<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kreslavsky IT blog &#187; Microsoft Windows</title>
	<atom:link href="http://www.kreslavsky.com/tag/microsoft-windows/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kreslavsky.com</link>
	<description>News, guides, and tips to antivirus programmes, scripts, and security</description>
	<lastBuildDate>Sun, 29 Jan 2012 04:57:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Manual uninstall of VMware Tools Windows 2003 and 2008</title>
		<link>http://www.kreslavsky.com/2011/01/manual-uninstall-of-vmware-tools-windows-2003-and-2008-2.html</link>
		<comments>http://www.kreslavsky.com/2011/01/manual-uninstall-of-vmware-tools-windows-2003-and-2008-2.html#comments</comments>
		<pubDate>Mon, 31 Jan 2011 15:32:18 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[ESX Server]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[Delete Directory]]></category>
		<category><![CDATA[Installation Wizard]]></category>
		<category><![CDATA[Machine Software]]></category>
		<category><![CDATA[Manual remove]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Search]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[New Tools]]></category>
		<category><![CDATA[Previous Version]]></category>
		<category><![CDATA[Products Search]]></category>
		<category><![CDATA[Registry Editor]]></category>
		<category><![CDATA[Search Tools]]></category>
		<category><![CDATA[Software Classes]]></category>
		<category><![CDATA[Software Microsoft]]></category>
		<category><![CDATA[Software Search]]></category>
		<category><![CDATA[Tools Windows]]></category>
		<category><![CDATA[Uninstall]]></category>
		<category><![CDATA[Uninstall Windows]]></category>
		<category><![CDATA[VMware tools]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/2011/01/manual-uninstall-of-vmware-tools-windows-2003-and-2008-2.html</guid>
		<description><![CDATA[Tweet &#160; When you try to upgrade to new version of VMware tools , Installation wizard asks you to uninstall older version . If you can’t do it , or uninstall feature failed to complete, you will need to uninstall them manually. You may receive the following errors A previous version of VMware Tools is already installed To remove old VMware tools follow the steps bellow: Open registry editor Navigate to the following key HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionuninstall search for VMware Tools related branch and delete the key Please note:Do not delete the entire uninstall branch. Navigate to HKEY_LOCAL_MACHINESoftwareClassesInstallerProducts search for VMware Tools related branch and delete the key Please note:Do not delete the entire Products&#160; key Navigate to HKEY_CLASSES_ROOTInstallerProducts search for VMware Tools related branch and delete the key Please note:Do not delete the entire Products&#160; key Navigate to HKEY_LOCAL_MACHINESoftwareVMware Delete the branch called VMware Tools. Delete the &#34;VMware Tools&#34; directory within in the Vmware directory under Program Files Restart the server Install updated version of VMware Tools through Vsphere Client or VMware client]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2011%2F01%2Fmanual-uninstall-of-vmware-tools-windows-2003-and-2008-2.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2011/01/manual-uninstall-of-vmware-tools-windows-2003-and-2008-2.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2011/01/manual-uninstall-of-vmware-tools-windows-2003-and-2008-2.html"  data-text="Manual uninstall of VMware Tools Windows 2003 and 2008" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2011/01/manual-uninstall-of-vmware-tools-windows-2003-and-2008-2.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2011/01/manual-uninstall-of-vmware-tools-windows-2003-and-2008-2.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>&#160;</p>
<p>When you try to upgrade to new version of VMware tools , Installation wizard asks you to uninstall older version .   <br />If you can’t do it , or uninstall feature failed to complete, you will need to uninstall them manually.</p>
<p>You may receive the following errors   <br />A previous version of VMware Tools is already installed<img title="A previous version of VMware Tools is already installed" alt="A previous version of VMware Tools is already installed" src="http://www.techhead.co.uk/wp-content/uploads/2009/06/image-thumb.png" width="386" height="154" /></p>
<p><img alt="Error 1316 A network error occured while attempting to read from the file C:WindowsInstalledVMware Tools.msi" src="http://www.techhead.co.uk/wp-content/uploads/2009/06/image-thumb1.png" width="391" height="147" /></p>
