<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Analysis and Removal</title>
	<atom:link href="http://greatis.com/blog/feed" rel="self" type="application/rss+xml" />
	<link>http://greatis.com/blog</link>
	<description>Malware Analysis and Removal</description>
	<lastBuildDate>Mon, 20 May 2013 04:36:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>SPD.EXE is Trojan MulDrop4</title>
		<link>http://greatis.com/blog/how-to-remove-malware/spd-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/spd-exe.htm#comments</comments>
		<pubDate>Mon, 20 May 2013 04:36:57 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[SPD.EXE]]></category>
		<category><![CDATA[Trojan.Muldrop4]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/spd-exe.htm</guid>
		<description><![CDATA[We checked some samples of SPD.EXE and detected the file SPD.EXE as threat. Remove the SPD.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of SPD.EXE Full path on a computer: %APPDATA%\ADOBE\FLASH PLAYER\SPEEDCACHE\SPD.EXE Detected by UnHackMe: SPD.EXE Default location: %APPDATA%\ADOBE\FLASH PLAYER\SPEEDCACHE\SPD.EXE Removal Results: Success Number of reboot: 1 SPD.EXE is known as: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>SPD.EXE</b>  and detected the file <b>SPD.EXE</b> as threat.<br />
Remove the <b>SPD.EXE</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of SPD.EXE<br />
Full path on a computer: %APPDATA%\ADOBE\FLASH PLAYER\SPEEDCACHE\SPD.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>SPD.EXE</b><br />
Default location: %APPDATA%\ADOBE\FLASH PLAYER\SPEEDCACHE\SPD.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>SPD.EXE</strong>  is known as:</h3>
<p>Trojan MulDrop4
</p></div>
<div id="clist">
How to quickly detect <strong>SPD.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\TMP-SETUP.EXE
<li>%APPDATA%\ADOBE\FLASH PLAYER\SPEEDCACHE\AFILE.VBS
<li>%TEMP%\NSF6.TMP\INSTALLOPTIONS.DLL
<li>%APPDATA%\ADOBE\FLASH PLAYER\SPEEDCACHE\PTHREADGC2.DLL
<li>%APPDATA%\ADOBE\FLASH PLAYER\SPEEDCACHE\SPD.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/spd-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/spd-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PRICEPEEP_1.EXE is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/pricepeep_1-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/pricepeep_1-exe.htm#comments</comments>
		<pubDate>Mon, 20 May 2013 04:36:57 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[PRICEPEEP_1.EXE]]></category>
		<category><![CDATA[trojan-downloader]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/pricepeep_1-exe.htm</guid>
		<description><![CDATA[We checked some samples of PRICEPEEP_1.EXE and detected the file PRICEPEEP_1.EXE as threat. Remove the PRICEPEEP_1.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of PRICEPEEP_1.EXE Full path on a computer: %TEMP%\PRICEPEEP_1.EXE Detected by UnHackMe: PRICEPEEP_1.EXE Default location: %TEMP%\PRICEPEEP_1.EXE Removal Results: Success Number of reboot: 1 PRICEPEEP_1.EXE is known as: Trojan Downloader [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>PRICEPEEP_1.EXE</b>  and detected the file <b>PRICEPEEP_1.EXE</b> as threat.<br />
Remove the <b>PRICEPEEP_1.EXE</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of PRICEPEEP_1.EXE<br />
Full path on a computer: %TEMP%\PRICEPEEP_1.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>PRICEPEEP_1.EXE</b><br />
Default location: %TEMP%\PRICEPEEP_1.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>PRICEPEEP_1.EXE</strong>  is known as:</h3>
<p>Trojan Downloader
</p></div>
<div id="clist">
How to quickly detect <strong>PRICEPEEP_1.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\GLUPGRADE\STORAGE.JS
<li>%TEMP%\GLUPGRADE\STATS.JS
<li>%PROGRAMFILES%\PRICEPEEP\INSTALLER.ICO
<li>%PROGRAMFILES%\PRICEPEEP\UNUTIL.EXE
<li>%TEMP%\PRICEPEEP_1.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/pricepeep_1-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/pricepeep_1-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NOCRYPT.EXE is Trojan Killfiles</title>
		<link>http://greatis.com/blog/how-to-remove-malware/nocrypt-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/nocrypt-exe.htm#comments</comments>
		<pubDate>Mon, 20 May 2013 04:36:57 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[NOCRYPT.EXE]]></category>
		<category><![CDATA[Trojan.Killfiles]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/nocrypt-exe.htm</guid>
		<description><![CDATA[The file NOCRYPT.EXE is identified as a virus dropper. The dropper NOCRYPT.EXE is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center. The file NOCRYPT.EXE loads into the computer memory and tries to connect to the dangerous web site. Usually the NOCRYPT.EXE dropper does not infect the [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>NOCRYPT.EXE</b> is identified as a virus dropper.<br />
The dropper <b>NOCRYPT.EXE</b> is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.<br />
The file <b>NOCRYPT.EXE</b> loads into the computer memory and tries to connect to the dangerous web site.<br />
Usually the  <b>NOCRYPT.EXE</b> dropper does not infect the files on the computer and does not replicate itself on other computers.<br />
Kill the <b>NOCRYPT.EXE</b> process and delete the file <b>NOCRYPT.EXE</b>.</p>
<h2>Malware Analysis of NOCRYPT.EXE<br />
Full path on a computer: %APPDATA%\NOCRYPT.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>NOCRYPT.EXE</b><br />
Default location: %APPDATA%\NOCRYPT.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>NOCRYPT.EXE</strong>  is known as:</h3>
<p>Trojan.Killfiles
</p></div>
<div id="clist">
How to quickly detect <strong>NOCRYPT.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\WER4050.DIR00\MANIFEST.TXT
<li>%TEMP%\WER4050.DIR00\APPCOMPAT.TXT
<li>%SYSTEMDRIVE%\SYSTEM VOLUME INFORMATION\_RESTORE{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\_FILELST.CFG
<li>%SYSTEMDRIVE%\SYSTEM VOLUME INFORMATION\_RESTORE{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\DRIVETABLE.TXT
<li>%APPDATA%\NOCRYPT.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/nocrypt-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/nocrypt-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MY VIDEOS.EXE is Trojan MulDrop4</title>
		<link>http://greatis.com/blog/how-to-remove-malware/my-videos-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/my-videos-exe.htm#comments</comments>
		<pubDate>Mon, 20 May 2013 04:36:57 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[MY VIDEOS.EXE]]></category>
		<category><![CDATA[Trojan.Muldrop4]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/my-videos-exe.htm</guid>
		<description><![CDATA[The file MY VIDEOS.EXE is identified as a virus dropper. The dropper MY VIDEOS.EXE is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center. The file MY VIDEOS.EXE loads into the computer memory and tries to connect to the dangerous web site. Usually the MY VIDEOS.EXE dropper [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>MY VIDEOS.EXE</b> is identified as a virus dropper.<br />
The dropper <b>MY VIDEOS.EXE</b> is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.<br />
The file <b>MY VIDEOS.EXE</b> loads into the computer memory and tries to connect to the dangerous web site.<br />
Usually the  <b>MY VIDEOS.EXE</b> dropper does not infect the files on the computer and does not replicate itself on other computers.<br />
Kill the <b>MY VIDEOS.EXE</b> process and delete the file <b>MY VIDEOS.EXE</b>.</p>
<h2>Malware Analysis of MY VIDEOS.EXE<br />
Full path on a computer: %ALLUSERSPROFILE%\DOCUMENTS\MY VIDEOS\MY VIDEOS.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>MY VIDEOS.EXE</b><br />
Default location: %ALLUSERSPROFILE%\DOCUMENTS\MY VIDEOS\MY VIDEOS.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>MY VIDEOS.EXE</strong>  is known as:</h3>
<p>Trojan MulDrop4
</p></div>
<div id="clist">
