<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6158434637838820059</id><updated>2011-11-27T15:21:43.762-08:00</updated><title type='text'>'Now We Hack Virus' Not They</title><subtitle type='html'>Hacking isn't illegal when we hack viruses!
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;

You don't need an antivirus everytime to kill virus</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-3659404463135169129</id><published>2008-07-27T03:36:00.000-07:00</published><updated>2008-07-27T04:08:23.284-07:00</updated><title type='text'>Remove PC Privacy Cleaner (PCPrivacyCleaner)</title><content type='html'>&lt;span style="font-size:100%;"&gt;A rogue antivirus which is often accompanied by other similar antivirus. Well if you have it in your system remove it as soon as possible as it will download so many similar programs that it will become a impossible to work on your computer. Some of the  screenshots of PC Privacy Cleaner&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SIxVmIgK2bI/AAAAAAAAAdo/RP1ZySQzE_A/s1600-h/virus.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SIxVmIgK2bI/AAAAAAAAAdo/RP1ZySQzE_A/s400/virus.JPG" alt="" id="BLOGGER_PHOTO_ID_5227647381076105650" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SIxVmRLW-0I/AAAAAAAAAdw/rC-qFsFnkik/s1600-h/baloon.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SIxVmRLW-0I/AAAAAAAAAdw/rC-qFsFnkik/s400/baloon.JPG" alt="" id="BLOGGER_PHOTO_ID_5227647383404739394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);font-size:100%;" &gt;NEVER CLICK YES A WARNING LIKE THIS ONE&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size:100%;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SIxVL3RYEVI/AAAAAAAAAdA/FsPxMcZiGDA/s1600-h/fakewarning.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SIxVL3RYEVI/AAAAAAAAAdA/FsPxMcZiGDA/s400/fakewarning.JPG" alt="" id="BLOGGER_PHOTO_ID_5227646929774055762" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;a style="color: rgb(0, 0, 0);" href="http://wehackvirus.blogspot.com/2008/07/remove-pc-privacy-cleaner.html"&gt;Manual Removal Steps&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;1.&lt;/span&gt;&lt;span style="font-size:100%;"&gt; Open task manager (Ctrl+Alt+Del) and kill the process &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;pcpc.exe&lt;/span&gt;&lt;br /&gt;If you also having a process named &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;PCPC_Setup_Free.exe&lt;/span&gt; running, end that too.&lt;br /&gt;If you get a message like &lt;u&gt;task manager has been disabled...&lt;/u&gt;, download a tool from &lt;a href="http://xp-solutions.blogspot.com/2008/07/enabledisable-task-manager.html" target="_blank"&gt;here&lt;/a&gt; to open task manager.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SIxVL715ysI/AAAAAAAAAdI/EiKv9v1TZTg/s1600-h/taskmanager.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SIxVL715ysI/AAAAAAAAAdI/EiKv9v1TZTg/s400/taskmanager.JPG" alt="" id="BLOGGER_PHOTO_ID_5227646931001002690" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2. &lt;/span&gt;Now go to C:\Program Files (assuming you ha&lt;/span&gt;&lt;span style="font-size:100%;"&gt;ve your windows in C drive) and delete the folder named &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;PCPrivacyCleaner&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3.&lt;/span&gt; Next remove shortcuts of &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;PC Privacy Cleaner&lt;/span&gt; from desktop, start menu and quick launch.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;4. &lt;/span&gt;&lt;span style="font-size:100%;"&gt;Empty Recycle Bin&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:130%;" &gt;Now we need to do some registry e&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;&lt;span style="font-size:130%;"&gt;diting. Be care ful as wrongly doing this can lead to system instability&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;5. &lt;/span&gt;Go Start-&gt;Run-&gt; type regedit and press enter&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;6. &lt;/span&gt;Navigate to&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:78%;" &gt;&lt;span style="font-style: italic;"&gt;HKEY_CURRENT_USER\Software\{65DE966D-11D1-4bb1-BF7E-B8A273514DAF}&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;and del the key &lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;{65DE966D-11D1-4bb1-BF7&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;E-B8A273514DAF}&lt;/span&gt;&lt;br /&gt;(See the pic after next step to know how to do it)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;7.&lt;/span&gt; Now navigate to&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:78%;" &gt;&lt;span style="font-style: italic;"&gt;HKEY_CURRENT_USER\Software\PCPrivacyCleaner&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;and delete the key &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;PCPrivacyCleaner&lt;/span&gt;.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SIxVL2w-xNI/AAAAAAAAAdQ/ik6E3XJtU-Y/s1600-h/regedit1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SIxVL2w-xNI/AAAAAAAAAdQ/ik6E3XJtU-Y/s400/regedit1.JPG" alt="" id="BLOGGER_PHOTO_ID_5227646929638180050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;8.&lt;/span&gt; Now navigate to&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color: rgb(255, 0, 0);font-size:78%;" &gt;&lt;span style="font-style: italic;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;locate and delete the string named &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;PCPrivacyCleaner&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SIxVL-hfUgI/AAAAAAAAAdY/dpVUVH-qeWU/s1600-h/regedit2.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SIxVL-hfUgI/AAAAAAAAAdY/dpVUVH-qeWU/s400/regedit2.JPG" alt="" id="BLOGGER_PHOTO_ID_5227646931720688130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;9.&lt;/span&gt; Again navigate to&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:78%;" &gt;&lt;span style="font-style: italic;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCPrivacyCleaner&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;And delete the key &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;PCPrivacyCleaner&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SIxVMJfyodI/AAAAAAAAAdg/l0eWmYaCf0Y/s1600-h/regedit3.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SIxVMJfyodI/AAAAAAAAAdg/l0eWmYaCf0Y/s400/regedit3.JPG" alt="" id="BLOGGER_PHOTO_ID_5227646934666355154" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;Your system is free from this rogue antivirus.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Because this usually is accompanied by other similar antiviruses be sure to check your pc.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-3659404463135169129?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/3659404463135169129/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=3659404463135169129&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/3659404463135169129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/3659404463135169129'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/07/remove-pc-privacy-cleaner.html' title='Remove PC Privacy Cleaner (PCPrivacyCleaner)'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wOu39jLJGgA/SIxVmIgK2bI/AAAAAAAAAdo/RP1ZySQzE_A/s72-c/virus.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-157764425822193464</id><published>2008-07-16T10:18:00.000-07:00</published><updated>2008-07-24T02:57:27.971-07:00</updated><title type='text'>Remove Antivirus 2009</title><content type='html'>Antivirus 2009 is the newer version of the Antivirus 2008 and is there to scam you. Also just like its older version, its makes your system slow, brings unwanted popups and can also make your system infected with some serious trojans. So its advisable to remove it as soon as you get infected.&lt;br /&gt;The following pics reveal how convincing this scam is that the user in major cases believe it to be a true antivirus.&lt;br /&gt;&lt;br /&gt;The new antivirus is out with an added professional look&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SH4u8FLm6zI/AAAAAAAAAcE/xvEXbpdfRCE/s1600-h/rogue.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SH4u8FLm6zI/AAAAAAAAAcE/xvEXbpdfRCE/s400/rogue.JPG" alt="" id="BLOGGER_PHOTO_ID_5223664227514247986" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Its make a fake security  center named '&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Windows Security Center&lt;/span&gt;', the windows one being the  Security Center&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SH4u8DmzQ6I/AAAAAAAAAcM/q4z8yHHnvxU/s1600-h/fakesecuritycenter.