<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Safer-Networking Forums - Malware Removal Guides</title>
		<link>http://forums.spybot.info/</link>
		<description>Automatically created guides for manual removal of various threats.</description>
		<language>en</language>
		<lastBuildDate>Wed, 16 May 2012 14:38:38 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forums.spybot.info/images/misc/rss.jpg</url>
			<title>Safer-Networking Forums - Malware Removal Guides</title>
			<link>http://forums.spybot.info/</link>
		</image>
		<item>
			<title>Manual Removal Guide for Win32.Yakes.adkv</title>
			<link>http://forums.spybot.info/showthread.php?t=65924&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:56 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Yakes.adkv" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Yakes.adkv&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
</ul><b>Description:</b><blockquote>Win32.Yakes.adkv copies malicious files into the program directory, starts itself in autorun and connects to the Internet in background without giving the user a possibility to cancel that process.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Autorun:</font></b></font><br />
<br />
<b>Important:</b> There are more autorun entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;&lt;$APPDATA&gt;\&lt;$ENV(Win32Yakes_Dir)&gt;&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.Yakes.adkv uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry key <i>&quot;Yqyt&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;12033:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;12033:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;12033:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;26693:UDP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;26693:UDP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;26693:UDP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
</ul>If Win32.Yakes.adkv uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65924</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.OnLineGames.gen</title>
			<link>http://forums.spybot.info/showthread.php?t=65923&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:55 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.OnLineGames.gen" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.OnLineGames.gen&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
<li>passwordstealer</li>
</ul><b>Description:</b><blockquote>Win32.OnLineGames.gen tries to steal passwords for online games. The library files get injected into running processes in order to avoid detection and to be executed by system files.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;&lt;$ENV(OLG1)&gt;.dll&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;&lt;$ENV(OLG1)&gt;&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(OLG1)&gt;.dll&quot;</i> from registry value <i>&quot;AppInit_DLLs&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li>
</ul>If Win32.OnLineGames.gen uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65923</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Mabezat</title>
			<link>http://forums.spybot.info/showthread.php?t=65922&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:54 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Mabezat" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Mabezat&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
<li>worm</li>
</ul><b>Description:</b><blockquote>Win32.Mabezat is a Worm with file infecting ability. It cloaks itself as a 3rd party installer or uses a document icon to mislead the user. Once installed it copies itself to all removable drives or network shares and creates an autorun entry for these files.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these files.<ul><li>A file with an unknown location named <i>&quot;InstallMSN11En.exe&quot;</i>.</li>
<li>A file with an unknown location named <i>&quot;KasperSky6.0 Key.doc.exe&quot;</i>.</li>
<li>A file with an unknown location named <i>&quot;Make Windows Original.exe&quot;</i>.</li>
<li>A file with an unknown location named <i>&quot;Office2007 Serial.txt.exe&quot;</i>.</li>
<li>A file with an unknown location named <i>&quot;WinrRarSerialInstall.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$APPDATA&gt;\Tazebama\tazebama.log&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$FIXEDDRIVES&gt;\InstallMSN11En.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$FIXEDDRIVES&gt;\KasperSky6.0 Key.doc.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$FIXEDDRIVES&gt;\Make Windows Original.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$FIXEDDRIVES&gt;\Office2007 Serial.txt.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$FIXEDDRIVES&gt;\WinrRarSerialInstall.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROFILES&gt;\hook.dl_&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROFILES&gt;\tazebama.dl_&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.Mabezat uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify files!<br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;&lt;$APPDATA&gt;\tazebama&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.Mabezat uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65922</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.IRCBot</title>
			<link>http://forums.spybot.info/showthread.php?t=65921&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:52 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.IRCBot" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.IRCBot&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
</ul><b>Description:</b><blockquote>Win32.IRCBot installs a file into the local temp directory. Variants create a subfolder within recycler and drop the copy into it. This malware is run via autorun and establishes a connection with a remote IRC Server. Win32.IRCbot installer pretends to be a cracking or other keygen tool.<br />
</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;c:\Windows\temp\mama&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.IRCBot uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65921</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Graftor.6078</title>
			<link>http://forums.spybot.info/showthread.php?t=65920&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:51 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Graftor.6078" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Graftor.6078&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
