<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys</title>
	<atom:link href="http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html</link>
	<description>Common IT  solutions. AD &#124; Messaging &#124; Virtualization &#124; Storage &#124; Security</description>
	<lastBuildDate>Tue, 23 Feb 2010 19:52:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: jan colen</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/comment-page-1#comment-17396</link>
		<dc:creator>jan colen</dc:creator>
		<pubDate>Sun, 14 Feb 2010 18:43:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-17396</guid>
		<description>Thanks, it works for me as well.
.-= jan colen&#180;s last blog ..&lt;a href=&quot;http://virusverwijderen.hildiid.com/9/virus-verwijderen/&quot; rel=&quot;nofollow&quot;&gt;Virus Verwijderen – Met De Juist Gereedschap Gaat Het Makkelijker&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Thanks, it works for me as well.<br />
<span class="cluv"> jan colen&#180;s last blog ..<a href="http://virusverwijderen.hildiid.com/9/virus-verwijderen/" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/virusverwijderen.hildiid.com/9/virus-verwijderen/?referer=');">Virus Verwijderen – Met De Juist Gereedschap Gaat Het Makkelijker</a> <span class="heart_tip_box"><img class="heart_tip" alt="My ComLuv Profile" border="0" width="16" height="14" src="http://www.kreslavsky.com/wp-content/plugins/commentluv/images/littleheart.gif"/></span></span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dj</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/comment-page-1#comment-2200</link>
		<dc:creator>Dj</dc:creator>
		<pubDate>Tue, 06 Jan 2009 06:11:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-2200</guid>
		<description>To remove shity virus..

Its simple.. download combofix and just click the exe.

It will clean everything all unknown virus other than this..

After testing all others instructions seen in the net..

This made it so simple in 12 mins.

Download it from here...
http://www.bleepingcomputer.com/combofix/how-to-use-combofix</description>
		<content:encoded><![CDATA[<p>To remove shity virus..</p>
<p>Its simple.. download combofix and just click the exe.</p>
<p>It will clean everything all unknown virus other than this..</p>
<p>After testing all others instructions seen in the net..</p>
<p>This made it so simple in 12 mins.</p>
<p>Download it from here&#8230;<br />
<a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.bleepingcomputer.com/combofix/how-to-use-combofix?referer=');">http://www.bleepingcomputer.com/combofix/how-to-use-combofix</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nigel</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/comment-page-1#comment-1974</link>
		<dc:creator>nigel</dc:creator>
		<pubDate>Wed, 26 Nov 2008 15:08:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-1974</guid>
		<description>Just to clarify the thing with ComboFix - follow these instructions and you should be sorted:

1) download ComboFix to a DIFFERENT COMPUTER if poss
2) rename it to, say, lkjhlkhjlhjk.exe, or you may prefer yteyteryt.exe (i.e. any old name)
3) copy it to the DESKTOP of the affected computer

It SHOULD work like that - I had the same trouble as others in getting it to run, the rootkit kept killing it, but this worked, though it&#039;s very slow and looks like it&#039;s crashed, but wait for the blue console to finish its job.

Nasty little rootkit - I bet the &quot;author&quot; gets a nice little jolly, perhaps even of a sexual nature, reading all this and seeing how much time we have wasted eliminating his &quot;work&quot;. I suppose about $200-worth, I&#039;ll take a check, thanks. Yes, if you are reading this, you are VERY VERY CLEVER, congratulations.</description>
		<content:encoded><![CDATA[<p>Just to clarify the thing with ComboFix &#8211; follow these instructions and you should be sorted:</p>
<p>1) download ComboFix to a DIFFERENT COMPUTER if poss<br />
2) rename it to, say, lkjhlkhjlhjk.exe, or you may prefer yteyteryt.exe (i.e. any old name)<br />
3) copy it to the DESKTOP of the affected computer</p>
<p>It SHOULD work like that &#8211; I had the same trouble as others in getting it to run, the rootkit kept killing it, but this worked, though it&#8217;s very slow and looks like it&#8217;s crashed, but wait for the blue console to finish its job.</p>
<p>Nasty little rootkit &#8211; I bet the &#8220;author&#8221; gets a nice little jolly, perhaps even of a sexual nature, reading all this and seeing how much time we have wasted eliminating his &#8220;work&#8221;. I suppose about $200-worth, I&#8217;ll take a check, thanks. Yes, if you are reading this, you are VERY VERY CLEVER, congratulations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stu</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/comment-page-1#comment-1927</link>
		<dc:creator>Stu</dc:creator>
		<pubDate>Thu, 20 Nov 2008 22:08:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-1927</guid>
		<description>Hi guys, excellent work, thanks you life savers!!!!!
I&#039;ve used combo fix - all good, my question is, now what?? Can I have step by step guide to really kill this thing, its all a bit confusing, should i now run that gmr thing or manually delete wintems files?? any file saying wintem??
Confused!! :)</description>
		<content:encoded><![CDATA[<p>Hi guys, excellent work, thanks you life savers!!!!!<br />
I&#8217;ve used combo fix &#8211; all good, my question is, now what?? Can I have step by step guide to really kill this thing, its all a bit confusing, should i now run that gmr thing or manually delete wintems files?? any file saying wintem??<br />
Confused!! <img src='http://www.kreslavsky.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alfred R. Baudisch</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/comment-page-1#comment-1571</link>
		<dc:creator>Alfred R. Baudisch</dc:creator>
		<pubDate>Tue, 28 Oct 2008 18:36:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-1571</guid>
		<description>Note: Windows XP 64 bits users, the viruses exe&#039;s are in folder: windows/SysWOW64 and windows/SysWOW64/Drivers. I just removed them.

