<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments for Question and Answer</title>
	<atom:link href="http://www.precisesecurity.com/qa/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://www.precisesecurity.com/qa</link>
	<description></description>
	<pubDate>Sat, 21 Nov 2009 08:20:51 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Trojan Horse Agent2.ZZG by Sven</title>
		<link>http://www.precisesecurity.com/qa/?p=890#comment-1205</link>
		<dc:creator>Sven</dc:creator>
		<pubDate>Thu, 19 Nov 2009 00:03:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/qa/?p=890#comment-1205</guid>
		<description>J found Agentt2.ZZG 15/11 with MalwareBytes. It was hidden HP\BIN\ProcessLogger.exe. I run Vista and scan with AVG every day, but AVG didn´t find it.</description>
		<content:encoded><![CDATA[<p>J found Agentt2.ZZG 15/11 with MalwareBytes. It was hidden HP\BIN\ProcessLogger.exe. I run Vista and scan with AVG every day, but AVG didn´t find it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on System Security Firewall Alert popup by Erin</title>
		<link>http://www.precisesecurity.com/qa/?p=50#comment-1204</link>
		<dc:creator>Erin</dc:creator>
		<pubDate>Wed, 18 Nov 2009 20:54:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/qa/?p=50#comment-1204</guid>
		<description>This is super annoying!

Everyone is right, as to where to find the virus
C:\Documents and Settings\All Users\Application Data

I had to go into safe mode to delete it (if you can't get into safe mode, restart your computer and keep pressing F8 until the safe mode comes up)
Once you are in safe mode, I had to type in that c:\ file drive in the "run" button.

Once you get in there, delete it &amp; the folder (about 10 digit folder) and then also go empty your recycle bin.


Restart into normal mode and you should be good to go!  It took me 24 hours to figure it out, but that's where it is!</description>
		<content:encoded><![CDATA[<p>This is super annoying!</p>
<p>Everyone is right, as to where to find the virus<br />
C:\Documents and Settings\All Users\Application Data</p>
<p>I had to go into safe mode to delete it (if you can&#8217;t get into safe mode, restart your computer and keep pressing F8 until the safe mode comes up)<br />
Once you are in safe mode, I had to type in that c:\ file drive in the &#8220;run&#8221; button.</p>
<p>Once you get in there, delete it &amp; the folder (about 10 digit folder) and then also go empty your recycle bin.</p>
<p>Restart into normal mode and you should be good to go!  It took me 24 hours to figure it out, but that&#8217;s where it is!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on E mail address has been intercepted by johnytango</title>
		<link>http://www.precisesecurity.com/qa/?p=886#comment-1203</link>
		<dc:creator>johnytango</dc:creator>
		<pubDate>Wed, 18 Nov 2009 09:48:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/qa/?p=886#comment-1203</guid>
		<description>You must have a worm that uses a computer as an SMTP server and symptoms are very much what is happening to yours. Update your antivirus program and do a complete scan in Safe Mode.</description>
		<content:encoded><![CDATA[<p>You must have a worm that uses a computer as an SMTP server and symptoms are very much what is happening to yours. Update your antivirus program and do a complete scan in Safe Mode.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Agent2.ZZG by adamnotsandler</title>
		<link>http://www.precisesecurity.com/qa/?p=890#comment-1201</link>
		<dc:creator>adamnotsandler</dc:creator>
		<pubDate>Tue, 17 Nov 2009 01:13:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/qa/?p=890#comment-1201</guid>
		<description>This is what I've got:
Trojan horse agent2.siq
--c:system volume information_restore{D341....
Trojan horse agent2.siq
--c:hprecoverywizardswr_wizard.exe

Trojan horse agent2.zzg
--c:system volume information_restore{D341....

Trojan horse agent2.zzg
--c:hpbinprocesslogger.exe

PC -- HP, windows XP

AVG version -- 8.5

I noticed most are using ver 9. I'm still at 8.5 with latest update.

