<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Malware Analysis and Removal</title>
	<atom:link href="http://greatis.com/blog/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://greatis.com/blog</link>
	<description>Malware Analysis and Removal</description>
	<lastBuildDate>Sat, 04 Feb 2012 19:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
	<item>
		<title>Comment on Removed: REGSRV.EXE, STDRT.EXE by bill</title>
		<link>http://greatis.com/blog/how-to-remove-malware/removed-regsrv-exe-stdrt-exe.htm/comment-page-1#comment-1285</link>
		<dc:creator>bill</dc:creator>
		<pubDate>Sat, 04 Feb 2012 19:16:49 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=1279#comment-1285</guid>
		<description>THIS SOLUTION DOES NOT WORK ON WINDOWS 7 x64</description>
		<content:encoded><![CDATA[<p>THIS SOLUTION DOES NOT WORK ON WINDOWS 7 x64</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1141</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Mon, 23 Jan 2012 11:45:09 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1141</guid>
		<description>http://greatis.com/blog/how-to-remove-malware/mvscavap-exe.htm</description>
		<content:encoded><![CDATA[<p><a href="http://greatis.com/blog/how-to-remove-malware/mvscavap-exe.htm" rel="nofollow">http://greatis.com/blog/how-to-remove-malware/mvscavap-exe.htm</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1129</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Sun, 22 Jan 2012 13:07:35 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1129</guid>
		<description>The easiest way to remove these trojans:)
http://youtu.be/sDU4_Jgydbs</description>
		<content:encoded><![CDATA[<p>The easiest way to remove these trojans:)<br />
<a href="http://youtu.be/sDU4_Jgydbs" rel="nofollow">http://youtu.be/sDU4_Jgydbs</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Blake</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1106</link>
		<dc:creator>Blake</dc:creator>
		<pubDate>Fri, 20 Jan 2012 17:17:33 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1106</guid>
		<description>just to clear things up at the beginning of my last post you only type in &quot;%temp%&quot; then you simply navigate in the window. &quot;Organize&quot; being found in the top left corner</description>
		<content:encoded><![CDATA[<p>just to clear things up at the beginning of my last post you only type in &#8220;%temp%&#8221; then you simply navigate in the window. &#8220;Organize&#8221; being found in the top left corner</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Blake</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1105</link>
		<dc:creator>Blake</dc:creator>
		<pubDate>Fri, 20 Jan 2012 17:15:54 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1105</guid>
		<description>i just got this figured out thanks for the great help guys!:D
anyone still struggling type in 
-&gt; %temp% -&gt; &quot;Organize&quot; -&gt; &quot;Folder and Search Options&quot; -&gt; &quot;View&quot; (Middle Tab)

from there you are going to change two thing... 
1). under the folder &quot;Hidden files and folders&quot; simply change the bubble from &quot;Don&#039;t show hidden files, folders, or drives&quot; to &quot;Show hidden files, folders, and drives&quot;

2).under the same folder there will be about 11 boxes, some being checked some unchecked. It should be the 3rd box from the top of that list of 11. its called &quot;Hide protected operating system files(Recommended)&quot; Un-check that box. it will give you a warning message, just hit yes. 

After doing the following click &quot;Apply&quot; -&gt; then &quot;Ok&quot;

you should be back in the temp folder. now look for the folder titled &quot;System&quot; 
(if you cannot locate system simply go to the navigation bar at the top of the window and re-click on temp to refresh it)

go into system and you will see siaport. Delete that bastard!

