<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
	<title>Emsi Software Support English</title>
	<description>Forum news in English language.</description>
	<link>http://support.emsisoft.com</link>
	<pubDate>Sun, 13 May 2012 14:29:26 +0000</pubDate>
	<ttl>10</ttl>
	<image>
		<title>Emsi Software Support English</title>
		<url>http://www.emsisoft.com/images/logos/a2_button_88x31.gif</url>
		<link>http://support.emsisoft.com</link>
	</image>
	<item>
		<title><![CDATA[KMW_SYS.sys - Rootkits can't be removed]]></title>
		<link>http://support.emsisoft.com/topic/8180-kmw-syssys-rootkits-cant-be-removed/</link>
		<description><![CDATA[New here.  Protocols ask for files and logs that do not exist on my pc.  Error message received<br />
<br />
C:&#092;WINDOWS&#092;System32&#092;Drivers&#092;KMW_SYS.sys - Rootkits can't be removed<br />
automatically. Please consult the experts in the Emsisoft online forum for<br />
help with manual removal of this Malware: <a href='http://support.emsisoft.com/' class='bbc_url' title=''>http://support.emsisoft.com</a><br />
<br />
I'm basically a babe in the wood when it comes to this game any help would be appreciated.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11445" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11445" title="Download attachment"><strong>a2scan_120513-042105.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>604bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">4 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11446" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11446" title="Download attachment"><strong>a2scan_120513-042133.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>924bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">4 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11447" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11447" title="Download attachment"><strong>quarantine_120513-091526.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>21.13K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">5 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sun, 13 May 2012 14:29:26 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8180-kmw-syssys-rootkits-cant-be-removed/</guid>
	</item>
	<item>
		<title>Riskware.Win32.InstallCore.AMN!E1 wont delete.</title>
		<link>http://support.emsisoft.com/topic/8178-riskwarewin32installcoreamne1-wont-delete/</link>
		<description><![CDATA[Hi<br />
<br />
Emsisoft found Riskware.Win32.InstallCore.AMN!E1 and wont delete or move it to the quarantine.  Avira found two trojans spy.zbot or somthing like that and found an infection when scaning for rootkits but wont remove it unless i have the full version. I really need some help on what to do next to get rid of these infections thanks.<br />
<br />
- Johnny]]></description>
		<pubDate>Sun, 13 May 2012 04:23:20 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8178-riskwarewin32installcoreamne1-wont-delete/</guid>
	</item>
	<item>
		<title>Virus.Win32.Vundo!E2</title>
		<link>http://support.emsisoft.com/topic/8172-viruswin32vundoe2/</link>
		<description><![CDATA[2 viruses found during Deep Scan: Virus.Win32.Vundo!E2   and    Trojan.Win32.Webprefix!E2<br />
<br />
I tried to follow directions on START HERE but OTL got stalled.<br />
<br />
Can you help me?<br />
<br />
Thank you,<br />
<br />
Jeanne]]></description>
		<pubDate>Sat, 12 May 2012 12:41:01 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8172-viruswin32vundoe2/</guid>
	</item>
	<item>
		<title>Virus.Win32.Obfuscator!IK</title>
		<link>http://support.emsisoft.com/topic/8157-viruswin32obfuscatorik/</link>
		<description><![CDATA[iexplore process starts, and system speakers keep playing advertisements. Virus.Win32.Obfuscator!IK detected by EEK<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11397" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11397" title="Download attachment"><strong>a2scan_120510-120158.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>4.46K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">4 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11398" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11398" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>56.85K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">4 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11399" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11399" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>97.42K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">5 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Thu, 10 May 2012 17:36:47 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8157-viruswin32obfuscatorik/</guid>
	</item>
	<item>
		<title>Conficker helpppppp</title>
		<link>http://support.emsisoft.com/topic/8149-conficker-helpppppp/</link>
		<description><![CDATA[I have 4 different networks with the virus listed below, your antimalware picks it up and removes it but it doesn’t prevent it from being pulled down, Also your scheduled task scans do not remove the threats automatically… please fix.I am still working on this issue but I was wondering if there was anything you would suggest, I have the file guard and behavior blocker enabled, with surf protection. These computers continue to get infected within a couple of hours of removing the conficker virus. Any idea’s?<br />
<br />
-Windows Firewall Group Policy forced enabled<br />
-Computers have all windows updates<br />
-tdsskiller all rootkits<br />
-Clean temp files<br />
-CCleaner reg fix/temp cleaners<br />
^^Have all been applied to the computers and still remain to get infected<br />
<br />
Windows XP Pro in a work environment with multiple sites connected 120+ computers<br />
Thanks<br />
<br />
<a href='http://www.emsisoft.com/en/malware/?Virus.Worm.Downadup!E2' class='bbc_url' title='External link' rel='external'>http://www.emsisoft.com/en/malware/?Virus.Worm.Downadup!E2</a>]]></description>
		<pubDate>Wed, 09 May 2012 21:00:24 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8149-conficker-helpppppp/</guid>
	</item>
	<item>
		<title>cant locate definition of infections</title>
		<link>http://support.emsisoft.com/topic/8138-cant-locate-definition-of-infections/</link>
		<description><![CDATA[I found this when I was scanning a friends computer.  He got these files from school.  I am trying to research where these came from.  Is it possible they are positive negatives?<br />
<br />
<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;History&#092;Level2&#092;C&#092;Program Files (x86)&#092;Yontoo Layers Runtime&#092;YontooIEClient.dll  detected: Adware.Win32.Yontoo.A!E1<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 4-6&#092;cdaclas1_MSH.exe  detected: Trojan.Win32.KillFiles!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 4-6&#092;copydata_MSH.exe  detected: Trojan.Win32.Shutdowner!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 4-6&#092;For fun&#092;collatz.exe  detected: Trojan.Win32.Regrun!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 4-6&#092;For fun&#092;change2_MSH.exe  detected: Trojan.Win32.Shutdowner!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 1-3&#092;multdivide.exe  detected: Trojan.Win32.Regrun!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 1-3&#092;Various Practice&#092;charprac.exe  detected: Trojan.Win32.Regrun!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 1-3&#092;Just Fo' Fun&#092;boardfoot.exe  detected: Trojan.Win32.Regrun!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 1-3&#092;factors_MSH.exe  detected: Trojan.Win32.Regrun!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 1-3&#092;Just Fo' Fun&#092;square_root.exe  detected: Trojan.Win32.Shutdowner!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 4-6&#092;stream1a.exe  detected: Trojan.Win32.Shutdowner!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;Documents&#092;School Stuff&#092;High&#092;Senior&#092;D C++ Programming&#092;Chapters 4-6&#092;For fun&#092;getprac.exe  detected: Trojan.Win32.KillFiles!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;AppData&#092;LocalLow&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;6.0&#092;16&#092;3a8d4910-2946cbce -&gt; ER.class  detected: Exploit.Java.CVE-2010!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;AppData&#092;LocalLow&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;6.0&#092;16&#092;3a8d4910-2946cbce -&gt; b.class  detected: Exploit.Java.CVE-2010!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;AppData&#092;LocalLow&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;6.0&#092;16&#092;3a8d4910-2946cbce -&gt; Inc.class  detected: Exploit.Java.CVE-2011!E2<br />
J:&#092;Seagate Backup&#092;THEOMNIMAX-PC&#092;C&#092;Users&#092;The Omnimax&#092;AppData&#092;LocalLow&#092;Sun&#092;Java&#092;Deployment&#092;cache&#092;6.0&#092;16&#092;3a8d4910-2946cbce -&gt; c.class  detected: Exploit.Java.CVE-2010!E2]]></description>
		<pubDate>Tue, 08 May 2012 22:04:42 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8138-cant-locate-definition-of-infections/</guid>
	</item>
	<item>
		<title>my pc infected by virus-Win32.virut.E2</title>
		<link>http://support.emsisoft.com/topic/8136-my-pc-infected-by-virus-win32virute2/</link>
		<description><![CDATA[<span style='color: #555555'><span style='font-family: arial, helvetica,'>Good evening, </span></span><br />
<span style='color: #555555'><span style='font-family: arial, helvetica,'>My PC is infected by the viruswin-32.virutE2 the access path isC:&#092;windows&#092;systeme32&#092;drivers&#092;http.sys,</span></span><br />
<span style='color: #555555'><span style='font-family: arial, helvetica,'> I provide you a copy of the report of scan. </span></span><span style='color: #555555'><span style='font-family: arial, helvetica,'>My English ispoor then if you could E answer in French it would be well</span></span><br />
<span style='color: #555555'><span style='font-family: arial, helvetica,'>I cannot quarantine it, can you bring to me of the assistance.</span></span><br />
<span style='color: #555555'><span style='font-family: arial, helvetica,'> Cordially.</span></span><br />
 <br />
<span style='color: #555555'><span style='font-family: arial, helvetica,'>Version - Emsisoft Anti-Malware 6.5</span></span><br />
Dernière mise à jour : 08/05/2012 10:01:36<br />
<br />
Paramètres du balayage :<br />
<br />
Type de balayage : Scan en Détail<br />
Objets : Rootkits, Mémoire, Traces, C:&#092;, D:&#092;<br />
Recherche dans les archives : Marche<br />
Balayage des ADS : Marche<br />
<br />
Début de l'analyse :		    08/05/2012 11:46:09<br />
<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;http.sys 		    Objets détectés : Virus.Win32.Virut!E2<br />
<br />
Analysé		    416102<br />
Objets trouvés		    1<br />
<br />
Fin du balayage :		    08/05/2012 12:56:27<br />
Temps de balayage :		    1:10:18<br />
<br />
<br />
En quarantaine		    0]]></description>
		<pubDate>Tue, 08 May 2012 20:00:26 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8136-my-pc-infected-by-virus-win32virute2/</guid>
	</item>
	<item>
		<title>Ebay Confirm your identity malware</title>
		<link>http://support.emsisoft.com/topic/8130-ebay-confirm-your-identity-malware/</link>
		<description><![CDATA[Please can you help me?<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11364" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11364" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>59.97K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">9 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11365" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11365" title="Download attachment"><strong>a2scan_120508-131723.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>45.72K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">8 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11366" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11366" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>79K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">9 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 08 May 2012 13:00:40 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8130-ebay-confirm-your-identity-malware/</guid>
	</item>
	<item>
		<title>Ebay etc. confim your identity malware</title>
		<link>http://support.emsisoft.com/topic/8097-ebay-etc-confim-your-identity-malware/</link>
		<description><![CDATA[Could you please assist me with my computer that has been infected causing windows to pop up when using sites such as ebay. These windows request personal credit card info. It also seems to have severely slowed down the functioning of my web browsers. I have attached the required files.<br />
<br />
Thanks<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11333" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11333" title="Download attachment"><strong>a2scan_120505-103641.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>16.37K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11334" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11334" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>61.11K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">3 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11335" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11335" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>48.55K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">3 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 05 May 2012 11:11:17 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8097-ebay-etc-confim-your-identity-malware/</guid>
	</item>
	<item>
		<title>Trace.Registry.palevo!E1  cannot delete</title>
		<link>http://support.emsisoft.com/topic/8096-traceregistrypalevoe1-cannot-delete/</link>
		<description>Emsisoft Anti-Malware  scan  Trace.Registry.palevo!E1  cannot delete  why cannot delete？？</description>
		<pubDate>Sat, 05 May 2012 09:53:41 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8096-traceregistrypalevoe1-cannot-delete/</guid>
	</item>
	<item>
		<title>Root Kits removel</title>
		<link>http://support.emsisoft.com/topic/8090-root-kits-removel/</link>
		<description><![CDATA[Hello. I got two recurring trojans on my weekley scan.<br />
They are Trojan.win32.hider!e2 and trojan.sirefef!E2.<br />
The rootkit is C:&#092;WINDOWS&#092;SYSTEM32&#092;DRIVERS&#092;MRXSMB.SYS<br />
Then it tells me that c:&#092;windows&#092;system32&#092;hpqcxs08.dll is locked <br />
and will be removed on next reboot. Problem is it comes back after <br />
reboot. Any help would be greatly appreciated. <br />
<br />
Thank you.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11320" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11320" title="Download attachment"><strong>a2scan_120430-111008.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>2.25K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11321" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11321" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>49.81K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11322" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11322" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>77.53K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">4 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Fri, 04 May 2012 17:16:22 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8090-root-kits-removel/</guid>
