<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kreslavsky IT blog &#187; Spyware</title>
	<atom:link href="http://www.kreslavsky.com/category/virus/spyware/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kreslavsky.com</link>
	<description>News, guides, and tips to antivirus programmes, scripts, and security</description>
	<lastBuildDate>Sun, 29 Jan 2012 04:57:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Online Virus Scan Sites</title>
		<link>http://www.kreslavsky.com/2009/06/online-virus-scan-sites.html</link>
		<comments>http://www.kreslavsky.com/2009/06/online-virus-scan-sites.html#comments</comments>
		<pubDate>Wed, 17 Jun 2009 07:05:15 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Malicious Software]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Online Scan]]></category>
		<category><![CDATA[Virus Clean]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/2009/06/online-virus-scan-sites.html</guid>
		<description><![CDATA[Tweet List of available Online Virus Scanners. McAfee FreeScan by McAfee Symantec Security Check by Symantec Housecall by Trend Micro Trend Micro Anti-Spyware for the Web Kaspersky File Scanner by Kaspersky Lab Panda ActiveScan by Panda Software Audit My PC by AuditMyPC]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2009%2F06%2Fonline-virus-scan-sites.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2009/06/online-virus-scan-sites.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2009/06/online-virus-scan-sites.html"  data-text="Online Virus Scan Sites" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2009/06/online-virus-scan-sites.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2009/06/online-virus-scan-sites.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>List of available Online Virus Scanners.</p>
<ul>
<li><a href="http://us.mcafee.com/root/mfs/default.asp">McAfee FreeScan by McAfee</a></li>
<li><a href="http://security.symantec.com/sscv6/default.asp?langid=ie&amp;venid=sym">Symantec Security Check by Symantec</a></li>
<li><a href="http://housecall.trendmicro.com/">Housecall by Trend Micro</a></li>
<li><a href="http://www.trendmicro.com/spyware-scan/">Trend Micro Anti-Spyware for the Web</a></li>
<li><a href="http://www.kaspersky.com/scanforvirus">Kaspersky File Scanner by Kaspersky Lab</a></li>
<li><a href="http://www.pandasoftware.com/products/ActiveScan.htm">Panda ActiveScan by Panda Software</a></li>
<li><a href="http://www.auditmypc.com/">Audit My PC by AuditMyPC</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2009/06/online-virus-scan-sites.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Sensor abilities of Windows 7</title>
		<link>http://www.kreslavsky.com/2008/12/sensor-abilityes-of-windows-7.html</link>
		<comments>http://www.kreslavsky.com/2008/12/sensor-abilityes-of-windows-7.html#comments</comments>
		<pubDate>Fri, 12 Dec 2008 19:18:11 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Malicious Software]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Capabilities]]></category>
		<category><![CDATA[Computer User]]></category>
		<category><![CDATA[Interaction]]></category>
		<category><![CDATA[Iphone]]></category>
		<category><![CDATA[Keyboard]]></category>
		<category><![CDATA[Media Content]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Programmers]]></category>
		<category><![CDATA[Mobile Devices]]></category>
		<category><![CDATA[New Operating System]]></category>
		<category><![CDATA[Photos]]></category>
		<category><![CDATA[Possibilities]]></category>
		<category><![CDATA[Specialized Software]]></category>
		<category><![CDATA[Technology Developers]]></category>
		<category><![CDATA[Windows Microsoft]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/?p=476</guid>
		<description><![CDATA[Tweet Despite the skepticism of many experts about Windows 7, Microsoft programmers now can boast a range of specialized software for the upcoming operating system with capabilities that are a couple of years ago could only dream of. Particular attention is paid technology developers and computer user interaction. For example, users of Windows 7 by using only one finger will have the opportunity to upload media content to mobile devices such iPod, iPhone, phones based or Android. Watching the possibilities of this new operating system, the question arises &#8211; why humans use keyboard and mouse, if he has his hands? That&#8217;s why Microsoft programmers and PQ-DVD decided to go further and allow each home user to evaluate sensory management to work with media content &#8211; to sort photos, watching video. Submitted video shows what you can do with your own hands is much easier and faster than using mouse and keyboard. However, to realize these opportunities may require a very powerful PC, not to mention the touch panel.]