<p><strong>To remove old VMware tools follow the steps bellow</strong>:</p>
<ol>
<li>Open registry editor</li>
<li>Navigate to the following key     <br />HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionuninstall search for VMware Tools related branch and delete the key <strong>Please note:Do not delete the entire uninstall branch</strong>.</li>
<li>Navigate to      <br />HKEY_LOCAL_MACHINESoftwareClassesInstallerProducts search for VMware Tools related branch and delete the key       <br /><strong>Please note:Do not delete the entire Products&#160; key</strong></li>
<li>Navigate to     <br /> HKEY_CLASSES_ROOTInstallerProducts search for VMware Tools related branch and delete the key      <br /><strong>Please note:Do not delete the entire Products&#160; key</strong> </li>
<li>Navigate to      <br />HKEY_LOCAL_MACHINESoftwareVMware Delete the branch called <strong>VMware Tools</strong>.</li>
<li>Delete the &quot;<strong>VMware Tools</strong>&quot; directory within in the Vmware directory under Program Files</li>
<li>Restart the server</li>
<li>Install updated version of VMware Tools through Vsphere Client or VMware client     </li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2011/01/manual-uninstall-of-vmware-tools-windows-2003-and-2008-2.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Same user info on all Terminal Server Office clients</title>
		<link>http://www.kreslavsky.com/2010/07/same-user-info-on-all-terminal-server-office-clients.html</link>
		<comments>http://www.kreslavsky.com/2010/07/same-user-info-on-all-terminal-server-office-clients.html#comments</comments>
		<pubDate>Wed, 07 Jul 2010 07:58:24 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Office 2007]]></category>
		<category><![CDATA[Server 2003]]></category>
		<category><![CDATA[Server 2008]]></category>
		<category><![CDATA[Terminal Server]]></category>
		<category><![CDATA[Delete]]></category>
		<category><![CDATA[Desktop]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Office Clients]]></category>
		<category><![CDATA[Registry]]></category>
		<category><![CDATA[Software Microsoft]]></category>
		<category><![CDATA[User Information]]></category>
		<category><![CDATA[Userdata]]></category>
		<category><![CDATA[Word Files]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/2010/07/same-user-info-on-all-terminal-server-office-clients.html</guid>
		<description><![CDATA[Tweet Terminal Server Office 2003/2007/2010 Installation issue If you installed office in the same way you install it on your desktop. Your user information will be replicated to all other users. You may receive complaints that some excel or word files are been hold by your username or username you used to install Office. You can fix it the following way. Search for the user in registry One of the keys under HKLMSOFTWAREMicrosoftWindowsCurentVersionInstallerUserData will have office instalation details. Delete user RegOwner key Information. Continue searching the registry right-click and delete the Username and UserInitials with problematic username &#160; Additional information can be found here:http://support.microsoft.com/kb/2001595]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2010%2F07%2Fsame-user-info-on-all-terminal-server-office-clients.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2010/07/same-user-info-on-all-terminal-server-office-clients.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2010/07/same-user-info-on-all-terminal-server-office-clients.html"  data-text="Same user info on all Terminal Server Office clients" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2010/07/same-user-info-on-all-terminal-server-office-clients.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2010/07/same-user-info-on-all-terminal-server-office-clients.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>Terminal Server Office 2003/2007/2010 Installation issue</p>
<p>If you installed office in the same way you install it on your desktop.   <br />Your user information will be replicated to all other users.</p>
<p>You may receive complaints that some excel or word files are been hold by your username or username you used to install Office.</p>
<p>You can fix it the following way.</p>
<p>Search for the user in registry    <br />One of the keys under HKLMSOFTWAREMicrosoftWindowsCurentVersionInstallerUserData will have office instalation details.</p>
<p>Delete user RegOwner key Information.</p>
<p><a href="http://www.kreslavsky.com/wp-content/uploads/2010/07/image.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.kreslavsky.com/wp-content/uploads/2010/07/image_thumb.png" width="530" height="326" /></a> </p>