</ul><b>Description:</b><blockquote>Win32.Graftor.6078 installs malicious files into the Program files and root directories and makes DoS-attack on 58.221.41.56-address.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\&lt;$ENV(Win32Graftor6078_Dir)&gt;&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.Graftor.6078 uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry key <i>&quot;Ghijkl Nopqrstu Wxy&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\&quot;</i>.</li>
<li>Delete the registry key <i>&quot;Ghijkl Nopqrstu Wxy&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\&quot;</i>.</li>
<li>Delete the registry key <i>&quot;Ghijkl Nopqrstu Wxy&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\&quot;</i>.</li>
<li>Delete the registry key <i>&quot;Ghijkl Nopqrstu Wxy&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(Win32Graftor6078_path)&gt;&quot;</i> from registry value <i>&quot;DLLPath&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\RouterManagers\Ip\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(Win32Graftor6078_path)&gt;&quot;</i> from registry value <i>&quot;DLLPath&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RemoteAccess\RouterManagers\Ip\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(Win32Graftor6078_path)&gt;&quot;</i> from registry value <i>&quot;DLLPath&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\RemoteAccess\RouterManagers\Ip\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(Win32Graftor6078_path)&gt;&quot;</i> from registry value <i>&quot;DLLPath&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\RouterManagers\Ip\&quot;</i>.</li>
</ul>If Win32.Graftor.6078 uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65920</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Downloader.bdld</title>
			<link>http://forums.spybot.info/showthread.php?t=65919&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:50 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Downloader.bdld" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Downloader.bdld&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>malware</li>
</ul><b>Description:</b><blockquote>Win32.Downloader.bdld copies malicious files into the Windows directory and itself via an userinit entry.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Remove <i>&quot;&lt;$ENV(Win32DownloaderBdld_Dir)&gt;&quot;</i> from registry value <i>&quot;Userinit&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&quot;</i>.</li>
</ul>If Win32.Downloader.bdld uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65919</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Autorun.ie</title>
			<link>http://forums.spybot.info/showthread.php?t=65918&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:49 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Autorun.ie" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Autorun.ie&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>malware</li>
</ul><b>Description:</b><blockquote>Win32.Autorun.ie tries to start itself in autorun as &quot;iexplorer&quot; to get started without raising suspicion.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Autorun:</font></b></font><br />
<br />
Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a>, <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a> or <i>msconfig.exe</i> to remove the following autorun entries.<ul><li>Entries named <i>&quot;iexplorer&quot;</i> and pointing to <i>&quot;&lt;$SYSDIR&gt;\iexplorer32.exe&quot;</i>.</li>
<li>Entries named <i>&quot;msnmsggr&quot;</i> and pointing to <i>&quot;&lt;$SYSDIR&gt;\msnmsggr2.exe&quot;</i>.</li>
</ul><font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65918</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Conficker.rtk</title>
			<link>http://forums.spybot.info/showthread.php?t=65917&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:48 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Conficker.rtk" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Conficker.rtk&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
<li>rootkit</li>
</ul><b>Description:</b><blockquote>Conficker.rtk is a Trojan horse that gets installed in background and can spread to the local network. It compromises the system security and uses rootkit functions to hide itself and stay persistent.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these files.<ul><li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Internet Explorer\mzeky.dll&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$SYSDIR&gt;\mzeky.dll&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Conficker.rtk uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify files!<br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;6628:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;6628:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;6628:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;Start=W=2&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;Start=W=2&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wuauserv\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;Start=W=2&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\wuauserv\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;Start=W=2&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\&quot;</i>.</li>
</ul>If Conficker.rtk uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65917</guid>
		</item>
		<item>
			<title>Manual Removal Guide for ClaroMultimedia</title>
			<link>http://forums.spybot.info/showthread.php?t=65916&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:46 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "ClaroMultimedia" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;ClaroMultimedia&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>malware</li>
</ul><b>Description:</b><blockquote>ClaroMultimedia tries to start a malicious executable file from the system directory via Autorun as &quot;Windows Defender&quot; or &quot;Winlogon&quot; without giving the user a possibility to cancel that process.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Autorun:</font></b></font><br />
<br />
Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a>, <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a> or <i>msconfig.exe</i> to remove the following autorun entries.<ul><li>Entries named <i>&quot;Winlogon&quot;</i> and pointing to <i>&quot;&lt;$WINDIR&gt;\scssrr.exe&quot;</i>.</li>
