<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys</title>
	<atom:link href="http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html</link>
	<description>News, guides, and tips to antivirus programmes, scripts, and security</description>
	<lastBuildDate>Sat, 04 Feb 2012 01:39:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Udi</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comment-48</link>
		<dc:creator>Udi</dc:creator>
		<pubDate>Wed, 23 Jun 2010 20:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-48</guid>
		<description>Thanks so much for your help - it worked for me</description>
		<content:encoded><![CDATA[<p>Thanks so much for your help &#8211; it worked for me</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jan colen</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comment-47</link>
		<dc:creator>jan colen</dc:creator>
		<pubDate>Sun, 14 Feb 2010 18:43:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-47</guid>
		<description>Thanks, it works for me as well.
.-= jan colen&#180;s last blog ..&lt;a href=&quot;http://virusverwijderen.hildiid.com/9/virus-verwijderen/&quot; rel=&quot;nofollow&quot;&gt;Virus Verwijderen – Met De Juist Gereedschap Gaat Het Makkelijker&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Thanks, it works for me as well.<br />
.-= jan colen&#180;s last blog ..<a href="http://virusverwijderen.hildiid.com/9/virus-verwijderen/" rel="nofollow">Virus Verwijderen – Met De Juist Gereedschap Gaat Het Makkelijker</a> =-.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dj</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comment-46</link>
		<dc:creator>Dj</dc:creator>
		<pubDate>Tue, 06 Jan 2009 06:11:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-46</guid>
		<description>To remove shity virus..

Its simple.. download combofix and just click the exe.

It will clean everything all unknown virus other than this..

After testing all others instructions seen in the net..

This made it so simple in 12 mins.

Download it from here...
http://www.bleepingcomputer.com/combofix/how-to-use-combofix</description>
		<content:encoded><![CDATA[<p>To remove shity virus..</p>
<p>Its simple.. download combofix and just click the exe.</p>
<p>It will clean everything all unknown virus other than this..</p>
<p>After testing all others instructions seen in the net..</p>
<p>This made it so simple in 12 mins.</p>
<p>Download it from here&#8230;<br />
<a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" rel="nofollow">http://www.bleepingcomputer.com/combofix/how-to-use-combofix</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nigel</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comment-45</link>
		<dc:creator>nigel</dc:creator>
		<pubDate>Wed, 26 Nov 2008 15:08:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-45</guid>
		<description>Just to clarify the thing with ComboFix - follow these instructions and you should be sorted:

1) download ComboFix to a DIFFERENT COMPUTER if poss
2) rename it to, say, lkjhlkhjlhjk.exe, or you may prefer yteyteryt.exe (i.e. any old name)
3) copy it to the DESKTOP of the affected computer

It SHOULD work like that - I had the same trouble as others in getting it to run, the rootkit kept killing it, but this worked, though it&#039;s very slow and looks like it&#039;s crashed, but wait for the blue console to finish its job.

Nasty little rootkit - I bet the &quot;author&quot; gets a nice little jolly, perhaps even of a sexual nature, reading all this and seeing how much time we have wasted eliminating his &quot;work&quot;. I suppose about $200-worth, I&#039;ll take a check, thanks. Yes, if you are reading this, you are VERY VERY CLEVER, congratulations.</description>
		<content:encoded><![CDATA[<p>Just to clarify the thing with ComboFix &#8211; follow these instructions and you should be sorted:</p>
<p>1) download ComboFix to a DIFFERENT COMPUTER if poss<br />
2) rename it to, say, lkjhlkhjlhjk.exe, or you may prefer yteyteryt.exe (i.e. any old name)<br />
3) copy it to the DESKTOP of the affected computer</p>
<p>It SHOULD work like that &#8211; I had the same trouble as others in getting it to run, the rootkit kept killing it, but this worked, though it&#8217;s very slow and looks like it&#8217;s crashed, but wait for the blue console to finish its job.</p>
<p>Nasty little rootkit &#8211; I bet the &#8220;author&#8221; gets a nice little jolly, perhaps even of a sexual nature, reading all this and seeing how much time we have wasted eliminating his &#8220;work&#8221;. I suppose about $200-worth, I&#8217;ll take a check, thanks. Yes, if you are reading this, you are VERY VERY CLEVER, congratulations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stu</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comment-44</link>
		<dc:creator>Stu</dc:creator>
		<pubDate>Thu, 20 Nov 2008 22:08:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-44</guid>
		<description>Hi guys, excellent work, thanks you life savers!!!!!
I&#039;ve used combo fix - all good, my question is, now what?? Can I have step by step guide to really kill this thing, its all a bit confusing, should i now run that gmr thing or manually delete wintems files?? any file saying wintem??
Confused!! :)</description>
		<content:encoded><![CDATA[<p>Hi guys, excellent work, thanks you life savers!!!!!<br />
I&#8217;ve used combo fix &#8211; all good, my question is, now what?? Can I have step by step guide to really kill this thing, its all a bit confusing, should i now run that gmr thing or manually delete wintems files?? any file saying wintem??<br />
Confused!! <img src='http://www.kreslavsky.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alfred R. Baudisch</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comment-43</link>
		<dc:creator>Alfred R. Baudisch</dc:creator>
		<pubDate>Tue, 28 Oct 2008 18:36:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-43</guid>
		<description>Note: Windows XP 64 bits users, the viruses exe&#039;s are in folder: windows/SysWOW64 and windows/SysWOW64/Drivers. I just removed them.