<p>Continue searching the registry right-click and delete the Username and UserInitials with problematic username</p>
<p><a href="http://www.kreslavsky.com/wp-content/uploads/2010/07/image1.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.kreslavsky.com/wp-content/uploads/2010/07/image_thumb1.png" width="531" height="232" /></a> </p>
<p>&#160;</p>
<p>Additional information can be found here:<a href="http://support.microsoft.com/kb/2001595">http://support.microsoft.com/kb/2001595</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2010/07/same-user-info-on-all-terminal-server-office-clients.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 7 Search in Start Menu bar is broken</title>
		<link>http://www.kreslavsky.com/2010/03/windows-7-search-in-start-menu-bar-is-broken.html</link>
		<comments>http://www.kreslavsky.com/2010/03/windows-7-search-in-start-menu-bar-is-broken.html#comments</comments>
		<pubDate>Sun, 07 Mar 2010 07:40:35 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Server 2008]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[0000]]></category>
		<category><![CDATA[Addresses]]></category>
		<category><![CDATA[Current User]]></category>
		<category><![CDATA[Explorer Exe]]></category>
		<category><![CDATA[Hotfix]]></category>
		<category><![CDATA[Key Start]]></category>
		<category><![CDATA[Menu Bar]]></category>
		<category><![CDATA[Microsoft Explorer]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Orig]]></category>
		<category><![CDATA[Search Bar]]></category>
		<category><![CDATA[Software Microsoft]]></category>
		<category><![CDATA[Software Windows]]></category>
		<category><![CDATA[Start Menu]]></category>
		<category><![CDATA[Support Microsoft]]></category>
		<category><![CDATA[Task Bar]]></category>
		<category><![CDATA[Task Manager]]></category>
		<category><![CDATA[User Software]]></category>
		<category><![CDATA[Windows 2008R2]]></category>
		<category><![CDATA[Windows 7 Search Bar]]></category>
		<category><![CDATA[Windows Explorer]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/2010/03/windows-7-search-in-start-menu-bar-is-broken.html</guid>
		<description><![CDATA[Tweet &#160; I got this after installing some update, can’t say exactly which. The problem symptom is that when you type anything in search bar it looks like that To solve it. Go to Run&#62; type regedit.exe Navigate to :HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurre ntVersionExplorerFolderTypes{EF87B4CB-F2CE-4785-8658-4CA6C63E38C6}TopViews You will see a key named {00000000-0000-0000-0000-000000000000} Just rename it to anything else like {00000000-0000-0000-0000-000000000000}.Orig After you rename the key , start Task manager and kill the explorer.exe process Run the process again from file&#62;New Task (Run..) Type in bar explorer.exe And Walla! It works! Microsoft published a hotfix that addresses the issue in Windows 7 and 2008R2 http://support.microsoft.com/kb/977380]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2010%2F03%2Fwindows-7-search-in-start-menu-bar-is-broken.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2010/03/windows-7-search-in-start-menu-bar-is-broken.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2010/03/windows-7-search-in-start-menu-bar-is-broken.html"  data-text="Windows 7 Search in Start Menu bar is broken" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2010/03/windows-7-search-in-start-menu-bar-is-broken.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2010/03/windows-7-search-in-start-menu-bar-is-broken.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>&#160;</p>
<p>I got this after installing some update, can’t say exactly which.   <br />The problem symptom is that when you type anything in search bar it looks like that    <br /><a href="http://www.kreslavsky.com/wp-content/uploads/2010/03/image.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="Search programs and files" border="0" alt="Search programs and files" src="http://www.kreslavsky.com/wp-content/uploads/2010/03/image_thumb.png" width="212" height="242" /></a> </p>
<p>To solve it.</p>
<p>Go to Run&gt; type regedit.exe</p>
<p>Navigate to :<em><strong>HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurre ntVersionExplorerFolderTypes{EF87B4CB-F2CE-4785-8658-4CA6C63E38C6}TopViews</strong></em></p>
<p>You will see a key named <strong>{00000000-0000-0000-0000-000000000000}     <br /></strong>Just rename it to anything else like {00000000-0000-0000-0000-000000000000}.Orig</p>
<p>After you rename the key , start Task manager and kill the explorer.exe process</p>
<p>Run the process again from file&gt;New Task (Run..)</p>