How to quickly detect <strong>MY VIDEOS.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SYSTEMDRIVE%\DOCUMENTS AND SETTINGS\DEFAULT USER\APPLICATION DATA\MICROSOFT\MEDIA PLAYER\MEDIA PLAYER.EXE
<li>%SYSTEMDRIVE%\DOCUMENTS AND SETTINGS\DEFAULT USER\APPLICATION DATA\MICROSOFT\SYSTEMCERTIFICATES\SYSTEMCERTIFICATES.EXE
<li>%SYSTEMDRIVE%\DOCUMENTS AND SETTINGS\DEFAULT USER\APPLICATION DATA\MICROSOFT\INTERNET EXPLORER\INTERNET EXPLORER.EXE
<li>%SYSTEMDRIVE%\DOCUMENTS AND SETTINGS\DEFAULT USER\APPLICATION DATA\APPLICATION DATA.EXE
<li>%ALLUSERSPROFILE%\DOCUMENTS\MY VIDEOS\MY VIDEOS.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/my-videos-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/my-videos-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/lahore-school-of-economics-student-girl-topless-hot-pics-pps.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/lahore-school-of-economics-student-girl-topless-hot-pics-pps.htm#comments</comments>
		<pubDate>Mon, 20 May 2013 04:36:57 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS]]></category>
		<category><![CDATA[trojan-downloader]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/lahore-school-of-economics-student-girl-topless-hot-pics-pps.htm</guid>
		<description><![CDATA[The file LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS is malware related. You must delete the file LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS immediately! Delete the file LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS without delay! Kill the process LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS</b> is malware related.<br />
You must delete the file <b>LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS</b> immediately!<br />
Delete the file <b>LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS</b> without delay!<br />
Kill the process <b>LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS</b> and remove <b>LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS</b> from the Windows startup.</p>
<h2>Malware Analysis of LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS<br />
Full path on a computer: %SYSDIR%\MACROMEDLE\LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS</b><br />
Default location: %SYSDIR%\MACROMEDLE\LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS</strong>  is known as:</h3>
<p>Trojan Downloader
</p></div>
<div id="clist">
How to quickly detect <strong>LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SYSDIR%\MACROMEDLE\SPOOLSV.EXE
<li>%SYSDIR%\MACROMEDLE\FTPBACKUP-2012-10-23.LOG
<li>%COMMON APPDATA%\MICROSOFT\CRYPTO\RSA\S-1-5-18\6D14E4B1D8CA773BAB785D1BE032546E_23EF5514-3059-436F-A4A7-4CEFAAB20EB1
<li>%SYSDIR%\MACROMEDLE\FTPBACKUP.CONFIG
<li>%SYSDIR%\MACROMEDLE\LAHORE SCHOOL OF ECONOMICS STUDENT GIRL TOPLESS HOT PICS.PPS
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/lahore-school-of-economics-student-girl-topless-hot-pics-pps.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/lahore-school-of-economics-student-girl-topless-hot-pics-pps.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE is Trojan AVKill</title>
		<link>http://greatis.com/blog/how-to-remove-malware/javatm-platform-se-auto-updater-2-0-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/javatm-platform-se-auto-updater-2-0-exe.htm#comments</comments>
		<pubDate>Mon, 20 May 2013 04:36:57 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE]]></category>
		<category><![CDATA[Trojan AVKill]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/javatm-platform-se-auto-updater-2-0-exe.htm</guid>
		<description><![CDATA[The file JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE is malware related. You must delete the file JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE immediately! Delete the file JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE without delay! Kill the process JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE and remove JAVA(TM) PLATFORM SE AUTO UPDATER 2 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE</b> is malware related.<br />
You must delete the file <b>JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE</b> immediately!<br />
Delete the file <b>JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE</b> without delay!<br />
Kill the process <b>JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE</b> and remove <b>JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE<br />
Full path on a computer: %APPDATA%\JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE</b><br />
Default location: %APPDATA%\JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE</strong>  is known as:</h3>
<p>Trojan AVKill
</p></div>
<div id="clist">
How to quickly detect <strong>JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%PROFILE%\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\KHMHGZ4F\0QF2I[1]
<li>%APPDATA%\JAVA(TM) PLATFORM SE AUTO UPDATER 2 0.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/javatm-platform-se-auto-updater-2-0-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/javatm-platform-se-auto-updater-2-0-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CASTING.DLL is Trojan Click</title>
		<link>http://greatis.com/blog/how-to-remove-malware/casting-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/casting-dll.htm#comments</comments>
		<pubDate>Mon, 20 May 2013 04:36:57 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[CASTING.DLL]]></category>
		<category><![CDATA[Trojan Click]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/casting-dll.htm</guid>
		<description><![CDATA[We checked up the file CASTING.DLL and found it hazardous. The file CASTING.DLL must be deleted from the system immediately. Kill the process CASTING.DLL and remove CASTING.DLL from the Windows startup. Malware Analysis of CASTING.DLL Full path on a computer: %WINDIR%\CASTING.DLL Detected by UnHackMe: CASTING.DLL Default location: %WINDIR%\CASTING.DLL Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>CASTING.DLL</b> and found it hazardous.<br />
The file <b>CASTING.DLL</b> must be deleted from the system immediately.<br />
Kill the process <b>CASTING.DLL</b> and remove <b>CASTING.DLL</b> from the Windows startup.</p>
<h2>Malware Analysis of CASTING.DLL<br />
Full path on a computer: %WINDIR%\CASTING.DLL</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>CASTING.DLL</b><br />
Default location: %WINDIR%\CASTING.DLL</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>CASTING.DLL</strong>  is known as:</h3>
<p>Trojan Click
</p></div>
<div id="clist">
How to quickly detect <strong>CASTING.DLL</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%PROFILE%\ALPHAF.DLL
<li>%WINDIR%\CASTING.DLL
<li>%PROFILE%\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\U98D4X8H\NOTIFY[1].PHP
<li>%PROFILE%\TMP.VBE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/casting-dll.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/casting-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TNT2USER.EXE is Trojan Barys</title>
		<link>http://greatis.com/blog/how-to-remove-malware/tnt2user-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/tnt2user-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 17:10:40 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Barys]]></category>
		<category><![CDATA[TNT2USER.EXE]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/tnt2user-exe.htm</guid>
		<description><![CDATA[We checked some samples of TNT2USER.EXE and detected the file TNT2USER.EXE as threat. Remove the TNT2USER.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of TNT2USER.EXE Full path on a computer: %Local Appdata%\TNT2\2.0.0.1534\TNT2User.exe Detected by UnHackMe: TNT2USER.EXE Default location: %Local Appdata%\TNT2\2.0.0.1534\TNT2User.exe Removal Results: Success Number of reboot: 1 TNT2USER.EXE is known as: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>TNT2USER.EXE</b>  and detected the file <b>TNT2USER.EXE</b> as threat.<br />
Remove the <b>TNT2USER.EXE</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of TNT2USER.EXE<br />
