pubDate>Wed, 15 Jul 2009 11:58:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/21/regsvrexe/#comment-4001</guid>
		<description>sorry to tell you this pal
     but the procedure u have explained might not work on all systems affected by this virus as regsvr.exe will disable the registry also. so you cannot remove it from registry.. and also once u open the autorun.inf file and try to save it back again it will accept any changes....</description>
		<content:encoded><![CDATA[<p>sorry to tell you this pal<br />
     but the procedure u have explained might not work on all systems affected by this virus as regsvr.exe will disable the registry also. so you cannot remove it from registry.. and also once u open the autorun.inf file and try to save it back again it will accept any changes&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on rncsys32.exe by Chris</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/08/rncsys32-exe/#comment-3999</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 14 Jul 2009 18:10:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2018#comment-3999</guid>
		<description>Found this on both computers in my house; probably transferred by a flash drive. Still not sure how it was conceived on the computers, but it was very frustrating. Re-routes all "Google" search results to a php error page.</description>
		<content:encoded><![CDATA[<p>Found this on both computers in my house; probably transferred by a flash drive. Still not sure how it was conceived on the computers, but it was very frustrating. Re-routes all &#8220;Google&#8221; search results to a php error page.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on USBCILLIN.EXE by nikhil</title>
		<link>http://www.precisesecurity.com/files-process/2009/05/02/usbcillin-exe/#comment-3995</link>
		<dc:creator>nikhil</dc:creator>
		<pubDate>Sat, 11 Jul 2009 14:40:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1814#comment-3995</guid>
		<description>plz help me to delet this virus usbcilin.exe</description>
		<content:encoded><![CDATA[<p>plz help me to delet this virus usbcilin.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winifighter.exe by shamsul hoque</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/09/winifighterexe/#comment-3994</link>
		<dc:creator>shamsul hoque</dc:creator>
		<pubDate>Fri, 10 Jul 2009 15:55:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2263#comment-3994</guid>
		<description>Its show me the on dialogbox "SSVICHOSST.exe" life not found ! when I start my computer . pls give me the proper helps .
thanks
shamsul hoque</description>
		<content:encoded><![CDATA[<p>Its show me the on dialogbox &#8220;SSVICHOSST.exe&#8221; life not found ! when I start my computer . pls give me the proper helps .<br />
thanks<br />
shamsul hoque</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SSVICHOSST.exe by shamsul hoque</title>
		<link>http://www.precisesecurity.com/files-process/2007/07/02/ssvichosstexe/#comment-3993</link>
		<dc:creator>shamsul hoque</dc:creator>
		<pubDate>Fri, 10 Jul 2009 15:44:51 +0000</pubDate>
		<guid isPermaLink="false">http://precisesecurity.com/files-process/2007/07/02/ssvichosstexe/#comment-3993</guid>
		<description>When I starte my computer then it show the dialog box "SSVICHOSST.exe" not found . pls sussest me for remady.</description>
		<content:encoded><![CDATA[<p>When I starte my computer then it show the dialog box &#8220;SSVICHOSST.exe&#8221; not found . pls sussest me for remady.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winupgro.exe by John</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/28/winupgro/#comment-3985</link>
		<dc:creator>John</dc:creator>
		<pubDate>Thu, 09 Jul 2009 07:41:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1408#comment-3985</guid>
		<description>Hi all, well it has been 12 hours now and I am still virus free.

The tt.bat did not work for me, I am using Vista ultimate 64 bit, I don't know if that makes a difference, but I did not get an output file. but the file size search did the trick perfectly.

Many thanks again.</description>
		<content:encoded><![CDATA[<p>Hi all, well it has been 12 hours now and I am still virus free.</p>
<p>The tt.bat did not work for me, I am using Vista ultimate 64 bit, I don&#8217;t know if that makes a difference, but I did not get an output file. but the file size search did the trick perfectly.</p>
<p>Many thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winupgro.exe by John</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/28/winupgro/#comment-3983</link>
		<dc:creator>John</dc:creator>
		<pubDate>Wed, 08 Jul 2009 20:44:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1408#comment-3983</guid>
		<description>I followed Pascal method, after waiting for more than 2 hours fore the tt.bat to run, and searched in Vista for files equal to 832Kb and found ISUSPM.exe, it even had the same icon as the winupgro.exe file.
Searched the registry and deleted all reference to the file, one was in the startup section. I will post again if I am still clean tommorow.