Any questions feel free to ask! Email me at dadiggin@live.com i will answer on that faster than this!</description>
		<content:encoded><![CDATA[<p>i just got this figured out thanks for the great help guys!:D<br />
anyone still struggling type in<br />
-&gt; %temp% -&gt; &#8220;Organize&#8221; -&gt; &#8220;Folder and Search Options&#8221; -&gt; &#8220;View&#8221; (Middle Tab)</p>
<p>from there you are going to change two thing&#8230;<br />
1). under the folder &#8220;Hidden files and folders&#8221; simply change the bubble from &#8220;Don&#8217;t show hidden files, folders, or drives&#8221; to &#8220;Show hidden files, folders, and drives&#8221;</p>
<p>2).under the same folder there will be about 11 boxes, some being checked some unchecked. It should be the 3rd box from the top of that list of 11. its called &#8220;Hide protected operating system files(Recommended)&#8221; Un-check that box. it will give you a warning message, just hit yes. </p>
<p>After doing the following click &#8220;Apply&#8221; -&gt; then &#8220;Ok&#8221;</p>
<p>you should be back in the temp folder. now look for the folder titled &#8220;System&#8221;<br />
(if you cannot locate system simply go to the navigation bar at the top of the window and re-click on temp to refresh it)</p>
<p>go into system and you will see siaport. Delete that bastard!</p>
<p>Any questions feel free to ask! Email me at <a href="mailto:dadiggin@live.com">dadiggin@live.com</a> i will answer on that faster than this!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Cannot find SiaPort.exe</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1103</link>
		<dc:creator>Cannot find SiaPort.exe</dc:creator>
		<pubDate>Fri, 20 Jan 2012 15:58:59 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1103</guid>
		<description>I found the system folder but I CANT FIND THE SiaPort.exe. If i organise it and pressing &quot;Hide all folders,files&quot;  It wont show. Plz Help me.............</description>
		<content:encoded><![CDATA[<p>I found the system folder but I CANT FIND THE SiaPort.exe. If i organise it and pressing &#8220;Hide all folders,files&#8221;  It wont show. Plz Help me&#8230;&#8230;&#8230;&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Hazza</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1100</link>
		<dc:creator>Hazza</dc:creator>
		<pubDate>Fri, 20 Jan 2012 08:49:58 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1100</guid>
		<description>never mind, found it... 

PEOPLE WHO CANT FIND THE &quot;SYSTEM&quot; FOLDER

When you go to the organise thing, there should be a little circle filled with blue with text next to it saying &quot;Hide all Folders, files etc.&quot; Click the one below it that says&quot;Show&quot; as well as the boxes below. Might help... :P</description>
		<content:encoded><![CDATA[<p>never mind, found it&#8230; </p>
<p>PEOPLE WHO CANT FIND THE &#8220;SYSTEM&#8221; FOLDER</p>
<p>When you go to the organise thing, there should be a little circle filled with blue with text next to it saying &#8220;Hide all Folders, files etc.&#8221; Click the one below it that says&#8221;Show&#8221; as well as the boxes below. Might help&#8230; <img src='http://greatis.com/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Hazza</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1099</link>
		<dc:creator>Hazza</dc:creator>
		<pubDate>Fri, 20 Jan 2012 08:42:43 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1099</guid>
		<description>I tried the &quot;Unhide Folders&quot; thing and i still cant find the System Folder, I think the Trojan might have let in a virus... HELP!!!</description>
		<content:encoded><![CDATA[<p>I tried the &#8220;Unhide Folders&#8221; thing and i still cant find the System Folder, I think the Trojan might have let in a virus&#8230; HELP!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Milo</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1091</link>
		<dc:creator>Milo</dc:creator>
		<pubDate>Thu, 19 Jan 2012 10:54:25 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1091</guid>
		<description>For those of us who dosn&#039;t know how to fix this: press windows button (Windows 7 here) and type in &quot;%TEMP%\SYSTEM\&quot; then there should be no files, click on organize (top left corner) then press Folder and search options from the drop down menu. Choose View and then you must uncheck the box that says &quot;Hide operating system files&quot; even though it&#039;s recommended not to. Then delete siaport.exe (click it once and press delete) then yes and it&#039;s outta the world :)</description>
		<content:encoded><![CDATA[<p>For those of us who dosn&#8217;t know how to fix this: press windows button (Windows 7 here) and type in &#8220;%TEMP%\SYSTEM\&#8221; then there should be no files, click on organize (top left corner) then press Folder and search options from the drop down menu. Choose View and then you must uncheck the box that says &#8220;Hide operating system files&#8221; even though it&#8217;s recommended not to. Then delete siaport.exe (click it once and press delete) then yes and it&#8217;s outta the world <img src='http://greatis.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Rostov</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1017</link>
		<dc:creator>Rostov</dc:creator>
		<pubDate>Sun, 15 Jan 2012 13:26:17 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1017</guid>
		<description>Can&#039;t find the System subfolder after the Temp subfolder.  I get into the Temp folder and there are hundreds of my other folders but no System folder.  Siaport.exe says it&#039;s in the System but I can see it, even with all hidden files made to appear.</description>
		<content:encoded><![CDATA[<p>Can&#8217;t find the System subfolder after the Temp subfolder.  I get into the Temp folder and there are hundreds of my other folders but no System folder.  Siaport.exe says it&#8217;s in the System but I can see it, even with all hidden files made to appear.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Johnny D</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-991</link>
		<dc:creator>Johnny D</dc:creator>
		<pubDate>Sat, 14 Jan 2012 05:39:48 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-991</guid>
		<description>This is simple. 

