<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4003604145017124760</id><updated>2011-11-27T16:33:26.252-08:00</updated><category term='Vundo Trojan Removal'/><category term='Net Screen Watcher'/><category term='newfolder.exe Removal'/><category term='SCVHOST.EXE Removal'/><category term='Zlob Trojan Removal'/><category term='Trojan-horse Removal'/><category term='WORM_AGENT.VDO Removal'/><category term='mobile virus removal'/><category term='Virus Removal Tools'/><category term='Remove Virus'/><category term='Conficker Removal'/><category term='Trojan Removal'/><category term='Virus Removal Videos'/><title type='text'>Virus Experts</title><subtitle type='html'>Solutions to Trojan, Adware, Spyware, Malware and Backdoor Virus Worms.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>20</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-1619096872607892043</id><published>2009-06-09T21:22:00.000-07:00</published><updated>2009-06-09T21:42:30.796-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Conficker Removal'/><title type='text'>Conficker Manual Removal Guide</title><content type='html'>&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Conficker Description&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;div align="justify"&gt;Conficker, also known as W32/Conficker.worm, Win32/Conficker.A, W32.Downadup, Downadup and Kido, is a worm that exploits flaws found in Windows MS08-067 vulnerability. When Conficker infects your PC, it may prevent you from accessing security websites and disables Windows system services such as Windows Security Center, Windows Error Reporting and Windows Defender. The danger with Conficker is its ability to spread itself to other vulnerable computers through network shares. If one computer in a network is infected, then it can spread to other computers within that network. Microsoft has released a patch to fix the Windows vulnerability. &lt;/div&gt;&lt;div align="justify"&gt; &lt;/div&gt;&lt;div align="justify"&gt; &lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Conficker Manual Removal Instructions&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;strong&gt;1b&lt;/strong&gt;. How to Kill Conficker DLL files.&lt;/div&gt;&lt;ol&gt;&lt;li&gt;Right-click the Explorer.exe process and choose the option “Properties”.&lt;/li&gt;&lt;li&gt;Click on the “Threads” Tab, locate and highlight the Conficker DLL files listed below.&lt;/li&gt;&lt;li&gt;To kill Conficker DLL files, click the “Kill” button.&lt;/li&gt;&lt;li&gt;Kill the following Conficker DLL files: &lt;/li&gt;&lt;/ol&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="justify"&gt;%All Users Application Data%\[RANDOM FILE NAME].dll &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;%Program Files%\Movie Maker\[RANDOM FILE NAME].dll&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;%Program Files%\Internet Explorer\[RANDOM FILE NAME].dll&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;%Temp%\[RANDOM FILE NAME].dll&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;vhoinp.dll&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;%System%\[RANDOM FILE NAME].dll &lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p align="justify"&gt;&lt;strong&gt;Step 1&lt;/strong&gt;: How to Delete Conficker Registry Keys and Values.&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Right-click on your Desktop &gt; select “New” option &gt; select “Text Document” (.txt file) option.&lt;/li&gt;&lt;li&gt;Rename the .txt file as a .reg file and call it “Delete_Registry_Conficker_Entities.reg”. This renamed .reg file is a command that creates a shortcut to your Windows registry and allows you to easily delete registry values.&lt;/li&gt;&lt;li&gt;Right-click and select the “Edit” option.&lt;/li&gt;&lt;li&gt;Copy and paste the Conficker keys listed below.&lt;/li&gt;&lt;li&gt;In the menu bar, go to “File” &gt; select “Save” &gt; then click the “X” button to close the file.&lt;/li&gt;&lt;li&gt;Double-click on the .reg file.&lt;/li&gt;&lt;li&gt;When the message box appears saying “Are you sure you want to add the information in C:DOCUME~1%username%DesktopDELETE~1.REG to the registry?”, click the “Yes” button.&lt;/li&gt;&lt;li&gt;When the message box appears saying “Information in C:DOCUME~1%username%DesktopDELETE~1.REG has been successfully entered into the registry.”, click the “OK” button.&lt;/li&gt;&lt;li&gt;The Conficker registry keys have been deleted from your registry.&lt;/li&gt;&lt;li&gt;Copy and paste the following Conficker keys:Windows Registry Editor Version 5.00&lt;br /&gt;[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\vhoinp.dll]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\vhoinp.dll]&lt;br /&gt;[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\vhoinp.dll]&lt;br /&gt;[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\vhoinp.dll]&lt;br /&gt;[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\vhoinp.dll]&lt;br /&gt;[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\vhoinp.dll]&lt;br /&gt;[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\vhoinp.dll]&lt;br /&gt;[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\vhoinp.dll]&lt;br /&gt;[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\vhoinp.dll]&lt;br /&gt;[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\vhoinp.dll]&lt;br /&gt;[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX\vhoinp.dll]&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-1619096872607892043?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/1619096872607892043/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=1619096872607892043' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/1619096872607892043'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/1619096872607892043'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2009/06/conficker-manual-removal-guide.html' title='Conficker Manual Removal Guide'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-8446134308051515712</id><published>2009-01-16T07:11:00.000-08:00</published><updated>2009-01-23T06:09:51.764-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Trojan Removal'/><title type='text'>Generic Trojan / Adware Infestation Removal Procedures</title><content type='html'>&lt;BR&gt;&lt;div style="text-align: left;"&gt;&lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;&lt;strong&gt;Generic Trojan / Adware Removal Procedures &lt;/strong&gt;&lt;br /&gt;         (&lt;strong&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;2 different procedures&lt;/span&gt;&lt;/strong&gt; you can try for malware removal)&lt;strong&gt;&lt;br /&gt;       &lt;/strong&gt;By: David Lipman&lt;/span&gt;&lt;/p&gt;           &lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;&lt;strong&gt;Procedure #1 &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;           &lt;ol&gt;&lt;li&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;Download the following four items (links will open a new browser window)...        &lt;br /&gt;       &lt;/span&gt;             &lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;McAfee Stinger&lt;br /&gt;             &lt;a href="http://vil.nai.com/vil/stinger/" target="_blank"&gt;http://vil.nai.com/vil/stinger/&lt;/a&gt;&lt;br /&gt;       &lt;br /&gt;           Trend Sysclean Package&lt;br /&gt;             &lt;a href="http://www.trendmicro.com/download/dcs.asp" target="_blank"&gt;http://www.trendmicro.com/download/dcs.asp&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt; Latest Trend Virus Pattern Files.  (example; lpt285.zip&lt;strong&gt;*&lt;/strong&gt;)&lt;br /&gt;             &lt;a href="http://www.trendmicro.com/download/pattern.asp" target="_blank"&gt;http://www.trendmicro.com/download/pattern.asp&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;(*The file name lpt285.zip is simply an example name of the file and you'll find the filename posted at TrendMicro will have a higher number than 285. Each time TrendMicro produces new Pattern Files the number in the file name will be incremented accordingly.)&lt;/span&gt;&lt;/div&gt;             &lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt; Ad-Aware SE (free personal edition)&lt;br /&gt;             &lt;a href="http://www.lavasoftusa.com/" target="_blank"&gt;http://www.lavasoftusa.com/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;    &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;Create a new directory.&lt;br /&gt;On drive "C:\"&lt;br /&gt;(e.g., "c:\New Folder")&lt;br /&gt;or the desktop&lt;br /&gt;(e.g., "C:\Documents and Settings\username\Desktop\New Folder")&lt;/span&gt;&lt;/p&gt;             &lt;p style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt; Place SYSCLEAN.COM (the Trend Sysclean Package referenced above) into the new directory you created. Extract the latest Trend Virus Pattern Files (Example: lpt$vpn.285 and WHATSNEW.TXT) from the zip file you downloaded above into the same new directory you created. The Trend Pattern File contained in the ZIP file &lt;strong&gt;must be placed in the same directory&lt;/strong&gt; as SYSCLEAN.COM!&lt;/span&gt;&lt;/p&gt;             &lt;p style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;&lt;strong&gt;Important&lt;/strong&gt;: The TrendMicro Pattern file is updated reguarly. Aywhere from once per day to a few times in a day. Always make sure you have the latest version of SYSCLEAN.COM and the Pattern File before you scan your platform. The McAfee Stinger Internet worm and Trojan removal tool is upgraded periodically. Always make sure you have the latest version of McAfee Stinger utility before you scan your platform.&lt;/span&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;Install and Update Ad-Aware with the latest definitions.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;      &lt;br /&gt;     &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;If you are using WinME or WinXP, disable System Restore.&lt;br /&gt;         &lt;a href="http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.aspx" target="_blank"&gt;http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.aspx&lt;/a&gt;&lt;br /&gt;     &lt;br /&gt;     &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;Reboot your PC into Safe Mode [F8 key during boot process].&lt;br /&gt;&lt;br /&gt;   How to Boot Into Safe Mode:&lt;br /&gt;   &lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&amp;amp;src=sec_doc_nam" target="_blank"&gt;&lt;br /&gt;   Generic&lt;/a&gt;&lt;/span&gt;   &lt;br /&gt;   &lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;&lt;a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx" target="_blank"&gt;Windows XP&lt;/a&gt;&lt;/span&gt;   &lt;br /&gt;   &lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;&lt;a href="http://support.microsoft.com/kb/310353" target="_blank"&gt;How to perform a clean boot in Windows XP&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;   &lt;/span&gt;        &lt;/li&gt;&lt;li style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;Using McAfee Stinger, the Trend Sysclean utility and Ad-Aware, perform a Full Scan of your     platform and clean and/or delete any infectors and/or parasites found     (a few cycles may be needed).&lt;br /&gt;&lt;br /&gt; &lt;/span&gt;&lt;/li&gt;&lt;li style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;Restart your PC and perform a "final" Full Scan of your platform using McAfee Stinger, the Trend Sysclean utility and Ad-Aware.&lt;br /&gt;&lt;br /&gt; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;If you are using WinME or WinXP,Re-enable System Restore and re-apply any     System Restore preferences (e.g. HD space to use suggested 400 ~ 600MB).&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;&lt;br /&gt; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;Reboot your PC.&lt;br /&gt;&lt;br /&gt; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;If you are using WinME or WinXP, create a new Restore point&lt;/span&gt;&lt;br /&gt; &lt;/li&gt;&lt;/ol&gt;           &lt;blockquote&gt;             &lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;End of  Procedure #1 &lt;/span&gt;&lt;/p&gt;             &lt;p align="center"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;* * *     Please report back your results  * * *&lt;/span&gt;&lt;/p&gt;           &lt;/blockquote&gt;&lt;br /&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;&lt;strong&gt;Procedure #2 &lt;/strong&gt;&lt;/span&gt;           &lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;Download MULTI_AV.EXE from the URL --&lt;br /&gt;             &lt;a href="http://www.pctipp.ch/index.cfm?pid=1411&amp;amp;pk=28470"&gt;http://www.pctipp.ch/index.cfm?pid=1411&amp;amp;pk=28470&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;           &lt;p style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;It is a self-extracting ZIP file that contains the Kixtart Script Interpreter { http://kixtart.org - Kixtart is CareWare } 4 batch files, 6 Kixtart scripts, one Link (.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will simplify the process of using; Sophos, Trend, Kaspersky and McAfee Anti VirusCommand Line Scanners to remove viruses, Trojans and various other malware.&lt;/span&gt;&lt;/p&gt;           &lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}&lt;br /&gt;           This will bring up the initial menu of choices and should be executed in Normal Mode.&lt;br /&gt;           This way all the components can be downloaded from each AV vendor’s web site.&lt;br /&gt;           The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.&lt;/span&gt;&lt;/p&gt;           &lt;p style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;You can choose to go to each menu item and just download the needed files or you can download the files and perform a scan in Normal Mode. Once you have downloaded the files needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key during boot] and re-run the menu again and choose which scanner you want to run in Safe Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.&lt;/span&gt;&lt;/p&gt;           &lt;p style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help file.&lt;/span&gt;&lt;/p&gt;           &lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;To use this utility, perform the following...&lt;br /&gt;           Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }&lt;br /&gt;           Choose; Unzip&lt;br /&gt;           Choose; Close&lt;/span&gt;&lt;/p&gt;           &lt;p&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;Execute; C:\AV-CLS\StartMenu.BAT&lt;br /&gt;           { or Double-click on 'Start Menu' in C:\AV-CLS }&lt;/span&gt;&lt;/p&gt;           &lt;p style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your FireWall to allow it to download the needed AV vendor related files.&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;           &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;End of  Procedure #2 &lt;/span&gt;&lt;/p&gt;           &lt;p align="center"&gt;&lt;span style="font-family:Arial,Helvetica,sans-serif;"&gt;* * *     Please report back your results  * * *&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-8446134308051515712?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/8446134308051515712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=8446134308051515712' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/8446134308051515712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/8446134308051515712'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2009/01/generic-trojan-adware-infestation.html' title='Generic Trojan / Adware Infestation Removal Procedures'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-2076526060884260487</id><published>2009-01-16T01:10:00.000-08:00</published><updated>2009-01-16T21:57:19.041-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mobile virus removal'/><title type='text'>How to remove virus from mobile phone?