<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-37837615</atom:id><lastBuildDate>Wed, 15 Mar 2023 21:57:13 +0000</lastBuildDate><title>how to remove virus from your computer</title><description></description><link>http://antivirustube.blogspot.com/</link><managingEditor>noreply@blogger.com (antivirus)</managingEditor><generator>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink="false">tag:blogger.com,1999:blog-37837615.post-116583982303231756</guid><pubDate>Mon, 11 Dec 2006 12:01:00 +0000</pubDate><atom:updated>2006-12-11T04:23:43.046-08:00</atom:updated><title>AntiVirus - Trojan horse IRC/BackDoor.SdBot2.MLV</title><description>Logfile of HijackThis v1.99.1&lt;br /&gt;Scan saved at 12:49:02 PM, on 12/4/2006&lt;br /&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;c:\windows\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\System32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;c:\windows\system32\Ati2evxx.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe&lt;br /&gt;C:\WINDOWS\system32\Rundll32.exe&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\cli.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe&lt;br /&gt;C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe&lt;br /&gt;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&lt;br /&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;br /&gt;C:\Program Files\D-Tools\daemon.exe&lt;br /&gt;C:\Program Files\UltraMon\UltraMon.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe&lt;br /&gt;C:\Program Files\UltraMon\UltraMonTaskbar.exe&lt;br /&gt;C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe&lt;br /&gt;C:\WINDOWS\System32\drivers\CDAC11BA.EXE&lt;br /&gt;C:\WINDOWS\System32\CTsvcCDA.exe&lt;br /&gt;C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe&lt;br /&gt;C:\Program Files\CyberLink\Shared files\RichVideo.exe&lt;br /&gt;C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\cli.exe&lt;br /&gt;C:\Program Files\ATI Technologies\ATI.ACE\cli.exe&lt;br /&gt;C:\Program Files\MSN Messenger\msnmsgr.exe&lt;br /&gt;C:\Program Files\AutoCAD 2004\acad.exe&lt;br /&gt;C:\DOCUME~1\Guggles\LOCALS~1\Temp\~e5d141.tmp&lt;br /&gt;C:\Program Files\Common Files\Autodesk Shared\WSCommCntr1.exe&lt;br /&gt;C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe&lt;br /&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Launchin\HijackThis.exe&lt;br /&gt;&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =&lt;br /&gt;&lt;br /&gt;127.0.0.1&lt;br /&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program&lt;br /&gt;&lt;br /&gt;Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: Alcohol Toolbar Helper - {0ACF00E0-C1E4-4F6B-B290-10AC7505C47A} - C:\Program&lt;br /&gt;&lt;br /&gt;Files\Alcohol Toolbar\v3.0.0.0\AudioGizmo_Toolbar.dll&lt;br /&gt;O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -&lt;br /&gt;&lt;br /&gt;C:\PROGRA~1\SPYBOT~1\SDHelper.dll&lt;br /&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program&lt;br /&gt;&lt;br /&gt;files\google\googletoolbar2.dll&lt;br /&gt;O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} -&lt;br /&gt;&lt;br /&gt;C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll&lt;br /&gt;O2 - BHO: (no name) - {B530D98C-7F26-427E-85F8-57FFFCBC6DBE} - C:\WINDOWS\system32\vturq.dll&lt;br /&gt;&lt;br /&gt;(file missing)&lt;br /&gt;O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program&lt;br /&gt;&lt;br /&gt;Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll&lt;br /&gt;O3 - Toolbar: Alcohol Toolbar - {DC59A0D4-0ED6-4A73-B356-1B977F2A7725} - C:\Program&lt;br /&gt;&lt;br /&gt;Files\Alcohol Toolbar\v3.0.0.0\AudioGizmo_Toolbar.dll&lt;br /&gt;O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program&lt;br /&gt;&lt;br /&gt;files\google\googletoolbar2.dll&lt;br /&gt;O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy LS\Surround&lt;br /&gt;&lt;br /&gt;Mixer\CTSysVol.exe /r&lt;br /&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;br /&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;br /&gt;O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper&lt;br /&gt;O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP&lt;br /&gt;O4 - HKLM\..