	</item>
	<item>
		<title>Amazon, ebay and paypal identification popups en slow internet</title>
		<link>http://support.emsisoft.com/topic/8088-amazon-ebay-and-paypal-identification-popups-en-slow-internet/</link>
		<description><![CDATA[Since a few days I have had several suspicious popups regarding identification from amazon, ebay and paypal even when I was not visiting their websites. At first I thought it was just another phishing attempt so I refreshed my browser and was able to continue with the internet.<br />
But now internet just gets slower with each day. I have run several virus scans, but the popups still continue.<br />
After googling I discovered this forum and read the instruction and created all the logs you need. Can you please help me? Thank you!<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11315" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11315" title="Download attachment"><strong>a2scan_120504-112300.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>9.95K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">7 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11316" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11316" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>70.6K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">8 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11317" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11317" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>93.96K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">5 downloads</span>]]></description>
		<pubDate>Fri, 04 May 2012 15:00:47 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8088-amazon-ebay-and-paypal-identification-popups-en-slow-internet/</guid>
	</item>
	<item>
		<title>New test-VirusBulletin</title>
		<link>http://support.emsisoft.com/topic/8068-new-test-virusbulletin/</link>
		<description><![CDATA[New Test for Windows XP SP3:<br />
<br />
<br />
<strong class='bbc'>F</strong><strong class='bbc'>ailed Test</strong>: <em class='bbc'>1 False Positive:</em> <a href='http://www.virusbtn.com/vb100/archive/test?recent=1' class='bbc_url' title='External link' rel='external'>http://www.virusbtn.com/vb100/archive/test?recent=1</a><br />
RAP Averages (I don´t find Emsisoft): <a href='http://www.virusbtn.com/vb100/RAP/RAP-quadrant-Oct11-Apr12-large.jpg' class='bbc_url' title='External link' rel='external'>http://www.virusbtn.com/vb100/RAP/RAP-quadrant-Oct11-Apr12-large.jpg</a>]]></description>
		<pubDate>Fri, 04 May 2012 00:07:35 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8068-new-test-virusbulletin/</guid>
	</item>
	<item>
		<title>Ebay/ccbill/Online Banking confirm your identity and/or security confirmation malware</title>
		<link>http://support.emsisoft.com/topic/8066-ebayccbillonline-banking-confirm-your-identity-andor-security-confirmation-malware/</link>
		<description><![CDATA[Hey guys,<br />
<br />
my post pretty much has the same content as phil0sophy's had earlier (<a href='http://support.emsisoft.com/topic/8041-yet-another-ebayccbill-confirm-your-identity-malware-hijacker/' class='bbc_url' title=''>http://support.emsisoft.com/topic/8041-yet-another-ebayccbill-confirm-your-identity-malware-hijacker/</a>).<br />
I wasn't quite sure if I should start a new thread or comment on phil0sophy's. If I chose the wrong option I'd like to excuse myself in advance!<br />
<br />
So as the topic already says, when I start the eBay, Amazon or my online banking website, I occasionally get asked for a confirmation of my security or account details. Of course I did not fill in anything whatsoever, but I guess that's something I should take care of right <img src='http://support.emsisoft.com/public/style_emoticons/default/wink.png' class='bbc_emoticon' alt=';)' />?<br />
<br />
Thanks a lot in advance and you guys cannot be appreciated enough for what you're doing here!<br />
<br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11291" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11291" title="Download attachment"><strong>a2scan_120503-152243.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>31.36K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">5 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11292" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11292" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>27.29K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">4 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11293" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11293" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>52.62K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">5 downloads</span>]]></description>
		<pubDate>Thu, 03 May 2012 16:08:53 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8066-ebayccbillonline-banking-confirm-your-identity-andor-security-confirmation-malware/</guid>
	</item>
	<item>
		<title>Malware Win32.AMN!E1 In Quarantine.</title>
		<link>http://support.emsisoft.com/topic/8061-malware-win32amne1-in-quarantine/</link>
		<description><![CDATA[Hello!<br />
Currently in Quarantine in your Anti-Malware program are 2 source's of Malware.Win32.AMN!E1. I was only able to quarantine them but not delete until yesterday's update. I am worried that a delete will not be enough. <br />
<br />
Could you please tell me how to proceed. <br />
<br />
The required tests were run with Emergency Kit and OTL and are attached. <br />
THANKS!!!! <a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11272" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11272" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>87.2K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">8 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11273" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11273" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>79.12K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">10 downloads</span>]]></description>
		<pubDate>Thu, 03 May 2012 01:56:54 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8061-malware-win32amne1-in-quarantine/</guid>
	</item>
	<item>
		<title>Help, is my PC infected please</title>
		<link>http://support.emsisoft.com/topic/8048-help-is-my-pc-infected-please/</link>
		<description><![CDATA[At the request of Fabian Wosar I am sending 3 logs.  EEK scan, OTL & Extras.<br />
<br />
So many weird things have been happening, unwanted files appearing, pages hanging, sound distorted etc. etc.  Emsisoft sometimes freezes in middle of scans, Outlook express hangs & have many Emsisoft Guard logs of suspected malware attacks, also services turn themselves on/off & enable/unable themselves.  Grateful for your advice.  Many thanks.<br />
<br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11246" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11246" title="Download attachment"><strong>a2scan_120501-175530.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>956bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">8 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11247" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11247" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>61.28K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">11 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11248" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11248" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>26.91K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">5 downloads</span>]]></description>
		<pubDate>Wed, 02 May 2012 07:39:56 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8048-help-is-my-pc-infected-please/</guid>
	</item>
	<item>
		<title>Yet another Ebay/ccbill confirm your identity malware/ Hijacker</title>
		<link>http://support.emsisoft.com/topic/8041-yet-another-ebayccbill-confirm-your-identity-malware-hijacker/</link>
		<description><![CDATA[Hey there,<br />
<br />
I am having the same issues as a few others on here, keep getting a pop up with certain sites like ebay and other sites that need log in`s requiring me to enter my bank details and atm pin, which obviously I have not done, Browsing is very slow and it seems to be a browser hijacker or redirection of some sort but I will let the experts decide as I am probably way off the mark, I have all the logs you require attached.<br />
<br />
<br />
Thanks very much and I really appreciate any help you can or may give me.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11237" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11237" title="Download attachment"><strong>a2scan_120501-183556.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>13.07K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">8 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11238" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11238" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>116.02K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">7 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11239" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11239" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>150.07K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 01 May 2012 19:49:42 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8041-yet-another-ebayccbill-confirm-your-identity-malware-hijacker/</guid>
	</item>
	<item>
		<title><![CDATA[plz &#62;&#62;&#62; i need help]]></title>
		<link>http://support.emsisoft.com/topic/8032-plz-i-need-help/</link>
		<description><![CDATA[hi&gt;&gt;&gt;<br />
<br />
plz see <br />
<br />
attach files<br />
<br />
i had delete ftmgr.sys+ntoskrnl.sys  from syestem 32?? because blue screean  the problem know in norton<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11215" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/gif.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11215" title="Download attachment"><strong>29.bmp</strong></a> &nbsp;&nbsp;<span class='desc'><strong>750.05K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">9 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11216" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/gif.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11216" title="Download attachment"><strong>30.bmp</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.2MB</strong></span>
&nbsp;&nbsp;<span class="desc lighter">9 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 30 Apr 2012 18:43:25 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8032-plz-i-need-help/</guid>
	</item>
	<item>
		<title>How to remove this Malware.</title>
		<link>http://support.emsisoft.com/topic/8030-how-to-remove-this-malware/</link>
		<description><![CDATA[&#092;&#092;.&#092;PhysicalDrive0 - Rootkits can't be removed automatically. Please consult the experts in the Emsisoft online forum for help with manual removal of this Malware: <a href='http://support.emsisoft.com' class='bbc_url' title=''>http://support.emsisoft.com</a><br />
<br />
<br />
1.http://i45.tinypic.com/1g5dn6.jpg<br />
<br />
When i try to remove or quartine this it shows as below..<br />
<br />
2.http://i45.tinypic.com/vnhwep.jpg<br />
<br />
With warning as-"&#092;&#092;.&#092;PhysicalDrive0 - Rootkits can't be removed automatically. Please consult the experts in the Emsisoft online forum for help with manual removal of this Malware: <a href='http://support.emsisoft.com' class='bbc_url' title=''>http://support.emsisoft.com"</a><br />
<br />
Please let me know the solution.<br />
<br />
I will be very thankfull 2 u.<br />
<br />
<span style='font-size: 48px;'><span style='color: #B22222'><span class='bbc_underline'><em class='bbc'><strong class='bbc'>Reports are attached</strong></em></span></span></span><div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11210" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11210" title="Download attachment"><strong>a2scan_120430-181517.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.76K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">12 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11211" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11211" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>33.88K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">8 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11212" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11212" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>617.68K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">12 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 30 Apr 2012 15:50:14 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8030-how-to-remove-this-malware/</guid>
	</item>
	<item>
		<title>How to remove this Malware.</title>
		<link>http://support.emsisoft.com/topic/8018-how-to-remove-this-malware/</link>
		<description><![CDATA[1.<a href='http://i45.tinypic.com/1g5dn6.jpg' class='bbc_url' title='External link' rel='external'>http://i45.tinypic.com/1g5dn6.jpg</a><br />
<span style='color: #ff0000'>When i try to remove or quartine this it shows as below..</span><br />
2.<a href='http://i45.tinypic.com/vnhwep.jpg' class='bbc_url' title='External link' rel='external'>http://i45.tinypic.com/vnhwep.jpg</a><br />
<br />
With warning as-"<span style='color: #008000'>&#092;&#092;.&#092;PhysicalDrive0 - Rootkits can't be removed automatically. Please consult the experts in the Emsisoft online forum for help with manual removal of this Malware: <a href='http://support.emsisoft.com' class='bbc_url' title=''>http://support.emsisoft.com</a></span>"<br />
<br />
<span class='bbc_underline'><em class='bbc'><strong class='bbc'><span style='color: #800000'>Please let me know the solution</span></strong></em></span>.<br />
<br />
I will be very thankfull 2 u.]]></description>
		<pubDate>Sun, 29 Apr 2012 12:52:08 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8018-how-to-remove-this-malware/</guid>
	</item>
	<item>
		<title>Programs keep launching in multiples by themselves</title>
		<link>http://support.emsisoft.com/topic/8016-programs-keep-launching-in-multiples-by-themselves/</link>
		<description><![CDATA[I downloaded a PDF from an insurance agent and within the hour my PC was sluggish and freezing.<br />
<br />
I ran Emsisoft to see what the problem was and it came back with a few trojans and a rootkit.  Tried the delete selected and was told the rootkit could not be removed and was pointed here.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11188" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11188" title="Download attachment"><strong>a2scan_120427-190032.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>28.75K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">12 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11189" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11189" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>90.06K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11190" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11190" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>51.92K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">8 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 28 Apr 2012 20:29:16 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8016-programs-keep-launching-in-multiples-by-themselves/</guid>
	</item>
	<item>
		<title>rootkit problem</title>
