<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2titles.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemtitles.css"?><!-- generator="Joomla! 1.5 - Open Source Content Management" --><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
	<channel>
		<title>How to remove</title>
		<description>Virus removal instructions, free software, computer troubleshooting</description>
		<link>http://comprolive.com/remove/component/content/frontpage</link>
		<lastBuildDate>Fri, 24 Feb 2012 06:14:50 +0000</lastBuildDate>
		<generator>Joomla! 1.5 - Open Source Content Management</generator>
		<language>en-gb</language>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/removalguides" /><feedburner:info uri="removalguides" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>removalguides</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/removalguides" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsalloy.com/?rss=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.newsalloy.com/subrss3.gif">Subscribe with NewsAlloy</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://download.attensa.com/app/get_attensa.html?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.attensa.com/blogs/attensa/WindowsLiveWriter/BadgeredintoBadges_10C02/attensa_feed_button5.gif">Subscribe with Attensa for Outlook</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.flurry.com/pushRssFeed.do?r=fb&amp;url=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.flurry.com/images/flurry_rss_logo2.gif">Subscribe with Flurry</feedburner:feedFlare><feedburner:feedFlare href="http://www.wikio.com/subscribe?url=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Ffeeds.feedburner.com%2Fremovalguides" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><feedburner:browserFriendly>Latest removal guide from Comprolive.com</feedburner:browserFriendly><item>
			<title>system32\System32\explorer.exe</title>
			<link>http://feedproxy.google.com/~r/removalguides/~3/uUp9VAlTP-k/system32-system32-explorer-exe</link>
			<description>&lt;p&gt;Suspicious file named C:\windows\system32\System32\explorer.exe has  appeared in a             virus analysis report. You  can see it  &lt;a href="http://www.threatexpert.com/report.aspx?md5=50fb0de4336282dd951629b53b096ef2" target="_blank" title="report"&gt;on this link&lt;/a&gt;&lt;/p&gt;&lt;p&gt;It creates a malicious folder C:\windows\system32\System32\ . And the file explorer.exe is the name of a legitimate process of windows explorer located at C:\windows\explorer.exe &lt;/p&gt;&lt;ul&gt;&lt;li&gt;The                                                                                                                                                                                                                                                                                                                                                                                    installer                 of                  this      virus           is               of                                                                                                                                                                                            about  168 KB.      It is not yet detected    by                                       any antivirus                        program&lt;/li&gt;&lt;li&gt;It creates registry entries so that C:\windows\system32\System32\explorer.exe run at startup&lt;/li&gt;&lt;li&gt; It connects to suspicious IP address in the US and starts outbound traffic on port 50100&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;     It creates                                                                                                                    fake explorer.exe                        and                                                         other                                  files                   on                                                                                                                                           the                                                                                                                                         infected                                                                                                                                                                                                                                                              computer                                                                             that                                         you                                                                                                    need                        to                                                                                        search                                                                                                 and                                                                        delete.                                           You                                                                                                                                                                                   should                                                                                  end                                                                                                                                                                  running                                                                                                                                                                               processes                                                                     named                                                                                                                                           fake explorer.exe                                          from                                                                                    Task                                                                                                                                                                       Manager.                                                  And                                                                                                                           also                                                                                                                                                        remove                                                                                                           the                                                file's                                                                                                                                                               entries                                            from                                                                                                                                                                    windows                                                                                     startup.&lt;/p&gt;&lt;p&gt;Warning:                                                                                                                                                                                                                                                                                                                              It                                                 is                                                             possible                                 that          some                                                                              legitimate                                                                            software                                     may                     be                                                                                   using                         the                                                    same                                                                                                                       file                                                          names                                       as                            that                of            the                                              virus                                                                 files.                                                  You                                      do                     not                                                       have                                              to                                                                                    delete                                                     these                                              files                                               if                                                  they                                             belong                                                to                                       some                                                                                                     legitimate                                                                 program                                                                                                      installed                       on                                                                your                                                                                                computer.                                                                                   Use                                                              Windows                                                          Defender                                    or                                                                                               SysInternals                                                                                      Process                                                                                                                           Explorer             to                                                                                                                                                                 differentiate                                       between                                                                                       them.                                               The                                                                                                                                      information             in                         this                                                                                  article                             is                                                                                                                          presented                                                       without                                                                                                                     making                 any                                           claims                                                                                          regarding                                                          its                                                                                                  usefulness         or                                                                                                                                                           otherwise.               If                             you                         have                                any                                                             objections                               or                                                               questions,                                                      please                                                  send          a                                    note            by                                                                                                                                                  adding   a                                                                                                comment                  at                                     the                                 end                        of                                                       this                               page,                or                                         mail                       on                                                                                                                                                                                                                                                                                                             support(at)comprolive.com    &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Preventive measures&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;                                                                                                                                                                                                     Most        of               the                                                        viruses                                     enter                           your                                                                                                                                  computer                                                             when                             you                                                        visit                                                      some                                                             harmful                                                                                        website.                                                          If                               you                                      use     a                                                                                                browser                                                                              plugin                                    that                                                                      warns                                                  you                                          about                                                                                                  harmful                                                                     websites,                you                                                                 can                                                                         prevent                                                                   this                                                        from                                                                                           happening.  A                                                                                                                                        popular                                                  browser                                                      plugin                                      is                                                                      called                            Web                                                   Of                                   Trust                                                                                                (WOT),                          you                                                                           can                                                                             install                   it                            from                                                       its                                                                    website   &lt;a href="http://www.mywot.com/" target="_blank" title="WOT "&gt;on this link&lt;/a&gt;. &lt;br /&gt;[ &lt;a href="http://www.youtube.com/watch?v=8DHx7wioFuM" target="_blank" title="WOT video"&gt;a video about WOT plugin &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Blocking                                                                                                                                                      Javascript       of         all             sites       by                      default             can                    help       to                               prevent                         drive              by                                              download                                infections.         You             can        use                                      Noscript                 Plugin                    for                     firefox                       as                                           explained&lt;a href="http://www.youtube.com/watch?v=IMPHD5dkCAA" target="_blank" title="Noscript video"&gt; in this video&lt;/a&gt;.                                                                                                                                                 Similar                             functionality         can       be                           achieved                  in                      Google's                                     Chromium                                        browser                               using        the                         settings           in                             Preferences                   &amp;gt;                       Under          the                         Hood            &amp;gt;                               Content                                             Settings             &amp;gt;              Java               Script                 &amp;gt;                       Select      "Do                   not                      Allow".                                   After             that            when                               you          visit  a                                  site,      you                will     see a                  pop                             up       next        to                the                     address                      bar              asking                              you            if           you                want     to                         allow                    JavaScript                 to          run                           for            that                                    particular                  site.   &lt;/li&gt;&lt;li&gt;Some                                                                                                                                                                                                                                                                         of              the                              viruses          are                                                                                downloaded                         in                                                                        Internet                                              Cache                            or          in                                             the                                                                       Temp                                                                          folder                              of                        the                                               windows.                              The                                                    viruses                                                         get                                                 activated                              when                                                               these                                                               files                                  are                                                                                          executed.                                   You                   can                                                    reduce                                         the                             risk                              of                                    virus                                                                        infection                                                 if                             you                                      empty                                                   your                                                browser                                                                                           cache      and                                                                   remove                           windows                                                            temp                                                files                                                                                                             occasionally,                                                                        ideally                          at                              the                                    end                  of                     a                                                                           browsing                                              session                                        or                                                         before                                                                            closing                        down                      your                                                                                                    computer.                                                Some                                          programs                                                                                           like                                               CCleaner                            can    be                                  set                                                    to                          do                                               these                                  things                                                                                                                                             automatically.  [&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt; a video about CCleaner &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Do                                                                                                                                                                                        not             leave            your                            computer                              infected                and                                           insecure.                  If                 you                                  doubt                                 that                                    there                          could        be                               some                        undetected                                virus          on                          your                                       computer,                                         don't                  leave                            it                          like                              that.               Format                              the            hard             disk                          and                                     reinstall                                                windows             and                  all                      other                                                     programs.                  That                     is         the                                   sure                    way       to                 clear                                               doubts.       &lt;/li&gt;&lt;/ul&gt;&lt;strong&gt; Using System Restore&lt;/strong&gt; &lt;p&gt;If                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               you                                                                                    know                            the                                                                                                       duration                                                                           since                                                                         your                                                                                                                                               computer                                       is                                                                                                                                                                                                      infected,                                       you                                                                                                                             can                                                                                    try                                      to                                                                                                                                                                                                  restore                                                       your                                                                                  computer                                            at    a                                                                                                                                                                         prior                                                 date,                                                                                    that                                                                                                                      will                                        be                                                                    an                                          easy                                                                       way                                                                                                     to                                                        undo                                                                                   the                                                                                                                                                                                   changes                             done                  by                                                                   the                                                                                                                                             virus&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Using        system   restore   in  &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-system-restore-in-xp" target="_blank" title="system restore in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using system restore                 in  &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system restore in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using          system restore in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-restore-in-windows7" target="_blank" title="System Restore in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;[ &lt;a href="http://www.youtube.com/watch?v=bhGrVLPIKXY" target="_blank" title="system restore video"&gt;Video of How to use System Restore&lt;/a&gt; ]&lt;br /&gt; &lt;p&gt;&lt;strong&gt; Boot              in safe mode&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Sometimes    you can not        delete  a      file. You should boot in safe mode and then try    to        delete it.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;How       to boot in safe in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/boot-in-safe-mode-in-xp" target="_blank" title="safe mode in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to boot in safe mode                 in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/boot-in-safe-mode-in-vista" target="_blank" title="safe mode in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to boot in safe mode in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/boot-in-safe-mode-in-windows7" target="_blank" title="safeboot in windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;  View              Hidden Files&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;You need to enable                 to view hidden files and folders before searching.&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-to-view-hidden-files-in-xp" target="_blank" title="view hidden files in xp"&gt; Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/view-hidden-files-in-vista" target="_blank" title="view hidden files in vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How         to Enable to View Hidden Files  and Folders in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/view-hidden-files-in-windows7" target="_blank" title="Enable to view hidden files in Windows7"&gt;Windows7             &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;[&lt;a href="http://www.youtube.com/watch?v=0ahhDa_bp0A" target="_blank" title="Enable Hidden Files video "&gt; Video of How to enable Hidden files and folders&lt;/a&gt; ]&lt;br /&gt; &lt;p&gt;&lt;strong&gt; Remove             Processes from &lt;span class="notranslate"&gt;Task Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt; Press              Ctrl Alt Del keys to open the &lt;span class="notranslate"&gt;Task          Manager&lt;/span&gt;.Select                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Processes                                                      tab.                                                                         You                                                                                                                     will                                              see          a                                                                                                 list.                                                                               Look                                                        for                                                                                                                                                                 the                                                                                                                                         names                                                                                                                                                                                fake explorer.exe                                                 in                                   it.                                                                                                                          Select                                    if                                                                      found                                                                                                                   and                                                                                                                                 press                                                                                                                       the                                                                                                          End                                                                                         Process                                       button.                                                                                                     It                                                    will                               ask                                                                       for                                                                                                 your                                                                                                                                                                                          confirmation                                                                                                                        to                                                                                        end                                                                                                        that                                                                                                                                  process.                                                                           Select                                                                        Yes.                                    You                                                                   can                                                                                                               end                                                                                            one                                                                                        process                                                                 at            a                                                                                                                                 time.                                                                      You                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       can                                                                                  find                                                                                                                                                                                      out                                                                   if   a                                                                                                                                                                                                                   process                                                    in              &lt;span class="notranslate"&gt;Task                       Manager&lt;/span&gt;     is      good                     or        bad  by  using  &lt;span class="notranslate"&gt;Windows                                Defender in  XP and Vista&lt;/span&gt;.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              It                                                                                                               shows                                                                                                                                                                               the                                                                                                                                                                                                                                                                                                            path                                                                                                 of                         a                                                                                                                                                                                                                                                                                                                         process                                                                                       and                                                                                                                        its                                                                                                                                                                                                                                                                                                                                                                                                       publisher.                                                                                                                                                                                        Harmful                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            processes                                                                                                                                                        may                                                                                                      be                                                                                                                                                                                                    shown                                                                                                                                                                                    under                                                                                                                                                                                                            Unknown                                                                                                                                                                                                                                                                                                                              Publisher                                                                                                   in                                                                                                                                                  &lt;span class="notranslate"&gt;windows                             defender&lt;/span&gt;.  Whereas in Windows7 you  can find that out from the task manager itself. You can watch a video on How to use &lt;a href="http://www.youtube.com/watch?v=TxE8zS9iiSI" target="_blank" title="Windows Defender video"&gt;Windows Defender&lt;/a&gt;. &lt;br /&gt;&lt;ul&gt;&lt;li&gt;How           to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-windows-defender-in-xp" target="_blank" title="windows defender in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-windows-defender-in-vista" target="_blank" title="windows defender in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to use Windows Defender in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/use-windows-defender-in-windows7" target="_blank" title="Use Windows Defender in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; Or                 you can use &lt;span class="notranslate"&gt;Sysinternal's    Process          Explorer&lt;/span&gt;. How  to use      Sysinternal's &lt;a href="http://comprolive.com:80/remove/../free/software/system-tools/process-explorer" target="_blank" title="sysinternal's process explorer"&gt;Process Explorer&lt;/a&gt;&lt;/p&gt;&lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=aD_E0q-x3ww" target="_blank" title="sysinternal's video"&gt;Video of How to use Sysinternal's/ Windows Process Explorer&lt;/a&gt;] &lt;/p&gt;&lt;p&gt;&lt;strong&gt; Removing              entry from windows startup&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         system                                                                                                                                                                                                                                                      configuration                                                can                                         be                                                                                                                      started                                        in                                                             xp                                                         and                                                in                                                                                                                                       vista                      by                                                                                                                       typing                                                                                                                                                                                   msconfig                                in                                                                                                                                                          the                                                run                                             box/                                                                                                     start                                                                         menu                                                                                               search                                                                                                                        box. &lt;br /&gt;In                                                                                                                                  xp                        by                                                                                                                                                                    clicking             on                                                                                                                                                                                     Start                                                                                                                  &amp;gt;                                                             run                      .                                                            The                                                                                                                   windows                                                                      startup                                                                                  is                                                                                                                                                         reversible.                                                                                                              You                                                         can                                                       check                                                  /                                                                                                                                                                                                                                                 uncheck                                                                                   any                                                      entry                                                                        from                                                                                                       windows                                                                                                                                          startup                    any                                                                                                                                                        number                                    of                                                                                                times.             Watch     a                     video                     on   &lt;a href="http://www.youtube.com/watch?v=0HVaxH_k5W8" target="_blank" title="windows startup video"&gt;How to Use the Windows Startup&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Open                                                                                                                                                                                                                                                                                                                                                                                                                                                                   system                                                                                                                                                                                                                   configuration                                                                                                                                                  window.Click                                                                                   on                                                                  the                                                                                                                                                                                                                               Startup                                                                                                                   tab.                                                     You                                                            will                                                  see                              a                                                                                        list                                       all                                                            the                                                                                                                          programs                                                                                                       that                                          are                                                                                                                                                                             scheduled                                                                                                                                                                                to                                                                                    start                           with                                                                                                                                                        windows.                                                                   Expand                                                                                             the                                                                                                       middle                                                                                                                                                                                                                     column                                                                                        using                                                                                       your                                                                               mouse                                                                                                pointer.                                                                                                           That                                                    will                                                                            show                                                                     you                                               the                                                                                                                                                              full                                                                   path                                                                                           of                             the                                                                                                                                                        program.                                                                                                                Locate                                                                  and                                                                                                                               uncheck                                                                                       the                                                                                                    boxes                                                               in                                                                                                                             front                of                                                                                                                                         these                                                                                                                            names                                                                                            "fake explorer.exe"                                                                                                                                (also                                                    look                                               for                                                                                                                                                               any                                                                                                  other                                                                                                                                                                                                                                          suspicious                                                                                           names)Press                                                                                                                                 Apply                       ,                                                                                                                                                       Press                                                                                                                                                            Close/Ok             ,                                                                                                                                                                                Select                                                                                                                      "restart"                                                                   at                     the                                                                                        next                         prompt.&lt;/p&gt;&lt;strong&gt; Deleting          files&lt;/strong&gt; &lt;p&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           computer                                          will                                                                                                                  restart                                                                          now.                                                                                                                                                                          Delete                                                                           the                                                                                                                                                                                          following                                                                                                  files                                                            and                                                                                                                                             folders.                                                        Boot                                        in                                                                   safe                                                      mode                                                                               or                                                                                                                                                boot                                                        in                                                         the                                                                                                                       dos                                                               prompt                                                                                  if                                                                                                            needed.               You                                                                                                   can                              use                                                                                                                 windows                                                                                                               search                                                                                                                                utility                                                                                                                                    to                                                                                                                       search                                                                                                          for                                                                                                                                                    fake explorer.exe&lt;/p&gt; &lt;p&gt;&lt;em&gt;Files&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%AppData%\Microsoft \Crypto\RSA \S-1-5-21-606747145 -764733703- 839522115- 1003\699c4b9cd ebca7aaea5193 cae8a50098_ a7bcc1a4-f7a4- 4502-8650- 8579e60 7f7f7&lt;br /&gt;C:\windows\system32\System32\explorer.exe&lt;br /&gt;C:\windows\system32\System32\logse.dat&lt;br /&gt;&lt;br /&gt;Folders&lt;br /&gt;&lt;/em&gt;&lt;em&gt;C:\windows\system32\System32&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Files  in Temp folder&lt;br /&gt;-&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Installer File&lt;/em&gt;&lt;br /&gt;[file                 and pathname of the sample #1]&lt;/p&gt;&lt;p&gt;You can find full path of the folders for your version of windows &lt;a href="http://comprolive.com:80/remove/folders" title="common folders"&gt; on this link&lt;/a&gt;.   &lt;/p&gt; &lt;p&gt;(We                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    do                                                                         not                                                                                know                                           the                                                         name                                     or                                                    the                                                                                                                            location                                               of                                                                                                                        sample                                                                            #1,                                                      it                                                                                                                        could                                                                      be                                       in                                                                                       your                                                                                                                                                    default                                                                                                                                                                            download                                                                                             location                                              or                                                            on                                                 the                                                                                                                                                                                       desktop                          or                                                      in                   a                                                                     Temp                                                                                                                                                                                  folder.                                               The                                                                                                     files                                                 and                                                                                                                                                                   folders                                         in                                                                  the                                                                                                 Temp                                                                     folder                                                                              can                                                              be                                                                                                                                                                                                                                                       automatically                                                                                                                            removed,                                                                            if                                                               you                                            use                  a                                                                                                                                                                                                                                                  freeware                                                                                     temp                                                                               files/                                                                                                       registry                                                                                                                                                        cleaner                                                                                                                                                                software                                                like                                                                                                                                                                                                                                   CCleaner)&lt;/p&gt;&lt;h3&gt;Some Common folder locations &lt;/h3&gt;&lt;p&gt;Virus makes create their files in uncommon locations. You can find such locations&lt;a href="http://comprolive.com:80/remove/folders" title="common folders"&gt; on this link&lt;/a&gt;.  &lt;/p&gt;&lt;p&gt;These                                               are the folders where you       should      find     sub         folders    of             legitimate                    programs.  