<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>spywareremovalguides.com &#187; Removal Instructions List</title>
	<atom:link href="http://spywareremovalguides.com/category/virus/feed" rel="self" type="application/rss+xml" />
	<link>http://spywareremovalguides.com</link>
	<description>Spyware Removal Guides</description>
	<lastBuildDate>Tue, 15 May 2012 18:56:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Backdoor.Dalsk &#8211; December 2010 released Trojan</title>
		<link>http://spywareremovalguides.com/backdoor-dalsk-trojan-removal.html</link>
		<comments>http://spywareremovalguides.com/backdoor-dalsk-trojan-removal.html#comments</comments>
		<pubDate>Sun, 04 Dec 2011 23:44:37 +0000</pubDate>
		<dc:creator>spywareguru</dc:creator>
				<category><![CDATA[Removal Instructions List]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[Backdoor.Dalsk]]></category>
		<category><![CDATA[dalsk]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://spywareremovalguides.com/?p=1283</guid>
		<description><![CDATA[Variant: Backdoor.Dalsk Operating Systems Affected: Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, Windows Vista, Windows XP, Windows 7 Backdoor.Dalsk is a newly discovered Trojan horse (Dec. 30, 2010) that opens a backdoor which in turn gives remote access and possibly full admin control on the infected system. The one responsible for the Trojan [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Variant: Backdoor.Dalsk</strong></p>
<p><strong><strong>Operating Systems Affected: </strong>Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, Windows Vista, Windows XP, Windows 7</strong></p>
<p style="text-align: center;"><img class="aligncenter" src="http://dc263.4shared.com/img/whZKAh7V/s3/0.1171577903787493/new_trojan.jpg" alt="" width="490" height="344" /></p>
<p style="text-align: center;">
<p style="text-align: left;"><strong>Backdoor.Dalsk</strong> is a newly discovered Trojan horse (Dec. 30, 2010) that opens a backdoor which in turn gives remote access and possibly full admin control on the infected system. The one responsible for the Trojan may perform the following actions: download files, capture image screenshots, creates, edit and/ or delete user accounts, services, files, etc&#8230;</p>
<p style="text-align: left;"><em>What’s a <strong>Backdoor</strong>?</em><br />
A backdoor [computer system] is a method of bypassing normal authentication, securing remote access to a computer, obtaining access to plaintext, and so on, while attempting to remain undetected  [Source: Wikipedia]</p>
<p style="text-align: left;">Here&#8217;s how to remove <strong>Backdoor.Dalsk</strong> manually:</p>
<p style="text-align: left;"><strong>• Temporarily disable system restore (Windows ME/ XP) </strong>- Click Start, right-click My Computer then click Properties. Click the System Restore tab, select Turn off System Restore or Turn off System Restore on all drives check box. Click OK.</p>
<p><strong>• Reboot and login under safe mode with networking</strong> &#8211; While booting, press and hold the F8 Key.On the Windows Advanced Options Menu use arrow keys to move and choose Safe Mode with Networking then press Enter key.</p>
<p><strong>• Show hidden files and folders &#8211; </strong>Open My Computer, click Folder Options and choose View Tab<strong>.</strong> Tick Show hidden files and folders, tick hide protected operating system files.</p>
<p><strong>• Navigate and delete the following registry values: </strong>- Click Start, run, then type regedit.</p>
<p><em>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\incs</em><br />
<em>HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\ipcdr</em><br />
<em>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\irpfit</em><br />
<em>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ScardClt</em></p>
<p><em><em><em><span style="color: #ff0000;">{Disclaimer: Registry modification is done at your own risk. Backup the registry before making any changes!}</span></em></em></em></p>
<p><strong>• Navigate and delete the following Backdoor.Dalsk created files:</strong></p>
<p><em>%System%\Setup\wuauclt1.exe<br />
%System%\rshx16.bak<br />
%System%\rshx16.dll<br />
%System%\Setup\hid32.log<br />
%System%\scardclt.exe<br />
%System%\drivers\ipcdr.sys<br />
%System%\drivers\ipcdr.bak<br />
%System%\ntmsapi16.dll<br />
%System%\igxpgb32.dll<br />
%System%\drivers\irpfit.sys<br />
%System%\drivers\irpfit.bak<br />
%System%\hid32.dll<br />
%System%\hid32.bak<br />
%System%\incs.exe<br />
%System%\msvfw16.dll<br />
%System%\dmome.dll</em></p>
<p><strong>• Re-enable system restore (Windows ME/ XP) - </strong>Click Start, right-click My Computer,  then click Properties. Click the System Restore tab, clear the Turn off System Restore or Turn off System Restore on all drives check box.Click OK.</p>
<p><strong>• Restart and boot under normal mode</strong></p>
<p><strong>• Update AV definition files</strong></p>
<p><strong>• Run Anti-Virus full system scan</strong></p>
<p><strong><br />
</strong></p>
<p><strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://spywareremovalguides.com/backdoor-dalsk-trojan-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Rotinom &#8211; Computer Worm</title>
		<link>http://spywareremovalguides.com/computer-worm-w32-rotinom-removal.html</link>