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SH4u8DmzQ6I/AAAAAAAAAcM/q4z8yHHnvxU/s400/fakesecuritycenter.JPG" alt="" id="BLOGGER_PHOTO_ID_5223664227091432354" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;REMOVAL STEPS&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;1. Open task manager(Ctrl+Alt+Del). Locate and end the process &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;av2009.exe&lt;/span&gt; using right click and selecting 'end process' option.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SH4u8f2tvrI/AAAAAAAAAcU/I_g583_VyoE/s1600-h/taskmanager.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SH4u8f2tvrI/AAAAAAAAAcU/I_g583_VyoE/s400/taskmanager.JPG" alt="" id="BLOGGER_PHOTO_ID_5223664234674372274" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2. Now go to C:\Program Files(Assuming that you have windows installed in C drive) and delete the entire folder named &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Antivirus 2009&lt;/span&gt;.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SH4uo7sD9LI/AAAAAAAAAbc/4NKrXETU0sE/s1600-h/program+files.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SH4uo7sD9LI/AAAAAAAAAbc/4NKrXETU0sE/s400/program+files.JPG" alt="" id="BLOGGER_PHOTO_ID_5223663898548499634" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;3. As seen in the second picture, Antivirus 2009 makes a fake Windows security center. So we need to remove that. So go to C:\windows\system32 and delete the file &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;scui.cpl&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SH4uo0EEOdI/AAAAAAAAAbk/HhyEEoEh3xk/s1600-h/system32scui.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SH4uo0EEOdI/AAAAAAAAAbk/HhyEEoEh3xk/s400/system32scui.jpg" alt="" id="BLOGGER_PHOTO_ID_5223663896501696978" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;4. Now delete all the shortcuts on desktop and start menu made by &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Antivirus 2009&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;5. Empty recycle bin&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:130%;" &gt;&lt;span style="font-weight: bold;"&gt;Now we need to do some registry editing&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);font-size:130%;" &gt;&lt;span style="font-weight: bold;"&gt;. Please complete the following steps carefully as improper registry editing could lead to system instability.&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);font-size:130%;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;6. Go to Start Menu-&gt;Run-&gt; Type regedit and press enter&lt;br /&gt;&lt;br /&gt;7. Navigate to&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:78%;" &gt;&lt;span style="font-style: italic;"&gt;HKEY_CURRENT_USER\Software\39148080807332159842981568027496&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Delete the &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;key&lt;/span&gt; ( i.e. &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;the key with a long number&lt;/span&gt; which may differ in your pc but will be very long)&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SH4upIdsx1I/AAAAAAAAAbs/mosvUU-GyAk/s1600-h/regedit1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SH4upIdsx1I/AAAAAAAAAbs/mosvUU-GyAk/s400/regedit1.JPG" alt="" id="BLOGGER_PHOTO_ID_5223663901977921362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;8. Now Navigate to&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:78%;" &gt;&lt;span style="font-style: italic;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;and d&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;elete name(long nos.)&lt;/span&gt; with data as C:\Program Files\Antivirus 2009\av2009.exe&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SH4updrl7tI/AAAAAAAAAb0/OjI_lsBpMiA/s1600-h/regedit2.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SH4updrl7tI/AAAAAAAAAb0/OjI_lsBpMiA/s400/regedit2.JPG" alt="" id="BLOGGER_PHOTO_ID_5223663907673337554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;9. Navigate to&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:78%;" &gt;&lt;span style="font-style: italic;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2009&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;Delete this key i.e. &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Antivirus 2009&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SH4upkS8SBI/AAAAAAAAAb8/Y65K9Y_7Kg0/s1600-h/regedit3.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SH4upkS8SBI/AAAAAAAAAb8/Y65K9Y_7Kg0/s400/regedit3.JPG" alt="" id="BLOGGER_PHOTO_ID_5223663909448992786" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;10 Now if your themes, appearance and settings are missing you can download small tool from &lt;span style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;&lt;a href="http://xp-solutions.blogspot.com/"&gt;here&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Your pc is clean&lt;br /&gt;&lt;br /&gt;Please post your comments in the &lt;u&gt;comments section or click the CONTACT ME PIC ABOVE.&lt;/u&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-157764425822193464?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/157764425822193464/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=157764425822193464&amp;isPopup=true' title='19 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/157764425822193464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/157764425822193464'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/07/remove-antivirus-2009.html' title='Remove Antivirus 2009'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wOu39jLJGgA/SH4u8FLm6zI/AAAAAAAAAcE/xvEXbpdfRCE/s72-c/rogue.JPG' height='72' width='72'/><thr:total>19</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-3019360381870831818</id><published>2008-07-16T01:27:00.000-07:00</published><updated>2008-07-24T02:58:06.380-07:00</updated><title type='text'>Remove Antivirus 2008 Pro Fake Antivirus</title><content type='html'>Antivirus2008Pro is another fake antivirus scam that wants your $50. It displays fake virus reports, hogs ups system memory and makes you frustrated. Though it is categorised as dangerous by many websites, it is quite simple to remove. You just need to follow the following to simple steps to remove it.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SH2x-gT8NVI/AAAAAAAAAas/YAElh8u1Qfg/s1600-h/rogue.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SH2x-gT8NVI/AAAAAAAAAas/YAElh8u1Qfg/s400/rogue.JPG" alt="" id="BLOGGER_PHOTO_ID_5223526830203221330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;REMOVAL STEPS&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1. Open task manager(Ctrl+Alt+Del). Locate and kill the process &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;Antivirus2008PRO.exe&lt;/span&gt; using right click.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SH2x-q98srI/AAAAAAAAAa0/-UaXdURTACQ/s1600-h/taskmanager.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SH2x-q98srI/AAAAAAAAAa0/-UaXdURTACQ/s400/taskmanager.JPG" alt="" id="BLOGGER_PHOTO_ID_5223526833063768754" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;2. Now go to C:\program files(Assuming that your windows are installed in C drive).&lt;br /&gt;Locate and delete the folder &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Antivirus 2008 PRO&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SH2x-7m5JfI/AAAAAAAAAa8/BM_wZ1P0IyI/s1600-h/programfilesfolder.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SH2x-7m5JfI/AAAAAAAAAa8/BM_wZ1P0IyI/s400/programfilesfolder.JPG" alt="" id="BLOGGER_PHOTO_ID_5223526837530469874" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;3. Now delete the shortcuts made by it on desktop and in start menu.