<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Malware Analysis and Removal</title>
	<atom:link href="http://greatis.com/blog/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://greatis.com/blog</link>
	<description>Malware Analysis and Removal</description>
	<lastBuildDate>Thu, 17 May 2012 02:45:33 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
	<item>
		<title>Comment on IMDCSC.EXE is Trojan CDur by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/imdcsc-exe.htm/comment-page-1#comment-2453</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Thu, 17 May 2012 02:45:33 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/imdcsc-exe.htm#comment-2453</guid>
		<description>Please visit our support center:
http://greatis.com/support
Attach your regrunlog.txt and we will help you.</description>
		<content:encoded><![CDATA[<p>Please visit our support center:<br />
<a href="http://greatis.com/support" rel="nofollow">http://greatis.com/support</a><br />
Attach your regrunlog.txt and we will help you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on IMDCSC.EXE is Trojan CDur by Zach</title>
		<link>http://greatis.com/blog/how-to-remove-malware/imdcsc-exe.htm/comment-page-1#comment-2452</link>
		<dc:creator>Zach</dc:creator>
		<pubDate>Wed, 16 May 2012 20:46:04 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/imdcsc-exe.htm#comment-2452</guid>
		<description>I had it on my computer, and as soon as I saw this I deleted it with this program.</description>
		<content:encoded><![CDATA[<p>I had it on my computer, and as soon as I saw this I deleted it with this program.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FACEBOOKUPDATE.EXE &#8211; not a virus by Rob</title>
		<link>http://greatis.com/blog/not-a-virus/facebookupdate-exe.htm/comment-page-1#comment-2245</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Thu, 26 Apr 2012 01:00:34 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=7359#comment-2245</guid>
		<description>It might not be a virus, but it sure as hell wasn&#039;t something I chose to install. I don&#039;t even have skype on this machine. Bye Bye...</description>
		<content:encoded><![CDATA[<p>It might not be a virus, but it sure as hell wasn&#8217;t something I chose to install. I don&#8217;t even have skype on this machine. Bye Bye&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by THANKYOU</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-2213</link>
		<dc:creator>THANKYOU</dc:creator>
		<pubDate>Fri, 20 Apr 2012 22:18:18 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-2213</guid>
		<description>OMG thank you so much my i7 was so slow the past days and kept having a pop up saying to allow the idiotic SiaPort.exe but with your help I successfully deleted it!</description>
		<content:encoded><![CDATA[<p>OMG thank you so much my i7 was so slow the past days and kept having a pop up saying to allow the idiotic SiaPort.exe but with your help I successfully deleted it!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on NVVSVC.EXE is trojan Sisron by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/nvvsvc-exe.htm/comment-page-1#comment-2175</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Sun, 15 Apr 2012 04:41:31 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=7978#comment-2175</guid>
		<description>VT info:
https://www.virustotal.com/file/3b9cdc2767b975ef0539bcd331e401e0894b96ecb7c6d5a7f65ebe2ac46b2503/analysis/</description>
		<content:encoded><![CDATA[<p>VT info:<br />
<a href="https://www.virustotal.com/file/3b9cdc2767b975ef0539bcd331e401e0894b96ecb7c6d5a7f65ebe2ac46b2503/analysis/" rel="nofollow">https://www.virustotal.com/file/3b9cdc2767b975ef0539bcd331e401e0894b96ecb7c6d5a7f65ebe2ac46b2503/analysis/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on NVVSVC.EXE is trojan Sisron by John</title>
		<link>http://greatis.com/blog/how-to-remove-malware/nvvsvc-exe.htm/comment-page-1#comment-2174</link>
		<dc:creator>John</dc:creator>
		<pubDate>Sun, 15 Apr 2012 02:04:27 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=7978#comment-2174</guid>
		<description>NVVSVC is the NVidea graphics card, I am not so sure you would want to remove it ?</description>
		<content:encoded><![CDATA[<p>NVVSVC is the NVidea graphics card, I am not so sure you would want to remove it ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FACEBOOKUPDATE.EXE &#8211; not a virus by Sahimone</title>
		<link>http://greatis.com/blog/not-a-virus/facebookupdate-exe.htm/comment-page-1#comment-2155</link>
		<dc:creator>Sahimone</dc:creator>
		<pubDate>Tue, 10 Apr 2012 09:56:32 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=7359#comment-2155</guid>
		<description>Bozo, what do I have to delete to get ride of all those crapware ?