		<link>http://support.emsisoft.com/topic/8005-rootkit-problem/</link>
		<description><![CDATA[Attached are results for EEK and OTL scans. I am sending these from a different computer as my computer will not let me get on your site. I do not get the security or verification text boxes. My computer is very sluggish and I get sent to strange sites on the internet. The original scan report with your malware program is also attached. Thanks, bar<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11168" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11168" title="Download attachment"><strong>a2scan_120426-172925.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>2.11K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">5 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11169" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11169" title="Download attachment"><strong>a2scan_120427-060923.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>978bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">5 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11170" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11170" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>278.79K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">7 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11171" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11171" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>61.93K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">4 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Fri, 27 Apr 2012 14:44:47 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/8005-rootkit-problem/</guid>
	</item>
	<item>
		<title>Virus.Win32.Vundo!E2</title>
		<link>http://support.emsisoft.com/topic/7980-viruswin32vundoe2/</link>
		<description><![CDATA[Please see the attached regarding the above named issue that could not be deleted or quarantined.<br />
Thank you-<br />
<br />
Mike<br />
<br />
(518)280-9907<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11125" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11125" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>41.09K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">7 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11126" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11126" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>55.07K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11127" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11127" title="Download attachment"><strong>a2scan_120425-111618.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>894bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">8 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 25 Apr 2012 19:03:44 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7980-viruswin32vundoe2/</guid>
	</item>
	<item>
		<title><![CDATA[Another Ebay &#34;Confirm your identity&#34; pop-up virus]]></title>
		<link>http://support.emsisoft.com/topic/7977-another-ebay-confirm-your-identity-pop-up-virus/</link>
		<description><![CDATA[Hi!<br />
<br />
I got pretty much the same problem as the other dude who posted about this topic. Internet browsing has become super slow, IE does not even work. When I search some sites I get this pop-up that wants me to confirm my identity with my credit card details.<br />
<br />
Please help and thx in prespect!<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11116" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11116" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>62.29K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">9 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11117" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11117" title="Download attachment"><strong>a2scan_120425-120743.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>11.77K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11118" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11118" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>67.96K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">11 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 25 Apr 2012 11:29:35 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7977-another-ebay-confirm-your-identity-pop-up-virus/</guid>
	</item>
	<item>
		<title>Trojan.Qhost.CU!IK</title>
		<link>http://support.emsisoft.com/topic/7975-trojanqhostcuik/</link>
		<description><![CDATA[windows xp sp3 need help removing Trojan.Qhost.CU!IK<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11112" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11112" title="Download attachment"><strong>a2scan_120424-125013.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>5.22K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">9 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11113" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11113" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>42.64K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">19 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11114" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11114" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>67.18K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 24 Apr 2012 20:50:32 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7975-trojanqhostcuik/</guid>
	</item>
	<item>
		<title><![CDATA[Can't Browse or Ping Microsoft sites]]></title>
		<link>http://support.emsisoft.com/topic/7967-cant-browse-or-ping-microsoft-sites/</link>
		<description><![CDATA[On April 10, I could not log in to my Hotmail account.  I then find that i cannot browse or ping Microsoft sites.  I scanned with several anti-virus/malware programs.  Only Emsisoft online scanner found Torjan.win32.scar!1k.  I quarantined the infection, but the problem did not go away.  I went to your site and followed the instructions on running the emergency kit and OTL on April 13.  I was on vacation for a week, so I waited to run them again today.  The OTL did not create a new Extras.txt file, so I am attaching the file from April 13.  Can you help me with this problem?  Thanks.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11099" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11099" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>77.43K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11100" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11100" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>53.99K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11101" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11101" title="Download attachment"><strong>a2scan_120423-092452.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>17.83K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">11 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 23 Apr 2012 18:34:11 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7967-cant-browse-or-ping-microsoft-sites/</guid>
	</item>
	<item>
		<title>sending logs</title>
		<link>http://support.emsisoft.com/topic/7966-sending-logs/</link>
		<description><![CDATA[here are the logs requested.  Also, when I try to use facebook through google chrome, I get a safety signature error.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11095" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11095" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>119.22K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11096" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11096" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>71.12K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">7 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11097" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11097" title="Download attachment"><strong>a2scan_120423-082538.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>11.31K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">5 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 23 Apr 2012 16:20:56 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7966-sending-logs/</guid>
	</item>
	<item>
		<title><![CDATA[Computer infected with Trojan:DOS&#092;Alureon]]></title>
		<link>http://support.emsisoft.com/topic/7959-computer-infected-with-trojandosalureon/</link>
		<description><![CDATA[I have tried to run several virus scanners but nothing seems to remove the virus.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11089" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11089" title="Download attachment"><strong>Emisoft Emergency Kit log.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>7.86K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">10 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11090" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11090" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>149.95K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11091" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11091" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>50.15K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sun, 22 Apr 2012 19:17:51 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7959-computer-infected-with-trojandosalureon/</guid>
	</item>
	<item>
		<title>After running Anti-Malware still do not see folder on desktop or C:</title>
		<link>http://support.emsisoft.com/topic/7946-after-running-anti-malware-still-do-not-see-folder-on-desktop-or-c/</link>
		<description><![CDATA[I had an SMART HDD infection and rab your product to clean it up. IT had one file identified as suspect ,but the message when it went to quanatine it was "file not found". When the infection started desktop went black, Exploer favorites showed empty and got lots of mesages about hard drive errors. Since cleaning the messages have stopped, but I still can not see my files. Isuspect they are still there but that the permissions got messed with and took away visibility. Since I wasn;t sure I was clean, I downloaded emergency kit and completed the task listed and have attached the results.<br />
<br />
Most important is confirmation that my mchine is clean. If you can help with how to fix visiblity that 's great, but I may be able to sort that by myself.<br />
<br />
<br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11043" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11043" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>44.12K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">6 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11044" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11044" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>52.38K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">7 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11045" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11045" title="Download attachment"><strong>a2scan_120419-222954.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>20.4K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">11 downloads</span>]]></description>
		<pubDate>Fri, 20 Apr 2012 11:22:21 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7946-after-running-anti-malware-still-do-not-see-folder-on-desktop-or-c/</guid>
	</item>
	<item>
		<title><![CDATA[What happened to my &#34;Resizer&#34; thread?]]></title>
		<link>http://support.emsisoft.com/topic/7942-what-happened-to-my-resizer-thread/</link>
		<description><![CDATA[What it removed? Was it in the wrong section and was moved to another section?<br />
<br />
Also, why didn't a moderator from the Emsisoft forum contact me and explain to me what happened?]]></description>
		<pubDate>Fri, 20 Apr 2012 02:54:27 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7942-what-happened-to-my-resizer-thread/</guid>
	</item>
	<item>
		<title>trojan Rootkit- Help!</title>
		<link>http://support.emsisoft.com/topic/7937-trojan-rootkit-help/</link>
		<description><![CDATA[Hello,<br />
<br />
I've recently been battling a nasty Trojan Rootkit on my company computer. I ran the Emsisoft software and it recommended I post to the forums.<br />
<br />
I am unable to use my computer effectively about 70% of the time.<br />
<br />
Attached are the three logs requested. I hope I did them right.<br />
<br />
Please any help would be GREATLY appreciated!!<br />
<br />
Thank-you in advance!<br />
Sarah<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11032" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11032" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>222.85K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">11 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11033" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11033" title="Download attachment"><strong>a2scan_120418-120839.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>7.3K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">11 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11034" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11034" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>32.15K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">31 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Thu, 19 Apr 2012 17:15:22 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7937-trojan-rootkit-help/</guid>
	</item>
	<item>
		<title>Trojan.Qhost.E! infection</title>
		<link>http://support.emsisoft.com/topic/7930-trojanqhoste-infection/</link>
		<description><![CDATA[I can't use google searches anymore since This trojan showed up. I am always redirected to other sites.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11022" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11022" title="Download attachment"><strong>a2scan_120418-194646.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>7.3K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">9 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11023" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11023" title="Download attachment"><strong>Extras.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>21.99K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">5 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11024" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11024" title="Download attachment"><strong>OTL.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>36.48K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">10 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Thu, 19 Apr 2012 05:24:57 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7930-trojanqhoste-infection/</guid>
	</item>
	<item>
		<title>Evasion attacks expoliting file-parsing vulnerabilities in antivirus products</title>
		<link>http://support.emsisoft.com/topic/7923-evasion-attacks-expoliting-file-parsing-vulnerabilities-in-antivirus-products/</link>
		<description><![CDATA[<span style='font-size: 14px;'><a href='http://seclists.org/bugtraq/2012/Mar/88?utm_source=twitterfeed&utm_medium=twitter' class='bbc_url' title='External link' rel='external'>http://seclists.org/bugtraq/2012/Mar/88?utm_source=twitterfeed&utm_medium=twitter</a></span><br />
<br />
<br />
<span style='font-size: 14px;'>Bad result for EAM (19 vulnerabilities).<br />
<br />
I hope EAM improves these problems.</span>]]></description>
		<pubDate>Wed, 18 Apr 2012 00:15:38 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7923-evasion-attacks-expoliting-file-parsing-vulnerabilities-in-antivirus-products/</guid>