<p><a href="http://www.kreslavsky.com/wp-content/uploads/2010/03/image1.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="File new task Run" border="0" alt="File new task Run" src="http://www.kreslavsky.com/wp-content/uploads/2010/03/image_thumb1.png" width="262" height="295" /></a> </p>
<p>Type in bar explorer.exe</p>
<p>And Walla! </p>
<p>It works!</p>
<p>Microsoft published a hotfix that addresses the issue in Windows 7 and 2008R2</p>
<p><a href="http://support.microsoft.com/kb/977380">http://support.microsoft.com/kb/977380</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2010/03/windows-7-search-in-start-menu-bar-is-broken.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vista Unable to send Fax &#8211; Error: Media is write protected</title>
		<link>http://www.kreslavsky.com/2009/03/vista-unable-to-send-fax-error-media-is-write-protected.html</link>
		<comments>http://www.kreslavsky.com/2009/03/vista-unable-to-send-fax-error-media-is-write-protected.html#comments</comments>
		<pubDate>Mon, 16 Mar 2009 07:57:22 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Vista]]></category>
		<category><![CDATA[Installation Folder]]></category>
		<category><![CDATA[Machine Software]]></category>
		<category><![CDATA[Microsoft Fax]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Reboot]]></category>
		<category><![CDATA[Search Field]]></category>
		<category><![CDATA[Send Fax]]></category>
		<category><![CDATA[Software Fax]]></category>
		<category><![CDATA[Software Microsoft]]></category>
		<category><![CDATA[Vista fax]]></category>
		<category><![CDATA[Windows Installation]]></category>
		<category><![CDATA[Windows Vista]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/?p=643</guid>
		<description><![CDATA[Tweet To fix fax sending issue in Windows Vista: Click Start &#62;in search field type &#8220;regedit&#8220;  hit Enter Navigate to HKEY_LOCAL_MACHINESOFTWAREMicrosoftFax On the right pane find and click on ArchiveFolder Check if  the value of the key is  C:ProgramDataMicrosoftWindows NTMSFax if not fill it note:The location can be D: or any other windows installation folder Reboot your Vista]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2009%2F03%2Fvista-unable-to-send-fax-error-media-is-write-protected.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2009/03/vista-unable-to-send-fax-error-media-is-write-protected.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2009/03/vista-unable-to-send-fax-error-media-is-write-protected.html"  data-text="Vista Unable to send Fax &#8211; Error: Media is write protected" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2009/03/vista-unable-to-send-fax-error-media-is-write-protected.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2009/03/vista-unable-to-send-fax-error-media-is-write-protected.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>To fix fax sending issue in Windows Vista:</p>
<ul>
<li>Click Start &gt;in search field type &#8220;<strong>regedit</strong>&#8220;  hit Enter</li>
<li>Navigate to HKEY_LOCAL_MACHINESOFTWAREMicrosoftFax</li>
<li>On the right pane find and click on <strong>ArchiveFolder</strong></li>
<li>Check if  the value of the key is  C:ProgramDataMicrosoftWindows NTMSFax if not fill it<br />
<span style="color: #ff0000;"> <span style="font-size: x-small;">note:The location can be D: or any other windows installation folder</span></span></li>
<li>Reboot your Vista</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2009/03/vista-unable-to-send-fax-error-media-is-write-protected.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Configure Fax Windows Server 2008</title>
		<link>http://www.kreslavsky.com/2008/12/configure-fax-windows-server-2008.html</link>
		<comments>http://www.kreslavsky.com/2008/12/configure-fax-windows-server-2008.html#comments</comments>
		<pubDate>Wed, 10 Dec 2008 08:44:46 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Server 2008]]></category>
		<category><![CDATA[7 Digits]]></category>
		<category><![CDATA[Activity Logging]]></category>
		<category><![CDATA[Area Code]]></category>
		<category><![CDATA[Code Target]]></category>
		<category><![CDATA[Default Location]]></category>
		<category><![CDATA[Digit Phone Number]]></category>
		<category><![CDATA[E Mail Address]]></category>
		<category><![CDATA[Fax Server]]></category>
		<category><![CDATA[Fax Windows]]></category>
		<category><![CDATA[Faxes]]></category>
		<category><![CDATA[Incoming Fax]]></category>
		<category><![CDATA[Logging Tab]]></category>
		<category><![CDATA[Mail Delivery]]></category>
		<category><![CDATA[Mail Server]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Outgoing Fax]]></category>
		<category><![CDATA[Receipts]]></category>