&lt;br /&gt;&lt;br /&gt;4. Empty recycle bin&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Now we need to do some registry editing. This need to be done carefully, otherwise it can lead to system in&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;stability&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;5. Open registry editing. Start Menu-&gt;Run-&gt; Type regedit and press enter&lt;br /&gt;&lt;br /&gt;6. Navigate to&lt;br /&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;&lt;span style="color: rgb(255, 0, 0);"&gt;HKEY_CURRENT_USER\Software\Antivirus 2008 PRO&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;and delete the key &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;Antivirus 2008 PRO&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SH2x_ELB9uI/AAAAAAAAAbE/2th4RTnol6E/s1600-h/regedit1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SH2x_ELB9uI/AAAAAAAAAbE/2th4RTnol6E/s400/regedit1.JPG" alt="" id="BLOGGER_PHOTO_ID_5223526839829526242" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;7. Now Navigate to&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:78%;" &gt;&lt;span style="font-style: italic;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Locate string &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;antivirus-2008pro.exe&lt;/span&gt; on right side and delete it using the right click.&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;&lt;u&gt;DONOT DELETE THE RUN KEY&lt;/u&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SH2x_NDt3NI/AAAAAAAAAbM/A4gemO1832o/s1600-h/regedit2.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SH2x_NDt3NI/AAAAAAAAAbM/A4gemO1832o/s400/regedit2.JPG" alt="" id="BLOGGER_PHOTO_ID_5223526842214767826" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;8. Now Navigate to&lt;br /&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;&lt;span style="color: rgb(255, 0, 0);"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus 2008 PRO&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;and delete the key&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt; Antivirus 2008 PRO&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SH27uX9EKsI/AAAAAAAAAbU/mFOrWbzmYJY/s1600-h/regedit3.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SH27uX9EKsI/AAAAAAAAAbU/mFOrWbzmYJY/s400/regedit3.JPG" alt="" id="BLOGGER_PHOTO_ID_5223537548198161090" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;9 Now if your themes, appearance and settings are missing you can download small tool from &lt;span style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;&lt;a href="http://xp-solutions.blogspot.com/"&gt;here&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now your system is free from this virus&lt;br /&gt;&lt;br /&gt;Please post your comments in the &lt;u&gt;comments section or click the CONTACT ME BUTTON&lt;/u&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-3019360381870831818?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/3019360381870831818/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=3019360381870831818&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/3019360381870831818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/3019360381870831818'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/07/remove-antivirus-2008-pro-fake.html' title='Remove Antivirus 2008 Pro Fake Antivirus'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_wOu39jLJGgA/SH2x-gT8NVI/AAAAAAAAAas/YAElh8u1Qfg/s72-c/rogue.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-2295365015026932125</id><published>2008-07-15T01:25:00.000-07:00</published><updated>2008-07-24T03:00:07.201-07:00</updated><title type='text'>Remove Nhatquanglan i.e. New Folder.exe Virus</title><content type='html'>New Folder.exe Virus also known as Nhatquanglan is a very common virus with high multiply rate. This virus hides itself as &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;scvhsot.exe&lt;/span&gt; though the actual actaul windows process is Scvhost.exe. The virus drops a copy of itself everytime you attach a removable media to your computer. Besides this it disables registry, task manager and removes the option of task manager.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SHxoUVEB1DI/AAAAAAAAAak/c8lhdXYUlX0/s1600-h/taskmanagerdisabled.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SHxoUVEB1DI/AAAAAAAAAak/c8lhdXYUlX0/s400/taskmanagerdisabled.JPG" alt="" id="BLOGGER_PHOTO_ID_5223164366303646770" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SHxnAEWPGlI/AAAAAAAAAZ8/ZmDKDKqN6NA/s1600-h/regeditdisabled.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SHxnAEWPGlI/AAAAAAAAAZ8/ZmDKDKqN6NA/s400/regeditdisabled.JPG" alt="" id="BLOGGER_PHOTO_ID_5223162918707599954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;span style="color: rgb(255, 0, 0);"&gt;SOFTWARES REQUIRED&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;As your task manager, registry editor and folder options are disabled we will need a couple of tiny but very helpful softwares.&lt;br /&gt;Click on them to download&lt;br /&gt;&lt;a href="http://www.neuber.com/taskmanager/download.html" target="_blank"&gt;Security Task Manager&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.softpedia.com/get/Security/Security-Related/RRT-Remove-Ristrictions-Tool.shtml" target="_blank"&gt;RRT&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;ATTACH YOUR INFECTED FLASH DRIVE(if any&lt;/u&gt;&lt;u&gt;) TO &lt;/u&gt;&lt;u&gt;Y&lt;/u&gt;&lt;u&gt;O&lt;/u&gt;&lt;u&gt;UR COMPUTER AND MAKE A BACKUP OF DATA ON IT&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;REMOVAL STEPS&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1.&lt;/span&gt; Install &lt;span style="font-style: italic;"&gt;security task manager&lt;/span&gt; and start it. You will see one,two or more processes named &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;Nhatquanglan&lt;/span&gt;. Select all of them by pressing Ctrl key and remove them&lt;br /&gt;(right click-&gt;remove -&gt;end process-&gt; yes)&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SHxnAqM1yKI/AAAAAAAAAaM/qbb7EhCLEtw/s1600-h/security+task+manager.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SHxnAqM1yKI/AAAAAAAAAaM/qbb7EhCLEtw/s400/security+task+manager.JPG" alt="" id="BLOGGER_PHOTO_ID_5223162928868739234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2.&lt;/span&gt; Next run the &lt;span style="font-style: italic;"&gt;RRT&lt;/span&gt; software and remove all the restrictions. Now you will be able to open task manager and registry editor. It will say you need a system restart but you dont need it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3.&lt;/span&gt; Go to Control panel-&gt;scheduled task and delete the &lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;At1&lt;/span&gt; task&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SHxnAdlyxEI/AAAAAAAAAaE/SuNjFJqZ2Ko/s1600-h/scheduled+task.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SHxnAdlyxEI/AAAAAAAAAaE/SuNjFJqZ2Ko/s400/scheduled+task.JPG" alt="" id="BLOGGER_PHOTO_ID_5223162925483738178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;4.&lt;/span&gt; Next C:\windows\system32 folder and click tools-&gt;folder options-&gt;view tab&lt;br /&gt;Find the Hide protected operating system.... and untick it.&lt;br /&gt;Click YES on the a warning-&gt; click Apply and OK.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SHxnABiBalI/AAAAAAAAAZ0/iB0WCZYkaK8/s1600-h/folderoptions.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SHxnABiBalI/AAAAAAAAAZ0/iB0WCZYkaK8/s400/folderoptions.JPG" alt="" id="BLOGGER_PHOTO_ID_5223162917951728210" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;u&gt;FORMAT YOU REMOVABLE DISK WITHOUT O&lt;/u&gt;&lt;u&gt;PENING IT OTHERWISE YOU WILL HAVE TO REPEAT ALL THE STEPS&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;5. Next we need to delete some files.&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(255, 0, 0);"&gt;Also you need to be a bit careful as if you double click any of these files you will have to start all over again from step 1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In the C:\windows\system32 folder delete the following files.&lt;br /&gt;(The last two files will have the icon of a folder as in the picture)&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;setting.ini&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;autorun.ini&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;SCVHSOT.exe (225792 bytes)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;blastclnnn.exe &lt;/span&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;(225792 bytes)&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SHxnVqKRASI/AAAAAAAAAac/SwrXLmwv1Lk/s1600-h/system32.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 489px; height: 135px;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SHxnVqKRASI/AAAAAAAAAac/SwrXLmwv1Lk/s400/system32.JPG" alt="" id="BLOGGER_PHOTO_ID_5223163289635193122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In the C:\windows folder delete the following files.