</ul><font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65916</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.OnLineGames.gen</title>
			<link>http://forums.spybot.info/showthread.php?t=65876&amp;goto=newpost</link>
			<pubDate>Wed, 09 May 2012 09:54:23 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.OnLineGames.gen" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.OnLineGames.gen&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
<li>passwordstealer</li>
</ul><b>Description:</b><blockquote>Win32.OnLineGames.gen tries to steal passwords for online games. The library files get injected into running processes in order to avoid detection and to be executed by system files.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;&lt;$ENV(OLG1)&gt;.dll&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;&lt;$ENV(OLG1)&gt;&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(OLG1)&gt;.dll&quot;</i> from registry value <i>&quot;AppInit_DLLs&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li>
</ul>If Win32.OnLineGames.gen uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65876</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Matsnu</title>
			<link>http://forums.spybot.info/showthread.php?t=65875&amp;goto=newpost</link>
			<pubDate>Wed, 09 May 2012 09:54:22 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Matsnu" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Matsnu&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
</ul><b>Description:</b><blockquote>Win32.Matsnu copies malicious files into the application data and system directories, starts itself via autorun and userinit entries. It blocks system processes like msconfig, taskmanager and regedit. Win32.Matsnu crypts all executable, library and data files and locks the computer. It forces the user to pay for unlocking and decoding the machine.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Autorun:</font></b></font><br />
<br />
<b>Important:</b> There are more autorun entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;&lt;$APPDATA&gt;\&lt;$ENV(Win32Matsnu_Dir)&gt;&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.Matsnu uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;Debugger&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;Debugger&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;Debugger&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(Win32Matsnu_Path)&gt;,&quot;</i> from registry value <i>&quot;Userinit&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;regexpr&gt;&lt;$SYSDIR&gt;\\[A-F0-9] \.exe,&quot;</i> from registry value <i>&quot;Userinit&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&quot;</i>.</li>
</ul>If Win32.Matsnu uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65875</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Chiznit</title>
			<link>http://forums.spybot.info/showthread.php?t=65874&amp;goto=newpost</link>
			<pubDate>Wed, 09 May 2012 09:54:21 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Chiznit" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Chiznit&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
</ul><b>Description:</b><blockquote>Win32.Chiznit copies malicious files into the application patch directory, starts itself via autorun, userinit and winlogon entries. It monitors system values and stores the data into log files and registry keys. Win32.Chiznit connects to remote web servers to download further malware.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Autorun:</font></b></font><br />
<br />
Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a>, <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a> or <i>msconfig.exe</i> to remove the following autorun entries.<ul><li>Entries named <i>&quot;userinit&quot;</i> and pointing to <i>&quot;&lt;$WINDIR&gt;\AppPatch\*.exe&quot;</i>.</li>
<li>Entries named <i>&quot;userinit&quot;</i> and pointing to <i>&quot;&lt;regexpr&gt;&lt;$WINDIR&gt;\\AppPatch\\([a-z] )\.exe&quot;</i>.</li>
</ul><font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;44d228d9&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$WINDIR&gt;\apppatch\&lt;$ENV(FLname)&gt;.exe,&quot;</i> from registry value <i>&quot;Userinit&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$WINDIR&gt;\apppatch\&lt;$ENV(FLname)&gt;.exe&quot;</i> from registry value <i>&quot;load&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$WINDIR&gt;\apppatch\&lt;$ENV(FLname)&gt;.exe&quot;</i> from registry value <i>&quot;run&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$WINDIR&gt;\apppatch\&lt;$ENV(FLname)&gt;.exe&quot;</i> from registry value <i>&quot;System&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;regexpr&gt;&lt;$WINDIR&gt;\\AppPatch\\([a-z] )\.exe\,&quot;</i> from registry value <i>&quot;Userinit&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&quot;</i>.</li>
<li>Remove <i>&quot;&lt;regexpr&gt;&lt;$WINDIR&gt;\\AppPatch\\([a-z] )\.exe&quot;</i> from registry value <i>&quot;load&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;regexpr&gt;&lt;$WINDIR&gt;\\AppPatch\\([a-z] )\.exe&quot;</i> from registry value <i>&quot;run&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;regexpr&gt;&lt;$WINDIR&gt;\\AppPatch\\([a-z] )\.exe&quot;</i> from registry value <i>&quot;System&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&quot;</i>.</li>
</ul>If Win32.Chiznit uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65874</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Autorun.gen</title>
			<link>http://forums.spybot.info/showthread.php?t=65873&amp;goto=newpost</link>
			<pubDate>Wed, 09 May 2012 09:54:20 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Autorun.gen" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Autorun.gen&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>malware</li>
</ul><b>Description:</b><blockquote>Win32.Autorun.gen copies malicious files into the program directory and starts itself via autorun (as &quot;Sext&quot;,&quot;Sliv&quot;,&quot;Smsn&quot; and &quot;Snet&quot;).</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Autorun:</font></b></font><br />
<br />
Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a>, <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a> or <i>msconfig.exe</i> to remove the following autorun entries.<ul><li>Entries named <i>&quot;Sext&quot;</i> and pointing to <i>&quot;c:\programdata\Sext.exe&quot;</i>.</li>