		<comments>http://spywareremovalguides.com/computer-worm-w32-rotinom-removal.html#comments</comments>
		<pubDate>Tue, 02 Aug 2011 01:19:29 +0000</pubDate>
		<dc:creator>spywareguru</dc:creator>
				<category><![CDATA[Removal Instructions List]]></category>
		<category><![CDATA[Rotinom]]></category>
		<category><![CDATA[W32.Rotinom]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://spywareremovalguides.com/?p=1402</guid>
		<description><![CDATA[Variant: W32.Rotinom [Symantec], Trojan.Win32.Agent2.ldt [Kaspersky], Trojan:Win32/Folstart.A [Microsoft], TR/Agent2.ldt.36 [Avira] Operating Systems Affected: Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, Windows XP, Windows Vista, Windows 7 W32.Rotinom is a computer worm that copies itself and spreads via removable drives or network shared drives. How does it propagates? The worm makes copies of itself using the [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Variant: W32.Rotinom </strong>[Symantec], <strong>Trojan.Win32.Agent2.ldt</strong> [Kaspersky], <strong>Trojan:Win32/Folstart.A</strong> [Microsoft], <strong>TR/Agent2.ldt.36 </strong>[Avira]</p>
<p><strong>Operating Systems Affected: <strong>Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, <strong><strong>Windows XP, </strong></strong>Windows Vista, Windows 7</strong></strong></p>
<p style="text-align: center;"><img class="aligncenter" src="http://dc308.4shared.com/img/4usNwtIU/s3/0.11970130232781129/W32Rotinom.jpg" alt="" width="490" height="342" /></p>
<p><strong>W32.Rotinom</strong> is a computer worm that copies itself and spreads via removable drives or network shared drives.<br />
<strong>How does it propagates?</strong><br />
The worm makes copies of itself using the folder names found on the root directory of the targeted removable or network drives, adds an &#8220;EXE&#8221; file extension, then it sets the infected folder attribute settings to hidden. Be wary, the hidden malware executable icon is cleverly disguised as a typical windows folder.</p>
<h2><span style="color: #ff0000;">Step by step manual removal guide:</span></h2>
<p><strong>• Disable system restore </strong>(Windows ME and XP users only)</p>
<p><strong>• Reboot and login under safe mode with networking</strong> (Press the F8 key on Windows boots up)</p>
<p><strong>• Show hidden files and folders</strong> &#8211; Open my computer, click folder options and choose view tab. Tick show hidden files and folders, untick hide protected operating system files.</p>
<p><strong>• Navigate and delete W32.Rotinom created files:</strong><br />
<img src="http://dc102.4shared.com/img/8_EMicsx/s3/0.755012102960136/CaptureJPG6.JPG" alt="" /></p>
<p><strong>• Navigate and restore the following registry entries to their original values:</strong> (Click Start → run → type regedit → click OK)<br />
<img src="http://dc342.4shared.com/img/pNL-WhyX/s3/0.19670348484590094/CaptureJPG7.JPG" alt="" /></p>
<p><span style="color: #ff0000;">{Disclaimer: Registry modification is done at your own risk. Backup the registry before making any changes!}</span></p>
<p><strong>• Update Anti-Virus definition files</strong></p>
<p><strong>• Run Anti-Virus full system scan</strong></p>
<p><strong>• Re-enable system restore</strong> (Windows ME and XP users only)</p>
<p><strong>• Reboot and login under normal mode</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://spywareremovalguides.com/computer-worm-w32-rotinom-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan.Karagany &#8211; Backdoor Trojan</title>
		<link>http://spywareremovalguides.com/remove-trojan-karagany.html</link>
		<comments>http://spywareremovalguides.com/remove-trojan-karagany.html#comments</comments>
		<pubDate>Tue, 02 Aug 2011 00:46:44 +0000</pubDate>
		<dc:creator>spywareguru</dc:creator>
				<category><![CDATA[Removal Instructions List]]></category>
		<category><![CDATA[Karagany]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Trojan.Karagany]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://spywareremovalguides.com/?p=1425</guid>
		<description><![CDATA[Variant: Trojan.Karagany Operating Systems Affected: Windows 9x, 2000, XP, Server 2003, Vista, 7 Trojan.Karagany is a computer trojan horse that bypasses normal authentication process of the Windows Operating System thus, manipulates its way into accessing the system without being detected. The backdoor trojan has the potential of being destructive and could compromise any confidential data [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Variant: Trojan.Karagany</strong></p>
<p><strong>Operating Systems Affected: Windows 9x, 2000, XP, Server 2003, Vista, 7</strong></p>
<p style="text-align: center;"><img class="aligncenter" src="http://dc316.4shared.com/img/XIfZYqKf/s3/0.25880566240103275/trojan_karagany.jpg" alt="" width="437" height="345" /></p>
<p style="text-align: left;"><strong>Trojan.Karagany</strong> is a computer trojan horse that bypasses normal authentication process of the Windows Operating System thus, manipulates its way into accessing the system without being detected. The backdoor trojan has the potential of being destructive and could compromise any confidential data stored on your computer. If you&#8217;re infected with it, follow the steps indicated below to manually remove the trojan.</p>
<h2><span style="color: #ff0000;">Step by step manual removal guide:</span></h2>