Cheers...</description>
		<content:encoded><![CDATA[<p>This is what I&#8217;ve got:<br />
Trojan horse agent2.siq<br />
&#8211;c:system volume information_restore{D341&#8230;.<br />
Trojan horse agent2.siq<br />
&#8211;c:hprecoverywizardswr_wizard.exe</p>
<p>Trojan horse agent2.zzg<br />
&#8211;c:system volume information_restore{D341&#8230;.</p>
<p>Trojan horse agent2.zzg<br />
&#8211;c:hpbinprocesslogger.exe</p>
<p>PC &#8212; HP, windows XP</p>
<p>AVG version &#8212; 8.5</p>
<p>I noticed most are using ver 9. I&#8217;m still at 8.5 with latest update.</p>
<p>Cheers&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to remove Z-Connect Virus by TSM - Swaziland</title>
		<link>http://www.precisesecurity.com/qa/?p=535#comment-1200</link>
		<dc:creator>TSM - Swaziland</dc:creator>
		<pubDate>Mon, 16 Nov 2009 18:31:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/qa/?p=535#comment-1200</guid>
		<description>Deleted the z-connect connection, added a new cnxtn called z-connect, entered isp details, now i am browsing. 

My fear is that as a spyware, assholes may still see into my laptop, so no more businessing on this laptop until i get a true removal tool. Any ideas</description>
		<content:encoded><![CDATA[<p>Deleted the z-connect connection, added a new cnxtn called z-connect, entered isp details, now i am browsing. </p>
<p>My fear is that as a spyware, assholes may still see into my laptop, so no more businessing on this laptop until i get a true removal tool. Any ideas</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Agent2.ZZG by christina jones</title>
		<link>http://www.precisesecurity.com/qa/?p=890#comment-1199</link>
		<dc:creator>christina jones</dc:creator>
		<pubDate>Mon, 16 Nov 2009 12:09:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/qa/?p=890#comment-1199</guid>
		<description>Well this is the email that I received back from HP




"Thank you for contacting HP Total Care.

After reviewing your email, I have understood that you are experiencing the issue with virus.

 

I regret the inconvenience you have faced in the course. I assure you that I, as a part of HP Total Care, take the ownership of the issue you are experiencing and would try to resolve the issue to the best of my abilities and up to your expectation.

 

The reason for this issue is virus.

 

In order to remove the virus I would suggest you to use malware bytes to remove the virus first after that if the issue still persists please download Liveone care for scanning the virus.

 

Please click on the link given below to download Liveone care:

 

http://onecare.live.com/site/en-us/default.htm

 

(The above mentioned URL will take you to a non-HP Web site. HP does not control and is not responsible for information outside of the HP Web site.

)

 

Please get back to us with your valuable observation, if any issue persists we would continue from there. We are waiting for your response.

 

If you need further assistance, please reply to this message and we will be happy to assist you further.



It has been a real pleasure assisting you.  If you need any further assistance, please feel free to contact us and we will be at your service right away

For information on keeping your HP and Compaq products up and running, please visit our Web site
at:
http://www.hp.com/go/totalcare"