Full path on a computer: %Local Appdata%\TNT2\2.0.0.1534\TNT2User.exe</h2>
<div id="alist">
<h3>Detected by <a href="http://greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>TNT2USER.EXE</b><br />
Default location: %Local Appdata%\TNT2\2.0.0.1534\TNT2User.exe</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>TNT2USER.EXE</strong>  is known as:</h3>
<p>Trojan.Barys</p>
<h3><strong>TNT2USER.EXE</strong> hash:</h3>
<ul>
<li>MD5: c89c47f425982d3d5100857af83939c1
</div>
<div id="clist">
How to quickly detect <strong>TNT2USER.EXE</strong> presence?</p>
<div class="icon"><img title="Registry" src="/blog/wp-content/themes/revolution-code-blue/images/reg.gif" width="32" height="32" />Registry:</div>
<ul>
<li>HKLM\Software\Classes\xmlfile\shell\Open\command\: &#8220;&#8221;%Program Files%\Internet Explorer\IEXPLORE.EXE&#8221; -nohome&#8221;
<li>HKLM\Software\Classes\xslfile\shell\Open\command\: &#8220;&#8221;%Program Files%\Internet Explorer\IEXPLORE.EXE&#8221; -nohome&#8221;
</ul>
<div class="icon"><img title="Folders" src="/blog/wp-content/themes/revolution-code-blue/images/folders.gif" width="32" height="32" />Folders:</div>
<ul>
<li>%Local Appdata%\TNT2
<li>%Local Appdata%\TNT2\2.0.0.1534
</ul>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%Local Appdata%\TNT2\2.0.0.1534\Autorun.inf
<li>%Local Appdata%\TNT2\2.0.0.1534\crx.tar
<li>%Local Appdata%\TNT2\2.0.0.1534\ffassist.1.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\GLOBALUNINSTALL.TNT
<li>%Local Appdata%\TNT2\2.0.0.1534\hmac.1.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\ie8starter.exe
<li>%Local Appdata%\TNT2\2.0.0.1534\iehpr.1.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\iestage2.1.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\IEToolbar.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\IEToolbar64.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\INSTALL.TNT
<li>%Local Appdata%\TNT2\2.0.0.1534\log.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\npTNT2.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\npTNT2Ghost.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\OldStyleSB.1.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\PARTNER.TNT
<li>%Local Appdata%\TNT2\2.0.0.1534\passport.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\passport64.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\pinnedSearch.htm
<li>%Local Appdata%\TNT2\2.0.0.1534\pinnedSearch_FindWide.htm
<li>%Local Appdata%\TNT2\2.0.0.1534\progress.1.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\regsvr.1.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\RemoteSkin.wms
<li>%Local Appdata%\TNT2\2.0.0.1534\sqlite.1.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\tnt2chrome.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\TNT2User.exe
<li>%Local Appdata%\TNT2\2.0.0.1534\TNT2UserPS.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\TNT2UserPS64.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\TntMagicDel.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\UnInjLib.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\UnInjLib64.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\UNINSTALL.TNT
<li>%Local Appdata%\TNT2\2.0.0.1534\UninstallDlg.1.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\untar.1.dll
<li>%Local Appdata%\TNT2\2.0.0.1534\UPDATE.TNT
<li>%Local Appdata%\TNT2\2.0.0.1534\xpi.tar
<li>%Local Appdata%\TNT2\2.0.0.1534\zipunzip.1.dll
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/tnt2user-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/tnt2user-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WMINIT.EXE is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/wminit-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/wminit-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan-downloader]]></category>
		<category><![CDATA[wminit.exe]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/wminit-exe.htm</guid>
		<description><![CDATA[The file WMINIT.EXE is malware related. You must delete the file WMINIT.EXE immediately! Delete the file WMINIT.EXE without delay! Kill the process WMINIT.EXE and remove WMINIT.EXE from the Windows startup. Malware Analysis of WMINIT.EXE Full path on a computer: %PROGRAM FILES COMMON%\SYSTEM\WMINIT.EXE Detected by UnHackMe: WMINIT.EXE Default location: %PROGRAM FILES COMMON%\SYSTEM\WMINIT.EXE Removal Results: Success Number [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>WMINIT.EXE</b> is malware related.<br />
You must delete the file <b>WMINIT.EXE</b> immediately!<br />
Delete the file <b>WMINIT.EXE</b> without delay!<br />
Kill the process <b>WMINIT.EXE</b> and remove <b>WMINIT.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of WMINIT.EXE<br />
Full path on a computer: %PROGRAM FILES COMMON%\SYSTEM\WMINIT.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>WMINIT.EXE</b><br />
Default location: %PROGRAM FILES COMMON%\SYSTEM\WMINIT.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>WMINIT.EXE</strong>  is known as:</h3>
<p>Trojan Downloader
</p></div>
<div id="clist">
How to quickly detect <strong>WMINIT.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%PROGRAM FILES COMMON%\SYSTEM\WMINIT.EXE
<li>%PROGRAM FILES COMMON%\SYSTEM\WMINIT.DAT
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/wminit-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/wminit-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WINXPKEY.EXE is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/winxpkey-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/winxpkey-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan-downloader]]></category>
		<category><![CDATA[WINXPKEY.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/winxpkey-exe.htm</guid>
		<description><![CDATA[We checked some samples of WINXPKEY.EXE and detected the file WINXPKEY.EXE as threat. Remove the WINXPKEY.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of WINXPKEY.EXE Full path on a computer: %SYSTEMDRIVE%\WINXPKEY.EXE Detected by UnHackMe: WINXPKEY.EXE Default location: %SYSTEMDRIVE%\WINXPKEY.EXE Removal Results: Success Number of reboot: 1 WINXPKEY.EXE is known as: Trojan Downloader [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked some samples of <b>WINXPKEY.EXE</b>  and detected the file <b>WINXPKEY.EXE</b> as threat.<br />
Remove the <b>WINXPKEY.EXE</b> file from your computer right now.<br />
Removal tool: <a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of WINXPKEY.EXE<br />
Full path on a computer: %SYSTEMDRIVE%\WINXPKEY.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>WINXPKEY.EXE</b><br />
Default location: %SYSTEMDRIVE%\WINXPKEY.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>WINXPKEY.EXE</strong>  is known as:</h3>
<p>Trojan Downloader
</p></div>
<div id="clist">
How to quickly detect <strong>WINXPKEY.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%PROFILE%\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\KHMHGZ4F\H7H36D8000212102120102010210[1].PAC
<li>%PROFILE%\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\U98D4X8H\GERAR[1].PHP
<li>%SYSTEMDRIVE%\MYINFECT.KEY
<li>%SYSTEMDRIVE%\WINXPKEY.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/winxpkey-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/winxpkey-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SIMPDATA.TLB is Trojan Killfiles</title>
		<link>http://greatis.com/blog/how-to-remove-malware/simpdata-tlb.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/simpdata-tlb.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[SIMPDATA.TLB]]></category>
		<category><![CDATA[Trojan.Killfiles]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/simpdata-tlb.htm</guid>
		<description><![CDATA[The file SIMPDATA.TLB is identified as the Trojan Program that is used for stealing bank information and users passwords. To delete SIMPDATA.TLB we suggest you should use UnHackMe: http://www.unhackme.com Malware Analysis of SIMPDATA.TLB Full path on a computer: %WINDIR%\WIN7\SIMPDATA.TLB Detected by UnHackMe: SIMPDATA.TLB Default location: %WINDIR%\WIN7\SIMPDATA.TLB Removal Results: Success Number of reboot: 1 SIMPDATA.TLB is [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>SIMPDATA.TLB</b>  is identified as the Trojan Program that is used for stealing bank information and  users passwords.<br />