<p><strong>• Temporarily disable system restore </strong>(Windows ME/ XP)<strong> </strong>Click Start, right-click My Computer then click Properties. Click the System Restore tab, select Turn off System Restore or Turn off System Restore on all drives check box. Click OK.</p>
<p><strong>• Reboot and login under safe mode with networking</strong> – While booting, press and hold the F8 Key.On the Windows Advanced Options Menu use arrow keys to move and choose Safe Mode with Networking then press Enter key.</p>
<p><strong>• Show hidden files and folders </strong>-<strong> </strong>Open my computer, click folder options and choose view tab. Tick show hidden files and folders, untick hide protected operating system files.</p>
<p><strong>• Navigate and delete the </strong><span style="font-weight: 800;">Trojan.Karagany</span><strong> created files:</strong><br />
<img src="http://dc123.4shared.com/img/-5PN-PZu/s3/0.1171946545603626/CaptureJPG4.JPG" alt="" /></p>
<p><strong>• Navigate and delete the Trojan.Karagny created folder:</strong></p>
<p>%ProgramFiles%\Common Files\WmiModules</p>
<p><strong>• Navigate and delete the Trojan.Karagany registry added values:</strong> (Start → run → type regedit → OK)<br />
<img src="http://dc269.4shared.com/img/E_q003wY/s3/0.3218740189906698/CaptureJPG5.JPG" alt="" /><br />
<span style="color: #ff0000;"><a href="http://support.microsoft.com/kb/256986" target="_blank">{Disclaimer: Registry modification is done at your own risk. Backup the registry before making any changes!}</a></span></p>
<p><strong>• Re-enable system restore </strong>(Windows ME/ XP) -<strong> </strong>Click Start, right-click My Computer,  then click Properties. Click the System Restore tab, clear the Turn off System Restore or Turn off System Restore on all drives check box.Click OK.</p>
<p><strong>• Update AV definition files</strong></p>
<p><strong>• Run Anti-Virus full system scan</strong></p>
<p><strong><strong>• Restart and boot under normal mode</strong></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://spywareremovalguides.com/remove-trojan-karagany.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TROJ_FAKEAV.WKA &#8211; Trojan disguised as an Anti-Virus app</title>
		<link>http://spywareremovalguides.com/troj_fakeav-wka-trojan-remover.html</link>
		<comments>http://spywareremovalguides.com/troj_fakeav-wka-trojan-remover.html#comments</comments>
		<pubDate>Fri, 15 Jul 2011 17:34:20 +0000</pubDate>
		<dc:creator>spywareguru</dc:creator>
				<category><![CDATA[Removal Instructions List]]></category>
		<category><![CDATA[FAKEAV]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[TROJ_FAKEAV.WKA]]></category>
		<category><![CDATA[WKA]]></category>

		<guid isPermaLink="false">http://spywareremovalguides.com/?p=1445</guid>
		<description><![CDATA[Variant: TROJ_FAKEAV.WKA [Trend Micro], Rogue:Win32/FakeSpypro [Microsoft] Operating Systems Affected: Windows 9x, Windows 2000, Windows XP, Windows Vista, Windows 7 TROJ_FAKEAV.WKA is a Trojan that disguises itself as a legitimate Anti-Virus program. The fake AV application will connect to a website then downloads the core component of the trojan which is TROJ_FAKEAV.WKA. Once the system is infected, the [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Variant: TROJ_FAKEAV.WKA</strong> [Trend Micro]<strong>, Rogue:Win32/FakeSpypro</strong> [Microsoft]</p>
<p style="text-align: left;"><strong>Operating Systems Affected: <strong>Windows 9x, Windows 2000, <strong><strong>Windows XP, </strong></strong>Windows Vista, Windows 7</strong></strong></p>
<p style="text-align: center;">
<p style="text-align: center;"><img class="aligncenter" src="http://dc314.4shared.com/img/geUcj8w7/s3/0.03320822231681331/FAKEAV_WKA.jpg" alt="" width="423" height="318" /></p>
<p style="text-align: center;">
<p style="text-align: left;">TROJ_FAKEAV.WKA is a Trojan that disguises itself as a legitimate Anti-Virus program. The fake AV application will connect to a website then downloads the core component of the trojan which is TROJ_FAKEAV.WKA. Once the system is infected, the said malware will display a fake scan result showing you that you have  multiple virus infection. After that, it gives you the option to purchase the software to be able to remove the pseudo infection. If you click on purchase, you will be redirected to particular website asking you to enter credit card information. Don&#8217;t be deceive, do not buy the fake Anti-Virus program!</p>
<p><strong>• Disable system restore</strong> (Windows ME and XP only)<br />
<strong>• Reboot and login under safe mode with networking</strong><br />
<strong>• Navigate and delete the Trojan added registry values:</strong><br />
<img src="http://dc356.4shared.com/img/KbbInqI4/s3/0.4137969525475156/CaptureJPG1.JPG" alt="" /></p>
<p><strong>• Navigate and restore the original registry values:</strong><br />
<img src="http://dc396.4shared.com/img/BzLvsj_j/s3/0.7252224667235605/CaptureJPG2.JPG" alt="" /><br />
<strong>• Navigate and delete this registry key:</strong><br />
<img src="http://dc385.4shared.com/img/6HuLdfdg/s3/0.8646729456217325/CaptureJPG3.JPG" alt="" /></p>
<p><span style="color: #ff0000;"><a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/regedit_overview.mspx?mfr=true" target="_blank"><span style="color: #ff0000;">{Disclaimer: Registry modification is done at your own risk. Backup the registry before making any changes!}</span></a></span></p>