A great help, and thanks to all the contributors.</description>
		<content:encoded><![CDATA[<p>I followed Pascal method, after waiting for more than 2 hours fore the tt.bat to run, and searched in Vista for files equal to 832Kb and found ISUSPM.exe, it even had the same icon as the winupgro.exe file.<br />
Searched the registry and deleted all reference to the file, one was in the startup section. I will post again if I am still clean tommorow.</p>
<p>A great help, and thanks to all the contributors.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on True_Love.exe by bhoobalan</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-3982</link>
		<dc:creator>bhoobalan</dc:creator>
		<pubDate>Wed, 08 Jul 2009 14:35:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/true_loveexe/#comment-3982</guid>
		<description>i have two viruses
true_love.exe
Ms_run.exe  
in my pen drive and computer if delete  after close and open they are reappeared 

help me to remove viruses
i cant open my taskmanager</description>
		<content:encoded><![CDATA[<p>i have two viruses<br />
true_love.exe<br />
Ms_run.exe<br />
in my pen drive and computer if delete  after close and open they are reappeared </p>
<p>help me to remove viruses<br />
i cant open my taskmanager</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on regsvr.exe by rahul naik</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/21/regsvrexe/#comment-3975</link>
		<dc:creator>rahul naik</dc:creator>
		<pubDate>Tue, 07 Jul 2009 07:41:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/21/regsvrexe/#comment-3975</guid>
		<description>my regsver.exe virus doesnt removed.</description>
		<content:encoded><![CDATA[<p>my regsver.exe virus doesnt removed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on tazebama.exe by rajl</title>
		<link>http://www.precisesecurity.com/files-process/2007/11/13/tazebamaexe/#comment-3968</link>
		<dc:creator>rajl</dc:creator>
		<pubDate>Sun, 05 Jul 2009 19:20:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2007/11/13/tazebamaexe/#comment-3968</guid>
		<description>Excuse please I have a very big problem with tazebama.dl_ could you help me ?
please
answe me 
to mine email :
vemberajil@yahoo.fr</description>
		<content:encoded><![CDATA[<p>Excuse please I have a very big problem with tazebama.dl_ could you help me ?<br />
please<br />
answe me<br />
to mine email :<br />
<a href="mailto:vemberajil@yahoo.fr">vemberajil@yahoo.fr</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on sysguard.exe by jim</title>
		<link>http://www.precisesecurity.com/files-process/2009/01/26/sysguardexe/#comment-3966</link>
		<dc:creator>jim</dc:creator>
		<pubDate>Fri, 03 Jul 2009 16:53:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1507#comment-3966</guid>
		<description>Thanks for the info</description>
		<content:encoded><![CDATA[<p>Thanks for the info</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on winudpmgr.exe by webmaster</title>
		<link>http://www.precisesecurity.com/files-process/2009/07/03/winudpmgr/#comment-3965</link>
		<dc:creator>webmaster</dc:creator>
		<pubDate>Fri, 03 Jul 2009 11:05:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2192#comment-3965</guid>
		<description>&lt;h4&gt;Removing Malware&lt;/h4&gt;
1. Download &lt;a rel="nofollow" href="http://www.precisesecurity.com/tools-resources/adware-tools/malwarebytes-anti-malware/" target="_blank" rel="nofollow"&gt;Malwarebytes’ Anti-Malware&lt;/a&gt; (mbam-setup.exe) and save it on your Desktop.
2. After downloading, double-click on mbam-setup.exe to install the application.
3. Follow the prompts and install as “default” only
4. Before the installation completes, check on the following prompts:
- Update Malwarebytes’ Anti-Malware
- Launch Malwarebytes’ Anti-Malware
5. Click “Finish.” Program will run automatically and you will be prompt to update the program before doing a scan. Please update.
6. Scan your computer thoroughly.
7. When scanning is finished click on the “Show Results”
8. Make sure that all detected threats are marked, click on Remove Selected.
9. Restart your computer.