If    you  find   any       files  (exe,    dll        etc)  at             this      location,     they                should  be    treated           suspiciously.       The   other          thing   to     look     out    for  is                     randomly  named     folders.  &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Repair Hosts File&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;To repair/ edit the hosts file. Login as administrator. open  the following file in notepad&lt;br /&gt; C:\ WINDOWS \system32 \drivers \etc \hosts&lt;br /&gt;remove anything other than 127.0.0.1 Localhost, and save and close the file.&lt;/p&gt;&lt;p&gt; &lt;strong&gt;Registry            Keys&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;There                 are several registry modifications done by this virus.   You     can     see     the   registry modifications in the report from   the   link    above.&lt;/p&gt;&lt;strong&gt; Using  CCleaner&lt;/strong&gt; &lt;p&gt;You                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  can                                                                                                                                               easily                                                                                remove                                         the                                                                        files                                                      in                                               the                                               temp                                                                                                                                folder                                               by                                                                                                                      running                                                                                                                                                                                                                     CCleaner.                                                                                                                  You                                               can                                                                       set                                                                                                                                                                     CCleaner                                       to                                           run                                                                                                                                                                                                                         automatically                                                  each                                                                                                               time                                                                            the                                                                                                                                 computer                                                                                                                                                                                                           starts.                                     Do                                                              not                                                                                                                                                                       forget                   to                             run                                                               CCleaner                                                                                                                                          &amp;gt;                                                                                                                                                                                                               Registry                                                                                menu                  to                                                                              remove                                                                                                                     the                                                                                                                                 obsolete                                                                                                                                                       registry                                                                                                                                                                                 entries.&lt;/p&gt; &lt;p&gt;more    about    CCleaner &lt;a href="http://comprolive.com:80/remove/../free/software/system-optimizer/ccleaner" target="_blank" title="CCleaner"&gt;on this link&lt;/a&gt;&lt;/p&gt;&lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt;Video on how to use CCleaner&lt;/a&gt;]  &lt;/p&gt; &lt;p&gt;&lt;strong&gt; Free     tools          to repair disabled &lt;span class="notranslate"&gt;folder options,              registry, Task Manager&lt;/span&gt; etc&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Whereas        you          can repair disabled Folder Options, disabled &lt;span class="notranslate"&gt;Registry     Tools, disabled Task Manager, Disabled             System Restore&lt;/span&gt; etc     using these free tools&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Tools        for&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/enable-registry-tools-in-vista" target="_blank" title="tools for windows Vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools              for &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-run-command-task-manager-and-registry-tools-in-xp" target="_blank" title="tools for windows XP"&gt;Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools          for &lt;a href="http://comprolive.com:80/remove/../howto/windows7/re-enable-disabled-tools-in-windows7" target="_blank" title="re-enable tool for Windows7"&gt;Windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt; Use              the &lt;span class="notranslate"&gt;System    File Checker&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;To              repair altered deleted or modified windows system    files.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;How              to run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility                 in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/system-file-checker-in-xp" target="_blank" title="system file checker in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How  to             run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility              in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system file checker in vista"&gt; windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to run System File Checker utility in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-file-checker-in-windows7" target="_blank" title="System File Checker in Windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;Additional Information &lt;/strong&gt;&lt;br /&gt; Virus                                                                                                                                                                              infections         are                         complex.                Most            of           the                            times    a                          virus           on                          the                                                   computer                                     downloads                      more            files                    and                       make       it                                              complicated.        In                       my                                             attempt  to                  warn                                   users                           about                the                                    different          ways                         that                          viruses           are                                      trying       to                             infect                        and                                          ways        to              find        them              and                                 remove,   I                          have                                       created              videos           on                                                   specific         Free                              tools         and                                    manual                                         methods,                   these                          videos                                could            be                  of              great                 help&lt;br /&gt;&lt;p&gt;1) To detect and remove malicious Alternate Data Streams - &lt;a href="http://www.youtube.com/watch?v=njAjGiSp98o" target="_blank" title="stream armour"&gt;Stream Armour  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) To detect and remove malicious Services -&lt;a href="http://www.youtube.com/watch?v=uCTUvgTHVsU" target="_blank" title="Advanced Winservice manager"&gt; Advanced WinService Manager  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) To detect and remove viruses in Fake recycle Bin - &lt;a href="http://www.youtube.com/watch?v=NfMtz3vzr3A" target="_blank" title="Fake recycle bin"&gt;Watch Video  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) keep an eye on suspicious connections using a Firewall  - &lt;a href="http://www.youtube.com/watch?v=W1qtOrQMfyk" target="_blank" title="comodo firewall video"&gt;Free Comodo Firewall &lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) A free tool to detect and remove unwanted BHOs - &lt;a href="http://www.youtube.com/watch?v=sU_hY1r26_g" target="_blank" title="spyBHO remover video"&gt;SpyBHO Remover  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;6) A     free tool  from  Microsoft to reset  the IE settings -  on &lt;a href="http://support.microsoft.com/kb/923737" target="_blank" title="mskb923737"&gt;Microsoft's website    &lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;  Reprinted              with    permission from Threatexpert.com   &lt;/p&gt; &lt;p&gt; &lt;a href="http://comprolive.com:80/remove/about-this-site" target="_blank" rel="author"&gt;Sanjay C Rajure&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/m2N2XU9BuYwjZmLnDPTdQVBK-ik/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/m2N2XU9BuYwjZmLnDPTdQVBK-ik/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/m2N2XU9BuYwjZmLnDPTdQVBK-ik/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/m2N2XU9BuYwjZmLnDPTdQVBK-ik/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/removalguides/~4/uUp9VAlTP-k" height="1" width="1"/&gt;</description>
			<category>frontpage</category>
			<pubDate>Wed, 22 Feb 2012 16:49:43 +0000</pubDate>
		<feedburner:origLink>http://comprolive.com/remove/trojan/generic/system32-system32-explorer-exe</feedburner:origLink></item>
		<item>
			<title>wsock32.sys, scvhost.exe</title>
			<link>http://feedproxy.google.com/~r/removalguides/~3/SA2dT7BgR5U/wsock32-sys-scvhost-exe</link>
			<description>&lt;p&gt;Suspicious files names wsock32.sys, scvhost.exe have  appeared in a             virus analysis report. You  can see it  &lt;a href="http://www.threatexpert.com/report.aspx?md5=9a8b4bae90f13c4972b14aa1eb06f023" target="_blank" title="report"&gt;on this link&lt;/a&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The                                                                                                                                                                                                                                                                                                                                                                                    installer                 of                  this      virus           is               of                                                                                                                                                                                            about 63 KB.      It is detected    by                                       antivirus                        programs as&lt;br /&gt;Backdoor.Ciadoor!rem [PCTools]&lt;br /&gt;Backdoor.Ciadoor [Symantec]&lt;br /&gt;Backdoor.Win32.Ciadoor.cdt [Kaspersky Lab]&lt;br /&gt;BackDoor-ASB.svr [McAfee]&lt;br /&gt;Mal/VBDrop-G [Sophos]&lt;br /&gt;Backdoor.Win32.Ciadoor [Ikarus]&lt;br /&gt;packed with: MewBundle [Kaspersky Lab]&lt;/li&gt;&lt;li&gt;It creates registry entries so that wsock32.sys, scvhost.exe and other malicious files run at startup&lt;/li&gt;&lt;li&gt;It creates malicious services named Nla/Network Location Awareness (NLA), SENS/System Event Notification, SharedAccess/Windows Firewall/Internet Connection Sharing (ICS). These services were not running. &lt;br /&gt;These names are similar to the names of legit windows services. The only way you might be able to differentiate is by looking at the names in the manufacturercolumn.&lt;/li&gt;&lt;li&gt;It stops a legitimate service named ALG/Application Layer Gateway Service. You need to start it again&lt;/li&gt;&lt;li&gt;Disables System Restore Settings link in the System Restore interface&lt;br /&gt;Disables the System Restore tools on the Start menu&lt;br /&gt;Prevents users from starting Task Manager (Taskmgr.exe)&lt;br /&gt;Disables the Windows registry editors (Regedt32.exe and Regedit.exe)&lt;/li&gt;&lt;li&gt; It connects to suspicious IP addresses in Germany and starts download from a dubious French website&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;     It creates                                                                                                                    wsock32.sys, scvhost.exe                        and                                                         other                                  files                   on                                                                                                                                           the                                                                                                                                         infected                                                                                                                                                                                                                                                              computer                                                                             that                                         you                                                                                                    need                        to                                                                                        search                                                                                                 and                                                                        delete.                                           You                                                                                                                                                                                   should                                                                                  end                                                                                                                                                                  running                                                                                                                                                                               processes                                                                     named                                                                                                                                           wsock32.sys, scvhost.exe                                          from                                                                                    Task                                                                                                                                                                       Manager.                                                  And                                                                                                                           also                                                                                                                                                        remove                                                                                                           the                                                file's                                                                                                                                                               entries                                            from                                                                                                                                                                    windows                                                                                     startup.&lt;/p&gt;&lt;p&gt;Warning:                                                                                                                                                                                                                                                                                                                              It                                                 is                                                             possible                                 that          some                                                                              legitimate                                                                            software                                     may                     be                                                                                   using                         the                                                    same                                                                                                                       file                                                          names                                       as                            that                of            the                                              virus                                                                 files.                                                  You                                      do                     not                                                       have                                              to                                                                                    delete                                                     these                                              files                                               if                                                  they                                             belong                                                to                                       some                                                                                                     legitimate                                                                 program                                                                                                      installed                       on                                                                your                                                                                                computer.                                                                                   Use                                                              Windows                                                          Defender                                    or                                                                                               SysInternals                                                                                      Process                                                                                                                           Explorer             to                                                                                                                                                                 differentiate                                       between                                                                                       them.                                               The                                                                                                                                      information             in                         this                                                                                  article                             is                                                                                                                          presented                                                       without                                                                                                                     making                 any                                           claims                                                                                          regarding                                                          its                                                                                                  usefulness         or                                                                                                                                                           otherwise.               If                             you                         have                                any                                                             objections                               or                                                               questions,                                                      please                                                  send          a                                    note            by                                                                                                                                                  adding   a                                                                                                comment                  at                                     the                                 end                        of                                                       this                               page,                or                                         mail                       on                                                                                                                                                                                                                                                                                                             support(at)comprolive.com    &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Preventive measures&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;                                                                                                                                                                                                     Most        of               the                                                        viruses                                     enter                           your                                                                                                                                  computer                                                             when                             you                                                        visit                                                      some                                                             harmful                                                                                        website.                                                          If                               you                                      use     a                                                                                                browser                                                                              plugin                                    that                                                                      warns                                                  you                                          about                                                                                                  harmful                                                                     websites,                you                                                                 can                                                                         prevent                                                                   this                                                        from                                                                                           happening.  A                                                                                                                                        popular                                                  browser                                                      plugin                                      is                                                                      called                            Web                                                   Of                                   Trust                                                                                                (WOT),                          you                                                                           can                                                                             install                   it                            from                                                       its                                                                    website   &lt;a href="http://www.mywot.com/" target="_blank" title="WOT "&gt;on this link&lt;/a&gt;. &lt;br /&gt;[ &lt;a href="http://www.youtube.com/watch?v=8DHx7wioFuM" target="_blank" title="WOT video"&gt;a video about WOT plugin &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Blocking                                                                                                                                                      Javascript       of         all             sites       by                      default             can                    help       to                               prevent                         drive              by                                              download                                infections.         You             can        use                                      Noscript                 Plugin                    for                     firefox                       as                                           explained&lt;a href="http://www.youtube.com/watch?v=IMPHD5dkCAA" target="_blank" title="Noscript video"&gt; in this video&lt;/a&gt;.                                                                                                                                                 Similar                             functionality         can       be                           achieved                  in                      Google's                                     Chromium                                        browser                               using        the                         settings           in                             Preferences                   &amp;gt;                       Under          the                         Hood            &amp;gt;                               Content                                             Settings             &amp;gt;              Java               Script                 &amp;gt;                       Select      "Do                   not                      Allow".                                   After             that            when                               you          visit  a                                  site,      you                will     see a                  pop                             up       next        to                the                     address                      bar              asking                              you            if           you                want     to                         allow                    JavaScript                 to          run                           for            that                                    particular                  site.   &lt;/li&gt;&lt;li&gt;Some                                                                                                                                                                                                                                                                         of              the                              viruses          are                                                                                downloaded                         in                                                                        Internet                                              Cache                            or          in                                             the                                                                       Temp                                                                          folder                              of                        the                                               windows.                              The                                                    viruses                                                         get                                                 activated                              when                                                               these                                                               files                                  are                                                                                          executed.                                   You                   can                                                    reduce                                         the                             risk                              of                                    virus                                                                        infection                                                 if                             you                                      empty                                                   your                                                browser                                                                                           cache      and                                                                   remove                           windows                                                            temp                                                files                                                                                                             occasionally,                                                                        ideally                          at                              the                                    end                  of                     a                                                                           browsing                                              session                                        or                                                         before                                                                            closing                        down                      your                                                                                                    computer.                                                Some                                          programs                                                                                           like                                               CCleaner                            can    be                                  set                                                    to                          do                                               these                                  things                                                                                                                                             automatically.  [&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt; a video about CCleaner &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Do                                                                                                                                                                                        not             leave            your                            computer                              infected                and                                           insecure.                  If                 you                                  doubt                                 that                                    there                          could        be                               some                        undetected                                virus          on                          your                                       computer,                                         don't                  leave                            it                          like                              that.               Format                              the            hard             disk                          and                                     reinstall                                                windows             and                  all                      other                                                     programs.                  That                     is         the                                   sure                    way       to                 clear                                               doubts.       &lt;/li&gt;&lt;/ul&gt;&lt;strong&gt; Using System Restore&lt;/strong&gt; &lt;p&gt;If                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               you                                                                                    know                            the                                                                                                       duration                                                                           since                                                                         your                                                                                                                                               computer                                       is                                                                                                                                                                                                      infected,                                       you                                                                                                                             can                                                                                    try                                      to                                                                                                                                                                                                  restore                                                       your                                                                                  computer                                            at    a                                                                                                                                                                         prior                                                 date,                                                                                    that                                                                                                                      will                                        be                                                                    an                                          easy                                                                       way                                                                                                     to                                                        undo                                                                                   the                                                                                                                                                                                   changes                             done                  by                                                                   the                                                                                                                                             virus&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Using        system   restore   in  &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-system-restore-in-xp" target="_blank" title="system restore in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using system restore                 in  &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system restore in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using          system restore in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-restore-in-windows7" target="_blank" title="System Restore in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;[ &lt;a href="http://www.youtube.com/watch?v=bhGrVLPIKXY" target="_blank" title="system restore video"&gt;Video of How to use System Restore&lt;/a&gt; ]&lt;br /&gt; &lt;p&gt;&lt;strong&gt; Boot              in safe mode&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Sometimes    you can not        delete  a      file. You should boot in safe mode and then try    to        delete it.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;How       to boot in safe in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/boot-in-safe-mode-in-xp" target="_blank" title="safe mode in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to boot in safe mode                 in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/boot-in-safe-mode-in-vista" target="_blank" title="safe mode in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to boot in safe mode in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/boot-in-safe-mode-in-windows7" target="_blank" title="safeboot in windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;  View              Hidden Files&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;You need to enable                 to view hidden files and folders before searching.&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-to-view-hidden-files-in-xp" target="_blank" title="view hidden files in xp"&gt; Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/view-hidden-files-in-vista" target="_blank" title="view hidden files in vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How         to Enable to View Hidden Files  and Folders in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/view-hidden-files-in-windows7" target="_blank" title="Enable to view hidden files in Windows7"&gt;Windows7             &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;[&lt;a href="http://www.youtube.com/watch?v=0ahhDa_bp0A" target="_blank" title="Enable Hidden Files video "&gt; Video of How to enable Hidden files and folders&lt;/a&gt; ]&lt;br /&gt; &lt;p&gt;&lt;strong&gt; Remove             Processes from &lt;span class="notranslate"&gt;Task Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt; Press              Ctrl Alt Del keys to open the &lt;span class="notranslate"&gt;Task          Manager&lt;/span&gt;.Select                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               Processes                                                      tab.                                                                         You                                                                                                                     will                                              see          a                                                                                                 list.                                                                               Look                                                        for                                                                                                                                                                 the                                                                                                                                         names                                                                                                                                                                                wsock32.sys, scvhost.exe                                                 in                                   it.                                                                                                                          Select                                    if                                                                      found                                                                                                                   and                                                                                                                                 press                                                                                                                       the                                                                                                          End                                                                                         Process                                       button.                                                                                                     It                                                    will                               ask                                                                       for                                                                                                 your                                                                                                                                                                                          confirmation                                                                                                                        to                                                                                        end                                                                                                        that                                                                                                                                  process.                                                                           Select                                                                        Yes.                                    You                                                                   can                                                                                                               end                                                                                            one                                                                                        process                                                                 at            a                                                                                                                                 time.                                                                      You                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       can                                                                                  find                                                                                                                                                                                      out                                                                   if   a                                                                                                                                                                                                                   process                                                    in              &lt;span class="notranslate"&gt;Task                       Manager&lt;/span&gt;     is      good                     or        bad  by  using  &lt;span class="notranslate"&gt;Windows                                Defender in  XP and Vista&lt;/span&gt;.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              It                                                                                                               shows                                                                                                                                                                               the                                                                                                                                                                                                                                                                                                            path                                                                                                 of                         a                                                                                                                                                                                                                                                                                                                         process                                                                                       and                                                                                                                        its                                                                                                                                                                                                                                                                                                                                                                                                       publisher.                                                                                                                                                                                        Harmful                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            processes                                                                                                                                                        may                                                                                                      be                                                                                                                                                                                                    shown                                                                                                                                                                                    under                                                                                                                                                                                                            Unknown                                                                                                                                                                                                                                                                                                                              Publisher                                                                                                   in                                                                                                                                                  &lt;span class="notranslate"&gt;windows                             defender&lt;/span&gt;.  Whereas in Windows7 you  can find that out from the task manager itself. You can watch a video on How to use &lt;a href="http://www.youtube.com/watch?v=TxE8zS9iiSI" target="_blank" title="Windows Defender video"&gt;Windows Defender&lt;/a&gt;. &lt;br /&gt;&lt;ul&gt;&lt;li&gt;How           to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-windows-defender-in-xp" target="_blank" title="windows defender in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-windows-defender-in-vista" target="_blank" title="windows defender in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to use Windows Defender in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/use-windows-defender-in-windows7" target="_blank" title="Use Windows Defender in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; Or                 you can use &lt;span class="notranslate"&gt;Sysinternal's    Process          Explorer&lt;/span&gt;. How  to use      Sysinternal's &lt;a href="http://comprolive.com:80/remove/../free/software/system-tools/process-explorer" target="_blank" title="sysinternal's process explorer"&gt;Process Explorer&lt;/a&gt;&lt;/p&gt;&lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=aD_E0q-x3ww" target="_blank" title="sysinternal's video"&gt;Video of How to use Sysinternal's/ Windows Process Explorer&lt;/a&gt;] &lt;/p&gt;&lt;p&gt;&lt;strong&gt; Removing              entry from windows startup&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         system                                                                                                                                                                                                                                                      configuration                                                can                                         be                                                                                                                      started                                        in                                                             xp                                                         and                                                in                                                                                                                                       vista                      by                                                                                                                       typing                                                                                                                                                                                   msconfig                                in                                                                                                                                                          the                                                run                                             box/                                                                                                     start                                                                         menu                                                                                               search                                                                                                                        box. &lt;br /&gt;In                                                                                                                                  xp                        by                                                                                                                                                                    clicking             on                                                                                                                                                                                     Start                                                                                                                  &amp;gt;                                                             run                      .                                                            The                                                                                                                   windows                                                                      startup                                                                                  is                                                                                                                                                         reversible.                                                                                                              You                                                         can                                                       check                                                  /                                                                                                                                                                                                                                                 uncheck                                                                                   any                                                      entry                                                                        from                                                                                                       windows                                                                                                                                          startup                    any                                                                                                                                                        number                                    of                                                                                                times.             Watch     a                     video                     on   &lt;a href="http://www.youtube.com/watch?v=0HVaxH_k5W8" target="_blank" title="windows startup video"&gt;How to Use the Windows Startup&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Open                                                                                                                                                                                                                                                                                                                                                                                                                                                                   system                                                                                                                                                                                                                   configuration                                                                                                                                                  window.Click                                                                                   on                                                                  the                                                                                                                                                                                                                               Startup                                                                                                                   tab.                                                     You                                                            will                                                  see                              a                                                                                        list                                       all                                                            the                                                                                                                          programs                                                                                                       that                                          are                                                                                                                                                                             scheduled                                                                                                                                                                                to                                                                                    start                           with                                                                                                                                                        windows.                                                                   Expand                                                                                             the                                                                                                       middle                                                                                                                                                                                                                     column                                                                                        using                                                                                       your                                                                               mouse                                                                                                pointer.                                                                                                           That                                                    will                                                                            show                                                                     you                                               the                                                                                                                                                              full                                                                   path                                                                                           of                             the                                                                                                                                                        program.                                                                                                                Locate                                                                  and                                                                                                                               uncheck                                                                                       the                                                                                                    boxes                                                               in                                                                                                                             front                of                                                                                                                                         these                                                                                                                            names                                                                                            "wsock32.sys, scvhost.exe"                                                                                                                                (also                                                    look                                               for                                                                                                                                                               any                                                                                                  other                                                                                                                                                                                                                                          suspicious                                                                                           names)Press                                                                                                                                 Apply                       ,                                                                                                                                                       Press                                                                                                                                                            Close/Ok             ,                                                                                                                                                                                Select                                                                                                                      "do not restart"                                                                   at                     the                                                                                        next                         prompt.