</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;Shit happens, or any virus has attacked your mobile, its inevitable          u do something wrong, Now what to do you simply have to format your phone.          To format the phone, press *#7370#, then enter the lock code, which is          the sec code of the phone. NOTE: battery must be filled, else if format          is disrupted by low battery, consequences will be disastrous.&lt;br /&gt;      I heard the code *#7780# works too, pretty much the same i think. For          6600 users, to format the fone, there's an alternative way. Press and          hold &lt;3&gt;, &lt;*&gt;, and the buttons, then power on fone, keep holding          on the 3 buttons, till u come to a format screen. This method ONLY works          on 6600, and need not enter the sec code. BUT sec code wun be reset to          default 12345 &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-2076526060884260487?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/2076526060884260487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=2076526060884260487' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/2076526060884260487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/2076526060884260487'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2009/01/how-to-remove-virus-from-mobile-phone.html' title='How to remove virus from mobile phone?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-4410555396126755973</id><published>2009-01-03T22:58:00.000-08:00</published><updated>2009-01-16T21:19:52.058-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Net Screen Watcher'/><title type='text'>How to Manually Remove Net Screen Watcher ?</title><content type='html'>&lt;br&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Net Screen Watcher:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1. a spyware program&lt;br /&gt;&lt;br /&gt;2. monitors user activity on the compromised computer&lt;br /&gt;&lt;br /&gt;3. can capture screenshots of the compromised computer&lt;br /&gt;&lt;br /&gt;4. also modifies Windows registry&lt;br /&gt;&lt;br /&gt;5. run each time Windows is started&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Solution:&lt;br /&gt;&lt;/span&gt;&lt;div class="commenttext-admin"&gt;&lt;p&gt;1. Temporarily &lt;span style="color: rgb(204, 51, 0);"&gt;Turn off&lt;/span&gt; System Restore.&lt;br /&gt;2. Update the virus definitions.&lt;br /&gt;3. Reboot computer in SafeMode (During BootUp process Press &lt;b&gt;F8&lt;/b&gt;)&lt;br /&gt;4. Run a full system scan and clean/delete all infected file(s)&lt;br /&gt;5. Delete/Modify any values added to the registry. &lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Click &lt;b&gt;Start &lt;/b&gt;&gt; &lt;b&gt;Run&lt;/b&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Type &lt;b&gt;regedit&lt;/b&gt; at the box&lt;/li&gt;&lt;li&gt;Click           OK.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span style="color: rgb(249, 124, 25);"&gt;Navigate to and delete the following registry entries:&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Net Screen Watcher ÍøÂçÆÁÄ»¼àÊÓ¹ÜÀí¶Ë ÆóÒµ°æ V1.78 (2008.08.26) wxw.mynsw.cn&lt;/li&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Net Screen Watcher ÍøÂçÆÁÄ»¼àÊÓ¹ÜÀí¶Ë ÆóÒµ°æ V1.78 (2008.08.26) wxw.mynsw.cn&lt;/li&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Net Screen WatcherÓÃ»§¶Ë£¨ÊÜ¼àÊÓ¶Ë£© ÆóÒµ°æ For Win98 V1.68 Beta3&lt;/li&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Net Screen WatcherÓÃ»§¶Ë£¨ÊÜ¼àÊÓ¶Ë£© ÆóÒµ°æ For Windows Vista V1.68 Beta3&lt;/li&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Net Screen WatcherÓÃ»§¶Ë£¨ÊÜ¼àÊÓ¶Ë£© ÆóÒµ°æ For Windows2000/XP/2003 V1.68 (2007.08.03) wxw.mynsw.cn&lt;/li&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Net Screen WatcherÓÃ»§¶Ë£¨ÊÜ¼àÊÓ¶Ë£© ÆóÒµ¾«¼ò°æ For Windows2000/XP/2003 V1.68 (2007.11.14) wxw.mynsw.cn&lt;/li&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SOFTWARE\ZQNSWkey&lt;/li&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SOFTWARE\ZQkey&lt;/li&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NSWServer&lt;/li&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR&lt;/li&gt;&lt;li&gt; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”mynsw” = “C:\Program Files\Net Screen Watcher\wntsrv.exe”&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;6. Exit registry editor and restart the computer.&lt;br /&gt;7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software.&lt;/p&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-4410555396126755973?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/4410555396126755973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=4410555396126755973' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/4410555396126755973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/4410555396126755973'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2009/01/how-to-manually-remove-net-screen.html' title='How to Manually Remove Net Screen Watcher ?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-4617467123432438831</id><published>2008-12-26T05:38:00.000-08:00</published><updated>2009-01-16T21:20:30.205-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vundo Trojan Removal'/><title type='text'>How To Manually Remove  Vundo Trojan ?</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Vundo Description:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Vundo is a widely-spread trojan that shows large amount of unsolicited pop-up advertisements. The spyware also silently downloads from the Internet and runs arbitrary potentially harmful files, mostly adware components. Vundo is distributed by e-mail in messages containing links to insecure web sites, which exploit certain security vulnerabilities of the Internet Explorer web browser. Once the user clicks on such a link, Internet Explorer opens a dangerous site that automatically installs the trojan into the computer without user knowledge and consent. Vundo is responsible for the severe decrease of the amount of computer virtual memory available. This results in noticeable PC performance slowdowns. Vundo secretly runs on every Windows startup.&lt;br /&gt;&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;Vundo Manual Removal Instructions&lt;/span&gt;&lt;/span&gt;:&lt;br /&gt;&lt;/span&gt;&lt;h3 class="manual"&gt;Step 1 : Use Windows File Search Tool to Find Vundo Path&lt;/h3&gt; &lt;ol style="text-align: justify;"&gt;&lt;li&gt;Go to &lt;b&gt;Start &gt; Search &gt; All Files or Folders&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;In the &lt;b&gt;"All or part of the the file name"&lt;/b&gt; section, type in &lt;b&gt;"Vundo"&lt;/b&gt; file name(s).&lt;/li&gt;&lt;li&gt;To get better results, select &lt;b&gt;"Look in: Local Hard Drives"&lt;/b&gt; or &lt;b&gt;"Look in: My Computer"&lt;/b&gt; and then click &lt;b&gt;"Search"&lt;/b&gt; button.&lt;/li&gt;&lt;li&gt;When Windows finishes your search, hover over the "In Folder" of &lt;b&gt;"Vundo"&lt;/b&gt;, highlight the file and copy/paste the path into the address bar. Save the file's path on your clipboard because  you'll need the file path to delete Vundo in the following manual removal steps.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h3 class="manual"&gt;Step 2 : Use Registry Editor to Remove Vundo Registry Values&lt;/h3&gt; &lt;ol style="text-align: justify;"&gt;&lt;li&gt;To open the Registry Editor, go to &lt;b&gt;Start &gt; Run &gt; type regedit&lt;/b&gt; and then press the &lt;b&gt;"OK"&lt;/b&gt; button.&lt;/li&gt;&lt;li&gt;Locate and delete the entry or entries whose data value (in the rightmost column) is the spyware file(s) detected earlier.&lt;/li&gt;&lt;li&gt;To delete &lt;b&gt;"Vundo"&lt;/b&gt; value, right-click on it and select the &lt;b&gt;"Delete"&lt;/b&gt; option.&lt;/li&gt;&lt;li&gt;Locate and delete &lt;b&gt;"Vundo"&lt;/b&gt; registry entries:&lt;/li&gt;&lt;/ol&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainActiveState 02F96FB7-8AF6-439B-B7BA-2F952F9E4800&lt;/li&gt;&lt;li style="text-align: justify;"&gt;HKEY_LOCAL_MACHINESOFTWAREClassesATLEvents.ATLEvents.1&lt;/li&gt;&lt;li style="text-align: justify;"&gt;HKEY_LOCAL_MACHINESOFTWAREClassesATLEvents.ATLEvents 8109AF33-6949-4833-8881-43DCC232B7B2 2316230A-C89C-4BCC-95C2-66659AC7A775&lt;/li&gt;&lt;li style="text-align: justify;"&gt;HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunOnce*[filename]&lt;/li&gt;&lt;li&gt;HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainActive State&lt;/li&gt;&lt;li&gt;HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunOnce*WinLogon&lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{8109AF33-6949-4833-8881-43DCC232B7B2} &lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{2316230A-C89C-4BCC-95C2-66659AC7A775} &lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{02F96FB7-8AF6-439B-B7BA-2F952F9E4800} &lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE SOFTWAREClassesCLSID{02F96FB7-8AF6-439B-B7BA-2F952F9E4800} &lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE SOFTWAREClassesATLEvents.ATLEvents.1 &lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE SOFTWAREClassesATLEvents.ATLEvents &lt;/li&gt;&lt;li&gt;HKEY_CLASSES_ROOTCLSID{8109AF33-6949-4833-8881-43DCC232B7B2} &lt;/li&gt;&lt;li&gt;HKEY_CLASSES_ROOTCLSID{2316230A-C89C-4BCC-95C2-66659AC7A775} &lt;/li&gt;&lt;li&gt;HKEY_LOCAL_MACHINE SoftwareMicrosoftWindows CurrentVersionRunOnce*[filename] &lt;/li&gt;&lt;li&gt;HKEY_CURRENT_USER SoftwareMicrosoftWindows CurrentVersionRunOnce*WinLogon&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class="manual"&gt;Step 3 : Use Windows Command Prompt to Unregister Vundo DLL Files&lt;/h3&gt; &lt;ol style="text-align: justify;"&gt;&lt;li&gt;To open the Windows Command Prompt, go to &lt;b&gt;Start &gt; Run &gt; type cmd&lt;/b&gt; and then click the &lt;b&gt;"OK"&lt;/b&gt; button.&lt;/li&gt;&lt;li&gt;Type &lt;b&gt;"cd"&lt;/b&gt; in order to change the current directory, press the &lt;b&gt;"space"&lt;/b&gt; button, enter the full path to where you believe the Vundo DLL file is located  and press the &lt;b&gt;"Enter"&lt;/b&gt; button on your keyboard. If you don't know where Vundo DLL file is located, use the &lt;b&gt;"dir"&lt;/b&gt; command to display the directory's contents.&lt;/li&gt;&lt;li&gt;To unregister &lt;b&gt;"Vundo"&lt;/b&gt; DLL file, type in the &lt;b&gt;exact directory path + "regsvr32 /u" +  [DLL_NAME]&lt;/b&gt; (for example, :C\Spyware-folder\&gt; regsvr32 /u Vundo.dll) and press the &lt;b&gt;"Enter"&lt;/b&gt; button. A message will pop up that says you successfully unregistered the file.&lt;/li&gt;&lt;li&gt;Search and unregister &lt;b&gt;"Vundo"&lt;/b&gt; DLL files: vzbb.dll&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h3 class="manual"&gt;Step 4 : Detect and Delete Other Vundo Files&lt;/h3&gt; &lt;ol&gt;&lt;li style="text-align: justify;"&gt;To open the Windows Command Prompt, go to &lt;b&gt;Start &gt; Run &gt; type cmd&lt;/b&gt; and then press the &lt;b&gt;"OK"&lt;/b&gt; button.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;Type in  &lt;b&gt;"dir /A name_of_the_folder"&lt;/b&gt; (for example, C:\Spyware-folder), which will display the folder's content even the hidden files.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;To change directory, type in &lt;b&gt;"cd name_of_the_folder"&lt;/b&gt;.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;Once you have the file you're looking for type in &lt;b&gt;"del name_of_the_file"&lt;/b&gt;.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;To delete a file in folder, type in &lt;b&gt;"del name_of_the_file"&lt;/b&gt;.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;To delete the entire folder, type in &lt;b&gt;"rmdir /S name_of_the_folder"&lt;/b&gt;.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;Select the &lt;b&gt;"Vundo"&lt;/b&gt; process and click on the &lt;b&gt;"End Process"&lt;/b&gt; button to kill it.&lt;/li&gt;&lt;li&gt;&lt;div style="text-align: justify;"&gt;Remove the &lt;b&gt;"Vundo"&lt;/b&gt; processes files: vzbb.dll&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-4617467123432438831?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/4617467123432438831/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=4617467123432438831' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/4617467123432438831'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/4617467123432438831'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/12/how-to-manually-remove-vundo-trojan.html' title='How To Manually Remove  Vundo Trojan ?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-3878688828205865863</id><published>2008-12-23T06:50:00.000-08:00</published><updated>2009-01-16T21:31:19.583-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Zlob Trojan Removal'/><title type='text'>How To Remove Zlob Trojan?</title><content type='html'>&lt;span style="font-weight: bold; font-style: italic;font-size:100%;" &gt;What's Zlob Trojan?&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;Zlob Trojan is a backdoor Trojan which can give an anonymous attacker remote control over your PC. Zlob Trojan also lets the attacker execute commands on your PC, so that the attacker can gain control of your system and disable your security. Zlob Trojan puts your personal and financial information at risk.&lt;br /&gt;&lt;/div&gt;&lt;h3 style="font-style: italic;"&gt;&lt;span style="font-size:100%;"&gt;Do I have Zlob Trojan?&lt;/span&gt;&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;&lt;strong style="font-weight: normal;"&gt;Slow computer performance&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong style="font-weight: normal;"&gt;New desktop shortcuts or switched homepage&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong style="font-weight: normal;"&gt;Annoying popups on your PC&lt;/strong&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h3 style="font-style: italic;"&gt;&lt;span style="font-size:100%;"&gt;How did I get Zlob Trojan?&lt;/span&gt;&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;&lt;strong style="font-weight: normal;"&gt;Freeware or Shareware&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong style="font-weight: normal;"&gt;Peer-to-Peer Software&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong style="font-weight: normal;"&gt;Questionable Websites&lt;/strong&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h3 style="font-weight: bold; font-style: italic;"&gt;&lt;span style="font-size:100%;"&gt;Remove Zlob Trojan Manually!&lt;br /&gt;&lt;/span&gt;&lt;/h3&gt;To remove Zlob Trojan manually, you need to delete Zlob Trojan files.&lt;br /&gt;&lt;h3 style="font-weight: normal;" class="manual"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Step 1&lt;/span&gt; : Use Windows File Search Tool to Find Zlob Path&lt;/span&gt;&lt;/h3&gt; &lt;ol&gt;&lt;li&gt;Go to &lt;b&gt;Start &gt; Search &gt; All Files or Folders&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;In the &lt;b&gt;"All or part of the the file name"&lt;/b&gt; section, type in &lt;b&gt;"Zlob"&lt;/b&gt; file name(s).&lt;/li&gt;&lt;li&gt;To get better results, select &lt;b&gt;"Look in: Local Hard Drives"&lt;/b&gt; or &lt;b&gt;"Look in: My Computer"&lt;/b&gt; and then click &lt;b&gt;"Search"&lt;/b&gt; button.