&lt;em&gt;Note: Some malware may prevent mbam-setup.exe from downloading and running. You can download and rename this program from a different computer before running it on infected system.&lt;/em&gt;</description>
		<content:encoded><![CDATA[<h4>Removing Malware</h4>
<p>1. Download <a rel="nofollow" href="http://www.precisesecurity.com/tools-resources/adware-tools/malwarebytes-anti-malware/" target="_blank" rel="nofollow">Malwarebytes’ Anti-Malware</a> (mbam-setup.exe) and save it on your Desktop.<br />
2. After downloading, double-click on mbam-setup.exe to install the application.<br />
3. Follow the prompts and install as “default” only<br />
4. Before the installation completes, check on the following prompts:<br />
- Update Malwarebytes’ Anti-Malware<br />
- Launch Malwarebytes’ Anti-Malware<br />
5. Click “Finish.” Program will run automatically and you will be prompt to update the program before doing a scan. Please update.<br />
6. Scan your computer thoroughly.<br />
7. When scanning is finished click on the “Show Results”<br />
8. Make sure that all detected threats are marked, click on Remove Selected.<br />
9. Restart your computer.</p>
<p><em>Note: Some malware may prevent mbam-setup.exe from downloading and running. You can download and rename this program from a different computer before running it on infected system.</em></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on rncsys32.exe by bob</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/08/rncsys32-exe/#comment-3963</link>
		<dc:creator>bob</dc:creator>
		<pubDate>Thu, 02 Jul 2009 23:42:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2018#comment-3963</guid>
		<description>This trojan steals ftp ids (stored where? filezilla maybe?) and inserts some  iframe tags into whatever php files it can found, preferably index.php files.

Whenever this tag is read by a client, he is contaminated with rncsys32.exe (if lack of protection).</description>
		<content:encoded><![CDATA[<p>This trojan steals ftp ids (stored where? filezilla maybe?) and inserts some  iframe tags into whatever php files it can found, preferably index.php files.</p>
<p>Whenever this tag is read by a client, he is contaminated with rncsys32.exe (if lack of protection).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ogard.exe by Wajeb</title>
		<link>http://www.precisesecurity.com/files-process/2009/02/17/ogard-exe/#comment-3959</link>
		<dc:creator>Wajeb</dc:creator>
		<pubDate>Tue, 30 Jun 2009 18:53:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1535#comment-3959</guid>
		<description>true, I have 3 malware, and anti spy, and AVG, none detected it except AVG but only acusing none are deleting it... :S... WTF?</description>
		<content:encoded><![CDATA[<p>true, I have 3 malware, and anti spy, and AVG, none detected it except AVG but only acusing none are deleting it&#8230; :S&#8230; WTF?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PAV.exe by LAW223</title>
		<link>http://www.precisesecurity.com/files-process/2009/04/22/pav-exe/#comment-3958</link>
		<dc:creator>LAW223</dc:creator>
		<pubDate>Tue, 30 Jun 2009 15:02:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1771#comment-3958</guid>
		<description>Thank you LiLi.. Killbox.net was the answer to my prayers here at the office. Got rid of PAV virus in a zap!</description>
		<content:encoded><![CDATA[<p>Thank you LiLi.. Killbox.net was the answer to my prayers here at the office. Got rid of PAV virus in a zap!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on rncsys32.exe by lek</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/08/rncsys32-exe/#comment-3957</link>
		<dc:creator>lek</dc:creator>
		<pubDate>Mon, 29 Jun 2009 15:43:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2018#comment-3957</guid>
		<description>I just got this virus in my computer.
Fortunately, my antivirus can delete it!