&lt;/p&gt;Restarting service&lt;p&gt;Select the services tab while still in the system configuration window. Loate and check the box in front of  ALG/Application Layer Gateway Service so as to start it. )&lt;/p&gt;&lt;p&gt;Finding malicious services&lt;/p&gt;This virus creates services with exactly same names as that of some Microsoft services. The easy way to find them is to check the box in front of "Hide All Microsoft services" and look for these names in the remaining list. &lt;br /&gt;Nla/Network Location Awareness (NLA), SENS/System Event Notification, SharedAccess/Windows Firewall/Internet Connection Sharing (ICS). Stop them if you find them active or running by unchecking the boxes. &lt;br /&gt;&lt;p&gt; Press                                                                                                                                 Apply                       ,                                                                                                                                                       Press                                                                                                                                                            Close/Ok             ,                                                                                                                                                                                Select                                                                                                                      "restart"                                                                   at                     the                                                                                        next                         prompt.&lt;/p&gt;&lt;strong&gt; Deleting          files&lt;/strong&gt; &lt;p&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           computer                                          will                                                                                                                  restart                                                                          now.                                                                                                                                                                          Delete                                                                           the                                                                                                                                                                                          following                                                                                                  files                                                            and                                                                                                                                             folders.                                                        Boot                                        in                                                                   safe                                                      mode                                                                               or                                                                                                                                                boot                                                        in                                                         the                                                                                                                       dos                                                               prompt                                                                                  if                                                                                                            needed.               You                                                                                                   can                              use                                                                                                                 windows                                                                                                               search                                                                                                                                utility                                                                                                                                    to                                                                                                                       search                                                                                                          for                                                                                                                                                    wsock32.sys, scvhost.exe&lt;/p&gt; &lt;p&gt;&lt;em&gt;Files&lt;/em&gt;&lt;br /&gt;&lt;em&gt;C:\windows\system32\ckl009.dat&lt;br /&gt;C:\windows\system32\scvhost.exe&lt;br /&gt;C:\windows\system32\UgPSCgIxag.ini&lt;br /&gt;C:\windows\system32\wsock32.sys&lt;br /&gt;&lt;br /&gt;Folders&lt;br /&gt;&lt;/em&gt;&lt;em&gt;-&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Files  in Temp folder&lt;br /&gt;-&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Installer File&lt;/em&gt;&lt;br /&gt;[file                 and pathname of the sample #1]&lt;/p&gt;&lt;p&gt;You can find full path of the folders for your version of windows &lt;a href="http://comprolive.com:80/remove/folders" title="common folders"&gt; on this link&lt;/a&gt;.   &lt;/p&gt; &lt;p&gt;(We                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    do                                                                         not                                                                                know                                           the                                                         name                                     or                                                    the                                                                                                                            location                                               of                                                                                                                        sample                                                                            #1,                                                      it                                                                                                                        could                                                                      be                                       in                                                                                       your                                                                                                                                                    default                                                                                                                                                                            download                                                                                             location                                              or                                                            on                                                 the                                                                                                                                                                                       desktop                          or                                                      in                   a                                                                     Temp                                                                                                                                                                                  folder.                                               The                                                                                                     files                                                 and                                                                                                                                                                   folders                                         in                                                                  the                                                                                                 Temp                                                                     folder                                                                              can                                                              be                                                                                                                                                                                                                                                       automatically                                                                                                                            removed,                                                                            if                                                               you                                            use                  a                                                                                                                                                                                                                                                  freeware                                                                                     temp                                                                               files/                                                                                                       registry                                                                                                                                                        cleaner                                                                                                                                                                software                                                like                                                                                                                                                                                                                                   CCleaner)&lt;/p&gt;&lt;h3&gt;Some Common folder locations &lt;/h3&gt;&lt;p&gt;Virus makes create their files in uncommon locations. You can find such locations&lt;a href="http://comprolive.com:80/remove/folders" title="common folders"&gt; on this link&lt;/a&gt;.  &lt;/p&gt;&lt;p&gt;These                                               are the folders where you       should      find     sub         folders    of             legitimate                    programs.  If    you  find   any       files  (exe,    dll        etc)  at             this      location,     they                should  be    treated           suspiciously.       The   other          thing   to     look     out    for  is                     randomly  named     folders.  &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Repair Hosts File&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;To repair/ edit the hosts file. Login as administrator. open  the following file in notepad&lt;br /&gt; C:\ WINDOWS \system32 \drivers \etc \hosts&lt;br /&gt;remove anything other than 127.0.0.1 Localhost, and save and close the file.&lt;/p&gt;&lt;p&gt; &lt;strong&gt;Registry            Keys&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;There                 are several registry modifications done by this virus.   You     can     see     the   registry modifications in the report from   the   link    above.&lt;/p&gt;&lt;strong&gt; Using  CCleaner&lt;/strong&gt; &lt;p&gt;You                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  can                                                                                                                                               easily                                                                                remove                                         the                                                                        files                                                      in                                               the                                               temp                                                                                                                                folder                                               by                                                                                                                      running                                                                                                                                                                                                                     CCleaner.                                                                                                                  You                                               can                                                                       set                                                                                                                                                                     CCleaner                                       to                                           run                                                                                                                                                                                                                         automatically                                                  each                                                                                                               time                                                                            the                                                                                                                                 computer                                                                                                                                                                                                           starts.                                     Do                                                              not                                                                                                                                                                       forget                   to                             run                                                               CCleaner                                                                                                                                          &amp;gt;                                                                                                                                                                                                               Registry                                                                                menu                  to                                                                              remove                                                                                                                     the                                                                                                                                 obsolete                                                                                                                                                       registry                                                                                                                                                                                 entries.&lt;/p&gt; &lt;p&gt;more    about    CCleaner &lt;a href="http://comprolive.com:80/remove/../free/software/system-optimizer/ccleaner" target="_blank" title="CCleaner"&gt;on this link&lt;/a&gt;&lt;/p&gt;&lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt;Video on how to use CCleaner&lt;/a&gt;]  &lt;/p&gt; &lt;p&gt;&lt;strong&gt; Free     tools          to repair disabled &lt;span class="notranslate"&gt;folder options,              registry, Task Manager&lt;/span&gt; etc&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Whereas        you          can repair disabled Folder Options, disabled &lt;span class="notranslate"&gt;Registry     Tools, disabled Task Manager, Disabled             System Restore&lt;/span&gt; etc     using these free tools&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Tools        for&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/enable-registry-tools-in-vista" target="_blank" title="tools for windows Vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools              for &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-run-command-task-manager-and-registry-tools-in-xp" target="_blank" title="tools for windows XP"&gt;Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools          for &lt;a href="http://comprolive.com:80/remove/../howto/windows7/re-enable-disabled-tools-in-windows7" target="_blank" title="re-enable tool for Windows7"&gt;Windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt; Use              the &lt;span class="notranslate"&gt;System    File Checker&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;To              repair altered deleted or modified windows system    files.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;How              to run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility                 in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/system-file-checker-in-xp" target="_blank" title="system file checker in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How  to             run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility              in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system file checker in vista"&gt; windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to run System File Checker utility in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-file-checker-in-windows7" target="_blank" title="System File Checker in Windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;Additional Information &lt;/strong&gt;&lt;br /&gt; Virus                                                                                                                                                                              infections         are                         complex.                Most            of           the                            times    a                          virus           on                          the                                                   computer                                     downloads                      more            files                    and                       make       it                                              complicated.        In                       my                                             attempt  to                  warn                                   users                           about                the                                    different          ways                         that                          viruses           are                                      trying       to                             infect                        and                                          ways        to              find        them              and                                 remove,   I                          have                                       created              videos           on                                                   specific         Free                              tools         and                                    manual                                         methods,                   these                          videos                                could            be                  of              great                 help&lt;br /&gt;&lt;p&gt;1) To detect and remove malicious Alternate Data Streams - &lt;a href="http://www.youtube.com/watch?v=njAjGiSp98o" target="_blank" title="stream armour"&gt;Stream Armour  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) To detect and remove malicious Services -&lt;a href="http://www.youtube.com/watch?v=uCTUvgTHVsU" target="_blank" title="Advanced Winservice manager"&gt; Advanced WinService Manager  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) To detect and remove viruses in Fake recycle Bin - &lt;a href="http://www.youtube.com/watch?v=NfMtz3vzr3A" target="_blank" title="Fake recycle bin"&gt;Watch Video  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) keep an eye on suspicious connections using a Firewall  - &lt;a href="http://www.youtube.com/watch?v=W1qtOrQMfyk" target="_blank" title="comodo firewall video"&gt;Free Comodo Firewall &lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) A free tool to detect and remove unwanted BHOs - &lt;a href="http://www.youtube.com/watch?v=sU_hY1r26_g" target="_blank" title="spyBHO remover video"&gt;SpyBHO Remover  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;6) A     free tool  from  Microsoft to reset  the IE settings -  on &lt;a href="http://support.microsoft.com/kb/923737" target="_blank" title="mskb923737"&gt;Microsoft's website    &lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;  Reprinted              with    permission from Threatexpert.com   &lt;/p&gt; &lt;p&gt; &lt;a href="http://comprolive.com:80/remove/about-this-site" target="_blank" rel="author"&gt;Sanjay C Rajure&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/zW0SEq2PrEMPP3dGc2opT-D2Vmg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zW0SEq2PrEMPP3dGc2opT-D2Vmg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/zW0SEq2PrEMPP3dGc2opT-D2Vmg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zW0SEq2PrEMPP3dGc2opT-D2Vmg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/removalguides/~4/SA2dT7BgR5U" height="1" width="1"/&gt;</description>
			<category>frontpage</category>
			<pubDate>Mon, 20 Feb 2012 11:28:30 +0000</pubDate>
		<feedburner:origLink>http://comprolive.com/remove/trojan/backdoor/wsock32-sys-scvhost-exe</feedburner:origLink></item>
		<item>
			<title>torrent.exe</title>
			<link>http://feedproxy.google.com/~r/removalguides/~3/AzC5RpvvfSg/torrent-exe</link>
			<description>&lt;p&gt;Suspicious files name torrent.exe has  appeared in a             virus analysis report. You  can see it  &lt;a href="http://www.threatexpert.com/report.aspx?md5=51ec2ce27a753a599cd8a5fcbba5d67d" target="_blank" title="report"&gt;on this link&lt;/a&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The                                                                                                                                                                                                                                                                                                                                                                              installer                 of                  this      virus          is               of                                                                                                                                                                                          about 108 KB.      It is detected    by                                      antivirus                        programs as&lt;br /&gt;Bat/sdel [McAfee]&lt;br /&gt;It creates registry entries so that torrent.exe and other malicious files run at startup&lt;/li&gt;&lt;li&gt; It connects to suspicious IP address in Russia and starts download from a dubious website&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;    It creates                                                                                                                   torrent.exe                       and                                                        other                                  files                   on                                                                                                                                         the                                                                                                                                       infected                                                                                                                                                                                                                                                          computer                                                                            that                                        you                                                                                                   need                        to                                                                                      search                                                                                                and                                                                       delete.                                          You                                                                                                                                                                                 should                                                                                end                                                                                                                                                                running                                                                                                                                                                             processes                                                                    named                                                                                                                                         torrent.exe                                         from                                                                                   Task                                                                                                                                                                    Manager.                                                  And                                                                                                                         also                                                                                                                                                      remove                                                                                                         the                                               file's                                                                                                                                                             entries                                           from                                                                                                                                                                  windows                                                                                    startup.&lt;/p&gt;&lt;p&gt;Warning:                                                                                                                                                                                                                                                                                                                         It                                                is                                                            possible                                 that          some                                                                            legitimate                                                                           software                                     may                    be                                                                                  using                         the                                                   same                                                                                                                     file                                                         names                                       as                           that                of            the                                             virus                                                                files.                                                  You                                     do                     not                                                      have                                             to                                                                                   delete                                                    these                                              files                                              if                                                 they                                            belong                                                to                                      some                                                                                                    legitimate                                                                program                                                                                                    installed                       on                                                               your                                                                                              computer.                                                                                  Use                                                             Windows                                                         Defender                                    or                                                                                             SysInternals                                                                                     Process                                                                                                                         Explorer             to                                                                                                                                                               differentiate                                      between                                                                                      them.                                              The                                                                                                                                    information             in                         this                                                                                article                             is                                                                                                                        presented                                                      without                                                                                                                    making                any                                           claims                                                                                        regarding                                                         its                                                                                                 usefulness         or                                                                                                                                                         otherwise.              If                             you                        have                                any                                                            objections                               or                                                              questions,                                                     please                                                 send          a                                   note            by                                                                                                                                                adding   a                                                                                               comment                 at                                     the                                end                        of                                                      this                               page,               or                                         mail                      on                                                                                                                                                                                                                                                                                                         support(at)comprolive.com    &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Preventive measures&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;                                                                                                                                                                                                  Most        of              the                                                        viruses                                    enter                           your                                                                                                                                computer                                                            when                            you                                                       visit                                                      some                                                            harmful                                                                                      website.                                                          If                              you                                      use    a                                                                                               browser                                                                             plugin                                   that                                                                     warns                                                  you                                         about                                                                                                 harmful                                                                   websites,                you                                                                can                                                                        prevent                                                                  this                                                       from                                                                                          happening.  A                                                                                                                                      popular                                                 browser                                                     plugin                                      is                                                                     called                           Web                                                   Of                                  Trust                                                                                               (WOT),                         you                                                                          can                                                                            install                   it                           from                                                      its                                                                   website   &lt;a href="http://www.mywot.com/" target="_blank" title="WOT "&gt;on this link&lt;/a&gt;. &lt;br /&gt;[ &lt;a href="http://www.youtube.com/watch?v=8DHx7wioFuM" target="_blank" title="WOT video"&gt;a video about WOT plugin &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Blocking                                                                                                                                                   Javascript       of         all             sites       by                     default             can                    help       to                              prevent                         drive             by                                              download                               infections.         You             can        use                                     Noscript                 Plugin                   for                     firefox                       as                                          explained&lt;a href="http://www.youtube.com/watch?v=IMPHD5dkCAA" target="_blank" title="Noscript video"&gt; in this video&lt;/a&gt;.                                                                                                                                              Similar                             functionality         can       be                          achieved                  in                     Google's                                     Chromium                                       browser                               using       the                         settings           in                            Preferences                   &amp;gt;                       Under         the                         Hood            &amp;gt;                              Content                                             Settings            &amp;gt;              Java               Script                &amp;gt;                       Select      "Do                   not                     Allow".                                   After            that            when                               you          visit  a                                 site,      you                will    see a                  pop                             up       next       to                the                     address                     bar              asking                              you            if          you                want     to                         allow                   JavaScript                 to          run                          for            that                                   particular                  site.   &lt;/li&gt;&lt;li&gt;Some                                                                                                                                                                                                                                                                     of              the                             viruses          are                                                                               downloaded                         in                                                                       Internet                                             Cache                           or          in                                             the                                                                      Temp                                                                        folder                              of                        the                                              windows.                             The                                                    viruses                                                        get                                                activated                              when                                                              these                                                              files                                 are                                                                                         executed.                                  You                   can                                                   reduce                                         the                            risk                              of                                   virus                                                                       infection                                                if                             you                                     empty                                                   your                                               browser                                                                                         cache      and                                                                  remove                           windows                                                           temp                                               files                                                                                                            occasionally,                                                                      ideally                          at                              the                                   end                  of                    a                                                                          browsing                                              session                                       or                                                        before                                                                           closing                        down                     your                                                                                                   computer.                                               Some                                         programs                                                                                          like                                              CCleaner                            can    be                                 set                                                    to                         do                                              these                                  things                                                                                                                                           automatically.  [&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt; a video about CCleaner &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Do                                                                                                                                                                                     not             leave           your                            computer                             infected                and                                          insecure.                  If                 you                                 doubt                                 that                                   there                          could        be                              some                        undetected                               virus          on                          your                                      computer,                                        don't                  leave                            it                         like                              that.              Format                              the            hard             disk                         and                                    reinstall                                                windows            and                  all                      other                                                    programs.                  That                    is         the                                   sure                   way       to                 clear                                              doubts.       &lt;/li&gt;&lt;/ul&gt;&lt;strong&gt; Using System Restore&lt;/strong&gt; &lt;p&gt;If                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      you                                                                                   know                           the                                                                                                      duration                                                                         since                                                                        your                                                                                                                                             computer                                       is                                                                                                                                                                                                   infected,                                      you                                                                                                                            can                                                                                  try                                      to                                                                                                                                                                                               restore                                                      your                                                                                 computer                                           at    a                                                                                                                                                                       prior                                                date,                                                                                   that                                                                                                                    will                                        be                                                                   an                                         easy                                                                      way                                                                                                    to                                                       undo                                                                                  the                                                                                                                                                                                changes                             done                 by                                                                   the                                                                                                                                           virus&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Using        system   restore   in  &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-system-restore-in-xp" target="_blank" title="system restore in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using system restore                 in  &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system restore in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using          system restore in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-restore-in-windows7" target="_blank" title="System Restore in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;[ &lt;a href="http://www.youtube.com/watch?v=bhGrVLPIKXY" target="_blank" title="system restore video"&gt;Video of How to use System Restore&lt;/a&gt; ]&lt;br /&gt; &lt;p&gt;&lt;strong&gt; Boot              in safe mode&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Sometimes    you can not        delete  a      file. You should boot in safe mode and then try    to        delete it.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;How       to boot in safe in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/boot-in-safe-mode-in-xp" target="_blank" title="safe mode in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to boot in safe mode                 in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/boot-in-safe-mode-in-vista" target="_blank" title="safe mode in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to boot in safe mode in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/boot-in-safe-mode-in-windows7" target="_blank" title="safeboot in windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;  View              Hidden Files&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;You need to enable                 to view hidden files and folders before searching.&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-to-view-hidden-files-in-xp" target="_blank" title="view hidden files in xp"&gt; Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/view-hidden-files-in-vista" target="_blank" title="view hidden files in vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How         to Enable to View Hidden Files  and Folders in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/view-hidden-files-in-windows7" target="_blank" title="Enable to view hidden files in Windows7"&gt;Windows7             &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;[&lt;a href="http://www.youtube.com/watch?v=0ahhDa_bp0A" target="_blank" title="Enable Hidden Files video "&gt; Video of How to enable Hidden files and folders&lt;/a&gt; ]&lt;br /&gt; &lt;p&gt;&lt;strong&gt; Remove             Processes from &lt;span class="notranslate"&gt;Task Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt; Press              Ctrl Alt Del keys to open the &lt;span class="notranslate"&gt;Task          Manager&lt;/span&gt;.Select                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Processes                                                     tab.                                                                        You                                                                                                                   will                                              see          a                                                                                               list.                                                                              Look                                                       for                                                                                                                                                               the                                                                                                                                       names                                                                                                                                                                             torrent.exe                                                 in                                  it.                                                                                                                        Select                                    if                                                                     found                                                                                                                 and                                                                                                                               press                                                                                                                      the                                                                                                        End                                                                                        Process                                      button.                                                                                                    It                                                   will                               ask                                                                      for                                                                                               your                                                                                                                                                                                        confirmation                                                                                                                      to                                                                                       end                                                                                                      that                                                                                                                                process.                                                                          Select                                                                       Yes.                                    You                                                                  can                                                                                                             end                                                                                           one                                                                                      process                                                                at            a                                                                                                                               time.                                                                     You                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             can                                                                                 find                                                                                                                                                                                    out                                                                  if   a                                                                                                                                                                                                                process                                                   in              &lt;span class="notranslate"&gt;Task                       Manager&lt;/span&gt;     is      good                     or        bad  by  using  &lt;span class="notranslate"&gt;Windows                                Defender in  XP and Vista&lt;/span&gt;.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   It                                                                                                              shows                                                                                                                                                                            the                                                                                                                                                                                                                                                                                                        path                                                                                                of                        a                                                                                                                                                                                                                                                                                                                     process                                                                                      and                                                                                                                      its                                                                                                                                                                                                                                                                                                                                                                                                  publisher.                                                                                                                                                                                     Harmful                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    processes                                                                                                                                                      may                                                                                                    be                                                                                                                                                                                                  shown                                                                                                                                                                                 under                                                                                                                                                                                                         Unknown                                                                                                                                                                                                                                                                                                                          Publisher                                                                                                 in                                                                                                                                                &lt;span class="notranslate"&gt;windows                             defender&lt;/span&gt;.  