&lt;/li&gt;&lt;li&gt;When Windows finishes your search, hover over the "In Folder" of &lt;b&gt;"Zlob"&lt;/b&gt;, highlight the file and copy/paste the path into the address bar. Save the file's path on your clipboard because  you'll need the file path to delete Zlob in the following manual removal steps. &lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;Step 2&lt;/span&gt; : Use Windows Task Manager to Remove Zlob Processes &lt;ol&gt;&lt;li&gt;To open the Windows Task Manager, use the combination of &lt;b&gt;CTRL+ALT+DEL&lt;/b&gt; or &lt;b&gt;CTRL+SHIFT+ESC&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Click on the &lt;b&gt;"Image Name"&lt;/b&gt; button to search for &lt;b&gt;"Zlob"&lt;/b&gt; process by name.&lt;/li&gt;&lt;li&gt;Select the &lt;b&gt;"Zlob"&lt;/b&gt; process and click on the &lt;b&gt;"End Process"&lt;/b&gt; button to kill it.&lt;/li&gt;&lt;li&gt;Remove the &lt;b&gt;"Zlob"&lt;/b&gt; processes files:&lt;/li&gt;&lt;/ol&gt;&lt;ul&gt;&lt;li&gt;msmsgs.exe&lt;/li&gt;&lt;li&gt;nvctrl.exe&lt;/li&gt;&lt;li&gt;msmsgs.exe&lt;/li&gt;&lt;li&gt;nvctrl.exe&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Step 3&lt;/span&gt; : Use Registry Editor to Remove Zlob Registry Values &lt;ol&gt;&lt;li&gt;To open the Registry Editor, go to &lt;b&gt;Start &gt; Run &gt; type regedit&lt;/b&gt; and then press the &lt;b&gt;"OK"&lt;/b&gt; button.&lt;/li&gt;&lt;li&gt;Locate and delete the entry or entries whose data value (in the rightmost column) is the spyware file(s) detected earlier.&lt;/li&gt;&lt;li&gt;To delete &lt;b&gt;"Zlob"&lt;/b&gt; value, right-click on it and select the &lt;b&gt;"Delete"&lt;/b&gt; option.&lt;/li&gt;&lt;li&gt;Locate and delete &lt;b&gt;"Zlob"&lt;/b&gt; registry entries:&lt;/li&gt;&lt;/ol&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsNTCurrentVersionWinlogonShell=explorer.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;HKEY_LOCAL_MACHINE SoftwareMicrosoftWindows NT CurrentVersionWinlogonShell=explorer.exe, msmsgs.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunRegSvr32=%System%msmsgs.exe&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;HKEY_LOCAL_MACHINE SoftwareMicrosoftWindows CurrentVersionRunRegSvr32=%System%msmsgs.exe &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Step 4&lt;/span&gt; : Use Windows Command Prompt to Unregister Zlob DLL Files &lt;ol&gt;&lt;li&gt;To open the Windows Command Prompt, go to &lt;b&gt;Start &gt; Run &gt; type cmd&lt;/b&gt; and then click the &lt;b&gt;"OK"&lt;/b&gt; button.&lt;/li&gt;&lt;li&gt;Type &lt;b&gt;"cd"&lt;/b&gt; in order to change the current directory, press the &lt;b&gt;"space"&lt;/b&gt; button, enter the full path to where you believe the Zlob DLL file is located  and press the &lt;b&gt;"Enter"&lt;/b&gt; button on your keyboard. If you don't know where Zlob DLL file is located, use the &lt;b&gt;"dir"&lt;/b&gt; command to display the directory's contents.&lt;/li&gt;&lt;li&gt;To unregister &lt;b&gt;"Zlob"&lt;/b&gt; DLL file, type in the &lt;b&gt;exact directory path + "regsvr32 /u" +  [DLL_NAME]&lt;/b&gt; (for example, :C\Spyware-folder\&gt; regsvr32 /u Zlob.dll) and press the &lt;b&gt;"Enter"&lt;/b&gt; button. A message will pop up that says you successfully unregistered the file.&lt;/li&gt;&lt;li&gt;Search and unregister &lt;b&gt;"Zlob"&lt;/b&gt; DLL files:&lt;/li&gt;&lt;/ol&gt;&lt;ul&gt;&lt;li&gt;uimcu.dll&lt;/li&gt;&lt;li&gt;antzozc.dll &lt;/li&gt;&lt;li&gt;dtjby.dll &lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Step 5&lt;/span&gt; : Detect and Delete Other Zlob Files &lt;ol&gt;&lt;li&gt;To open the Windows Command Prompt, go to &lt;b&gt;Start &gt; Run &gt; type cmd&lt;/b&gt; and then press the &lt;b&gt;"OK"&lt;/b&gt; button.&lt;/li&gt;&lt;li&gt;Type in  &lt;b&gt;"dir /A name_of_the_folder"&lt;/b&gt; (for example, C:\Spyware-folder), which will display the folder's content even the hidden files.&lt;/li&gt;&lt;li&gt;To change directory, type in &lt;b&gt;"cd name_of_the_folder"&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Once you have the file you're looking for type in &lt;b&gt;"del name_of_the_file"&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;To delete a file in folder, type in &lt;b&gt;"del name_of_the_file"&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;To delete the entire folder, type in &lt;b&gt;"rmdir /S name_of_the_folder"&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Select the &lt;b&gt;"Zlob"&lt;/b&gt; process and click on the &lt;b&gt;"End Process"&lt;/b&gt; button to kill it.&lt;/li&gt;&lt;li&gt;Remove the &lt;b&gt;"Zlob"&lt;/b&gt; processes files:&lt;/li&gt;&lt;/ol&gt;&lt;ul&gt;&lt;li&gt;uimcu.dll &lt;/li&gt;&lt;li&gt;antzozc.dll &lt;/li&gt;&lt;li&gt;dtjby.dll &lt;/li&gt;&lt;li&gt;dumpserv.com&lt;/li&gt;&lt;li&gt;zxserv0.com &lt;/li&gt;&lt;li&gt;vnp7s.net &lt;/li&gt;&lt;li&gt;Protect &lt;/li&gt;&lt;li&gt;RSA &lt;/li&gt;&lt;li&gt;ncompat.tlb &lt;/li&gt;&lt;li&gt;msvol.tlb &lt;/li&gt;&lt;li&gt;hp[X].tmp &lt;/li&gt;&lt;li&gt;msmsgs.exe &lt;/li&gt;&lt;li&gt;nvctrl.exe &lt;/li&gt;&lt;li&gt;dumpserv.com  &lt;/li&gt;&lt;li&gt;zxserv0.com &lt;/li&gt;&lt;li&gt;vnp7s.net &lt;/li&gt;&lt;li&gt;%UserProfile%\Application Data\Microsoft\Protect  &lt;/li&gt;&lt;li&gt;%UserProfile%\Application Data\Microsoft\Crypto\RSA &lt;/li&gt;&lt;li&gt;ncompat.tlb  &lt;/li&gt;&lt;li&gt;msvol.tlb &lt;/li&gt;&lt;li&gt;hp[X].tmp &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-weight: bold;"&gt;Note:&lt;/span&gt; Here &lt;span class="style1"&gt;"&lt;span style="font-weight: bold;"&gt;%System&lt;/span&gt;" is a variable referring to your PC's System folder. Maybe you renamed it, but by default your System folder is "C:\Windows\System32" on Windows XP, "C:\Winnt\System32" on Windows NT/2000," or "C:\Windows\System" on Windows 95/98/Me.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;p class="style1"&gt;&lt;span style="font-size:78%;"&gt;"%Program_Files", "%ProgramFiles", or "%Profile" is a variable referring to a folder in your PC where applications that aren't a part of your PC's operating system are installed by default. You may have changed this folder's name or moved it, but if you didn't touch it, find the folder as "C:\Program Files". If you're having trouble finding this folder, you can locate it by looking up registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir".&lt;/span&gt;&lt;/p&gt;  &lt;p class="style1"&gt;&lt;span style="font-size:78%;"&gt;Also, "%UserProfile" is a variable referring to your current user's profile folder. If you're using Windows NT/2000/XP, by default this is "C:\Documents and Settings\[CURRENT USER]" (e.g., "C:\Documents and Settings\JoeSmith").&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-3878688828205865863?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/3878688828205865863/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=3878688828205865863' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/3878688828205865863'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/3878688828205865863'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/12/remove-zlob-trojan.html' title='How To Remove Zlob Trojan?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-5794822106910652320</id><published>2008-12-21T05:56:00.000-08:00</published><updated>2009-01-16T21:21:33.304-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SCVHOST.EXE Removal'/><title type='text'>How To Manually Remove SCVHOST.EXE Virus?</title><content type='html'>&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:78%;"&gt;In some antivirus they are detected as &lt;span style="font-weight: bold;"&gt;W32/YahLover.Worm.gen&lt;/span&gt; from McAfee Antivirus and &lt;span style="font-weight: bold;"&gt;Win32/Autorun.R.worm&lt;/span&gt; from NOD32&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:78%;" &gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-style: italic;"&gt;Solution&lt;/span&gt;:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;&lt;span style=";font-size:100%;" &gt;Restart  your PC and press F8 and select the option &lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;strong style="font-weight: normal;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style=""&gt;Safe  Mode Command Prompt Only&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;span style=";font-size:100%;" &gt;  &lt;/span&gt;  &lt;/li&gt;&lt;li&gt;&lt;span style=";font-size:100%;" &gt;And  after you log-in the command prompt you must &lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;strong style="font-weight: normal;"&gt;&lt;span style=""&gt;log-in  as Administrator&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;span style=";font-size:100%;" &gt;. &lt;/span&gt;  &lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Type cd&lt;/span&gt;&lt;span style="font-size:100%;"&gt;  C:\windows\system32&lt;/span&gt;   &lt;/li&gt;&lt;li&gt;&lt;span style=";font-size:100%;" &gt;Type  dir&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style=""&gt; /ah, &lt;/span&gt;&lt;/span&gt;&lt;span style=";font-size:100%;" &gt;to display all hidden files on this directory folder. You will see the following files which is used by the virus to spread itself: &lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;span style=""&gt;AUTORUN.INI&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;span style=""&gt;,  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;span style=""&gt;BLASTCLNNN.EXE&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style=""&gt;,  and &lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;SCVHOST.EXE&lt;/span&gt;   &lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Type &lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;ATTRIB -H -R -S SCVHOST.EXE&lt;/span&gt;   &lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Type ATTRIB -H -R -S  BLASTCLNNN.EXE   &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Type ATTRIB -H -R -S AUTORUN.INI   &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Type DEL SCVHOST.EXE   &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Type DEL BLASTCLNNNN.EXE   &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Type DEL AUTORUN.INI   &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Type CD\   &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Type ATTRIB -H -R -S AUTORUN.INF   &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Type &lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;DEL AUTORUN.INF&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;You are almost done, reboot your PC.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;Go Start Menu and click the Run and type the REGEDIT command. Take note guys before make any changes into your Registry Editor you must make a full back-up to your registry to avoid system errors. :) &lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;Look the location entry:&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ol style="text-align: justify;"&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;span style="font-size:100%;"&gt;,  if you see an entry &lt;a href="http://guideandtips.blogspot.com/2008/03/how-to-remove-scvhostexe-scvhostsexe.html"&gt;Yahoo! Messengger&lt;/a&gt; (it’s spelled like this)  with a value c:\windows\system32\scvhost.exe, Delete this entry.   &lt;/span&gt;&lt;/p&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="margin-bottom: 0in; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;Look the location entry:&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;ol style="text-align: justify;" start="0"&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows  NT\CurrentVersion\Winlogon&lt;/span&gt;&lt;span style="font-size:100%;"&gt;, in the entry named: SHELL, a value = Explorer.exe,SCVHOST.EXE. Edit this value, delete the SCVHOST.EXE only and the value must be Explorer.exe. Once you delete all this value, your computer will not login anymore.&lt;/span&gt;&lt;/p&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;We are now done. Please Restart your PC now.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-5794822106910652320?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/5794822106910652320/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=5794822106910652320' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/5794822106910652320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/5794822106910652320'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/12/how-to-manually-remove-scvhostexe-virus.html' title='How To Manually Remove SCVHOST.EXE Virus?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-8655095108184935470</id><published>2008-12-17T08:40:00.000-08:00</published><updated>2009-01-16T21:22:09.231-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WORM_AGENT.VDO Removal'/><title type='text'>How to remove WORM_AGENT.VDO?</title><content type='html'>&lt;span class="section-head-lg-red"&gt;&lt;span style="font-weight: bold;"&gt;Solution&lt;/span&gt;:&lt;/span&gt;&lt;br /&gt;&lt;!-- ########## Identifying the Malware Program ########## --&gt;  &lt;p&gt;&lt;b&gt;Identifying the Malware Program&lt;/b&gt;&lt;/p&gt;  &lt;p style="text-align: justify;"&gt;To remove this malware, first identify the malware program.&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ol style="text-align: justify;"&gt;&lt;li&gt;Scan your computer with your antivirus product.&lt;/li&gt;&lt;li&gt;NOTE the path and file name of all files detected as &lt;b&gt;WORM_AGENT.VDO&lt;/b&gt;.&lt;/li&gt;&lt;/ol&gt;        &lt;!-- ########## Terminating the Malware Program - Unknown File Name ########## --&gt;  &lt;p&gt;&lt;b&gt;Terminating the Malware Program&lt;/b&gt;&lt;!--unknown file name--&gt;&lt;/p&gt;  &lt;p style="text-align: justify;"&gt;This procedure terminates the running malware process. You will need the name(s) of the file(s) detected earlier.&lt;/p&gt;&lt;p style="text-align: justify;"&gt;If the process you are looking for is not in the list displayed by Task Manager, proceed to the succeeding solution set.&lt;/p&gt;  &lt;ol style="text-align: justify;"&gt;&lt;li&gt;Open Windows Task Manager.&lt;br /&gt;&lt;b&gt;• On Windows 98 and ME&lt;/b&gt;, press&lt;br /&gt;CTRL+ALT+DELETE&lt;br /&gt;&lt;b&gt;• On Windows NT, 2000, XP, and Server 2003&lt;/b&gt;, press&lt;br /&gt;CTRL+SHIFT+ESC, then click the Processes tab.&lt;/li&gt;&lt;li&gt;In the list of running programs*, locate the malware file(s) detected earlier. &lt;/li&gt;&lt;li&gt;Select one of the detected files, then press either the End Task or the End Process button, depending on the version of Windows on your computer. &lt;/li&gt;&lt;li&gt;Do the same for all detected malware files in the list of running processes. &lt;/li&gt;&lt;li&gt;To check if the malware process has been terminated, close Task Manager, and then open it again. &lt;/li&gt;&lt;li&gt;Close Task Manager. &lt;/li&gt;&lt;/ol&gt;  &lt;hr align="left" color="Silver" size="1" width="15%"&gt;  &lt;div style="text-align: justify;"&gt;&lt;b&gt;*NOTE:&lt;/b&gt; On computers running Windows 98 and ME, Windows Task Manager may &lt;i&gt;not&lt;/i&gt; show certain processes. You can use a third party process viewer such as &lt;a href="http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx"&gt;Process Explorer&lt;/a&gt; to terminate the malware process. &lt;/div&gt;&lt;p style="text-align: justify;"&gt;On computers running all Windows platforms, if the process you are looking for is not in the list displayed by Task Manager or Process Explorer, continue with the next solution procedure, noting additional instructions. If the malware process is in the list displayed by either Task Manager or Process Explorer, but you are unable to terminate it, restart your computer in &lt;a href="http://support.microsoft.com/kb/315222"&gt;safe mode&lt;/a&gt;.