For Windows 7, Go to the directory of the file... AppData\Local\Temp\System
If you don&#039;t see any files it means they&#039;re hidden, so what you&#039;ll need to do is
simply unhide them. Near the Top Left, click on (Organize). A drop down menu
should appear. Now go to (Folder and search options). A window will appear. At the top you&#039;ll see 3 tabs/pages. Click on (View). Now, in the list, you want to look for (Hide protected operating system files Recommended). Now uncheck that. A warning may pop up but that&#039;s ok. Click (Yes). Now click (Apply) then (OK).
If you did all that correctly you should see 2 files.... Delete them and you&#039;re Done! :)  
Now you might want to go back and make sure you Hide the system files. Just Check the box for (Hide protected operating system files Recommended) then click Apply and OK! Easy!</description>
		<content:encoded><![CDATA[<p>This is simple. </p>
<p>For Windows 7, Go to the directory of the file&#8230; AppData\Local\Temp\System<br />
If you don&#8217;t see any files it means they&#8217;re hidden, so what you&#8217;ll need to do is<br />
simply unhide them. Near the Top Left, click on (Organize). A drop down menu<br />
should appear. Now go to (Folder and search options). A window will appear. At the top you&#8217;ll see 3 tabs/pages. Click on (View). Now, in the list, you want to look for (Hide protected operating system files Recommended). Now uncheck that. A warning may pop up but that&#8217;s ok. Click (Yes). Now click (Apply) then (OK).<br />
If you did all that correctly you should see 2 files&#8230;. Delete them and you&#8217;re Done! <img src='http://greatis.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Now you might want to go back and make sure you Hide the system files. Just Check the box for (Hide protected operating system files Recommended) then click Apply and OK! Easy!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on REGSRV64.EXE is trojan Offend by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/regsrv64-exe.htm/comment-page-1#comment-957</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Thu, 12 Jan 2012 03:17:06 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8342#comment-957</guid>
		<description>Please visit our support center:
http://greatis.com/support
Attach your regrunlog.txt and we will help you.</description>
		<content:encoded><![CDATA[<p>Please visit our support center:<br />
<a href="http://greatis.com/support" rel="nofollow">http://greatis.com/support</a><br />
Attach your regrunlog.txt and we will help you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on REGSRV64.EXE is trojan Offend by Ket</title>
		<link>http://greatis.com/blog/how-to-remove-malware/regsrv64-exe.htm/comment-page-1#comment-950</link>
		<dc:creator>Ket</dc:creator>
		<pubDate>Wed, 11 Jan 2012 15:11:43 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8342#comment-950</guid>
		<description>I cannot remove the file. It always said this file has been used by another program even though I open only a folder to delete it. How can I delete it? Please help.</description>
		<content:encoded><![CDATA[<p>I cannot remove the file. It always said this file has been used by another program even though I open only a folder to delete it. How can I delete it? Please help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Removed: C:\WINDOWS\system32\system\dll.exe (trojan VBInject) by Mark</title>
		<link>http://greatis.com/blog/how-to-remove-malware/dll-exe-trojan-vbinject.htm/comment-page-1#comment-934</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Tue, 10 Jan 2012 01:17:54 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=4296#comment-934</guid>
		<description>Before deleting suspect malware it is best to create a system restore point first in case the system crashes. I am new to removing malware and it appears it may be easier to block the IP addresses and close the ports. As you can imagine a hacker may not be very happy to find out that the RATs have been cutoff. The hacker will try everything to regain access. Once the user knows who is doing what it is a lot easier to manage the risk.  I have only found 1 software package that monitors the traffic. BeeHive is good stuff, and if you want to be a wise guy you can cause the hacker to have many sleepless nights as they watch the user watch the hacker. 