\Run: [ATICCC] &quot;C:\Program Files\ATI Technologies\ATI.ACE\cli.exe&quot; runtime&lt;br /&gt;&lt;br /&gt;-Delay&lt;br /&gt;O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI&lt;br /&gt;&lt;br /&gt;HYDRAVISION\HydraDM.exe&lt;br /&gt;O4 - HKLM\..\Run: [SSBkgdUpdate] &quot;C:\Program Files\Common Files\Scansoft&lt;br /&gt;&lt;br /&gt;Shared\SSBkgdUpdate\SSBkgdupdate.exe&quot; -Embedding -boot&lt;br /&gt;O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe&lt;br /&gt;O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [Acrobat Assistant 7.0] &quot;C:\Program Files\Adobe\Acrobat&lt;br /&gt;&lt;br /&gt;7.0\Distillr\Acrotray.exe&quot;&lt;br /&gt;O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;&lt;br /&gt;&lt;br /&gt;-osboot&lt;br /&gt;O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k&lt;br /&gt;O4 - HKLM\..\Run: [LanguageShortcut] &quot;C:\Program&lt;br /&gt;&lt;br /&gt;Files\CyberLink\PowerDVD\Language\Language.exe&quot;&lt;br /&gt;O4 - HKLM\..\Run: [DAEMON Tools-1033] &quot;C:\Program Files\D-Tools\daemon.exe&quot; -lang 1033&lt;br /&gt;O4 - HKLM\..\Run: [UltraMon] &quot;C:\Program Files\UltraMon\UltraMon.exe&quot; /auto&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [Toronto Star Alerts] &quot;C:\Program Files\Toronto Star&lt;br /&gt;&lt;br /&gt;Alerts\torontostaralerts.exe&quot;&lt;br /&gt;O4 - HKCU\..\Run: [swg] C:\Program&lt;br /&gt;&lt;br /&gt;Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe&lt;br /&gt;O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?&lt;br /&gt;O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common&lt;br /&gt;&lt;br /&gt;Files\Autodesk Shared\acstart16.exe&lt;br /&gt;O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program&lt;br /&gt;&lt;br /&gt;Files\InterVideo\Common\Bin\WinCinemaMgr.exe&lt;br /&gt;O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program&lt;br /&gt;&lt;br /&gt;Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program&lt;br /&gt;&lt;br /&gt;Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program&lt;br /&gt;&lt;br /&gt;Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html&lt;br /&gt;O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program&lt;br /&gt;&lt;br /&gt;Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html&lt;br /&gt;O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program&lt;br /&gt;&lt;br /&gt;Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program&lt;br /&gt;&lt;br /&gt;Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat&lt;br /&gt;&lt;br /&gt;7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;br /&gt;O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat&lt;br /&gt;&lt;br /&gt;7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel -&lt;br /&gt;&lt;br /&gt;res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000&lt;br /&gt;O8 - Extra context menu item: Open Client to monitor &amp;1 - C:\WINDOWS\web\AOpenClient.htm&lt;br /&gt;O8 - Extra context menu item: Open Client to monitor &amp;amp;2 - C:\WINDOWS\web\AOpenClient.htm&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program&lt;br /&gt;&lt;br /&gt;Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &#39;Tools&#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -&lt;br /&gt;&lt;br /&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -&lt;br /&gt;&lt;br /&gt;http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab&lt;br /&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -&lt;br /&gt;&lt;br /&gt;http://spaces.msn.com/PhotoUpload/MsnPUpld.cab?10,0,911,0&lt;br /&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -&lt;br /&gt;&lt;br /&gt;http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147980&lt;br /&gt;&lt;br /&gt;428421&lt;br /&gt;O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -&lt;br /&gt;&lt;br /&gt;http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab&lt;br /&gt;O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -&lt;br /&gt;&lt;br /&gt;http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab&lt;br /&gt;O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) -&lt;br /&gt;&lt;br /&gt;http://messenger.zone.msn.com/binary/WoF.cab31267.cab&lt;br /&gt;O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} -&lt;br /&gt;&lt;br /&gt;&quot;C:\PROGRA~1\MSNMES~1\msgrapp.dll&quot; (file missing)&lt;br /&gt;O20 - Winlogon Notify: vturq - C:\WINDOWS\system32\vturq.dll (file missing)&lt;br /&gt;O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll&lt;br /&gt;O20 - Winlogon Notify: winjjq32 - winjjq32.dll (file missing)&lt;br /&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -&lt;br /&gt;&lt;br /&gt;C:\WINDOWS\system32\WPDShServiceObj.dll&lt;br /&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe&lt;br /&gt;&lt;br /&gt;Systems Shared\Service\Adobelmsvc.exe&lt;br /&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe&lt;br /&gt;O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe&lt;br /&gt;O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common&lt;br /&gt;&lt;br /&gt;Files\Autodesk Shared\Service\AdskScSrv.exe&lt;br /&gt;O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -&lt;br /&gt;&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe&lt;br /&gt;O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -&lt;br /&gt;&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe&lt;br /&gt;O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. -&lt;br /&gt;&lt;br /&gt;C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe&lt;br /&gt;O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE&lt;br /&gt;O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -&lt;br /&gt;&lt;br /&gt;C:\WINDOWS\System32\CTsvcCDA.exe&lt;br /&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program&lt;br /&gt;&lt;br /&gt;Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: iPodService - Apple Computer, Inc. - C:\Program&lt;br /&gt;&lt;br /&gt;Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program&lt;br /&gt;&lt;br /&gt;Files\CyberLink\Shared files\RichVideo.exe&lt;br /&gt;O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program&lt;br /&gt;&lt;br /&gt;Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcDataSrv.exe&lt;br /&gt;O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program&lt;br /&gt;&lt;br /&gt;Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcSandraSrv.exe&lt;br /&gt;O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software -&lt;br /&gt;&lt;br /&gt;C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe</description><link>http://antivirustube.blogspot.com/2006/12/antivirus-trojan-horse.html</link><author>noreply@blogger.com (Anonymous)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-37837615.post-116583825101210372</guid><pubDate>Mon, 11 Dec 2006 11:14:00 +0000</pubDate><atom:updated>2006-12-11T03:57:31.253-08:00</atom:updated><title>Antivirus Tube - Remove Registry Virus !!!</title><description>&lt;div align=&quot;justify&quot;&gt;If your anti-virus software warns you of  a &quot;malicious&quot; script, this is normal if you have &quot;Script Safe&quot; or similar technology enabled.  These scripts are not malicious, but they do make changes to the System Registry.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt; &lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;please Visit On :&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt; &lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;a href=&quot;http://www.kellys-korner-xp.com/xp_tweaks.htm&quot;&gt;http://www.kellys-korner-xp.com/xp_tweaks.htm&lt;/a&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt; &lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;or &lt;/div&gt;&lt;div align=&quot;justify&quot;&gt; &lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Download &lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;a href=&quot;http://www.killbox.net/downloads/KillBox.exe&quot;&gt;http://www.killbox.net/downloads/KillBox.exe&lt;/a&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt; &lt;/div&gt;&lt;div align=&quot;left&quot;&gt;Click Killbox.exe.Select the option &quot;Delete on reboot&quot; and &quot;unregister dll&#39;s before deleting&quot;.Click the button: All Files (Important!)Now it should flash green.