	</item>
	<item>
		<title>Trojan when accessing online banking, H2 remove?</title>
		<link>http://support.emsisoft.com/topic/7917-trojan-when-accessing-online-banking-h2-remove/</link>
		<description><![CDATA[Hi, when accessing my online banking account i get this page (see attachment trojan-pic.png<a class='resized_img' rel='lightbox[48174]' id='ipb-attach-url-11002-0-48442600-1337200829' href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=11002" title="trojan-pic.PNG - Size: 23.45K, Downloads: 26"><img src="http://support.emsisoft.com/uploads/monthly_04_2012/post-22323-0-86222000-1334654079_thumb.png" id='ipb-attach-img-11002-0-48442600-1337200829' style='width:100;height:88' class='attach' width="100" height="88" alt="Attached Image: trojan-pic.PNG" /></a>).<br />
<br />
I have run all your suggested tools, see attached log files. Help is appreciated.<br />
<br />
Thanks!<br />
<br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11003" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11003" title="Download attachment"><strong>a2scan_120416-203610.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>15.58K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">12 downloads</span><br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11004" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11004" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>98.17K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">19 downloads</span><br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11005" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=11005" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>77.83K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">9 downloads</span>]]></description>
		<pubDate>Tue, 17 Apr 2012 09:16:56 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7917-trojan-when-accessing-online-banking-h2-remove/</guid>
	</item>
	<item>
		<title>Rootkit.Win32.ZAccess!E2</title>
		<link>http://support.emsisoft.com/topic/7903-rootkitwin32zaccesse2/</link>
		<description><![CDATA[Hi,<br />
<br />
After running Emsisoft Malware, there is a rootkit (Rootkit.Win32.ZAccess!E2) that cannot be removed automatically and requires your support please. I attached the 3 files required from the instructions.<br />
<br />
I thank you a lot for your attention and your help.<br />
<br />
Sincerely,<br />
Candide.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10986" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10986" title="Download attachment"><strong>a2scan_120416-105217.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>2.05K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">13 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10987" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10987" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>81.42K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">8 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10988" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10988" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>39.52K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">8 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 16 Apr 2012 16:31:50 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7903-rootkitwin32zaccesse2/</guid>
	</item>
	<item>
		<title><![CDATA[Can't get rid of Search Browsing (www.searchbrowsing.com) from Internet Explorer 9]]></title>
		<link>http://support.emsisoft.com/topic/7866-cant-get-rid-of-search-browsing-wwwsearchbrowsingcom-from-internet-explorer-9/</link>
		<description><![CDATA[I have somehow got a highjacker on my system, and I've tried different things, including your malware scanner, but to no avail.<br />
<br />
I think I've got rid of it from Firefox, but in Internet Explorer, as soon as I change the start page, it's changed back to searchbrowser again.<br />
<br />
I enclose the reports you've asked for.<br />
<br />
Roy<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10940" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10940" title="Download attachment"><strong>a2scan_120413-094445.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.52K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10941" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10941" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>49.47K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">13 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10942" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10942" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>477.34K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">10 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Fri, 13 Apr 2012 09:54:40 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7866-cant-get-rid-of-search-browsing-wwwsearchbrowsingcom-from-internet-explorer-9/</guid>
	</item>
	<item>
		<title>How do I remove/delete these?</title>
		<link>http://support.emsisoft.com/topic/7865-how-do-i-removedelete-these/</link>
		<description><![CDATA[Software directed me to this site to find out how to remove/delete the following:<br />
<br />
C:&#092;WINDOWS&#092;System32&#092;Drivers&#092;mrxsmb.sys<br />
<br />
c:&#092;windows&#092;system32&#092;smserial.dll]]></description>
		<pubDate>Fri, 13 Apr 2012 01:06:39 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7865-how-do-i-removedelete-these/</guid>
	</item>
	<item>
		<title>Daily testing:</title>
		<link>http://support.emsisoft.com/topic/7859-daily-testing/</link>
		<description><![CDATA[<strong class='bbc'>Daily Test: </strong>	 <a href='http://www.shadowserver.org/wiki/pmwiki.php/AV/VirusDailyStats' class='bbc_url' title='External link' rel='external'>http://www.shadowser...VirusDailyStats</a><br />
<br />
<strong class='bbc'>Weekly Test:</strong>  <a href='http://www.shadowserver.org/wiki/pmwiki.php/AV/VirusWeeklyStats' class='bbc_url' title='External link' rel='external'>http://www.shadowser...irusWeeklyStats</a><br />
<br />
<strong class='bbc'>Monthly Test: </strong><a href='http://www.shadowserver.org/wiki/pmwiki.php/AV/VirusMonthlyStats' class='bbc_url' title='External link' rel='external'>http://www.shadowser...rusMonthlyStats</a><br />
<br />
<br />
Today, Emsisoft is among the best.]]></description>
		<pubDate>Thu, 12 Apr 2012 16:24:22 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7859-daily-testing/</guid>
	</item>
	<item>
		<title>trojan crypt cannot remove</title>
		<link>http://support.emsisoft.com/topic/7836-trojan-crypt-cannot-remove/</link>
		<description><![CDATA[Am unable to remove trojan.crypt, I have disabled system restore as it said the trojan was their, but it still remains? I was unsure as I run/use Emsisoft Anti-Malware whether I should run the emergency scan. Any help would be appreciated - OTL scan is attached. Tony Cole.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10906" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10906" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>39.06K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">11 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10907" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10907" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>80.58K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">10 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 10 Apr 2012 14:42:21 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7836-trojan-crypt-cannot-remove/</guid>
	</item>
	<item>
		<title>I have Malware.Win32.AMN</title>
		<link>http://support.emsisoft.com/topic/7831-i-have-malwarewin32amn/</link>
		<description><![CDATA[I scanned my computer and found that I have Malware.Win32.AMN and when I ran emsissoft anti-malware 6.0 it scanned everything and then I quarantined the selected file and I need help with the manual removal of this malware.<br />
<br />
The files that couldn't be removed by EA6.0 are:<br />
<br />
AdWare.BHO!E2<br />
Trojan.SuspectCRC!E2<br />
BH0.Win32.Zwangi!E2<br />
<br />
<br />
All help will be greatly appreciated.<br />
<br />
edit:<br />
<br />
Im doing the emergency kit and OTL scans and will post those files when they are complete.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10874" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10874" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>87.59K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">15 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10875" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10875" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>48.19K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">15 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 09 Apr 2012 17:56:19 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7831-i-have-malwarewin32amn/</guid>
	</item>
	<item>
		<title>ZMRYKR0PWA HELP!</title>
		<link>http://support.emsisoft.com/topic/7830-zmrykr0pwa-help/</link>
		<description><![CDATA[I've scanned my computer and found ZMRYKR0PWA.exe, which seems impossible to delete. My antivirus do not work, they seem blocked by this trojan.<br />
Anyone knows how to delete it?<br />
Thank you]]></description>
		<pubDate>Mon, 09 Apr 2012 17:16:49 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7830-zmrykr0pwa-help/</guid>
	</item>
	<item>
		<title>Stepped away from the computer and PC shutdown.</title>
		<link>http://support.emsisoft.com/topic/7821-stepped-away-from-the-computer-and-pc-shutdown/</link>
		<description><![CDATA[I stepped away from the computer and my pc shutdown. Would really like someone to check my hijackfree log.<br />
<a href='http://analyze.hijackfree.com/analyze/?id=38e57dea-69e9-4d31-88f6-90f8f9422449' class='bbc_url' title='External link' rel='external'>http://analyze.hijackfree.com/analyze/?id=38e57dea-69e9-4d31-88f6-90f8f9422449</a>]]></description>
		<pubDate>Mon, 09 Apr 2012 12:36:13 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7821-stepped-away-from-the-computer-and-pc-shutdown/</guid>
	</item>
	<item>
		<title>How do i delete a Rootkey?</title>
		<link>http://support.emsisoft.com/topic/7805-how-do-i-delete-a-rootkey/</link>
		<description><![CDATA[<span style='color: red'>&lt;log removed from post&gt;</span><div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10862" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10862" title="Download attachment"><strong>a2scan_120406-231524.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>21.81K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">10 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10863" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10863" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>75.63K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10864" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10864" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>42.69K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">11 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 07 Apr 2012 10:27:47 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7805-how-do-i-delete-a-rootkey/</guid>
	</item>
	<item>
		<title>Detected: Trojan-Banker.Win32.Banbra!E2</title>
		<link>http://support.emsisoft.com/topic/7798-detected-trojan-bankerwin32banbrae2/</link>
		<description><![CDATA[Hello there, I come to you with the same problem: Trojan-Banker.Win32.Banbra!E2. You resovled it  a few day ago and it is there again. Emsisoft Emergency Kit says that there are no infections, but Emsisoft Anti-Malware - Version 6.0 says there is. What should I do? Do I follow the previous direction or should I wait for a new one? Thank You.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10850" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10850" title="Download attachment"><strong>a2scan_120405-164351.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>872bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10851" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10851" title="Download attachment"><strong>a2scan_120405-170550.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>954bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">12 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10852" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10852" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>318.05K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">12 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10853" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10853" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>26.97K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">12 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Fri, 06 Apr 2012 03:02:53 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7798-detected-trojan-bankerwin32banbrae2/</guid>
	</item>
	<item>
		<title>My PC is infected</title>
		<link>http://support.emsisoft.com/topic/7789-my-pc-is-infected/</link>
		<description><![CDATA[I could not run the emergencykitscanner because I got an error that said it could not find a2emergencykit.exe.  However I was able to run OTL.exe.  I have attached the OTL.Txt and Extras.Txt files.<br />
<br />
My browser is disabling my browser window and displaying phishing popups asking for my credit card numbers, pins and other personal info when I log into any of my credit card sites in Firefox.  I am not seeing those popups in Windows.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10840" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10840" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>40.85K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">10 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10841" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10841" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>85.82K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Thu, 05 Apr 2012 09:21:01 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7789-my-pc-is-infected/</guid>
	</item>
	<item>
		<title>Emsisoft Anti-Malware unable to quarantine or delete infected file - need help</title>
		<link>http://support.emsisoft.com/topic/7762-emsisoft-anti-malware-unable-to-quarantine-or-delete-infected-file-need-help/</link>
		<description><![CDATA[File is:  C;&#092;Windows&#092;System32&#092;Drivers&#092;UMDF&#092;WpdMtpDr.dll<br />
<br />
Infected by: Trojan.JPG.IframeRef!E2<br />
<br />
EEK and OTL files attached.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10809" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10809" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>41.77K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">19 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10810" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10810" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>89.17K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10812" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10812" title="Download attachment"><strong>a2scan_120401-134151.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>50.5K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">13 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 02 Apr 2012 01:24:20 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7762-emsisoft-anti-malware-unable-to-quarantine-or-delete-infected-file-need-help/</guid>
	</item>
	<item>