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F12%2Fsensor-abilityes-of-windows-7.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/12/sensor-abilityes-of-windows-7.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/12/sensor-abilityes-of-windows-7.html"  data-text="Sensor abilities of Windows 7" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/12/sensor-abilityes-of-windows-7.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/12/sensor-abilityes-of-windows-7.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p style="text-align: left;">Despite the skepticism of many experts about Windows 7, Microsoft programmers now can boast a range of specialized software for the upcoming operating system with capabilities that are a couple of years ago could only dream of.</p>
<p style="text-align: left;">Particular attention is paid technology developers and computer user interaction. For example, users of Windows 7 by using only one finger will have the opportunity to upload media content to mobile devices such iPod, iPhone, phones based or Android.</p>
<p style="text-align: left;">Watching the possibilities of this new operating system, the question arises &#8211; why humans use keyboard and mouse, if he has his hands? That&#8217;s why Microsoft programmers and PQ-DVD decided to go further and allow each home user to evaluate sensory management to work with media content &#8211; to sort photos, watching video.</p>
<p style="text-align: left;">Submitted video shows what you can do with your own hands is much easier and faster than using mouse and keyboard. However, to realize these opportunities may require a very powerful PC, not to mention the touch panel.</p>
<p style="text-align: center;"><object width="425" height="344" data="http://www.youtube.com/v/YO_790BZVqc&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/YO_790BZVqc&amp;hl=en&amp;fs=1" /><param name="allowfullscreen" value="true" /></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/12/sensor-abilityes-of-windows-7.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Manual Remove of  Winspywareprotectscan.exe</title>
		<link>http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html</link>
		<comments>http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html#comments</comments>
		<pubDate>Wed, 16 Jul 2008 08:58:22 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Malicious Software]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Adsl Software]]></category>
		<category><![CDATA[Amp]]></category>
		<category><![CDATA[Anti Spyware]]></category>
		<category><![CDATA[Balloon]]></category>
		<category><![CDATA[Corrupt Registry]]></category>
		<category><![CDATA[Critical System]]></category>
		<category><![CDATA[Dangerous Symptoms]]></category>
		<category><![CDATA[Dlls]]></category>
		<category><![CDATA[Exe Files]]></category>
		<category><![CDATA[Limited]]></category>
		<category><![CDATA[Machine Software]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Pop]]></category>
		<category><![CDATA[Registry Entries]]></category>
		<category><![CDATA[Risk Level]]></category>
		<category><![CDATA[Software Microsoft]]></category>
		<category><![CDATA[Software Windows]]></category>
		<category><![CDATA[System Error]]></category>
		<category><![CDATA[Winspywareprotectscan.exe]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/?p=151</guid>
		<description><![CDATA[Tweet Risk Level : Very High ( Dangerous ) Symptoms Pop up balloon warning messages claiming that your PC is infected. * &#8220;Critical System Error&#8221;, * &#8220;Your computer is infected&#8221;, Search and kill the following processes * antivirus.v.1.0.0, WinSpywareProtect.EXE, WinSpywareProtectSetup.exe Remove Scan.Winspywareprotectscan.com files &#38; dlls files * antivirus.v.1.0.0, * WinSpywareProtect.EXE, * WinSpywareProtectSetup.exe Remove/Modify corrupt Registry Entries HKEY_LOCAL_MACHINESOFTWAREWinSpywareProtect HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion UninstallWinSpywareProtect HKEY_ALL_USERSSoftwareAdsl Software Limited HKEY_CLASSES_ROOTTacOnlyOne Use Shield Deluxe 2008 &#8211; Antivirus &#38; Anti-Spyware to scan yor computer for other threats]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F07%2Fmanual-remove-of-winspywareprotectscanexe.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html"  data-text="Manual Remove of  Winspywareprotectscan.exe" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>Risk Level : Very High ( Dangerous )</p>
<p>Symptoms</p>
<p>Pop up balloon warning messages claiming that your PC is infected.</p>
<p>* &#8220;Critical System Error&#8221;,<br />
* &#8220;Your computer is infected&#8221;,</p>
<p>Search and kill the following processes</p>
<p>* antivirus.v.1.0.0, WinSpywareProtect.EXE, WinSpywareProtectSetup.exe</p>
<p>Remove Scan.Winspywareprotectscan.com files &amp; dlls files</p>