&lt;/p&gt;    &lt;!-- ########## Editing the Registry ########## --&gt;  &lt;p&gt;&lt;b&gt;Editing the Registry&lt;/b&gt;&lt;/p&gt;  &lt;p style="text-align: justify;"&gt;This malware modifies the computer's registry. Users affected by this malware may need to modify or delete specific registry keys or entries. For detailed information regarding registry editing, please refer to the following articles from Microsoft:&lt;/p&gt;  &lt;ol style="text-align: justify;" type="a"&gt;&lt;li&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;322754"&gt; HOW TO: Backup, Edit, and Restore the Registry in Windows 95, Windows 98, and Windows ME&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;323170"&gt; HOW TO: Backup, Edit, and Restore the Registry in Windows NT 4.0&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;322755"&gt; HOW TO: Backup, Edit, and Restore the Registry in Windows 2000&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;322756"&gt; HOW TO: Back Up, Edit, and Restore the Registry in Windows XP and Server 2003&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;     &lt;!-- ########## Removing Autostart Entries from the Registry - Unknown Registry Name ########## --&gt;  &lt;p&gt;&lt;b&gt;Removing Autostart Entry from the Registry&lt;/b&gt;&lt;!--unknown registry name--&gt;&lt;/p&gt;  &lt;p style="text-align: justify;"&gt;Removing autostart entries from the registry prevents the malware from executing at startup. In this procedure, you will need the name(s) of the file(s) detected earlier. &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;If the registry entry below is not found, the malware may not have executed as of detection. If so, proceed to the succeeding solution set.&lt;/p&gt;  &lt;ol&gt;&lt;li&gt;Open Registry Editor. Click Start&gt;Run, type REGEDIT, then press Enter.  &lt;!--REPEAT_START_HERE--&gt; &lt;!--REPEAT_KEY_START--&gt; &lt;/li&gt;&lt;li&gt;In the left panel, double-click the following:&lt;br /&gt;HKEY_LOCAL_MACHINE&gt;SOFTWARE&gt;Microsoft&gt;&lt;br /&gt;Windows&gt;CurrentVersion&gt;Run&lt;/li&gt;&lt;!--REPEAT_KEY_END--&gt;&lt;!--REPEAT_ENTRY_START--&gt;&lt;li&gt;In the right panel, locate and delete the entry or entries whose data value is the malware path and file name of the file(s) detected earlier. &lt;/li&gt;&lt;!--REPEAT_ENTRY_END--&gt;&lt;!--REPEAT_END_HERE--&gt;&lt;/ol&gt;  &lt;!--Supplement: Use only when applicable. Suggest after the removal of ALL autostart entries.--&gt;     &lt;!-- ########## Restoring Modified Registry Entry ########## --&gt;  &lt;p&gt;&lt;b&gt;Restoring Modified Registry Entry&lt;/b&gt;&lt;/p&gt; &lt;ol&gt;&lt;!--REPEAT_START_HERE--&gt;&lt;!--REPEAT_KEY_START--&gt;&lt;li&gt;Still in the Registry Editor, in the left panel, double-click the following:&lt;br /&gt;HKEY_LOCAL_MACHINE&gt;SOFTWARE&gt;Microsoft\&lt;br /&gt;Windows NT\CurrentVersion\Winlogon&lt;/li&gt;&lt;!--REPEAT_KEY_END--&gt;&lt;!--REPEAT_ENTRY_START--&gt;&lt;li&gt;In the right panel, locate the entry:&lt;br /&gt;&lt;b&gt;Userinit = "%System%\userinit.exe, {Malware name}"&lt;/b&gt;&lt;br /&gt;(Note: &lt;i&gt;%System%&lt;/i&gt; is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)&lt;/li&gt;&lt;!--REPEAT_ENTRY_END--&gt;&lt;!--REPEAT_DEFAULT_START--&gt;&lt;li&gt;Right-click on the &lt;i&gt;value name&lt;/i&gt; and choose Modify. Change the &lt;i&gt;value data&lt;/i&gt; of this entry to:&lt;br /&gt;&lt;b&gt;Userinit = "%System%\userinit.exe,"&lt;/b&gt; &lt;!--REPEAT_DEFAULT_END--&gt; &lt;!--REPEAT_END_HERE--&gt;  &lt;/li&gt;&lt;li&gt;Close Registry Editor.&lt;/li&gt;&lt;/ol&gt;    &lt;p&gt;&lt;b&gt;Deleting AUTORUN.INF&lt;/b&gt;&lt;/p&gt;&lt;!--for dropped AUTORUN.INF files--&gt;  &lt;ol&gt;&lt;li&gt;Right-click Start then click &lt;i&gt;Search...&lt;/i&gt; or &lt;i&gt;Find...&lt;/i&gt;, depending on the version of Windows you are running.&lt;/li&gt;&lt;li&gt;In the Named input box, type:&lt;br /&gt;&lt;b&gt; AUTORUN.INF &lt;/b&gt;&lt;/li&gt;&lt;li&gt;In the Look In drop-down list, select a drive, then press Enter. &lt;/li&gt;&lt;li&gt;Select the file, then open using &lt;i&gt;Notepad&lt;/i&gt;. &lt;/li&gt;&lt;li&gt;Check if the following lines are present in the file:&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;[Autorun]&lt;br /&gt;OPEN=fooool.exe&lt;br /&gt;shell\open=&lt;br /&gt;shell\open\Command=fooool.exe&lt;br /&gt;shell\open\Default=1&lt;br /&gt;shell\explore=&lt;br /&gt;shell\explore\Command=fooool.exe &lt;/b&gt;&lt;/li&gt;&lt;li&gt;If the lines are present, delete the file. &lt;/li&gt;&lt;li&gt;Repeat steps 3 to 6 for &lt;i&gt;AUTORUN.INF&lt;/i&gt; files in the remaining removable drives. &lt;/li&gt;&lt;li&gt;Close &lt;i&gt;Search Results&lt;/i&gt;. &lt;/li&gt;&lt;/ol&gt;    &lt;!-- ########## Important Windows ME/XP Cleaning Instructions ########## --&gt;  &lt;p&gt;&lt;b&gt;Important Windows ME/XP Cleaning Instructions&lt;/b&gt;&lt;/p&gt;  &lt;p style="text-align: justify;"&gt;Users running Windows ME and XP must &lt;b&gt;&lt;a href="http://support.microsoft.com/kb/310405"&gt;disable System Restore&lt;/a&gt;&lt;/b&gt; to allow full scanning of infected computers. &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;Users running other Windows versions can proceed with the succeeding solution set(s). &lt;/p&gt;    &lt;!-- ########## Running Trend Micro Antivirus - DELETE ########## --&gt;  &lt;p&gt;&lt;b&gt;Running Antivirus&lt;/b&gt;&lt;!--DELETE--&gt;&lt;/p&gt;  &lt;!-- Insert only for SYMBOS solutions &lt;p&gt;If you have recently transferred file from your Symbian Series 60 phone to your desktop computer, please also perform the following solution.&lt;/p&gt; --&gt;  &lt;p style="text-align: justify;"&gt;If you are currently running in safe mode, please restart your computer normally before performing the following solution.&lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;Scan your computer with antivirus and delete files detected as &lt;b&gt;WORM_AGENT.VDO&lt;/b&gt;. To do this, users must download the latest virus pattern file and scan their computer.&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-8655095108184935470?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/8655095108184935470/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=8655095108184935470' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/8655095108184935470'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/8655095108184935470'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/12/how-to-remove-wormagentvdo.html' title='How to remove WORM_AGENT.VDO?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-5505508786880842187</id><published>2008-12-15T07:04:00.000-08:00</published><updated>2009-01-16T21:22:56.817-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='newfolder.exe Removal'/><title type='text'>How to remove newfolder.exe or regsvr.exe or autorun.inf virus?</title><content type='html'>&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;1. Cut The Supply Line&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;         Search for autorun.inf file. It is a read only file so you will have to change it to normal by right clicking the file , selecting the properties and un-check the read only option&lt;/li&gt;&lt;li&gt;         Open the file in notepad and delete everything and save the file.&lt;/li&gt;&lt;li&gt;         Now change the file status back to read only mode so that the virus could not get access again.&lt;/li&gt;&lt;li&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_v8GkDAeqKqA/SUZ02fbTf_I/AAAAAAAAAFU/FAS_7cetsGk/s1600-h/n1.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 128px; height: 102px;" src="http://1.bp.blogspot.com/_v8GkDAeqKqA/SUZ02fbTf_I/AAAAAAAAAFU/FAS_7cetsGk/s400/n1.gif" alt="Autorun INF: cutting the supply line" id="BLOGGER_PHOTO_ID_5280036092636266482" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;         Click start-&gt;run and type msconfig and click ok&lt;/li&gt;&lt;li&gt;         Go to startup tab look for regsvr and uncheck the option click OK.&lt;/li&gt;&lt;li&gt;         Click on Exit without Restart, cause there are still few things we need to do before we can restart the PC.&lt;/li&gt;&lt;li&gt;         Now go to control panel -&gt; scheduled tasks, and delete the At1 task listed their.&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;   2. Open The Gates Of Castle&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;         Click on start -&gt; run and type gpedit.msc and click Ok.&lt;/li&gt;&lt;li&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_v8GkDAeqKqA/SUZ1Hs2ru_I/AAAAAAAAAFc/txgYP8J8YpY/s1600-h/n2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 128px; height: 121px;" src="http://2.bp.blogspot.com/_v8GkDAeqKqA/SUZ1Hs2ru_I/AAAAAAAAAFc/txgYP8J8YpY/s400/n2.jpg" alt="Opening the gate of castle: starting the gepedit or msconfig" id="BLOGGER_PHOTO_ID_5280036388298537970" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;         If you are Windows XP Home Edition user you might not have gpedit.msc in that case download and install it from Windows XP Home Edition: gpedit.msc and then follow these steps.&lt;/li&gt;&lt;li&gt;Go to users configuration-&gt;Administrative templates-&gt;system&lt;/li&gt;&lt;li&gt;         Find “prevent access to registry editing tools” and change the option to disable.&lt;/li&gt;&lt;li&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_v8GkDAeqKqA/SUZ1hyWacEI/AAAAAAAAAFk/_F2s8C-_aUs/s1600-h/n3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 128px; height: 86px;" src="http://2.bp.blogspot.com/_v8GkDAeqKqA/SUZ1hyWacEI/AAAAAAAAAFk/_F2s8C-_aUs/s400/n3.jpg" alt="Opening the gate of castle: Group Edit Policies" id="BLOGGER_PHOTO_ID_5280036836450398274" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;         Once you do this you have registry access back.&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;   3. Launch The Attack At Heart Of Castle&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Click on start-&gt;run and type regedit and click ok&lt;/li&gt;&lt;li&gt;Go to edit-&gt;find and start the search for regsvr.exe,&lt;/li&gt;&lt;li&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_v8GkDAeqKqA/SUZ2K5top4I/AAAAAAAAAFs/3fdKMHb0OtI/s1600-h/n4.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 128px; height: 89px;" src="http://4.bp.blogspot.com/_v8GkDAeqKqA/SUZ2K5top4I/AAAAAAAAAFs/3fdKMHb0OtI/s400/n4.jpg" alt="Launch the attack in the heart of castle: registry search" id="BLOGGER_PHOTO_ID_5280037542801483650" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;         Delete all the occurrence of regsvr.exe; remember to take a backup before deleting. KEEP IN MIND regsvr32.exe is not to be deleted. Delete regsvr.exe occurrences only.&lt;/li&gt;&lt;li&gt;         At one ore two places you will find it after explorer.exe in theses cases only delete the regsvr.exe part and not the whole part. E.g. Shell = “Explorer.exe regsvr.exe” the just delete the regsvr.exe and leave the explorer.exe&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;   4. Seek And Destroy the enemy soldiers&lt;/span&gt;, no one should be left behind&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Click on start-&gt;search-&gt;for files and folders.&lt;/li&gt;&lt;li&gt;Their click all files and folders&lt;/li&gt;&lt;li&gt;         Type “*.exe” as filename to search for&lt;/li&gt;&lt;li&gt;Click on ‘when was it modified ‘ option and select the specify date option&lt;/li&gt;&lt;li&gt;Type from date as 1/31/2008 and also type To date as 1/31/2008&lt;/li&gt;&lt;li&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_v8GkDAeqKqA/SUZ2cqfTJMI/AAAAAAAAAF0/2uXOUIAEvNU/s1600-h/n5.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 40px; height: 128px;" src="http://2.bp.blogspot.com/_v8GkDAeqKqA/SUZ2cqfTJMI/AAAAAAAAAF0/2uXOUIAEvNU/s400/n5.jpg" alt="Seek and destory enemy soldiers: the search option" id="BLOGGER_PHOTO_ID_5280037847952467138" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Now hit search and wait for all the exe’s to show up.&lt;/li&gt;&lt;li&gt;Once search is over select all the exe files and shift+delete the files, caution must be taken so that you don’t delete the legitimate exe file that you have installed on 31st January.&lt;/li&gt;&lt;li&gt;Also selecting lot of files together might make your computer unresponsive so delete them in small bunches.&lt;/li&gt;&lt;li&gt;Also find and delete regsvr.exe, svchost .exe( notice an extra space between the svchost and .exe)&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;   5. Time For Celebrations&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Now do a cold reboot (ie press the reboot button instead) and you are done.&lt;/li&gt;&lt;/ol&gt;Soon all antivirus programs will be able to automatically detect and clean this virus.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-5505508786880842187?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/5505508786880842187/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=5505508786880842187' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/5505508786880842187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/5505508786880842187'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/12/how-to-remove-newfolderexe-or-regsvrexe.html' title='How to remove newfolder.exe or regsvr.exe or autorun.inf virus?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_v8GkDAeqKqA/SUZ02fbTf_I/AAAAAAAAAFU/FAS_7cetsGk/s72-c/n1.gif' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-2227943763145447674</id><published>2008-12-13T07:05:00.000-08:00</published><updated>2009-01-16T21:23:46.087-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Remove Virus'/><title type='text'>Four Easy Steps to Manually Remove Viruses from Your Computer!</title><content type='html'>&lt;span style="font-size:78%;"&gt;[Note: This solution will work only against those Viruses which does not infect Windows own .exe files (e.g. like Explorer.exe)]&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Some of the &lt;span style="font-weight: bold;"&gt;symptoms of viruses&lt;/span&gt; are:&lt;br /&gt;&lt;ul&gt;&lt;li&gt; Disables Task Manager&lt;/li&gt;&lt;li&gt; Disables Registry Editor&lt;/li&gt;&lt;li&gt; Disables Command Prompt&lt;/li&gt;&lt;li&gt; Sometime you have no application running but CPU usage goes over 50%&lt;/li&gt;&lt;li&gt; Computer Drives are not opening by Double Click&lt;/li&gt;&lt;li&gt; Automatic Shutdown&lt;/li&gt;&lt;li&gt; Computer Slows down&lt;/li&gt;&lt;li&gt; Hidden Files will not be showing&lt;/li&gt;&lt;li&gt; Folder Options will disappear&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Solution:&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:78%;"&gt;[Caution: While the manual process is going on do not open any My Computer drive through My Computer]&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Step1&lt;/span&gt;&lt;span style="font-style: italic;"&gt;. &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-style: italic;"&gt;Process Termination&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Download &lt;a href="http://www.technize.com/?dl_id=7" target="_blank" rel="nofollow"&gt;&lt;strong&gt;&lt;span style="color: rgb(0, 0, 255);"&gt;Process Explorer&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; and &lt;a href="http://www.sysinternals.com/Utilities/Autoruns.html" target="_blank" rel="nofollow"&gt;&lt;strong&gt;&lt;span style="color: rgb(0, 0, 255);"&gt;Autoruns&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/span&gt; in order to complete the instructions below.