&lt;br /&gt;(The files will have icon of a folder)&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;SVCHSOT.exe &lt;/span&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;(225792 bytes)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;hinhem.scr &lt;/span&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;(225792 bytes)&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SHxnVXmnsQI/AAAAAAAAAaU/VDlPFVJWcQQ/s1600-h/windowsfolder.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SHxnVXmnsQI/AAAAAAAAAaU/VDlPFVJWcQQ/s400/windowsfolder.JPG" alt="" id="BLOGGER_PHOTO_ID_5223163284653846786" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;6. Empty Recycle bin&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:130%;" &gt;Now we need to do some registry editing&lt;br /&gt;Please follow these steps very carefully as improper registry editing could lead to system crash.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;7. Go to start-&gt;run-&gt;type regedit and press enter&lt;br /&gt;&lt;br /&gt;8. Navigate to&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-style: italic;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;and delete the string &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;Yahoo Messengger&lt;/span&gt; with data pointing to &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;SCVHSOT.exe&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SHxm_39-qPI/AAAAAAAAAZs/ls0EkiJrlBY/s1600-h/regedit1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SHxm_39-qPI/AAAAAAAAAZs/ls0EkiJrlBY/s400/regedit1.JPG" alt="" id="BLOGGER_PHOTO_ID_5223162915384633586" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;9. Navigate to&lt;br /&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentV&lt;/span&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;ersion\Winlogon&lt;/span&gt;&lt;br /&gt;Find the string named shell on the right side with data as &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;Explorer.exe&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;SCVHSOT.exe&lt;/span&gt;&lt;br /&gt;Double click it and Change its value to &lt;span style="color: rgb(255, 0, 0);"&gt;Explorer.exe&lt;/span&gt;&lt;br /&gt;You dont have to delete anything here&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SHxmaxl62fI/AAAAAAAAAZk/H6p-kNFPgZc/s1600-h/regedit2.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SHxmaxl62fI/AAAAAAAAAZk/H6p-kNFPgZc/s400/regedit2.JPG" alt="" id="BLOGGER_PHOTO_ID_5223162278017948146" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;10 Now if your themes, appearance and settings are missing you can download small tool from &lt;span style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;&lt;a href="http://xp-solutions.blogspot.com/"&gt;here&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now your pc is clean from this nasty virus.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;WORD OF CAUTION&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Well as a word of caution, whenever you see a file with an icon of a folder, BE CAREFUL. In 99.99% cases it will be a virus ready to infect as soon as you double click it.&lt;br /&gt;&lt;br /&gt;For any comments, suggestions or queries please use the &lt;u&gt;comments section or click the contact me picture above&lt;/u&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-2295365015026932125?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/2295365015026932125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=2295365015026932125&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/2295365015026932125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/2295365015026932125'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/07/remove-nhatquanglan-ie-new-folderexe.html' title='Remove Nhatquanglan i.e. New Folder.exe Virus'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wOu39jLJGgA/SHxoUVEB1DI/AAAAAAAAAak/c8lhdXYUlX0/s72-c/taskmanagerdisabled.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-4047432809088200257</id><published>2008-07-13T12:51:00.000-07:00</published><updated>2008-08-01T20:58:00.428-07:00</updated><title type='text'>Remove Antivirus XP 2008</title><content type='html'>Antivirus XP 2008 has been scamming many people off late. It installs on your pc shows false scanning showing that you have plenty of viruses and to remove them you will have to purchase the Antivirus XP 2008. Seeing this many people have already shelled out there hard earned money for this fake software. Besides this it also slows down your pc making it impossible to work. Well following are some of shots of this virus.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SHpg9Cr6GkI/AAAAAAAAAZc/fsRjfF0OSEc/s1600-h/virus.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SHpg9Cr6GkI/AAAAAAAAAZc/fsRjfF0OSEc/s400/virus.JPG" alt="" id="BLOGGER_PHOTO_ID_5222593319698831938" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SHpg0w0oYSI/AAAAAAAAAZU/wiqttrxCtSU/s1600-h/warning.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SHpg0w0oYSI/AAAAAAAAAZU/wiqttrxCtSU/s400/warning.JPG" alt="" id="BLOGGER_PHOTO_ID_5222593177464627490" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Well if you have downloaded it from some website, here is the screen shot its website.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SHpgjRsgSeI/AAAAAAAAAZM/TG0s_2a7g_0/s1600-h/website.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SHpgjRsgSeI/AAAAAAAAAZM/TG0s_2a7g_0/s400/website.JPG" alt="" id="BLOGGER_PHOTO_ID_5222592877051267554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Browser Hijack by Antivirus XP 2008&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SHpgUuEMd1I/AAAAAAAAAZE/DRReLXamab4/s1600-h/browser+hijack.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SHpgUuEMd1I/AAAAAAAAAZE/DRReLXamab4/s400/browser+hijack.JPG" alt="" id="BLOGGER_PHOTO_ID_5222592626968786770" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;a href="http://wehackvirus.blogspot.com/2008/07/remove-antivirus-xp-2008.html"&gt;REMOVAL PROCEDURE&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1. Open task manager(Ctrl+Alt+Del) &amp;amp; kill the following processes by using right click in the following order(&lt;span style="color: rgb(255, 0, 0);"&gt;the exact names of the files will differ but the&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;y will be 12 character long. Also note the names of the files before deleting as at all places the variation of name will be there accordingly. Because of variation I will be using Virus1 for the first one and Virus2 for the second on&lt;/span&gt;e)&lt;br /&gt;&lt;br /&gt;&lt;ul style="color: rgb(204, 0, 0);"&gt;&lt;li&gt;rhc1cdj0e12r.exe&lt;/li&gt;&lt;li&gt;pphc5cdj0e12r.exe&lt;/li&gt;&lt;/ul&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SHpgEsIrnpI/AAAAAAAAAY8/1H4Ah3_YEec/s1600-h/taskmanager.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SHpgEsIrnpI/AAAAAAAAAY8/1H4Ah3_YEec/s400/taskmanager.JPG" alt="" id="BLOGGER_PHOTO_ID_5222592351572827794" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;2. Now open C:\windows\system32(Assuming you have windows installed in C drive) and trace &lt;span style="font-style: italic; font-weight: bold; color: rgb(204, 0, 0);"&gt;Virus2&lt;/span&gt; and delete it.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SHpf0bRdeHI/AAAAAAAAAY0/rgcb7eThRIQ/s1600-h/system32file.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SHpf0bRdeHI/AAAAAAAAAY0/rgcb7eThRIQ/s400/system32file.bmp" alt="" id="BLOGGER_PHOTO_ID_5222592072168339570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;3. Next open c:\program files and find the folder named &lt;span style="color: rgb(204, 0, 0); font-style: italic; font-weight: bold;"&gt;Virus1&lt;/span&gt;. Delete the entire folder.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SHpfq8YsDLI/AAAAAAAAAYs/lCxIMjKuycY/s1600-h/virusfolder.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SHpfq8YsDLI/AAAAAAAAAYs/lCxIMjKuycY/s400/virusfolder.JPG" alt="" id="BLOGGER_PHOTO_ID_5222591909258333362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;4. Next delete all traces of &lt;span style="font-style: italic; font-weight: bold; color: rgb(204, 0, 0);"&gt;Antivirus XP 2008&lt;/span&gt; from desktop and start menu(shortcuts)&lt;br /&gt;&lt;br /&gt;5. Empty recycle bin&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;The following steps require registry editing&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt; so follow them carefully. Improper editing could lead to system crash.