		<title><![CDATA[Can't log in to Windows]]></title>
		<link>http://support.emsisoft.com/topic/7747-cant-log-in-to-windows/</link>
		<description><![CDATA[This may or may not be related to an issue I reported here on 3/12/2012, but now when I get to the log in screen and type in my password, it doesn't recognize my password and won't let me log in. I tried as administrator as well, to no avail.<br />
<br />
I leave my computer on all the time, and sometimes I will come in to my office and find my computer at the log-in window, which means it had to have logged off on it's own. At the log-in screen, there will sometimes be two log-in options instead of the usual one: one option is as "Administrator," the other is my normal log-in as myself. When this happens, If I log in as Administrator, the desktop and icons look different than usual, and the files are not open that I had open originally. Sometimes when this happened in the past, it wouldn't let me log in as myself. But if I reboot the computer at this point, it usually takes me back to a normal log-in screen and let's me log in normally.<br />
<br />
This time, however, no matter what I do, it won't let me log in, either as administrator or myself. I've tried shorting the CMOS, and still no luck.<br />
<br />
Does this sound like some kind of virus, or some other problem? Any ideas for how to get back into my system?<br />
<br />
Thanks.<br />
Mark]]></description>
		<pubDate>Fri, 30 Mar 2012 16:30:10 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7747-cant-log-in-to-windows/</guid>
	</item>
	<item>
		<title>Everything is gone</title>
		<link>http://support.emsisoft.com/topic/7744-everything-is-gone/</link>
		<description><![CDATA[all of my computer data is gone. I only have on my desktop computer icon and recycle bin icon. I had stuff saved up like on my notepad<br />
other programs stuff in my documents. Even the internet was inaccessible until I figured out a way around that. I'm on the internet by the skin of my teeth. Can you help me get everything back like it wass?<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10776" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10776" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>50.4K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">29 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Thu, 29 Mar 2012 17:04:26 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7744-everything-is-gone/</guid>
	</item>
	<item>
		<title>pernicious rootkit</title>
		<link>http://support.emsisoft.com/topic/7735-pernicious-rootkit/</link>
		<description><![CDATA[Please help me remove a rootkit<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10751" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10751" title="Download attachment"><strong>a2scan_120327-182140.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>2.84K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">18 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10752" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10752" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>33.92K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">12 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10753" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10753" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>67.56K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">25 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 28 Mar 2012 03:23:34 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7735-pernicious-rootkit/</guid>
	</item>
	<item>
		<title><![CDATA[Virus &#34;ZX Games&#34; ?]]></title>
		<link>http://support.emsisoft.com/topic/7732-virus-zx-games/</link>
		<description><![CDATA[I'm afraid to have a virus / rootkit problem: Using Win 7 / 64 in the taskmanager apear after logon several processes with the description "ZX Games - The old ZX Spectrum Games" (32 bit process). The process names are random (looking like hex numbers). In the application list there are no additional entries. The main problem is that permanently more and more of this processes are started, causing the system to page to disk. After about 700 to 800 processes Windows gets stuck completely. Starting Windows in secure mode (boot to commandline) this does --NOT-- happen. It looks like the processes are started from %user%&#092;AppData&#092;Local&#092;Temp, because the corresponding *.exe files (several hundred) can be found here, some of them having 0 size, what indicates they are written by an other process (I removed the power supply to stop the machine). Corresponding *.tmp files (same names, all of them zero size) are found in the same directory.<br />
<br />
Since I can use the commandline only I tried a2cmd and stinger as commanline virus scanners, but nothing has been found.<br />
<br />
What to do ???]]></description>
		<pubDate>Tue, 27 Mar 2012 16:11:37 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7732-virus-zx-games/</guid>
	</item>
	<item>
		<title>MBR Rootkit not removable by EmsiSoft</title>
		<link>http://support.emsisoft.com/topic/7716-mbr-rootkit-not-removable-by-emsisoft/</link>
		<description><![CDATA[Hi there,<br />
<br />
last run with Emsisoft virusscanner showed an MBR Rootkit not removable<br />
<br />
I followed your advice on the forum and used:<br />
<br />
Emsisoft Emergency Kit (log included)<br />
<br />
OTL (2 logs included)<br />
<br />
I also ran Kaspersky TSS killer but the program did not recognise any Rootkit!<br />
<br />
So I am very curious wether there is a problem or not.<br />
<br />
Awaiting your response..........<br />
<br />
MadMax<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10698" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10698" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>135.57K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">28 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10699" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10699" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>207.42K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">40 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10697" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10697" title="Download attachment"><strong>a2scan_120325-133457.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>3.9K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sun, 25 Mar 2012 16:24:07 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7716-mbr-rootkit-not-removable-by-emsisoft/</guid>
	</item>
	<item>
		<title>Rootkits cannot be removed automatically. Consult forum experts.</title>
		<link>http://support.emsisoft.com/topic/7713-rootkits-cannot-be-removed-automatically-consult-forum-experts/</link>
		<description><![CDATA[Emsisoft scan advised &#092;&#092;.&#092;PhysicalDrive0--"Rootkits can't be removed automatically ..." I believe the TSDDKiller note was "Heuristic.Possible.MBR.Rootkit!E1." Attached are the EKK and OTL files, as requested. I was unable to generate a TDSS report. That may have been a failure on my part, or perhaps a blocking action on the part of the rootkit.<br />
<br />
TIA.<br />
<br />
Francis<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10687" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10687" title="Download attachment"><strong>a2scan_120324-145832.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>13.98K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10689" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10689" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>128.87K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10688" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10688" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>51.71K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">23 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sun, 25 Mar 2012 00:58:24 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7713-rootkits-cannot-be-removed-automatically-consult-forum-experts/</guid>
	</item>
	<item>
		<title>Emsisoft Deep Scan found 2 files it could not remove</title>
		<link>http://support.emsisoft.com/topic/7712-emsisoft-deep-scan-found-2-files-it-could-not-remove/</link>
		<description><![CDATA[I am attaching the 3 logs per this posting protocol and also the log from a deep scan I did prior to downloading the EEK and OTL scanning software.  Emsisoft deep scan instructed me to go to this forum for help manually removing the 2 files listed on the deep scan log.<br />
<br />
I would gladly appreciate any help.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10682" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10682" title="Download attachment"><strong>EEK_a2scan_120324-181549.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>964bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10683" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10683" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>74.2K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10685" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10685" title="Download attachment"><strong>prior_to_EEK_a2scan_120324-134503.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.74K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10684" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10684" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>35.96K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sun, 25 Mar 2012 00:26:14 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7712-emsisoft-deep-scan-found-2-files-it-could-not-remove/</guid>
	</item>
	<item>
		<title>How to delete these objects ?</title>
		<link>http://support.emsisoft.com/topic/7709-how-to-delete-these-objects/</link>
		<description><![CDATA[Hi,<br />
<br />
Could you help me to destroy these objects from my PC ?<br />
<br />
Thanks in advance.<br />
<br />
Best Regards from France,<br />
Philippe<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10661" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/zip.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10661" title="Download attachment"><strong>Emsisoft_help.zip</strong></a> &nbsp;&nbsp;<span class='desc'><strong>19.63K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">12 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 24 Mar 2012 11:42:31 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7709-how-to-delete-these-objects/</guid>
	</item>
	<item>
		<title>Trojan-Banker.Win32.Banbra!E2 identified in scan</title>
		<link>http://support.emsisoft.com/topic/7708-trojan-bankerwin32banbrae2-identified-in-scan/</link>
		<description><![CDATA[<span style='color: #282828'>Followed the reporting /submission guidelines as posted. When I ran the EEK scan, the report was 'no suspect files were found.' </span><br />
<br />
<span style='color: #282828'>Emsisoft Emergency Kit log and OTL.txt attached. OTL scan opened only one notepad window: OTL.txt. I was not able to find Extras txt.<br />
<br />
Thank you for your prompt assistance, Serge.</span><div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10657" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10657" title="Download attachment"><strong>a2scan_120324-014532.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>966bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10658" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10658" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>302.49K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">15 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 24 Mar 2012 08:49:24 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7708-trojan-bankerwin32banbrae2-identified-in-scan/</guid>
	</item>
	<item>
		<title>Rootkit Boot Wistler!E2 identified in scan</title>
		<link>http://support.emsisoft.com/topic/7705-rootkit-boot-wistlere2-identified-in-scan/</link>
		<description><![CDATA[Followed the reporting /submission guidelines as posted. When I ran the EEK scan, the report was 'no suspect files were found.' I believe I have attahced the correct log.<br />
<br />
OTL.txt and Extras.txt logs attached.<br />
<br />
Thank you for your prompt assistance.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10651" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10651" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>58.49K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">18 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10652" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10652" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>37.15K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">15 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10653" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10653" title="Download attachment"><strong>a2scan_120323-194349.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>964bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">13 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 24 Mar 2012 03:01:33 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7705-rootkit-boot-wistlere2-identified-in-scan/</guid>
	</item>
	<item>
		<title>How to delete rootkits manually ?</title>
		<link>http://support.emsisoft.com/topic/7700-how-to-delete-rootkits-manually/</link>
		<description><![CDATA[Hi,<br />
<br />
My emsisoft version (6.0) can't delete rootkits automatically.<br />
<br />
This the object that I want to delete:<br />
C:&#092;WINDOWS&#092;System32&#092;Drivers&#092;netbt.sys<br />
<br />
Can you help me please ?<br />
<br />
Best Regards from France,<br />
Philippe<br />
<br />
PS: Sorry for my bad english]]></description>
		<pubDate>Thu, 22 Mar 2012 19:04:32 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7700-how-to-delete-rootkits-manually/</guid>
	</item>
	<item>
		<title>System Check Malware</title>
		<link>http://support.emsisoft.com/topic/7695-system-check-malware/</link>
		<description><![CDATA[My computer is infected with the system check malware, please find attatched the reports you need. Thanks<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10635" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10635" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>41.61K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10636" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10636" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>150.45K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10634" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10634" title="Download attachment"><strong>a2scan_120322-105140.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.21K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">13 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Thu, 22 Mar 2012 02:21:07 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7695-system-check-malware/</guid>
	</item>
	<item>
		<title>another rootkit that wont quarentine.</title>
		<link>http://support.emsisoft.com/topic/7647-another-rootkit-that-wont-quarentine/</link>
		<description><![CDATA[Hello<br />