To delete  <b>SIMPDATA.TLB</b>  we suggest you should use UnHackMe:<br />
<a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of SIMPDATA.TLB<br />
Full path on a computer: %WINDIR%\WIN7\SIMPDATA.TLB</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>SIMPDATA.TLB</b><br />
Default location: %WINDIR%\WIN7\SIMPDATA.TLB</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>SIMPDATA.TLB</strong>  is known as:</h3>
<p>Trojan.Killfiles
</p></div>
<div id="clist">
How to quickly detect <strong>SIMPDATA.TLB</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%WINDIR%\WIN7\MSPRIVS.DLL
<li>%WINDIR%\WIN7\MSMMSP.DLL
<li>%WINDIR%\WIN7\MSRLE32.DLL
<li>%WINDIR%\WIN7\MSRALEGACY.TLB
<li>%WINDIR%\WIN7\SIMPDATA.TLB
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/simpdata-tlb.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/simpdata-tlb.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PRIMNOG.DLL is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/primnog-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/primnog-dll.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[PRIMNOG.DLL]]></category>
		<category><![CDATA[trojan-downloader]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/primnog-dll.htm</guid>
		<description><![CDATA[The file PRIMNOG.DLL is identified as a virus dropper. The dropper PRIMNOG.DLL is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center. The file PRIMNOG.DLL loads into the computer memory and tries to connect to the dangerous web site. Usually the PRIMNOG.DLL dropper does not infect the [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>PRIMNOG.DLL</b> is identified as a virus dropper.<br />
The dropper <b>PRIMNOG.DLL</b> is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.<br />
The file <b>PRIMNOG.DLL</b> loads into the computer memory and tries to connect to the dangerous web site.<br />
Usually the  <b>PRIMNOG.DLL</b> dropper does not infect the files on the computer and does not replicate itself on other computers.<br />
Kill the <b>PRIMNOG.DLL</b> process and delete the file <b>PRIMNOG.DLL</b>.</p>
<h2>Malware Analysis of PRIMNOG.DLL<br />
Full path on a computer: %LOCAL APPDATA%\PRIMNOG.DLL</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>PRIMNOG.DLL</b><br />
Default location: %LOCAL APPDATA%\PRIMNOG.DLL</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>PRIMNOG.DLL</strong>  is known as:</h3>
<p>Trojan Downloader
</p></div>
<div id="clist">
How to quickly detect <strong>PRIMNOG.DLL</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%LOCAL APPDATA%\PRIMNOG.DLL
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/primnog-dll.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/primnog-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NOIR.ART is Trojan Siggen</title>
		<link>http://greatis.com/blog/how-to-remove-malware/noir-art.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/noir-art.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[NOIR.ART]]></category>
		<category><![CDATA[Trojan Siggen]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/noir-art.htm</guid>
		<description><![CDATA[We checked up the file NOIR.ART and found it hazardous. The file NOIR.ART must be deleted from the system immediately. Kill the process NOIR.ART and remove NOIR.ART from the Windows startup. Malware Analysis of NOIR.ART Full path on a computer: %TEMP%\NOIR.ART Detected by UnHackMe: NOIR.ART Default location: %TEMP%\NOIR.ART Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>NOIR.ART</b> and found it hazardous.<br />
The file <b>NOIR.ART</b> must be deleted from the system immediately.<br />
Kill the process <b>NOIR.ART</b> and remove <b>NOIR.ART</b> from the Windows startup.</p>
<h2>Malware Analysis of NOIR.ART<br />
Full path on a computer: %TEMP%\NOIR.ART</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>NOIR.ART</b><br />
Default location: %TEMP%\NOIR.ART</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>NOIR.ART</strong>  is known as:</h3>
<p>Trojan Siggen
</p></div>
<div id="clist">
How to quickly detect <strong>NOIR.ART</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\NOIR.ART
<li>%TEMP%\AUT1.TMP
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/noir-art.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/noir-art.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MINERDINSTALL.EXE is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/minerdinstall-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/minerdinstall-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[MINERDINSTALL.EXE]]></category>
		<category><![CDATA[trojan-downloader]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/minerdinstall-exe.htm</guid>
		<description><![CDATA[The file MINERDINSTALL.EXE can destroy your system, thus making the computer to work abnormally. MINERDINSTALL.EXE is a dangerous file. RemoveMINERDINSTALL.EXE from your computer immediately. Kill the process MINERDINSTALL.EXE and remove MINERDINSTALL.EXE from the Windows startup. Malware Analysis of MINERDINSTALL.EXE Full path on a computer: %TEMP%\RARSFX0\MINERDINSTALL.EXE Detected by UnHackMe: MINERDINSTALL.EXE Default location: %TEMP%\RARSFX0\MINERDINSTALL.EXE Removal Results: Success [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>MINERDINSTALL.EXE</b> can destroy your system, thus making the computer to work abnormally.<br />
<b>MINERDINSTALL.EXE</b> is a dangerous file.<br />
Remove<b>MINERDINSTALL.EXE</b> from your computer immediately.<br />
Kill the process <b>MINERDINSTALL.EXE</b> and remove <b>MINERDINSTALL.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of MINERDINSTALL.EXE<br />
Full path on a computer: %TEMP%\RARSFX0\MINERDINSTALL.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>MINERDINSTALL.EXE</b><br />
Default location: %TEMP%\RARSFX0\MINERDINSTALL.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>MINERDINSTALL.EXE</strong>  is known as:</h3>
<p>Trojan Downloader
</p></div>
<div id="clist">
How to quickly detect <strong>MINERDINSTALL.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%PROGRAMFILES%\MINER\LIBCURL-4.DLL
<li>%PROGRAMFILES%\MINER\LIBCURL.DLL
<li>%PROGRAMFILES%\MINER\LIBEAY32.DLL
<li>%PROGRAMFILES%\MINER\MINERDUNINSTALL.EXE
<li>%TEMP%\RARSFX0\MINERDINSTALL.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/minerdinstall-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/minerdinstall-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>INS64.EXE is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/ins64-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/ins64-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[INS64.EXE]]></category>
		<category><![CDATA[trojan-downloader]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/ins64-exe.htm</guid>
		<description><![CDATA[We checked up the file INS64.EXE and found it hazardous. The file INS64.EXE must be deleted from the system immediately. Kill the process INS64.EXE and remove INS64.EXE from the Windows startup. Malware Analysis of INS64.EXE Full path on a computer: %TEMP%\INS\INS64.EXE Detected by UnHackMe: INS64.EXE Default location: %TEMP%\INS\INS64.EXE Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>INS64.EXE</b> and found it hazardous.<br />
The file <b>INS64.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>INS64.EXE</b> and remove <b>INS64.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of INS64.EXE<br />
Full path on a computer: %TEMP%\INS\INS64.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>INS64.EXE</b><br />
Default location: %TEMP%\INS\INS64.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>INS64.EXE</strong>  is known as:</h3>
<p>Trojan Downloader
</p></div>
<div id="clist">