I&#039;lm really concern by the fact that FB is selling all our info. By the way the privacy terms in FB are getting crazy !

Hope you will help me.

Cheers; Sahimone</description>
		<content:encoded><![CDATA[<p>Bozo, what do I have to delete to get ride of all those crapware ?</p>
<p>I&#8217;lm really concern by the fact that FB is selling all our info. By the way the privacy terms in FB are getting crazy !</p>
<p>Hope you will help me.</p>
<p>Cheers; Sahimone</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FACEBOOKUPDATE.EXE &#8211; not a virus by Bozo</title>
		<link>http://greatis.com/blog/not-a-virus/facebookupdate-exe.htm/comment-page-1#comment-2109</link>
		<dc:creator>Bozo</dc:creator>
		<pubDate>Wed, 04 Apr 2012 18:34:54 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=7359#comment-2109</guid>
		<description>I believe it&#039;s a vector.  I&#039;ve had multiple attacks since this loaded onto my rig without asking, including a complete takeover of my Facebook account by someone advertising shoes.  Disable, or better yet, remove with CCleaner. When did Facebook ask for permission to install ANY programs on my computer? They are a website. Nothing more. And for those &quot;hey, it&#039;s free&quot; people, no, it&#039;s not.  Facebook sells your life story for a buck - billions of them, actually, and needs to be more respectful of the souls they are exploiting.

Did I say respectful? I am a dreamer...

So far, after removing all background Facebook crapware, my connection has stopped logging on and off at random,and my Facebook account has not been spammed.</description>
		<content:encoded><![CDATA[<p>I believe it&#8217;s a vector.  I&#8217;ve had multiple attacks since this loaded onto my rig without asking, including a complete takeover of my Facebook account by someone advertising shoes.  Disable, or better yet, remove with CCleaner. When did Facebook ask for permission to install ANY programs on my computer? They are a website. Nothing more. And for those &#8220;hey, it&#8217;s free&#8221; people, no, it&#8217;s not.  Facebook sells your life story for a buck &#8211; billions of them, actually, and needs to be more respectful of the souls they are exploiting.</p>
<p>Did I say respectful? I am a dreamer&#8230;</p>
<p>So far, after removing all background Facebook crapware, my connection has stopped logging on and off at random,and my Facebook account has not been spammed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FACEBOOKUPDATE.EXE &#8211; not a virus by Ummm</title>
		<link>http://greatis.com/blog/not-a-virus/facebookupdate-exe.htm/comment-page-1#comment-2087</link>
		<dc:creator>Ummm</dc:creator>
		<pubDate>Fri, 30 Mar 2012 07:04:54 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=7359#comment-2087</guid>
		<description>C:\Users\Rohan\AppData\Local\Facebook\Update\FacebookUpdate.exe&quot; /c /nocrashserver