Whereas in Windows7 you  can find that out from the task manager itself. You can watch a video on How to use &lt;a href="http://www.youtube.com/watch?v=TxE8zS9iiSI" target="_blank" title="Windows Defender video"&gt;Windows Defender&lt;/a&gt;. &lt;br /&gt;&lt;ul&gt;&lt;li&gt;How           to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-windows-defender-in-xp" target="_blank" title="windows defender in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-windows-defender-in-vista" target="_blank" title="windows defender in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to use Windows Defender in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/use-windows-defender-in-windows7" target="_blank" title="Use Windows Defender in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; Or                 you can use &lt;span class="notranslate"&gt;Sysinternal's    Process          Explorer&lt;/span&gt;. How  to use      Sysinternal's &lt;a href="http://comprolive.com:80/remove/../free/software/system-tools/process-explorer" target="_blank" title="sysinternal's process explorer"&gt;Process Explorer&lt;/a&gt;&lt;/p&gt;&lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=aD_E0q-x3ww" target="_blank" title="sysinternal's video"&gt;Video of How to use Sysinternal's/ Windows Process Explorer&lt;/a&gt;] &lt;/p&gt;&lt;p&gt;&lt;strong&gt; Removing              entry from windows startup&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                system                                                                                                                                                                                                                                                  configuration                                                can                                        be                                                                                                                    started                                        in                                                            xp                                                        and                                               in                                                                                                                                     vista                      by                                                                                                                     typing                                                                                                                                                                                 msconfig                               in                                                                                                                                                        the                                                run                                            box/                                                                                                   start                                                                        menu                                                                                              search                                                                                                                      box. &lt;br /&gt;In                                                                                                                                xp                        by                                                                                                                                                                  clicking            on                                                                                                                                                                                   Start                                                                                                                &amp;gt;                                                            run                      .                                                           The                                                                                                                  windows                                                                    startup                                                                                 is                                                                                                                                                       reversible.                                                                                                            You                                                         can                                                      check                                                 /                                                                                                                                                                                                                                              uncheck                                                                                  any                                                     entry                                                                       from                                                                                                     windows                                                                                                                                        startup                    any                                                                                                                                                      number                                   of                                                                                               times.             Watch    a                     video                     on   &lt;a href="http://www.youtube.com/watch?v=0HVaxH_k5W8" target="_blank" title="windows startup video"&gt;How to Use the Windows Startup&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Open                                                                                                                                                                                                                                                                                                                                                                                                                                                            system                                                                                                                                                                                                                configuration                                                                                                                                                window.Click                                                                                  on                                                                 the                                                                                                                                                                                                                            Startup                                                                                                                 tab.                                                    You                                                           will                                                  see                             a                                                                                       list                                      all                                                            the                                                                                                                        programs                                                                                                     that                                          are                                                                                                                                                                          scheduled                                                                                                                                                                              to                                                                                   start                          with                                                                                                                                                      windows.                                                                  Expand                                                                                            the                                                                                                     middle                                                                                                                                                                                                                  column                                                                                       using                                                                                      your                                                                             mouse                                                                                               pointer.                                                                                                         That                                                    will                                                                           show                                                                    you                                              the                                                                                                                                                            full                                                                  path                                                                                         of                             the                                                                                                                                                      program.                                                                                                              Locate                                                                 and                                                                                                                             uncheck                                                                                      the                                                                                                   boxes                                                              in                                                                                                                           front                of                                                                                                                                       these                                                                                                                          names                                                                                           "torrent.exe"                                                                                                                              (also                                                   look                                              for                                                                                                                                                             any                                                                                                 other                                                                                                                                                                                                                                      suspicious                                                                                          names)Press                                                                                                                               Apply                       ,                                                                                                                                                     Press                                                                                                                                                         Close/Ok             ,                                                                                                                                                                              Select                                                                                                                    "restart"                                                                  at                     the                                                                                      next                         prompt.&lt;/p&gt;&lt;strong&gt; Deleting          files&lt;/strong&gt; &lt;p&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   computer                                         will                                                                                                                restart                                                                         now.                                                                                                                                                                        Delete                                                                          the                                                                                                                                                                                       following                                                                                                 files                                                           and                                                                                                                                           folders.                                                       Boot                                       in                                                                  safe                                                      mode                                                                             or                                                                                                                                              boot                                                        in                                                        the                                                                                                                     dos                                                              prompt                                                                                 if                                                                                                          needed.               You                                                                                                  can                             use                                                                                                                windows                                                                                                             search                                                                                                                              utility                                                                                                                                  to                                                                                                                      search                                                                                                        for                                                                                                                                                  torrent.exe&lt;/p&gt; &lt;p&gt;&lt;em&gt;Files&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%AppData%\Microsoft\torrent.exe&lt;br /&gt;C:\windows\system32\clean.bat&lt;br /&gt;&lt;br /&gt;Folders&lt;br /&gt;&lt;/em&gt;&lt;em&gt;-&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Files  in Temp folder&lt;br /&gt;-&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Installer File&lt;/em&gt;&lt;br /&gt;[file                 and pathname of the sample #1]&lt;/p&gt;&lt;p&gt;You can find full path of the folders for your version of windows &lt;a href="http://comprolive.com:80/remove/folders" title="common folders"&gt; on this link&lt;/a&gt;.   &lt;/p&gt; &lt;p&gt;(We                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           do                                                                        not                                                                               know                                          the                                                        name                                     or                                                   the                                                                                                                          location                                               of                                                                                                                      sample                                                                           #1,                                                     it                                                                                                                      could                                                                     be                                       in                                                                                      your                                                                                                                                                 default                                                                                                                                                                          download                                                                                            location                                             or                                                           on                                                the                                                                                                                                                                                     desktop                         or                                                      in                  a                                                                    Temp                                                                                                                                                                                folder.                                              The                                                                                                    files                                                and                                                                                                                                                                 folders                                        in                                                                 the                                                                                                Temp                                                                    folder                                                                             can                                                             be                                                                                                                                                                                                                                                   automatically                                                                                                                          removed,                                                                           if                                                              you                                            use                 a                                                                                                                                                                                                                                               freeware                                                                                    temp                                                                              files/                                                                                                     registry                                                                                                                                                      cleaner                                                                                                                                                              software                                               like                                                                                                                                                                                                                                CCleaner)&lt;/p&gt;&lt;h3&gt;Some Common folder locations &lt;/h3&gt;&lt;p&gt;Virus makes create their files in uncommon locations. You can find such locations&lt;a href="http://comprolive.com:80/remove/folders" title="common folders"&gt; on this link&lt;/a&gt;.  &lt;/p&gt;&lt;p&gt;These                                              are the folders where you      should      find     sub         folders    of            legitimate                    programs.  If    you  find   any      files  (exe,    dll        etc)  at             this      location,    they                should  be    treated           suspiciously.      The   other          thing   to     look     out    for  is                    randomly  named     folders.  &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Repair Hosts File&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;To repair/ edit the hosts file. Login as administrator. open  the following file in notepad&lt;br /&gt; C:\ WINDOWS \system32 \drivers \etc \hosts&lt;br /&gt;remove anything other than 127.0.0.1 Localhost, and save and close the file.&lt;/p&gt;&lt;p&gt; &lt;strong&gt;Registry            Keys&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;There                are several registry modifications done by this virus.  You     can     see     the   registry modifications in the report from  the   link    above.&lt;/p&gt;&lt;strong&gt; Using  CCleaner&lt;/strong&gt; &lt;p&gt;You                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          can                                                                                                                                             easily                                                                               remove                                        the                                                                       files                                                     in                                               the                                              temp                                                                                                                              folder                                              by                                                                                                                     running                                                                                                                                                                                                                  CCleaner.                                                                                                                You                                              can                                                                      set                                                                                                                                                                   CCleaner                                      to                                           run                                                                                                                                                                                                                      automatically                                                 each                                                                                                             time                                                                           the                                                                                                                               computer                                                                                                                                                                                                         starts.                                    Do                                                             not                                                                                                                                                                     forget                  to                             run                                                              CCleaner                                                                                                                                        &amp;gt;                                                                                                                                                                                                            Registry                                                                               menu                  to                                                                             remove                                                                                                                   the                                                                                                                               obsolete                                                                                                                                                     registry                                                                                                                                                                              entries.&lt;/p&gt; &lt;p&gt;more    about    CCleaner &lt;a href="http://comprolive.com:80/remove/../free/software/system-optimizer/ccleaner" target="_blank" title="CCleaner"&gt;on this link&lt;/a&gt;&lt;/p&gt;&lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt;Video on how to use CCleaner&lt;/a&gt;]  &lt;/p&gt; &lt;p&gt;&lt;strong&gt; Free     tools          to repair disabled &lt;span class="notranslate"&gt;folder options,              registry, Task Manager&lt;/span&gt; etc&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Whereas        you          can repair disabled Folder Options, disabled &lt;span class="notranslate"&gt;Registry     Tools, disabled Task Manager, Disabled             System Restore&lt;/span&gt; etc     using these free tools&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Tools        for&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/enable-registry-tools-in-vista" target="_blank" title="tools for windows Vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools              for &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-run-command-task-manager-and-registry-tools-in-xp" target="_blank" title="tools for windows XP"&gt;Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools          for &lt;a href="http://comprolive.com:80/remove/../howto/windows7/re-enable-disabled-tools-in-windows7" target="_blank" title="re-enable tool for Windows7"&gt;Windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt; Use              the &lt;span class="notranslate"&gt;System    File Checker&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;To              repair altered deleted or modified windows system    files.&lt;/p&gt; &lt;ul&gt;&lt;li&gt;How              to run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility                 in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/system-file-checker-in-xp" target="_blank" title="system file checker in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How  to             run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility              in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system file checker in vista"&gt; windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to run System File Checker utility in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-file-checker-in-windows7" target="_blank" title="System File Checker in Windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;Additional Information &lt;/strong&gt;&lt;br /&gt; Virus                                                                                                                                                                           infections         are                        complex.                Most            of           the                           times    a                          virus           on                         the                                                  computer                                     downloads                     more            files                    and                      make       it                                              complicated.       In                       my                                            attempt  to                  warn                                  users                           about                the                                   different          ways                         that                         viruses           are                                     trying       to                             infect                       and                                          ways        to             find        them              and                                remove,   I                          have                                      created              videos           on                                                  specific         Free                             tools         and                                    manual                                        methods,                   these                         videos                                could           be                  of              great                 help&lt;br /&gt;&lt;p&gt;1) To detect and remove malicious Alternate Data Streams - &lt;a href="http://www.youtube.com/watch?v=njAjGiSp98o" target="_blank" title="stream armour"&gt;Stream Armour  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) To detect and remove malicious Services -&lt;a href="http://www.youtube.com/watch?v=uCTUvgTHVsU" target="_blank" title="Advanced Winservice manager"&gt; Advanced WinService Manager  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) To detect and remove viruses in Fake recycle Bin - &lt;a href="http://www.youtube.com/watch?v=NfMtz3vzr3A" target="_blank" title="Fake recycle bin"&gt;Watch Video  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) keep an eye on suspicious connections using a Firewall  - &lt;a href="http://www.youtube.com/watch?v=W1qtOrQMfyk" target="_blank" title="comodo firewall video"&gt;Free Comodo Firewall &lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) A free tool to detect and remove unwanted BHOs - &lt;a href="http://www.youtube.com/watch?v=sU_hY1r26_g" target="_blank" title="spyBHO remover video"&gt;SpyBHO Remover  &lt;/a&gt;&lt;/p&gt;&lt;p&gt;6) A     free tool  from  Microsoft to reset  the IE settings -  on &lt;a href="http://support.microsoft.com/kb/923737" target="_blank" title="mskb923737"&gt;Microsoft's website    &lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;  Reprinted              with    permission from Threatexpert.com   &lt;/p&gt; &lt;p&gt; &lt;a href="http://comprolive.com:80/remove/about-this-site" target="_blank" rel="author"&gt;Sanjay C Rajure&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/KWApFep6cx8p6ONDUtOF0qXq7Cg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KWApFep6cx8p6ONDUtOF0qXq7Cg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/KWApFep6cx8p6ONDUtOF0qXq7Cg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KWApFep6cx8p6ONDUtOF0qXq7Cg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/removalguides/~4/AzC5RpvvfSg" height="1" width="1"/&gt;</description>
			<category>frontpage</category>
			<pubDate>Tue, 14 Feb 2012 07:57:38 +0000</pubDate>
		<feedburner:origLink>http://comprolive.com/remove/trojan/generic/torrent-exe</feedburner:origLink></item>
		<item>
			<title>UpSysGrade.exe</title>
			<link>http://feedproxy.google.com/~r/removalguides/~3/xbgO7LPhvT8/upsysgrade-exe</link>
			<description>&lt;p&gt;The name UpSysGrade.exe &lt;strong&gt; &lt;/strong&gt;               has                             appeared       in        a                                                                                                                                                                                          virus                                                                                                                                                                                                                                                                                                                                                                                               analysis                                                                                                                                    report.                            You                      can                                                                                         see                                              it                                                     &lt;a href="http://www.threatexpert.com/report.aspx?md5=09758461d383bcd6944132c605073579" target="_blank" title="report"&gt;on this link&lt;/a&gt;&lt;/p&gt;        &lt;ul&gt;&lt;li&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      installer           is                   of                                                                 about  32 KB.               It could  be    a        virus       Trojan               Infostealer          Bancos/          Banker/Banbra. &lt;/li&gt;&lt;li&gt;It                                    has  threat     characteristics of ZBot  -  a          banking        trojan         that            disables        firewall,     steals      sensitive         financial     data          (credit   card            numbers,        online      banking      login     details),       makes       screen           snapshots,            downloads        additional           components,   and         provides a         hacker     with  the             remote   access    to the               compromised     system.&lt;/li&gt;&lt;li&gt;It may stop services ALG/ Application Layer Gateway Service, SharedAccess/ Windows Firewall/Internet Connection Sharing (ICS)&lt;/li&gt;&lt;li&gt;Trojan.Bancos                                                    runs silently in the           background    to         monitor     web         browser                            activities.       It    can      create  fake     login       page            for   certain        banking           sites          which    is       used    for     stealing         usernames    and            passwords                 which       can be     sent         to  the             attacker     via       e-mail.&lt;/li&gt;&lt;li&gt;It may modify the hosts file so as to redirect or block sites. Or it deletes the hosts file.&lt;/li&gt;&lt;li&gt;It                                          may delete safeboot registry    keys.      This      will         prevent     the          computer         from        starting   in    safe   mode.   The     remedy  to     this         problem         is to         reinstall         windows. &lt;/li&gt;&lt;li&gt;According              to      Symantec &lt;em&gt;           &lt;br /&gt;&lt;br /&gt;&lt;/em&gt;The                                                    Trojan is most often       spread    by     way    of    an       email            containing   a                 social                  engineering   trick     such  as   a        fake           email   from a    bank           asking         the     user       to          run  the        attached              program   and     perform     some        other            actions to           verify           their             banking     details.    If     the      user        complies             with    the     request        they            could            potentially         reveal   their           account              access        information           which      may    lead   to                  significant       financial    loss.&lt;br /&gt;&lt;br /&gt;You   can  read the the   writeup at   Symantec &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-071710-2826-99&amp;tabid=2" target="_blank" title="Symantec writeup"&gt;on this link&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;     &lt;p&gt;                                                                                                                                                                                                                                                                                                                                       It                                                                                  creates        UpSysGrade.exe                                                  and                                         other                     files             on                                                                               the                                                                                                                                                                                 infected                                                                                                   computer                                                                                                                                            that                                         you                                                                          need                                                                                         to                                                                                                                                                                  search                                                and                                                                                                       delete.   You    should also remove   the entries  of  these  files   from the  windows     startup. &lt;/p&gt;       &lt;p&gt;Warning:                                                                                                                   It                is                     possible           that  some                       legitimate                             software          may        be                                using           the                 same                                              file                      names           as          that      of      the             virus                     files.                     You            do            not            have                    to                                    delete               these                files                  if                     they             belong               to              some                                     legitimate                  program                                      installed           on                    your                                        computer.                          Use                      Windows                    Defender               or                                 SysInternals                         Process                                                  Explorer     to                                                      differentiate             between                                 them.                  The                                               information   in           this                      article            is                                                  presented                without                                        making            any              claims                         regarding                its                                             usefulness   or                                                      otherwise.        If      you    have            any                      objections             or           questions,                            please            send   a             note      by                                                         adding a                                     comment    at         the          end           of                          this      page,     or                mail    on                                                                                                          support(at)comprolive.com &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Preventive measures&lt;/strong&gt;&lt;/p&gt;     &lt;ul&gt;&lt;li&gt;                                                           Most of  the                         viruses           enter        your                                               computer                      when          you                 visit                        some                  harmful                                 website.                     If          you               use  a                             browser                                   plugin          that                        warns                  you                 about                                 harmful                        websites,   you                           can                           prevent                      this                     from                                 happening. A                                           popular                      browser                   plugin              is                    called              Web                     Of          Trust                                   (WOT),         you                                can                        install   it             from                    its                       website  &lt;a href="http://www.mywot.com/" target="_blank" title="WOT "&gt;on this link&lt;/a&gt;. &lt;br /&gt;[ &lt;a href="http://www.youtube.com/watch?v=8DHx7wioFuM" target="_blank" title="WOT video"&gt;a video about WOT plugin &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Blocking                                       Javascript of all sites by default     can      help    to         prevent       drive    by            download        infections.  You   can   use       Noscript   Plugin       for     firefox       as             explained&lt;a href="http://www.youtube.com/watch?v=IMPHD5dkCAA" target="_blank" title="Noscript video"&gt; in this video&lt;/a&gt;.                                        Similar functionality can be    achieved    in          Google's          Chromium         browser          using  the     settings   in       Preferences   &amp;gt;       Under the      Hood    &amp;gt;         Content               Settings &amp;gt; Java      Script    &amp;gt;      Select   "Do    not     Allow".           After that    when           you  visit a       site,   you   will see a    pop          up  next to      the   address       bar   asking         you   if    you   want  to       allow    JavaScript    to   run      for    that         particular      site.          The    author  of     NoScript is         writing a          similar   plugin        for   IE9  called               GoodScript.    Keep  an eye     on    when it         becomes           available.  &lt;/li&gt;&lt;li&gt;Some                                                                                                of      the         viruses   are                        downloaded          in                         Internet               Cache        or     in                 the                          Temp                           folder            of       the            windows.             The                  viruses                   get                activated           when                     these                       files            are                              executed.             You       can                reduce               the         risk           of             virus                       infection                   if          you              empty                 your                browser                                 cache and                     remove          windows                     temp                 files                                    ocasionally,                          ideally         at        the              end     of       a                           browsing                  session           or                    before                            closing       down       your                                   computer.                   Some            programs                                 like            CCleaner           can  be          set                       to        do               these           things                                                  automatically. [&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt; a video about CCleaner &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Do                                                       not leave your      computer          infected     and           insecure.    If     you            doubt           that             there       could  be         some      undetected       virus      on      your          computer,              don't    leave           it       like        that.   Format          the     hard    disk       and         reinstall               windows   and      all        other               programs.    That       is   the            sure      way to    clear              doubts.    &lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt; Using System Restore&lt;/strong&gt;   &lt;p&gt;If                                                                                                                                                                                                                                                 you                              know           the                                      duration                           since                            your                                                    computer               is                                                                         infected,                     you                                              can                             try                   to                                                                          restore                  your                             computer                  at a                                                                  prior               date,                                 that                                             will               be                         an                  easy                          way                                         to                    undo                                 the                                                                  changes          done      by                         the                                                       virus&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Using        system   restore   in  &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-system-restore-in-xp" target="_blank" title="system restore in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using system restore                 in  &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system restore in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using          system restore in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-restore-in-windows7" target="_blank" title="System Restore in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [ &lt;a href="http://www.youtube.com/watch?v=bhGrVLPIKXY" target="_blank" title="system restore video"&gt;Video of How to use System Restore&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Boot              in safe mode&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Sometimes    you can not        delete  a      file. You should boot in safe mode and then try    to        delete it.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How       to boot in safe in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/boot-in-safe-mode-in-xp" target="_blank" title="safe mode in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to boot in safe mode                 in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/boot-in-safe-mode-in-vista" target="_blank" title="safe mode in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to boot in safe mode in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/boot-in-safe-mode-in-windows7" target="_blank" title="safeboot in windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt;  View              Hidden Files&lt;/strong&gt;&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;You need to enable                 to view hidden files and folders before searching.&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-to-view-hidden-files-in-xp" target="_blank" title="view hidden files in xp"&gt; Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/view-hidden-files-in-vista" target="_blank" title="view hidden files in vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How         to Enable to View Hidden Files  and Folders in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/view-hidden-files-in-windows7" target="_blank" title="Enable to view hidden files in Windows7"&gt;Windows7             &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [&lt;a href="http://www.youtube.com/watch?v=0ahhDa_bp0A" target="_blank" title="Enable Hidden Files video "&gt; Video of How to enable Hidden files and folders&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Remove             Processes from &lt;span class="notranslate"&gt;Task Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;     Press              Ctrl Alt Del keys to open the &lt;span class="notranslate"&gt;Task          Manager&lt;/span&gt;.                              Select                                                                                                                                                                                                         Processes                    tab.                           You                                             will                see      a                                      list.                           Look                        for                                                               the   names  UpSysGrade.exe                    in                it.                                         Select               if                           found                                            any  and                                              press                                                      the                                     End                                Process                   button.                                It                      will          ask                            for                                        your                                                                   confirmation                                           to                                   end                                              that                                           process.                                Select                    Yes.                 You                          can                                            end                               one                               process                                at    a                                              time.                            You                                                                                                                                                                                                                                                                                                      can                               find                                                                        out                           if  a                                                                             process                       in  &lt;span class="notranslate"&gt;Task                       Manager&lt;/span&gt;     is      good                     or        bad  by  using  &lt;span class="notranslate"&gt;Windows                                Defender in  XP and Vista&lt;/span&gt;.                                                                                                                                                                                                                                                                                           It                                            shows                                                                     the                                                                                                                        path                                      of         a                                                                                                                            process                                  and                                               its                                                                                                                                                          publisher.                                                                      Harmful                                                                                                                                                                                                                                     processes                                                         may                                         be                                                                              shown                                                                       under                                                                                Unknown                                                                                                                           Publisher                                      in                                                           &lt;span class="notranslate"&gt;windows                             defender&lt;/span&gt;.  Whereas in Windows7 you  can find that out from the task manager itself. You can watch a video on How to use &lt;a href="http://www.youtube.com/watch?v=TxE8zS9iiSI" target="_blank" title="Windows Defender video"&gt;Windows Defender&lt;/a&gt;. &lt;br /&gt;     &lt;ul&gt;&lt;li&gt;How           to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-windows-defender-in-xp" target="_blank" title="windows defender in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-windows-defender-in-vista" target="_blank" title="windows defender in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to use Windows Defender in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/use-windows-defender-in-windows7" target="_blank" title="Use Windows Defender in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;     &lt;p&gt; Or                 you can use &lt;span class="notranslate"&gt;Sysinternal's    Process          Explorer&lt;/span&gt;. How  to use      Sysinternal's &lt;a href="http://comprolive.com:80/remove/../free/software/system-tools/process-explorer" target="_blank" title="sysinternal's process explorer"&gt;Process Explorer&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=aD_E0q-x3ww" target="_blank" title="sysinternal's video"&gt;Video of How to use Sysinternal's/ Windows Process Explorer&lt;/a&gt;] &lt;/p&gt;     &lt;p&gt;&lt;strong&gt; Removing              entry from windows startup&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;The                                                                                                                                                                                                                                   system                                                                                             configuration                 can               be                                             started              in                        xp                     and                  in                                                    vista        by                                             typing                                                                      msconfig          in                                                              the                  run                box/                                     start                          menu                                      search                                             box. &lt;br /&gt;In                                                xp         by                                                             clicking     on                                                                       Start                                            &amp;gt;                       run         .                     The                                             windows                       startup                               is                                                          reversible.                                         You                        can                    check                  /                                                                                               uncheck                               any                   entry                           from                                       windows                                                  startup         any                                                       number                of                                 times.     Watch  a      video     on &lt;a href="http://www.youtube.com/watch?v=0HVaxH_k5W8" target="_blank" title="windows startup video"&gt;How to Use the Windows Startup&lt;/a&gt;&lt;/p&gt;       &lt;p&gt;Open                                                                                                                                                                system                                                                               configuration                                                    window.Click                               on                        the                                                                                        Startup                                             tab.                    You                     will                  see              a                                list              all                       the                                             programs                                        that              are                                                                  scheduled                                                                      to                                 start         with                                                       windows.                       Expand                                     the                                     middle                                                                                    column                                 using                                your                             mouse                                     pointer.                                        That                     will                        show                              you                the                                                               full                         path                                  of          the                                                            program.                                        Locate                        and                                                uncheck                                  the                                     boxes                          in                                               front        of                                                  these                                               names                                 "UpSysGrade.exe"                                                   (also                  look                    for                                                            any                                      other                                                                                        suspicious                             names)Press                                                  Apply         ,                                                              Press                                                         Close/Ok     ,                                                                    Select                                      "do   not     restart"                             at      the                             next       prompt.&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;modified services&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;                                While      still  in the above window,   click   on         Services      tab.     Click    on      "Hide     All         Microsoft        Services".  