		<category><![CDATA[Server Address]]></category>
		<category><![CDATA[Server Manager]]></category>
		<category><![CDATA[Smtp Mail]]></category>
		<category><![CDATA[Target Device]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[windows server 2008]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/?p=457</guid>
		<description><![CDATA[Tweet Configure Fax properties &#8211; Windows server 2008 Within Server Manager, expand Roles and then expand Fax Server. Right-click Fax and choose Properties. On the Receipts tab, click the box labeled Enable SMTP E-Mail Receipts Delivery and enter a From e-mail address, SMTP server address, and port number. Select the Activity Logging tab. Click the boxes next to Log Incoming Fax Activity and Log Outgoing Fax Activity. In the Activity Log Folder text box, enter the path to store the activity log. The default location is C:ProgramDataMicrosoftWindows NTMSFaxActivityLog. Select the Outbox tab, check the Automatically Delete Faxes Older Than option and then choose the number of days to keep faxes. Select the Archives tab and then check Archive All Faxes to This Folder. Browse to the location that should be used to store archived faxes. The default is C:ProgramDataMicrosoftWindows NTMSFax. To allow faxes to be reassigned, select the Accounts tab and then check the On box under Reassign Settings. Click OK. Defining a Dialing Rule Setting up dialing rules will help the fax server understand what your area requires. For example, most locations in the United States require dialing a 1 before dialing a number outside a local area code. When dialing within an area code, only 7 digits are needed. Alternatively, if a local area uses 10-digit dialing, a user has to put in an area code plus the 7-digit phone number. As you can see, by setting up the dialing rules first, you keep your users from having to enter numbers such as 1 before the area code.You can configure the following options for dialing rules: Dialed Number You can enter a region code and area code. Target Device Choose to apply your rule to devices. Configuring a Dialing Rule Under Fax Server in Server Manager, expand Outgoing Routing. Right-click on Rules and choose New and then Rule. In the Dialed Number section of the Add New Rule dialog box, enter your region code. If you are unsure, click Select and then choose from the list. In the Target Device section, choose whether you want this rule to apply to a device or a routing group and then choose from the list in the drop-down box. Click OK.]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F12%2Fconfigure-fax-windows-server-2008.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/12/configure-fax-windows-server-2008.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/12/configure-fax-windows-server-2008.html"  data-text="Configure Fax Windows Server 2008" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/12/configure-fax-windows-server-2008.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/12/configure-fax-windows-server-2008.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><h2>Configure Fax properties &#8211; Windows server 2008</h2>
<ul>
<li>Within Server Manager, expand Roles and then expand Fax Server.</li>
<li>Right-click Fax and choose Properties.</li>
<li>On the Receipts tab, click the box labeled Enable SMTP E-Mail Receipts Delivery and<br />
enter a From e-mail address, SMTP server address, and port number.</li>
<li> Select the Activity Logging tab. Click the boxes next to Log Incoming Fax Activity and<br />
Log Outgoing Fax Activity.</li>
<li>In the Activity Log Folder text box, enter the path to store the activity log. The default<br />
location is C:ProgramDataMicrosoftWindows NTMSFaxActivityLog.</li>
<li>Select the Outbox tab, check the Automatically Delete Faxes Older Than option and<br />
then choose the number of days to keep faxes.</li>
<li>Select the Archives tab and then check Archive All Faxes to This Folder.</li>
<li>Browse to the location that should be used to store archived faxes. The default is<br />
C:ProgramDataMicrosoftWindows NTMSFax.</li>
<li>To allow faxes to be reassigned, select the Accounts tab and then check the On box<br />
under Reassign Settings.</li>
<li> Click OK.</li>
</ul>
<h2>Defining a Dialing Rule</h2>
<p>Setting up dialing rules will help the fax server understand what your area requires. For<br />
example, most locations in the United States require dialing a 1 before dialing a number<br />
outside a local area code. When dialing within an area code, only 7 digits are needed.<br />
Alternatively, if a local area uses 10-digit dialing, a user has to put in an area code plus the<br />