&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Close all programs (even from tray) except your Internet Browser.&lt;/li&gt;&lt;li&gt;Run Process Explorer by typing procexp in the Start menu. Run and do as illustrated.&lt;/li&gt;&lt;/ol&gt;&lt;img style="font-weight: bold;" src="file:///C:/DOCUME%7E1/abcd/LOCALS%7E1/Temp/moz-screenshot.jpg" alt="Process Explorer" /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_v8GkDAeqKqA/SUPR7EsTsMI/AAAAAAAAAEU/sbOSXqhnP2Q/s1600-h/1.GIF"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 334px;" src="http://1.bp.blogspot.com/_v8GkDAeqKqA/SUPR7EsTsMI/AAAAAAAAAEU/sbOSXqhnP2Q/s400/1.GIF" alt="Process Explorer" id="BLOGGER_PHOTO_ID_5279294001010421954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-size:100%;"&gt;After collapsing:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_v8GkDAeqKqA/SUPRNveUuDI/AAAAAAAAAEM/p9ElLBdArN8/s1600-h/2.GIF"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 334px;" src="http://4.bp.blogspot.com/_v8GkDAeqKqA/SUPRNveUuDI/AAAAAAAAAEM/p9ElLBdArN8/s400/2.GIF" alt="mspaint.exe Properties" id="BLOGGER_PHOTO_ID_5279293222220511282" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;font-size:78%;" &gt;[Note: procexp.exe is Process Explorer’s own process]&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-weight: bold;font-size:78%;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;All the system processes are collapsed in the system tree, so if you see a process like winlogon.exe in explorer tree then it is surely a virus.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;If you do see any suspicious process, Processes can be sought for their suspiciousness at Process Library. And follow the following steps:&lt;br /&gt;&lt;/div&gt;&lt;ol style="text-align: justify;"&gt;&lt;li&gt;Right click on it if the process is found and then properties. In the path: field copy the path and Open Run Dialogue and paste the path there.&lt;/li&gt;&lt;li&gt;Now terminate the suspicious task in Process Explorer.&lt;/li&gt;&lt;li&gt;If the same process starts again then suspend the process by right clicking on it and click suspend on the menu. Remove the name of the application from path now listing only folder.&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt;E.g.:- If you have copied C:\WINDOWS\System32\mspaint.exe then remove mspaint.exe and you will see C:\WINDOWS\System32\ this in the Run Dialogue.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_v8GkDAeqKqA/SUPTJH-NjuI/AAAAAAAAAEc/lbeH5Lw2XvM/s1600-h/3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 351px; height: 400px;" src="http://3.bp.blogspot.com/_v8GkDAeqKqA/SUPTJH-NjuI/AAAAAAAAAEc/lbeH5Lw2XvM/s400/3.jpg" alt="7-ZIP File Manager" id="BLOGGER_PHOTO_ID_5279295341920620258" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Step2. File Deletion&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;The second step is deleting files. If you have installed powerexe, Start Menu–&gt; 7-ZIP–&gt; 7-ZIP File Manager which will show you all hidden files and go through the root path of every drive.&lt;br /&gt;&lt;/div&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_v8GkDAeqKqA/SUPT7VEVGvI/AAAAAAAAAEk/lABFPJDkT3E/s1600-h/4.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 276px;" src="http://4.bp.blogspot.com/_v8GkDAeqKqA/SUPT7VEVGvI/AAAAAAAAAEk/lABFPJDkT3E/s400/4.jpg" alt="Autoruns" id="BLOGGER_PHOTO_ID_5279296204429400818" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Delete &lt;span style="font-weight: bold;"&gt;.exe&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;autorun.inf&lt;/span&gt; like ravmon.exe, smss.exe, Funny UST Scandal.exe. But do not delete the following files autoexec.bat, boot.ini, bootmgr, config.sys, io.sys, msdos.sys, ntdetect.com, pagefile.sys, ntldr, hiberfil.sys as these are system files.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Step3. Removal of Startup Entries&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;Now you have successfully terminated virus process the next thing is to remove those virus files which run upon system start.&lt;br /&gt;&lt;/div&gt;&lt;ol&gt;&lt;li style="text-align: justify;"&gt;Open Autoruns by typing autoruns in the Run Dialogue. Wait while refreshing completes.&lt;/li&gt;&lt;li style="text-align: justify;"&gt;In the Options –&gt; Hide Microsoft Entries. And click Refresh button on the interface OR Close the program and start again.    &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_v8GkDAeqKqA/SUPUM0kf1FI/AAAAAAAAAEs/MG1v47NkAmA/s1600-h/5.GIF"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 284px;" src="http://4.bp.blogspot.com/_v8GkDAeqKqA/SUPUM0kf1FI/AAAAAAAAAEs/MG1v47NkAmA/s400/5.GIF" alt="" id="BLOGGER_PHOTO_ID_5279296504943596626" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li style="text-align: justify;"&gt;After scanning completes select Logon tab and uncheck all the entries be sure do not unselect any Microsoft Entry. Restart system for the changes to take effect.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Step4. Restoring Windows Default settings&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Now scan your system with a fully functional Anti-Virus will be the last suggestion.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Troubleshooting&lt;/span&gt;: Incase of any problem means you did a wrong move. Open Autoruns, in the Options –&gt; Unselect Hide Microsoft Entries. And click Refresh button on the interface OR and select all entries. Close the program and start your system again.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-2227943763145447674?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/2227943763145447674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=2227943763145447674' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/2227943763145447674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/2227943763145447674'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/12/four-easy-steps-to-manually-remove.html' title='Four Easy Steps to Manually Remove Viruses from Your Computer!'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_v8GkDAeqKqA/SUPR7EsTsMI/AAAAAAAAAEU/sbOSXqhnP2Q/s72-c/1.GIF' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-2604780920486169748</id><published>2008-12-07T06:29:00.000-08:00</published><updated>2009-01-16T21:24:48.628-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Trojan-horse Removal'/><title type='text'>How to manually remove Backdoor.livup (msstart.exe) Trojan-horse?</title><content type='html'>&lt;p class="MsoNormal" style="text-align: justify;"&gt;This method only works on Windows 2000/XP/2003/NT/ME.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;Step 1&lt;/b&gt;: Configure Microsoft Windows Explorer to show all files, because most Virus and&lt;span style=""&gt;          &lt;/span&gt;Trojan horse can hide itself. If you already did it, you may skip this step.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;1. Click Start, point to Settings, and Control Panel, and then click Folder Options.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;2. In the Folder Options dialog box, click the View tab.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;3. In the Advanced settings box, deselect the Hide protected operating system files (Recommended).&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;4. Select the Show hidden files and folders.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;5. Deselect the Hide file extensions for unknown file types.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;6. Click OK to save changes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;Or Download &lt;a href="http://www.softpedia.com/get/Security/Security-Related/RRT-Remove-Ristrictions-Tool.shtml" target="_blank" rel="nofollow"&gt;&lt;strong&gt;&lt;span style="color: rgb(0, 0, 255);"&gt;RRT&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;(Remove Restrictions Tool) a tool to re-enable Ctrl+Alt+&lt;st1:state&gt;&lt;st1:place&gt;Del&lt;/st1:place&gt;&lt;/st1:state&gt;, Folder Options and Registry tools.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;Step 2&lt;/b&gt;: Press Ctrl+Alt+&lt;st1:state&gt;&lt;st1:place&gt;Del&lt;/st1:place&gt;&lt;/st1:state&gt;, open Task Manager Program, click Processes tab, and find msstart.exe process, if found, select it and click End Process to kill it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;Step 3&lt;/b&gt;: Go to the folder of SystemRoot\Winnt\System32 (If your Windows NT/2000/XP/2003 installed on driver C: then the folder is C:\Winnt\System32), find msstart.exe and directly delete it. Or you can also search for all of msstart.exe files by using Windows Search feature (WINDOWS+F shortcut key), and delete them all.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;If all of the steps are completed correctly, then the Trojan has been completely removed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-2604780920486169748?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/2604780920486169748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=2604780920486169748' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/2604780920486169748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/2604780920486169748'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/12/how-to-manually-remove-backdoorlivup.html' title='How to manually remove Backdoor.livup (msstart.exe) Trojan-horse?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-4879734860638508327</id><published>2008-11-10T06:48:00.000-08:00</published><updated>2008-11-16T05:49:02.621-08:00</updated><title type='text'>How To Manually Remove Trojan?</title><content type='html'>&lt;p&gt;If you have identified the particular program that is part     of the malware, and you want to remove it, please follow these steps.&lt;/p&gt; &lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ol style="text-align: justify;"&gt;&lt;li&gt;     Download and extract the &lt;a href="http://www.sysinternals.com/Utilities/Autoruns.html" target="_blank" rel="nofollow"&gt;&lt;strong&gt;&lt;span style="color: rgb(0, 0, 255);"&gt;Autoruns&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; program by Sysinternals       to &lt;strong&gt;C:\Autoruns&lt;br /&gt; &lt;br /&gt;  &lt;/strong&gt;   &lt;/li&gt;&lt;li&gt;Reboot into Safe Mode &lt;strong&gt;&lt;/strong&gt;so that the malware is not started when you are doing         these steps. Many malware monitor the keys that allow them to start and         if they notice they have been removed, will automatically replace that         startup key. For this reason booting into safe mode allows us to get         past that defense in most cases.&lt;br /&gt;   &lt;br /&gt;&lt;/li&gt;&lt;li&gt;Navigate to the &lt;strong&gt;C:\Autoruns&lt;/strong&gt; folder you created in Step     1 and double-click on &lt;strong&gt;autoruns.exe.&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;When the program starts, click on the &lt;strong&gt;Options &lt;/strong&gt; menu and     enable the following options by clicking on them. This will place a checkmark     next     to each of these options.  &lt;br /&gt;&lt;br /&gt;      &lt;ol&gt;&lt;li&gt;&lt;strong&gt;Include empty locations&lt;/strong&gt;&lt;br /&gt;   &lt;br /&gt;    &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Verify Code Signatures&lt;/strong&gt;&lt;br /&gt;   &lt;br /&gt;    &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hide Signed Microsoft Entries&lt;br /&gt;      &lt;/strong&gt;&lt;br /&gt;    &lt;/li&gt;&lt;/ol&gt;   &lt;/li&gt;&lt;li&gt;Then press the &lt;strong&gt;F5 &lt;/strong&gt;key on your keyboard to refresh the     startups list using these new settings.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The program shows information about your startup entries in 8 different     tabs. For the most part, the filename you are looking for will be found under     the &lt;strong&gt;Logon&lt;/strong&gt; or the &lt;strong&gt;Services&lt;/strong&gt; tabs, but you     should check all the other tabs to make sure they are not loading elsewhere     as well. Click on each tab and look through the list for the filename that     you want to remove. The filename will     be found     under     the &lt;strong&gt;Image     Path&lt;/strong&gt; column.     There may be more than one entry associated with the same file as it is common     for malware     to create multiple startup entries.&lt;strong&gt;&lt;span style="color: rgb(255, 0, 0);"&gt; It is important     to note that many malware programs disguise themselves by using     the same     filenames as valid     Microsoft files. it is therefore important to know exactly which file, and     the folder they are in, that you want to remove&lt;/span&gt;&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Once you find the entry that is associated with the malware, you want to     delete that entry so it will not start again on the next reboot. To do that     right click on the entry and select &lt;strong&gt;delete&lt;/strong&gt;. This startup     entry will now be removed from the Registry.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Now that we made it so it will not start on boot up, you should delete     the file using My Computer or Windows Explorer. If you can not see the file,     it may be hidden. &lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;When you are finished removing the malware entries from the Registry and     deleting the files, reboot into normal mode as you will now be clean from     the infection.&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt;    &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-4879734860638508327?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/4879734860638508327/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=4879734860638508327' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/4879734860638508327'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/4879734860638508327'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/11/how-to-manually-remove-trojan.html' title='How To Manually Remove Trojan?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-1329334231821899989</id><published>2008-11-07T22:31:00.000-08:00</published><updated>2008-11-10T06:59:33.637-08:00</updated><title type='text'>Top 10 computer virus threat and what can you do about it?</title><content type='html'>&lt;br&gt;&lt;strong&gt;1. Number of password-stealing Web sites will increase using fake sign-in pages for popular online services&lt;/strong&gt; &lt;p&gt;WCYD: You can visually verify the URL or even better  type the URL on your own rather than clicking on a link received via email.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;2. Volume of spam, particularly bandwidth-eating image spam, will rise&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;WCYD: You can't do much about this other than enabling text only viewing on their mail application. You can hope that your security administrators will install anti SPAM gateway which can filter out image SPAM.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;3. Popularity of video sharing on the Web makes it inevitable that hackers will target MPEG files&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;WCYD: Stick to well known video sharing sites and hope that they do something about this! or even stay away from video sharing sites if practical.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;4. Mobile phone attacks will become more prevalent as mobile devices become smarter.