How to quickly detect <strong>INS64.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%PROGRAMFILES%\BAIDU\TOOLBAR\IMG\24.ICO
<li>%PROGRAMFILES%\BAIDU\TOOLBAR\IMG\23.ICO
<li>%PROGRAMFILES%\BAIDU\TOOLBAR\IMG\27.ICO
<li>%PROGRAMFILES%\BAIDU\TOOLBAR\IMG\3.ICO
<li>%TEMP%\INS\INS64.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/ins64-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/ins64-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IASS.EXE is Trojan MulDrop4</title>
		<link>http://greatis.com/blog/how-to-remove-malware/iass-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/iass-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[IASS.EXE]]></category>
		<category><![CDATA[Trojan.Muldrop4]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/iass-exe.htm</guid>
		<description><![CDATA[Is the file IASS.EXE located on your computer? Then your computer is infected. We do suggest you should remove IASS.EXE from your computer as soon as possible. IASS.EXE is Trojan/Backdoor. Kill the process IASS.EXE and remove IASS.EXE from the Windows startup. Malware Analysis of IASS.EXE Full path on a computer: %SYSDIR%\IASS.EXE Detected by UnHackMe: IASS.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Is the file <b>IASS.EXE</b> located on your computer? Then your computer is infected.<br />
We do suggest you should remove <b>IASS.EXE</b> from your computer as soon as possible.<br />
<b>IASS.EXE</b> is Trojan/Backdoor.<br />
Kill the process <b>IASS.EXE</b> and remove <b>IASS.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of IASS.EXE<br />
Full path on a computer: %SYSDIR%\IASS.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>IASS.EXE</b><br />
Default location: %SYSDIR%\IASS.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>IASS.EXE</strong>  is known as:</h3>
<p>Trojan MulDrop4
</p></div>
<div id="clist">
How to quickly detect <strong>IASS.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>\XPDLL.DLL
<li>%SYSDIR%\IASS.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/iass-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/iass-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GXTHLDY.DLL is Trojan AVKill</title>
		<link>http://greatis.com/blog/how-to-remove-malware/gxthldy-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/gxthldy-dll.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[GXTHLDY.DLL]]></category>
		<category><![CDATA[Trojan AVKill]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/gxthldy-dll.htm</guid>
		<description><![CDATA[The file GXTHLDY.DLL is malware related. You must delete the file GXTHLDY.DLL immediately! Delete the file GXTHLDY.DLL without delay! Kill the process GXTHLDY.DLL and remove GXTHLDY.DLL from the Windows startup. Malware Analysis of GXTHLDY.DLL Full path on a computer: %TEMP%\GXTHLDY\GXTHLDY.DLL Detected by UnHackMe: GXTHLDY.DLL Default location: %TEMP%\GXTHLDY\GXTHLDY.DLL Removal Results: Success Number of reboot: 1 GXTHLDY.DLL [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>GXTHLDY.DLL</b> is malware related.<br />
You must delete the file <b>GXTHLDY.DLL</b> immediately!<br />
Delete the file <b>GXTHLDY.DLL</b> without delay!<br />
Kill the process <b>GXTHLDY.DLL</b> and remove <b>GXTHLDY.DLL</b> from the Windows startup.</p>
<h2>Malware Analysis of GXTHLDY.DLL<br />
Full path on a computer: %TEMP%\GXTHLDY\GXTHLDY.DLL</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>GXTHLDY.DLL</b><br />
Default location: %TEMP%\GXTHLDY\GXTHLDY.DLL</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>GXTHLDY.DLL</strong>  is known as:</h3>
<p>Trojan AVKill
</p></div>
<div id="clist">
How to quickly detect <strong>GXTHLDY.DLL</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%LOCAL APPDATA%\MOZILLA\MOZILLA\GXTHLDY.DLL
<li>%APPDATA%\MOZILLA\FIREFOX\PROFILES\CWDGT0Y8.DEFAULT\EXTENSIONS\CJACMYCNQJ@CJACMYCNQJ.ORG.XPI
<li>%TEMP%\GXTHLDY\GXTHLDY.DLL
<li>%TEMP%\NSF2.TMP
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/gxthldy-dll.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/gxthldy-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GOOGLEWORD.EXE is under review</title>
		<link>http://greatis.com/blog/unknown/googleword-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/unknown/googleword-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[unknown]]></category>
		<category><![CDATA[GOOGLEWORD.EXE]]></category>
		<category><![CDATA[under review]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/googleword-exe.htm</guid>
		<description><![CDATA[GOOGLEWORD.EXE is unknown, probably legitimate. If the file GOOGLEWORD.EXE is located on your computer, download UnHackMe for free to fix the problem with GOOGLEWORD.EXE. Malware Analysis of GOOGLEWORD.EXE Full path on a computer: %SYSDIR%\GOOGLEWORD.EXE Detected by UnHackMe: GOOGLEWORD.EXE Default location: %SYSDIR%\GOOGLEWORD.EXE Removal Results: Success Number of reboot: 1 GOOGLEWORD.EXE is known as: Dialer.Netvision How to [...]]]></description>
			<content:encoded><![CDATA[<p class="sign"><b>GOOGLEWORD.EXE</b> is unknown, probably legitimate.<br />
If the file <b>GOOGLEWORD.EXE</b> is located on your computer, download <a href="http://www.greatis.com/unhackme/download.htm">UnHackMe for free</a> to fix the problem with <b>GOOGLEWORD.EXE</b>.</p>
<h2>Malware Analysis of GOOGLEWORD.EXE<br />
Full path on a computer: %SYSDIR%\GOOGLEWORD.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>GOOGLEWORD.EXE</b><br />
Default location: %SYSDIR%\GOOGLEWORD.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>GOOGLEWORD.EXE</strong>  is known as:</h3>
<p>Dialer.Netvision
</p></div>
<div id="clist">
How to quickly detect <strong>GOOGLEWORD.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\00019CD7.BAT
<li>%SYSDIR%\GOOGLEWORD.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/unknown/googleword-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/unknown/googleword-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GAMELOGIN.EXE is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/gamelogin-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/gamelogin-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[GAMELOGIN.EXE]]></category>
		<category><![CDATA[trojan-downloader]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/gamelogin-exe.htm</guid>
		<description><![CDATA[We checked up the file GAMELOGIN.EXE and found it hazardous. The file GAMELOGIN.EXE must be deleted from the system immediately. Kill the process GAMELOGIN.EXE and remove GAMELOGIN.EXE from the Windows startup. Malware Analysis of GAMELOGIN.EXE Full path on a computer: \GAMELOGIN.EXE Detected by UnHackMe: GAMELOGIN.EXE Default location: \GAMELOGIN.EXE Removal Results: Success Number of reboot: 1 [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We checked up the file <b>GAMELOGIN.EXE</b> and found it hazardous.<br />
The file <b>GAMELOGIN.EXE</b> must be deleted from the system immediately.<br />
Kill the process <b>GAMELOGIN.EXE</b> and remove <b>GAMELOGIN.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of GAMELOGIN.EXE<br />
Full path on a computer: \GAMELOGIN.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>GAMELOGIN.EXE</b><br />
Default location: \GAMELOGIN.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>GAMELOGIN.EXE</strong>  is known as:</h3>
<p>Trojan Downloader
</p></div>
<div id="clist">
How to quickly detect <strong>GAMELOGIN.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>\UPDATE.BAT
<li>\WGET.EXE
<li>\LOGIN.TXT
<li>\UP.VBS
<li>\GAMELOGIN.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/gamelogin-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/gamelogin-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FREE DOWNLOAD MANAGER793686.EXE is Adware InstallBrain</title>
		<link>http://greatis.com/blog/adware/free-download-manager793686-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/adware/free-download-manager793686-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[Adware InstallBrain]]></category>