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;6. Go start menu-&gt;run-&gt; type 'regedit' and press enter. Regsitry Editor will open up.&lt;br /&gt;&lt;br /&gt;7. Navigate to&lt;br /&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion&lt;/span&gt;&lt;br /&gt;Locate and delete &lt;span style="color: rgb(204, 0, 0); font-style: italic; font-weight: bold;"&gt;virus1&lt;/span&gt; using right click&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SHpfZ-szU9I/AAAAAAAAAYk/AWNUnREOnlU/s1600-h/regedit1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SHpfZ-szU9I/AAAAAAAAAYk/AWNUnREOnlU/s400/regedit1.JPG" alt="" id="BLOGGER_PHOTO_ID_5222591617821791186" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;8. Next Navigate to&lt;br /&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Cur&lt;/span&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;rentVersion\Run&lt;/span&gt;&lt;br /&gt;Locate &amp;amp; delete &lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;SM&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(204, 0, 0);"&gt;virus1&lt;/span&gt; using right click&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SHpfPRS7fyI/AAAAAAAAAYc/G1a45UnPUbA/s1600-h/regedit2.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SHpfPRS7fyI/AAAAAAAAAYc/G1a45UnPUbA/s400/regedit2.JPG" alt="" id="BLOGGER_PHOTO_ID_5222591433834987298" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;9. Now go to&lt;br /&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhc1cdj0e12r&lt;/span&gt;&lt;br /&gt;del key &lt;span style="font-weight: bold; font-style: italic; color: rgb(204, 0, 0);"&gt;Virus1&lt;/span&gt; using right click&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SHpfCU_GIoI/AAAAAAAAAYU/GZsuoH6bq7k/s1600-h/regedit3.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SHpfCU_GIoI/AAAAAAAAAYU/GZsuoH6bq7k/s400/regedit3.JPG" alt="" id="BLOGGER_PHOTO_ID_5222591211487240834" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;10. Now&lt;br /&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform&lt;/span&gt;&lt;br /&gt;Locate '&lt;span style="color: rgb(204, 0, 0); font-weight: bold; font-style: italic;"&gt;AntivirXP08&lt;/span&gt;' on right side and delete it.&lt;br /&gt;&lt;br /&gt;Now there is only one step left which can be performed only when you log in to windows next time.&lt;br /&gt;&lt;br /&gt;11.Navigate to&lt;br /&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;HKEY_LOCAL_MACHINE\SOFTWARE\rhc1cdj0e12r&lt;/span&gt;&lt;br /&gt;del key &lt;span style="font-weight: bold; font-style: italic; color: rgb(153, 0, 0);"&gt;Virus1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;12 Navigate to&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-style: italic;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus XP 2008&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;And delete the key &lt;span style="color: rgb(204, 0, 0); font-weight: bold; font-style: italic;"&gt;Antivirus XP 2008&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;13 Now if your themes, appearance and settings are missing you can download small tool from &lt;span style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;&lt;a href="http://xp-solutions.blogspot.com/"&gt;here&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now your system is clean from this fake antivirus.&lt;br /&gt;&lt;br /&gt;For any comments, questions or suggestions, please do &lt;u&gt;comment in the comment section or click the contact me button above&lt;/u&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-4047432809088200257?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/4047432809088200257/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=4047432809088200257&amp;isPopup=true' title='18 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/4047432809088200257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/4047432809088200257'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/07/remove-antivirus-xp-2008.html' title='Remove Antivirus XP 2008'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wOu39jLJGgA/SHpg9Cr6GkI/AAAAAAAAAZc/fsRjfF0OSEc/s72-c/virus.JPG' height='72' width='72'/><thr:total>18</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-1041150215196252740</id><published>2008-07-12T11:45:00.000-07:00</published><updated>2008-07-24T02:59:04.440-07:00</updated><title type='text'>Remove Vista Antivirus 2008</title><content type='html'>Vista Antivirus is a new rogue antivirus which tries to rob your money. Besides that it slows down your pc and with unwanted popups, it makes your working on the computer impossible. &lt;u&gt;The following is a screenshot of Vista Antivirus 2008 and its warning&lt;/u&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SHj8ciV4vNI/AAAAAAAAAXc/9rkPqRY1F5A/s1600-h/rogueantivirus.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5222201335121231058" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SHj8ciV4vNI/AAAAAAAAAXc/9rkPqRY1F5A/s400/rogueantivirus.JPG" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SHj9QYVVkDI/AAAAAAAAAXk/6xHJWiNryMk/s1600-h/warning.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5222202225787768882" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SHj9QYVVkDI/AAAAAAAAAXk/6xHJWiNryMk/s400/warning.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Also if you downloaded it from its website, here is the screenshot of the website&lt;/u&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SHj9pEtWT6I/AAAAAAAAAXs/n869qBmpq64/s1600-h/website.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5222202650016501666" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SHj9pEtWT6I/AAAAAAAAAXs/n869qBmpq64/s400/website.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Though it may be very harmful, it is very easy to clean. Just follow these easy steps accompanied by pictures to clean your pc from this false vista antivirus.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;1.&lt;/span&gt; First of all open task manager(Ctrl+Alt+Del) and go to process tab. Now search the process &lt;span style="FONT-WEIGHT: bold; COLOR: rgb(255,0,0)"&gt;vav.exe&lt;/span&gt;. Kill process vav.exe by right clicking on it and selecting end process.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wOu39jLJGgA/SHj-7nGO2sI/AAAAAAAAAYM/90YBkDseYqM/s1600-h/end+process.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5222204067996949186" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_wOu39jLJGgA/SHj-7nGO2sI/AAAAAAAAAYM/90YBkDseYqM/s400/end+process.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;2.&lt;/span&gt; Now go to C:\windows\system32 folder(assuming that you have windows in your C drive).&lt;br /&gt;Locate and delete file &lt;span style="FONT-WEIGHT: bold; COLOR: rgb(255,0,0)"&gt;vav.cpl&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;3.&lt;/span&gt; Now go to C:\program files&lt;br /&gt;Locate a folder named &lt;span style="FONT-WEIGHT: bold; COLOR: rgb(255,0,0)"&gt;vav&lt;/span&gt;. It will be having four files(vav0.dat, vav1.dat, vav.cpl, vav.exe) in most cases. Delete the entire folder&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;4.&lt;/span&gt; Vista Antivirus 2008 also makes a shortcut on your desktop. Delete that also&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;5.&lt;/span&gt; Empty recycle bin&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="COLOR: rgb(255,0,0)"&gt;Now we will be doing some registry editing which is to be done very carefully. If not done with care it can lead to system instability&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;6.&lt;/span&gt; Go to start-&gt;run-&gt;type 'regedit' and press enter&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;7.&lt;/span&gt; Now navigate to the following key and del the string named antivirus as shown in the picture.&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="FONT-STYLE: italic"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SHj-XDHNSKI/AAAAAAAAAYE/vIuL4j74Sz0/s1600-h/regedit1.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5222203439862073506" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SHj-XDHNSKI/AAAAAAAAAYE/vIuL4j74Sz0/s400/regedit1.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;8.