&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;WCYD: Install mobile phone anti-virus software. Make sure that signature is updated. This could be one of the things to ask the mobile company before you buy your next mobile phone.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;5. Adware will go mainstream&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;WCYD: You can't do much about this. You could discourage products from companies that use this slimy advertising channel.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;6. Identity theft and data loss will continue to be a public issue&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;WCYD: Identity theft has been a nuisance for several years. The victims of identity fraud include lawyers, doctors and security professionals. It is a good idea to protect yourself so that you don't become a identity theft victim.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;7. The use of bots will increase as a tool favoured by hackers&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;WCYD: You can't do much about hacker's trend. You can prevent your computer being used as a bot by installing firewall to block unauthorized services. Installing anti-virus, anti-spyware and host intrusion prevention system will provide layered defense.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;8. Parasitic malware, or viruses that modify existing files on a disk, will make a comeback&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;WCYD: You can install anti-virus Et. Al.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;9. The number of rootkits on 32-bit platforms will increase&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;WCYD: Your traditional anti-virus software usually comes with rootkit detection, removal capability. Make sure to check with your anti-virus software vendor about its effectiveness in the removal of rootkits. I heard Symantec Norton ranks best in rootkit removal, but you should consult experts before you make the decision.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;10. Vulnerabilities will continue to cause concern fueled by the underground market for vulnerabilities&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;WCYD: You can't do much about this other than not supporting folks who try to create a market for vulnerabilities.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-1329334231821899989?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/1329334231821899989/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=1329334231821899989' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/1329334231821899989'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/1329334231821899989'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/11/top-10-computer-virus-threat-and-what.html' title='Top 10 computer virus threat and what can you do about it?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-1504604116286371414</id><published>2008-10-12T06:33:00.000-07:00</published><updated>2009-01-18T06:42:26.702-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus Removal Tools'/><title type='text'>Trojan.Vundo Removal Tool</title><content type='html'>This tool is designed to remove the infections of the following threats:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112111-3912-99"&gt;Trojan.Vundo&lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-042810-2611-99"&gt;Trojan.Vundo.B&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;Important:&lt;/strong&gt; &lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;div style="text-align: justify;"&gt;If you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem, disconnect the computer from the network and Internet. Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with Read Only access or by using password protection.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;For instructions on how to do this, refer to your Windows documentation, or the document: &lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2000091415173339?OpenDocument&amp;amp;src=sec_doc_nam"&gt;How to configure shared Windows folders for maximum network protection.&lt;/a&gt; &lt;/div&gt;&lt;/li&gt;&lt;li style="text-align: justify;"&gt;If you are removing an infection from a network, first make sure that all the shares are disabled or set to Read Only. &lt;/li&gt;&lt;li style="text-align: justify;"&gt;This tool is not designed to run on Novell NetWare servers. To remove this threat from a NetWare server, first make sure that you have the current virus definitions, and then run a full system scan with the Symantec antivirus product.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt; &lt;strong&gt;&lt;br /&gt;How to download and run the tool&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;strong&gt;Important:&lt;/strong&gt; You must have administrative rights to run this tool on Windows NT 4.0, Windows 2000, or Windows XP.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Note for network administrators:&lt;/strong&gt; If you are running MS Exchange 2000 Server, we recommend that you exclude the M drive from the scan by running the tool from a command line, with the Exclude switch. For more information, read the Microsoft knowledge base article: &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;298924"&gt;XADM: Do Not Back Up or Scan Exchange 2000 Drive M&lt;/a&gt; (Article 298924).&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Follow these steps to download and run the tool:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li style="text-align: justify;"&gt;Download the FixVundo.exe file from: &lt;a href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixVundo.exe" class="download"&gt;Download Removal Tool&lt;/a&gt; &lt;/li&gt;&lt;li style="text-align: justify;"&gt;Save the file to a convenient location, such as your Windows desktop. &lt;/li&gt;&lt;li style="text-align: justify;"&gt;Optional: To check the authenticity of the digital signature, refer to the "Digital signature" section later in this writeup.&lt;strong&gt;&lt;br /&gt;&lt;br /&gt;Note:&lt;/strong&gt; If you are sure that you are downloading this tool from the Security Response Web site, you can skip this step. If you are not sure, or are a network administrator and need to authenticate the files before deployment, follow the steps in the "Digital signature" section before proceeding with step 4.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="text-align: justify;"&gt;Close all the running programs. &lt;/li&gt;&lt;li style="text-align: justify;"&gt;If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet. &lt;/li&gt;&lt;li style="text-align: justify;"&gt;If you are running Windows Me or XP, turn off System Restore. For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:&lt;/li&gt;&lt;li style="text-align: justify;"&gt;Locate the file that you just downloaded.&lt;br /&gt;&lt;/li&gt;&lt;li style="text-align: justify;"&gt;Double-click the FixVundo.exe file to start the removal tool.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;div style="text-align: justify;"&gt;Click Start to begin the process, and then allow the tool to run.&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/div&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;div style="text-align: justify;"&gt;&lt;strong&gt;Note:&lt;/strong&gt; If you have any problems when you run the tool, or it does nor appear to remove the threat, &lt;a href="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406"&gt;restart the computer in Safe mode&lt;/a&gt; and run the tool again.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/li&gt;&lt;li style="text-align: justify;"&gt;Restart the computer. &lt;/li&gt;&lt;li style="text-align: justify;"&gt;Run the removal tool again to ensure that the system is clean. &lt;/li&gt;&lt;li style="text-align: justify;"&gt;If you are running Windows Me/XP, then reenable System Restore. &lt;/li&gt;&lt;li style="text-align: justify;"&gt;If you are on a network or if you have a full-time connection to the Internet, reconnect the computer to the network or to the Internet connection. &lt;/li&gt;&lt;li style="text-align: justify;"&gt;Run LiveUpdate to make sure that you are using the most current virus definitions. &lt;/li&gt;&lt;/ol&gt;      &lt;br /&gt;&lt;div style="text-align: justify;"&gt;When the tool has finished running, you will see a message indicating whether the threat has infected the computer. The tool displays results similar to the following:&lt;br /&gt;&lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Total number of the scanned files &lt;/li&gt;&lt;li&gt;Number of deleted files &lt;/li&gt;&lt;li&gt;Number of repaired files &lt;/li&gt;&lt;li&gt;Number of terminated viral processes &lt;/li&gt;&lt;li&gt;Number of fixed registry entries &lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-1504604116286371414?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/1504604116286371414/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=1504604116286371414' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/1504604116286371414'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/1504604116286371414'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/10/trojanvundo-removal-tool.html' title='Trojan.Vundo Removal Tool'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-3891059119862512488</id><published>2008-10-11T00:52:00.000-07:00</published><updated>2009-01-17T01:04:55.276-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus Removal Videos'/><title type='text'>trojan-downloader.win32.agent (ZLOB) Virus removal</title><content type='html'>&lt;br&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/fGH7NxSEGtA&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/fGH7NxSEGtA&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-3891059119862512488?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/3891059119862512488/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=3891059119862512488' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/3891059119862512488'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/3891059119862512488'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2009/01/trojan-downloaderwin32agent-zlob-virus.html' title='trojan-downloader.win32.agent (ZLOB) Virus removal'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-5385369284209465388</id><published>2008-10-09T01:44:00.000-07:00</published><updated>2009-01-03T02:03:46.806-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus Removal Videos'/><title type='text'>How To Remove Virus Without Using Antivirus Program ?</title><content type='html'>&lt;br/&gt;&lt;span style="font-style:italic;"&gt;Powered by Metacafe&lt;/span&gt;&lt;br /&gt;&lt;embed src="http://www.metacafe.com/fplayer/956046/how_to_remove_virus_without_using_antivirus_program.swf" wmode="transparent" pluginspage="http://www.macromedia.com/go/getflashplayer" type="application/x-shockwave-flash" height="345" width="400"&gt;&lt;/embed&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;              &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-5385369284209465388?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/5385369284209465388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=5385369284209465388' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/5385369284209465388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/5385369284209465388'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/10/how-to-remove-virus-without-using.html' title='How To Remove Virus Without Using Antivirus Program ?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-1360019295082936439</id><published>2008-09-12T05:21:00.000-07:00</published><updated>2009-01-03T01:36:33.621-08:00</updated><title type='text'>Information security in economic slowdown!</title><content type='html'>&lt;br&gt;&lt;div style="text-align: justify;"&gt;There is no doubt that this economy is impacting all companies and most individuals. I've read about and heard from many organizations that, as a result, their information security and privacy budgets are being drastically reduced, or even cut completely, in an attempt to save money during these uncertain times.&lt;br /&gt;&lt;br /&gt;Throwing out the baby with the bath water in this way is a very bad idea!&lt;br /&gt;&lt;br /&gt;As the economy continues to be bad, you are going to see more cybercrime attempts, and more cybercrime successes. All the more reason for folks to stay security aware and practice good security.&lt;br /&gt;&lt;br /&gt;Yes, now is the time to make smart information security investments. There are many ways in which organizations can have good security without overpaying. So it *IS* a good time to review your information security expenditures.&lt;br /&gt;&lt;br /&gt;One of the ways is to invest in the comparatively inexpensive information security and privacy training and awareness activities. Humans have always been&lt;br /&gt;the weakest link in information security success. Take the time, without the large bucks, to make personnel your best security tool.&lt;br /&gt;&lt;br /&gt;And, of course, maintain your basic security tools, such as firewall updates, up-to-date anti-malware protections, and enforced policies, just to name a few.&lt;br /&gt;&lt;br /&gt;If your company is struggling, the last thing you want to happen is a security incident that could have been prevented; a security incident and/or privacy breach could just be the final nail in the coffin for your organization.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-1360019295082936439?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/1360019295082936439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=1360019295082936439' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/1360019295082936439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/1360019295082936439'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/11/information-security-in-economic.html' title='Information security in economic slowdown!'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-703190946064326866</id><published>2008-09-10T22:04:00.000-07:00</published><updated>2009-01-16T22:09:00.960-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus Removal Tools'/><title type='text'>Free Virus Removal Tools</title><content type='html'>By &lt;span class="cp"&gt;BITDEFENDER&lt;/span&gt;   &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;              &lt;table cellpadding="3" cellspacing="3" width="100%"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-96908-en--Backdoor.IRC.Sticy.A.html"&gt;Backdoor.IRC.Sticy.A&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/180/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000001-en--Backdoor.K0wbot.1.2---1.3.A---1.3.B.html"&gt;Backdoor.K0wbot.1.2 / 1.3.A / 1.3.B&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/128/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000028-en--BackDoor.Rebbew-%28ABCD%29.html"&gt;BackDoor.Rebbew (A,B,C,D)&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/206/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-103997-en--Backdoor.Sticy.B.html"&gt;Backdoor.Sticy.B&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/181/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000000-en--I-Worm.Sircam.html"&gt;I-Worm.Sircam&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/203/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-170347-en--Trojan.VB.AE.html"&gt;Trojan.VB.AE&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/695/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-117972-en--Win32.Antiman.A@mm.html"&gt;Win32.Antiman.