For all users: after deleting, create empty files named wintems.exe hldrrr.exe srosa.sys and change permissions &quot;DENY for All Users&quot;, also set Read Only.
To create the blank files: (right click inside the folder, New, text document and type the names (blah.exe). make sure you can edit file extensions, otherwise the files will be wintems.exe.txt)

Make folder drivers/down or drivers/downld (was in my case) the same.

This way if there stills some stuff from the virus, you will fake the files, and they wont be accessible by the little evil. :)</description>
		<content:encoded><![CDATA[<p>Note: Windows XP 64 bits users, the viruses exe&#8217;s are in folder: windows/SysWOW64 and windows/SysWOW64/Drivers. I just removed them.</p>
<p>For all users: after deleting, create empty files named wintems.exe hldrrr.exe srosa.sys and change permissions &#8220;DENY for All Users&#8221;, also set Read Only.<br />
To create the blank files: (right click inside the folder, New, text document and type the names (blah.exe). make sure you can edit file extensions, otherwise the files will be wintems.exe.txt)</p>
<p>Make folder drivers/down or drivers/downld (was in my case) the same.</p>
<p>This way if there stills some stuff from the virus, you will fake the files, and they wont be accessible by the little evil. <img src='http://www.kreslavsky.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: virginia</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/comment-page-1#comment-1382</link>
		<dc:creator>virginia</dc:creator>
		<pubDate>Tue, 21 Oct 2008 10:37:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-1382</guid>
		<description>I am having the same problem as you nightshade, a black box pops up with administrator saying there is already a program of that name there please please please help!</description>
		<content:encoded><![CDATA[<p>I am having the same problem as you nightshade, a black box pops up with administrator saying there is already a program of that name there please please please help!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nightshade</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/comment-page-1#comment-582</link>
		<dc:creator>nightshade</dc:creator>
		<pubDate>Tue, 09 Sep 2008 15:13:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-582</guid>
		<description>guys i tried downloading combofix...after it downloads....it doesnt open.....it says no permission to access or something like that...plz help.....:(</description>
		<content:encoded><![CDATA[<p>guys i tried downloading combofix&#8230;after it downloads&#8230;.it doesnt open&#8230;..it says no permission to access or something like that&#8230;plz help&#8230;..:(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/comment-page-1#comment-114</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Tue, 19 Aug 2008 16:31:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-114</guid>
		<description>Thanks Eran, that did the trick for me on a Vaio, but I had to boot Knoppix with a few cheatcodes.</description>
		<content:encoded><![CDATA[<p>Thanks Eran, that did the trick for me on a Vaio, but I had to boot Knoppix with a few cheatcodes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eran Amir</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/comment-page-1#comment-63</link>
		<dc:creator>Eran Amir</dc:creator>
		<pubDate>Tue, 22 Jul 2008 09:26:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-63</guid>
		<description>this is one of the hardest i have ever tried to scrub off my hard drive
this is something i have tried from this forums responses at and modified it slightly.
this method removes the wintems.exe trojan virus from your computer.

this first part is done using linux. 
if you have a dual boot machine (Ubuntu and Windows Xp), use linux. 
otherwise download knoppix live cd.