...is this what you mean though..? I don&#039;t think anything that runs from &#039;appdata\local&quot; is meant to be on your startup list O.o
...I just have it disabled with ccleaner...it sounds too much like a virus .-.</description>
		<content:encoded><![CDATA[<p>C:\Users\Rohan\AppData\Local\Facebook\Update\FacebookUpdate.exe&#8221; /c /nocrashserver</p>
<p>&#8230;is this what you mean though..? I don&#8217;t think anything that runs from &#8216;appdata\local&#8221; is meant to be on your startup list O.o<br />
&#8230;I just have it disabled with ccleaner&#8230;it sounds too much like a virus .-.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FLINT4YTW.EXE is Locker Randsom by NightWatcher</title>
		<link>http://greatis.com/blog/ransomware/flint4ytw-exe.htm/comment-page-1#comment-2025</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Mon, 19 Mar 2012 07:16:30 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/flint4ytw-exe.htm#comment-2025</guid>
		<description>The desktop is clean!
Follow these steps to solve the problem:
1. Press “Win+R”, type &quot;regedit&quot; and press &quot;Enter&quot;.
2. Set in the Registry Editor key value:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
equal to &quot;0&quot;
3. Reboot.</description>
		<content:encoded><![CDATA[<p>The desktop is clean!<br />
Follow these steps to solve the problem:<br />
1. Press “Win+R”, type &#8220;regedit&#8221; and press &#8220;Enter&#8221;.<br />
2. Set in the Registry Editor key value:<br />
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons<br />
equal to &#8220;0&#8243;<br />
3. Reboot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on LOBOUYVVYW.EXE is Trojan Patched by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/lobouyvvyw-exe.htm/comment-page-1#comment-1742</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Mon, 05 Mar 2012 03:37:04 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/lobouyvvyw-exe.htm#comment-1742</guid>
		<description>The desktop is clean!
Follow these steps to solve the problem:
- Press &quot;Win + R&quot;
- Type &quot;attrib -h /S /D c:\ *.*&quot; and press &quot;Enter&quot;</description>
		<content:encoded><![CDATA[<p>The desktop is clean!<br />
Follow these steps to solve the problem:<br />
- Press &#8220;Win + R&#8221;<br />
- Type &#8220;attrib -h /S /D c:\ *.*&#8221; and press &#8220;Enter&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on AON32.EXE is BackDoor Ddoser by Jason</title>
		<link>http://greatis.com/blog/backdoor/aon32-exe.htm/comment-page-1#comment-1436</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Mon, 13 Feb 2012 18:42:21 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8608#comment-1436</guid>
		<description>Ok so to remove it you open task manager and there should many duplicate task normally some type of browser now forget those you cannot close them as fast as it will reopen now find the process aon32.exe right click and select properties now change its preference from hidden to un hidden then close those windows leaving you with just task manager now right click aon32.exe and select OPEN FILE LOCATION now you should see the file as aon32.exe now first end the process and delete the file and you are done!</description>
		<content:encoded><![CDATA[<p>Ok so to remove it you open task manager and there should many duplicate task normally some type of browser now forget those you cannot close them as fast as it will reopen now find the process aon32.exe right click and select properties now change its preference from hidden to un hidden then close those windows leaving you with just task manager now right click aon32.exe and select OPEN FILE LOCATION now you should see the file as aon32.exe now first end the process and delete the file and you are done!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on REACTIVATEIE.EXE is Adware Zugo by kimo</title>
		<link>http://greatis.com/blog/adware/reactivateie-exe.htm/comment-page-1#comment-1419</link>
		<dc:creator>kimo</dc:creator>
		<pubDate>Sun, 12 Feb 2012 16:41:36 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/reactivateie-exe.htm#comment-1419</guid>
		<description>thanks pro (:
that is found in startnow toolbar</description>
		<content:encoded><![CDATA[<p>thanks pro (:<br />
that is found in startnow toolbar</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Removed: REGSRV.EXE, STDRT.EXE by bill</title>
		<link>http://greatis.com/blog/how-to-remove-malware/removed-regsrv-exe-stdrt-exe.htm/comment-page-1#comment-1285</link>
		<dc:creator>bill</dc:creator>
		<pubDate>Sat, 04 Feb 2012 19:16:49 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=1279#comment-1285</guid>
		<description>THIS SOLUTION DOES NOT WORK ON WINDOWS 7 x64</description>
		<content:encoded><![CDATA[<p>THIS SOLUTION DOES NOT WORK ON WINDOWS 7 x64</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1141</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Mon, 23 Jan 2012 11:45:09 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1141</guid>
		<description>http://greatis.com/blog/how-to-remove-malware/mvscavap-exe.htm</description>
		<content:encoded><![CDATA[<p><a href="http://greatis.com/blog/how-to-remove-malware/mvscavap-exe.htm" rel="nofollow">http://greatis.com/blog/how-to-remove-malware/mvscavap-exe.htm</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1129</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Sun, 22 Jan 2012 13:07:35 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1129</guid>
		<description>The easiest way to remove these trojans:)
http://youtu.be/sDU4_Jgydbs</description>
		<content:encoded><![CDATA[<p>The easiest way to remove these trojans:)<br />
<a href="http://youtu.be/sDU4_Jgydbs" rel="nofollow">http://youtu.be/sDU4_Jgydbs</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Blake</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1106</link>
		<dc:creator>Blake</dc:creator>
		<pubDate>Fri, 20 Jan 2012 17:17:33 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1106</guid>
		<description>just to clear things up at the beginning of my last post you only type in &quot;%temp%&quot; then you simply navigate in the window. &quot;Organize&quot; being found in the top left corner</description>
		<content:encoded><![CDATA[<p>just to clear things up at the beginning of my last post you only type in &#8220;%temp%&#8221; then you simply navigate in the window. &#8220;Organize&#8221; being found in the top left corner</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Blake</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1105</link>
		<dc:creator>Blake</dc:creator>
		<pubDate>Fri, 20 Jan 2012 17:15:54 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1105</guid>
		<description>i just got this figured out thanks for the great help guys!:D
anyone still struggling type in 
-&gt; %temp% -&gt; &quot;Organize&quot; -&gt; &quot;Folder and Search Options&quot; -&gt; &quot;View&quot; (Middle Tab)

from there you are going to change two thing... 
1). under the folder &quot;Hidden files and folders&quot; simply change the bubble from &quot;Don&#039;t show hidden files, folders, or drives&quot; to &quot;Show hidden files, folders, and drives&quot;