Maybe you software guys could creatre some fun software to better monitor the hackers activities.</description>
		<content:encoded><![CDATA[<p>Before deleting suspect malware it is best to create a system restore point first in case the system crashes. I am new to removing malware and it appears it may be easier to block the IP addresses and close the ports. As you can imagine a hacker may not be very happy to find out that the RATs have been cutoff. The hacker will try everything to regain access. Once the user knows who is doing what it is a lot easier to manage the risk.  I have only found 1 software package that monitors the traffic. BeeHive is good stuff, and if you want to be a wise guy you can cause the hacker to have many sleepless nights as they watch the user watch the hacker. </p>
<p>Maybe you software guys could creatre some fun software to better monitor the hackers activities.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Removed: pb.dll, forinout.exe, LiveSS.exe, pb.sys (FakeAV &#8211; Live Security Suite) by Reena mathew</title>
		<link>http://greatis.com/blog/how-to-remove-malware/removed-pb-dll-forinout-exe-livess-exe-pb-sys-fakeav-live-security-suite.htm/comment-page-1#comment-928</link>
		<dc:creator>Reena mathew</dc:creator>
		<pubDate>Mon, 09 Jan 2012 08:17:58 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=3846#comment-928</guid>
		<description>I have searched so many weblogs for a solution, at last I got the complete fix from here, KUDOS to greatis.com technical team. You guys are really rocking!!! 

Thanks, please keep on posting on new spyware issues.</description>
		<content:encoded><![CDATA[<p>I have searched so many weblogs for a solution, at last I got the complete fix from here, KUDOS to greatis.com technical team. You guys are really rocking!!! </p>
<p>Thanks, please keep on posting on new spyware issues.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-892</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Thu, 05 Jan 2012 10:26:26 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-892</guid>
		<description>Please visit our support center:
http://greatis.com/support
Attach your regrunlog.txt and we will help you.</description>
		<content:encoded><![CDATA[<p>Please visit our support center:<br />
<a href="http://greatis.com/support" rel="nofollow">http://greatis.com/support</a><br />
Attach your regrunlog.txt and we will help you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by will</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-885</link>
		<dc:creator>will</dc:creator>
		<pubDate>Wed, 04 Jan 2012 22:09:13 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-885</guid>
		<description>same problem here... how to solve it???</description>
		<content:encoded><![CDATA[<p>same problem here&#8230; how to solve it???</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by sam</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-883</link>
		<dc:creator>sam</dc:creator>
		<pubDate>Wed, 04 Jan 2012 17:56:31 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-883</guid>
		<description>@cas i have the same problem. siaport.exe cant be stopped. it starts again and again.</description>
		<content:encoded><![CDATA[<p>@cas i have the same problem. siaport.exe cant be stopped. it starts again and again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by cas</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-879</link>
		<dc:creator>cas</dc:creator>
		<pubDate>Wed, 04 Jan 2012 09:37:30 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-879</guid>
		<description>im fucked i cant seem to find the file but the pop up keeps coming please help me. thanks</description>
		<content:encoded><![CDATA[<p>im fucked i cant seem to find the file but the pop up keeps coming please help me. thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on NavaShield.exe &#8211; Fake AntiVirus Nava Shield by joy mathew</title>
		<link>http://greatis.com/blog/how-to-remove-malware/fakeav/navashield-exe-fake-antivirus-nava-shield.htm/comment-page-1#comment-877</link>
		<dc:creator>joy mathew</dc:creator>
		<pubDate>Wed, 04 Jan 2012 07:47:08 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=5878#comment-877</guid>
		<description>Nava shield is a rougue antispyware, which will create unwanted pop ups and mis lead you to buy that application. 
Most of the antivirus like Avast, Norton, Mcafee arre able to remove its source file and at the same time they are failed to remove the unwanted registry entries created by the infection. Once its source file is removed by the antivirus, the registry entries started to disable all the executables (applications or softwares) installed on your computer. 