<p>* antivirus.v.1.0.0,<br />
* WinSpywareProtect.EXE,<br />
* WinSpywareProtectSetup.exe</p>
<p>Remove/Modify corrupt Registry Entries</p>
<p>HKEY_LOCAL_MACHINESOFTWAREWinSpywareProtect<br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion<br />
UninstallWinSpywareProtect<br />
HKEY_ALL_USERSSoftwareAdsl Software Limited<br />
HKEY_CLASSES_ROOTTacOnlyOne</p>
<p>Use Shield Deluxe 2008 &#8211; Antivirus &amp; Anti-Spyware to scan yor computer for other threats</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Virusheat.com trojan</title>
		<link>http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html</link>
		<comments>http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html#comments</comments>
		<pubDate>Sun, 17 Feb 2008 16:37:00 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Malicious Software]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Annoying Pop]]></category>
		<category><![CDATA[C Program]]></category>
		<category><![CDATA[Computer Virus]]></category>
		<category><![CDATA[Delete]]></category>
		<category><![CDATA[Dll]]></category>
		<category><![CDATA[Hkey Local Machine]]></category>
		<category><![CDATA[Hkey Local Machine Software]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Program Files Folder]]></category>
		<category><![CDATA[Remove Trojan]]></category>
		<category><![CDATA[Remove Virus]]></category>
		<category><![CDATA[Safe Mode]]></category>
		<category><![CDATA[Software Microsoft]]></category>
		<category><![CDATA[Stop Virus]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Trojan Virus]]></category>
		<category><![CDATA[Trojan Win32]]></category>
		<category><![CDATA[Uninstall]]></category>
		<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[Witch]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan/</guid>
		<description><![CDATA[Tweet Virus Heat is a Trojan.Win32 . More or less, it does degrade performance of computers and generate annoying pop up witch send you to virusheat.com. Virus Heat Manual Removal Process: 1. Go to Control Panel &#62;Add or Remove Programs and uninstall Virus Heat 2. Close all programs. 3. Go to &#62;Start&#62;Run &#62;regedit find and delete key “HKEY_LOCAL_MACHINESOFTWAREMicrosoft WindowsCurrentVersionUninstallVirus Heat” 4. Restart the computer. 5. Stop Virus Heat process 6. Find and delete the following infected files from your system. Don’t worry if you don’t find these files. Just proceed to next step. Virus Heat 3.9.exe, wuuawkz.dll , iinqyl.dll 7. Go to C:Program Files folder and delete the “Virus Heat” folder (if you can’t delete it, reboot your computer to safe mode then delete the folder. 8. After all steps go to http://siri.geekstogo.com/SmitfraudFix.php and download last version of Smitfraudfix.exe 9. Reboot the computer in safe mode and run the utility.]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F02%2Fremove-virusheatcom-trojan.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html"  data-text="Remove Virusheat.com trojan" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><span style="font-size:85%;"><strong>Virus Heat</strong> is a <strong>Trojan.Win32</strong> . More or less, it does degrade performance of computers and generate annoying pop up witch send you to virusheat.com. </span></p>
<p><span style="font-size:85%;"><strong>Virus Heat Manual Removal Process:</strong> </span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">1.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Go to </span> <span style=";font-size:85%;"> </span> <span style="font-size:85%;">Control Panel &gt;Add or Remove Programs and uninstall Virus Heat</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">2.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Close all programs.</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">3.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Go to &gt;Start&gt;Run &gt;regedit find and delete key</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><span style="font-size:85%;">“HKEY_LOCAL_MACHINESOFTWAREMicrosoft</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><span style="font-size:85%;">WindowsCurrentVersionUninstallVirus Heat” </span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">4.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Restart the computer.</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">5.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Stop Virus Heat process</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">6.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Find and delete the following infected files from your system. Don’t worry if you don’t find these files. Just proceed to next step.</span> <span style=";font-size:85%;"> </span> <span style="font-size: 85%; color: red;">Virus Heat 3.9.exe, wuuawkz.dll , iinqyl.dll</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">7.