I didn't think that was too helpful but others might. I was thinking of maybe contacting AVG seeing as it was their product that detected it.</description>
		<content:encoded><![CDATA[<p>Well this is the email that I received back from HP</p>
<p>&#8220;Thank you for contacting HP Total Care.</p>
<p>After reviewing your email, I have understood that you are experiencing the issue with virus.</p>
<p>I regret the inconvenience you have faced in the course. I assure you that I, as a part of HP Total Care, take the ownership of the issue you are experiencing and would try to resolve the issue to the best of my abilities and up to your expectation.</p>
<p>The reason for this issue is virus.</p>
<p>In order to remove the virus I would suggest you to use malware bytes to remove the virus first after that if the issue still persists please download Liveone care for scanning the virus.</p>
<p>Please click on the link given below to download Liveone care:</p>
<p><a href="http://onecare.live.com/site/en-us/default.htm" rel="nofollow">http://onecare.live.com/site/en-us/default.htm</a></p>
<p>(The above mentioned URL will take you to a non-HP Web site. HP does not control and is not responsible for information outside of the HP Web site.</p>
<p>)</p>
<p>Please get back to us with your valuable observation, if any issue persists we would continue from there. We are waiting for your response.</p>
<p>If you need further assistance, please reply to this message and we will be happy to assist you further.</p>
<p>It has been a real pleasure assisting you.  If you need any further assistance, please feel free to contact us and we will be at your service right away</p>
<p>For information on keeping your HP and Compaq products up and running, please visit our Web site<br />
at:<br />
<a href="http://www.hp.com/go/totalcare" rel="nofollow">http://www.hp.com/go/totalcare</a>&#8221;</p>
<p>I didn&#8217;t think that was too helpful but others might. I was thinking of maybe contacting AVG seeing as it was their product that detected it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Agent2.ZZG by Wanda</title>
		<link>http://www.precisesecurity.com/qa/?p=890#comment-1198</link>
		<dc:creator>Wanda</dc:creator>
		<pubDate>Sun, 15 Nov 2009 18:43:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/qa/?p=890#comment-1198</guid>
		<description>I found something on the HP site about the ZZG file but nothing on the SIQ.  http://h30434.www3.hp.com/psg/board/message?board.id=OSandSW&amp;message.id=13134&amp;query.id=133991#M13134</description>
		<content:encoded><![CDATA[<p>I found something on the HP site about the ZZG file but nothing on the SIQ.  <a href="http://h30434.www3.hp.com/psg/board/message?board.id=OSandSW&amp;message.id=13134&amp;query.id=133991#M13134" rel="nofollow">http://h30434.www3.hp.com/psg/board/message?board.id=OSandSW&amp;message.id=13134&amp;query.id=133991#M13134</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Agent2.ZZG by christina jones</title>
		<link>http://www.precisesecurity.com/qa/?p=890#comment-1197</link>
		<dc:creator>christina jones</dc:creator>
		<pubDate>Sun, 15 Nov 2009 06:14:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/qa/?p=890#comment-1197</guid>
		<description>I have the same issue. my mum was so worried and rang me to come look. We are running XP on a Hp computer. We apprently have it three times. The process name is: C:\\WINDOWS
system32\cidaemon.exe for all three threats. 

2 of the files are the same and have the torjan horse agant2.SIQ 'infection' and the other is the 2.ZZG. 