In this scenario, we have to remove the registry entries manually. </description>
		<content:encoded><![CDATA[<p>Nava shield is a rougue antispyware, which will create unwanted pop ups and mis lead you to buy that application.<br />
Most of the antivirus like Avast, Norton, Mcafee arre able to remove its source file and at the same time they are failed to remove the unwanted registry entries created by the infection. Once its source file is removed by the antivirus, the registry entries started to disable all the executables (applications or softwares) installed on your computer. </p>
<p>In this scenario, we have to remove the registry entries manually.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5016.SYS is rootkit Pakes by baba</title>
		<link>http://greatis.com/blog/rootkit/5016-sys.htm/comment-page-1#comment-863</link>
		<dc:creator>baba</dc:creator>
		<pubDate>Sun, 01 Jan 2012 23:30:40 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8235#comment-863</guid>
		<description>Thanks, I just found this on my Grandma&#039;s computer. She is 97 and in the hospital with a broken hip. You are code/internet heroes.</description>
		<content:encoded><![CDATA[<p>Thanks, I just found this on my Grandma&#8217;s computer. She is 97 and in the hospital with a broken hip. You are code/internet heroes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on CLIPVIEW.EXE is Adware Clipview by Baba</title>
		<link>http://greatis.com/blog/adware/clipview-exe.htm/comment-page-1#comment-862</link>
		<dc:creator>Baba</dc:creator>
		<pubDate>Sun, 01 Jan 2012 23:28:56 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/clipview-exe.htm#comment-862</guid>
		<description>Thanks, Nightwatcher(and unhackme team) your rootkit submission(from 11/16, rloader.1 5016.sys) was just found on my grandma&#039;s computer. She is 97 and in the hospital with a broken hip. Just letting you know that you are helping an old woman out(even though she hates being called that).</description>
		<content:encoded><![CDATA[<p>Thanks, Nightwatcher(and unhackme team) your rootkit submission(from 11/16, rloader.1 5016.sys) was just found on my grandma&#8217;s computer. She is 97 and in the hospital with a broken hip. Just letting you know that you are helping an old woman out(even though she hates being called that).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FACEBOOKUPDATE.EXE &#8211; not a virus by Felipe Drumond</title>
		<link>http://greatis.com/blog/not-a-virus/facebookupdate-exe.htm/comment-page-1#comment-754</link>
		<dc:creator>Felipe Drumond</dc:creator>
		<pubDate>Wed, 21 Dec 2011 09:21:13 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=7359#comment-754</guid>
		<description>It´s the Skype plug-in. It&#039;s safe.</description>
		<content:encoded><![CDATA[<p>It´s the Skype plug-in. It&#8217;s safe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MAHMUD.EXE is trojan LockScreen by loltheripper</title>
		<link>http://greatis.com/blog/locker/mahmud-exe.htm/comment-page-1#comment-582</link>
		<dc:creator>loltheripper</dc:creator>
		<pubDate>Mon, 05 Dec 2011 05:56:11 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8041#comment-582</guid>
		<description>U dont need a recovery cd or something u have to start your pc in the protected mod (i dont know if thats right im german)  than just delet the mahmud.exe in the roaming folder. And after that put ur cammand prompt on your help button in the login area (this is very help full if you get another trojan or lockscreen). You can find a how to on youtube.</description>
		<content:encoded><![CDATA[<p>U dont need a recovery cd or something u have to start your pc in the protected mod (i dont know if thats right im german)  than just delet the mahmud.exe in the roaming folder. And after that put ur cammand prompt on your help button in the login area (this is very help full if you get another trojan or lockscreen). You can find a how to on youtube.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WINWIRPL.DLL is trojan Sefnit by eric</title>
		<link>http://greatis.com/blog/how-to-remove-malware/winwirpl-dll.htm/comment-page-1#comment-484</link>
		<dc:creator>eric</dc:creator>
		<pubDate>Tue, 22 Nov 2011 08:56:54 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8264#comment-484</guid>
		<description>Hello, 