<p><span style="color: #333333;"><a href="http://support.microsoft.com/kb/322756" target="_blank">Windows XP Registry Backup</a></span><br />
<span style="color: #333333;"><a href="http://windows.microsoft.com/en-us/windows7/Back-up-the-registry" target="_blank">Windows 7 Registry Backup</a></span></p>
<p><span style="color: #333333;"> </span></p>
<div><strong>• Update Anti-Virus definition files</strong></div>
<div><strong>• Run Anti-Virus full system scan</strong></div>
<div><strong>• Re-enable system restore </strong>(Windows ME and XP only)</div>
<div><strong>• Reboot and login under normal mode</strong></div>
]]></content:encoded>
			<wfw:commentRss>http://spywareremovalguides.com/troj_fakeav-wka-trojan-remover.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adware.Magoo &#8211; Annoying pop up ads</title>
		<link>http://spywareremovalguides.com/adware-magoo-popup-removal.html</link>
		<comments>http://spywareremovalguides.com/adware-magoo-popup-removal.html#comments</comments>
		<pubDate>Thu, 07 Jul 2011 21:31:05 +0000</pubDate>
		<dc:creator>spywareguru</dc:creator>
				<category><![CDATA[Removal Instructions List]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Adware.Magoo]]></category>
		<category><![CDATA[Magoo]]></category>
		<category><![CDATA[pop up ads]]></category>

		<guid isPermaLink="false">http://spywareremovalguides.com/?p=1339</guid>
		<description><![CDATA[Variant: Adware.Magoo Operating Systems Affected: Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, Windows Vista, Windows XP, Windows 7 [Image shown above is not the actual Adware.Magoo pop ups but is just an example of the annoying pop up windows that we constantly encounter on the web] Adware.Magoo is not a virus, trojan or [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Variant: Adware.Magoo</strong></p>
<p style="text-align: left;"><strong> Operating Systems Affected: <strong>Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, Window</strong></strong><strong>s Vista, Windows XP, Windows 7</strong></p>
<p style="text-align: left;"><strong><img class="aligncenter" src="http://english474awe.weebly.com/uploads/4/7/1/0/4710028/7256363.jpg?341" alt="" width="341" height="255" /> </strong></p>
<p style="text-align: left;">[Image shown above is not the actual <strong>Adware.Magoo</strong> pop ups but is just an example of the annoying pop up windows that we constantly encounter on the web]</p>
<p><strong>Adware.Magoo</strong> is not a virus, trojan or a worm – it is an adware program that displays annoying pop up ads while surfing the web.</p>
<p><em>What is an <strong>Adware</strong>?</em><br />
<em></em>Adware, or advertising-supported software, is any software package which automatically plays, displays, or downloads advertisements to a computer. [Source: Wikipedia]</p>
<h2><span style="color: #ff0000;">Step by step manual removal guide:</span></h2>
<p><strong>• Disable system restore </strong>(Windows ME, XP users only)</p>
<p><strong>• Reboot and login under safe mode with networking</strong> (Press the F8 key on Windows boots up)</p>
<p><strong>• Delete temporary internet files</strong></p>
<p>(IE 8 → Safety menu → delete browsing history → tick temporary internet files, cookies, and history → delete)</p>
<p>(Firefox→ tools menu → select clear recent internet history/ cookies → drop-down menu → select the desired range → click clear now)</p>
<p><strong>• Show hidden files and folders </strong>(Open my computer, click folder options and choose view tab. Tick show hidden files and folders, untick hide protected operating system files.)</p>
<p><strong>• Delete the following infected files:</strong><br />
<img src="http://dc239.4shared.com/img/Zig1AAZB/s3/0.7024893127324949/CaptureJPG8.JPG" alt="" /><br />
<strong>• Delete the infected registry key: </strong>(Start → run → type regdit → navigate to the listed entry and delete)</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;Mightymagoo&#8221; = &#8220;%ProgramFiles%\Mighty Magoo\mightymagoo32.exe a&#8221;</p>
<p><strong>• Delete the following infected registry values:</strong><br />
<img src="http://dc415.4shared.com/img/MOy_b_LL/s3/0.5492568113470909/CaptureJPG9.JPG" alt="" /><br />
<em><em><em><span style="color: #ff0000;">{Disclaimer: Registry modification is done at your own risk. Backup the registry before making any changes!}</span></em></em></em></p>
<p><strong>• Update Anti-Malware definition files</strong></p>
<p><strong>• Run Anti-Malware full system scan</strong></p>
<p><strong>• Re-enable system restore</strong> (Windows ME, XP users only)</p>
<p><strong>• Reboot and login under normal mode</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://spywareremovalguides.com/adware-magoo-popup-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Infostealer.Spunst &#8211; Trojan that steals personal confidential information </title>
		<link>http://spywareremovalguides.com/infostealer-spunst-trojan-removal.html</link>
		<comments>http://spywareremovalguides.com/infostealer-spunst-trojan-removal.html#comments</comments>
		<pubDate>Tue, 21 Jun 2011 17:08:28 +0000</pubDate>
		<dc:creator>spywareguru</dc:creator>
				<category><![CDATA[Removal Instructions List]]></category>
		<category><![CDATA[infostealer]]></category>