I'm looking for some help.  I've completed the directions in one of the other files and rescaned with eset and it says i have 3 files with rootkit trojan in them.  I reran the EEK and OTL scans and am attaching them.  This time when I did the OTL scan only got one file, i ran it a second time and still only one file.<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10619" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10619" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>67.53K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10620" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10620" title="Download attachment"><strong>a2scan_120319-182447.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.27K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">15 downloads</span>]]></description>
		<pubDate>Tue, 20 Mar 2012 02:27:09 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7647-another-rootkit-that-wont-quarentine/</guid>
	</item>
	<item>
		<title><![CDATA[&#34;Confirm Your Identity&#34; eBay pop-up]]></title>
		<link>http://support.emsisoft.com/topic/7624-confirm-your-identity-ebay-pop-up/</link>
		<description><![CDATA[Hi!<br />
I'm having the same problem as a few previous posters - every time I try to search on eBay, a pop-up appears asking for credit card info. As far as I know, it started yesterday. I've attached the requested scan logs, thanks for any help <img src='http://support.emsisoft.com/public/style_emoticons/default/smile.png' class='bbc_emoticon' alt=':)' /><div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10548" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10548" title="Download attachment"><strong>a2scan_120316-144020.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>4.2K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10549" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10549" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>36.84K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10550" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10550" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>86.97K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Fri, 16 Mar 2012 16:40:17 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7624-confirm-your-identity-ebay-pop-up/</guid>
	</item>
	<item>
		<title>tmpassthru ?</title>
		<link>http://support.emsisoft.com/topic/7618-tmpassthru/</link>
		<description><![CDATA[HI I have the eek log otl txt & extras txt. in my documents but am not sure how to paste them.I apologize for my lack of knowlege.<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10537" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10537" title="Download attachment"><strong>a2scan_120309-180337.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.26K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10538" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10538" title="Download attachment"><strong>hijackthis.log</strong></a> &nbsp;&nbsp;<span class='desc'><strong>5.92K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">11 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10539" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10539" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>72.45K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10540" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10540" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>37.96K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">11 downloads</span><br />
hope this is correct.]]></description>
		<pubDate>Fri, 16 Mar 2012 01:22:08 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7618-tmpassthru/</guid>
	</item>
	<item>
		<title>rootkit that wont go to quarenteen plz help</title>
		<link>http://support.emsisoft.com/topic/7614-rootkit-that-wont-go-to-quarenteen-plz-help/</link>
		<description>i have a rootkit on my laptop that wont go to quarenteen when ive done a scan. the laptop has been unbarely slow for a few weeks and malwarebytes pops up every minute or so blocking unsafe sites. could you plz help to remove it, thanks</description>
		<pubDate>Thu, 15 Mar 2012 21:45:36 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7614-rootkit-that-wont-go-to-quarenteen-plz-help/</guid>
	</item>
	<item>
		<title><![CDATA[Ebay &#34;Confirm your identity&#34; pop-up virus]]></title>
		<link>http://support.emsisoft.com/topic/7595-ebay-confirm-your-identity-pop-up-virus/</link>
		<description><![CDATA[Hey guys, came across a couple threads from here about a similar issue I'm having,<br />
every time i try to search something in ebay i get a popup asking me to confirm my details by entering in stuff like credit number and bank info, only noticed it in the past couple days.<br />
i followed the instructions in ShadowPuterDude's thread and the logs are attached below<br />
Any help would be greatly appreciated<br />
cheers<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10492" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10492" title="Download attachment"><strong>a2scan_120313-235730.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>2.58K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">34 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10493" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10493" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>70.32K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">20 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10494" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10494" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>55.51K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">18 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 13 Mar 2012 15:25:31 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7595-ebay-confirm-your-identity-pop-up-virus/</guid>
	</item>
	<item>
		<title>rootkit ...file in drivers directory, update.sys</title>
		<link>http://support.emsisoft.com/topic/7590-rootkit-file-in-drivers-directory-updatesys/</link>
		<description><![CDATA[Hi!  The software was not able to remove a rootkit.  It found update.sys in the drivers directory. When running the emergency kit, I did not see this entry come up. I have attached the requested files below.  Thank you in advance for all your assistance!<br />
<br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10485" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10485" title="Download attachment"><strong>a2scan_120311-230033.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>968bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">22 downloads</span><br />
<br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10483" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10483" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>91.57K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span><br />
<br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10484" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10484" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>38.8K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>]]></description>
		<pubDate>Tue, 13 Mar 2012 04:00:26 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7590-rootkit-file-in-drivers-directory-updatesys/</guid>
	</item>
	<item>
		<title>Is this malware - Safesurf / Surfguard?</title>
		<link>http://support.emsisoft.com/topic/7588-is-this-malware-safesurf-surfguard/</link>
		<description><![CDATA[First, I'm sorry for having to post again so soon since last time, but this install package just appeared on my desktop, and I never clicked it, but apparently it installed itself. I keep getting messages about Safesurf and Surfguard. I went to uninstall them but they didn't show up in Add/Remove Programs. But I found them under Processes in Task Manager and ended the processes. I'm sure they'll show up again when I restart my computer. I don't want them at all, but can't figure out how to uninstall them, so I'm assuming it's malware.<br />
<br />
Note: When I changed my Folder Options to Show Hidden Files and Folders, a folder titled "js" showed up on my C drive. In it are the safesurf.exe and surfguard.exe files, among some other files. There is also a SafeSurf ABUSE README.txt document that reads:<br />
<br />
ENGLISH VERSION BELOW<br />
Если вы обнаружили этот файл, на вашем копьютере установлена программа SafeSurf, предназначенная для просмотра сайтов пользователями системы JetSwap<br />
Если вы являетесь владельцем компьютера и программа была установлена без вашего согласия или ведома, перейдите по ссылке <a href='http://go.jetswap.com/abuse.php?user=arzamas&authid=78724434&authkey=98589' class='bbc_url' title='External link' rel='external'>http://go.jetswap.co...4&authkey=98589</a><br />
Пользователь будет заблокирован, а программа удалена с компьютера. Приносим Вам свои извинения за действия одного из наших пользователей, нарушающего правила системы.<br />
<br />
If you found this file on your computer installed SafeSurf, designed for browsing by users of the system JetSwap<br />
If you own a computer and the program was installed without your consent or knowledge, go to <a href='http://go.jetswap.com/abuse.php?user=arzamas&authid=78724434&authkey=98589' class='bbc_url' title='External link' rel='external'>http://go.jetswap.co...4&authkey=98589</a><br />
The user will be blocked and the program will be deleted from your computer. We apologize for the actions of one of our users who abuse the system.<br />
<br />
I don't know if I should trust it enough to go to that website to have it deleted from my computer????<br />
<br />
I've attached the EEK and OTL reports. I couldn't find the OTL.txt or the Extras.txt documents anywhere, but when I tried to save to my desktop the OTL.txt report that opened when the scan finished, it asked me if I wanted to overwrite the existing file there, even though I could not find a file there. So I saved it as OTL2.txt instead of overwriting it. I'm sure the Extra.txt file is there somewhere hidden, but I can't find it or see it.<br />
<br />
Thanks.<br />
Mark<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10469" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10469" title="Download attachment"><strong>a2scan_120312-151930.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>18.35K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">18 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10470" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10470" title="Download attachment"><strong>OTL2.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>69.92K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 12 Mar 2012 21:02:10 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7588-is-this-malware-safesurf-surfguard/</guid>
	</item>
	<item>
		<title>Help with - Heuristic. Possible.MBR.Rootkit!E1</title>
		<link>http://support.emsisoft.com/topic/7570-help-with-heuristic-possiblembrrootkite1/</link>
		<description><![CDATA[As i was enjoying my saturday morning I think my pc caught a bug, virus, malware?  I am not sure.  what i am sure of is I am in over my head and i need some help.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10430" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10430" title="Download attachment"><strong>a2scan_120310-132623.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>45.26K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10431" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10431" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>43.58K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">18 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10432" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10432" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>50.71K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 10 Mar 2012 21:29:59 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7570-help-with-heuristic-possiblembrrootkite1/</guid>
	</item>
	<item>
		<title><![CDATA[EAM &#38; OA (and others) Test by local hobbyist]]></title>
		<link>http://support.emsisoft.com/topic/7565-eam-oa-and-others-test-by-local-hobbyist/</link>
		<description><![CDATA[On March 09, 2012 from 2315 to 2330 UTC I downloaded 24 malicious executables as posted on Malware Domain and Malc0de.  No anti-anything applications were running when all files were saved to one directory.  That folder was selected within the EAM and Immunet scan utilities while HMP and MBAM were used via the folder context menu.  (Immunet was cloud only; no ClamAv or Tetra.)  All scanning was completed within 25 minutes of downloading.  See the screenshot for the results.<br />
<br />
Finally, Online Armor Free was opened and updated and each executable was run.<br />
Every exe evoked a "wants to run" popup which was Allowed with neither Remember, Trust, Install nor RunSafer selected.<br />
All further popups were Blocked and when available Remember selected.<br />
Many required more than one remembered Block and for a few a popup appeared where Terminate could be selected.<br />
Most popups were Orange.  A few were Red and none Green.<br />
carta and telipol remained in memory and were terminated with Task Manager.<br />
MBAM found and cleaned three tmp files.<br />
EAM6, HMP and Immunet scans returned zero hits.<br />
<br />
Monitoring NirSoft CurrPorts and NetMeter, zero network connectivity was observed during the OA Free exercise.<br />
There did not seem to be any evidence of the New cloud-based scan and Anti-Malware Network Integration as implemented in the release of 5.5.0.1543.  <br />
<br />
All popups were fully the result of OA's stellar (and IMHO unequalled) HIPS protection as none made any mention of signature detection.  Some Red popups indicated the local threat database (a2wl.dat) came into play, as I understand it.<br />
<br />
Environment was from a clean Windows XP Pro SP3 x86 single partion image slipstreamed up to December, 2012's Patch Tuesday blasted onto a low level formatted hard drive and then Windows Updated.<br />
<br />
Cheers.<br />
<br />
EDIT:<strong class='bbc'>  The screenshot should read 2315-2355 UTC!</strong><div id='attach_wrap' class=''>
	<h4>Attached Thumbnails</h4>
	<ul>
		
			<li class=''>
				<a class='resized_img' rel='lightbox[46024]' id='ipb-attach-url-10422-0-63525400-1337200829' href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=10422" title="AVtest.jpg - Size: 232.83K, Downloads: 49"><img src="http://support.emsisoft.com/uploads/monthly_03_2012/post-15448-0-33498900-1331352726_thumb.jpg" id='ipb-attach-img-10422-0-63525400-1337200829' style='width:100;height:41' class='attach' width="100" height="41" alt="Attached Image: AVtest.jpg" /></a>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 10 Mar 2012 04:23:14 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7565-eam-oa-and-others-test-by-local-hobbyist/</guid>
	</item>
	<item>
		<title>Help, my PC is out of my control</title>
		<link>http://support.emsisoft.com/topic/7539-help-my-pc-is-out-of-my-control/</link>