I've moved them to the virus vault so if anyone here's anthing back from Hp or gets any info that would be great if they share it =]</description>
		<content:encoded><![CDATA[<p>I have the same issue. my mum was so worried and rang me to come look. We are running XP on a Hp computer. We apprently have it three times. The process name is: C:\\WINDOWS<br />
system32\cidaemon.exe for all three threats. </p>
<p>2 of the files are the same and have the torjan horse agant2.SIQ &#8216;infection&#8217; and the other is the 2.ZZG. </p>
<p>I&#8217;ve moved them to the virus vault so if anyone here&#8217;s anthing back from Hp or gets any info that would be great if they share it =]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Google Redirect Virus by ?????? ???????? ??????????</title>
		<link>http://www.precisesecurity.com/qa/?p=157#comment-1195</link>
		<dc:creator>?????? ???????? ??????????</dc:creator>
		<pubDate>Sun, 15 Nov 2009 02:14:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/qa/?p=157#comment-1195</guid>
		<description>&#1055;&#1088;&#1080;&#1074;&#1077;&#1090;! &#1042;&#1080;&#1076;&#1077;&#1083; &#1090;&#1074;&#1086;&#1081; &#1073;&#1083;&#1086;&#1075; &#1076;&#1072;&#1074;&#1085;&#1086; &#1085;&#1077; &#1088;&#1072;&#1073;&#1086;&#1090;&#1072;&#1083;, &#1072; &#1090;&#1077;&#1087;&#1077;&#1088;&#1100; &#1089;&#1084;&#1086;&#1090;&#1088;&#1102; &#1087;&#1072;&#1096;&#1077;&#1090; 24\7\365 :) &#1089; &#1074;&#1086;&#1079;&#1074;&#1088;&#1072;&#1097;&#1077;&#1085;&#1080;&#1077;&#1084;, &#1082;&#1089;&#1090;&#1072;&#1090;&#1080; &#1085;&#1077; &#1087;&#1086;&#1076;&#1089;&#1082;&#1072;&#1078;&#1077;&#1096;&#1100; &#1095;&#1090;&#1086; &#1101;&#1090;&#1086; &#1091; &#1090;&#1077;&#1073;&#1103; &#1079;&#1072; &#1093;&#1086;&#1089;&#1090;&#1080;&#1085;&#1075;?
&#1057;&#1087;&#1072;&#1089;&#1080;&#1073;&#1086;, &#1085;&#1072;&#1076;&#1077;&#1102;&#1089;&#1100; &#1086;&#1090;&#1074;&#1077;&#1090;&#1080;&#1096;&#1100; :)</description>
		<content:encoded><![CDATA[<p>&#1055;&#1088;&#1080;&#1074;&#1077;&#1090;! &#1042;&#1080;&#1076;&#1077;&#1083; &#1090;&#1074;&#1086;&#1081; &#1073;&#1083;&#1086;&#1075; &#1076;&#1072;&#1074;&#1085;&#1086; &#1085;&#1077; &#1088;&#1072;&#1073;&#1086;&#1090;&#1072;&#1083;, &#1072; &#1090;&#1077;&#1087;&#1077;&#1088;&#1100; &#1089;&#1084;&#1086;&#1090;&#1088;&#1102; &#1087;&#1072;&#1096;&#1077;&#1090; 24\7\365 <img src='http://www.precisesecurity.com/qa/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> &#1089; &#1074;&#1086;&#1079;&#1074;&#1088;&#1072;&#1097;&#1077;&#1085;&#1080;&#1077;&#1084;, &#1082;&#1089;&#1090;&#1072;&#1090;&#1080; &#1085;&#1077; &#1087;&#1086;&#1076;&#1089;&#1082;&#1072;&#1078;&#1077;&#1096;&#1100; &#1095;&#1090;&#1086; &#1101;&#1090;&#1086; &#1091; &#1090;&#1077;&#1073;&#1103; &#1079;&#1072; &#1093;&#1086;&#1089;&#1090;&#1080;&#1085;&#1075;?<br />
&#1057;&#1087;&#1072;&#1089;&#1080;&#1073;&#1086;, &#1085;&#1072;&#1076;&#1077;&#1102;&#1089;&#1100; &#1086;&#1090;&#1074;&#1077;&#1090;&#1080;&#1096;&#1100; <img src='http://www.precisesecurity.com/qa/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trojan Horse Agent2.ZZG by Brian</title>
		<link>http://www.precisesecurity.com/qa/?p=890#comment-1194</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Sat, 14 Nov 2009 19:44:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.precisesecurity.com/qa/?p=890#comment-1194</guid>
		<description>I also got this virus, but it listed three files in:
C:\System Volume Information\_restore{00EFF...

Each one said it was the C:\WINDOWS\system32\svchost.exe process that was running that had the issue.

Is this something that was lurking until today? Or something else?</description>
		<content:encoded><![CDATA[<p>I also got this virus, but it listed three files in:<br />
C:\System Volume Information\_restore{00EFF&#8230;</p>
<p>Each one said it was the C:\WINDOWS\system32\svchost.exe process that was running that had the issue.</p>
<p>Is this something that was lurking until today? Or something else?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