&lt;br /&gt;Now copy the next bold part:&lt;br /&gt;&lt;br /&gt;C:\WINDOWS\system32\winmgd.win&lt;br /&gt;&lt;br /&gt;Open &#39;file&#39; in the killboxmenu on top and choose &quot;Paste from clipboard&quot;&lt;br /&gt;Then press the button that looks like a red circle with a white X in it.Killbox will tell you that all listed files will be removed on next reboot and asks if you would like to Reboot now, click YES.&lt;br /&gt;&lt;br /&gt;Please re-open HijackThis, close all browser windows other than HijackThis, check these entries, and click FIX.&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href=&quot;http://us9.hpwis.com/&quot; target=&quot;_blank&quot;&gt;http://us9.hpwis.com/&lt;/a&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href=&quot;http://srch-us9.hpwis.com/&quot; target=&quot;_blank&quot;&gt;http://srch-us9.hpwis.com/&lt;/a&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;a href=&quot;http://srch-us9.hpwis.com/&quot; target=&quot;_blank&quot;&gt;http://srch-us9.hpwis.com/&lt;/a&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href=&quot;http://srch-us9.hpwis.com/&quot; target=&quot;_blank&quot;&gt;http://srch-us9.hpwis.com/&lt;/a&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;a href=&quot;http://srch-us9.hpwis.com/&quot; target=&quot;_blank&quot;&gt;http://srch-us9.hpwis.com/&lt;/a&gt;F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\winmgd.winO2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1&lt;br /&gt;&lt;br /&gt;Close HijackThis.&lt;br /&gt;&lt;br /&gt;Boot into safe mode (you can do this by switching off your machine and continually tap the F8 key at first blank screen)&lt;br /&gt;&lt;br /&gt;Please navigate to this file C:\WINDOWS\system32\winmgd.win&lt;br /&gt;Right click winmgd.win and delete.&lt;br /&gt;&lt;br /&gt;Boot to normal windows.&lt;br /&gt;&lt;br /&gt;Please download Ewido Anti-Spyware and save that file to your desktop.&lt;br /&gt;&lt;a href=&quot;http://www.ewido.net/en/download/&quot; target=&quot;_blank&quot;&gt;http://www.ewido.net/en/download/&lt;/a&gt;&lt;br /&gt;This is a 30 day trial of the program&lt;br /&gt;&lt;br /&gt;1. Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.2. Once the setup is complete you will need run ewido and update the definition files.3. On the main screen select the icon &quot; Update &quot; then select the &quot; Update now &quot; link.4. Next select the &quot; Start update &quot; button, the update will start and a progress bar will show the updates being installed.&lt;br /&gt;5. Once the update has completed select the &quot; Scanner &quot; icon at the top of the screen, then select the &quot; Settings &quot; tab.6. Once in the Settings screen click on &quot; Recommended actions &quot; and then select &quot; Quarantine &quot;.7. Under &quot; Reports &quot;8. Select &quot; Automatically generate report after every scan &quot;9. UnSelect &quot; Only if threats were found &quot;&lt;br /&gt;Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.10. Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.&lt;br /&gt;&lt;br /&gt;IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:&lt;br /&gt;&lt;br /&gt;1. Lauch ewido-anti-spyware by double-clicking the icon on your desktop.2. Select the &quot;Scanner&quot; icon at the top and then the &quot;Scan&quot; tab then click on &quot;Complete System Scan&quot;.&lt;br /&gt;&lt;br /&gt;Ewido will now begin the scanning process, be patient this may take a little time.