7-digit phone number. As you can see, by setting up the dialing rules first, you keep your<br />
users from having to enter numbers such as 1 before the area code.You can configure the<br />
following options for dialing rules:<br />
<strong>Dialed Number</strong> You can enter a region code and area code.<br />
<strong>Target Device</strong> Choose to apply your rule to devices.</p>
<h2>Configuring a Dialing Rule</h2>
<ul>
<li>Under Fax Server in Server Manager, expand Outgoing Routing.</li>
<li>Right-click on Rules and choose New and then Rule.</li>
<li>In the Dialed Number section of the Add New Rule dialog box, enter your region<br />
code. If you are unsure, click Select and then choose from the list.</li>
<li>In the Target Device section, choose whether you want this rule to apply to a device<br />
or a routing group and then choose from the list in the drop-down box.</li>
<li>Click OK.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/12/configure-fax-windows-server-2008.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Manual Remove of  Winspywareprotectscan.exe</title>
		<link>http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html</link>
		<comments>http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html#comments</comments>
		<pubDate>Wed, 16 Jul 2008 08:58:22 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Malicious Software]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Adsl Software]]></category>
		<category><![CDATA[Amp]]></category>
		<category><![CDATA[Anti Spyware]]></category>
		<category><![CDATA[Balloon]]></category>
		<category><![CDATA[Corrupt Registry]]></category>
		<category><![CDATA[Critical System]]></category>
		<category><![CDATA[Dangerous Symptoms]]></category>
		<category><![CDATA[Dlls]]></category>
		<category><![CDATA[Exe Files]]></category>
		<category><![CDATA[Limited]]></category>
		<category><![CDATA[Machine Software]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Pop]]></category>
		<category><![CDATA[Registry Entries]]></category>
		<category><![CDATA[Risk Level]]></category>
		<category><![CDATA[Software Microsoft]]></category>
		<category><![CDATA[Software Windows]]></category>
		<category><![CDATA[System Error]]></category>
		<category><![CDATA[Winspywareprotectscan.exe]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/?p=151</guid>
		<description><![CDATA[Tweet Risk Level : Very High ( Dangerous ) Symptoms Pop up balloon warning messages claiming that your PC is infected. * &#8220;Critical System Error&#8221;, * &#8220;Your computer is infected&#8221;, Search and kill the following processes * antivirus.v.1.0.0, WinSpywareProtect.EXE, WinSpywareProtectSetup.exe Remove Scan.Winspywareprotectscan.com files &#38; dlls files * antivirus.v.1.0.0, * WinSpywareProtect.EXE, * WinSpywareProtectSetup.exe Remove/Modify corrupt Registry Entries HKEY_LOCAL_MACHINESOFTWAREWinSpywareProtect HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion UninstallWinSpywareProtect HKEY_ALL_USERSSoftwareAdsl Software Limited HKEY_CLASSES_ROOTTacOnlyOne Use Shield Deluxe 2008 &#8211; Antivirus &#38; Anti-Spyware to scan yor computer for other threats]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F07%2Fmanual-remove-of-winspywareprotectscanexe.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html"  data-text="Manual Remove of  Winspywareprotectscan.exe" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>Risk Level : Very High ( Dangerous )</p>
<p>Symptoms</p>
<p>Pop up balloon warning messages claiming that your PC is infected.</p>
<p>* &#8220;Critical System Error&#8221;,<br />
* &#8220;Your computer is infected&#8221;,</p>
<p>Search and kill the following processes</p>
<p>* antivirus.v.1.0.0, WinSpywareProtect.EXE, WinSpywareProtectSetup.exe</p>
<p>Remove Scan.Winspywareprotectscan.com files &amp; dlls files</p>
<p>* antivirus.v.1.0.0,<br />
* WinSpywareProtect.EXE,<br />
* WinSpywareProtectSetup.exe</p>
<p>Remove/Modify corrupt Registry Entries</p>
<p>HKEY_LOCAL_MACHINESOFTWAREWinSpywareProtect<br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion<br />
UninstallWinSpywareProtect<br />
HKEY_ALL_USERSSoftwareAdsl Software Limited<br />
HKEY_CLASSES_ROOTTacOnlyOne</p>
<p>Use Shield Deluxe 2008 &#8211; Antivirus &amp; Anti-Spyware to scan yor computer for other threats</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/07/manual-remove-of-winspywareprotectscanexe.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Virusheat.com trojan</title>
		<link>http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html</link>
		<comments>http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html#comments</comments>