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/91/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-14610-en--Win32.Auric.A@mm.html"&gt;Win32.Auric.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/202/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-29-en--Win32.Badtrans.B@mm.html"&gt;Win32.Badtrans.B@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/92/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-23575-en--Win32.Bagle.A@mm.html"&gt;Win32.Bagle.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/96/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-43719-en--Win32.Bagle.AU@mm.html"&gt;Win32.Bagle.AU@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/93/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000037-en--Win32.Bagle.%7BC-E%7D@mm.html"&gt;Win32.Bagle.{C-E}@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/95/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000062-en--Win32.Bagle.FO@mm.html"&gt;Win32.Bagle.FO@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/679/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-43994-en--Win32.Bagz.B@mm.html"&gt;Win32.Bagz.B@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/97/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-115-en--Win32.Bride.A@mm.html"&gt;Win32.Bride.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/100/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-53156-en--Win32.Bride.B@mm.html"&gt;Win32.Bride.B@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/101/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-612-en--Win32.Bride.C@mm.html"&gt;Win32.Bride.C@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/102/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-157247-en--Win32.Brontok.A@mm.html"&gt;Win32.Brontok.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/773/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-116-en--Win32.BugBear.A@mm.html"&gt;Win32.BugBear.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/104/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-39-en--Win32.BugBear.B@mm.html"&gt;Win32.BugBear.B@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/105/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-28972-en--Win32.BugBear.C@mm.html"&gt;Win32.BugBear.C@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/106/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1890-en--Win32.Dumaru.A@mm.html"&gt;Win32.Dumaru.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/109/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000030-en--Win32.Dumaru.B-C@mm.html"&gt;Win32.Dumaru.B/C@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/110/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-23097-en--Win32.Dumaru.Y@mm.html"&gt;Win32.Dumaru.Y@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/111/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-92-en--Win32.Elkern.A.html"&gt;Win32.Elkern.A&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/201/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-41101-en--Win32.Evaman.A@mm.html"&gt;Win32.Evaman.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/113/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1195-en--Win32.Fizzer.A@mm.html"&gt;Win32.Fizzer.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/114/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-461-en--Win32.Frethem.F@mm.html"&gt;Win32.Frethem.F@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/115/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000002-en--Win32.Funlove.html"&gt;Win32.Funlove&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/756/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-800-en--Win32.Ganda.A@mm.html"&gt;Win32.Ganda.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/116/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-486-en--Win32.Gibe.A@mm.html"&gt;Win32.Gibe.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/182/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-273-en--Win32.Gone.A@mm.html"&gt;Win32.Gone.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/117/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-507-en--Win32.Holar.H@mm.html"&gt;Win32.Holar.H@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/118/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-2873-en--Win32.IISWorm.CodeRed.F.html"&gt;Win32.IISWorm.CodeRed.F&lt;/a&gt; (.zip)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/205/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-7670-en--Win32.Ivrol.A@mm.html"&gt;Win32.Ivrol.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/119/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-680-en--Win32.Jeefo.A.html"&gt;Win32.Jeefo.A&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/120/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-44-en--Win32.Klez.A@mm.html"&gt;Win32.Klez.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/112/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-326-en--Win32.Klez.D@mm.html"&gt;Win32.Klez.D@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/122/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-30-en--Win32.Klez.E@mm.html"&gt;Win32.Klez.E@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/123/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-101-en--Win32.Klez.H@mm.html"&gt;Win32.Klez.H@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/124/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-402-en--Win32.Lirva.B@mm.html"&gt;Win32.Lirva.B@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/129/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2" class="in_tabel1"&gt;&lt;img alt="file.gif" src="http://download.bitdefender.com/resources/images/file.gif" align="absmiddle" /&gt;  &lt;a href="http://www.bitdefender.com/VIRUS-303-en--Win32.LovGate.C@mm.html"&gt;Win32.LovGate.C@mm&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left: 60px;"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" /&gt;antilovgate-en.exe&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/130/FreeRemovalTool" onclick="oFileDownload('Removal Tool','antilovgate-en.exe');"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left: 60px;"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" /&gt;antilovgate-en.exe&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/132/FreeRemovalTool" onclick="oFileDownload('Removal Tool','antilovgate-en.exe');"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000015-en--Win32.LovGate.G-H-J-K@mm.html"&gt;Win32.LovGate.G/H/J/K@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/131/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-36853-en--Win32.Mabutu.A@mm.html"&gt;Win32.Mabutu.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/133/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-88-en--Win32.Magistr.B@mm.html"&gt;Win32.Magistr.B@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/134/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-26000-en--Win32.Melare.A@mm.html"&gt;Win32.Melare.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/135/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1190-en--Win32.Mimail.A@mm.html"&gt;Win32.Mimail.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/138/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-15207-en--Win32.Mimail.C@mm.html"&gt;Win32.Mimail.C@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/139/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000033-en--Win32.Mimail.DEFH@mm.html"&gt;Win32.Mimail.D,E,F,H@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/140/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-17211-en--Win32.Mimail.I@mm.html"&gt;Win32.Mimail.I@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/141/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1205-en--Win32.Msblast.A.html"&gt;Win32.Msblast.A&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/142/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-14844-en--Win32.Msblast.B.html"&gt;Win32.Msblast.B&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/143/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000029-en--Win32.Msblast.C.html"&gt;Win32.Msblast.C&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/144/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-2332-en--Win32.Msblast.F.html"&gt;Win32.Msblast.F&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/145/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-168759-en--Win32.Muce.A.html"&gt;Win32.Muce.A&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/630/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000035-en--Win32.Mydoom.B@mm-%28Win32.Novarg.B@mm%29.html"&gt;Win32.Mydoom.B@mm (Win32.Novarg.B@mm)&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/147/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-466-en--Win32.Myparty.A@mm.html"&gt;Win32.Myparty.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/148/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-18407-en--Win32.Neroma.A@mm.html"&gt;Win32.Neroma.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/150/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-26989-en--Win32.Neroma.B@mm.html"&gt;Win32.Neroma.B@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/151/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-25201-en--Win32.Netsky.B@mm.html"&gt;Win32.Netsky.B@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/107/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000042-en--Win32.Netsky.Q@mm.html"&gt;Win32.Netsky.Q@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/152/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-107-en--Win32.Nimda.A@mm.html"&gt;Win32.Nimda.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/153/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-83-en--Win32.Nimda.E@mm.html"&gt;Win32.Nimda.E@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/154/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-23255-en--Win32.Novarg.A@mm.html"&gt;Win32.Novarg.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/146/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000060-en--Win32.Nyxem.E@mm.html"&gt;Win32.Nyxem.E@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/641/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000025-en--Win32.Parite.A-B-C.html"&gt;Win32.Parite.A/B/C&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/158/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000066-en--Win32.Polip.A.html"&gt;Win32.Polip.A&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/719/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-162541-en--Win32.Sober.AD@mm.html"&gt;Win32.Sober.AD@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/611/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-15120-en--Win32.Sober.A@mm.html"&gt;Win32.Sober.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/160/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-21258-en--Win32.Sober.B@mm.html"&gt;Win32.Sober.B@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/161/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-21281-en--Win32.Sober.C@mm.html"&gt;Win32.Sober.C@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/162/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-26897-en--Win32.Sober.D@mm.html"&gt;Win32.Sober.D@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/163/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-28680-en--Win32.Sober.F@mm.html"&gt;Win32.Sober.F@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/164/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-120399-en--Win32.Sober.O@mm.html"&gt;Win32.Sober.O@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/165/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-172-en--Win32.Sobig.A@mm.html"&gt;Win32.Sobig.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/156/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000016-en--Win32.Sobig.B@mm-%28Palyh%29.html"&gt;Win32.Sobig.B@mm (Palyh)&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/157/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000024-en--Win32.Sobig.C@mm.html"&gt;Win32.Sobig.C@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/168/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2" class="in_tabel1"&gt;&lt;img alt="file.gif" src="http://download.bitdefender.com/resources/images/file.gif" align="absmiddle" /&gt;  &lt;a href="http://www.bitdefender.com/VIRUS-146-en--Win32.SoBig.E@mm.html"&gt;Win32.SoBig.E@mm&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left: 60px;"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" /&gt;antisobig-en.exe&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/166/FreeRemovalTool" onclick="oFileDownload('Removal Tool','antisobig-en.exe');"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left: 60px;"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" /&gt;antisobig-en.exe&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/169/FreeRemovalTool" onclick="oFileDownload('Removal Tool','antisobig-en.exe');"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1519-en--Win32.Sobig.F@mm.html"&gt;Win32.Sobig.F@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/167/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-111-en--Win32.Valhalla.2048.html"&gt;Win32.Valhalla.2048&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/188/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000003-en--Win32.Worm.Benjamin.html"&gt;Win32.Worm.Benjamin&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/98/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2" class="in_tabel1"&gt;&lt;img alt="file.gif" src="http://download.bitdefender.com/resources/images/file.gif" align="absmiddle" /&gt;  &lt;a href="http://www.bitdefender.com/VIRUS-1000045-en--Win32.Worm.Bobax.A-C.html"&gt;Win32.Worm.Bobax.A/C&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left: 60px;"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" /&gt;antibobax-en.exe&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/99/FreeRemovalTool" onclick="oFileDownload('Removal Tool','antibobax-en.exe');"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left: 60px;"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" /&gt;antitest-en.exe&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/187/FreeRemovalTool" onclick="oFileDownload('Removal Tool','antitest-en.exe');"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-31398-en--Win32.Worm.Dabber.A.html"&gt;Win32.Worm.Dabber.A&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/108/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000224-en--Win32.Worm.Delf.NCZ.html"&gt;Win32.Worm.Delf.NCZ&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/1456/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2" class="in_tabel1"&gt;&lt;img alt="file.gif" src="http://download.bitdefender.com/resources/images/file.gif" align="absmiddle" /&gt;  &lt;a href="http://www.bitdefender.com/VIRUS-1000462-en--Win32.Worm.Downadup.Gen.html"&gt;Win32.Worm.Downadup.Gen&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left: 60px;"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" /&gt;anti-Downadup-EN.zip&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/1582/FreeRemovalTool" onclick="oFileDownload('Removal Tool','anti-Downadup-EN.zip');"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left: 60px;"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" /&gt;anti-Downadup-EN.zip&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/1583/FreeRemovalTool" onclick="oFileDownload('Removal Tool','anti-Downadup-EN.zip');"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left: 