		<category><![CDATA[Infostealer.Spunst]]></category>
		<category><![CDATA[spunst]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://spywareremovalguides.com/?p=1372</guid>
		<description><![CDATA[Variant: Infostealer.Spunst Operating Systems Affected: Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, Windows XP, Windows Vista, Windows 7 Infostealer.Spunst is a Trojan horse that is primarily designed to steal personal confidential information on a compromised computer. A Trojan horse, or Trojan, is a malware that appears to perform a desirable function for the user prior [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Variant: Infostealer.Spunst</strong></p>
<p><strong>Operating Systems Affected: <strong>Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, <strong><strong>Windows XP, </strong></strong>Windows Vista, Windows 7</strong></strong></p>
<p><img class="alignleft" src="http://dc302.4shared.com/img/w9E867P3/s3/0.1394054277893323/info_stealer.jpg" alt="" width="312" height="252" /></p>
<p><strong>Infostealer.Spunst</strong> is a Trojan horse that is primarily designed to steal personal confidential information on a compromised computer.</p>
<p>A <strong>Trojan horse</strong>, or <strong>Trojan</strong>, is a malware that appears to perform a desirable function for the user prior to run or install but instead facilitates unauthorized access of the user&#8217;s computer system.[source: <a title="Wikipedia" href="http://en.wikipedia.org/wiki/Wikipedia" target="_blank">Wikipedia</a>]</p>
<h2><span style="color: #ff0000;">Step by step manual removal guide:</span></h2>
<p><strong>• Temporarily disable system restore </strong>(Windows ME/ XP)<strong> </strong>Click Start, right-click My Computer then click Properties. Click the System Restore tab, select Turn off System Restore or Turn off System Restore on all drives check box. Click OK.</p>
<p><strong>• Reboot and login under safe mode with networking</strong> – While booting, press and hold the F8 Key.On the Windows Advanced Options Menu use arrow keys to move and choose Safe Mode with Networking then press Enter key.</p>
<p><strong>• Show hidden files and folders </strong>-<strong> </strong>Open my computer, click folder options and choose view tab. Tick show hidden files and folders, untick hide protected operating system files.</p>
<p><strong>• Navigate and delete Infostealer.Spunst infected files:</strong></p>
<p>%UserProfile%\Application Data\colectinf.tag<br />
%UserProfile%\Application Data\dllcache32.exe</p>
<p><strong>• Navigate and delete Infostealer.Spunst registry added value:</strong> Start → run → type regedit</p>
<p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\&#8221;NoDriveTypeAutoRun&#8221; = &#8220;dllcache32.exe&#8221;</p>
<p><em><em><em><span style="color: #ff0000;">{Disclaimer: Registry modification is done at your own risk. Backup the registry before making any changes!}</span></em></em></em></p>
<p><strong>• Re-enable system restore </strong>(Windows ME/ XP) -<strong> </strong>Click Start, right-click My Computer,  then click Properties. Click the System Restore tab, clear the Turn off System Restore or Turn off System Restore on all drives check box.Click OK.</p>
<p><strong>• Update AV definition files</strong></p>
<p><strong>• Run Anti-Virus full system scan</strong></p>
<p><strong><strong>• Restart and boot under normal mode</strong></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://spywareremovalguides.com/infostealer-spunst-trojan-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan.Bohu – Disables Cloud-Based Antivirus </title>
		<link>http://spywareremovalguides.com/trojan-bohu-removal-steps.html</link>
		<comments>http://spywareremovalguides.com/trojan-bohu-removal-steps.html#comments</comments>
		<pubDate>Fri, 20 May 2011 19:17:41 +0000</pubDate>
		<dc:creator>spywareguru</dc:creator>
				<category><![CDATA[Removal Instructions List]]></category>
		<category><![CDATA[Bohu]]></category>
		<category><![CDATA[disables cloud based antivirus]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Trojan.Bohu]]></category>

		<guid isPermaLink="false">http://spywareremovalguides.com/?p=1529</guid>
		<description><![CDATA[Variant: Trojan.Bohu Operating Systems Affected: Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, Windows XP, Windows Vista, Windows 7 Trojan.Bohu is a recently discovered Trojan horse dated January 19, 2011. The malware is primarily designed to disable cloud based Antivirus software and its corresponding web dependent service. It proliferates through social networking sites by [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Variant: Trojan.Bohu</strong></p>
<p><strong>Operating Systems Affected: Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, Windows XP, Windows Vista, Windows 7</strong></p>
<p style="text-align: center;"><img class="aligncenter" src="http://dc303.4shared.com/img/QlQoA3JV/s7/0.05328986793740509/edited_TrojanBohu.jpg" alt="Trojan.Bohu" width="451" height="310" /></p>
<p><strong>Trojan.Bohu</strong> is a recently discovered Trojan horse dated January 19, 2011. The malware is primarily designed to disable cloud based Antivirus software and its corresponding web dependent service. It proliferates through social networking sites by sharing the download link of the trojan, a bogus video playback application as shown in the image above.</p>