<li>Entries named <i>&quot;Sliv&quot;</i> and pointing to <i>&quot;c:\programdata\Sliv.exe&quot;</i>.</li>
<li>Entries named <i>&quot;Smsn&quot;</i> and pointing to <i>&quot;c:\programdata\Smsn.exe&quot;</i>.</li>
<li>Entries named <i>&quot;Snet&quot;</i> and pointing to <i>&quot;c:\programdata\Snet.exe&quot;</i>.</li>
</ul><font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65873</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Autorun.bomb</title>
			<link>http://forums.spybot.info/showthread.php?t=65872&amp;goto=newpost</link>
			<pubDate>Wed, 09 May 2012 09:54:19 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Autorun.bomb" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Autorun.bomb&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
</ul><b>Description:</b><blockquote>Win32.Autorun.bomb copies several malicious files to the profile directory and creates an autorun entry in order to get launched on every startup.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Autorun:</font></b></font><br />
<br />
Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a>, <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a> or <i>msconfig.exe</i> to remove the following autorun entries.<ul><li>Entries named <i>&quot;MSClient&quot;</i> and pointing to <i>&quot;&quot;&lt;$COMMONPROGRAMFILES&gt;\MS\MSClient.exe&quot; /w&quot;</i>.</li>
</ul><b>Important:</b> There are more autorun entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;&lt;$COMMONPROGRAMFILES&gt;\MS&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.Autorun.bomb uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;ShowSuperHidden=W=1&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&quot;</i>.</li>
</ul>If Win32.Autorun.bomb uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65872</guid>
		</item>
		<item>
			<title>Manual Removal Guide for UltraAccessNetworks.NetBusPro</title>
			<link>http://forums.spybot.info/showthread.php?t=65871&amp;goto=newpost</link>
			<pubDate>Wed, 09 May 2012 09:54:18 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "UltraAccessNetworks.NetBusPro" manually. 
Use this guide at your own risk;...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;UltraAccessNetworks.NetBusPro&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>spyware</li>
<li>keylogger</li>
</ul><b>Description:</b><blockquote>UltraAccessNetworks.NetBusPro is an adsupported spyware that enables to spy on other users once the serve components are hidden on the target computer.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Installed Software List:</font></b></font><br />
<br />
You can try to uninstall products with the names listed below; for items identified by other properties or to avoid malware getting active again on uninstallation, use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> or <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a> to locate and get rid of these entries.<ul><li>Products that have a key or property named <i>&quot;NetBus Pro&quot;</i>.</li>
</ul><font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these files.<ul><li>The file at <i>&quot;&lt;$COMMONPROGRAMS&gt;\NetBus Pro\Get Paid To Be Online.lnk&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$COMMONPROGRAMS&gt;\NetBus Pro\NetBus Help.lnk&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$COMMONPROGRAMS&gt;\NetBus Pro\NetBus Server.lnk&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$COMMONPROGRAMS&gt;\NetBus Pro\NetBus.lnk&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$COMMONPROGRAMS&gt;\NetBus Pro\Readme.lnk&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\ad468x60.gif&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\ad468x60.url&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\DB\Broadcast1.db&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\DB\Command1.db&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\DB\Host.db&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\DB\Schedule1.db&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\DB\Script1.db&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\Lang\Default.lng&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\Lang\Swedish.lng&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\Log.txt&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\NBFind.dll&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\NBHelp.dll&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\NBSvr.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\NBUninst.dll&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\NetBus.cnt&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\NetBus.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\NetBus.hlp&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\Readme.txt&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\Skin\Listen.bmp&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\Skin\Logotype.bmp&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\Uninst.isu&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If UltraAccessNetworks.NetBusPro uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify files!<br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;&lt;$COMMONPROGRAMS&gt;\NetBus Pro&quot;</i>.</li>
<li>The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\DB&quot;</i>.</li>
<li>The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\Down&quot;</i>.</li>
<li>The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\Lang&quot;</i>.</li>
<li>The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro\Skin&quot;</i>.</li>
<li>The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\NetBus Pro&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If UltraAccessNetworks.NetBusPro uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry key <i>&quot;Net Solutions&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\&quot;</i>.</li>
<li>Delete the registry key <i>&quot;NetBus.exe&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\&quot;</i>.</li>
<li>Delete the registry key <i>&quot;NetBus&quot;</i> at <i>&quot;HKEY_CURRENT_USER\&quot;</i>.</li>
<li>Delete the registry key <i>&quot;UltraAccess Networks&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\&quot;</i>.</li>
</ul>If UltraAccessNetworks.NetBusPro uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65871</guid>
		</item>
	</channel>
</rss>