Look    for   ALG/     Application           Layer     Gateway           Service,     SharedAccess/  Windows              Firewall/Internet          Connection    Sharing        (ICS).   If   they     are        checked,  then       do nothing. If  they     are     unchecked        then  you  need   to      check          them  again.  &lt;/p&gt;     &lt;p&gt;Locate          and Check  the  box      in           front of      these      services  if they    are      unchecked.     Press   Apply.     Press             Ok/close.  Click  on            "restart"   at    the   next      prompt.    &lt;/p&gt;    &lt;strong&gt; Deleting          files&lt;/strong&gt;   &lt;p&gt;The                                                                                                                                                                                                                   computer                will                                        restart                            now.                                                            Delete                                   the                                                                        following                                   files                         and                                                 folders.                     Boot                   in                   safe                       mode                             or                                                            boot               in                             the                                            dos                prompt                                       if                                     needed.      You                                    can               use                                         windows                                            search                                          utility                                                        to                                           search                                          for         UpSysGrade.exe&lt;/p&gt;       &lt;p&gt;&lt;em&gt;Files&lt;br /&gt;  C:\windows\system32\AvAtualizacao.exe&lt;br /&gt;C:\windows\system32\AvMaster.exe&lt;br /&gt;C:\windows\system32\AVSCD1A40%ComputerName%.log&lt;br /&gt;C:\windows\system32\SysGrade.exe&lt;br /&gt;C:\windows\system32\SysUpGrade.exe&lt;br /&gt;C:\windows\system32\UpSys.exe&lt;br /&gt;C:\windows\system32\UpSysGrade.exe&lt;/em&gt;&lt;/p&gt;Folders&lt;br /&gt;&lt;p&gt;&lt;em&gt;-&lt;/em&gt;&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Files in Temp folder&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%Temp%\80EB2F5C&lt;/em&gt;&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Installer File&lt;/em&gt;&lt;br /&gt;[file                 and pathname of the sample #1]&lt;/p&gt;       &lt;p&gt;(We                                                                                                                                                                                                                                   do                             not                             know                 the                     name             or                   the                                              location                  of                                             sample                              #1,                     it                                              could                          be              in                                    your                                                       default                                                                 download                                  location                or                      on                    the                                                                      desktop        or                        in      a                        Temp                                                                    folder.                  The                                        files                  and                                                              folders                 in                     the                                       Temp                          folder                            can                          be                                                                                            automatically                                            removed,                               if                       you                use       a                                                                                             freeware                                temp                              files/                                      registry                                                        cleaner                                                             software                   like                                                                                       CCleaner)&lt;br /&gt;&lt;em&gt;Folders&lt;/em&gt;&lt;br /&gt;-&lt;/p&gt;    &lt;strong&gt;Repair Hosts File&lt;/strong&gt;  &lt;p&gt;To repair/ edit the hosts file. Login as administrator. open  the following file in notepad&lt;br /&gt; C:\ WINDOWS \system32 \drivers \etc \hosts&lt;br /&gt;remove anything other than 127.0.0.1 Localhost, and save and close the file.&lt;/p&gt;     &lt;p&gt; &lt;strong&gt;Registry            Keys&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;Some                                                                                                                                                                                                                 of           the                            registry                   keys                          will                  be                                                                                                                                         automatically                                               removed                        if                     you         run                                                               Registry                         menu           of                                                                   CCleaner.                           For                                                                                  others                   you                     can                     see              the                           report                                                               mentioned                         at           the                                                                      beginning                                           of                     this                                                               article         .&lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Using  CCleaner&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;You                                                                                                                                                                                                                  can                                                      easily                                remove               the                        files                       in               the                 temp                                                   folder               by                                              running                                                                                CCleaner.                                             You                   can                       set                                                                CCleaner             to                  run                                                                               automatically                    each                                         time                             the                                                computer                                                                                 starts.            Do                         not                                                               forget        to          run                CCleaner                                                      &amp;gt;                                                                                   Registry                             menu        to                             remove                                          the                                                obsolete                                                            registry                                                                  entries.&lt;/p&gt;       &lt;p&gt;more    about    CCleaner &lt;a href="http://comprolive.com:80/remove/../free/software/system-optimizer/ccleaner" target="_blank" title="CCleaner"&gt;on this link&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt;Video on how to use CCleaner&lt;/a&gt;]  &lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Free     tools          to repair disabled &lt;span class="notranslate"&gt;folder options,              registry, Task Manager&lt;/span&gt; etc&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Whereas        you          can repair disabled Folder Options, disabled &lt;span class="notranslate"&gt;Registry     Tools, disabled Task Manager, Disabled             System Restore&lt;/span&gt; etc     using these free tools&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Tools        for&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/enable-registry-tools-in-vista" target="_blank" title="tools for windows Vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools              for &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-run-command-task-manager-and-registry-tools-in-xp" target="_blank" title="tools for windows XP"&gt;Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools          for &lt;a href="http://comprolive.com:80/remove/../howto/windows7/re-enable-disabled-tools-in-windows7" target="_blank" title="re-enable tool for Windows7"&gt;Windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt; Use              the &lt;span class="notranslate"&gt;System    File Checker&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;To              repair altered deleted or modified windows system    files.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How              to run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility                 in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/system-file-checker-in-xp" target="_blank" title="system file checker in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How  to             run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility              in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system file checker in vista"&gt; windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to run System File Checker utility in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-file-checker-in-windows7" target="_blank" title="System File Checker in Windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt;Additional Information &lt;/strong&gt;&lt;br /&gt;                                 Virus                   infections are          complex.      Most of     the       times  a     virus on    the                   computer                downloads  more      files    and     make      it        complicated.    In    my           attempt   to       warn               users     about  the         different     ways    that      viruses        are           trying  to       infect     and                ways to  find    them    and        remove, I        have           created       videos   on          specific    Free         tools     and        manual             methods,     these         videos      could  be  of        great    help&lt;br /&gt;     &lt;p&gt;1) To detect and remove malicious Alternate Data Streams - &lt;a href="http://www.youtube.com/watch?v=njAjGiSp98o" target="_blank" title="stream armour"&gt;Stream Armour  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;2) To detect and remove malicious Services -&lt;a href="http://www.youtube.com/watch?v=uCTUvgTHVsU" target="_blank" title="Advanced Winservice manager"&gt; Advanced WinService Manager  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;3) To detect and remove viruses in Fake recycle Bin - &lt;a href="http://www.youtube.com/watch?v=NfMtz3vzr3A" target="_blank" title="Fake recycle bin"&gt;Watch Video  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;4) keep an eye on suspicious connections using a Firewall  - &lt;a href="http://www.youtube.com/watch?v=W1qtOrQMfyk" target="_blank" title="comodo firewall video"&gt;Free Comodo Firewall &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;5) A free tool to detect and remove unwanted BHOs - &lt;a href="http://www.youtube.com/watch?v=sU_hY1r26_g" target="_blank" title="spyBHO remover video"&gt;SpyBHO Remover &lt;/a&gt;&lt;/p&gt;&lt;h3&gt;&lt;strong&gt;If nothing works &lt;/strong&gt;&lt;/h3&gt;&lt;p&gt;More often a virus makes it difficult to remove its files while you are logged in windows. It may do one of the following&lt;/p&gt;&lt;p&gt;1) You may see the suspicious virus process running in the task manager but can not remove it. &lt;/p&gt;&lt;p&gt;2) Even if you delete a virus file/ or terminate the process, the process may spawn again.&lt;/p&gt;&lt;p&gt;3) The virus may disable system restore, registry tools, task manager, safe boot etc. &lt;/p&gt;&lt;p&gt;If                                                   any of these or other       things      done    by     the       virus      make     you              think/         feel           that   you   are   not     able to            remove the        virus     files         then   do   as            follows&lt;/p&gt;&lt;p&gt;1) Download a Knoppix Boot only CD ISO  image from in your language from one of the download links &lt;a href="http://www.knopper.net/knoppix/index-en.html" target="_blank" title="knpooix"&gt;from this website&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;2) Burn the ISO image on a blank CD &lt;/p&gt;&lt;p&gt;3) Put the Knoppix Boot disk in your computer's CD drive and boot from the CD&lt;/p&gt;&lt;p&gt;At the beginning of boot process you will see a prompt as boot:&lt;/p&gt;&lt;p&gt;Type&lt;br /&gt; knoppix screen=1280x1024&lt;br /&gt;knoppix screen=1024x728 or any suitable resolution that your computer supports. &lt;br /&gt;If                                                   you do not specify    screen             resolution,     the         knoppix      will         boot         with                  minimal     resolution   and   you        may   have    to     use              command  line         options         which    is                 inconvenient       for a    windows             user.  &lt;/p&gt;&lt;p&gt;Once               the    knoppix             window       opens,           click   on  the           folder  icon in        the        bottom       left of    the           screen     to       open    the               PCMan   file    manager.      It     is  a            graphical    file            manager   in                 Knoppix. It      has       two  panels.       In    the         left     panel   you       should        see        the           partitions of       your       hard      disk.           Select    the         partition   in                which   windows  is         installed   and           you      will              instantly  see     all    the            folders.   Now      you    can            access      the    contents    of          your         folders     and             delete       suspicious     files  and                folders   just   as     you           would    do      in    the       windows         explorer.   &lt;/p&gt;&lt;p&gt;When             you          are            finished.        Click     on   Log  off.     Now       you      can     Turn     Off or             restart.     Take        out         the     knoppix  CD      from your           drive        and      you     can        normally    boot  in                   windows.    &lt;/p&gt;&lt;p&gt;  Reprinted              with    permission from Threatexpert.com   &lt;/p&gt; &lt;p&gt; &lt;a href="http://comprolive.com:80/remove/about-this-site" target="_blank" rel="author"&gt;Sanjay C Rajure&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/L6LHoVbBguzLLsNxclFC4w5KxjI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/L6LHoVbBguzLLsNxclFC4w5KxjI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/L6LHoVbBguzLLsNxclFC4w5KxjI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/L6LHoVbBguzLLsNxclFC4w5KxjI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/removalguides/~4/xbgO7LPhvT8" height="1" width="1"/&gt;</description>
			<category>frontpage</category>
			<pubDate>Mon, 13 Feb 2012 09:03:47 +0000</pubDate>
		<feedburner:origLink>http://comprolive.com/remove/trojan/w32-bancos/upsysgrade-exe</feedburner:origLink></item>
		<item>
			<title>UpSys.exe</title>
			<link>http://feedproxy.google.com/~r/removalguides/~3/_Rzz1WYLGYU/upsys-exe</link>
			<description>&lt;p&gt;The name UpSys.exe &lt;strong&gt; &lt;/strong&gt;               has                            appeared       in        a                                                                                                                                                                                       virus                                                                                                                                                                                                                                                                                                                                                                                          analysis                                                                                                                                  report.                            You                     can                                                                                        see                                             it                                                     &lt;a href="http://www.threatexpert.com/report.aspx?md5=09758461d383bcd6944132c605073579" target="_blank" title="report"&gt;on this link&lt;/a&gt;&lt;/p&gt;        &lt;ul&gt;&lt;li&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           installer           is                   of                                                                about  32 KB.               It could be    a        virus       Trojan               Infostealer         Bancos/          Banker/Banbra. &lt;/li&gt;&lt;li&gt;It                                   has  threat     characteristics of ZBot  -  a          banking       trojan         that            disables        firewall,     steals     sensitive         financial     data          (credit   card           numbers,        online      banking      login     details),      makes       screen           snapshots,            downloads       additional           components,   and         provides a         hacker    with  the             remote   access    to the              compromised     system.&lt;/li&gt;&lt;li&gt;It may stop services ALG/ Application Layer Gateway Service, SharedAccess/ Windows Firewall/Internet Connection Sharing (ICS)&lt;/li&gt;&lt;li&gt;Trojan.Bancos                                                   runs silently in the          background    to         monitor     web         browser                           activities.       It    can      create  fake    login       page            for   certain        banking           sites         which    is       used    for     stealing         usernames   and            passwords                 which       can be     sent        to  the             attacker     via       e-mail.&lt;/li&gt;&lt;li&gt;It may modify the hosts file so as to redirect or block sites. Or it deletes the hosts file.&lt;/li&gt;&lt;li&gt;It                                         may delete safeboot registry   keys.      This      will         prevent     the          computer        from        starting   in    safe   mode.   The     remedy  to    this         problem         is to         reinstall         windows. &lt;/li&gt;&lt;li&gt;According              to      Symantec &lt;em&gt;           &lt;br /&gt;&lt;br /&gt;&lt;/em&gt;The                                                   Trojan is most often      spread    by     way    of    an       email            containing  a                 social                  engineering   trick     such as   a        fake           email   from a    bank           asking        the     user       to          run  the        attached             program   and     perform     some        other            actions to          verify           their             banking     details.    If    the      user        complies             with    the     request       they            could            potentially         reveal   their          account              access        information           which     may    lead   to                  significant       financial    loss.&lt;br /&gt;&lt;br /&gt;You   can  read the the   writeup at   Symantec &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-071710-2826-99&amp;tabid=2" target="_blank" title="Symantec writeup"&gt;on this link&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;     &lt;p&gt;                                                                                                                                                                                                                                                                                                                                  It                                                                                 creates        UpSys.exe                                                 and                                        other                     files             on                                                                              the                                                                                                                                                                              infected                                                                                                  computer                                                                                                                                          that                                        you                                                                         need                                                                                        to                                                                                                                                                               search                                                and                                                                                                     delete.   You    should also remove   the entries of  these  files   from the  windows     startup. &lt;/p&gt;       &lt;p&gt;Warning:                                                                                                                 It                is                    possible           that  some                       legitimate                            software          may        be                               using           the                 same                                             file                      names          as          that      of      the             virus                    files.                     You            do            not           have                    to                                    delete              these                files                  if                    they             belong               to              some                                    legitimate                  program                                     installed           on                    your                                       computer.                         Use                      Windows                    Defender              or                                 SysInternals                        Process                                                  Explorer    to                                                      differentiate            between                                 them.                 The                                               information   in          this                      article            is                                                 presented                without                                       making            any              claims                        regarding                its                                            usefulness   or                                                     otherwise.        If      you    have            any                     objections             or           questions,                           please            send   a             note      by                                                        adding a                                    comment    at         the          end          of                          this      page,     or                mail   on                                                                                                         support(at)comprolive.com &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Preventive measures&lt;/strong&gt;&lt;/p&gt;     &lt;ul&gt;&lt;li&gt;                                                          Most of  the                        viruses           enter        your                                              computer                      when         you                 visit                        some                 harmful                                 website.                     If         you               use  a                             browser                                  plugin          that                       warns                  you                 about                                harmful                        websites,   you                          can                           prevent                      this                    from                                 happening. A                                          popular                     browser                   plugin              is                   called              Web                     Of          Trust                                  (WOT),         you                               can                        install   it             from                   its                       website  &lt;a href="http://www.mywot.com/" target="_blank" title="WOT "&gt;on this link&lt;/a&gt;. &lt;br /&gt;[ &lt;a href="http://www.youtube.com/watch?v=8DHx7wioFuM" target="_blank" title="WOT video"&gt;a video about WOT plugin &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Blocking                                      Javascript of all sites by default    can      help    to         prevent       drive    by           download        infections.  You   can   use       Noscript   Plugin      for     firefox       as             explained&lt;a href="http://www.youtube.com/watch?v=IMPHD5dkCAA" target="_blank" title="Noscript video"&gt; in this video&lt;/a&gt;.                                       Similar functionality can be   achieved    in          Google's          Chromium         browser         using  the     settings   in       Preferences   &amp;gt;       Under the     Hood    &amp;gt;         Content               Settings &amp;gt; Java     Script    &amp;gt;      Select   "Do    not     Allow".           After that   when           you  visit a       site,   you   will see a    pop         up  next to      the   address       bar   asking         you   if   you   want  to       allow    JavaScript    to   run      for    that        particular      site.          The    author  of     NoScript is        writing a          similar   plugin        for   IE9  called              GoodScript.    Keep  an eye     on    when it         becomes          available.  &lt;/li&gt;&lt;li&gt;Some                                                                                               of      the        viruses   are                        downloaded          in                        Internet               Cache        or     in                the                          Temp                           folder           of       the            windows.             The                 viruses                   get                activated           when                    these                       files            are                             executed.             You       can               reduce               the         risk           of             virus                      infection                   if          you             empty                 your                browser                                cache and                     remove          windows                    temp                 files                                   ocasionally,                          ideally         at        the             end     of       a                           browsing                 session           or                    before                           closing       down       your                                  computer.                   Some            programs                                like            CCleaner           can  be          set                      to        do               these           things                                                 automatically. [&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt; a video about CCleaner &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Do                                                      not leave your     computer          infected     and           insecure.    If     you           doubt           that             there       could  be        some      undetected       virus      on      your          computer,             don't    leave           it       like        that.   Format         the     hard    disk       and         reinstall              windows   and      all        other               programs.    That      is   the            sure      way to    clear              doubts.    &lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt; Using System Restore&lt;/strong&gt;   &lt;p&gt;If                                                                                                                                                                                                                                             you                              know           the                                     duration                          since                            your                                                   computer               is                                                                        infected,                    you                                              can                            try                   to                                                                         restore                  your                            computer                  at a                                                                 prior               date,                                that                                            will               be                         an                  easy                         way                                         to                   undo                                 the                                                                 changes          done     by                         the                                                      virus&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Using        system   restore   in  &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-system-restore-in-xp" target="_blank" title="system restore in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using system restore                 in  &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system restore in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using          system restore in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-restore-in-windows7" target="_blank" title="System Restore in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [ &lt;a href="http://www.youtube.com/watch?v=bhGrVLPIKXY" target="_blank" title="system restore video"&gt;Video of How to use System Restore&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Boot              in safe mode&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Sometimes    you can not        delete  a      file. You should boot in safe mode and then try    to        delete it.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How       to boot in safe in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/boot-in-safe-mode-in-xp" target="_blank" title="safe mode in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to boot in safe mode                 in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/boot-in-safe-mode-in-vista" target="_blank" title="safe mode in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to boot in safe mode in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/boot-in-safe-mode-in-windows7" target="_blank" title="safeboot in windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt;  View              Hidden Files&lt;/strong&gt;&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;You need to enable                 to view hidden files and folders before searching.&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-to-view-hidden-files-in-xp" target="_blank" title="view hidden files in xp"&gt; Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/view-hidden-files-in-vista" target="_blank" title="view hidden files in vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How         to Enable to View Hidden Files  and Folders in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/view-hidden-files-in-windows7" target="_blank" title="Enable to view hidden files in Windows7"&gt;Windows7             &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [&lt;a href="http://www.youtube.com/watch?v=0ahhDa_bp0A" target="_blank" title="Enable Hidden Files video "&gt; Video of How to enable Hidden files and folders&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Remove             Processes from &lt;span class="notranslate"&gt;Task Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;     Press              Ctrl Alt Del keys to open the &lt;span class="notranslate"&gt;Task          Manager&lt;/span&gt;.                             Select                                                                                                                                                                                                      Processes                    tab.                          You                                             will               see      a                                      list.                          Look                        for                                                              the   names  UpSys.exe                    in               it.                                         Select              if                           found                                           any  and                                              press                                                     the                                    End                                Process                  button.                                It                     will          ask                            for                                       your                                                                  confirmation                                           to                                  end                                             that                                           process.                               Select                    Yes.                 You                         can                                           end                               one                              process                                at    a                                             time.                            You                                                                                                                                                                                                                                                                                                  can                              find                                                                       out                           if  a                                                                            process                      in  &lt;span class="notranslate"&gt;Task                       Manager&lt;/span&gt;     is      good                     or        bad  by  using  &lt;span class="notranslate"&gt;Windows                                Defender in  XP and Vista&lt;/span&gt;.                                                                                                                                                                                                                                                                                       It                                           shows                                                                    the                                                                                                                      path                                      of         a                                                                                                                          process                                 and                                               its                                                                                                                                                       publisher.                                                                     Harmful                                                                                                                                                                                                                                  processes                                                        may                                         be                                                                            shown                                                                      under                                                                               Unknown                                                                                                                         Publisher                                      in                                                          &lt;span class="notranslate"&gt;windows                             defender&lt;/span&gt;.  Whereas in Windows7 you  can find that out from the task manager itself. You can watch a video on How to use &lt;a href="http://www.youtube.com/watch?v=TxE8zS9iiSI" target="_blank" title="Windows Defender video"&gt;Windows Defender&lt;/a&gt;. &lt;br /&gt;     &lt;ul&gt;&lt;li&gt;How           to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-windows-defender-in-xp" target="_blank" title="windows defender in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-windows-defender-in-vista" target="_blank" title="windows defender in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to use Windows Defender in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/use-windows-defender-in-windows7" target="_blank" title="Use Windows Defender in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;     &lt;p&gt; Or                 you can use &lt;span class="notranslate"&gt;Sysinternal's    Process          Explorer&lt;/span&gt;. How  to use      Sysinternal's &lt;a href="http://comprolive.com:80/remove/../free/software/system-tools/process-explorer" target="_blank" title="sysinternal's process explorer"&gt;Process Explorer&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=aD_E0q-x3ww" target="_blank" title="sysinternal's video"&gt;Video of How to use Sysinternal's/ Windows Process Explorer&lt;/a&gt;] &lt;/p&gt;     &lt;p&gt;&lt;strong&gt; Removing              entry from windows startup&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;The                                                                                                                                                                                                                               system                                                                                            configuration                 can              be                                             started             in                        xp                     and                 in                                                    vista        by                                            typing                                                                     msconfig          in                                                             the                 run                box/                                     start                         menu                                      search                                            box. &lt;br /&gt;In                                               xp         by                                                            clicking     on                                                                      Start                                           &amp;gt;                       run         .                    The                                             windows                      startup                               is                                                         reversible.                                        You                        can                    check                 /                                                                                              uncheck                              any                   entry                           from                                      windows                                                 startup         any                                                      number                of                                 times.    Watch  a      video     on &lt;a href="http://www.youtube.com/watch?v=0HVaxH_k5W8" target="_blank" title="windows startup video"&gt;How to Use the Windows Startup&lt;/a&gt;&lt;/p&gt;       &lt;p&gt;Open                                                                                                                                                             system                                                                              configuration                                                   window.Click                               on                       the                                                                                       Startup                                            tab.                    You                     will                 see              a                                list             all                       the                                            programs                                        that              are                                                                scheduled                                                                     to                                 start         with                                                      windows.                      Expand                                     the                                    middle                                                                                   column                                 using                               your                             mouse                                    pointer.                                       That                     will                        show                             you                the                                                              full                         path                                 of          the                                                           program.                                       Locate                        and                                               uncheck                                  the                                    boxes                          in                                              front        of                                                 these                                              names                                 "UpSys.exe"                                                  (also                  look                   for                                                            any                                     other                                                                                       suspicious                            names)Press                                                 Apply         ,                                                             Press                                                        Close/Ok     ,                                                                   Select                                      "do   not    restart"                             at      the                            next       prompt.&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;modified services&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;                               While      still  in the above window,  click   on         Services      tab.     Click    on      "Hide     All        Microsoft        Services".  Look    for   ALG/     Application          Layer     Gateway           Service,     SharedAccess/  Windows             Firewall/Internet          Connection    Sharing       (ICS).   If   they     are        checked,  then       do nothing. If they     are     unchecked        then  you  need   to      check         them  again.  &lt;/p&gt;     &lt;p&gt;Locate          and Check  the  box      in          front of      these      services  if they    are     unchecked.     Press   Apply.     Press             Ok/close.  Click  on           "restart"   at    the   next      prompt.    &lt;/p&gt;    &lt;strong&gt; Deleting          files&lt;/strong&gt;   &lt;p&gt;The                                                                                                                                                                                                                computer               will                                        restart                           now.                                                           Delete                                   the                                                                       following                                  files                         and                                                folders.                     Boot                  in                   safe                       mode                            or                                                           boot               in                             the                                           dos                prompt                                      if                                     needed.     You                                    can               use                                        windows                                           search                                          utility                                                       to                                          search                                          for        UpSys.exe&lt;/p&gt;       &lt;p&gt;&lt;em&gt;Files&lt;br /&gt;  C:\windows\system32\AvAtualizacao.exe&lt;br /&gt;C:\windows\system32\AvMaster.exe&lt;br /&gt;C:\windows\system32\AVSCD1A40%ComputerName%.log&lt;br /&gt;C:\windows\system32\SysGrade.exe&lt;br /&gt;C:\windows\system32\SysUpGrade.exe&lt;br /&gt;C:\windows\system32\UpSys.exe&lt;br /&gt;C:\windows\system32\UpSysGrade.exe&lt;/em&gt;&lt;/p&gt;Folders&lt;br /&gt;&lt;p&gt;&lt;em&gt;-&lt;/em&gt;&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Files in Temp folder&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%Temp%\80EB2F5C&lt;/em&gt;&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Installer File&lt;/em&gt;&lt;br /&gt;[file                 and pathname of the sample #1]&lt;/p&gt;       &lt;p&gt;(We                                                                                                                                                                                                                               do                             not                            know                 the                     name             or                  the                                              location                 of                                             sample                             #1,                     it                                             could                          be              in                                   your                                                      default                                                                download                                  location               or                      on                    the                                                                     desktop       or                        in      a                        Temp                                                                   folder.                 The                                        files                 and                                                             folders                 in                     the                                      Temp                          folder                           can                          be                                                                                           automatically                                           removed,                              if                       you                use       a                                                                                           freeware                                temp                             files/                                      registry                                                       cleaner                                                            software                   like                                                                                     CCleaner)&lt;br /&gt;&lt;em&gt;Folders&lt;/em&gt;&lt;br /&gt;-&lt;/p&gt;    &lt;strong&gt;Repair Hosts File&lt;/strong&gt;  &lt;p&gt;To repair/ edit the hosts file. Login as administrator. open  the following file in notepad&lt;br /&gt; C:\ WINDOWS \system32 \drivers \etc \hosts&lt;br /&gt;remove anything other than 127.0.0.1 Localhost, and save and close the file.&lt;/p&gt;     &lt;p&gt; &lt;strong&gt;Registry            Keys&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;Some                                                                                                                                                                                                              of          the                            registry                   keys                         will                  be                                                                                                                                       automatically                                              removed                        if                    you         run                                                              Registry                         menu           of                                                                  CCleaner.                          For                                                                                 others                   you                    can                     see              the                          report                                                              mentioned                         at           the                                                                     beginning                                          of                     this                                                              article         .&lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Using  CCleaner&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;You                                                                                                                                                                                                               can                                                     easily                               remove               the                        files                      in               the                 temp                                                  folder               by                                             running                                                                               CCleaner.                                            You                   can                      set                                                               CCleaner             to                  run                                                                              automatically                   each                                         time                            the                                               computer                                                                                starts.            Do                         not                                                              forget        to         run                CCleaner                                                     &amp;gt;                                                                                  Registry                             menu       to                             remove                                         the                                                obsolete                                                           registry                                                                 entries.&lt;/p&gt;       &lt;p&gt;more    about    CCleaner &lt;a href="http://comprolive.com:80/remove/../free/software/system-optimizer/ccleaner" target="_blank" title="CCleaner"&gt;on this link&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt;Video on how to use CCleaner&lt;/a&gt;]  &lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Free     tools          to repair disabled &lt;span class="notranslate"&gt;folder options,              registry, Task Manager&lt;/span&gt; etc&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Whereas        you          can repair disabled Folder Options, disabled &lt;span class="notranslate"&gt;Registry     Tools, disabled Task Manager, Disabled             System Restore&lt;/span&gt; etc     using these free tools&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Tools        for&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/enable-registry-tools-in-vista" target="_blank" title="tools for windows Vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools              for &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-run-command-task-manager-and-registry-tools-in-xp" target="_blank" title="tools for windows XP"&gt;Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools          for &lt;a href="http://comprolive.com:80/remove/../howto/windows7/re-enable-disabled-tools-in-windows7" target="_blank" title="re-enable tool for Windows7"&gt;Windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt; Use              the &lt;span class="notranslate"&gt;System    File Checker&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;To              repair altered deleted or modified windows system    files.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How              to run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility                 in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/system-file-checker-in-xp" target="_blank" title="system file checker in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How  to             run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility              in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system file checker in vista"&gt; windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to run System File Checker utility in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-file-checker-in-windows7" target="_blank" title="System File Checker in Windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt;Additional Information &lt;/strong&gt;&lt;br /&gt;                                Virus                   infections are         complex.      Most of     the       times  a     virus on    the                  computer                downloads  more      files   and     make      it        complicated.    In    my           attempt  to       warn               users     about  the         different    ways    that      viruses        are           trying  to       infect    and                ways to  find    them    and        remove, I       have           created       videos   on          specific    Free        tools     and        manual             methods,     these        videos      could  be  of        great    help&lt;br /&gt;     &lt;p&gt;1) To detect and remove malicious Alternate Data Streams - &lt;a href="http://www.youtube.com/watch?v=njAjGiSp98o" target="_blank" title="stream armour"&gt;Stream Armour  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;2) To detect and remove malicious Services -&lt;a href="http://www.youtube.com/watch?v=uCTUvgTHVsU" target="_blank" title="Advanced Winservice manager"&gt; Advanced WinService Manager  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;3) To detect and remove viruses in Fake recycle Bin - &lt;a href="http://www.youtube.com/watch?v=NfMtz3vzr3A" target="_blank" title="Fake recycle bin"&gt;Watch Video  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;4) keep an eye on suspicious connections using a Firewall  - &lt;a href="http://www.youtube.com/watch?v=W1qtOrQMfyk" target="_blank" title="comodo firewall video"&gt;Free Comodo Firewall &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;5) A free tool to detect and remove unwanted BHOs - &lt;a href="http://www.youtube.com/watch?v=sU_hY1r26_g" target="_blank" title="spyBHO remover video"&gt;SpyBHO Remover &lt;/a&gt;&lt;/p&gt;&lt;h3&gt;&lt;strong&gt;If nothing works &lt;/strong&gt;&lt;/h3&gt;&lt;p&gt;More often a virus makes it difficult to remove its files while you are logged in windows. It may do one of the following&lt;/p&gt;&lt;p&gt;1) You may see the suspicious virus process running in the task manager but can not remove it. &lt;/p&gt;&lt;p&gt;2) Even if you delete a virus file/ or terminate the process, the process may spawn again.&lt;/p&gt;&lt;p&gt;3) The virus may disable system restore, registry tools, task manager, safe boot etc. &lt;/p&gt;&lt;p&gt;If                                                  any of these or other      things      done    by     the       virus      make     you             think/         feel           that   you   are   not     able to           remove the        virus     files         then   do   as           follows&lt;/p&gt;&lt;p&gt;1) Download a Knoppix Boot only CD ISO  image from in your language from one of the download links &lt;a href="http://www.knopper.net/knoppix/index-en.html" target="_blank" title="knpooix"&gt;from this website&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;2) Burn the ISO image on a blank CD &lt;/p&gt;&lt;p&gt;3) Put the Knoppix Boot disk in your computer's CD drive and boot from the CD&lt;/p&gt;&lt;p&gt;At the beginning of boot process you will see a prompt as boot:&lt;/p&gt;&lt;p&gt;Type&lt;br /&gt; knoppix screen=1280x1024&lt;br /&gt;knoppix screen=1024x728 or any suitable resolution that your computer supports. &lt;br /&gt;If                                                  you do not specify   screen             resolution,     the         knoppix      will        boot         with                  minimal     resolution   and   you       may   have    to     use              command  line         options        which    is                 inconvenient       for a    windows            user.  &lt;/p&gt;&lt;p&gt;Once               the    knoppix            window       opens,           click   on  the           folder  icon in       the        bottom       left of    the           screen     to      open    the               PCMan   file    manager.      It     is  a           graphical    file            manager   in                Knoppix. It      has       two  panels.       In    the         left    panel   you       should        see        the           partitions of      your       hard      disk.           Select    the         partition  in                which   windows  is         installed   and          you      will              instantly  see     all    the           folders.   Now      you    can            access      the    contents   of          your         folders     and             delete      suspicious     files  and                folders   just   as     you          would    do      in    the       windows         explorer.   &lt;/p&gt;&lt;p&gt;When            you          are            finished.        Click     on  Log  off.     Now       you      can     Turn     Off or            restart.     Take        out         the     knoppix  CD      from your          drive        and      you     can        normally    boot  in                  windows.    &lt;/p&gt;&lt;p&gt;  Reprinted              with    permission from Threatexpert.com   &lt;/p&gt; &lt;p&gt; &lt;a href="http://comprolive.com:80/remove/about-this-site" target="_blank" rel="author"&gt;Sanjay C Rajure&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/HoKMZIhNxaBB0_BHYNMvBT9xSDg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HoKMZIhNxaBB0_BHYNMvBT9xSDg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/HoKMZIhNxaBB0_BHYNMvBT9xSDg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HoKMZIhNxaBB0_BHYNMvBT9xSDg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/removalguides/~4/_Rzz1WYLGYU" height="1" width="1"/&gt;</description>