I didn&#039;t find the the registry key you pointed, but found this one:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Sidebar something

deleated it then managed to erease the file in:
%AppData%\DesktopMain32\winWIRpl.dll

Sacnned the temp folder and found jar_cache temp files also infected (might be the actuall intrusion) 

regards</description>
		<content:encoded><![CDATA[<p>Hello, </p>
<p>I didn&#8217;t find the the registry key you pointed, but found this one:<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Sidebar something</p>
<p>deleated it then managed to erease the file in:<br />
%AppData%\DesktopMain32\winWIRpl.dll</p>
<p>Sacnned the temp folder and found jar_cache temp files also infected (might be the actuall intrusion) </p>
<p>regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MAHMUD.EXE is trojan LockScreen by NightWatcher</title>
		<link>http://greatis.com/blog/locker/mahmud-exe.htm/comment-page-1#comment-462</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Fri, 18 Nov 2011 05:07:47 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8041#comment-462</guid>
		<description>Use RegRun Warrior CD.
How to make RegRun Warrior CD - http://www.youtube.com/watch?v=l-tuBVOsXns
How to remove mahmud.exe - http://www.youtube.com/watch?v=ueghm5uGHZM</description>
		<content:encoded><![CDATA[<p>Use RegRun Warrior CD.<br />
How to make RegRun Warrior CD &#8211; <a href="http://www.youtube.com/watch?v=l-tuBVOsXns" rel="nofollow">http://www.youtube.com/watch?v=l-tuBVOsXns</a><br />
How to remove mahmud.exe &#8211; <a href="http://www.youtube.com/watch?v=ueghm5uGHZM" rel="nofollow">http://www.youtube.com/watch?v=ueghm5uGHZM</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MAHMUD.EXE is trojan LockScreen by Rym</title>
		<link>http://greatis.com/blog/locker/mahmud-exe.htm/comment-page-1#comment-461</link>
		<dc:creator>Rym</dc:creator>
		<pubDate>Thu, 17 Nov 2011 18:47:13 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8041#comment-461</guid>
		<description>mahmud.exe; one nast F***** indeed!
One of my friends who is computer illiterate, recently found himself bugged with mahmud, at first shocked and in despair for the wild acusation the exe was claiming. So after taken a first look, not that i&#039;m a computer genius, but as I did manage to softmod and jailbreak my own gadgets, most my friends come to me for advice. Well now, I&#039;m trying hard to figure any possible methods to bypass this mahmud.exe to be started as it freezes up the screen making it impossible to go to any directory paths to shut down the program.
The situation: windows XP computer (I tempted to tell my friend to &quot;forget it mate, time for an upgrade anyway&quot; but the Macgyver in me wants this solved), 3 user accounts. A) password protected. B) infected account. C) Guest account.
Tried: 1) log into B and tried to shut down the program before it started...FAIL. 2) tried from guest account, which fully works aside from no start-menu visible. but no admin powers... fail. 3) safe mode, got into &#039;administrator&#039; account and WHAM there is mahmud. FAIL. 4) basically tried all other start up possibilities without success. At the moment I&#039;m trying to reel in a free program to hack lost passwords, so I can log into account A and hopefully which has more admin powers so I can get into account B&#039;s directory paths etc.
Now, IF there&#039;s anything easier I can try, please let me know!
any other info/suggestions are most welcome.</description>
		<content:encoded><![CDATA[<p>mahmud.exe; one nast F***** indeed!<br />
One of my friends who is computer illiterate, recently found himself bugged with mahmud, at first shocked and in despair for the wild acusation the exe was claiming. So after taken a first look, not that i&#8217;m a computer genius, but as I did manage to softmod and jailbreak my own gadgets, most my friends come to me for advice. Well now, I&#8217;m trying hard to figure any possible methods to bypass this mahmud.exe to be started as it freezes up the screen making it impossible to go to any directory paths to shut down the program.<br />