&lt;/span&gt; Now navigate to the following key and del the key as shown in the picture.&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="FONT-STYLE: italic"&gt;HKEY_CURRENT_USER\Software\VAV&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SHj-TPkiREI/AAAAAAAAAX8/o9sSwylrWPo/s1600-h/regedit2.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5222203374486832194" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SHj-TPkiREI/AAAAAAAAAX8/o9sSwylrWPo/s400/regedit2.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;9.&lt;/span&gt; Now navigate to the following key and del the string named antivirus as shown in the picture.&lt;br /&gt;&lt;span style="FONT-STYLE: italic;font-size:78%;" &gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SHj-OikD0TI/AAAAAAAAAX0/vVCUKpMsjkE/s1600-h/regedit3.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5222203293685764402" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SHj-OikD0TI/AAAAAAAAAX0/vVCUKpMsjkE/s400/regedit3.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;10&lt;/span&gt; Now if your themes, appearance and settings are missing you can download small tool from &lt;span style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;&lt;a href="http://xp-solutions.blogspot.com/"&gt;here&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold; COLOR: rgb(51,51,255)"&gt;Now your system is clean from this Scam Antivirus.&lt;/span&gt;&lt;br /&gt;If you have any queries post it in the &lt;u&gt;comments section&lt;/u&gt; or click the &lt;u&gt;contact me pic&lt;/u&gt; above&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-1041150215196252740?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/1041150215196252740/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=1041150215196252740&amp;isPopup=true' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/1041150215196252740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/1041150215196252740'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/07/remove-vista-antivirus-2008.html' title='Remove Vista Antivirus 2008'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wOu39jLJGgA/SHj8ciV4vNI/AAAAAAAAAXc/9rkPqRY1F5A/s72-c/rogueantivirus.JPG' height='72' width='72'/><thr:total>12</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-5054712925693613213</id><published>2008-07-08T12:16:00.000-07:00</published><updated>2008-07-13T09:05:07.664-07:00</updated><title type='text'>Remove IE Antivirus Spyware</title><content type='html'>&lt;div style="TEXT-ALIGN: justify"&gt;This is one of the common spywares infecting systems around the world. When people reach these websites, they are made to believe that there systems are full of viruses, trojans &amp;amp; spywares and therefore they need to delete these viruses. Reading this people download and install the fake SPYWARE antivirus program and are thus infected with this spyware.&lt;br /&gt;&lt;u&gt;Remember its a SCAM and the spyware will ask you to buy the software online and take you to a website&lt;/u&gt; (Like this one)&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SHO9ulg1iWI/AAAAAAAAAWU/CUsiPb1tuKA/s1600-h/purchase.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5220725001094007138" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SHO9ulg1iWI/AAAAAAAAAWU/CUsiPb1tuKA/s320/purchase.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="COLOR: rgb(255,0,0);font-size:130%;" &gt;&lt;span style="FONT-WEIGHT: bold"&gt;Am I Infected&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;If a window like this troubles you each time you start windows and while you are working, with title IE Antivirus, then you are infected with this spyware and need to remove it as soon as possible.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SHO-H1-1pEI/AAAAAAAAAWc/7FQyI5_OOD8/s1600-h/the+spyware.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5220725435011540034" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SHO-H1-1pEI/AAAAAAAAAWc/7FQyI5_OOD8/s320/the+spyware.JPG" border="0" /&gt;&lt;/a&gt;&lt;span style="COLOR: rgb(255,0,0);font-size:130%;" &gt;&lt;span style="FONT-WEIGHT: bold"&gt;Removal Steps&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Follow the following steps to remove it&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;1&lt;/span&gt;. Open windows task manager(Ctrl+Alt+Del). Go to Processes Tab. Find the image name &lt;span style="FONT-WEIGHT: bold"&gt;antivir.exe&lt;/span&gt; and highlight it. Next kill the process by clicking end process. Click yes on task manager warning.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="TEXT-ALIGN: justify"&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;2.&lt;/span&gt; Next go to control panel and Open Add remove programs. Find &lt;span style="FONT-WEIGHT: bold"&gt;IE Antivirus&lt;/span&gt; and remove it. It will say the program looks to be already uninstalled &lt;span style="FONT-STYLE: italic"&gt;but its not so&lt;/span&gt;.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SHO_GkSdUpI/AAAAAAAAAWs/xrpx9hyknBA/s1600-h/addremove.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5220726512593752722" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SHO_GkSdUpI/AAAAAAAAAWs/xrpx9hyknBA/s400/addremove.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;3.&lt;/span&gt; Now go to C:\Program Files(assuming that you have windows in C drive) and delete the folder named IEAntiVirus.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SHO_WZSGcnI/AAAAAAAAAW0/KoE7dFKWPvM/s1600-h/programfiles.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5220726784517370482" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SHO_WZSGcnI/AAAAAAAAAW0/KoE7dFKWPvM/s400/programfiles.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You have deleted the spyware except that its to be removed from registry.&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;(Registry editing is dangerous and improper editing could lead to system crash)&lt;/span&gt; &lt;span style="FONT-WEIGHT: bold"&gt;Please follow the following instructions very carefully otherwise can lead to system instability.&lt;/span&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;4.&lt;/span&gt; Go start menu-&gt; Run-&gt; type 'regedit' without commas-&gt; press enter&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;5.&lt;/span&gt;Now in the left menu go to the following key&lt;br /&gt;&lt;span style="COLOR: rgb(255,0,0);font-size:85%;" &gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;br /&gt;On the right side spot antispy and delete it&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SHO_wXDh1_I/AAAAAAAAAW8/c-tvM6ltkdc/s1600-h/registry.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5220727230595979250" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SHO_wXDh1_I/AAAAAAAAAW8/c-tvM6ltkdc/s400/registry.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;6.&lt;/span&gt; Now go to&lt;br /&gt;&lt;span style="COLOR: rgb(255,0,0);font-size:85%;" &gt;HKEY_CURRENT_USER\Software\IEAntiVirus&lt;/span&gt;&lt;br /&gt;And delete the key 'IEAntivirus' by right clicking on it and selecting delete.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You have cleaned the Spyware from your system. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-5054712925693613213?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/5054712925693613213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=5054712925693613213&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/5054712925693613213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/5054712925693613213'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/07/remove-ie-antivirus-spyware.html' title='Remove IE Antivirus Spyware'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wOu39jLJGgA/SHO9ulg1iWI/AAAAAAAAAWU/CUsiPb1tuKA/s72-c/purchase.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-837647241433027848</id><published>2008-06-20T00:34:00.000-07:00</published><updated>2008-07-13T09:05:31.904-07:00</updated><title type='text'>Remove Kavo.exe</title><content type='html'>Well kavo.exe is a worm very similar to amvo.exe but very cumbersome to remove. Well here I will explain how to remove it manually &amp;amp; completely.&lt;br /&gt;&lt;br /&gt;If your drves on double click are opening in new folder &amp;amp; you are not bing able to view your hidden folders &amp;amp; files (even after selecting show hidden flies from tools-&gt;folder options...), then &lt;span style="color: rgb(255, 0, 0);"&gt;you may be infected with this virus&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Well to be sure that you are infected with this virus do the following steps&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1.