&lt;br /&gt;Once the scan is complete do the following:&lt;br /&gt;&lt;br /&gt;* If you have any infections you will prompted, then select &quot;Apply all actions&quot;* Next select the &quot;Reports&quot; icon at the top.* Select the &quot;Save report as&quot; button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).* Close ewido and reboot your system back into Normal Mode.&lt;br /&gt;&lt;br /&gt;ENABLE TASK MANAGER&lt;br /&gt;&lt;br /&gt;Download to desktop- enable the taskmanager - line 51 -right&lt;a href=&quot;http://www.kellys-korner-xp.com/xp_tweaks.htm&quot; target=&quot;_blank&quot;&gt;http://www.kellys-korner-xp.com/xp_tweaks.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Doubleclick on  taskmanager reg file, say yes to mergeReboot and see if taskmanager is back to normal behaviour.&lt;br /&gt;&lt;br /&gt;ENABLE REGEDIT&lt;br /&gt;&lt;br /&gt;Open Notepad pad, copy paste the following text to the note pad REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio n\Policies\System] &quot;DisableRegistryTools&quot;=dword:00000000 Save the text file as enable.reg After that double click enable.reg to merge to registry.&lt;br /&gt;&lt;br /&gt;Please post the Ewido logfile, and a fresh HijackThis logfile.&lt;br /&gt;Has Task Manager and Regedit come back to normal??&lt;/div&gt;</description><link>http://antivirustube.blogspot.com/2006/12/antivirus-tube-remove-registry-virus.html</link><author>noreply@blogger.com (Anonymous)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-37837615.post-116489785852543829</guid><pubDate>Thu, 30 Nov 2006 14:26:00 +0000</pubDate><atom:updated>2006-11-30T06:45:41.610-08:00</atom:updated><title>AntiVirus Tube - How to Remove W32.Myzor.FK@yf</title><description>&lt;div align=&quot;justify&quot;&gt;How you can remove the &lt;a href=&quot;mailto:W32.Myzor.FK@yf&quot;&gt;W32.Myzor.FK@yf&lt;/a&gt; from your computer ?&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;its time you fix the problem with this virus, W32.Myzor.FK@yf is a part of another rogue AntiSpyware program that send alarm to user about a possible threat on his computer and advise to buy the full version of the AntiSpyware to be able to clean the infection. It will redirect homepage of compromised computer to Security Center or Internet Security titled websites.&lt;/div&gt;&lt;p align=&quot;center&quot;&gt;&lt;a href=&quot;http://photos1.blogger.com/x/blogger/916/4074/1600/730674/myzorsite.gif&quot;&gt;&lt;img style=&quot;CURSOR: hand&quot; alt=&quot;&quot; src=&quot;http://photos1.blogger.com/x/blogger/916/4074/320/184598/myzorsite.png&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div align=&quot;justify&quot;&gt;&lt;/div&gt;&lt;div align=&quot;center&quot;&gt;&lt;a href=&quot;http://photos1.blogger.com/x/blogger/916/4074/1600/966032/myzorsite.gif&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://photos1.blogger.com/x/blogger/916/4074/1600/966032/myzorsite.gif&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://photos1.blogger.com/x/blogger/916/4074/1600/966032/myzorsite.gif&quot;&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;/div&gt;&lt;div align=&quot;center&quot;&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;a href=&quot;mailto:W32.Myzor.FK@yf&quot;&gt;W32.Myzor.FK@yf&lt;/a&gt; is Worm Virus, and Risk Level is Medium.&lt;a href=&quot;mailto:Medium.32.Myzor.FK@yf&quot;&gt;mailto:Medium.32.Myzor.FK@yf&lt;/a&gt; always Displays a pop-up &lt;a href=&quot;mailto:W32.Myzor.FK@yf&quot;&gt;warning. &lt;/a&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;/div&gt;&lt;strong&gt;&lt;em&gt;&lt;blockquote&gt;&lt;p align=&quot;justify&quot;&gt;&lt;strong&gt;&lt;em&gt;&lt;span style=&quot;color:#ff0000;&quot;&gt;W32.Myzor.FK@yf is a virus that infects files with .exe extentions. It attempts to steal passwords and private information from the infected&lt;br /&gt;computer.