<p>The <strong>Trojan.Bohu</strong> threat is acknowledged as the first of its kind that targets cloud-based antivirus application but definitely not the last one.</p>
<p>A <strong>Trojan horse</strong>, or <strong>Trojan</strong>, is a malware that appears to perform a desirable function for the user prior to run or install but instead facilitates unauthorized access of the user’s computer system. [source: <a title="Wikipedia" href="http://en.wikipedia.org/wiki/Wikipedia" target="_blank">Wikipedia</a>]<strong> </strong></p>
<h2><strong><span style="color: #ff0000;">Step by step manual removal guide:</span></strong></h2>
<p><strong>• Temporarily disable system restore</strong> [Windows ME / XP only]<br />
<strong>• Reboot and login under safe mode with networking </strong><br />
<strong></strong> [Press the F8 key on Windows boots up]<br />
<strong>• Temporarily show hidden files and folders</strong><br />
<strong></strong>[My Computer → Tools → Folder Options → View Tab → Tick show hidden folders, files and drives → Untick hide operating systems files → OK]<br />
<strong>• Navigate and delete the Trojan.Bohu created files:</strong><br />
<img src="http://dc362.4shared.com/img/bCD73-kJ/s3/0.167872376859044/ScreenHunter_03.jpg" alt="" /><br />
<strong></strong><br />
<strong>• Navigate and delete the Trojan.Bohu created registry key:</strong><br />
[Click Start → run → type regedit → click OK]<br />
<img src="http://dc226.4shared.com/img/lGuNN8f_/s3/0.07860844014073576/ScreenHunter_04.jpg" alt="" /><br />
<strong>• Navigate and delete the Trojan.Bohu created registry subkeys:</strong><br />
<img src="http://dc398.4shared.com/img/s_gmnjVi/s3/0.4505519407293268/ScreenHunter_05.jpg" alt="" /><br />
<strong>• Navigate and restore the original registry value:</strong><br />
<img src="http://dc239.4shared.com/img/V5Pz6HYt/s3/ScreenHunter_06.jpg" alt="" /></p>
<p><a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/regedit_overview.mspx?mfr=true" target="_blank"><span style="color: #ff0000;">Disclaimer: Registry modification is done at your own risk. Backup the registry before making any changes!</span></a></p>
<p><strong><a href="http://support.microsoft.com/kb/322756" target="_blank">Windows XP Registry Backup</a><br />
<a href="http://windows.microsoft.com/en-us/windows7/Back-up-the-registry" target="_blank">Windows 7 Registry Backup</a></strong></p>
<p><strong>• Update Antivirus definition files</strong><br />
<strong>• Run Antivirus full system scan</strong><br />
<strong>• Restore hidden files and folders settings</strong><br />
<strong></strong>[My Computer → Tools → Folder Options → View Tab → untiick show hidden folders, files and drives → tick hide operating systems files → OK]<br />
<strong>• Re-enable system restore </strong>[Windows ME / XP only]<br />
<strong>• Reboot and login under normal mode</strong><br />
<strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://spywareremovalguides.com/trojan-bohu-removal-steps.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TROJ_RANSOM.QOWA &#8211; Ransomware Trojan </title>
		<link>http://spywareremovalguides.com/ransomware-troj_ransom-removal.html</link>
		<comments>http://spywareremovalguides.com/ransomware-troj_ransom-removal.html#comments</comments>
		<pubDate>Sun, 20 Mar 2011 19:19:50 +0000</pubDate>
		<dc:creator>spywareguru</dc:creator>
				<category><![CDATA[Removal Instructions List]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[QOWA]]></category>
		<category><![CDATA[ransom]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Troj_Ransom]]></category>
		<category><![CDATA[TROJ_RANSOM.QOWA]]></category>

		<guid isPermaLink="false">http://spywareremovalguides.com/?p=1464</guid>
		<description><![CDATA[Variant: TROJ_RANSOM.QOWA [Trojan Ransomware] Operating Systems Affected: Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, Windows XP, Windows Vista, Windows 7 TROJ_RANSOM.QOWA is the latest ransomware trojan that has been detected by Trend Micro.  The malware threat is consistently on the rise and getting to be more destructive by the day than the previous variant of [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Variant: TROJ_RANSOM.QOWA</strong> [Trojan Ransomware]</p>
<p style="text-align: left;"><strong>Operating Systems Affected: <strong>Windows 2000, Windows 9x, Windows Me, Windows NT, Windows Server, <strong><strong>Windows XP, </strong></strong>Windows Vista, Windows 7</strong></strong></p>
<p style="text-align: center;"><img class="aligncenter" src="http://dc303.4shared.com/img/mWLQDuDa/s3/0.08157360205024289/ransomware.jpg" alt="" width="470" height="356" /></p>
<p style="text-align: left;">
<p style="text-align: left;">
<p><strong><em>TROJ_RANSOM.QOWA</em> </strong>is the latest ransomware trojan that has been detected by Trend Micro.  The malware threat is consistently on the rise and getting to be more destructive by the day than the previous variant of the trojan.</p>
<p><strong><em>Ransomware</em></strong> is computer malware which holds a computer system, or the data it contains, hostage against its user by demanding a ransom for its restoration. [source: <a href="http://en.wikipedia.org/wiki/Ransomware_(malware)" target="_blank">Wikipedia.org</a>]</p>