		<pubDate>Sun, 17 Feb 2008 16:37:00 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Malicious Software]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Annoying Pop]]></category>
		<category><![CDATA[C Program]]></category>
		<category><![CDATA[Computer Virus]]></category>
		<category><![CDATA[Delete]]></category>
		<category><![CDATA[Dll]]></category>
		<category><![CDATA[Hkey Local Machine]]></category>
		<category><![CDATA[Hkey Local Machine Software]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Program Files Folder]]></category>
		<category><![CDATA[Remove Trojan]]></category>
		<category><![CDATA[Remove Virus]]></category>
		<category><![CDATA[Safe Mode]]></category>
		<category><![CDATA[Software Microsoft]]></category>
		<category><![CDATA[Stop Virus]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Trojan Virus]]></category>
		<category><![CDATA[Trojan Win32]]></category>
		<category><![CDATA[Uninstall]]></category>
		<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[Witch]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan/</guid>
		<description><![CDATA[Tweet Virus Heat is a Trojan.Win32 . More or less, it does degrade performance of computers and generate annoying pop up witch send you to virusheat.com. Virus Heat Manual Removal Process: 1. Go to Control Panel &#62;Add or Remove Programs and uninstall Virus Heat 2. Close all programs. 3. Go to &#62;Start&#62;Run &#62;regedit find and delete key “HKEY_LOCAL_MACHINESOFTWAREMicrosoft WindowsCurrentVersionUninstallVirus Heat” 4. Restart the computer. 5. Stop Virus Heat process 6. Find and delete the following infected files from your system. Don’t worry if you don’t find these files. Just proceed to next step. Virus Heat 3.9.exe, wuuawkz.dll , iinqyl.dll 7. Go to C:Program Files folder and delete the “Virus Heat” folder (if you can’t delete it, reboot your computer to safe mode then delete the folder. 8. After all steps go to http://siri.geekstogo.com/SmitfraudFix.php and download last version of Smitfraudfix.exe 9. Reboot the computer in safe mode and run the utility.]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F02%2Fremove-virusheatcom-trojan.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html"  data-text="Remove Virusheat.com trojan" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><span style="font-size:85%;"><strong>Virus Heat</strong> is a <strong>Trojan.Win32</strong> . More or less, it does degrade performance of computers and generate annoying pop up witch send you to virusheat.com. </span></p>
<p><span style="font-size:85%;"><strong>Virus Heat Manual Removal Process:</strong> </span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">1.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Go to </span> <span style=";font-size:85%;"> </span> <span style="font-size:85%;">Control Panel &gt;Add or Remove Programs and uninstall Virus Heat</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">2.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Close all programs.</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">3.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Go to &gt;Start&gt;Run &gt;regedit find and delete key</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><span style="font-size:85%;">“HKEY_LOCAL_MACHINESOFTWAREMicrosoft</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><span style="font-size:85%;">WindowsCurrentVersionUninstallVirus Heat” </span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">4.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Restart the computer.</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">5.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Stop Virus Heat process</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">6.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Find and delete the following infected files from your system. Don’t worry if you don’t find these files. Just proceed to next step.</span> <span style=";font-size:85%;"> </span> <span style="font-size: 85%; color: red;">Virus Heat 3.9.exe, wuuawkz.dll , iinqyl.dll</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">7.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">Go to C:Program Files folder and delete the “Virus Heat” folder (if you can’t delete it, reboot your computer to safe mode then delete the folder.</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">8.<span> </span> </span> <!-- [endif]--><span style="font-size:85%;">After all steps go to <a href="http://siri.geekstogo.com/SmitfraudFix.php">http://siri.geekstogo.com/SmitfraudFix.php</a> and download last version of </span> <span style=";font-size:85%;">Smitfraudfix.exe</span></p>