2).under the same folder there will be about 11 boxes, some being checked some unchecked. It should be the 3rd box from the top of that list of 11. its called &quot;Hide protected operating system files(Recommended)&quot; Un-check that box. it will give you a warning message, just hit yes. 

After doing the following click &quot;Apply&quot; -&gt; then &quot;Ok&quot;

you should be back in the temp folder. now look for the folder titled &quot;System&quot; 
(if you cannot locate system simply go to the navigation bar at the top of the window and re-click on temp to refresh it)

go into system and you will see siaport. Delete that bastard!

Any questions feel free to ask! Email me at dadiggin@live.com i will answer on that faster than this!</description>
		<content:encoded><![CDATA[<p>i just got this figured out thanks for the great help guys!:D<br />
anyone still struggling type in<br />
-&gt; %temp% -&gt; &#8220;Organize&#8221; -&gt; &#8220;Folder and Search Options&#8221; -&gt; &#8220;View&#8221; (Middle Tab)</p>
<p>from there you are going to change two thing&#8230;<br />
1). under the folder &#8220;Hidden files and folders&#8221; simply change the bubble from &#8220;Don&#8217;t show hidden files, folders, or drives&#8221; to &#8220;Show hidden files, folders, and drives&#8221;</p>
<p>2).under the same folder there will be about 11 boxes, some being checked some unchecked. It should be the 3rd box from the top of that list of 11. its called &#8220;Hide protected operating system files(Recommended)&#8221; Un-check that box. it will give you a warning message, just hit yes. </p>
<p>After doing the following click &#8220;Apply&#8221; -&gt; then &#8220;Ok&#8221;</p>
<p>you should be back in the temp folder. now look for the folder titled &#8220;System&#8221;<br />
(if you cannot locate system simply go to the navigation bar at the top of the window and re-click on temp to refresh it)</p>
<p>go into system and you will see siaport. Delete that bastard!</p>
<p>Any questions feel free to ask! Email me at <a href="mailto:dadiggin@live.com">dadiggin@live.com</a> i will answer on that faster than this!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Cannot find SiaPort.exe</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1103</link>
		<dc:creator>Cannot find SiaPort.exe</dc:creator>
		<pubDate>Fri, 20 Jan 2012 15:58:59 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1103</guid>
		<description>I found the system folder but I CANT FIND THE SiaPort.exe. If i organise it and pressing &quot;Hide all folders,files&quot;  It wont show. Plz Help me.............</description>
		<content:encoded><![CDATA[<p>I found the system folder but I CANT FIND THE SiaPort.exe. If i organise it and pressing &#8220;Hide all folders,files&#8221;  It wont show. Plz Help me&#8230;&#8230;&#8230;&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Hazza</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1100</link>
		<dc:creator>Hazza</dc:creator>
		<pubDate>Fri, 20 Jan 2012 08:49:58 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1100</guid>
		<description>never mind, found it... 