PS: I found this virus in my startup.</description>
		<content:encoded><![CDATA[<p>I just got this virus in my computer.<br />
Fortunately, my antivirus can delete it!</p>
<p>PS: I found this virus in my startup.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MsRun32.exe by malar</title>
		<link>http://www.precisesecurity.com/files-process/2008/02/23/msrun32exe/#comment-3956</link>
		<dc:creator>malar</dc:creator>
		<pubDate>Sun, 28 Jun 2009 06:10:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/02/23/msrun32exe/#comment-3956</guid>
		<description>In my pc a new virus entered and in process showing MsRun32.exe.
please instruct me how to remove completely.
thanks</description>
		<content:encoded><![CDATA[<p>In my pc a new virus entered and in process showing MsRun32.exe.<br />
please instruct me how to remove completely.<br />
thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PAV.exe by LiLi</title>
		<link>http://www.precisesecurity.com/files-process/2009/04/22/pav-exe/#comment-3952</link>
		<dc:creator>LiLi</dc:creator>
		<pubDate>Thu, 25 Jun 2009 04:39:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1771#comment-3952</guid>
		<description>KILLBOX.net! enter a search for PAV and it kills it dead!</description>
		<content:encoded><![CDATA[<p>KILLBOX.net! enter a search for PAV and it kills it dead!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PAV.exe by Julie</title>
		<link>http://www.precisesecurity.com/files-process/2009/04/22/pav-exe/#comment-3944</link>
		<dc:creator>Julie</dc:creator>
		<pubDate>Mon, 22 Jun 2009 17:44:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1771#comment-3944</guid>
		<description>What if the virus has now locked me out of the internet?  I can't get to the Microsoft website to follow the steps.</description>
		<content:encoded><![CDATA[<p>What if the virus has now locked me out of the internet?  I can&#8217;t get to the Microsoft website to follow the steps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on rncsys32.exe by dc</title>
		<link>http://www.precisesecurity.com/files-process/2009/06/08/rncsys32-exe/#comment-3935</link>
		<dc:creator>dc</dc:creator>
		<pubDate>Mon, 15 Jun 2009 05:42:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=2018#comment-3935</guid>
		<description>think this is pretty new. detected slight increase in network traffic activity.

sits in start up folder, no other source exes or files it links to/references found on the pc (so far..)

anyone has more details abt it's origins/what it is related to, what it might do etc?