&lt;/span&gt; click on start menu &lt;span style="font-weight: bold;"&gt;2.&lt;/span&gt; click on RUN &lt;span style="font-weight: bold;"&gt;3.&lt;/span&gt; type in there 'msconfig' without commas &lt;span style="font-weight: bold;"&gt;4.&lt;/span&gt; go to the last tab named 'startup' &lt;span style="font-weight: bold;"&gt;5.&lt;/span&gt; under the 'startup item' check if there is any item named 'KAVA'. Well if its there you got this virus.&lt;br /&gt;&lt;br /&gt;The virus usually spreads through external drives like flash drives, pen drives etc.&lt;br /&gt;It copies itself to all the drives on being run thus ensuring that the virus is activated as every time any drive is opened.&lt;br /&gt;&lt;br /&gt;First of all as the virus hides the hidden files you need a software RRT to unhide them. To download the software &lt;a href="http://download.sergiwa.com/security/RRT.exe"&gt;click here&lt;/a&gt;.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Follow these easy steps to remove the virus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1.&lt;/span&gt; Open all the drives in new window (Just like here)&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wOu39jLJGgA/SFtfrQSJ0KI/AAAAAAAAAV0/mh3SdFOffiI/s1600-h/folderopen.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_wOu39jLJGgA/SFtfrQSJ0KI/AAAAAAAAAV0/mh3SdFOffiI/s320/folderopen.JPG" alt="" id="BLOGGER_PHOTO_ID_5213866190321602722" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.&lt;/span&gt; In an another window go to C:\windows\system32 folder (if your windows is in drive other than C use another drive letter)&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3.&lt;/span&gt; Open registry editor by going to&lt;span style="font-size:85%;"&gt; start-&gt;run-&gt;regedit&lt;/span&gt; (&lt;span style="color: rgb(255, 0, 0);"&gt;Registry editing could be dangerous if not done properly so be careful&lt;/span&gt;)&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;4.&lt;/span&gt; Now run the RRT utility and click on auto remove. Dont close the utility.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;5.&lt;/span&gt; The utility helps in keeping hidden files unhidden but the virus keeps hiding the system files every few seconds. So you will have to perform this function every few seconds&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Find the Tools option at the top of the window -&gt; folder optiond -&gt;view tab -&gt; untick hide protected operating system(recommended) -&gt; click yes on the warning and click apply&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SFtgkQ1TofI/AAAAAAAAAV8/ktjloVanFTo/s1600-h/warning.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SFtgkQ1TofI/AAAAAAAAAV8/ktjloVanFTo/s320/warning.JPG" alt="" id="BLOGGER_PHOTO_ID_5213867169721590258" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;6.&lt;/span&gt; Now in the C:\windows\system32 folder trace these files and try deleting them using shift + Delete (You may have to redo 5th step to unhide them)&lt;br /&gt; kavo.exe&lt;br /&gt; kavo0.dll&lt;br /&gt; kavo1.dll&lt;br /&gt; kavo2.dll&lt;br /&gt; kavo3.dll&lt;br /&gt;You may be able to delete all of them except one. Dont worry we will treat with it later.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;7.&lt;/span&gt; As I have told you earlier that virus copies it self to all the drives we need to proceed to the drives now. You will have to repeat step 5 on each drive atleast once. Its assumed that you have all the drives already opened in new different windows.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;8.&lt;/span&gt; The virus makes a common file with an extension of &lt;span style="font-style: italic;"&gt;.bat&lt;/span&gt;(example 1.bat) in each drive. Find out the common .bat file in each folder and delete them along with the &lt;span style="font-style: italic;"&gt;autorun.inf&lt;/span&gt; file. To enable exensions do the following&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Find the Tools option at the top of the window -&gt; folder optiond -&gt;view tab -&gt; untick hide extensions for known file types -&gt; click apply&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;9.&lt;/span&gt; Well now we need to do some registry editing to open registry editor go to&lt;br /&gt;&lt;span style="font-size:85%;"&gt;start-&gt; run-&gt; type regedit &amp;amp; enter&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;10.&lt;/span&gt; Go the following key &amp;amp; delete value named &lt;span style="font-style: italic;"&gt;'kava'&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:85%;" &gt;&lt;span style="font-style: italic;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Now search thw whole of registry with the name '&lt;span style="font-style: italic;"&gt;kava'&lt;/span&gt; and delete all instances where you find it in use with word '&lt;span style="font-style: italic;"&gt;kavo&lt;/span&gt;'(Use ctrl + F to search &amp;amp; F3 to find next).&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;11.&lt;/span&gt; Now you are almost done. Just log off and log in again into windows (&lt;span style="font-size:85%;"&gt;start-&gt;log off&lt;/span&gt;) and delete the file from the sixth step which you couldn't. You should be able to do it now.&lt;br /&gt;&lt;br /&gt;Well now you are free from the Kavo.exe virus.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-837647241433027848?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/837647241433027848/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=837647241433027848&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/837647241433027848'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/837647241433027848'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/06/remove-kavoexe.html' title='Remove Kavo.exe'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wOu39jLJGgA/SFtfrQSJ0KI/AAAAAAAAAV0/mh3SdFOffiI/s72-c/folderopen.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-2051487582287945273</id><published>2008-06-13T06:26:00.000-07:00</published><updated>2008-07-13T09:05:59.806-07:00</updated><title type='text'>Remove Sandeep Verma virus i.e. snake.exe.vbs</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_wOu39jLJGgA/SFKtj5hZ9LI/AAAAAAAAAVs/s-MfT-rihK0/s1600-h/untitled.JPG"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://1.bp.blogspot.com/_wOu39jLJGgA/SFKtj5hZ9LI/AAAAAAAAAVs/s-MfT-rihK0/s320/untitled.JPG" alt="" id="BLOGGER_PHOTO_ID_5211418551069045938" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The virus also known as snake.exe.vbs is in form a vbs script which copies itself in the system32 folder and adds itself to the startup items so that it starts as soon as windows boots. The most common feature of this virus is that it sets the homepage of your internet explorer to http://sandeep-verma.blogspot.com&lt;br /&gt;&lt;br /&gt;The virus creates the following files in system32 folder&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;snake.exe.vbs&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;To remove the virus you need to first of all kill the following process&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;wscript.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Next delete the virus i.e. the following files from the removable media if the virus came from there.&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;snake.exe.vbs&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;autorun.inf&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Next go to C:\WINDOWS\system32 folder and find the following file and delete it&lt;br /&gt;snake.exe.vbs&lt;br /&gt;(It may be hidden. You may need &lt;a href="http://download.sergiwa.com/security/RRT.exe"&gt;RRT a free tool&lt;/a&gt; to show hidden files)&lt;br /&gt;&lt;br /&gt;Now you need to do some editing with the registry.&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;(Be careful before you edit registry. Improper edition could lead to system crash)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Go to the following key&lt;br /&gt;&lt;span style="font-size:78%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\&lt;br /&gt;{0d0717e0-2102-11dd-b5a9-00c026a310b1}\Shell\AutoRun\command&lt;/span&gt;&lt;br /&gt;On the right hand side there will be value of &lt;span style="font-style: italic;"&gt;default&lt;/span&gt; with data of &lt;span style="color: rgb(255, 0, 0);"&gt;wscript.exe snake.exe.vbs&lt;/span&gt;&lt;br /&gt;Click on default and delete the value data and click ok.