<p>Once your system is infected with the Trojan ransomware, it displays an image as shown above which locks the user’s desktop thus preventing access to the computer.  At the same time, the malware provides a paid access number to dial for sms communication. Don’t send any sms to the listed number! Don’t be scammed by this ransomware blackmail!</p>
<h2><span style="color: #ff0000;">Step by step manual removal guide:</span></h2>
<p><strong>• Disable system restore</strong> [Windows XP and ME]<br />
<strong> • Boot from Windows Installation CD</strong><br />
<img src="http://dc97.4shared.com/img/EZ39dRlM/s3/image_1.jpg" alt="" /><br />
<strong>• Remove the Windows Install CD</strong><br />
<strong> • Restart Windows and boot under normal mode</strong><br />
<strong> • Navigate and restore the original registry value:</strong><br />
<img src="http://dc381.4shared.com/img/UO7eiyD3/s3/image_2.jpg" alt="" /></p>
<p><a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/regedit_overview.mspx?mfr=true" target="_blank"><span style="color: #ff0000;">{Disclaimer: Registry modification is done at your own risk!}</span></a></p>
<div><a href="http://support.microsoft.com/kb/322756" target="_blank">How to do registry backup on your Windows XP? </a></div>
<div><a href="http://windows.microsoft.com/en-us/windows7/Back-up-the-registry" target="_blank">How to do registry backup on your Windows 7?</a></div>
<p><strong>• Update Anti-Virus Definiton files</strong><br />
<strong>• Run an Anti-Virus full system scan</strong><br />
<strong> • Re-enable system restore</strong> [Windows XP and ME]<br />
<strong> • Restart the computer</strong><br />
<strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://spywareremovalguides.com/ransomware-troj_ransom-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan.Ransomlock.F &#8211; Trojan horse that locks user’s desktop</title>
		<link>http://spywareremovalguides.com/trojan-ransomlock-f-removal.html</link>
		<comments>http://spywareremovalguides.com/trojan-ransomlock-f-removal.html#comments</comments>
		<pubDate>Sat, 25 Dec 2010 19:39:16 +0000</pubDate>
		<dc:creator>spywareguru</dc:creator>
				<category><![CDATA[Removal Instructions List]]></category>
		<category><![CDATA[ransomlock]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Trojan.Ransomlock.F]]></category>

		<guid isPermaLink="false">http://spywareremovalguides.com/?p=1201</guid>
		<description><![CDATA[Variant: Trojan.Ransomlock.F Operating Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7 WARNING! You surfed gay porn videos for three hours. The free viewing time has expired. To pay for the service, you need to make an online payment through the Beeline system to 9646280479 for the amount of $400 USD. Upon receipt of the [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong><span style="color: #333333;">Variant: Trojan.Ransomlock.F</span></strong></p>
<p><strong><span style="color: #333333;">Operating Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7</span></strong></p>
<p style="text-align: center;"><img class="alignleft" style="margin: 2px; border: 2px solid black;" src="http://dc192.4shared.com/img/tA7A_Jp5/s3/0.5545688270093521/RansomlockF.jpg" alt="" width="356" height="359" /><span style="color: #ff0000;">WARNING!</span></p>
<p style="text-align: center;"><span style="color: #ff0000;">You surfed gay porn videos for three hours.<br />
The free viewing time has expired.</span></p>
<p style="text-align: center;"><span style="color: #ff0000;">To pay for the service, you need to make an online payment through the Beeline system to 9646280479 for the amount of $400 USD.</span></p>
<p style="text-align: center;"><span style="color: #ff0000;">Upon receipt of the payment you will be given an activation code.<br />
Enter it in the box below and press Enter.</span></p>
<p><span style="font-weight: normal;"><span style="color: #333333;">[message shown above is a Russian to English translated text from the actual Trojan.Ransomlock.F pop up screen image]</span></span></p>
<p><span style="color: #333333;"><strong><em>Trojan.Ransomlock.F</em></strong> is a newly discovered Trojan horse (December 20, 2010) that locks PC user&#8217;s desktop thus making it unusable. First, the  malware adds a registry value to make itself load up every time Windows boots up. Once it&#8217;s activated it will stop running programs and processes making the operating system unstable. Then, it will disable the keyboard and mouse functionalities. Finally, it then displays the image with a message in Russian context and a lewd picture at the bottom right portion of the image.</span></p>
<p><span style="color: #333333;">Follow the listed steps below to remove <strong><em>Trojan.Ransomlock.F </em></strong>infection:</span></p>
<p><span style="color: #333333;"><strong>• Disable system restore </strong>(Windows ME and Windows XP users only)</span></p>
<p style="text-align: left;"><span style="color: #333333;"><strong><strong>• Boot to Safe Mode with Networking</strong> </strong>(press the F8 key before the Windows Logo appears then choose safe mode with networking → hit enter → and login on an account with Administrator credentials)</span></p>
<p style="text-align: left;">
<p style="text-align: left;"><span style="color: #333333;"><strong>• Show hidden files and folders </strong>(My Computer → Tools → Folder Options → View Tab → Tick show hidden folders, files and drives → Untick hide operating systems files → OK)</span></p>