		<description><![CDATA[My computer has been taken over by Malware, other users and administrators. Can't even install Emsisoft, since internet connection has been altered.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10361" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10361" title="Download attachment"><strong>a2scan_120304-155748.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>2.8K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10362" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10362" title="Download attachment"><strong>a2scan_120305-090005.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>968bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">14 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10363" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10363" title="Download attachment"><strong>a2scan_120306-085439.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>924bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">15 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10364" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10364" title="Download attachment"><strong>a2scan_120306-180202.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>968bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10365" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10365" title="Download attachment"><strong>a2scan_120306-200133.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>968bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10366" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10366" title="Download attachment"><strong>ImportGPO_error_2012_03_01_23 _30_09.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>60.98K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">23 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10367" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10367" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>71.33K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">20 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 07 Mar 2012 15:20:38 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7539-help-my-pc-is-out-of-my-control/</guid>
	</item>
	<item>
		<title>browser virus</title>
		<link>http://support.emsisoft.com/topic/7534-browser-virus/</link>
		<description><![CDATA[<a href='http://support.emsisoft.com/topic/7533-malaware-10/' class='bbc_url' title=''>http://support.emsisoft.com/topic/7533-malaware-10/</a> first topic.<br />
<br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10340" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10340" title="Download attachment"><strong>a2scan_120306-202041.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>5.27K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">22 downloads</span> <a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10341" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10341" title="Download attachment"><strong>a2scan_120306-214151.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.02K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span> <a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10342" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10342" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>29.1K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">19 downloads</span> <a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10343" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10343" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>80.55K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>]]></description>
		<pubDate>Tue, 06 Mar 2012 18:20:50 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7534-browser-virus/</guid>
	</item>
	<item>
		<title><![CDATA[&#34;ebay Confirm Your Identity&#34; pop up asking for credit card and bank info]]></title>
		<link>http://support.emsisoft.com/topic/7523-ebay-confirm-your-identity-pop-up-asking-for-credit-card-and-bank-info/</link>
		<description><![CDATA[I came across this site through Google when I found someone else had posted here with the same exact problem.<br />
<br />
Whenever typing in any ebay search box and pressing search, a pop up appears asking for CC info and ATM pin. All the fields are required and the only way to get out is to press back or open a new tab. This happens with both IE and Mozilla. It is not an issue with them as the site works fine from any other computer that I used.<br />
<br />
Attached are the files you have asked for... please help.. thank you<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10324" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10324" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>76.73K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">19 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10325" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10325" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>70.96K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10326" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10326" title="Download attachment"><strong>a2scan_120304-214449.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.73K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">26 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 05 Mar 2012 07:37:13 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7523-ebay-confirm-your-identity-pop-up-asking-for-credit-card-and-bank-info/</guid>
	</item>
	<item>
		<title>Manual malware removal</title>
		<link>http://support.emsisoft.com/topic/7521-manual-malware-removal/</link>
		<description><![CDATA[Hello,<br />
<br />
There is malware on my system that I can't clear with the regular Emsisoft scan, and so I followed the instructions and have attached my EEK log, OTL & Extras text files.<br />
<br />
I would appreciate advice as to what steps I should take from here.<br />
<br />
Thanks!<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10319" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10319" title="Download attachment"><strong>a2scan_120303-112857.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>19.32K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">22 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10320" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10320" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>78.27K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">19 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10321" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10321" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>40.89K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 05 Mar 2012 01:53:10 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7521-manual-malware-removal/</guid>
	</item>
	<item>
		<title>Please help with Trojan.crypt!E2</title>
		<link>http://support.emsisoft.com/topic/7520-please-help-with-trojancrypte2/</link>
		<description><![CDATA[Hello.<br />
Thank you in advance. We seem to have picked up some kind of trojan and need your assistance.<br />
Log files attached.<br />
<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10315" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10315" title="Download attachment"><strong>a2scan_120304-145918.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>127.67K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10316" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10316" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>47.83K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10317" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10317" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>148.02K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">18 downloads</span>]]></description>
		<pubDate>Mon, 05 Mar 2012 00:29:17 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7520-please-help-with-trojancrypte2/</guid>
	</item>
	<item>
		<title>AV-Comparatives?</title>
		<link>http://support.emsisoft.com/topic/7514-av-comparatives/</link>
		<description><![CDATA[How I wish that Emsisisoft aloud AV-Comparatives to test the Emsisoft IS pack…<br />
 <br />
Will it ever happen?]]></description>
		<pubDate>Sat, 03 Mar 2012 20:19:43 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7514-av-comparatives/</guid>
	</item>
	<item>
		<title><![CDATA[Suspicious popup @amazon &#38; ebay and running very slow in browser]]></title>
		<link>http://support.emsisoft.com/topic/7510-suspicious-popup-amazon-ebay-and-running-very-slow-in-browser/</link>
		<description><![CDATA[My browser has been acting weird lately and I couldn't discover what the problem was since all my other programs were running smooth. This week I went to the Amazon website without logging on and tried to search something. A popup appeared asking me for my creditcarddata and ATM-pin. I clicked it away and googled this phenomenon. It brought me to this forum. I had seen that my virus scanner found some things the week before but I thought nothing of since it had dealt with the threat. Could you please help me? I'm in the middle of finishing a postgraduate course, so it's perfect timing for computer problems <img src='http://support.emsisoft.com/public/style_emoticons/default/wink.png' class='bbc_emoticon' alt=';)' /> I've read the instructions and created all the logs you need. Thank you in advance<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10305" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10305" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>88.97K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10306" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10306" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>61.89K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10307" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10307" title="Download attachment"><strong>a2scan_120302-014324.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>38.47K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 03 Mar 2012 11:52:40 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7510-suspicious-popup-amazon-ebay-and-running-very-slow-in-browser/</guid>
	</item>
	<item>
		<title>Weird DISCOVER!</title>
		<link>http://support.emsisoft.com/topic/7484-weird-discover/</link>
		<description><![CDATA[PLZ SEE THE ATTACH PICTURE<br />
<br />
super anti spy ware discover<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10260" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/gif.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10260" title="Download attachment"><strong>987654321.bmp</strong></a> &nbsp;&nbsp;<span class='desc'><strong>2.93MB</strong></span>
&nbsp;&nbsp;<span class="desc lighter">36 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 29 Feb 2012 18:20:40 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7484-weird-discover/</guid>
	</item>
	<item>
		<title><![CDATA[My pc is infected and i can't run OTL]]></title>
		<link>http://support.emsisoft.com/topic/7475-my-pc-is-infected-and-i-cant-run-otl/</link>
		<description><![CDATA[Hi,<br />
I have downloaded the Emergency Kit and run the scan, 2 trojans have been found, pls see attached file. Then tried to run the OTL following the instructions given, this appears to have been unsuccessful, there was no sign that a scan was in progress, and no logs were created. Please help  <img src='http://support.emsisoft.com/public/style_emoticons/default/sad.png' class='bbc_emoticon' alt=':(' /><div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10242" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10242" title="Download attachment"><strong>a2scan_120228-150542.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.26K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 28 Feb 2012 22:27:28 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7475-my-pc-is-infected-and-i-cant-run-otl/</guid>
	</item>
	<item>
		<title>Trojan.Alureon!E2</title>
		<link>http://support.emsisoft.com/topic/7470-trojanalureone2/</link>
		<description><![CDATA[My Labtop is infected by a series of viruses or trojan (The operaton system is win7 64 bit).<br />
<br />
The first attemped was carried out by running <span style='color: #ff0000'>Eset smart security Nod32</span>. The scan log <span style='color: #ff0000'>show win32/Olmarik.TDL4 trojan</span>, but unable to clean it.<br />
<br />
<span rel='lightbox'><img src='http://up5.iranblog.com/images/07136459325325911408.jpg' alt='Posted Image' class='bbc_img' /></span><br />
<br />
<br />
The next solution  was Emsisoft pakage. After running your <a href='http://download4.emsisoft.com/EmsisoftInternetSecuritySetup.exe' class='bbc_url' title='External link' rel='external'>Emsisoft Internet Security</a>, The result show 10 Trojans and qaurantied 9 of them which has a low risk and the high risk trojan that named  <span style='color: #0000ff'>Trojan.Alureon!E2</span>  was unable to clean or  quarantined.<br />
(Scan with malware.txt)<br />
<br />
<span rel='lightbox'><img src='http://up5.iranblog.com/images/07393946212637910442.jpg' alt='Posted Image' class='bbc_img' /></span><br />
<br />
I follow the instructions to created a report.<br />
<br />
after runnig the EEk, the result log dosen't show the high risk trojan that was mentioned above.<br />
<br />
<span rel='lightbox'><img src='http://up5.iranblog.com/images/26845693641704950216.jpg' alt='Posted Image' class='bbc_img' /></span><div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10233" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10233" title="Download attachment"><strong>Emsisoft Emergency Kit log.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>3.14K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10232" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10232" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>62.57K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10229" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10229" title="Download attachment"><strong>Scan with malware.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>6.25K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10230" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10230" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>70.97K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 28 Feb 2012 16:53:11 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7470-trojanalureone2/</guid>
	</item>
	<item>
		<title>Help! Found Rootkit.Win32.Pihar!E2</title>
		<link>http://support.emsisoft.com/topic/7455-help-found-rootkitwin32pihare2/</link>
		<description><![CDATA[Scanned with Emsisoft Anti-Malware, Deep Scan. Found Rootkit.Win32.Pihar!E2. Says to contact support for rootkit removal/repair. AVG Antivirus seemd to find the rootkit, but could provide no info, not even a name. Couldn't heal it either. I think whatever this virus/malware is...it's letting all kinds of other malicious junk in too. What do I do now?<br />
<br />
Emsisoft Emergency Kit seemed only to find a minor "cookie", but I left everything untouched as instructed. Logs from EEK & OTL are attached.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10201" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10201" title="Download attachment"><strong>a2scan_120226-120528.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.27K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">24 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10202" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10202" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>18.26K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">20 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10203" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10203" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>36.76K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sun, 26 Feb 2012 20:21:04 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7455-help-found-rootkitwin32pihare2/</guid>
	</item>
	<item>
		<title>PC infected by Trojans</title>