- dc</description>
		<content:encoded><![CDATA[<p>think this is pretty new. detected slight increase in network traffic activity.</p>
<p>sits in start up folder, no other source exes or files it links to/references found on the pc (so far..)</p>
<p>anyone has more details abt it&#8217;s origins/what it is related to, what it might do etc?</p>
<p>- dc</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on tazebama.dll by Vod</title>
		<link>http://www.precisesecurity.com/files-process/2008/01/16/tazebamadll/#comment-3934</link>
		<dc:creator>Vod</dc:creator>
		<pubDate>Thu, 11 Jun 2009 13:44:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2008/01/16/tazebamadll/#comment-3934</guid>
		<description>Try Nod32 anti virus, hope it will fix your problem :)</description>
		<content:encoded><![CDATA[<p>Try Nod32 anti virus, hope it will fix your problem <img src='http://www.precisesecurity.com/files-process/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ramal Jodoh.pif by NOVRIALTANJUNG</title>
		<link>http://www.precisesecurity.com/files-process/2007/11/01/ramal-jodohpif/#comment-3933</link>
		<dc:creator>NOVRIALTANJUNG</dc:creator>
		<pubDate>Thu, 11 Jun 2009 06:18:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2007/11/01/ramal-jodohpif/#comment-3933</guid>
		<description>ramalkan saya dan pasangan saya</description>
		<content:encoded><![CDATA[<p>ramalkan saya dan pasangan saya</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ramal Jodoh.pif by NOVRIALTANJUNG</title>
		<link>http://www.precisesecurity.com/files-process/2007/11/01/ramal-jodohpif/#comment-3932</link>
		<dc:creator>NOVRIALTANJUNG</dc:creator>
		<pubDate>Thu, 11 Jun 2009 06:01:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/2007/11/01/ramal-jodohpif/#comment-3932</guid>
		<description>tgl lahir 13-11-1985
pasangan
nama: erna dewi puspita saputri
tgl lahir 28-08-1988</description>
		<content:encoded><![CDATA[<p>tgl lahir 13-11-1985<br />
pasangan<br />
nama: erna dewi puspita saputri<br />
tgl lahir 28-08-1988</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PAV.exe by Tim</title>
		<link>http://www.precisesecurity.com/files-process/2009/04/22/pav-exe/#comment-3931</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Tue, 09 Jun 2009 13:22:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1771#comment-3931</guid>
		<description>For step 6 run "Autoruns" as administrator by right clicking it and it will let you delete</description>
		<content:encoded><![CDATA[<p>For step 6 run &#8220;Autoruns&#8221; as administrator by right clicking it and it will let you delete</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ProtectFile.vbs by srichandar</title>
		<link>http://www.precisesecurity.com/files-process/2008/11/26/protectfile-vbs/#comment-3930</link>
		<dc:creator>srichandar</dc:creator>
		<pubDate>Sat, 06 Jun 2009 10:55:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1362#comment-3930</guid>
		<description>go to task manager kill the processes explorer and wscript.exe(if available)
now go to applications tab and press new task
enter cmd in the cmd go to the drive c:\
enter del /f/q/a protectfile.vbs
and del /f/q/a autorun.inf
and now go to c:\windows\system32
and enter del /f/q/a secureguard.vbs
now u have deleted all the infected files in ur system
and now goto
regedit and search for protectfile.vbs and delete all the files with this name
and again search for the secureguard.vbs
and u have to modify it as in the path del only"c:\windows\system32\secureguard.vbs... and let the other part of the path be there alive..
and restart ur system
thats all u r done...!!!!!!!!
Source(s):
self, i tried it when it occurred in my system</description>
		<content:encoded><![CDATA[<p>go to task manager kill the processes explorer and wscript.exe(if available)<br />
now go to applications tab and press new task<br />
enter cmd in the cmd go to the drive c:\<br />
enter del /f/q/a protectfile.vbs<br />
and del /f/q/a autorun.inf<br />
and now go to c:\windows\system32<br />
and enter del /f/q/a secureguard.vbs<br />
now u have deleted all the infected files in ur system<br />
and now goto<br />
regedit and search for protectfile.vbs and delete all the files with this name<br />
and again search for the secureguard.vbs<br />
and u have to modify it as in the path del only&#8221;c:\windows\system32\secureguard.vbs&#8230; and let the other part of the path be there alive..<br />
and restart ur system<br />
thats all u r done&#8230;!!!!!!!!<br />
Source(s):<br />
self, i tried it when it occurred in my system</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PAV.exe by Jim</title>
		<link>http://www.precisesecurity.com/files-process/2009/04/22/pav-exe/#comment-3928</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Sat, 06 Jun 2009 00:45:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1771#comment-3928</guid>
		<description>Excellent right on the money got rid of that stupid thing easily. thanks</description>
		<content:encoded><![CDATA[<p>Excellent right on the money got rid of that stupid thing easily. thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PAV.exe by Joe-Tech</title>
		<link>http://www.precisesecurity.com/files-process/2009/04/22/pav-exe/#comment-3927</link>
		<dc:creator>Joe-Tech</dc:creator>
		<pubDate>Wed, 03 Jun 2009 20:32:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1771#comment-3927</guid>
		<description>@Keith Schmidt: Un-register the .DLL ("Step 5.995") file prior to deleting it. 