<p style="margin-left: 0.5in; text-indent: -0.25in;"><!-- [if !supportLists]--><span style=";font-size:85%;">9.<span> </span> </span> <!-- [endif]--><span style=";font-size:85%;">Reboot the computer in safe mode and run the utility.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/02/remove-virusheatcom-trojan.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys</title>
		<link>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html</link>
		<comments>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html#comments</comments>
		<pubDate>Sat, 09 Feb 2008 19:53:00 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Malicious Software]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Anti Virus]]></category>
		<category><![CDATA[Antivirus Software]]></category>
		<category><![CDATA[Bagle Virus]]></category>
		<category><![CDATA[Current User]]></category>
		<category><![CDATA[Hldrrr]]></category>
		<category><![CDATA[hldrrr.exe]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Panda]]></category>
		<category><![CDATA[Program Download]]></category>
		<category><![CDATA[Safe Mode]]></category>
		<category><![CDATA[Scanner]]></category>
		<category><![CDATA[Service Pack]]></category>
		<category><![CDATA[Software Microsoft]]></category>
		<category><![CDATA[srosa.sys]]></category>
		<category><![CDATA[Sys]]></category>
		<category><![CDATA[User Software]]></category>
		<category><![CDATA[Virus Download]]></category>
		<category><![CDATA[Virus Exe]]></category>
		<category><![CDATA[Virus Program]]></category>
		<category><![CDATA[Virus Updates]]></category>
		<category><![CDATA[W32 Virus]]></category>
		<category><![CDATA[W32.BAGLE]]></category>
		<category><![CDATA[wintems.exe]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/2008/02/wintemsexe-hldrrrexe-srosasys/</guid>
		<description><![CDATA[Tweet W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys I must say that with all my of experience that one was one of the hardest to remove .. It disables your current antivirus software, prohibit you from accessing system in safe mode , and changes names each time it starts. So.. Here are the steps Go to http://www.majorgeeks.com/GMER_d5198.html and download GMER Run the tool and when it finds wintems.exe process kill him.. Run regedit go to HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache and see all entries regarding &#8220;C:WINDOWSsystem32drivers&#8221; . In Explorer window Go to&#62; tools&#62;folder options&#62;view and select show hidden files Browse to your C:WINDOWSsystem32drivers .. find drivers folder and try to delete all files listed in HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache Scan your system with panda online scanner (the only one that actually cleans , not only detects Install anti virus program, download last updates and do a full scan to your system Of course there is always an option to reapply service pack or do a reinstall to your system. The problem is solved ! Thanks to Eran Amir]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F02%2Fwintermsexe-hldrrrexe.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html"  data-text="W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>W32.BAGLE virus &#8211; wintems.exe hldrrr.exe srosa.sys</p>
<p>I must say that with all my  of experience that one was one of the hardest to remove ..<br />
It disables your current antivirus software, prohibit you from accessing system in safe mode , and changes names each time it starts.</p>
<p>So.. Here are the steps</p>
<p>Go to http://www.majorgeeks.com/GMER_d5198.html and download GMER<br />
Run the tool and when it finds wintems.exe process kill him..</p>
<ol>
<li>Run regedit go to HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache and see  all entries regarding &#8220;C:WINDOWSsystem32drivers&#8221; .</li>
<li>In Explorer window Go to&gt; tools&gt;folder options&gt;view and select show hidden files</li>
<li>Browse to your C:WINDOWSsystem32drivers ..  find drivers folder and try to delete all files listed   in HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache</li>
<li>Scan your system with panda online scanner (the only one that actually cleans , not only detects</li>
<li>Install anti virus program, download last updates and do a full scan to your system</li>
</ol>
<p>Of course there is always an option to reapply service pack or do a reinstall to your system.</p>
<p>The problem is solved !</p>
<p>Thanks to Eran Amir</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/02/wintermsexe-hldrrrexe.html/feed</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
	</channel>
</rss>