			<category>frontpage</category>
			<pubDate>Mon, 13 Feb 2012 09:01:14 +0000</pubDate>
		<feedburner:origLink>http://comprolive.com/remove/trojan/w32-bancos/upsys-exe</feedburner:origLink></item>
		<item>
			<title>SysUpGrade.exe</title>
			<link>http://feedproxy.google.com/~r/removalguides/~3/JFNGODL9DOg/sysupgrade-exe</link>
			<description>&lt;p&gt;The name SysUpGrade.exe &lt;strong&gt; &lt;/strong&gt;               has                           appeared       in        a                                                                                                                                                                                    virus                                                                                                                                                                                                                                                                                                                                                                                     analysis                                                                                                                                report.                            You                     can                                                                                      see                                             it                                                    &lt;a href="http://www.threatexpert.com/report.aspx?md5=09758461d383bcd6944132c605073579" target="_blank" title="report"&gt;on this link&lt;/a&gt;&lt;/p&gt;        &lt;ul&gt;&lt;li&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 installer          is                   of                                                               about  32 KB.               It could be    a       virus       Trojan               Infostealer         Bancos/         Banker/Banbra. &lt;/li&gt;&lt;li&gt;It                                   has  threat    characteristics of ZBot  -  a          banking       trojan        that            disables        firewall,     steals     sensitive        financial     data          (credit   card           numbers,       online      banking      login     details),      makes       screen          snapshots,            downloads       additional          components,   and         provides a         hacker    with  the            remote   access    to the              compromised     system.&lt;/li&gt;&lt;li&gt;It may stop services ALG/ Application Layer Gateway Service, SharedAccess/ Windows Firewall/Internet Connection Sharing (ICS)&lt;/li&gt;&lt;li&gt;Trojan.Bancos                                                  runs silently in the         background    to         monitor     web         browser                          activities.       It    can      create  fake    login      page            for   certain        banking           sites        which    is       used    for     stealing         usernames   and           passwords                 which       can be     sent        to the             attacker     via       e-mail.&lt;/li&gt;&lt;li&gt;It may modify the hosts file so as to redirect or block sites. Or it deletes the hosts file.&lt;/li&gt;&lt;li&gt;It                                        may delete safeboot registry  keys.      This      will         prevent     the          computer       from        starting   in    safe   mode.   The     remedy  to    this        problem         is to         reinstall         windows. &lt;/li&gt;&lt;li&gt;According              to      Symantec &lt;em&gt;           &lt;br /&gt;&lt;br /&gt;&lt;/em&gt;The                                                  Trojan is most often     spread    by     way    of    an       email            containing  a                social                  engineering   trick     such as  a        fake           email   from a    bank           asking       the     user       to          run  the        attached            program   and     perform     some        other            actions to         verify           their             banking     details.    If   the      user        complies             with    the     request      they            could            potentially         reveal   their         account              access        information           which    may    lead   to                  significant       financial    loss.&lt;br /&gt;&lt;br /&gt;You   can  read the the   writeup at   Symantec &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-071710-2826-99&amp;tabid=2" target="_blank" title="Symantec writeup"&gt;on this link&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;     &lt;p&gt;                                                                                                                                                                                                                                                                                                                             It                                                                                creates        SysUpGrade.exe                                                and                                       other                     files             on                                                                             the                                                                                                                                                                           infected                                                                                                 computer                                                                                                                                        that                                       you                                                                        need                                                                                       to                                                                                                                                                             search                                               and                                                                                                   delete.   You    should also remove   the entries of  these  files  from the  windows     startup. &lt;/p&gt;       &lt;p&gt;Warning:                                                                                                               It                is                   possible           that  some                       legitimate                           software          may        be                              using           the                 same                                            file                      names          as         that      of      the             virus                    files.                    You            do            not           have                   to                                    delete             these                files                  if                    they            belong               to              some                                   legitimate                  program                                    installed           on                    your                                      computer.                         Use                     Windows                    Defender              or                                SysInternals                        Process                                                 Explorer    to                                                     differentiate            between                                them.                 The                                              information   in          this                     article            is                                                presented                without                                      making            any              claims                       regarding                its                                           usefulness   or                                                    otherwise.        If      you    have            any                    objections             or           questions,                          please            send   a             note      by                                                       adding a                                   comment    at         the          end          of                         this      page,     or                mail   on                                                                                                       support(at)comprolive.com &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Preventive measures&lt;/strong&gt;&lt;/p&gt;     &lt;ul&gt;&lt;li&gt;                                                         Most of  the                       viruses           enter        your                                             computer                      when        you                 visit                        some                harmful                                 website.                     If        you               use  a                             browser                                 plugin          that                      warns                  you                 about                               harmful                        websites,   you                         can                           prevent                      this                   from                                 happening. A                                         popular                     browser                  plugin              is                   called             Web                     Of          Trust                                 (WOT),         you                               can                       install   it             from                   its                      website  &lt;a href="http://www.mywot.com/" target="_blank" title="WOT "&gt;on this link&lt;/a&gt;. &lt;br /&gt;[ &lt;a href="http://www.youtube.com/watch?v=8DHx7wioFuM" target="_blank" title="WOT video"&gt;a video about WOT plugin &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Blocking                                     Javascript of all sites by default   can      help    to         prevent       drive    by          download        infections.  You   can   use       Noscript   Plugin     for     firefox       as             explained&lt;a href="http://www.youtube.com/watch?v=IMPHD5dkCAA" target="_blank" title="Noscript video"&gt; in this video&lt;/a&gt;.                                      Similar functionality can be  achieved    in          Google's          Chromium         browser        using  the     settings   in       Preferences   &amp;gt;       Under the    Hood    &amp;gt;         Content               Settings &amp;gt; Java    Script    &amp;gt;      Select   "Do    not     Allow".           After that  when           you  visit a       site,   you   will see a    pop        up  next to      the   address       bar   asking         you   if  you   want  to       allow    JavaScript    to   run      for    that       particular      site.          The    author  of     NoScript is       writing a          similar   plugin        for   IE9  called             GoodScript.    Keep  an eye     on    when it         becomes         available.  &lt;/li&gt;&lt;li&gt;Some                                                                                              of      the       viruses   are                        downloaded          in                       Internet               Cache        or     in               the                          Temp                           folder          of       the            windows.             The                viruses                   get                activated           when                   these                       files            are                            executed.             You       can              reduce               the         risk           of             virus                     infection                   if          you            empty                 your                browser                               cache and                     remove          windows                   temp                 files                                  ocasionally,                          ideally         at        the            end     of       a                           browsing                session           or                    before                          closing       down       your                                 computer.                   Some            programs                               like            CCleaner           can  be          set                     to        do               these           things                                                automatically. [&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt; a video about CCleaner &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Do                                                     not leave your    computer          infected     and           insecure.    If     you          doubt           that             there       could  be        some     undetected       virus      on      your          computer,            don't    leave           it       like        that.   Format        the     hard    disk       and         reinstall              windows  and      all        other               programs.    That      is   the           sure      way to    clear              doubts.    &lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt; Using System Restore&lt;/strong&gt;   &lt;p&gt;If                                                                                                                                                                                                                                         you                              know           the                                    duration                          since                           your                                                  computer               is                                                                       infected,                    you                                             can                            try                  to                                                                        restore                  your                           computer                  at a                                                                prior               date,                               that                                            will              be                         an                  easy                        way                                         to                  undo                                 the                                                                changes          done     by                        the                                                     virus&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Using        system   restore   in  &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-system-restore-in-xp" target="_blank" title="system restore in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using system restore                 in  &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system restore in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using          system restore in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-restore-in-windows7" target="_blank" title="System Restore in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [ &lt;a href="http://www.youtube.com/watch?v=bhGrVLPIKXY" target="_blank" title="system restore video"&gt;Video of How to use System Restore&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Boot              in safe mode&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Sometimes    you can not        delete  a      file. You should boot in safe mode and then try    to        delete it.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How       to boot in safe in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/boot-in-safe-mode-in-xp" target="_blank" title="safe mode in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to boot in safe mode                 in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/boot-in-safe-mode-in-vista" target="_blank" title="safe mode in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to boot in safe mode in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/boot-in-safe-mode-in-windows7" target="_blank" title="safeboot in windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt;  View              Hidden Files&lt;/strong&gt;&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;You need to enable                 to view hidden files and folders before searching.&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-to-view-hidden-files-in-xp" target="_blank" title="view hidden files in xp"&gt; Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/view-hidden-files-in-vista" target="_blank" title="view hidden files in vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How         to Enable to View Hidden Files  and Folders in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/view-hidden-files-in-windows7" target="_blank" title="Enable to view hidden files in Windows7"&gt;Windows7             &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [&lt;a href="http://www.youtube.com/watch?v=0ahhDa_bp0A" target="_blank" title="Enable Hidden Files video "&gt; Video of How to enable Hidden files and folders&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Remove             Processes from &lt;span class="notranslate"&gt;Task Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;     Press              Ctrl Alt Del keys to open the &lt;span class="notranslate"&gt;Task          Manager&lt;/span&gt;.                            Select                                                                                                                                                                                                   Processes                    tab.                         You                                             will               see     a                                      list.                         Look                        for                                                             the   names  SysUpGrade.exe                    in              it.                                         Select             if                           found                                          any  and                                              press                                                    the                                   End                                Process                 button.                                It                     will         ask                            for                                      your                                                                 confirmation                                           to                                 end                                             that                                          process.                              Select                    Yes.                 You                        can                                           end                              one                              process                               at    a                                             time.                           You                                                                                                                                                                                                                                                                                              can                              find                                                                      out                          if  a                                                                           process                      in  &lt;span class="notranslate"&gt;Task                       Manager&lt;/span&gt;     is      good                     or        bad  by  using  &lt;span class="notranslate"&gt;Windows                                Defender in  XP and Vista&lt;/span&gt;.                                                                                                                                                                                                                                                                                   It                                          shows                                                                   the                                                                                                                    path                                      of         a                                                                                                                        process                                and                                               its                                                                                                                                                     publisher.                                                                   Harmful                                                                                                                                                                                                                               processes                                                       may                                         be                                                                           shown                                                                     under                                                                             Unknown                                                                                                                        Publisher                                     in                                                         &lt;span class="notranslate"&gt;windows                             defender&lt;/span&gt;.  Whereas in Windows7 you  can find that out from the task manager itself. You can watch a video on How to use &lt;a href="http://www.youtube.com/watch?v=TxE8zS9iiSI" target="_blank" title="Windows Defender video"&gt;Windows Defender&lt;/a&gt;. &lt;br /&gt;     &lt;ul&gt;&lt;li&gt;How           to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-windows-defender-in-xp" target="_blank" title="windows defender in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-windows-defender-in-vista" target="_blank" title="windows defender in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to use Windows Defender in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/use-windows-defender-in-windows7" target="_blank" title="Use Windows Defender in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;     &lt;p&gt; Or                 you can use &lt;span class="notranslate"&gt;Sysinternal's    Process          Explorer&lt;/span&gt;. How  to use      Sysinternal's &lt;a href="http://comprolive.com:80/remove/../free/software/system-tools/process-explorer" target="_blank" title="sysinternal's process explorer"&gt;Process Explorer&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=aD_E0q-x3ww" target="_blank" title="sysinternal's video"&gt;Video of How to use Sysinternal's/ Windows Process Explorer&lt;/a&gt;] &lt;/p&gt;     &lt;p&gt;&lt;strong&gt; Removing              entry from windows startup&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;The                                                                                                                                                                                                                           system                                                                                           configuration                 can             be                                             started             in                       xp                     and                 in                                                   vista        by                                           typing                                                                    msconfig          in                                                            the                 run               box/                                     start                        menu                                      search                                           box. &lt;br /&gt;In                                              xp         by                                                           clicking     on                                                                     Start                                          &amp;gt;                       run         .                    The                                            windows                      startup                              is                                                        reversible.                                        You                       can                    check                 /                                                                                            uncheck                              any                  entry                           from                                     windows                                                 startup        any                                                      number               of                                 times.    Watch  a      video    on &lt;a href="http://www.youtube.com/watch?v=0HVaxH_k5W8" target="_blank" title="windows startup video"&gt;How to Use the Windows Startup&lt;/a&gt;&lt;/p&gt;       &lt;p&gt;Open                                                                                                                                                          system                                                                             configuration                                                  window.Click                               on                      the                                                                                      Startup                                           tab.                    You                     will                see              a                                list             all                      the                                           programs                                        that              are                                                               scheduled                                                                    to                                start         with                                                     windows.                      Expand                                    the                                    middle                                                                                 column                                 using                              your                             mouse                                   pointer.                                       That                    will                        show                            you                the                                                             full                         path                                of          the                                                          program.                                       Locate                       and                                               uncheck                                 the                                    boxes                         in                                             front        of                                                 these                                             names                                "SysUpGrade.exe"                                                 (also                  look                   for                                                           any                                    other                                                                                      suspicious                            names)Press                                                Apply         ,                                                            Press                                                       Close/Ok     ,                                                                  Select                                     "do   not    restart"                             at     the                            next       prompt.&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;modified services&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;                              While      still  in the above window, click   on         Services      tab.     Click    on      "Hide     All       Microsoft        Services".  Look    for   ALG/     Application         Layer     Gateway           Service,     SharedAccess/  Windows            Firewall/Internet          Connection    Sharing       (ICS).  If   they     are        checked,  then       do nothing. If they    are     unchecked        then  you  need   to      check         them again.  &lt;/p&gt;     &lt;p&gt;Locate          and Check  the  box      in         front of      these      services  if they    are     unchecked.    Press   Apply.     Press             Ok/close.  Click  on          "restart"   at    the   next      prompt.    &lt;/p&gt;    &lt;strong&gt; Deleting          files&lt;/strong&gt;   &lt;p&gt;The                                                                                                                                                                                                             computer              will                                        restart                          now.                                                          Delete                                   the                                                                      following                                 files                         and                                               folders.                     Boot                 in                   safe                       mode                           or                                                          boot               in                             the                                          dos                prompt                                     if                                     needed.     You                                   can               use                                       windows                                          search                                          utility                                                      to                                         search                                          for       SysUpGrade.exe&lt;/p&gt;       &lt;p&gt;&lt;em&gt;Files&lt;br /&gt;  C:\windows\system32\AvAtualizacao.exe&lt;br /&gt;C:\windows\system32\AvMaster.exe&lt;br /&gt;C:\windows\system32\AVSCD1A40%ComputerName%.log&lt;br /&gt;C:\windows\system32\SysGrade.exe&lt;br /&gt;C:\windows\system32\SysUpGrade.exe&lt;br /&gt;C:\windows\system32\UpSys.exe&lt;br /&gt;C:\windows\system32\UpSysGrade.exe&lt;/em&gt;&lt;/p&gt;Folders&lt;br /&gt;&lt;p&gt;&lt;em&gt;-&lt;/em&gt;&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Files in Temp folder&lt;/em&gt;&lt;br /&gt;&lt;em&gt;%Temp%\80EB2F5C&lt;/em&gt;&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Installer File&lt;/em&gt;&lt;br /&gt;[file                 and pathname of the sample #1]&lt;/p&gt;       &lt;p&gt;(We                                                                                                                                                                                                                           do                             not                            know                the                     name             or                 the                                              location                of                                             sample                            #1,                     it                                            could                          be              in                                  your                                                     default                                                               download                                  location               or                     on                    the                                                                    desktop       or                       in      a                        Temp                                                                  folder.                 The                                       files                 and                                                            folders                 in                    the                                      Temp                         folder                           can                         be                                                                                          automatically                                          removed,                              if                      you                use       a                                                                                          freeware                               temp                             files/                                     registry                                                      cleaner                                                           software                   like                                                                                    CCleaner)&lt;br /&gt;&lt;em&gt;Folders&lt;/em&gt;&lt;br /&gt;-&lt;/p&gt;    &lt;strong&gt;Repair Hosts File&lt;/strong&gt;  &lt;p&gt;To repair/ edit the hosts file. Login as administrator. open  the following file in notepad&lt;br /&gt; C:\ WINDOWS \system32 \drivers \etc \hosts&lt;br /&gt;remove anything other than 127.0.0.1 Localhost, and save and close the file.&lt;/p&gt;     &lt;p&gt; &lt;strong&gt;Registry            Keys&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;Some                                                                                                                                                                                                           of         the                            registry                   keys                        will                  be                                                                                                                                     automatically                                             removed                        if                    you        run                                                             Registry                         menu           of                                                                 CCleaner.                         For                                                                                others                   you                    can                    see              the                          report                                                             mentioned                        at           the                                                                    beginning                                         of                     this                                                             article         .&lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Using  CCleaner&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;You                                                                                                                                                                                                            can                                                    easily                              remove               the                        files                     in               the                 temp                                                 folder               by                                            running                                                                              CCleaner.                                           You                   can                      set                                                              CCleaner            to                  run                                                                             automatically                   each                                        time                            the                                              computer                                                                               starts.           Do                         not                                                             forget        to         run               CCleaner                                                     &amp;gt;                                                                                Registry                             menu       to                            remove                                         the                                               obsolete                                                          registry                                                                entries.&lt;/p&gt;       &lt;p&gt;more    about    CCleaner &lt;a href="http://comprolive.com:80/remove/../free/software/system-optimizer/ccleaner" target="_blank" title="CCleaner"&gt;on this link&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt;Video on how to use CCleaner&lt;/a&gt;]  &lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Free     tools          to repair disabled &lt;span class="notranslate"&gt;folder options,              registry, Task Manager&lt;/span&gt; etc&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Whereas        you          can repair disabled Folder Options, disabled &lt;span class="notranslate"&gt;Registry     Tools, disabled Task Manager, Disabled             System Restore&lt;/span&gt; etc     using these free tools&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Tools        for&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/enable-registry-tools-in-vista" target="_blank" title="tools for windows Vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools              for &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-run-command-task-manager-and-registry-tools-in-xp" target="_blank" title="tools for windows XP"&gt;Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools          for &lt;a href="http://comprolive.com:80/remove/../howto/windows7/re-enable-disabled-tools-in-windows7" target="_blank" title="re-enable tool for Windows7"&gt;Windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt; Use              the &lt;span class="notranslate"&gt;System    File Checker&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;To              repair altered deleted or modified windows system    files.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How              to run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility                 in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/system-file-checker-in-xp" target="_blank" title="system file checker in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How  to             run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility              in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system file checker in vista"&gt; windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to run System File Checker utility in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-file-checker-in-windows7" target="_blank" title="System File Checker in Windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt;Additional Information &lt;/strong&gt;&lt;br /&gt;                               Virus                   infections are        complex.      Most of     the       times  a     virus on    the                 computer                downloads  more      files   and    make      it        complicated.    In    my           attempt  to      warn               users     about  the         different    ways   that      viruses        are           trying  to       infect    and               ways to  find    them    and        remove, I       have          created       videos   on          specific    Free        tools    and        manual             methods,     these        videos     could  be  of        great    help&lt;br /&gt;     &lt;p&gt;1) To detect and remove malicious Alternate Data Streams - &lt;a href="http://www.youtube.com/watch?v=njAjGiSp98o" target="_blank" title="stream armour"&gt;Stream Armour  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;2) To detect and remove malicious Services -&lt;a href="http://www.youtube.com/watch?v=uCTUvgTHVsU" target="_blank" title="Advanced Winservice manager"&gt; Advanced WinService Manager  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;3) To detect and remove viruses in Fake recycle Bin - &lt;a href="http://www.youtube.com/watch?v=NfMtz3vzr3A" target="_blank" title="Fake recycle bin"&gt;Watch Video  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;4) keep an eye on suspicious connections using a Firewall  - &lt;a href="http://www.youtube.com/watch?v=W1qtOrQMfyk" target="_blank" title="comodo firewall video"&gt;Free Comodo Firewall &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;5) A free tool to detect and remove unwanted BHOs - &lt;a href="http://www.youtube.com/watch?v=sU_hY1r26_g" target="_blank" title="spyBHO remover video"&gt;SpyBHO Remover &lt;/a&gt;&lt;/p&gt;&lt;h3&gt;&lt;strong&gt;If nothing works &lt;/strong&gt;&lt;/h3&gt;&lt;p&gt;More often a virus makes it difficult to remove its files while you are logged in windows. It may do one of the following&lt;/p&gt;&lt;p&gt;1) You may see the suspicious virus process running in the task manager but can not remove it. &lt;/p&gt;&lt;p&gt;2) Even if you delete a virus file/ or terminate the process, the process may spawn again.&lt;/p&gt;&lt;p&gt;3) The virus may disable system restore, registry tools, task manager, safe boot etc. &lt;/p&gt;&lt;p&gt;If                                                 any of these or other     things      done    by     the       virus      make     you            think/         feel           that   you   are   not     able to          remove the        virus     files         then   do   as          follows&lt;/p&gt;&lt;p&gt;1) Download a Knoppix Boot only CD ISO  image from in your language from one of the download links &lt;a href="http://www.knopper.net/knoppix/index-en.html" target="_blank" title="knpooix"&gt;from this website&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;2) Burn the ISO image on a blank CD &lt;/p&gt;&lt;p&gt;3) Put the Knoppix Boot disk in your computer's CD drive and boot from the CD&lt;/p&gt;&lt;p&gt;At the beginning of boot process you will see a prompt as boot:&lt;/p&gt;&lt;p&gt;Type&lt;br /&gt; knoppix screen=1280x1024&lt;br /&gt;knoppix screen=1024x728 or any suitable resolution that your computer supports. &lt;br /&gt;If                                                 you do not specify  screen             resolution,     the         knoppix      will       boot         with                  minimal     resolution   and   you      may   have    to     use              command  line         options       which    is                 inconvenient       for a    windows           user.  &lt;/p&gt;&lt;p&gt;Once               the    knoppix            window      opens,           click   on  the           folder  icon in      the        bottom       left of    the           screen     to      open   the               PCMan   file    manager.      It     is  a          graphical    file            manager   in                Knoppix. It     has       two  panels.       In    the         left    panel   you      should        see        the           partitions of      your      hard      disk.           Select    the         partition  in               which   windows  is         installed   and          you      will             instantly  see     all    the           folders.   Now     you    can            access      the    contents   of          your        folders     and             delete      suspicious     files  and               folders   just   as     you          would    do      in   the       windows         explorer.   &lt;/p&gt;&lt;p&gt;When            you         are            finished.        Click     on  Log  off.     Now      you      can     Turn     Off or            restart.     Take        out        the     knoppix  CD      from your          drive        and     you     can        normally    boot  in                  windows.    &lt;/p&gt;&lt;p&gt;  Reprinted              with    permission from Threatexpert.com   &lt;/p&gt; &lt;p&gt; &lt;a href="http://comprolive.com:80/remove/about-this-site" target="_blank" rel="author"&gt;Sanjay C Rajure&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/WLOBY8Pn6tl5o4TuQQNZ91Ze-04/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/WLOBY8Pn6tl5o4TuQQNZ91Ze-04/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/WLOBY8Pn6tl5o4TuQQNZ91Ze-04/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/WLOBY8Pn6tl5o4TuQQNZ91Ze-04/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/removalguides/~4/JFNGODL9DOg" height="1" width="1"/&gt;</description>
			<category>frontpage</category>
			<pubDate>Mon, 13 Feb 2012 08:56:29 +0000</pubDate>
		<feedburner:origLink>http://comprolive.com/remove/trojan/w32-bancos/sysupgrade-exe</feedburner:origLink></item>
		<item>
			<title>SysGrade.exe</title>
			<link>http://feedproxy.google.com/~r/removalguides/~3/-HB5-acJ4rU/sysgrade-exe</link>
			<description>&lt;p&gt;The name SysGrade.exe &lt;strong&gt; &lt;/strong&gt;               has                          appeared       in        a                                                                                                                                                                                  virus                                                                                                                                                                                                                                                                                                                                                                               analysis                                                                                                                              report.                            You                     can                                                                                    see                                             it                                                   &lt;a href="http://www.threatexpert.com/report.aspx?md5=09758461d383bcd6944132c605073579" target="_blank" title="report"&gt;on this link&lt;/a&gt;&lt;/p&gt;        &lt;ul&gt;&lt;li&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       installer          is                  of                                                              about  32 KB.               It could be    a       virus      Trojan               Infostealer         Bancos/         Banker/Banbra. &lt;/li&gt;&lt;li&gt;It                                  has  threat    characteristics of ZBot -  a          banking       trojan        that            disables       firewall,     steals     sensitive        financial     data         (credit   card           numbers,       online      banking      login    details),      makes       screen          snapshots,           downloads       additional          components,   and         provides a        hacker    with  the            remote   access    to the             compromised     system.&lt;/li&gt;&lt;li&gt;It may stop services ALG/ Application Layer Gateway Service, SharedAccess/ Windows Firewall/Internet Connection Sharing (ICS)&lt;/li&gt;&lt;li&gt;Trojan.Bancos                                                 runs silently in the        background    to         monitor     web         browser                         activities.       It    can      create  fake    login     page            for   certain        banking           sites       which    is       used    for     stealing         usernames   and          passwords                 which       can be     sent        to the            attacker     via       e-mail.&lt;/li&gt;&lt;li&gt;It may modify the hosts file so as to redirect or block sites. Or it deletes the hosts file.&lt;/li&gt;&lt;li&gt;It                                       may delete safeboot registry keys.      This      will         prevent     the          computer      from        starting   in    safe   mode.   The     remedy  to    this       problem         is to         reinstall         windows. &lt;/li&gt;&lt;li&gt;According              to      Symantec &lt;em&gt;           &lt;br /&gt;&lt;br /&gt;&lt;/em&gt;The                                                 Trojan is most often    spread    by     way    of    an       email            containing  a               social                  engineering   trick     such as  a       fake           email   from a    bank           asking       the    user       to          run  the        attached            program  and     perform     some        other            actions to        verify           their             banking     details.    If   the     user        complies             with    the     request      they           could            potentially         reveal   their         account             access        information           which    may    lead  to                  significant       financial    loss.&lt;br /&gt;&lt;br /&gt;You   can  read the the   writeup at   Symantec &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-071710-2826-99&amp;tabid=2" target="_blank" title="Symantec writeup"&gt;on this link&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;     &lt;p&gt;                                                                                                                                                                                                                                                                                                                        It                                                                               creates        SysGrade.exe                                               and                                      other                     files             on                                                                            the                                                                                                                                                                        infected                                                                                                computer                                                                                                                                      that                                      you                                                                       need                                                                                      to                                                                                                                                                           search                                              and                                                                                                  delete.   You   should also remove   the entries of  these  files  from the  windows    startup. &lt;/p&gt;       &lt;p&gt;Warning:                                                                                                             It                is                   possible          that  some                       legitimate                          software          may        be                              using          the                 same                                           file                      names          as         that      of     the             virus                    files.                    You           do            not           have                   to                                   delete             these                files                 if                    they            belong              to              some                                   legitimate                 program                                    installed          on                    your                                     computer.                         Use                     Windows                   Defender              or                               SysInternals                        Process                                                Explorer    to                                                    differentiate            between                               them.                 The                                             information   in          this                     article           is                                                presented               without                                      making            any             claims                       regarding                its                                          usefulness   or                                                   otherwise.        If      you    have           any                    objections             or          questions,                          please            send   a            note      by                                                      adding a                                   comment    at         the         end          of                         this      page,     or               mail   on                                                                                                     support(at)comprolive.com &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Preventive measures&lt;/strong&gt;&lt;/p&gt;     &lt;ul&gt;&lt;li&gt;                                                        Most of  the                      viruses           enter        your                                            computer                      when        you                visit                        some                harmful                                website.                     If        you              use  a                             browser                                plugin          that                      warns                 you                 about                               harmful                       websites,   you                         can                          prevent                      this                  from                                 happening. A                                        popular                     browser                 plugin              is                   called             Web                    Of          Trust                                 (WOT),        you                               can                       install  it             from                   its                      website  &lt;a href="http://www.mywot.com/" target="_blank" title="WOT "&gt;on this link&lt;/a&gt;. &lt;br /&gt;[ &lt;a href="http://www.youtube.com/watch?v=8DHx7wioFuM" target="_blank" title="WOT video"&gt;a video about WOT plugin &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Blocking                                    Javascript of all sites by default  can      help    to         prevent       drive    by          download       infections.  You   can   use       Noscript   Plugin     for    firefox       as             explained&lt;a href="http://www.youtube.com/watch?v=IMPHD5dkCAA" target="_blank" title="Noscript video"&gt; in this video&lt;/a&gt;.                                     Similar functionality can be achieved    in          Google's          Chromium         browser       using  the     settings   in       Preferences   &amp;gt;       Under the   Hood    &amp;gt;         Content               Settings &amp;gt; Java    Script   &amp;gt;      Select   "Do    not     Allow".           After that  when          you  visit a       site,   you   will see a    pop        up next to      the   address       bar   asking         you   if  you  want  to       allow    JavaScript    to   run      for    that      particular      site.          The    author  of     NoScript is      writing a          similar   plugin        for   IE9  called            GoodScript.    Keep  an eye     on    when it         becomes        available.  &lt;/li&gt;&lt;li&gt;Some                                                                                             of      the       viruses  are                        downloaded          in                      Internet               Cache        or     in               the                         Temp                           folder          of      the            windows.             The                viruses                  get                activated           when                  these                       files            are                           executed.             You       can              reduce              the         risk           of             virus                    infection                   if          you            empty                your                browser                               cache and                    remove          windows                   temp                files                                  ocasionally,                         ideally         at        the            end     of       a                          browsing                session           or                   before                          closing       down      your                                 computer.                   Some           programs                               like            CCleaner          can  be          set                     to        do              these           things                                               automatically. [&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt; a video about CCleaner &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Do                                                    not leave your   computer          infected     and           insecure.    If     you         doubt           that             there       could  be        some    undetected       virus      on      your          computer,           don't    leave           it       like        that.   Format        the    hard    disk       and         reinstall              windows  and     all        other               programs.    That      is   the          sure      way to    clear              doubts.    &lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt; Using System Restore&lt;/strong&gt;   &lt;p&gt;If                                                                                                                                                                                                                                     you                              know           the                                   duration                          since                          your                                                 computer               is                                                                      infected,                    you                                            can                            try                 to                                                                       restore                  your                           computer                 at a                                                               prior               date,                               that                                           will              be                        an                  easy                        way                                        to                  undo                                the                                                               changes          done     by                        the                                                    virus&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Using        system   restore   in  &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-system-restore-in-xp" target="_blank" title="system restore in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using system restore                 in  &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system restore in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using          system restore in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-restore-in-windows7" target="_blank" title="System Restore in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [ &lt;a href="http://www.youtube.com/watch?v=bhGrVLPIKXY" target="_blank" title="system restore video"&gt;Video of How to use System Restore&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Boot              in safe mode&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Sometimes    you can not        delete  a      file. You should boot in safe mode and then try    to        delete it.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How       to boot in safe in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/boot-in-safe-mode-in-xp" target="_blank" title="safe mode in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to boot in safe mode                 in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/boot-in-safe-mode-in-vista" target="_blank" title="safe mode in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to boot in safe mode in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/boot-in-safe-mode-in-windows7" target="_blank" title="safeboot in windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt;  View              Hidden Files&lt;/strong&gt;&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;You need to enable                 to view hidden files and folders before searching.&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-to-view-hidden-files-in-xp" target="_blank" title="view hidden files in xp"&gt; Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/view-hidden-files-in-vista" target="_blank" title="view hidden files in vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How         to Enable to View Hidden Files  and Folders in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/view-hidden-files-in-windows7" target="_blank" title="Enable to view hidden files in Windows7"&gt;Windows7             &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [&lt;a href="http://www.youtube.com/watch?v=0ahhDa_bp0A" target="_blank" title="Enable Hidden Files video "&gt; Video of How to enable Hidden files and folders&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Remove             Processes from &lt;span class="notranslate"&gt;Task Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;     Press              Ctrl Alt Del keys to open the &lt;span class="notranslate"&gt;Task          Manager&lt;/span&gt;.                           Select                                                                                                                                                                                                Processes                    tab.                         You                                            will               see     a                                     list.                         Look                       for                                                            the   names  SysGrade.exe                    in             it.                                         Select             if                          found                                          any and                                              press                                                   the                                  End                                Process                 button.                               It                     will         ask                           for                                      your                                                                confirmation                                          to                                end                                             that                                         process.                              Select                   Yes.                 You                        can                                          end                              one                             process                               at    a                                            time.                          You                                                                                                                                                                                                                                                                                          can                              find                                                                     out                          if  a                                                                         process                      in  &lt;span class="notranslate"&gt;Task                       Manager&lt;/span&gt;     is      good                     or        bad  by  using  &lt;span class="notranslate"&gt;Windows                                Defender in  XP and Vista&lt;/span&gt;.                                                                                                                                                                                                                                                                               It                                         shows                                                                  the                                                                                                                  path                                      of         a                                                                                                                      process                                and                                              its                                                                                                                                                   publisher.                                                                  Harmful                                                                                                                                                                                                                           processes                                                       may                                        be                                                                          shown                                                                    under                                                                            Unknown                                                                                                                      Publisher                                    in                                                         &lt;span class="notranslate"&gt;windows                             defender&lt;/span&gt;.  Whereas in Windows7 you  can find that out from the task manager itself. You can watch a video on How to use &lt;a href="http://www.youtube.com/watch?v=TxE8zS9iiSI" target="_blank" title="Windows Defender video"&gt;Windows Defender&lt;/a&gt;. &lt;br /&gt;     &lt;ul&gt;&lt;li&gt;How           to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-windows-defender-in-xp" target="_blank" title="windows defender in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-windows-defender-in-vista" target="_blank" title="windows defender in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to use Windows Defender in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/use-windows-defender-in-windows7" target="_blank" title="Use Windows Defender in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;     &lt;p&gt; Or                 you can use &lt;span class="notranslate"&gt;Sysinternal's    Process          Explorer&lt;/span&gt;. How  to use      Sysinternal's &lt;a href="http://comprolive.com:80/remove/../free/software/system-tools/process-explorer" target="_blank" title="sysinternal's process explorer"&gt;Process Explorer&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=aD_E0q-x3ww" target="_blank" title="sysinternal's video"&gt;Video of How to use Sysinternal's/ Windows Process Explorer&lt;/a&gt;] &lt;/p&gt;     &lt;p&gt;&lt;strong&gt; Removing              entry from windows startup&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;The                                                                                                                                                                                                                       system                                                                                          configuration                 can             be                                            started             in                      xp                     and                 in                                                  vista        by                                          typing                                                                   msconfig          in                                                           the                 run              box/                                     start                       menu                                      search                                          box. &lt;br /&gt;In                                             xp         by                                                          clicking     on                                                                    Start                                          &amp;gt;                      run         .                    The                                           windows                      startup                             is                                                       reversible.                                        You                      can                    check                 /                                                                                          uncheck                              any                  entry                          from                                     windows                                                startup        any                                                     number               of                                times.    Watch  a      video    on &lt;a href="http://www.youtube.com/watch?v=0HVaxH_k5W8" target="_blank" title="windows startup video"&gt;How to Use the Windows Startup&lt;/a&gt;&lt;/p&gt;       &lt;p&gt;Open                                                                                                                                                       system                                                                            configuration                                                 window.Click                               on                     the                                                                                     Startup                                           tab.                   You                     will                see             a                                list             all                     the                                           programs                                       that              are                                                              scheduled                                                                   to                               start         with                                                    windows.                      Expand                                   the                                    middle                                                                                column                                using                              your                            mouse                                   pointer.                                      That                    will                       show                            you                the                                                            full                        path                                of          the                                                         program.                                      Locate                       and                                              uncheck                                 the                                   boxes                         in                                            front        of                                                these                                            names                                "SysGrade.exe"                                                (also                  look                  for                                                           any                                   other                                                                                     suspicious                           names)Press                                               Apply         ,                                                           Press                                                       Close/Ok    ,                                                                 Select                                     "do   not    restart"                            at     the                            next      prompt.&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;modified services&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;                             While      still  in the above window, click   on        Services      tab.     Click    on      "Hide     All       Microsoft       Services".  Look    for   ALG/     Application         Layer    Gateway           Service,     SharedAccess/  Windows           Firewall/Internet          Connection    Sharing       (ICS).  If   they    are        checked,  then       do nothing. If they    are    unchecked        then  you  need   to      check         them again.  &lt;/p&gt;     &lt;p&gt;Locate         and Check  the  box      in         front of      these     services  if they    are     unchecked.    Press   Apply.     Press            Ok/close.  Click  on          "restart"   at    the   next     prompt.    &lt;/p&gt;    &lt;strong&gt; Deleting          files&lt;/strong&gt;   &lt;p&gt;The                                                                                                                                                                                                          computer              will                                       restart                         now.                                                          Delete                                  the                                                                     following                                files                         and                                              folders.                     Boot                 in                  safe                       mode                           or                                                         boot               in                            the                                         dos                prompt                                     if                                    needed.     You                                  can               use                                       windows                                         search                                         utility                                                     to                                         search                                         for       SysGrade.exe&lt;/p&gt;       &lt;p&gt;&lt;em&gt;Files&lt;br /&gt;  C:\windows\system32\AvAtualizacao.exe&lt;br /&gt;C:\windows\system32\AvMaster.exe&lt;br /&gt;C:\windows\system32\AVSCD1A40%ComputerName%.log&lt;br /&gt;C:\windows\system32\SysGrade.exe&lt;br /&gt;C:\windows\system32\SysUpGrade.exe&lt;br /&gt;C:\windows\system32\UpSys.exe&lt;br /&gt;C:\windows\system32\UpSysGrade.exe&lt;/em&gt;&lt;/p&gt;Folders&lt;br /&gt;&lt;p&gt;&lt;em&gt;-&lt;/em&gt;&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Files in Temp folder&lt;/em&gt;&lt;br /&gt;%Temp%\80EB2F5C&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Installer File&lt;/em&gt;&lt;br /&gt;[file                 and pathname of the sample #1]&lt;/p&gt;       &lt;p&gt;(We                                                                                                                                                                                                                       do                             not                            know               the                     name             or                 the                                             location                of                                            sample                           #1,                     it                                           could                          be              in                                 your                                                    default                                                              download                                  location               or                    on                    the                                                                   desktop       or                      in      a                        Temp                                                                 folder.                 The                                      files                 and                                                           folders                 in                   the                                      Temp                        folder                           can                         be                                                                                        automatically                                         removed,                              if                      you               use       a                                                                                         freeware                              temp                             files/                                    registry                                                     cleaner                                                          software                   like                                                                                   CCleaner)&lt;br /&gt;&lt;em&gt;Folders&lt;/em&gt;&lt;br /&gt;-&lt;/p&gt;    &lt;strong&gt;Repair Hosts File&lt;/strong&gt;  &lt;p&gt;To repair/ edit the hosts file. Login as administrator. open  the following file in notepad&lt;br /&gt; C:\ WINDOWS \system32 \drivers \etc \hosts&lt;br /&gt;remove anything other than 127.0.0.1 Localhost, and save and close the file.&lt;/p&gt;     &lt;p&gt; &lt;strong&gt;Registry            Keys&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;Some                                                                                                                                                                                                        of         the                           registry                   keys                       will                  be                                                                                                                                   automatically                                            removed                        if                    you        run                                                            Registry                        menu           of                                                                CCleaner.                         For                                                                              others                   you                    can                   see              the                          report                                                            mentioned                       at           the                                                                   beginning                                         of                    this                                                            article         .&lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Using  CCleaner&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;You                                                                                                                                                                                                         can                                                   easily                             remove               the                        files                    in               the                 temp                                                folder               by                                           running                                                                             CCleaner.                                          You                   can                      set                                                             CCleaner            to                 run                                                                            automatically                   each                                       time                            the                                             computer                                                                              starts.           Do                        not                                                            forget        to         run               CCleaner                                                    &amp;gt;                                                                               Registry                            menu       to                            remove                                        the                                              obsolete                                                         registry                                                               entries.&lt;/p&gt;       &lt;p&gt;more    about    CCleaner &lt;a href="http://comprolive.com:80/remove/../free/software/system-optimizer/ccleaner" target="_blank" title="CCleaner"&gt;on this link&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt;Video on how to use CCleaner&lt;/a&gt;]  &lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Free     tools          to repair disabled &lt;span class="notranslate"&gt;folder options,              registry, Task Manager&lt;/span&gt; etc&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Whereas        you          can repair disabled Folder Options, disabled &lt;span class="notranslate"&gt;Registry     Tools, disabled Task Manager, Disabled             System Restore&lt;/span&gt; etc     using these free tools&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Tools        for&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/enable-registry-tools-in-vista" target="_blank" title="tools for windows Vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools              for &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-run-command-task-manager-and-registry-tools-in-xp" target="_blank" title="tools for windows XP"&gt;Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools          for &lt;a href="http://comprolive.com:80/remove/../howto/windows7/re-enable-disabled-tools-in-windows7" target="_blank" title="re-enable tool for Windows7"&gt;Windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt; Use              the &lt;span class="notranslate"&gt;System    File Checker&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;To              repair altered deleted or modified windows system    files.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How              to run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility                 in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/system-file-checker-in-xp" target="_blank" title="system file checker in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How  to             run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility              in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system file checker in vista"&gt; windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to run System File Checker utility in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-file-checker-in-windows7" target="_blank" title="System File Checker in Windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt;Additional Information &lt;/strong&gt;&lt;br /&gt;                              Virus                   infections are       complex.      Most of     the       times  a     virus on    the                computer                downloads  more      files   and   make      it        complicated.    In    my           attempt  to     warn               users     about  the         different    ways   that     viruses        are           trying  to       infect    and              ways to  find    them    and        remove, I       have         created       videos   on          specific    Free        tools    and       manual             methods,     these        videos     could  be of        great    help&lt;br /&gt;     &lt;p&gt;1) To detect and remove malicious Alternate Data Streams - &lt;a href="http://www.youtube.com/watch?v=njAjGiSp98o" target="_blank" title="stream armour"&gt;Stream Armour  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;2) To detect and remove malicious Services -&lt;a href="http://www.youtube.com/watch?v=uCTUvgTHVsU" target="_blank" title="Advanced Winservice manager"&gt; Advanced WinService Manager  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;3) To detect and remove viruses in Fake recycle Bin - &lt;a href="http://www.youtube.com/watch?v=NfMtz3vzr3A" target="_blank" title="Fake recycle bin"&gt;Watch Video  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;4) keep an eye on suspicious connections using a Firewall  - &lt;a href="http://www.youtube.com/watch?v=W1qtOrQMfyk" target="_blank" title="comodo firewall video"&gt;Free Comodo Firewall &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;5) A free tool to detect and remove unwanted BHOs - &lt;a href="http://www.youtube.com/watch?v=sU_hY1r26_g" target="_blank" title="spyBHO remover video"&gt;SpyBHO Remover &lt;/a&gt;&lt;/p&gt;&lt;h3&gt;&lt;strong&gt;If nothing works &lt;/strong&gt;&lt;/h3&gt;&lt;p&gt;More often a virus makes it difficult to remove its files while you are logged in windows. It may do one of the following&lt;/p&gt;&lt;p&gt;1) You may see the suspicious virus process running in the task manager but can not remove it. &lt;/p&gt;&lt;p&gt;2) Even if you delete a virus file/ or terminate the process, the process may spawn again.&lt;/p&gt;&lt;p&gt;3) The virus may disable system restore, registry tools, task manager, safe boot etc. &lt;/p&gt;&lt;p&gt;If                                                any of these or other    things      done    by     the       virus      make     you           think/         feel           that   you   are   not     able to         remove the        virus     files         then   do   as         follows&lt;/p&gt;&lt;p&gt;1) Download a Knoppix Boot only CD ISO  image from in your language from one of the download links &lt;a href="http://www.knopper.net/knoppix/index-en.html" target="_blank" title="knpooix"&gt;from this website&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;2) Burn the ISO image on a blank CD &lt;/p&gt;&lt;p&gt;3) Put the Knoppix Boot disk in your computer's CD drive and boot from the CD&lt;/p&gt;&lt;p&gt;At the beginning of boot process you will see a prompt as boot:&lt;/p&gt;&lt;p&gt;Type&lt;br /&gt; knoppix screen=1280x1024&lt;br /&gt;knoppix screen=1024x728 or any suitable resolution that your computer supports. &lt;br /&gt;If                                                you do not specify screen             resolution,     the         knoppix      will      boot         with                  minimal     resolution   and   you     may   have    to     use              command  line         options      which    is                 inconvenient       for a    windows          user.  &lt;/p&gt;&lt;p&gt;Once               the    knoppix            window     opens,           click   on  the           folder  icon in      the       bottom       left of    the           screen     to      open   the              PCMan   file    manager.      It     is  a         graphical    file            manager   in                Knoppix. It    has       two  panels.       In    the         left    panel   you     should        see        the           partitions of      your      hard     disk.           Select    the         partition  in              which   windows  is         installed   and          you      will            instantly  see     all    the           folders.   Now     you   can            access      the    contents   of          your       folders     and             delete      suspicious     files  and              folders   just   as     you          would    do      in   the      windows         explorer.   &lt;/p&gt;&lt;p&gt;When            you         are           finished.        Click     on  Log  off.     Now      you     can     Turn     Off or            restart.     Take        out       the     knoppix  CD      from your          drive        and     you    can        normally    boot  in                  windows.    &lt;/p&gt;&lt;p&gt;  Reprinted              with    permission from Threatexpert.com   &lt;/p&gt; &lt;p&gt; &lt;a href="http://comprolive.com:80/remove/about-this-site" target="_blank" rel="author"&gt;Sanjay C Rajure&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/XGgUIrgf6wLe9swmw0l2G2RAeHM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XGgUIrgf6wLe9swmw0l2G2RAeHM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/XGgUIrgf6wLe9swmw0l2G2RAeHM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XGgUIrgf6wLe9swmw0l2G2RAeHM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/removalguides/~4/-HB5-acJ4rU" height="1" width="1"/&gt;</description>
			<category>frontpage</category>
			<pubDate>Mon, 13 Feb 2012 08:53:47 +0000</pubDate>
		<feedburner:origLink>http://comprolive.com/remove/trojan/w32-bancos/sysgrade-exe</feedburner:origLink></item>
		<item>
			<title>AvAtualizacao.exe</title>
			<link>http://feedproxy.google.com/~r/removalguides/~3/ILKVO-DHdEE/avatualizacao-exe</link>
			<description>&lt;p&gt;The name AvAtualizacao.exe &lt;strong&gt; &lt;/strong&gt;               has                         appeared       in        a                                                                                                                                                                                virus                                                                                                                                                                                                                                                                                                                                                                         analysis                                                                                                                             report.                           You                     can                                                                                   see                                            it                                                  &lt;a href="http://www.threatexpert.com/report.aspx?md5=09758461d383bcd6944132c605073579" target="_blank" title="report"&gt;on this link&lt;/a&gt;&lt;/p&gt;        &lt;ul&gt;&lt;li&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             installer          is                 of                                                              about 32 KB.               It could be    a       virus      Trojan              Infostealer         Bancos/         Banker/Banbra. &lt;/li&gt;&lt;li&gt;It                                 has  threat    characteristics of ZBot -  a         banking       trojan        that            disables      firewall,     steals     sensitive        financial     data        (credit   card           numbers,       online      banking      login   details),      makes       screen          snapshots,          downloads       additional          components,   and         provides a       hacker    with  the            remote   access    to the            compromised     system.&lt;/li&gt;&lt;li&gt;It may stop services ALG/ Application Layer Gateway Service, SharedAccess/ Windows Firewall/Internet Connection Sharing (ICS)&lt;/li&gt;&lt;li&gt;Trojan.Bancos                                                runs silently in the       background    to         monitor     web         browser                        activities.       It    can      create  fake    login    page            for   certain        banking           sites       which   is       used    for     stealing         usernames   and         passwords                 which       can be     sent        to the           attacker     via       e-mail.&lt;/li&gt;&lt;li&gt;It may modify the hosts file so as to redirect or block sites. Or it deletes the hosts file.&lt;/li&gt;&lt;li&gt;It                                      may delete safeboot registry keys.     This      will         prevent     the          computer      from       starting   in    safe   mode.   The     remedy  to    this      problem         is to         reinstall         windows. &lt;/li&gt;&lt;li&gt;According              to      Symantec &lt;em&gt;           &lt;br /&gt;&lt;br /&gt;&lt;/em&gt;The                                                Trojan is most often   spread    by     way    of    an       email            containing  a              social                  engineering   trick     such as  a      fake           email   from a    bank           asking       the   user       to          run  the        attached            program  and    perform     some        other            actions to        verify          their             banking     details.    If   the     user       complies             with    the     request      they           could           potentially         reveal   their         account            access        information           which    may    lead  to                 significant       financial    loss.&lt;br /&gt;&lt;br /&gt;You   can  read the the   writeup at   Symantec &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-071710-2826-99&amp;tabid=2" target="_blank" title="Symantec writeup"&gt;on this link&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;     &lt;p&gt;                                                                                                                                                                                                                                                                                                                   It                                                                              creates        AvAtualizacao.exe                                              and                                     other                     files             on                                                                           the                                                                                                                                                                     infected                                                                                               computer                                                                                                                                    that                                     you                                                                      need                                                                                     to                                                                                                                                                         search                                             and                                                                                                 delete.   You   should also remove  the entries of  these  files  from the  windows    startup. &lt;/p&gt;       &lt;p&gt;Warning:                                                                                                           It                is                  possible          that  some                       legitimate                         software          may        be                             using          the                 same                                          file                      names          as         that     of     the             virus                    files.                   You           do            not           have                   to                                  delete             these               files                 if                    they            belong             to              some                                   legitimate                program                                    installed         on                    your                                    computer.                         Use                     Windows                  Defender              or                              SysInternals                        Process                                               Explorer    to                                                   differentiate            between                              them.                 The                                            information   in          this                     article           is                                               presented              without                                      making            any            claims                       regarding                its                                         usefulness   or                                                  otherwise.        If      you    have          any                    objections             or          questions,                         please            send   a            note      by                                                     adding a                                  comment    at         the         end          of                        this      page,     or               mail   on                                                                                                   support(at)comprolive.com &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Preventive measures&lt;/strong&gt;&lt;/p&gt;     &lt;ul&gt;&lt;li&gt;                                                       Most of  the                     viruses           enter        your                                           computer                      when        you               visit                        some                harmful                               website.                     If        you             use  a                             browser                               plugin          that                      warns                you                 about                               harmful                      websites,   you                         can                         prevent                      this                  from                                happening. A                                       popular                     browser                 plugin             is                   called             Web                    Of         Trust                                 (WOT),        you                              can                       install  it             from                  its                      website  &lt;a href="http://www.mywot.com/" target="_blank" title="WOT "&gt;on this link&lt;/a&gt;. &lt;br /&gt;[ &lt;a href="http://www.youtube.com/watch?v=8DHx7wioFuM" target="_blank" title="WOT video"&gt;a video about WOT plugin &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Blocking                                   Javascript of all sites by default can      help    to         prevent       drive    by          download      infections.  You   can   use       Noscript   Plugin     for   firefox       as             explained&lt;a href="http://www.youtube.com/watch?v=IMPHD5dkCAA" target="_blank" title="Noscript video"&gt; in this video&lt;/a&gt;.                                    Similar functionality can be achieved   in          Google's          Chromium         browser       using the     settings   in       Preferences   &amp;gt;       Under the   Hood   &amp;gt;         Content               Settings &amp;gt; Java    Script   &amp;gt;     Select   "Do    not     Allow".           After that  when         you  visit a       site,   you   will see a    pop        up next to     the   address       bar   asking         you   if  you  want  to      allow    JavaScript    to   run      for    that      particular     site.          The    author  of     NoScript is      writing a         similar   plugin        for   IE9  called            GoodScript.    Keep an eye     on    when it         becomes        available.  &lt;/li&gt;&lt;li&gt;Some                                                                                           of      the       viruses  are                       downloaded          in                      Internet               Cache       or     in               the                         Temp                          folder          of      the            windows.            The                viruses                  get               activated           when                  these                      files            are                           executed.             You      can              reduce              the         risk           of            virus                    infection                   if         you            empty                your                browser                              cache and                    remove         windows                   temp                files                                 ocasionally,                         ideally         at       the            end     of       a                          browsing               session           or                   before                         closing       down      your                                computer.                   Some           programs                              like            CCleaner          can  be          set                    to        do              these           things                                              automatically. [&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt; a video about CCleaner &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Do                                                   not leave your  computer          infected     and           insecure.    If     you        doubt           that             there       could  be        some   undetected       virus      on      your          computer,          don't    leave           it       like        that.   Format        the   hard    disk       and         reinstall              windows  and    all        other               programs.    That      is   the         sure      way to    clear              doubts.    &lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt; Using System Restore&lt;/strong&gt;   &lt;p&gt;If                                                                                                                                                                                                                                 you                              know           the                                  duration                          since                         your                                                computer               is                                                                     infected,                    you                                           can                            try                to                                                                      restore                  your                           computer                at a                                                              prior               date,                               that                                          will              be                       an                  easy                        way                                       to                  undo                               the                                                              changes          done     by                        the                                                   virus&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Using        system   restore   in  &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-system-restore-in-xp" target="_blank" title="system restore in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using system restore                 in  &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system restore in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using          system restore in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-restore-in-windows7" target="_blank" title="System Restore in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [ &lt;a href="http://www.youtube.com/watch?v=bhGrVLPIKXY" target="_blank" title="system restore video"&gt;Video of How to use System Restore&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Boot              in safe mode&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Sometimes    you can not        delete  a      file. You should boot in safe mode and then try    to        delete it.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How       to boot in safe in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/boot-in-safe-mode-in-xp" target="_blank" title="safe mode in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to boot in safe mode                 in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/boot-in-safe-mode-in-vista" target="_blank" title="safe mode in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to boot in safe mode in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/boot-in-safe-mode-in-windows7" target="_blank" title="safeboot in windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt;  View              Hidden Files&lt;/strong&gt;&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;You need to enable                 to view hidden files and folders before searching.&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-to-view-hidden-files-in-xp" target="_blank" title="view hidden files in xp"&gt; Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/view-hidden-files-in-vista" target="_blank" title="view hidden files in vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How         to Enable to View Hidden Files  and Folders in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/view-hidden-files-in-windows7" target="_blank" title="Enable to view hidden files in Windows7"&gt;Windows7             &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [&lt;a href="http://www.youtube.com/watch?v=0ahhDa_bp0A" target="_blank" title="Enable Hidden Files video "&gt; Video of How to enable Hidden files and folders&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Remove             Processes from &lt;span class="notranslate"&gt;Task Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;     Press              Ctrl Alt Del keys to open the &lt;span class="notranslate"&gt;Task          Manager&lt;/span&gt;.                          Select                                                                                                                                                                                             Processes                    tab.                         You                                           will               see     a                                    list.                         Look                      for                                                           the   names  AvAtualizacao.exe                    in             it.                                        Select             if                         found                                          any and                                             press                                                  the                                  End                               Process                 button.                              It                     will         ask                          for                                      your                                                               confirmation                                         to                                end                                            that                                        process.                              Select                   Yes.                You                        can                                         end                              one                            process                               at    a                                           time.                          You                                                                                                                                                                                                                                                                                      can                             find                                                                    out                          if  a                                                                        process                      in  &lt;span class="notranslate"&gt;Task                       Manager&lt;/span&gt;     is      good                     or        bad  by  using  &lt;span class="notranslate"&gt;Windows                                Defender in  XP and Vista&lt;/span&gt;.                                                                                                                                                                                                                                                                           It                                        shows                                                                 the                                                                                                                 path                                     of         a                                                                                                                    process                                and                                             its                                                                                                                                                 publisher.                                                                 Harmful                                                                                                                                                                                                                        processes                                                      may                                       be                                                                         shown                                                                   under                                                                           Unknown                                                                                                                    Publisher                                    in                                                        &lt;span class="notranslate"&gt;windows                             defender&lt;/span&gt;.  Whereas in Windows7 you  can find that out from the task manager itself. You can watch a video on How to use &lt;a href="http://www.youtube.com/watch?v=TxE8zS9iiSI" target="_blank" title="Windows Defender video"&gt;Windows Defender&lt;/a&gt;. &lt;br /&gt;     &lt;ul&gt;&lt;li&gt;How           to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-windows-defender-in-xp" target="_blank" title="windows defender in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-windows-defender-in-vista" target="_blank" title="windows defender in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to use Windows Defender in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/use-windows-defender-in-windows7" target="_blank" title="Use Windows Defender in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;     &lt;p&gt; Or                 you can use &lt;span class="notranslate"&gt;Sysinternal's    Process          Explorer&lt;/span&gt;. How  to use      Sysinternal's &lt;a href="http://comprolive.com:80/remove/../free/software/system-tools/process-explorer" target="_blank" title="sysinternal's process explorer"&gt;Process Explorer&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=aD_E0q-x3ww" target="_blank" title="sysinternal's video"&gt;Video of How to use Sysinternal's/ Windows Process Explorer&lt;/a&gt;] &lt;/p&gt;     &lt;p&gt;&lt;strong&gt; Removing              entry from windows startup&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;The                                                                                                                                                                                                                   system                                                                                         configuration                 can             be                                           started             in                     xp                     and                 in                                                 vista        by                                         typing                                                                  msconfig          in                                                          the                 run              box/                                    start                       menu                                     search                                         box. &lt;br /&gt;In                                             xp         by                                                         clicking     on                                                                   Start                                         &amp;gt;                      run        .                    The                                          windows                      startup                             is                                                      reversible.                                       You                      can                   check                 /                                                                                         uncheck                             any                  entry                          from                                    windows                                               startup        any                                                    number               of                                times.   Watch  a      video    on &lt;a href="http://www.youtube.com/watch?v=0HVaxH_k5W8" target="_blank" title="windows startup video"&gt;How to Use the Windows Startup&lt;/a&gt;&lt;/p&gt;       &lt;p&gt;Open                                                                                                                                                    system                                                                           configuration                                                window.Click                               on                     the                                                                                   Startup                                           tab.                  You                     will                see             a                               list             all                    the                                           programs                                      that              are                                                             scheduled                                                                  to                               start        with                                                    windows.                     Expand                                   the                                   middle                                                                               column                               using                              your                           mouse                                   pointer.                                     That                    will                       show                           you                the                                                           full                        path                               of          the                                                        program.                                     Locate                       and                                             uncheck                                 the                                  boxes                         in                                           front        of                                               these                                            names                               "AvAtualizacao.exe"                                               (also                  look                  for                                                          any                                  other                                                                                    suspicious                          names)Press                                               Apply         ,                                                          Press                                                      Close/Ok    ,                                                                Select                                    "do   not    restart"                            at    the                            next      prompt.&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;modified services&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;                            While      still  in the above window, click  on        Services      tab.     Click    on      "Hide     All      Microsoft       Services".  Look    for   ALG/     Application        Layer    Gateway           Service,     SharedAccess/  Windows          Firewall/Internet          Connection    Sharing       (ICS).  If   they   are        checked,  then       do nothing. If they    are   unchecked        then  you  need   to      check         them again.  &lt;/p&gt;     &lt;p&gt;Locate        and Check  the  box      in         front of      these    services  if they    are     unchecked.    Press   Apply.     Press           Ok/close.  Click  on          "restart"   at    the   next    prompt.    &lt;/p&gt;    &lt;strong&gt; Deleting          files&lt;/strong&gt;   &lt;p&gt;The                                                                                                                                                                                                       computer              will                                      restart                         now.                                                         Delete                                 the                                                                    following                                files                        and                                             folders.                     