		<category><![CDATA[FREE DOWNLOAD MANAGER793686.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/free-download-manager793686-exe.htm</guid>
		<description><![CDATA[We received the file FREE DOWNLOAD MANAGER793686.EXE and detected that FREE DOWNLOAD MANAGER793686.EXE is not good. FREE DOWNLOAD MANAGER793686.EXE is Adware. You should remove the file FREE DOWNLOAD MANAGER793686.EXE. Kill the process FREE DOWNLOAD MANAGER793686.EXE and remove FREE DOWNLOAD MANAGER793686.EXE from Windows. Malware Analysis of FREE DOWNLOAD MANAGER793686.EXE Full path on a computer: %TEMP%\FREE DOWNLOAD [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We received the file <b>FREE DOWNLOAD MANAGER793686.EXE</b> and detected that <b>FREE DOWNLOAD MANAGER793686.EXE</b> is not good.<br />
<b>FREE DOWNLOAD MANAGER793686.EXE</b> is Adware. You should remove the file <b>FREE DOWNLOAD MANAGER793686.EXE</b>.<br />
Kill the process <b>FREE DOWNLOAD MANAGER793686.EXE</b> and remove <b>FREE DOWNLOAD MANAGER793686.EXE</b> from Windows.</p>
<h2>Malware Analysis of FREE DOWNLOAD MANAGER793686.EXE<br />
Full path on a computer: %TEMP%\FREE DOWNLOAD MANAGER793686.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>FREE DOWNLOAD MANAGER793686.EXE</b><br />
Default location: %TEMP%\FREE DOWNLOAD MANAGER793686.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>FREE DOWNLOAD MANAGER793686.EXE</strong>  is known as:</h3>
<p>Adware InstallBrain</p>
<h3><strong>FREE DOWNLOAD MANAGER793686.EXE</strong> hash:</h3>
<ul>
MD5: E57A9AC74B271A8DAE166A25F0CFD4E9
</div>
<div id="clist">
How to quickly detect <strong>FREE DOWNLOAD MANAGER793686.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\FREE DOWNLOAD MANAGER793686.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/adware/free-download-manager793686-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/adware/free-download-manager793686-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FILEEXTHANDLER.EXE is Trojan UnwantedProgram</title>
		<link>http://greatis.com/blog/how-to-remove-malware/fileexthandler-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/fileexthandler-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[FILEEXTHANDLER.EXE]]></category>
		<category><![CDATA[Trojan UnwantedProgram]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/fileexthandler-exe.htm</guid>
		<description><![CDATA[The file FILEEXTHANDLER.EXE can destroy your system, thus making the computer to work abnormally. FILEEXTHANDLER.EXE is a dangerous file. RemoveFILEEXTHANDLER.EXE from your computer immediately. Kill the process FILEEXTHANDLER.EXE and remove FILEEXTHANDLER.EXE from the Windows startup. Malware Analysis of FILEEXTHANDLER.EXE Full path on a computer: %LOCAL APPDATA%\PC MIGHTYMAX 2012\FILEEXTHANDLER.EXE Detected by UnHackMe: FILEEXTHANDLER.EXE Default location: %LOCAL [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>FILEEXTHANDLER.EXE</b> can destroy your system, thus making the computer to work abnormally.<br />
<b>FILEEXTHANDLER.EXE</b> is a dangerous file.<br />
Remove<b>FILEEXTHANDLER.EXE</b> from your computer immediately.<br />
Kill the process <b>FILEEXTHANDLER.EXE</b> and remove <b>FILEEXTHANDLER.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of FILEEXTHANDLER.EXE<br />
Full path on a computer: %LOCAL APPDATA%\PC MIGHTYMAX 2012\FILEEXTHANDLER.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>FILEEXTHANDLER.EXE</b><br />
Default location: %LOCAL APPDATA%\PC MIGHTYMAX 2012\FILEEXTHANDLER.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>FILEEXTHANDLER.EXE</strong>  is known as:</h3>
<p>Trojan UnwantedProgram
</p></div>
<div id="clist">
How to quickly detect <strong>FILEEXTHANDLER.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%LOCAL APPDATA%\PC MIGHTYMAX 2012\DIAGNOSTICREPORTER.ICO
<li>%LOCAL APPDATA%\PC MIGHTYMAX 2012\ELEVATEHELPER.EXE
<li>%PROFILE%\START MENU\PROGRAMS\PC MIGHTYMAX 2012\PC MIGHTYMAX 2012.LNK
<li>%LOCAL APPDATA%\PC MIGHTYMAX 2012\ICON.ICO
<li>%LOCAL APPDATA%\PC MIGHTYMAX 2012\FILEEXTHANDLER.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/fileexthandler-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/fileexthandler-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>D3DX9_21.DLL is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/d3dx9_21-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/d3dx9_21-dll.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[D3DX9_21.DLL]]></category>
		<category><![CDATA[trojan-downloader]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/d3dx9_21-dll.htm</guid>
		<description><![CDATA[The file D3DX9_21.DLL is identified as the Trojan Program that is used for stealing bank information and users passwords. To delete D3DX9_21.DLL we suggest you should use UnHackMe: http://www.unhackme.com Malware Analysis of D3DX9_21.DLL Full path on a computer: %SYSDIR%\D3DX9_21.DLL Detected by UnHackMe: D3DX9_21.DLL Default location: %SYSDIR%\D3DX9_21.DLL Removal Results: Success Number of reboot: 1 D3DX9_21.DLL is [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>D3DX9_21.DLL</b>  is identified as the Trojan Program that is used for stealing bank information and  users passwords.<br />
To delete  <b>D3DX9_21.DLL</b>  we suggest you should use UnHackMe:<br />
<a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of D3DX9_21.DLL<br />
Full path on a computer: %SYSDIR%\D3DX9_21.DLL</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>D3DX9_21.DLL</b><br />
Default location: %SYSDIR%\D3DX9_21.DLL</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>D3DX9_21.DLL</strong>  is known as:</h3>
<p>Trojan Downloader
</p></div>
<div id="clist">
How to quickly detect <strong>D3DX9_21.DLL</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%SYSDIR%\D3DX9_21.DLL
<li>%LOCAL APPDATA%\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\6P5SDOMI\COCOADGSPY_CO19_KR[1]
<li>%LOCAL APPDATA%\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\BOWDBRP7\COCOAMSWINSCK_CO19_KR[1]
<li>%SYSDIR%\MSWINSCK.OCX
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/d3dx9_21-dll.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/d3dx9_21-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CRLS.EXE is Trojan Muldrop3</title>
		<link>http://greatis.com/blog/how-to-remove-malware/crls-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/crls-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[CRLS.EXE]]></category>
		<category><![CDATA[Trojan.Muldrop3]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/crls-exe.htm</guid>
		<description><![CDATA[The file CRLS.EXE is identified as the Trojan Program that is used for stealing bank information and users passwords. To delete CRLS.EXE we suggest you should use UnHackMe: http://www.unhackme.com Malware Analysis of CRLS.EXE Full path on a computer: %SYSTEMDRIVE%\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\MICROSOFT\SYSTEMCERTIFICATES\MY\CRLS.EXE Detected by UnHackMe: CRLS.EXE Default location: %SYSTEMDRIVE%\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\MICROSOFT\SYSTEMCERTIFICATES\MY\CRLS.EXE Removal Results: Success [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>CRLS.EXE</b>  is identified as the Trojan Program that is used for stealing bank information and  users passwords.<br />
To delete  <b>CRLS.EXE</b>  we suggest you should use UnHackMe:<br />
<a title="http://www.unhackme.com" href="http://www.unhackme.com">http://www.unhackme.com</a></p>
<h2>Malware Analysis of CRLS.EXE<br />
Full path on a computer: %SYSTEMDRIVE%\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\MICROSOFT\SYSTEMCERTIFICATES\MY\CRLS.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>CRLS.EXE</b><br />
Default location: %SYSTEMDRIVE%\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\MICROSOFT\SYSTEMCERTIFICATES\MY\CRLS.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>CRLS.EXE</strong>  is known as:</h3>
<p>Trojan.Muldrop3
</p></div>
<div id="clist">