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Go to C:Program Files folder and delete the “Virus Heat” folder (if you can’t delete it, reboot your computer to safe mode then delete the folder.</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">8.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">After all steps go to <a href="http://siri.geekstogo.com/SmitfraudFix.php">http://siri.geekstogo.com/SmitfraudFix.php</a> and download last version of </span> <span style=";font-size:85%;">Smitfraudfix.exe</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">9.<span> </span> </span> <!-- [endif]--><span style=";font-size:85%;">Reboot the computer in safe mode and run the utility.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html</link>
		<comments>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comments</comments>
		<pubDate>Sat, 09 Feb 2008 19:53:00 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Malicious Software]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Anti Virus]]></category>
		<category><![CDATA[Antivirus Software]]></category>
		<category><![CDATA[Bagle Virus]]></category>
		<category><![CDATA[Current User]]></category>
		<category><![CDATA[Hldrrr]]></category>
		<category><![CDATA[hldrrr.exe]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Panda]]></category>
		<category><![CDATA[Program Download]]></category>
		<category><![CDATA[Safe Mode]]></category>
		<category><![CDATA[Scanner]]></category>
		<category><![CDATA[Service Pack]]></category>
		<category><![CDATA[Software Microsoft]]></category>
		<category><![CDATA[srosa.sys]]></category>
		<category><![CDATA[Sys]]></category>
		<category><![CDATA[User Software]]></category>
		<category><![CDATA[Virus Download]]></category>
		<category><![CDATA[Virus Exe]]></category>
		<category><![CDATA[Virus Program]]></category>
		<category><![CDATA[Virus Updates]]></category>
		<category><![CDATA[W32 Virus]]></category>
		<category><![CDATA[W32.BAGLE]]></category>
		<category><![CDATA[wintems.exe]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/</guid>
		<description><![CDATA[Tweet W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys I must say that with all my of experience that one was one of the hardest to remove .. It disables your current antivirus software, prohibit you from accessing system in safe mode , and changes names each time it starts. So.. Here are the steps Go to http://www.majorgeeks.com/GMER_d5198.html and download GMER Run the tool and when it finds wintems.exe process kill him.. Run regedit go to HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache and see all entries regarding &#8220;C:WINDOWSsystem32drivers&#8221; . In Explorer window Go to&#62; tools&#62;folder options&#62;view and select show hidden files Browse to your C:WINDOWSsystem32drivers .. find drivers folder and try to delete all files listed in HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache Scan your system with panda online scanner (the only one that actually cleans , not only detects Install anti virus program, download last updates and do a full scan to your system Of course there is always an option to reapply service pack or do a reinstall to your system. The problem is solved ! Thanks to Eran Amir]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F02%2Fwintermsexe-hldrrrexe.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html"  data-text="W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys</p>
<p>I must say that with all my  of experience that one was one of the hardest to remove ..<br />
It disables your current antivirus software, prohibit you from accessing system in safe mode , and changes names each time it starts.</p>
<p>So.. Here are the steps</p>
<p>Go to http://www.majorgeeks.com/GMER_d5198.html and download GMER<br />
Run the tool and when it finds wintems.exe process kill him..</p>
<ol>
<li>Run regedit go to HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache and see  all entries regarding &#8220;C:WINDOWSsystem32drivers&#8221; .</li>
<li>In Explorer window Go to&gt; tools&gt;folder options&gt;view and select show hidden files</li>
<li>Browse to your C:WINDOWSsystem32drivers ..  find drivers folder and try to delete all files listed   in HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache</li>
<li>Scan your system with panda online scanner (the only one that actually cleans , not only detects</li>
<li>Install anti virus program, download last updates and do a full scan to your system</li>
</ol>
<p>Of course there is always an option to reapply service pack or do a reinstall to your system.</p>
<p>The problem is solved !</p>
<p>Thanks to Eran Amir</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/feed</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
	</channel>
</rss>