PEOPLE WHO CANT FIND THE &quot;SYSTEM&quot; FOLDER

When you go to the organise thing, there should be a little circle filled with blue with text next to it saying &quot;Hide all Folders, files etc.&quot; Click the one below it that says&quot;Show&quot; as well as the boxes below. Might help... :P</description>
		<content:encoded><![CDATA[<p>never mind, found it&#8230; </p>
<p>PEOPLE WHO CANT FIND THE &#8220;SYSTEM&#8221; FOLDER</p>
<p>When you go to the organise thing, there should be a little circle filled with blue with text next to it saying &#8220;Hide all Folders, files etc.&#8221; Click the one below it that says&#8221;Show&#8221; as well as the boxes below. Might help&#8230; <img src='http://greatis.com/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Hazza</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1099</link>
		<dc:creator>Hazza</dc:creator>
		<pubDate>Fri, 20 Jan 2012 08:42:43 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1099</guid>
		<description>I tried the &quot;Unhide Folders&quot; thing and i still cant find the System Folder, I think the Trojan might have let in a virus... HELP!!!</description>
		<content:encoded><![CDATA[<p>I tried the &#8220;Unhide Folders&#8221; thing and i still cant find the System Folder, I think the Trojan might have let in a virus&#8230; HELP!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Milo</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1091</link>
		<dc:creator>Milo</dc:creator>
		<pubDate>Thu, 19 Jan 2012 10:54:25 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1091</guid>
		<description>For those of us who dosn&#039;t know how to fix this: press windows button (Windows 7 here) and type in &quot;%TEMP%\SYSTEM\&quot; then there should be no files, click on organize (top left corner) then press Folder and search options from the drop down menu. Choose View and then you must uncheck the box that says &quot;Hide operating system files&quot; even though it&#039;s recommended not to. Then delete siaport.exe (click it once and press delete) then yes and it&#039;s outta the world :)</description>
		<content:encoded><![CDATA[<p>For those of us who dosn&#8217;t know how to fix this: press windows button (Windows 7 here) and type in &#8220;%TEMP%\SYSTEM\&#8221; then there should be no files, click on organize (top left corner) then press Folder and search options from the drop down menu. Choose View and then you must uncheck the box that says &#8220;Hide operating system files&#8221; even though it&#8217;s recommended not to. Then delete siaport.exe (click it once and press delete) then yes and it&#8217;s outta the world <img src='http://greatis.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Rostov</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-1017</link>
		<dc:creator>Rostov</dc:creator>
		<pubDate>Sun, 15 Jan 2012 13:26:17 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-1017</guid>
		<description>Can&#039;t find the System subfolder after the Temp subfolder.  I get into the Temp folder and there are hundreds of my other folders but no System folder.  Siaport.exe says it&#039;s in the System but I can see it, even with all hidden files made to appear.</description>
		<content:encoded><![CDATA[<p>Can&#8217;t find the System subfolder after the Temp subfolder.  I get into the Temp folder and there are hundreds of my other folders but no System folder.  Siaport.exe says it&#8217;s in the System but I can see it, even with all hidden files made to appear.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by Johnny D</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-991</link>
		<dc:creator>Johnny D</dc:creator>
		<pubDate>Sat, 14 Jan 2012 05:39:48 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-991</guid>
		<description>This is simple. 

For Windows 7, Go to the directory of the file... AppData\Local\Temp\System
If you don&#039;t see any files it means they&#039;re hidden, so what you&#039;ll need to do is
simply unhide them. Near the Top Left, click on (Organize). A drop down menu
should appear. Now go to (Folder and search options). A window will appear. At the top you&#039;ll see 3 tabs/pages. Click on (View). Now, in the list, you want to look for (Hide protected operating system files Recommended). Now uncheck that. A warning may pop up but that&#039;s ok. Click (Yes). Now click (Apply) then (OK).
If you did all that correctly you should see 2 files.... Delete them and you&#039;re Done! :)  
Now you might want to go back and make sure you Hide the system files. Just Check the box for (Hide protected operating system files Recommended) then click Apply and OK! Easy!</description>
		<content:encoded><![CDATA[<p>This is simple. </p>
<p>For Windows 7, Go to the directory of the file&#8230; AppData\Local\Temp\System<br />
If you don&#8217;t see any files it means they&#8217;re hidden, so what you&#8217;ll need to do is<br />
simply unhide them. Near the Top Left, click on (Organize). A drop down menu<br />
should appear. Now go to (Folder and search options). A window will appear. At the top you&#8217;ll see 3 tabs/pages. Click on (View). Now, in the list, you want to look for (Hide protected operating system files Recommended). Now uncheck that. A warning may pop up but that&#8217;s ok. Click (Yes). Now click (Apply) then (OK).<br />
If you did all that correctly you should see 2 files&#8230;. Delete them and you&#8217;re Done! <img src='http://greatis.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Now you might want to go back and make sure you Hide the system files. Just Check the box for (Hide protected operating system files Recommended) then click Apply and OK! Easy!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on REGSRV64.EXE is trojan Offend by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/regsrv64-exe.htm/comment-page-1#comment-957</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Thu, 12 Jan 2012 03:17:06 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8342#comment-957</guid>
		<description>Please visit our support center:
http://greatis.com/support
Attach your regrunlog.txt and we will help you.</description>
		<content:encoded><![CDATA[<p>Please visit our support center:<br />
<a href="http://greatis.com/support" rel="nofollow">http://greatis.com/support</a><br />
Attach your regrunlog.txt and we will help you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on REGSRV64.EXE is trojan Offend by Ket</title>
		<link>http://greatis.com/blog/how-to-remove-malware/regsrv64-exe.htm/comment-page-1#comment-950</link>
		<dc:creator>Ket</dc:creator>
		<pubDate>Wed, 11 Jan 2012 15:11:43 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=8342#comment-950</guid>
		<description>I cannot remove the file. It always said this file has been used by another program even though I open only a folder to delete it. How can I delete it? Please help.</description>
		<content:encoded><![CDATA[<p>I cannot remove the file. It always said this file has been used by another program even though I open only a folder to delete it. How can I delete it? Please help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Removed: C:\WINDOWS\system32\system\dll.exe (trojan VBInject) by Mark</title>
		<link>http://greatis.com/blog/how-to-remove-malware/dll-exe-trojan-vbinject.htm/comment-page-1#comment-934</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Tue, 10 Jan 2012 01:17:54 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=4296#comment-934</guid>
		<description>Before deleting suspect malware it is best to create a system restore point first in case the system crashes. I am new to removing malware and it appears it may be easier to block the IP addresses and close the ports. As you can imagine a hacker may not be very happy to find out that the RATs have been cutoff. The hacker will try everything to regain access. Once the user knows who is doing what it is a lot easier to manage the risk.  I have only found 1 software package that monitors the traffic. BeeHive is good stuff, and if you want to be a wise guy you can cause the hacker to have many sleepless nights as they watch the user watch the hacker. 