&lt;br /&gt;&lt;br /&gt;Repeat the above procedure for the following key also&lt;br /&gt;&lt;span style="font-size:78%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\&lt;br /&gt;{0d0717e0-2102-11dd-b5a9-00c026a310b1}\Shell\open\Command&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Now go to&lt;br /&gt;&lt;span style="font-size:78%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&lt;/span&gt;&lt;br /&gt;And find the value &lt;span style="font-weight: bold; font-style: italic;"&gt;userinit&lt;/span&gt; with data value &lt;span style="color: rgb(255, 0, 0);font-size:85%;" &gt;C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wscript.exe C:\WINDOWS\system32\snake.exe.vbs&lt;/span&gt;&lt;br /&gt;Change it to &lt;span style="color: rgb(51, 102, 255);font-size:85%;" &gt;C:\WINDOWS\system32\userinit.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now to correct the internet explorer settings go to&lt;br /&gt;&lt;span style="font-size:78%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main&lt;/span&gt;&lt;br /&gt;Find the Value &lt;span style="font-style: italic; font-weight: bold;"&gt;Start Page&lt;/span&gt;. It will be having data as&lt;span style="color: rgb(255, 0, 0);"&gt; http://sandeep-verma.blogspot.com/&lt;/span&gt;&lt;br /&gt;Change the data value to &lt;span style="font-weight: bold; font-style: italic;"&gt;about:blank&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Next below it you will find a value named &lt;span style="font-weight: bold; font-style: italic;"&gt;Window Title &lt;/span&gt;with data as &lt;span style="color: rgb(255, 0, 0);"&gt;Sandeep Verma&lt;/span&gt;&lt;br /&gt;Click the Name and delete the data.&lt;br /&gt;&lt;br /&gt;Congrats! Now you are free from Sandeep Verma Virus&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-2051487582287945273?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/2051487582287945273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=2051487582287945273&amp;isPopup=true' title='16 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/2051487582287945273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/2051487582287945273'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/06/remove-sandeep-verma-virus-ie.html' title='Remove Sandeep Verma virus i.e. snake.exe.vbs'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wOu39jLJGgA/SFKtj5hZ9LI/AAAAAAAAAVs/s-MfT-rihK0/s72-c/untitled.JPG' height='72' width='72'/><thr:total>16</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-848283917143260936</id><published>2008-06-12T09:07:00.000-07:00</published><updated>2008-07-13T09:06:21.428-07:00</updated><title type='text'>Remove Kinza.exe</title><content type='html'>The following files are created in the system32 folder&lt;br /&gt;kinza.exe&lt;br /&gt;fiber.exe&lt;br /&gt;boot.vbs&lt;br /&gt;actmon.ini&lt;br /&gt;The following variation may also be there&lt;br /&gt;imapde.dll&lt;br /&gt;imapdc.vxd&lt;br /&gt;imapd.exe&lt;br /&gt;imapdb.dll&lt;br /&gt;imapdb.exe&lt;br /&gt;imapdc.dll&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wOu39jLJGgA/SFFN028zWvI/AAAAAAAAAUw/dWqnyfSXFrU/s1600-h/kinza.exe.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://2.bp.blogspot.com/_wOu39jLJGgA/SFFN028zWvI/AAAAAAAAAUw/dWqnyfSXFrU/s320/kinza.exe.jpg" alt="" id="BLOGGER_PHOTO_ID_5211031814343449330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;imapdd.dll&lt;br /&gt;imapde.dll&lt;br /&gt;rbwinx1.dll&lt;br /&gt;&lt;br /&gt;Kill the following processes with your username from task manager&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;    wscript.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;    cmd.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;    netsh.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;First of all the taskmanager, registry editor &amp;amp; folder options may be disabled&lt;br /&gt;To enable it use the free tool RRT &lt;a href="http://download.sergiwa.com/security/RRT.exe"&gt;(To Download click here)&lt;/a&gt;&lt;br /&gt;On How to use it click here&lt;br /&gt;&lt;br /&gt;Change the following registry values&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;(Be careful before you edit registry. Improper editing could lead to system crash)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-style: italic;"&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;On the Right Side find the entry named &lt;span style="font-weight: bold;"&gt;Userinit&lt;/span&gt;&lt;br /&gt;It will have data as&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);font-size:78%;" &gt;C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wscript.exe C:\WINDOWS\system32\boot.vbs   &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Change it to&lt;br /&gt;&lt;span style="color: rgb(51, 102, 255);"&gt;C:\WINDOWS\system32\userinit.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now delete the following files located at C:\windows\system32\&lt;br /&gt;kinza.exe&lt;br /&gt;fiber.exe&lt;br /&gt;actmon.ini&lt;br /&gt;imapde.dll&lt;br /&gt;imapdc.vxd&lt;br /&gt;imapd.exe&lt;br /&gt;imapdb.dll&lt;br /&gt;imapdb.exe&lt;br /&gt;imapdc.dll&lt;br /&gt;imapdd.dll&lt;br /&gt;imapde.dll&lt;br /&gt;rbwinx1.dll&lt;br /&gt;&lt;br /&gt;The virus disables windows firewall which you have to activate by going to control panel, clicking on security center, and then on windows firewall. It will say that the service has been stopped, do you want to start it. Click yes to start the firewall again.&lt;br /&gt;&lt;br /&gt;Delete the following registry values to complete the removal of unnecessary registry keys&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-style: italic;font-size:78%;" &gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shellnoroam\MUICache&lt;/span&gt;&lt;br /&gt;On the right side locate and delete value&lt;span style="color: rgb(255, 0, 0);"&gt; c:\windows\system32\fiber.exe&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-848283917143260936?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/848283917143260936/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=848283917143260936&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/848283917143260936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/848283917143260936'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/06/remove-kinzaexe.html' title='Remove Kinza.exe'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_wOu39jLJGgA/SFFN028zWvI/AAAAAAAAAUw/dWqnyfSXFrU/s72-c/kinza.exe.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6158434637838820059.post-6439113468485969543</id><published>2008-06-10T10:33:00.000-07:00</published><updated>2008-06-13T10:43:28.412-07:00</updated><title type='text'>Contact me</title><content type='html'>Please feel free to contact me at my email muditgoyal1131@yahoo.co.in&lt;br /&gt;Also you can post in the comments section.&lt;br /&gt;I will try my best to solve your virus related problems asap.&lt;br /&gt;&lt;br /&gt;Also &lt;span style="font-weight: bold;"&gt;if you want me to personally remove virus from your pc&lt;/span&gt;, I would be available for minimal charges. Just shoot me a mail and we can set up time which is suitable to both of us.&lt;span style="font-weight: bold; font-style: italic;"&gt; I would be cleaning the virus by remote controlling  your pc using a specialized software in which you would also have a full control over your pc.&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;As for now&lt;br /&gt;Happy Virus Hacking&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6158434637838820059-6439113468485969543?l=wehackvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://wehackvirus.blogspot.com/feeds/6439113468485969543/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6158434637838820059&amp;postID=6439113468485969543&amp;isPopup=true' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/6439113468485969543'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6158434637838820059/posts/default/6439113468485969543'/><link rel='alternate' type='text/html' href='http://wehackvirus.blogspot.com/2008/06/contact-me.html' title='Contact me'/><author><name>THE ONE</name><uri>http://www.blogger.com/profile/11718951900946231341</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>13</thr:total></entry></feed>