How to quickly detect <strong>CRLS.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%PROGRAM FILES COMMON%\MICROSOFT SHARED\WEB SERVER EXTENSIONS\40\ISAPI.EXE
<li>%PROGRAM FILES COMMON%\MICROSOFT SHARED\WEB SERVER EXTENSIONS\40\BOTS\VINAVBAR.EXE
<li>%PROGRAM FILES COMMON%\MICROSOFT SHARED\WEB SERVER EXTENSIONS\40\ISAPI\_VTI_AUT.EXE
<li>%PROGRAM FILES COMMON%\MICROSOFT SHARED\WEB SERVER EXTENSIONS\40\ISAPI\_VTI_ADM.EXE
<li>%SYSTEMDRIVE%\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\MICROSOFT\SYSTEMCERTIFICATES\MY\CRLS.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/crls-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/crls-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>COOKIEMAN.EXE is Adware W3I</title>
		<link>http://greatis.com/blog/adware/cookieman-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/adware/cookieman-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[Adware.W3I]]></category>
		<category><![CDATA[COOKIEMAN.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/cookieman-exe.htm</guid>
		<description><![CDATA[We received the file COOKIEMAN.EXE and detected that COOKIEMAN.EXE is not good. COOKIEMAN.EXE is Adware. You should remove the file COOKIEMAN.EXE. Kill the process COOKIEMAN.EXE and remove COOKIEMAN.EXE from Windows. Malware Analysis of COOKIEMAN.EXE Full path on a computer: %LOCAL APPDATA%LOW\COOKIEMAN.EXE Detected by UnHackMe: COOKIEMAN.EXE Default location: %LOCAL APPDATA%LOW\COOKIEMAN.EXE Removal Results: Success Number of reboot: [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We received the file <b>COOKIEMAN.EXE</b> and detected that <b>COOKIEMAN.EXE</b> is not good.<br />
<b>COOKIEMAN.EXE</b> is Adware. You should remove the file <b>COOKIEMAN.EXE</b>.<br />
Kill the process <b>COOKIEMAN.EXE</b> and remove <b>COOKIEMAN.EXE</b> from Windows.</p>
<h2>Malware Analysis of COOKIEMAN.EXE<br />
Full path on a computer: %LOCAL APPDATA%LOW\COOKIEMAN.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>COOKIEMAN.EXE</b><br />
Default location: %LOCAL APPDATA%LOW\COOKIEMAN.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>COOKIEMAN.EXE</strong>  is known as:</h3>
<p>Adware.W3I
</p></div>
<div id="clist">
How to quickly detect <strong>COOKIEMAN.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\PKG_1112322080\DETECTIONRULES.DAT
<li>%LOCAL APPDATA%LOW\COOKIEMAN.EXE
<li>\DEVICE\HARDDISKVOLUME1\BOOT\BCD
<li>\DEVICE\HARDDISKVOLUME1\BOOT\BCD.LOG
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/adware/cookieman-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/adware/cookieman-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>COLOUS.EXE is Trojan FrauDrop</title>
		<link>http://greatis.com/blog/how-to-remove-malware/colous-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/colous-exe.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:36 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[COLOUS.EXE]]></category>
		<category><![CDATA[Trojan FrauDrop]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/colous-exe.htm</guid>
		<description><![CDATA[The file COLOUS.EXE can destroy your system, thus making the computer to work abnormally. COLOUS.EXE is a dangerous file. RemoveCOLOUS.EXE from your computer immediately. Kill the process COLOUS.EXE and remove COLOUS.EXE from the Windows startup. Malware Analysis of COLOUS.EXE Full path on a computer: %WINDIR%\COLOUS.EXE Detected by UnHackMe: COLOUS.EXE Default location: %WINDIR%\COLOUS.EXE Removal Results: Success [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>COLOUS.EXE</b> can destroy your system, thus making the computer to work abnormally.<br />
<b>COLOUS.EXE</b> is a dangerous file.<br />
Remove<b>COLOUS.EXE</b> from your computer immediately.<br />
Kill the process <b>COLOUS.EXE</b> and remove <b>COLOUS.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of COLOUS.EXE<br />
Full path on a computer: %WINDIR%\COLOUS.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>COLOUS.EXE</b><br />
Default location: %WINDIR%\COLOUS.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>COLOUS.EXE</strong>  is known as:</h3>
<p>Trojan FrauDrop</p>
<h3><strong>COLOUS.EXE</strong> hash:</h3>
<ul>
MD5: AD83AE05604B32C0380AD26E69CA50CD
</div>
<div id="clist">
How to quickly detect <strong>COLOUS.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>C:\AT-DESTROYER.TXT
<li>%TEMP%\17.TMP\AT-DESTROYER.BAT
<li>%TEMP%\AT-DESTROYER\AT-DESTROYER.EXE
<li>%WINDIR%\COLOUS.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/colous-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/colous-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ACTIVEX1.BIN is Trojan SwfDrop</title>
		<link>http://greatis.com/blog/how-to-remove-malware/activex1-bin.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/activex1-bin.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:35 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[ACTIVEX1.BIN]]></category>
		<category><![CDATA[Trojan SwfDrop]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/activex1-bin.htm</guid>
		<description><![CDATA[The file ACTIVEX1.BIN can destroy your system, thus making the computer to work abnormally. ACTIVEX1.BIN is a dangerous file. RemoveACTIVEX1.BIN from your computer immediately. Kill the process ACTIVEX1.BIN and remove ACTIVEX1.BIN from the Windows startup. Malware Analysis of ACTIVEX1.BIN Full path on a computer: %TEMP%\WORD\ACTIVEX\ACTIVEX1.BIN Detected by UnHackMe: ACTIVEX1.BIN Default location: %TEMP%\WORD\ACTIVEX\ACTIVEX1.BIN Removal Results: Success [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>ACTIVEX1.BIN</b> can destroy your system, thus making the computer to work abnormally.<br />
<b>ACTIVEX1.BIN</b> is a dangerous file.<br />
Remove<b>ACTIVEX1.BIN</b> from your computer immediately.<br />
Kill the process <b>ACTIVEX1.BIN</b> and remove <b>ACTIVEX1.BIN</b> from the Windows startup.</p>
<h2>Malware Analysis of ACTIVEX1.BIN<br />
Full path on a computer: %TEMP%\WORD\ACTIVEX\ACTIVEX1.BIN</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>ACTIVEX1.BIN</b><br />
Default location: %TEMP%\WORD\ACTIVEX\ACTIVEX1.BIN</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>ACTIVEX1.BIN</strong>  is known as:</h3>
<p>Trojan SwfDrop</p>
<h3><strong>ACTIVEX1.BIN</strong> hash:</h3>
<ul>
MD5: E84119E5D1DBF340AA4F601ACBD82BA2
</div>
<div id="clist">
How to quickly detect <strong>ACTIVEX1.BIN</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\WORD\ACTIVEX\ACTIVEX1.BIN
<li>%TEMP%\WORD\ACTIVEX\_RELS\ACTIVEX1.XML.RELS
<li>%TEMP%\WORD\_RELS\DOCUMENT.XML.RELS
<li>%TEMP%\_RELS\.RELS
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/activex1-bin.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/activex1-bin.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>39EIPLUG.DLL is Adware FunWeb</title>
		<link>http://greatis.com/blog/adware/39eiplug-dll.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/adware/39eiplug-dll.htm#comments</comments>
		<pubDate>Sun, 19 May 2013 14:23:35 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[39EIPLUG.DLL]]></category>
		<category><![CDATA[adware FunWeb]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/39eiplug-dll.htm</guid>
		<description><![CDATA[We received the file 39EIPLUG.DLL and detected that 39EIPLUG.DLL is not good. 39EIPLUG.DLL is Adware. You should remove the file 39EIPLUG.DLL. Kill the process 39EIPLUG.DLL and remove 39EIPLUG.DLL from Windows. Malware Analysis of 39EIPLUG.DLL Full path on a computer: %PROGRAMFILES%\MAPSGALAXY_39EI\INSTALLR\1.BIN\39EIPLUG.DLL Detected by UnHackMe: 39EIPLUG.DLL Default location: %PROGRAMFILES%\MAPSGALAXY_39EI\INSTALLR\1.BIN\39EIPLUG.DLL Removal Results: Success Number of reboot: 1 39EIPLUG.DLL [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">We received the file <b>39EIPLUG.DLL</b> and detected that <b>39EIPLUG.DLL</b> is not good.<br />
<b>39EIPLUG.DLL</b> is Adware. You should remove the file <b>39EIPLUG.DLL</b>.<br />
Kill the process <b>39EIPLUG.DLL</b> and remove <b>39EIPLUG.DLL</b> from Windows.</p>
<h2>Malware Analysis of 39EIPLUG.DLL<br />