For all users: after deleting, create empty files named wintems.exe hldrrr.exe srosa.sys and change permissions &quot;DENY for All Users&quot;, also set Read Only.
To create the blank files: (right click inside the folder, New, text document and type the names (blah.exe). make sure you can edit file extensions, otherwise the files will be wintems.exe.txt)

Make folder drivers/down or drivers/downld (was in my case) the same.

This way if there stills some stuff from the virus, you will fake the files, and they wont be accessible by the little evil. :)</description>
		<content:encoded><![CDATA[<p>Note: Windows XP 64 bits users, the viruses exe&#8217;s are in folder: windows/SysWOW64 and windows/SysWOW64/Drivers. I just removed them.</p>
<p>For all users: after deleting, create empty files named wintems.exe hldrrr.exe srosa.sys and change permissions &#8220;DENY for All Users&#8221;, also set Read Only.<br />
To create the blank files: (right click inside the folder, New, text document and type the names (blah.exe). make sure you can edit file extensions, otherwise the files will be wintems.exe.txt)</p>
<p>Make folder drivers/down or drivers/downld (was in my case) the same.</p>
<p>This way if there stills some stuff from the virus, you will fake the files, and they wont be accessible by the little evil. <img src='http://www.kreslavsky.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: virginia</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comment-42</link>
		<dc:creator>virginia</dc:creator>
		<pubDate>Tue, 21 Oct 2008 10:37:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-42</guid>
		<description>I am having the same problem as you nightshade, a black box pops up with administrator saying there is already a program of that name there please please please help!</description>
		<content:encoded><![CDATA[<p>I am having the same problem as you nightshade, a black box pops up with administrator saying there is already a program of that name there please please please help!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nightshade</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comment-41</link>
		<dc:creator>nightshade</dc:creator>
		<pubDate>Tue, 09 Sep 2008 15:13:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-41</guid>
		<description>guys i tried downloading combofix...after it downloads....it doesnt open.....it says no permission to access or something like that...plz help.....:(</description>
		<content:encoded><![CDATA[<p>guys i tried downloading combofix&#8230;after it downloads&#8230;.it doesnt open&#8230;..it says no permission to access or something like that&#8230;plz help&#8230;..:(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comment-40</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Tue, 19 Aug 2008 16:31:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-40</guid>
		<description>Thanks Eran, that did the trick for me on a Vaio, but I had to boot Knoppix with a few cheatcodes.</description>
		<content:encoded><![CDATA[<p>Thanks Eran, that did the trick for me on a Vaio, but I had to boot Knoppix with a few cheatcodes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eran Amir</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comment-39</link>
		<dc:creator>Eran Amir</dc:creator>
		<pubDate>Tue, 22 Jul 2008 09:26:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-39</guid>
		<description>this is one of the hardest i have ever tried to scrub off my hard drive
this is something i have tried from this forums responses at and modified it slightly.
this method removes the wintems.exe trojan virus from your computer.

this first part is done using linux. 
if you have a dual boot machine (Ubuntu and Windows Xp), use linux. 
otherwise download knoppix live cd.

here goes:

1) start you computer in linux using Ubuntu or knoppix live CD.
2) mount your ntfs file system using something like: 
mount /dev/sdaX /media (x is your ntfs partition)
and delete wintems.exe from c:windowssystem32wintems.exe (mine was in /media/sda1)
also delete:
rm -f  /media/WINDOWNS/system32/drivers/hldrrr.exe 
and rm -f /media/WINDOWNS/system32/drivers/srosa.sys.
(it might be slightly different path or case-sensitive)
3. Then I delete the directory c:windowssystemdriversdown or downld 

4. reboot and start Windowx XP
5. I delete the registry key:

# Run regedit go to:

 HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache 


and see all entries regarding &quot;C:WINDOWSsystem32drivers&quot; .
# In Explorer window Go to&gt; tools&gt;folder options&gt;view and select show hidden files
# Browse to your C:WINDOWSsystem32drivers .. 
    find drivers folder and try to delete all files listed in:

 HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache




7. install Avast or AVG and make a full scan without problem

good luck!

Eran</description>
		<content:encoded><![CDATA[<p>this is one of the hardest i have ever tried to scrub off my hard drive<br />
this is something i have tried from this forums responses at and modified it slightly.<br />
this method removes the wintems.exe trojan virus from your computer.</p>
<p>this first part is done using linux.<br />
if you have a dual boot machine (Ubuntu and Windows Xp), use linux.<br />
otherwise download knoppix live cd.</p>
<p>here goes:</p>
<p>1) start you computer in linux using Ubuntu or knoppix live CD.<br />
2) mount your ntfs file system using something like:<br />
mount /dev/sdaX /media (x is your ntfs partition)<br />
and delete wintems.exe from c:windowssystem32wintems.exe (mine was in /media/sda1)<br />
also delete:<br />
rm -f  /media/WINDOWNS/system32/drivers/hldrrr.exe<br />
and rm -f /media/WINDOWNS/system32/drivers/srosa.sys.<br />
(it might be slightly different path or case-sensitive)<br />
3. Then I delete the directory c:windowssystemdriversdown or downld </p>
<p>4. reboot and start Windowx XP<br />
5. I delete the registry key:</p>
<p># Run regedit go to:</p>
<p> HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache </p>
<p>and see all entries regarding &#8220;C:WINDOWSsystem32drivers&#8221; .<br />
# In Explorer window Go to&gt; tools&gt;folder options&gt;view and select show hidden files<br />
# Browse to your C:WINDOWSsystem32drivers ..<br />
    find drivers folder and try to delete all files listed in:</p>
<p> HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache</p>
<p>7. install Avast or AVG and make a full scan without problem</p>
<p>good luck!</p>
<p>Eran</p>
]]></content:encoded>
	</item>
</channel>
</rss>