Maybe you software guys could creatre some fun software to better monitor the hackers activities.</description>
		<content:encoded><![CDATA[<p>Before deleting suspect malware it is best to create a system restore point first in case the system crashes. I am new to removing malware and it appears it may be easier to block the IP addresses and close the ports. As you can imagine a hacker may not be very happy to find out that the RATs have been cutoff. The hacker will try everything to regain access. Once the user knows who is doing what it is a lot easier to manage the risk.  I have only found 1 software package that monitors the traffic. BeeHive is good stuff, and if you want to be a wise guy you can cause the hacker to have many sleepless nights as they watch the user watch the hacker. </p>
<p>Maybe you software guys could creatre some fun software to better monitor the hackers activities.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Removed: pb.dll, forinout.exe, LiveSS.exe, pb.sys (FakeAV &#8211; Live Security Suite) by Reena mathew</title>
		<link>http://greatis.com/blog/how-to-remove-malware/removed-pb-dll-forinout-exe-livess-exe-pb-sys-fakeav-live-security-suite.htm/comment-page-1#comment-928</link>
		<dc:creator>Reena mathew</dc:creator>
		<pubDate>Mon, 09 Jan 2012 08:17:58 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/?p=3846#comment-928</guid>
		<description>I have searched so many weblogs for a solution, at last I got the complete fix from here, KUDOS to greatis.com technical team. You guys are really rocking!!! 

Thanks, please keep on posting on new spyware issues.</description>
		<content:encoded><![CDATA[<p>I have searched so many weblogs for a solution, at last I got the complete fix from here, KUDOS to greatis.com technical team. You guys are really rocking!!! </p>
<p>Thanks, please keep on posting on new spyware issues.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by NightWatcher</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-892</link>
		<dc:creator>NightWatcher</dc:creator>
		<pubDate>Thu, 05 Jan 2012 10:26:26 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-892</guid>
		<description>Please visit our support center:
http://greatis.com/support
Attach your regrunlog.txt and we will help you.</description>
		<content:encoded><![CDATA[<p>Please visit our support center:<br />
<a href="http://greatis.com/support" rel="nofollow">http://greatis.com/support</a><br />
Attach your regrunlog.txt and we will help you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SIAPORT.EXE is Trojan Kazy by will</title>
		<link>http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm/comment-page-1#comment-885</link>
		<dc:creator>will</dc:creator>
		<pubDate>Wed, 04 Jan 2012 22:09:13 +0000</pubDate>
		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/siaport-exe.htm#comment-885</guid>
		<description>same problem here... how to solve it???</description>
		<content:encoded><![CDATA[<p>same problem here&#8230; how to solve it???</p>
]]></content:encoded>
	</item>
</channel>
</rss>