hxxp://www.xp-vista.com/other/how-to-unregister-dll-files</description>
		<content:encoded><![CDATA[<p>@Keith Schmidt: Un-register the .DLL (&#8221;Step 5.995&#8243;) file prior to deleting it. </p>
<p>hxxp://www.xp-vista.com/other/how-to-unregister-dll-files</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PAV.exe by Keith Schmidt</title>
		<link>http://www.precisesecurity.com/files-process/2009/04/22/pav-exe/#comment-3925</link>
		<dc:creator>Keith Schmidt</dc:creator>
		<pubDate>Sat, 30 May 2009 18:48:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1771#comment-3925</guid>
		<description>I get to step six and it doesnt let me, it says access is denied. How can i get past this?</description>
		<content:encoded><![CDATA[<p>I get to step six and it doesnt let me, it says access is denied. How can i get past this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FUvirus.exe by Nintendo.com</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/11/fuvirusexe/#comment-3924</link>
		<dc:creator>Nintendo.com</dc:creator>
		<pubDate>Sat, 30 May 2009 15:54:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1373#comment-3924</guid>
		<description>i have ClamWin</description>
		<content:encoded><![CDATA[<p>i have ClamWin</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FUvirus.exe by Nintendo.com</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/11/fuvirusexe/#comment-3923</link>
		<dc:creator>Nintendo.com</dc:creator>
		<pubDate>Sat, 30 May 2009 15:52:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1373#comment-3923</guid>
		<description>i know</description>
		<content:encoded><![CDATA[<p>i know</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MarioForever.exe by Roy</title>
		<link>http://www.precisesecurity.com/files-process/2008/05/10/marioforeverexe/#comment-3922</link>
		<dc:creator>Roy</dc:creator>
		<pubDate>Sat, 30 May 2009 15:50:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1136#comment-3922</guid>
		<description>Sorry napnap i was not looking</description>
		<content:encoded><![CDATA[<p>Sorry napnap i was not looking</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MarioForever.exe by Roy</title>
		<link>http://www.precisesecurity.com/files-process/2008/05/10/marioforeverexe/#comment-3921</link>
		<dc:creator>Roy</dc:creator>
		<pubDate>Sat, 30 May 2009 15:48:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1136#comment-3921</guid>
		<description>Look, Type Carefully [EXAMPLE]You called Mario Forever.exe marioforeever.exe</description>
		<content:encoded><![CDATA[<p>Look, Type Carefully [EXAMPLE]You called Mario Forever.exe marioforeever.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MarioForever.exe by Roy</title>
		<link>http://www.precisesecurity.com/files-process/2008/05/10/marioforeverexe/#comment-3920</link>
		<dc:creator>Roy</dc:creator>
		<pubDate>Sat, 30 May 2009 15:42:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1136#comment-3920</guid>
		<description>I'm Replying to mukti ranjan senapaty:
Look, Type Carefully +
You called Mario Forever.exe marioforeever.exe What are you Chinese?
I'm Replying to napnap:
Look, Type Carefully +
You called Mario Forever.exe marioforeever.exe What are you Chinese?</description>
		<content:encoded><![CDATA[<p>I&#8217;m Replying to mukti ranjan senapaty:<br />
Look, Type Carefully +<br />
You called Mario Forever.exe marioforeever.exe What are you Chinese?<br />
I&#8217;m Replying to napnap:<br />
Look, Type Carefully +<br />
You called Mario Forever.exe marioforeever.exe What are you Chinese?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MarioForever.exe by Roy</title>
		<link>http://www.precisesecurity.com/files-process/2008/05/10/marioforeverexe/#comment-3919</link>
		<dc:creator>Roy</dc:creator>
		<pubDate>Sat, 30 May 2009 15:38:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1136#comment-3919</guid>
		<description>From Softendo (NINTENDO FANGAMES)</description>
		<content:encoded><![CDATA[<p>From Softendo (NINTENDO FANGAMES)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MarioForever.exe by Roy</title>
		<link>http://www.precisesecurity.com/files-process/2008/05/10/marioforeverexe/#comment-3918</link>
		<dc:creator>Roy</dc:creator>
		<pubDate>Thu, 28 May 2009 17:46:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1136#comment-3918</guid>
		<description>i have Super Mario 3: Mario Forever</description>
		<content:encoded><![CDATA[<p>i have Super Mario 3: Mario Forever</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FUvirus.exe by bonsainess.com</title>
		<link>http://www.precisesecurity.com/files-process/2008/12/11/fuvirusexe/#comment-3917</link>
		<dc:creator>bonsainess.com</dc:creator>
		<pubDate>Wed, 27 May 2009 18:45:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/files-process/?p=1373#comment-3917</guid>
		<description>Hello.... im new here... try downloading the latest bit defender Total Security. Works very fine and removes all malwares and viruses. works like more better than  malwareProtection.....

my only problem is like with lupin, my files where gone and i followed ADDIN's instruction with the show folder factor.... 

im sorry i just dont understand the  "highlight all folders, and drop to isreset
press reset, and that should do it "

please guide..... i dont get the highlight thing....
please guide in step by step...thank you very much....</description>
		<content:encoded><![CDATA[<p>Hello&#8230;. im new here&#8230; try downloading the latest bit defender Total Security. Works very fine and removes all malwares and viruses. works like more better than  malwareProtection&#8230;..</p>
<p>my only problem is like with lupin, my files where gone and i followed ADDIN&#8217;s instruction with the show folder factor&#8230;. </p>
<p>im sorry i just dont understand the  &#8220;highlight all folders, and drop to isreset<br />
press reset, and that should do it &#8221;</p>
<p>please guide&#8230;.. i dont get the highlight thing&#8230;.<br />
please guide in step by step&#8230;thank you very much&#8230;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