<p style="text-align: left;"><span style="color: #000000;"><strong><strong><span style="color: #333333;">• Navigate and Delete the Trojan.Ransomlock.F file</span></strong></strong></span></p>
<p style="text-align: left;"><em><span style="color: #333333;">%UserProfile%\15886941\15886941.exe</span></em></p>
<p style="text-align: left;"><span style="color: #333333;"><strong>• Navigate and Delete the Trojan.Ransomlock.F added registry key </strong>(Start → run → regedit → navigate and delete the listed registry entry)</span></p>
<p style="text-align: left;"><em><span style="color: #333333;">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\&#8221;15886941&#8243; = &#8220;%UserProfile%\15886941\15886941.exe</span></em></p>
<p><strong><span style="color: #333333;">• Update anti-virus definition files</span></strong></p>
<p><strong><span style="color: #333333;">• Run a full anti-virus system scan</span></strong></p>
<p><span style="color: #333333;"><strong>• Re-enable System Restore</strong> (Windows ME and Windows XP users only)</span></p>
<p><strong><span style="color: #333333;">• Restart the computer</span></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://spywareremovalguides.com/trojan-ransomlock-f-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Backdoor.Riken &#8211; exploits Adobe Acrobat PDF file</title>
		<link>http://spywareremovalguides.com/backdoor-riken-removal.html</link>
		<comments>http://spywareremovalguides.com/backdoor-riken-removal.html#comments</comments>
		<pubDate>Thu, 23 Dec 2010 17:30:10 +0000</pubDate>
		<dc:creator>spywareguru</dc:creator>
				<category><![CDATA[Removal Instructions List]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[Backdoor.Riken]]></category>
		<category><![CDATA[riken]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://spywareremovalguides.com/?p=1168</guid>
		<description><![CDATA[Variant: Backdoor.Riken Operating Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7 Backdoor.Riken is a malicious Trojan that exploits Adobe Acrobat PDF vulnerability. Once the Trojan is activated, it will try to download and install other malware files to the already infected system. The Trojan then edits the registry to add itself to the startup [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Variant: Backdoor.Riken</strong></p>
<p style="text-align: left;"><strong>Operating Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7</strong><br />
<img class="aligncenter" src="http://dc190.4shared.com/img/mXimnyT8/s3/0.7023493889057947/PDF-exploit.jpg" alt="" width="405" height="305" /></p>
<p><em><strong>Backdoor.Riken</strong> </em>is a malicious Trojan that exploits Adobe Acrobat PDF vulnerability. Once the Trojan is activated, it will try to download and install other malware files to the already infected system. The Trojan then edits the registry to add itself to the startup list, so that every time Windows boots up, it automatically starts as well. <strong><em>Backdoor.Riken</em></strong>’s main objective is to embed snippets or coded scripts to steal PC users confidential account log-in information from online banking sites.</p>
<p>Step by step instructions on manual removal of  <strong>Backdoor.Riken </strong>:</p>
<p><strong>• Disable system restore </strong>(Windows ME and Windows XP users only) Right click My Computer → Properties → System Restore tab → Tick  turn off system restore on all drives box → Restart Computer</p>
<p><strong><strong>• </strong>Boot to Safe Mode </strong>(Press the F8 key before the Windows Logo appears then log in on an account with administrator credentials)</p>
<p><strong>• Show hidden files and folders </strong>(My Computer → Tools → Folder Options → View Tab → Tick show hidden folders, files and drives → Untick hide operating systems files → OK)</p>
<p><strong>• Delete Backdoor.Riken created files:</strong></p>
<p><em>%System%\svcvc.exe<br />
%System%\UsbStorageLog.txt</em></p>
<p><strong>• Delete Backdoor.Riken added registry values: </strong>(Start → run → regedit → navigate and delete the listed registry entries)</p>
<p><em>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”SamPs” = “C:\WINDOWS\system32\svcvc.exe”</em></p>
<p><em>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy \StandardProfile\AuthorizedApplications\List\”C:\WINDOWS\system32\svcvc.exe”  = “C:\WINDOWS\system32\svcvc.exe:*:Enabled:svcvc.exe”</em></p>
<p><em>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Window\”monstate” = “ID”</em></p>
<p><em>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Window\”KeyKill” = “ID”</em></p>
<p><em><span style="color: #ff0000;">{Disclaimer: Registry modification is done at your own risk. Backup the registry before making any changes!}</span></em></p>
<p><strong>• Update anti-virus definition files</strong></p>
<p><strong>• Run anti-virus full system scan</strong></p>
<p><strong>• Re-enable System Restore</strong> (Windows ME and XP users only) Right click My Computer → Properties → System Restore tab → Untick  turn off system restore on all drives box.</p>
<p><strong><strong>• Restart the computer</strong></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://spywareremovalguides.com/backdoor-riken-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