60px;"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" /&gt;anti-downadup.zip&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/1584/FreeRemovalTool" onclick="oFileDownload('Removal Tool','anti-downadup.zip');"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000046-en--Win32.Worm.Korgo.AB.html"&gt;Win32.Worm.Korgo.A,B&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/125/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-32126-en--Win32.Worm.Korgo.C.html"&gt;Win32.Worm.Korgo.C&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/126/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-34582-en--Win32.Worm.Korgo.P.html"&gt;Win32.Worm.Korgo.P&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/185/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-34642-en--Win32.Worm.Korgo.R.html"&gt;Win32.Worm.Korgo.R&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/127/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-43541-en--Win32.Worm.Mexer.E.html"&gt;Win32.Worm.Mexer.E&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/137/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-125090-en--Win32.Worm.Mytob.BY.html"&gt;Win32.Worm.Mytob.BY&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/149/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000004-en--Win32.Worm.Opaserv.html"&gt;Win32.Worm.Opaserv&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/155/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000011-en--Win32.Worm.SQLExp.Slammer.A.html"&gt;Win32.Worm.SQLExp.Slammer.A&lt;/a&gt; (.zip)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/204/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1476-en--Win32.Worm.Welchia.A.html"&gt;Win32.Worm.Welchia.A&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/189/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-24150-en--Win32.Worm.Welchia.B.html"&gt;Win32.Worm.Welchia.B&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/190/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-497-en--Win32.Yahaa.D@mm.html"&gt;Win32.Yahaa.D@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/191/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-421-en--Win32.Yahaa.E@mm.html"&gt;Win32.Yahaa.E@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/192/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-423-en--Win32.Yahaa.J@mm.html"&gt;Win32.Yahaa.J@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/195/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-433-en--Win32.Yahaa.K@mm.html"&gt;Win32.Yahaa.K@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/194/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-1000010-en--Win32.Yahaa.P@mm-Q@mm.html"&gt;Win32.Yahaa.P@mm/Q@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/193/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-29359-en--Win32.Zafi.A@mm.html"&gt;Win32.Zafi.A@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/196/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-33771-en--Win32.Zafi.B@mm.html"&gt;Win32.Zafi.B@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/198/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-90506-en--Win32.Zafi.D@mm.html"&gt;Win32.Zafi.D@mm&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/199/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="in_tabel1" width="80%"&gt;&lt;img src="http://www.bitdefender.com/images/file.gif" align="absmiddle" /&gt; &lt;a href="http://www.bitdefender.com/VIRUS-35047-en--Worm.Kibuv.A.html"&gt;Worm.Kibuv.A&lt;/a&gt; (.exe)&lt;/td&gt;&lt;td align="right" valign="top"&gt;&lt;a href="http://www.bitdefender.com/site/Downloads/downloadFile/121/FreeRemovalTool"&gt;download&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-703190946064326866?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/703190946064326866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=703190946064326866' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/703190946064326866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/703190946064326866'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2009/01/free-virus-removal-tools.html' title='Free Virus Removal Tools'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-5305582841961594297</id><published>2008-09-09T01:10:00.000-07:00</published><updated>2009-01-03T01:33:49.356-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus Removal Tools'/><title type='text'>Virus Removal Tools</title><content type='html'>&lt;span style="font-size:78%;"&gt;by Kaspersky Lab&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;When a new virus appears, timely intervention can prevent damage to your computer and data, and help to prevent the spread of the virus.&lt;br /&gt;&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;Remove a virus for free&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Kaspersky Lab has developed free virus removal tools. If your computer has been infected by any of the viruses listed below, you can download a free removal utility here.&lt;br /&gt;&lt;/div&gt;&lt;h3 style="text-align: justify;" class="m0" klmark="loc_msg:vrtool_byname"&gt;&lt;span style="font-size:100%;"&gt;Ordered by Name&lt;/span&gt;&lt;/h3&gt; &lt;ul style="list-style-image: url(http://images.kaspersky.com/en/draft/bul_a_gre2.gif); margin-top: 5px;"&gt;&lt;li klmark="curedvir:146412176"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Backdoor.Win32.Afcore.l-ad&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:148911890"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Backdoor.Win32.Agent.ac&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826265"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Backdoor.Win32.Allaple.a&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146412070"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Backdoor.Win32.Small.d&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411824"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Avron.a-e&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146412196"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Bagle.a-j,n-r,z&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:154293711"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Email-Worm.Win32.Bagle.at,au&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:172294908"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Email-Worm.Win32.Bagle.cx-dw&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411187"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Blebla.b&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146410689"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410387#open"&gt;Email-Worm.Win32.Bridex.a&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:187972528"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Email-Worm.Win32.Brontok.n&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411968"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Dumaru.a-m&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411935"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Fizzer&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411429"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Goner&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411451"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Klez.a,e,f,g,h&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411687"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Lentin.a-p&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411933"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.LovGate.a-l&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411949"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Magold.a-e&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146412188"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Mydoom.a-b,e&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411290"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Navidad.a&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146412192"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.NetSky.b-d&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146410667"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410317#open"&gt;Email-Worm.Win32.Nimda.a&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411355"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Sircam.a&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146412179"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Sober.a,c&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411965"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Sobig.f&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146412141"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Swen&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411700"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Tanatos.a,b&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146412190"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Email-Worm.Win32.Torvil.d&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146410703"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410387#open"&gt;Email-Worm.Win32.Winevar&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:154293697"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Email-Worm.Win32.Zafi.b&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826267"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;IM-Worm.Win32.Sohanad.as&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411953"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Net-Worm.Win32.Lovesan&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146410923"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410387#open"&gt;Net-Worm.Win32.Opasoft.a-h&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411714"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Net-Worm.Win32.Opasoft.a-p&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826280"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Net-Worm.Win32.Rovud.a-c&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:148129211"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Net-Worm.Win32.Sasser.a-d,f&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411962"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Net-Worm.Win32.Welchia&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826268"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;P2P-Worm.Win32.Malas.b&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146412194"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Trojan-Downloader.Win32.Agent.a-j&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826275"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Trojan-Downloader.Win32.Losabel.ap&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826274"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Trojan-Downloader.Win32.Todon.an&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826273"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Trojan.Win32.Agent.aec&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826271"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Trojan.Win32.KillAV.nj&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:172295078"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Trojan.Win32.Krotten&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146412015"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Trojan.Win32.SilentLog.a-b&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:148911898"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Trojan.Win32.StartPage.fw&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826269"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Virus.Win32.AutoRun.acw&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146410853"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410387#open"&gt;Virus.Win32.FunLove&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:158267735"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Virus.Win32.Implinker.a&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826266"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Virus.Win32.VB.he&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:146411453"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=146410248#open"&gt;Virus.Win32.Win32.Elkern.c&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826272"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Worm.Win32.AutoRun.cby&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826276"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Worm.Win32.AutoRun.czz&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826277"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Worm.Win32.AutoRun.daa&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826279"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Worm.Win32.AutoRun.dfx&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826278"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Worm.Win32.AutoRun.dhq&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826281"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Worm.Win32.AutoRun.hr&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:196826270"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;Worm.Win32.VB.jn&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:158267743"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=154293695#open"&gt;not-a-virus:AdWare.Win32.Visiter&lt;/a&gt;&lt;/li&gt;&lt;li klmark="curedvir:180063853"&gt;&lt;a href="http://www.kaspersky.com/removaltools?vtopen=180063414#open"&gt;not-a-virus:RiskTool.Win32.XCP.a-b&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-5305582841961594297?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/5305582841961594297/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=5305582841961594297' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/5305582841961594297'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/5305582841961594297'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/09/virus-removal-tools.html' title='Virus Removal Tools'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4003604145017124760.post-7453434984810864844</id><published>2008-08-09T01:50:00.000-07:00</published><updated>2009-01-03T01:53:06.163-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus Removal Videos'/><title type='text'>How To Remove VIRUS From Pendrive?</title><content type='html'>&lt;span style="font-weight: bold;font-size:78%;" &gt;&lt;span style="font-style:italic;"&gt;Powered by Metacafe&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;embed src="http://www.metacafe.com/fplayer/902071/how_to_remove_virus_from_pendrive.swf" wmode="transparent" pluginspage="http://www.macromedia.com/go/getflashplayer" type="application/x-shockwave-flash" height="345" width="400"&gt;&lt;/embed&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;    &lt;a href="http://www.metacafe.com/watch/902071/how_to_remove_virus_from_pendrive/"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4003604145017124760-7453434984810864844?l=virusexperts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusexperts.blogspot.com/feeds/7453434984810864844/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4003604145017124760&amp;postID=7453434984810864844' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/7453434984810864844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4003604145017124760/posts/default/7453434984810864844'/><link rel='alternate' type='text/html' href='http://virusexperts.blogspot.com/2008/10/how-to-remove-virus-from-pendrive.html' title='How To Remove VIRUS From Pendrive?'/><author><name>Mayank Jain</name><uri>http://www.blogger.com/profile/09668702774730034599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