Full path on a computer: %PROGRAMFILES%\MAPSGALAXY_39EI\INSTALLR\1.BIN\39EIPLUG.DLL</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>39EIPLUG.DLL</b><br />
Default location: %PROGRAMFILES%\MAPSGALAXY_39EI\INSTALLR\1.BIN\39EIPLUG.DLL</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>39EIPLUG.DLL</strong>  is known as:</h3>
<p>Adware FunWeb</p>
<h3><strong>39EIPLUG.DLL</strong> hash:</h3>
<ul>
MD5: FF65CDF22CCBD62B9D360DAD3220B41B
</div>
<div id="clist">
How to quickly detect <strong>39EIPLUG.DLL</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%PROGRAMFILES%\MAPSGALAXY_39EI\INSTALLR\1.BIN\39EIPLUG.DLL
<li>%PROGRAMFILES%\MAPSGALAXY_39EI\INSTALLR\1.BIN\39EZSETP.DLL
<li>%PROGRAMFILES%\MAPSGALAXY_39EI\INSTALLR\1.BIN\NP39EISB.DLL
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/adware/39eiplug-dll.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/adware/39eiplug-dll.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XF-MCCS6.EXE is Worm AMN</title>
		<link>http://greatis.com/blog/worm/xf-mccs6-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/worm/xf-mccs6-exe.htm#comments</comments>
		<pubDate>Sat, 18 May 2013 09:08:48 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[Worm AMN]]></category>
		<category><![CDATA[XF-MCCS6.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/xf-mccs6-exe.htm</guid>
		<description><![CDATA[The file XF-MCCS6.EXE is a computer worm. The worm XF-MCCS6.EXE is a self-replicating malicious program, which uses a computer network to send copies of itself to other computers. You must fix the XF-MCCS6.EXE problem as soon as possible! Delete the file XF-MCCS6.EXE from all infected computers in your network. Set up your network firewall against [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">The file <b>XF-MCCS6.EXE</b> is a computer worm.<br />
The worm <b>XF-MCCS6.EXE</b> is a self-replicating malicious program,<br />
which uses a computer network to send copies of itself to other computers.<br />
You must fix the <b>XF-MCCS6.EXE</b> problem as soon as possible!<br />
Delete the file <b>XF-MCCS6.EXE</b> from all infected computers in your network.<br />
Set up your network firewall against <b>XF-MCCS6.EXE</b> intervention.</p>
<h2>Malware Analysis of XF-MCCS6.EXE<br />
Full path on a computer: %TEMP%\CRACK-WINDOWS\XF-MCCS6.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>XF-MCCS6.EXE</b><br />
Default location: %TEMP%\CRACK-WINDOWS\XF-MCCS6.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>XF-MCCS6.EXE</strong>  is known as:</h3>
<p>Worm AMN</p>
<h3><strong>XF-MCCS6.EXE</strong> hash:</h3>
<ul>
MD5: 1AF76EF8857935EB1D8E46DC9CFE3729
</div>
<div id="clist">
How to quickly detect <strong>XF-MCCS6.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\CRACK-WINDOWS\DISABLE_ACTIVATION.CMD
<li>%TEMP%\CRACK-WINDOWS\INSTALL.TXT
<li>%TEMP%\CRACK-WINDOWS\README.TXT
<li>%TEMP%\CRACK-WINDOWS\XF-MCCS6.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/worm/xf-mccs6-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/worm/xf-mccs6-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VPSCONFIG.EXE is Trojan Downloader</title>
		<link>http://greatis.com/blog/how-to-remove-malware/vpsconfig-exe.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/how-to-remove-malware/vpsconfig-exe.htm#comments</comments>
		<pubDate>Sat, 18 May 2013 09:08:48 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan-downloader]]></category>
		<category><![CDATA[VPSCONFIG.EXE]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/vpsconfig-exe.htm</guid>
		<description><![CDATA[Is the file VPSCONFIG.EXE located on your computer? Then your computer is infected. We do suggest you should remove VPSCONFIG.EXE from your computer as soon as possible. VPSCONFIG.EXE is Trojan/Backdoor. Kill the process VPSCONFIG.EXE and remove VPSCONFIG.EXE from the Windows startup. Malware Analysis of VPSCONFIG.EXE Full path on a computer: %PROGRAMFILES%\NEWMEDIACODEC\VPSCONFIG.EXE Detected by UnHackMe: VPSCONFIG.EXE [...]]]></description>
			<content:encoded><![CDATA[<p class="sign">Is the file <b>VPSCONFIG.EXE</b> located on your computer? Then your computer is infected.<br />
We do suggest you should remove <b>VPSCONFIG.EXE</b> from your computer as soon as possible.<br />
<b>VPSCONFIG.EXE</b> is Trojan/Backdoor.<br />
Kill the process <b>VPSCONFIG.EXE</b> and remove <b>VPSCONFIG.EXE</b> from the Windows startup.</p>
<h2>Malware Analysis of VPSCONFIG.EXE<br />
Full path on a computer: %PROGRAMFILES%\NEWMEDIACODEC\VPSCONFIG.EXE</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>VPSCONFIG.EXE</b><br />
Default location: %PROGRAMFILES%\NEWMEDIACODEC\VPSCONFIG.EXE</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>VPSCONFIG.EXE</strong>  is known as:</h3>
<p>Trojan Downloader
</p></div>
<div id="clist">
How to quickly detect <strong>VPSCONFIG.EXE</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\TMP3.TMP
<li>%TEMP%\TMP3.TMP.BAT
<li>%TEMP%\NSL2.TMP\NSISDL.DLL
<li>%TEMP%\BIT4.TMP
<li>%PROGRAMFILES%\NEWMEDIACODEC\VPSCONFIG.EXE
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/how-to-remove-malware/vpsconfig-exe.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/how-to-remove-malware/vpsconfig-exe.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TRULER 120 GAMEZER.JAR is under review</title>
		<link>http://greatis.com/blog/unknown/truler-120-gamezer-jar.htm#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://greatis.com/blog/unknown/truler-120-gamezer-jar.htm#comments</comments>
		<pubDate>Sat, 18 May 2013 09:08:48 +0000</pubDate>
		<dc:creator>NightWatcher</dc:creator>
				<category><![CDATA[unknown]]></category>
		<category><![CDATA[TRULER 120 GAMEZER.JAR]]></category>
		<category><![CDATA[under review]]></category>

		<guid isPermaLink="false">http://greatis.com/blog/how-to-remove-malware/truler-120-gamezer-jar.htm</guid>
		<description><![CDATA[TRULER 120 GAMEZER.JAR is unknown, probably legitimate. If the file TRULER 120 GAMEZER.JAR is located on your computer, download UnHackMe for free to fix the problem with TRULER 120 GAMEZER.JAR. Malware Analysis of TRULER 120 GAMEZER.JAR Full path on a computer: %TEMP%\E4J8.TMP_DIR23867\TRULER 120 GAMEZER.JAR Detected by UnHackMe: TRULER 120 GAMEZER.JAR Default location: %TEMP%\E4J8.TMP_DIR23867\TRULER 120 GAMEZER.JAR [...]]]></description>
			<content:encoded><![CDATA[<p class="sign"><b>TRULER 120 GAMEZER.JAR</b> is unknown, probably legitimate.<br />
If the file <b>TRULER 120 GAMEZER.JAR</b> is located on your computer, download <a href="http://www.greatis.com/unhackme/download.htm">UnHackMe for free</a> to fix the problem with <b>TRULER 120 GAMEZER.JAR</b>.</p>
<h2>Malware Analysis of TRULER 120 GAMEZER.JAR<br />
Full path on a computer: %TEMP%\E4J8.TMP_DIR23867\TRULER 120 GAMEZER.JAR</h2>
<div id="alist">
<h3>Detected by <a href="http://www.greatis.com/iunhackme">UnHackMe</a>:</h3>
<p><b>TRULER 120 GAMEZER.JAR</b><br />
Default location: %TEMP%\E4J8.TMP_DIR23867\TRULER 120 GAMEZER.JAR</p>
<h3>Removal Results: Success<br />
Number of reboot: 1</h3>
</div>
<div id="blist">
<h3><strong>TRULER 120 GAMEZER.JAR</strong>  is known as:</h3>
<p>Unknow</p>
<h3><strong>TRULER 120 GAMEZER.JAR</strong> hash:</h3>
<ul>
MD5: 998C8D43711A6112B5C8A527E9DB0A3B
</div>
<div id="clist">
How to quickly detect <strong>TRULER 120 GAMEZER.JAR</strong> presence?</p>
<div class="icon"><img title="Files" src="/blog/wp-content/themes/revolution-code-blue/images/files.gif" width="32" height="32" />Files:</div>
<ul>
<li>%TEMP%\CRVA.EXE
<li>%TEMP%\E4J8.TMP_DIR23867\EXE4JLIB.JAR
<li>%TEMP%\E4J8.TMP_DIR23867\I4JDEL.EXE
<li>%TEMP%\E4J8.TMP_DIR23867\TRULER 120 GAMEZER.JAR
</ul>
</div>
<p><!-- end --></p>
<div class="plus-one-wrap"><g:plusone href="http://greatis.com/blog/unknown/truler-120-gamezer-jar.htm"></g:plusone></div><div style='clear:both'></div>]]></content:encoded>
			<wfw:commentRss>http://greatis.com/blog/unknown/truler-120-gamezer-jar.htm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