here goes:

1) start you computer in linux using Ubuntu or knoppix live CD.
2) mount your ntfs file system using something like: 
mount /dev/sdaX /media (x is your ntfs partition)
and delete wintems.exe from c:\windows\system32\wintems.exe (mine was in /media/sda1)
also delete:
rm -f  /media/WINDOWNS/system32/drivers/hldrrr.exe 
and rm -f /media/WINDOWNS/system32/drivers/srosa.sys.
(it might be slightly different path or case-sensitive)
3. Then I delete the directory c:\windows\system\drivers\down or downld 

4. reboot and start Windowx XP
5. I delete the registry key:

# Run regedit go to:

 HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache 


and see all entries regarding &quot;C:\WINDOWS\system32\drivers&quot; .
# In Explorer window Go to&gt; tools&gt;folder options&gt;view and select show hidden files
# Browse to your C:\WINDOWS\system32\drivers .. 
    find drivers folder and try to delete all files listed in:

 HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache




7. install Avast or AVG and make a full scan without problem

good luck!

Eran</description>
		<content:encoded><![CDATA[<p>this is one of the hardest i have ever tried to scrub off my hard drive<br />
this is something i have tried from this forums responses at and modified it slightly.<br />
this method removes the wintems.exe trojan virus from your computer.</p>
<p>this first part is done using linux.<br />
if you have a dual boot machine (Ubuntu and Windows Xp), use linux.<br />
otherwise download knoppix live cd.</p>
<p>here goes:</p>
<p>1) start you computer in linux using Ubuntu or knoppix live CD.<br />
2) mount your ntfs file system using something like:<br />
mount /dev/sdaX /media (x is your ntfs partition)<br />
and delete wintems.exe from c:\windows\system32\wintems.exe (mine was in /media/sda1)<br />
also delete:<br />
rm -f  /media/WINDOWNS/system32/drivers/hldrrr.exe<br />
and rm -f /media/WINDOWNS/system32/drivers/srosa.sys.<br />
(it might be slightly different path or case-sensitive)<br />
3. Then I delete the directory c:\windows\system\drivers\down or downld </p>
<p>4. reboot and start Windowx XP<br />
5. I delete the registry key:</p>
<p># Run regedit go to:</p>
<p> HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache </p>
<p>and see all entries regarding &#8220;C:\WINDOWS\system32\drivers&#8221; .<br />
# In Explorer window Go to&gt; tools&gt;folder options&gt;view and select show hidden files<br />
# Browse to your C:\WINDOWS\system32\drivers ..<br />
    find drivers folder and try to delete all files listed in:</p>
<p> HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache</p>
<p>7. install Avast or AVG and make a full scan without problem</p>
<p>good luck!</p>
<p>Eran</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Serge</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/comment-page-1#comment-37</link>
		<dc:creator>Serge</dc:creator>
		<pubDate>Wed, 25 Jun 2008 07:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/#comment-37</guid>
		<description>Thank you guys so much. You were really very helpful. In my case, I had VirusScan, AnVir and ThreatFire installed, but only the latter noticed the virus, though it couldn&#039;t fully block it. &lt;br/&gt;&lt;br/&gt;The virus rebooted the PC, then infected a couple of service programs to load with Windows. &lt;br/&gt;&lt;br/&gt;The thing that worked, was &lt;b&gt;Combofix&lt;/b&gt;, when renamed on downloading. Then everything (almost) got cured by Gmer and manually in Regedit - all the keys related to the filenames of the virus files. Then I used Panda to clear the traces. &lt;br/&gt;&lt;br/&gt;It won&#039;t show after reboot, but I am not sure as to what it has done and what information destructed or stole. Are there any ideas on that point?</description>
		<content:encoded><![CDATA[<p>Thank you guys so much. You were really very helpful. In my case, I had VirusScan, AnVir and ThreatFire installed, but only the latter noticed the virus, though it couldn&#8217;t fully block it. </p>
<p>The virus rebooted the PC, then infected a couple of service programs to load with Windows. </p>
<p>The thing that worked, was <b>Combofix</b>, when renamed on downloading. Then everything (almost) got cured by Gmer and manually in Regedit &#8211; all the keys related to the filenames of the virus files. Then I used Panda to clear the traces. </p>
<p>It won&#8217;t show after reboot, but I am not sure as to what it has done and what information destructed or stole. Are there any ideas on that point?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