&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/em&gt;&lt;/strong&gt;&lt;div align=&quot;justify&quot;&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;/div&gt;&lt;p align=&quot;center&quot;&gt;&lt;a href=&quot;http://photos1.blogger.com/x/blogger/916/4074/1600/190676/myzorpopup.gif&quot;&gt;&lt;img style=&quot;CURSOR: hand&quot; alt=&quot;&quot; src=&quot;http://photos1.blogger.com/x/blogger/916/4074/320/246618/myzorpopup.png&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div align=&quot;justify&quot;&gt;and HOw to remove ? Folow This Way.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;MANUAL REMOVAL:&lt;br /&gt;1. Disable System Restore (Windows Me/XP). &lt;a class=&quot;commlnks&quot; href=&quot;http://www.precisesecurity.com/how-to/ht-srxp.htm&quot; target=&quot;_blank&quot;&gt;[how to]&lt;/a&gt;&lt;br /&gt;2. Download &lt;a class=&quot;commonlink&quot; href=&quot;http://www.download.com/Webroot-Spy-Sweeper/3000-8022_4-10192729.html&quot; target=&quot;_blank&quot;&gt;Webroot SpySweeper&lt;/a&gt; and save it to a desired location.&lt;br /&gt;Note: This is a trial working version. It can clean infections for a given period only. You can also use &lt;a class=&quot;commonlink&quot; href=&quot;http://www.precisesecurity.com/anti-spyware/as-ewf.htm&quot; target=&quot;_blank&quot;&gt;Free Ewido Anti-Spyware&lt;/a&gt; which is a Freeware for home users.)&lt;br /&gt;&lt;br /&gt;3. After downloading, browse where the file was saved and double click to install it.&lt;br /&gt;4. After installation, connect to internet and download all necessary updates.&lt;br /&gt;&lt;br /&gt;5. Download &lt;a class=&quot;commonlink&quot; href=&quot;http://siri.urz.free.fr/Fix/SmitfraudFix.zip&quot; target=&quot;_blank&quot;&gt;SmitfraudFix&lt;/a&gt; (by S!Ri) and save it to a desired location. This will be in ZIP File.&lt;br /&gt;6. Extract all the files to your Desktop, it will create a folder SmitfraudFix&lt;br /&gt;Note: When extracting or executing, some files might be detected as Potential Threat or Harmful Script. Please disable AntiVirus or Any Script Blocking Software temporarily. It may harm or make the Fix incomplete.&lt;br /&gt;&lt;br /&gt;7. Reboot your computer in SafeMode &lt;a class=&quot;commlnks&quot; href=&quot;http://www.precisesecurity.com/how-to/ht-smode.htm&quot; target=&quot;_blank&quot;&gt;[how to]&lt;/a&gt;&lt;br /&gt;8. Run Spysweeper and do a thorough scan. Delete all infected files.&lt;br /&gt;9. Close SpySweeper and other open Applications.&lt;br /&gt;10. Browse the folder SmitfraudFix on your Desktop and double-click on smitfraudfix.cmd&lt;br /&gt;11. &quot;Enter your Choice: (1,2,3,4,L,Q):&quot; Press no. 2 on your keyboard to select Option 2&lt;br /&gt;12. Wait for the process to finish.&lt;br /&gt;13. If prompted for: Registry cleaning - Do you want to clean the registry? Press Y, as Yes&lt;br /&gt;14. It will check if your wininet.dll file is damaged, if so it will ask you to Replace Infected File? Press Y as Yes and hit Enter&lt;br /&gt;15. If it prompts you to Reboot your computer, Please do so.&lt;br /&gt;16. Reboot your computer in SafeMode with Networking &lt;a class=&quot;commlnks&quot; href=&quot;http://www.precisesecurity.com/how-to/ht-smodewnet.htm&quot; target=&quot;_blank&quot;&gt;[how to]&lt;/a&gt;&lt;br /&gt;17. After successful boot in SafeMode with Networking, connect to internet.&lt;br /&gt;&lt;br /&gt;18. In order to make sure that W32.Myzor.Fk is completely eliminated from your computer, carry out a full scan of your computer using &lt;a class=&quot;commonlink&quot; href=&quot;http://www.precisesecurity.com/antivirus/online-scan.htm&quot;&gt;Online Virus Scanner.&lt;/a&gt; Scan at least on three different scanners.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Sources : http://www.precisesecurity.com/computer-virus/avmyzor-may01.htm&lt;/div&gt;</description><link>http://antivirustube.blogspot.com/2006/11/antivirus-tube-how-to-remove.html</link><author>noreply@blogger.com (Anonymous)</author><thr:total>0</thr:total></item></channel></rss>