Boot                 in                 safe                       mode                           or                                                        boot               in                           the                                         dos               prompt                                     if                                   needed.     You                                  can              use                                       windows                                        search                                        utility                                                     to                                        search                                        for       AvAtualizacao.exe&lt;/p&gt;       &lt;p&gt;&lt;em&gt;Files&lt;br /&gt;  C:\windows\system32\AvAtualizacao.exe&lt;br /&gt;C:\windows\system32\AvMaster.exe&lt;br /&gt;C:\windows\system32\AVSCD1A40%ComputerName%.log&lt;br /&gt;C:\windows\system32\SysGrade.exe&lt;br /&gt;C:\windows\system32\SysUpGrade.exe&lt;br /&gt;C:\windows\system32\UpSys.exe&lt;br /&gt;C:\windows\system32\UpSysGrade.exe&lt;/em&gt;&lt;/p&gt;Folders&lt;br /&gt;&lt;p&gt;&lt;em&gt;-&lt;/em&gt;&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Files in Temp folder&lt;/em&gt;&lt;br /&gt;%Temp%\80EB2F5C&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Installer File&lt;/em&gt;&lt;br /&gt;[file                 and pathname of the sample #1]&lt;/p&gt;       &lt;p&gt;(We                                                                                                                                                                                                                    do                            not                            know              the                     name             or                 the                                            location                of                                           sample                           #1,                    it                                           could                         be              in                                your                                                    default                                                             download                                 location               or                    on                   the                                                                  desktop       or                      in      a                       Temp                                                                folder.                 The                                     files                 and                                                          folders                 in                   the                                     Temp                        folder                          can                         be                                                                                       automatically                                        removed,                             if                      you               use       a                                                                                       freeware                              temp                            files/                                    registry                                                    cleaner                                                         software                   like                                                                                  CCleaner)&lt;br /&gt;&lt;em&gt;Folders&lt;/em&gt;&lt;br /&gt;-&lt;/p&gt;    &lt;strong&gt;Repair Hosts File&lt;/strong&gt;  &lt;p&gt;To repair/ edit the hosts file. Login as administrator. open  the following file in notepad&lt;br /&gt; C:\ WINDOWS \system32 \drivers \etc \hosts&lt;br /&gt;remove anything other than 127.0.0.1 Localhost, and save and close the file.&lt;/p&gt;     &lt;p&gt; &lt;strong&gt;Registry            Keys&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;Some                                                                                                                                                                                                     of         the                          registry                   keys                      will                  be                                                                                                                                 automatically                                           removed                        if                    you        run                                                           Registry                       menu           of                                                               CCleaner.                         For                                                                             others                  you                    can                   see             the                          report                                                           mentioned                       at          the                                                                  beginning                                         of                   this                                                            article        .&lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Using  CCleaner&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;You                                                                                                                                                                                                      can                                                  easily                             remove              the                        files                    in              the                 temp                                               folder               by                                          running                                                                            CCleaner.                                          You                  can                      set                                                            CCleaner            to                 run                                                                          automatically                   each                                      time                            the                                            computer                                                                             starts.           Do                        not                                                           forget        to        run               CCleaner                                                   &amp;gt;                                                                              Registry                            menu       to                           remove                                       the                                              obsolete                                                        registry                                                              entries.&lt;/p&gt;       &lt;p&gt;more    about    CCleaner &lt;a href="http://comprolive.com:80/remove/../free/software/system-optimizer/ccleaner" target="_blank" title="CCleaner"&gt;on this link&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt;Video on how to use CCleaner&lt;/a&gt;]  &lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Free     tools          to repair disabled &lt;span class="notranslate"&gt;folder options,              registry, Task Manager&lt;/span&gt; etc&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Whereas        you          can repair disabled Folder Options, disabled &lt;span class="notranslate"&gt;Registry     Tools, disabled Task Manager, Disabled             System Restore&lt;/span&gt; etc     using these free tools&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Tools        for&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/enable-registry-tools-in-vista" target="_blank" title="tools for windows Vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools              for &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-run-command-task-manager-and-registry-tools-in-xp" target="_blank" title="tools for windows XP"&gt;Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools          for &lt;a href="http://comprolive.com:80/remove/../howto/windows7/re-enable-disabled-tools-in-windows7" target="_blank" title="re-enable tool for Windows7"&gt;Windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt; Use              the &lt;span class="notranslate"&gt;System    File Checker&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;To              repair altered deleted or modified windows system    files.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How              to run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility                 in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/system-file-checker-in-xp" target="_blank" title="system file checker in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How  to             run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility              in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system file checker in vista"&gt; windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to run System File Checker utility in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-file-checker-in-windows7" target="_blank" title="System File Checker in Windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt;Additional Information &lt;/strong&gt;&lt;br /&gt;                             Virus                   infections are      complex.      Most of     the       times  a     virus on    the               computer                downloads  more      files   and   make     it        complicated.    In    my           attempt  to     warn              users     about  the         different    ways   that    viruses        are           trying  to       infect    and             ways to  find    them    and        remove, I       have         created      videos   on          specific    Free        tools    and      manual             methods,     these        videos     could  be of       great    help&lt;br /&gt;     &lt;p&gt;1) To detect and remove malicious Alternate Data Streams - &lt;a href="http://www.youtube.com/watch?v=njAjGiSp98o" target="_blank" title="stream armour"&gt;Stream Armour  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;2) To detect and remove malicious Services -&lt;a href="http://www.youtube.com/watch?v=uCTUvgTHVsU" target="_blank" title="Advanced Winservice manager"&gt; Advanced WinService Manager  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;3) To detect and remove viruses in Fake recycle Bin - &lt;a href="http://www.youtube.com/watch?v=NfMtz3vzr3A" target="_blank" title="Fake recycle bin"&gt;Watch Video  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;4) keep an eye on suspicious connections using a Firewall  - &lt;a href="http://www.youtube.com/watch?v=W1qtOrQMfyk" target="_blank" title="comodo firewall video"&gt;Free Comodo Firewall &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;5) A free tool to detect and remove unwanted BHOs - &lt;a href="http://www.youtube.com/watch?v=sU_hY1r26_g" target="_blank" title="spyBHO remover video"&gt;SpyBHO Remover &lt;/a&gt;&lt;/p&gt;&lt;h3&gt;&lt;strong&gt;If nothing works &lt;/strong&gt;&lt;/h3&gt;&lt;p&gt;More often a virus makes it difficult to remove its files while you are logged in windows. It may do one of the following&lt;/p&gt;&lt;p&gt;1) You may see the suspicious virus process running in the task manager but can not remove it. &lt;/p&gt;&lt;p&gt;2) Even if you delete a virus file/ or terminate the process, the process may spawn again.&lt;/p&gt;&lt;p&gt;3) The virus may disable system restore, registry tools, task manager, safe boot etc. &lt;/p&gt;&lt;p&gt;If                                               any of these or other   things      done    by     the       virus      make     you          think/         feel           that   you   are   not     able to        remove the        virus     files         then   do   as         follows&lt;/p&gt;&lt;p&gt;1) Download a Knoppix Boot only CD ISO  image from in your language from one of the download links &lt;a href="http://www.knopper.net/knoppix/index-en.html" target="_blank" title="knpooix"&gt;from this website&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;2) Burn the ISO image on a blank CD &lt;/p&gt;&lt;p&gt;3) Put the Knoppix Boot disk in your computer's CD drive and boot from the CD&lt;/p&gt;&lt;p&gt;At the beginning of boot process you will see a prompt as boot:&lt;/p&gt;&lt;p&gt;Type&lt;br /&gt; knoppix screen=1280x1024&lt;br /&gt;knoppix screen=1024x728 or any suitable resolution that your computer supports. &lt;br /&gt;If                                               you do not specify screen            resolution,     the         knoppix      will      boot        with                  minimal     resolution   and   you     may  have    to     use              command  line         options      which   is                 inconvenient       for a    windows          user. &lt;/p&gt;&lt;p&gt;Once               the    knoppix            window     opens,          click   on  the           folder  icon in      the       bottom      left of    the           screen     to      open   the             PCMan   file    manager.      It     is  a         graphical    file           manager   in                Knoppix. It    has       two  panels.      In    the         left    panel   you     should        see       the           partitions of      your      hard     disk.          Select    the         partition  in              which   windows  is        installed   and          you      will            instantly  see    all    the           folders.   Now     you   can            access     the    contents   of          your       folders     and            delete      suspicious     files  and              folders   just   as    you          would    do      in   the      windows         explorer.  &lt;/p&gt;&lt;p&gt;When            you         are           finished.        Click    on  Log  off.     Now      you     can     Turn     Off or           restart.     Take        out       the     knoppix  CD      from your         drive        and     you    can        normally    boot  in                 windows.    &lt;/p&gt;&lt;p&gt;  Reprinted              with    permission from Threatexpert.com   &lt;/p&gt; &lt;p&gt; &lt;a href="http://comprolive.com:80/remove/about-this-site" target="_blank" rel="author"&gt;Sanjay C Rajure&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/gVgIAlMWSBvWXYUnpvoghCvoYdY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gVgIAlMWSBvWXYUnpvoghCvoYdY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/gVgIAlMWSBvWXYUnpvoghCvoYdY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gVgIAlMWSBvWXYUnpvoghCvoYdY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/removalguides/~4/ILKVO-DHdEE" height="1" width="1"/&gt;</description>
			<category>frontpage</category>
			<pubDate>Mon, 13 Feb 2012 08:21:43 +0000</pubDate>
		<feedburner:origLink>http://comprolive.com/remove/trojan/w32-bancos/avatualizacao-exe</feedburner:origLink></item>
		<item>
			<title>avmaster.exe</title>
			<link>http://feedproxy.google.com/~r/removalguides/~3/chEjlXnrlFs/avmaster-exe</link>
			<description>&lt;p&gt;The name avmaster.exe &lt;strong&gt; &lt;/strong&gt;               has                        appeared       in        a                                                                                                                                                                              virus                                                                                                                                                                                                                                                                                                                                                                    analysis                                                                                                                           report.                          You                     can                                                                                  see                                           it                                                  &lt;a href="http://www.threatexpert.com/report.aspx?md5=09758461d383bcd6944132c605073579" target="_blank" title="report"&gt;on this link&lt;/a&gt;&lt;/p&gt;        &lt;ul&gt;&lt;li&gt;The                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   installer          is                 of                                                             about 32 KB.              It could be    a       virus      Trojan             Infostealer         Bancos/         Banker/Banbra. &lt;/li&gt;&lt;li&gt;It                                has  threat    characteristics of ZBot -  a        banking       trojan        that            disables      firewall,    steals     sensitive        financial     data        (credit   card          numbers,       online      banking      login   details),     makes       screen          snapshots,          downloads      additional          components,   and         provides a       hacker   with  the            remote   access    to the            compromised    system.&lt;/li&gt;&lt;li&gt;It may stop services ALG/ Application Layer Gateway Service, SharedAccess/ Windows Firewall/Internet Connection Sharing (ICS)&lt;/li&gt;&lt;li&gt;Trojan.Bancos                                               runs silently in the      background    to         monitor     web         browser                       activities.       It    can      create  fake    login    page           for   certain        banking           sites       which   is      used    for     stealing         usernames   and         passwords                which       can be     sent        to the          attacker     via       e-mail.&lt;/li&gt;&lt;li&gt;It may modify the hosts file so as to redirect or block sites. Or it deletes the hosts file.&lt;/li&gt;&lt;li&gt;It                                     may delete safeboot registry keys.    This      will         prevent     the          computer      from      starting   in    safe   mode.   The     remedy  to    this     problem         is to         reinstall         windows. &lt;/li&gt;&lt;li&gt;According              to      Symantec &lt;em&gt;           &lt;br /&gt;&lt;br /&gt;&lt;/em&gt;The                                               Trojan is most often  spread    by     way    of    an       email            containing  a             social                  engineering   trick     such as  a     fake           email   from a    bank           asking       the   user      to          run  the        attached            program  and   perform     some        other            actions to        verify         their             banking     details.    If   the     user      complies             with    the     request      they           could          potentially         reveal   their         account           access        information           which    may    lead  to                significant       financial    loss.&lt;br /&gt;&lt;br /&gt;You   can  read the the   writeup at   Symantec &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2003-071710-2826-99&amp;tabid=2" target="_blank" title="Symantec writeup"&gt;on this link&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;     &lt;p&gt;                                                                                                                                                                                                                                                                                                              It                                                                             creates        avmaster.exe                                             and                                     other                    files             on                                                                          the                                                                                                                                                                   infected                                                                                             computer                                                                                                                                  that                                     you                                                                     need                                                                                    to                                                                                                                                                      search                                             and                                                                                               delete.   You   should also remove  the entries of  these  files from the  windows    startup. &lt;/p&gt;       &lt;p&gt;Warning:                                                                                                         It                is                 possible          that  some                       legitimate                        software          may        be                            using          the                 same                                         file                      names          as         that     of    the             virus                    files.                   You          do            not           have                   to                                 delete             these               files                if                    they            belong             to             some                                   legitimate               program                                    installed         on                   your                                    computer.                        Use                     Windows                  Defender             or                              SysInternals                       Process                                               Explorer   to                                                   differentiate           between                              them.                 The                                           information   in          this                    article           is                                              presented              without                                     making            any            claims                      regarding                its                                        usefulness   or                                                 otherwise.        If      you    have          any                   objections             or          questions,                        please            send   a            note      by                                                    adding a                                 comment    at         the         end          of                       this      page,     or               mail   on                                                                                                 support(at)comprolive.com &lt;/p&gt;     &lt;p&gt;&lt;strong&gt;Preventive measures&lt;/strong&gt;&lt;/p&gt;     &lt;ul&gt;&lt;li&gt;                                                      Most of  the                    viruses           enter        your                                          computer                      when        you              visit                        some                harmful                              website.                     If        you            use  a                             browser                              plugin          that                      warns                you                about                               harmful                     websites,   you                         can                        prevent                      this                  from                               happening. A                                       popular                    browser                 plugin             is                  called             Web                    Of         Trust                                (WOT),        you                             can                       install  it             from                 its                      website  &lt;a href="http://www.mywot.com/" target="_blank" title="WOT "&gt;on this link&lt;/a&gt;. &lt;br /&gt;[ &lt;a href="http://www.youtube.com/watch?v=8DHx7wioFuM" target="_blank" title="WOT video"&gt;a video about WOT plugin &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Blocking                                  Javascript of all sites by default can     help    to         prevent       drive    by          download     infections.  You   can   use       Noscript   Plugin     for   firefox      as             explained&lt;a href="http://www.youtube.com/watch?v=IMPHD5dkCAA" target="_blank" title="Noscript video"&gt; in this video&lt;/a&gt;.                                   Similar functionality can be achieved  in          Google's          Chromium         browser       using the    settings   in       Preferences   &amp;gt;       Under the   Hood   &amp;gt;        Content               Settings &amp;gt; Java    Script   &amp;gt;    Select   "Do    not     Allow".           After that  when         you visit a       site,   you   will see a    pop        up next to     the  address       bar   asking         you   if  you  want  to      allow   JavaScript    to   run      for    that      particular     site.         The    author  of     NoScript is      writing a         similar  plugin        for   IE9  called            GoodScript.    Keep an eye    on    when it         becomes        available.  &lt;/li&gt;&lt;li&gt;Some                                                                                         of      the       viruses  are                       downloaded         in                      Internet               Cache       or    in               the                         Temp                         folder          of      the            windows.            The               viruses                  get               activated          when                  these                      files            are                          executed.             You      can             reduce              the         risk           of            virus                   infection                   if         you            empty               your                browser                             cache and                    remove         windows                  temp                files                                 ocasionally,                        ideally         at       the            end     of      a                          browsing               session          or                   before                         closing       down     your                                computer.                   Some          programs                              like            CCleaner         can  be          set                    to        do             these           things                                             automatically. [&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt; a video about CCleaner &lt;/a&gt;]&lt;/li&gt;&lt;li&gt;Do                                                  not leave your computer          infected     and           insecure.    If     you       doubt           that             there       could  be        some  undetected       virus      on      your          computer,         don't    leave           it       like        that.   Format        the  hard    disk       and         reinstall              windows  and   all        other               programs.    That      is   the        sure      way to    clear              doubts.    &lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt; Using System Restore&lt;/strong&gt;   &lt;p&gt;If                                                                                                                                                                                                                             you                              know           the                                 duration                          since                        your                                                computer              is                                                                    infected,                    you                                          can                            try                to                                                                     restore                 your                           computer                at a                                                             prior              date,                               that                                         will              be                       an                 easy                        way                                      to                  undo                               the                                                             changes          done    by                        the                                                  virus&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Using        system   restore   in  &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-system-restore-in-xp" target="_blank" title="system restore in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using system restore                 in  &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system restore in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Using          system restore in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-restore-in-windows7" target="_blank" title="System Restore in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [ &lt;a href="http://www.youtube.com/watch?v=bhGrVLPIKXY" target="_blank" title="system restore video"&gt;Video of How to use System Restore&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Boot              in safe mode&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Sometimes    you can not        delete  a      file. You should boot in safe mode and then try    to        delete it.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How       to boot in safe in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/boot-in-safe-mode-in-xp" target="_blank" title="safe mode in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to boot in safe mode                 in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/boot-in-safe-mode-in-vista" target="_blank" title="safe mode in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to boot in safe mode in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/boot-in-safe-mode-in-windows7" target="_blank" title="safeboot in windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt;  View              Hidden Files&lt;/strong&gt;&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;You need to enable                 to view hidden files and folders before searching.&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-to-view-hidden-files-in-xp" target="_blank" title="view hidden files in xp"&gt; Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to Enable to View Hidden Files and              Folders in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/view-hidden-files-in-vista" target="_blank" title="view hidden files in vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How         to Enable to View Hidden Files  and Folders in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/view-hidden-files-in-windows7" target="_blank" title="Enable to view hidden files in Windows7"&gt;Windows7             &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    [&lt;a href="http://www.youtube.com/watch?v=0ahhDa_bp0A" target="_blank" title="Enable Hidden Files video "&gt; Video of How to enable Hidden files and folders&lt;/a&gt; ]&lt;br /&gt;       &lt;p&gt;&lt;strong&gt; Remove             Processes from &lt;span class="notranslate"&gt;Task Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;     Press              Ctrl Alt Del keys to open the &lt;span class="notranslate"&gt;Task          Manager&lt;/span&gt;.                         Select                                                                                                                                                                                          Processes                    tab.                         You                                          will               see     a                                   list.                         Look                     for                                                           the  names  avmaster.exe                    in             it.                                       Select             if                        found                                          any and                                            press                                                 the                                  End                              Process                 button.                              It                    will         ask                          for                                     your                                                              confirmation                                        to                                end                                           that                                        process.                             Select                   Yes.                You                       can                                         end                             one                            process                              at    a                                           time.                         You                                                                                                                                                                                                                                                                                  can                             find                                                                   out                         if  a                                                                       process                      in  &lt;span class="notranslate"&gt;Task                       Manager&lt;/span&gt;     is      good                     or        bad  by  using  &lt;span class="notranslate"&gt;Windows                                Defender in  XP and Vista&lt;/span&gt;.                                                                                                                                                                                                                                                                       It                                       shows                                                                the                                                                                                                path                                    of         a                                                                                                                  process                                and                                            its                                                                                                                                               publisher.                                                                Harmful                                                                                                                                                                                                                     processes                                                     may                                       be                                                                        shown                                                                  under                                                                         Unknown                                                                                                                   Publisher                                   in                                                       &lt;span class="notranslate"&gt;windows                             defender&lt;/span&gt;.  Whereas in Windows7 you  can find that out from the task manager itself. You can watch a video on How to use &lt;a href="http://www.youtube.com/watch?v=TxE8zS9iiSI" target="_blank" title="Windows Defender video"&gt;Windows Defender&lt;/a&gt;. &lt;br /&gt;     &lt;ul&gt;&lt;li&gt;How           to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/use-windows-defender-in-xp" target="_blank" title="windows defender in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How to use &lt;span class="notranslate"&gt;Windows Defender&lt;/span&gt; in &lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-windows-defender-in-vista" target="_blank" title="windows defender in vista"&gt;windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to use Windows Defender in &lt;a href="http://comprolive.com:80/remove/../howto/windows7/use-windows-defender-in-windows7" target="_blank" title="Use Windows Defender in Windows7"&gt;windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;     &lt;p&gt; Or                 you can use &lt;span class="notranslate"&gt;Sysinternal's    Process          Explorer&lt;/span&gt;. How  to use      Sysinternal's &lt;a href="http://comprolive.com:80/remove/../free/software/system-tools/process-explorer" target="_blank" title="sysinternal's process explorer"&gt;Process Explorer&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=aD_E0q-x3ww" target="_blank" title="sysinternal's video"&gt;Video of How to use Sysinternal's/ Windows Process Explorer&lt;/a&gt;] &lt;/p&gt;     &lt;p&gt;&lt;strong&gt; Removing              entry from windows startup&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;The                                                                                                                                                                                                                system                                                                                       configuration                 can             be                                          started             in                    xp                     and                 in                                                vista        by                                        typing                                                                 msconfig          in                                                         the                 run              box/                                   start                       menu                                    search                                         box. &lt;br /&gt;In                                            xp         by                                                        clicking     on                                                                  Start                                        &amp;gt;                      run        .                   The                                          windows                     startup                             is                                                     reversible.                                      You                      can                   check                 /                                                                                       uncheck                             any                 entry                          from                                   windows                                               startup        any                                                   number              of                                times.   Watch  a      video    on &lt;a href="http://www.youtube.com/watch?v=0HVaxH_k5W8" target="_blank" title="windows startup video"&gt;How to Use the Windows Startup&lt;/a&gt;&lt;/p&gt;       &lt;p&gt;Open                                                                                                                                                 system                                                                          configuration                                               window.Click                               on                     the                                                                                 Startup                                           tab.                 You                     will                see             a                              list             all                    the                                          programs                                     that              are                                                            scheduled                                                                 to                               start        with                                                   windows.                    Expand                                   the                                  middle                                                                              column                               using                             your                           mouse                                  pointer.                                     That                   will                       show                          you                the                                                          full                        path                              of          the                                                       program.                                     Locate                      and                                             uncheck                                the                                  boxes                        in                                           front        of                                              these                                           names                               "avmaster.exe"                                              (also                  look                 for                                                         any                                  other                                                                                   suspicious                         names)Press                                              Apply         ,                                                         Press                                                      Close/Ok   ,                                                               Select                                    "do   not    restart"                           at    the                            next      prompt.&lt;/p&gt;     &lt;p&gt;&lt;strong&gt;modified services&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;                           While      still  in the above window, click on        Services      tab.     Click    on      "Hide     All     Microsoft       Services".  Look    for   ALG/     Application       Layer    Gateway           Service,     SharedAccess/  Windows         Firewall/Internet          Connection    Sharing       (ICS).  If   they  are        checked,  then       do nothing. If they    are   unchecked       then  you  need   to      check         them again.  &lt;/p&gt;     &lt;p&gt;Locate       and Check  the  box      in         front of      these   services  if they    are     unchecked.    Press   Apply.     Press          Ok/close.  Click  on          "restart"   at    the   next   prompt.    &lt;/p&gt;    &lt;strong&gt; Deleting          files&lt;/strong&gt;   &lt;p&gt;The                                                                                                                                                                                                    computer              will                                     restart                         now.                                                        Delete                                the                                                                   following                                files                       and                                             folders.                    Boot                 in                 safe                      mode                           or                                                       boot               in                          the                                         dos               prompt                                    if                                  needed.     You                                  can              use                                      windows                                       search                                        utility                                                    to                                       search                                        for      avmaster.exe&lt;/p&gt;       &lt;p&gt;&lt;em&gt;Files&lt;br /&gt;  C:\windows\system32\AvAtualizacao.exe&lt;br /&gt;C:\windows\system32\AvMaster.exe&lt;br /&gt;C:\windows\system32\AVSCD1A40%ComputerName%.log&lt;br /&gt;C:\windows\system32\SysGrade.exe&lt;br /&gt;C:\windows\system32\SysUpGrade.exe&lt;br /&gt;C:\windows\system32\UpSys.exe&lt;br /&gt;C:\windows\system32\UpSysGrade.exe&lt;/em&gt;Folders&lt;/p&gt;&lt;p&gt;&lt;em&gt;Folders &lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;-&lt;/em&gt;     &lt;/p&gt;&lt;p&gt;&lt;em&gt;Files in Temp folder&lt;/em&gt;&lt;br /&gt;%Temp%\80EB2F5C&lt;/p&gt;     &lt;p&gt;&lt;em&gt;Installer File&lt;/em&gt;&lt;br /&gt;[file                 and pathname of the sample #1]&lt;/p&gt;       &lt;p&gt;(We                                                                                                                                                                                                                 do                           not                            know             the                     name             or                 the                                           location                of                                          sample                           #1,                   it                                           could                        be              in                                your                                                   default                                                            download                                location               or                    on                  the                                                                 desktop       or                      in      a                      Temp                                                               folder.                 The                                     files                and                                                         folders                 in                   the                                    Temp                        folder                         can                         be                                                                                      automatically                                       removed,                             if                     you               use       a                                                                                      freeware                             temp                            files/                                   registry                                                   cleaner                                                        software                   like                                                                                 CCleaner)&lt;br /&gt;&lt;em&gt;Folders&lt;/em&gt;&lt;br /&gt;-&lt;/p&gt;    &lt;strong&gt;Repair Hosts File&lt;/strong&gt;  &lt;p&gt;To repair/ edit the hosts file. Login as administrator. open  the following file in notepad&lt;br /&gt; C:\ WINDOWS \system32 \drivers \etc \hosts&lt;br /&gt;remove anything other than 127.0.0.1 Localhost, and save and close the file.&lt;/p&gt;     &lt;p&gt; &lt;strong&gt;Registry            Keys&lt;/strong&gt;&lt;/p&gt;     &lt;p&gt;Some                                                                                                                                                                                                  of         the                         registry                   keys                     will                  be                                                                                                                               automatically                                           removed                       if                    you        run                                                          Registry                      menu           of                                                              CCleaner.                         For                                                                            others                 you                    can                   see             the                         report                                                          mentioned                       at          the                                                                 beginning                                        of                   this                                                           article        .&lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Using  CCleaner&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;You                                                                                                                                                                                                   can                                                 easily                             remove             the                        files                    in             the                 temp                                              folder               by                                         running                                                                           CCleaner.                                          You                 can                      set                                                           CCleaner            to                 run                                                                        automatically                   each                                     time                            the                                           computer                                                                            starts.           Do                        not                                                          forget        to       run               CCleaner                                                  &amp;gt;                                                                             Registry                            menu       to                          remove                                       the                                             obsolete                                                       registry                                                             entries.&lt;/p&gt;       &lt;p&gt;more    about    CCleaner &lt;a href="http://comprolive.com:80/remove/../free/software/system-optimizer/ccleaner" target="_blank" title="CCleaner"&gt;on this link&lt;/a&gt;&lt;/p&gt;     &lt;p&gt;[&lt;a href="http://www.youtube.com/watch?v=OVjpcu5eMtc" target="_blank" title="ccleaner video"&gt;Video on how to use CCleaner&lt;/a&gt;]  &lt;/p&gt;       &lt;p&gt;&lt;strong&gt; Free     tools          to repair disabled &lt;span class="notranslate"&gt;folder options,              registry, Task Manager&lt;/span&gt; etc&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;Whereas        you          can repair disabled Folder Options, disabled &lt;span class="notranslate"&gt;Registry     Tools, disabled Task Manager, Disabled             System Restore&lt;/span&gt; etc     using these free tools&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;Tools        for&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/enable-registry-tools-in-vista" target="_blank" title="tools for windows Vista"&gt; Windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools              for &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/enable-run-command-task-manager-and-registry-tools-in-xp" target="_blank" title="tools for windows XP"&gt;Windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Tools          for &lt;a href="http://comprolive.com:80/remove/../howto/windows7/re-enable-disabled-tools-in-windows7" target="_blank" title="re-enable tool for Windows7"&gt;Windows7   &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;       &lt;p&gt;&lt;strong&gt; Use              the &lt;span class="notranslate"&gt;System    File Checker&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;       &lt;p&gt;To              repair altered deleted or modified windows system    files.&lt;/p&gt;       &lt;ul&gt;&lt;li&gt;How              to run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility                 in &lt;a href="http://comprolive.com:80/remove/../howto/win-xp/system-file-checker-in-xp" target="_blank" title="system file checker in xp"&gt;windows XP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How  to             run &lt;span class="notranslate"&gt;System File Checker&lt;/span&gt; utility              in&lt;a href="http://comprolive.com:80/remove/../howto/windows-vista/use-system-restore-in-vista" target="_blank" title="system file checker in vista"&gt; windows Vista&lt;/a&gt;&lt;/li&gt;&lt;li&gt;How          to run System File Checker utility in&lt;a href="http://comprolive.com:80/remove/../howto/windows7/system-file-checker-in-windows7" target="_blank" title="System File Checker in Windows7"&gt; windows7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;    &lt;strong&gt;Additional Information &lt;/strong&gt;&lt;br /&gt;                            Virus                   infections are     complex.      Most of     the       times  a     virus on    the              computer                downloads  more      files   and   make    it        complicated.    In    my           attempt  to     warn             users     about  the         different    ways   that    viruses       are           trying  to       infect    and             ways to find    them    and        remove, I       have         created     videos   on          specific    Free        tools    and      manual            methods,     these        videos     could  be of       great   help&lt;br /&gt;     &lt;p&gt;1) To detect and remove malicious Alternate Data Streams - &lt;a href="http://www.youtube.com/watch?v=njAjGiSp98o" target="_blank" title="stream armour"&gt;Stream Armour  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;2) To detect and remove malicious Services -&lt;a href="http://www.youtube.com/watch?v=uCTUvgTHVsU" target="_blank" title="Advanced Winservice manager"&gt; Advanced WinService Manager  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;3) To detect and remove viruses in Fake recycle Bin - &lt;a href="http://www.youtube.com/watch?v=NfMtz3vzr3A" target="_blank" title="Fake recycle bin"&gt;Watch Video  &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;4) keep an eye on suspicious connections using a Firewall  - &lt;a href="http://www.youtube.com/watch?v=W1qtOrQMfyk" target="_blank" title="comodo firewall video"&gt;Free Comodo Firewall &lt;/a&gt;&lt;/p&gt;     &lt;p&gt;5) A free tool to detect and remove unwanted BHOs - &lt;a href="http://www.youtube.com/watch?v=sU_hY1r26_g" target="_blank" title="spyBHO remover video"&gt;SpyBHO Remover &lt;/a&gt;&lt;/p&gt;&lt;h3&gt;&lt;strong&gt;If nothing works &lt;/strong&gt;&lt;/h3&gt;&lt;p&gt;More often a virus makes it difficult to remove its files while you are logged in windows. It may do one of the following&lt;/p&gt;&lt;p&gt;1) You may see the suspicious virus process running in the task manager but can not remove it. &lt;/p&gt;&lt;p&gt;2) Even if you delete a virus file/ or terminate the process, the process may spawn again.&lt;/p&gt;&lt;p&gt;3) The virus may disable system restore, registry tools, task manager, safe boot etc. &lt;/p&gt;&lt;p&gt;If                                              any of these or other  things      done    by     the       virus      make     you         think/         feel           that   you   are   not     able to       remove the        virus     files         then   do   as         follows&lt;/p&gt;&lt;p&gt;1) Download a Knoppix Boot only CD ISO  image from in your language from one of the download links &lt;a href="http://www.knopper.net/knoppix/index-en.html" target="_blank" title="knpooix"&gt;from this website&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;2) Burn the ISO image on a blank CD &lt;/p&gt;&lt;p&gt;3) Put the Knoppix Boot disk in your computer's CD drive and boot from the CD&lt;/p&gt;&lt;p&gt;At the beginning of boot process you will see a prompt as boot:&lt;/p&gt;&lt;p&gt;Type&lt;br /&gt; knoppix screen=1280x1024&lt;br /&gt;knoppix screen=1024x728 or any suitable resolution that your computer supports. &lt;br /&gt;If                                              you do not specify screen           resolution,     the         knoppix      will      boot       with                  minimal     resolution   and   you     may  have   to     use              command  line         options      which   is                inconvenient       for a    windows          user. &lt;/p&gt;&lt;p&gt;Once              the    knoppix            window     opens,          click  on  the           folder  icon in      the       bottom      left of   the           screen     to      open   the             PCMan   file   manager.      It     is  a         graphical    file           manager  in                Knoppix. It    has       two  panels.      In    the        left    panel   you     should        see       the          partitions of      your      hard     disk.          Select    the        partition  in              which   windows  is        installed   and         you      will            instantly  see    all    the          folders.   Now     you   can            access     the    contents   of         your       folders     and            delete      suspicious    files  and              folders   just   as    you          would    do     in   the      windows         explorer.  &lt;/p&gt;&lt;p&gt;When            you        are           finished.        Click    on  Log  off.     Now     you     can     Turn     Off or           restart.     Take        out      the     knoppix  CD      from your         drive        and     you   can        normally    boot  in                 windows.    &lt;/p&gt;&lt;p&gt;  Reprinted              with    permission from Threatexpert.com   &lt;/p&gt; &lt;p&gt; &lt;a href="http://comprolive.com:80/remove/about-this-site" target="_blank" rel="author"&gt;Sanjay C Rajure&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/iED2gItBc5knHoVlZn2OyGqnw_4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iED2gItBc5knHoVlZn2OyGqnw_4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/iED2gItBc5knHoVlZn2OyGqnw_4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iED2gItBc5knHoVlZn2OyGqnw_4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/removalguides/~4/chEjlXnrlFs" height="1" width="1"/&gt;</description>
			<category>frontpage</category>
			<pubDate>Mon, 13 Feb 2012 08:14:28 +0000</pubDate>
		<feedburner:origLink>http://comprolive.com/remove/trojan/w32-bancos/avmaster-exe</feedburner:origLink></item>
		<item>
			<title>msnsmgsr.exe</title>
			<link>http://feedproxy.google.com/~r/removalguides/~3/TLDE-fgJXwQ/msnsmgsr-exe</link>
			<description>&lt;p&gt;Suspicious files name msnsmgsr.exe has  appeared in a             virus analysis report. You  can see it  &lt;a href="http://www.threatexpert.com/report.aspx?md5=9338142884ceec9da8125b3e774e14d0" target="_blank" title="report"&gt;on this link&lt;/a&gt;&lt;/p&gt;&lt;p&gt;This file has a similarity with and should not be misunderstood as msnmsgr.exe which was the name of the process of MSN Messenger. This file has been replaced by msmsgs.exe in the current version of this application which is now called as Windows Live messenger.  &lt;/p&gt;&lt;ul&gt;&lt;li&gt;The                                                                                                                                                                                                                                                                                                                                                   