The situation: windows XP computer (I tempted to tell my friend to &#8220;forget it mate, time for an upgrade anyway&#8221; but the Macgyver in me wants this solved), 3 user accounts. A) password protected. B) infected account. C) Guest account.<br />
Tried: 1) log into B and tried to shut down the program before it started&#8230;FAIL. 2) tried from guest account, which fully works aside from no start-menu visible. but no admin powers&#8230; fail. 3) safe mode, got into &#8216;administrator&#8217; account and WHAM there is mahmud. FAIL. 4) basically tried all other start up possibilities without success. At the moment I&#8217;m trying to reel in a free program to hack lost passwords, so I can log into account A and hopefully which has more admin powers so I can get into account B&#8217;s directory paths etc.<br />
Now, IF there&#8217;s anything easier I can try, please let me know!<br />
any other info/suggestions are most welcome.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on I6G8XS.EXE is trojan Jorik by Crescencio Aragón</title>
		<link>http://greatis.com/blog/how-to-remove-malware/i6g8xs-exe.htm/comment-page-1#comment-449</link>
		<dc:creator>Crescencio Aragón</dc:creator>
		<pubDate>Tue, 15 Nov 2011 18:04:09 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8198#comment-449</guid>
		<description>the process is hard to eliminate because in the process task manager it is &quot;moving&quot;, i mean closing and opening that for appears in deferents place on the list and we can´t select... aniway this file es generated by other file because i stop the process in the msdossetup, i kill it booting from a safe disk, i remove with UNHackMe, and its still.. is not &quot;moving&quot; but i apreciate that is another file in the process with aleatory name but extension &quot;.tmp&quot; i found this at the ...windows\temp
really i found a lot of files that are opened in the task manager...  right now the next step is to format and reinstall all system on the PC</description>
		<content:encoded><![CDATA[<p>the process is hard to eliminate because in the process task manager it is &#8220;moving&#8221;, i mean closing and opening that for appears in deferents place on the list and we can´t select&#8230; aniway this file es generated by other file because i stop the process in the msdossetup, i kill it booting from a safe disk, i remove with UNHackMe, and its still.. is not &#8220;moving&#8221; but i apreciate that is another file in the process with aleatory name but extension &#8220;.tmp&#8221; i found this at the &#8230;windows\temp<br />
really i found a lot of files that are opened in the task manager&#8230;  right now the next step is to format and reinstall all system on the PC</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WKOCFFMPAI.EXE is Fake System Tools by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/fake-system-tool/wkocffmpai-exe.htm/comment-page-1#comment-401</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Fri, 28 Oct 2011 14:54:59 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8093#comment-401</guid>
		<description>How to make files and folders visible again?
Open Command Prompt and type in: &quot;attrib -h c:\*.* /s /d&quot; and press Enter.</description>
		<content:encoded><![CDATA[<p>How to make files and folders visible again?<br />
Open Command Prompt and type in: &#8220;attrib -h c:\*.* /s /d&#8221; and press Enter.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on X30811.EXE is trojan BitMiner by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/x30811-exe.htm/comment-page-1#comment-395</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Tue, 25 Oct 2011 03:47:50 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=7747#comment-395</guid>
		<description>Please visit our support center:
http://greatis.com/support
Attach your regrunlog.txt and we will help you.</description>
		<content:encoded><![CDATA[<p>Please visit our support center:<br />
<a href="http://greatis.com/support" rel="nofollow">http://greatis.com/support</a><br />
Attach your regrunlog.txt and we will help you.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