		<link>http://support.emsisoft.com/topic/7453-pc-infected-by-trojans/</link>
		<description><![CDATA[Hi, <br />
<br />
An initial scan detected Trojan.Agent-UM!E2 and Trojan.Agent-UN!E2 however these were not removed. <br />
<br />
I have not attached the requested logs as I cannot complete a scan in normal mode using either EEK or OTL (or with any other program I have tried). My PC freezes during any scan and I have to hard boot, although I can complete scans in safe mode. <br />
<br />
Any help would be much appreciated thanks.]]></description>
		<pubDate>Sun, 26 Feb 2012 19:00:41 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7453-pc-infected-by-trojans/</guid>
	</item>
	<item>
		<title>JPG.IframeREf!E2 removal?</title>
		<link>http://support.emsisoft.com/topic/7442-jpgiframerefe2-removal/</link>
		<description><![CDATA[Ok, so I followed the "Start Here or we..." page and downloaded the Emsisoft Emergency Kit (EEK) and OTL by OldTimer. I ran the EEK and did the Smart scan as directed. It took a while to run and it did NOT find the JPG.IframeRef!E2 problem!<br />
<br />
I did get the Extra.note and OTL.note logs but not the EEK.log, because one was not made, I presume because the EEK did not find the problem.<br />
<br />
I have Emsisoft 6.0.0.57 installed on my computer (Windows 7 - 64 bit) and when I run it, it finds the JPG.IframeRef!E2 and says it is a High risk. When I click on it, it takes me to Emsisoft's web site with instructions on how to remove JPG.IframeRef!E2 and all I have to do is <em class='bbc'><strong class='bbc'>buy Emsisoft Anti-Malware</strong></em>!   I already have a license for EAM software and it exspires in 300 days - don't need to buy it again.<br />
<br />
I have (2) questions:<br />
1. Why did your EEK software n<em class='bbc'>ot find </em>the JPG.IframeRef!E2 during its long scan?<br />
2. Why does my EEM software (6.0.0.57) not remove the JPG.IframeRef!E2 as the Emsisoft web site says it will do?<br />
 <br />
This is what my EEM Diagnosis states:<br />
JPG.IframeRef!E2<br />
		 + Rootkits:c:&#092;windows&#092;system32&#092;drivers&#092;mpio.sys<br />
 <br />
When I try to delete it, a message pops up saying Windows cannot delete root kits (See Attached .jpg screen shot) and directs me to Emsisoft forums.  <em class='bbc'><strong class='bbc'><span style='color: #FF0000'>C:&#092;Windows&#092;System32&#092;Drivers&#092;mpio.sys - Rootkits can't be removed automatically. Please consult the experts in the Emsisoft online forum for help with manual removal of this Malware:</span></strong></em> <a href='http://support.emsisoft.com' class='bbc_url' title=''>http://support.emsisoft.com</a><br />
<br />
I have attached, per the Emsisoft forum requirements, (3) files<br />
1.  OTL.notes<br />
2.  Extra.notes; and<br />
3.  My EEM scan log a2scan_120225-160534.txt<br />
<br />
In additon to the (3) files listed above,  I have added a .jpeg file showing my EEM scan window with the diagnosis.<br />
<br />
I hope you guys can help me out.<br />
<br />
Thanks<br />
capgun56<div id='attach_wrap' class=''>
	<h4>Attached Thumbnails</h4>
	<ul>
		
			<li class=''>
				<a class='resized_img' rel='lightbox[45214]' id='ipb-attach-url-10196-0-71233100-1337200829' href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=10196" title="EEM diagnosis.JPG - Size: 93.49K, Downloads: 26"><img src="http://support.emsisoft.com/uploads/monthly_02_2012/post-21264-0-43628400-1330204912_thumb.jpg" id='ipb-attach-img-10196-0-71233100-1337200829' style='width:100;height:72' class='attach' width="100" height="72" alt="Attached Image: EEM diagnosis.JPG" /></a>
			</li>
		
	</ul>
</div><div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10193" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10193" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>82K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">22 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10194" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10194" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>79.2K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">25 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10195" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=10195" title="Download attachment"><strong>a2scan_120225-160534.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>734bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">25 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 25 Feb 2012 21:39:16 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7442-jpgiframerefe2-removal/</guid>
	</item>
	<item>
		<title>Trojan.Win32.Qhost!E2</title>
		<link>http://support.emsisoft.com/topic/7426-trojanwin32qhoste2/</link>
		<description>Good day! help on how to remove this virus Trojan.Win32.Qhost!E2 ??? the program Emsisoft Anti-Malware writes that can not delete it! help please</description>
		<pubDate>Fri, 24 Feb 2012 08:35:53 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7426-trojanwin32qhoste2/</guid>
	</item>
	<item>
		<title>Emsisoft Internet Security Pack places first in comss.ru comparison</title>
		<link>http://support.emsisoft.com/topic/7382-emsisoft-internet-security-pack-places-first-in-comssru-comparison/</link>
		<description><![CDATA[<p>The highly accredited Russian IT platform <a href="http://www.comss.ru/page.php?id=808" target="_blank">comss.ru</a> has recently published a dynamic test of Anti-Virus products which will be repeated monthly. Testing in February 2012 was conducted in virtual machines running Windows 7 x86 SP 1 with 500 samples of real threats, collected on the Internet. The dynamic test involves checks during unpacking an archive, on-demand scanning and executing files. Anti-Virus programs and their components have been configured for optimum protection.</p>
<p>The <a href="http://www.emsisoft.com/en/software/internetsecurity/" target="_blank">Emsisoft Internet Security Pack</a> has received the <strong>Virusovnet High + award</strong> for the <strong>best detection rate</strong> from all of the test objects. This latest victory once more shows that the Emsisoft products stand out with their top detection rate and are capable to secure everyone&#8217;s computer reliably.</p>
<p><img class="aligncenter" title="Comss.ru high + award" src="http://cdn.comss.net/img/virnet_199x110.png" alt="" width="199" height="110" /></p>
<p>These are the complete test results with the overall detection rate in percent:</p>
<p><a href="http://www.anti-malware-reviews.com/wp-content/uploads/2012/02/comss.ru-Feb2012.png" rel="shadowbox[sbpost-305];player=img;"><img class="aligncenter size-full wp-image-306" title="comss.ru Feb 2012 Anti-Virus testing" src="http://www.anti-malware-reviews.com/wp-content/uploads/2012/02/comss.ru-Feb2012.png" alt="" width="729" height="565" /></a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-reviews.com/2012/01/12/emsisoft-anti-malware-6-with-great-result-in-latest-vb100-test/" rel="bookmark" class="crp_title">Emsisoft Anti-Malware 6 with great result in latest VB100 test</a></li><li><a href="http://www.anti-malware-reviews.com/2010/02/25/pc-security-labs-says-emsisoft-anti-malware-4-5-is-anti-virus-of-the-year-2009/" rel="bookmark" class="crp_title">PC Security Labs says: Emsisoft Anti-Malware 4.5 is Anti-virus of the year 2009!</a></li><li><a href="http://www.anti-malware-reviews.com/2009/12/28/mrg-on-demand-and-system-rescue-test-a-squared-wins/" rel="bookmark" class="crp_title">MRG On Demand and System Rescue test: a-squared wins!</a></li><li><a href="http://www.anti-malware-reviews.com/2010/05/12/pcsl-test-may-results/" rel="bookmark" class="crp_title">PCSL China Malware Test May 2010</a></li><li><a href="http://www.anti-malware-reviews.com/2010/12/28/mrg-flash-test-results-2010/" rel="bookmark" class="crp_title">MRG Flash Test Results 2010</a></li></ul></div><br /><a href='http://www.anti-malware-reviews.com/2012/02/20/emsisoft-internet-security-pack-places-first-in-comss-ru-comparison/' class='bbc_url' title='External link' rel='external'>View the full article</a>]]></description>
		<pubDate>Mon, 20 Feb 2012 16:11:52 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7382-emsisoft-internet-security-pack-places-first-in-comssru-comparison/</guid>
	</item>
	<item>
		<title>Oddly Specific Facebook/Wordpress Redirect</title>
		<link>http://support.emsisoft.com/topic/7353-oddly-specific-facebookwordpress-redirect/</link>
		<description><![CDATA[We have a self-hosted Wordpress blog that we use as a Web site for our non-profit organization (<a href='http://laundrybasketsfulloflove.org' class='bbc_url' title='External link' rel='external'>http://laundrybasketsfulloflove.org</a>).  We also have a Facebook fan page for the same organization, and we have a FB app named RSS Grafitti that automatically pushes posts to the Wordpress blog to the Facebook fan page.<br />
<br />
Everything has worked fine for about a month until this week, when an oddly specific redirect began happening.<br />
<br />
My sister, who lives across the state and runs the non-profit, contacted me that she was having some problems with links onthe Facebook fan page when trying to visit the site.  I went to the FB page and got the same result that she described:<br />
<br />
When we click on a link to our site URL in a post (whether is was posted via RSS Grafitti or manually), the status bar shows the proper URL, but the browser address fluctuates and eventually takes us to one of several spam/malware sites, such as:<ul class='bbc'><li>hxxp://www2.powertdc...%2B4727087H09qe<br /></li><li>monkeyball.osa.pl</li></ul>
If we type the URL in the address bar of a browser, we can get to the site successfully.<br />
<br />
If we post the URL to another web site on the FB fan page, we can click it and get to that site properly.<br />
<br />
It ONLY happens when we click a link to our organization's site from Facebook.<br />
<br />
I've run deep scans with about 10 virus/malware products (including Emsisoft Anti-Malware) and although a couple reported a moderate threat object and cleaned or deleted it, the problem persists.]]></description>
		<pubDate>Fri, 17 Feb 2012 16:24:34 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7353-oddly-specific-facebookwordpress-redirect/</guid>
	</item>
	<item>
		<title>Many supposed windows temp 0000000xxxxxxxxxx.av$ detections for many days?</title>
		<link>http://support.emsisoft.com/topic/7330-many-supposed-windows-temp-0000000xxxxxxxxxxav-detections-for-many-days/</link>
		<description><![CDATA[<span style='font-size: 14px;'><strong class='bbc'>Many supposed windows temp 0000000xxxxxxxxxx.av$ detections for many days?</strong></span><br />
<br />
<span style='font-size: 18px;'>Can that be right?  They seem possibly to be antivirus definitions?</span><br />
<br />
<br />
<span style='font-size: 14px;'>C:\windows\temp\00000008-ef6cecbb.av$</span><br />
<br />
<span style='font-size: 14px;'>C:\windows\temp\00000008-f2d92057.av$</span><br />
<br />
<br />
These are just two recent examples of many many more that have occurred.<br />
<br />
always in the windows temp folder, always 0000000xxxxxxxxxx.av$   sort of file<br />
<br />
<span style='font-size: 14px;'>Also for several days another thing happening many times repeatedly:</span><br />
<br />
<br />
<span style='font-size: 24px;'>Malware removal notification.</span><br />
<span style='font-size: 14px;'>Some infections could not be removed. It is required to reboot the PC in order to remove them completely. Do you want to reboot the PC now?</span><br />
<span style='font-size: 18px;'>Restart computer  Don't show again</span><br />
<br />
<br />
<span style='font-size: 14px;'>That has happened many times over the past several days, and Yes, I have done many restarts, with that persisting and recurring. </span><br />
<br />
<span style='font-size: 18px;'>Any ideas or help please?   <strong class='bbc'>Thank you.  </strong></span><br />
<br />
<br />
<br />
<span style='font-size: 14px;'><strong class='bbc'><a class='resized_img' rel='lightbox[44379]' id='ipb-attach-url-9987-0-77428900-1337200829' href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=9987" title="notification.png - Size: 46.51K, Downloads: 39"><img src="http://support.emsisoft.com/uploads/monthly_02_2012/post-20646-0-75775500-1329299033_thumb.png" id='ipb-attach-img-9987-0-77428900-1337200829' style='width:100;height:33' class='attach' width="100" height="33" alt="Attached Image: notification.png" /></a></strong></span><br />
<br />
<span style='font-size: 14px;'><strong class='bbc'><a class='resized_img' rel='lightbox[44379]' id='ipb-attach-url-9988-0-77451500-1337200829' href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=9988" title="notification2.png - Size: 119.38K, Downloads: 43"><img src="http://support.emsisoft.com/uploads/monthly_02_2012/post-20646-0-81044400-1329299047_thumb.png" id='ipb-attach-img-9988-0-77451500-1337200829' style='width:100;height:50' class='attach' width="100" height="50" alt="Attached Image: notification2.png" /></a></strong></span><br />
<br />
<span style='font-size: 14px;'><strong class='bbc'><a class='resized_img' rel='lightbox[44379]' id='ipb-attach-url-9989-0-77468600-1337200829' href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=9989" title="notification3.png - Size: 105.2K, Downloads: 38"><img src="http://support.emsisoft.com/uploads/monthly_02_2012/post-20646-0-43564700-1329299054_thumb.png" id='ipb-attach-img-9989-0-77468600-1337200829' style='width:100;height:75' class='attach' width="100" height="75" alt="Attached Image: notification3.png" /></a></strong></span><br />
<br />
<span style='font-size: 14px;'><strong class='bbc'><a class='resized_img' rel='lightbox[44379]' id='ipb-attach-url-9990-0-77485100-1337200829' href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=9990" title="notification4.png - Size: 34.81K, Downloads: 37"><img src="http://support.emsisoft.com/uploads/monthly_02_2012/post-20646-0-48012800-1329299060_thumb.png" id='ipb-attach-img-9990-0-77485100-1337200829' style='width:100;height:50' class='attach' width="100" height="50" alt="Attached Image: notification4.png" /></a></strong></span><br />
<br />
<span style='font-size: 14px;'><strong class='bbc'><a class='resized_img' rel='lightbox[44379]' id='ipb-attach-url-9991-0-77501500-1337200829' href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=9991" title="notification5.png - Size: 60.4K, Downloads: 34"><img src="http://support.emsisoft.com/uploads/monthly_02_2012/post-20646-0-70104100-1329299066_thumb.png" id='ipb-attach-img-9991-0-77501500-1337200829' style='width:100;height:79' class='attach' width="100" height="79" alt="Attached Image: notification5.png" /></a></strong></span><br />
<br />
<span style='font-size: 14px;'><strong class='bbc'><a class='resized_img' rel='lightbox[44379]' id='ipb-attach-url-9992-0-77518000-1337200829' href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=9992" title="notification6.png - Size: 37.91K, Downloads: 35"><img src="http://support.emsisoft.com/uploads/monthly_02_2012/post-20646-0-14785400-1329299072_thumb.png" id='ipb-attach-img-9992-0-77518000-1337200829' style='width:100;height:50' class='attach' width="100" height="50" alt="Attached Image: notification6.png" /></a></strong></span><br />
<br />
<span style='font-size: 14px;'><strong class='bbc'><a class='resized_img' rel='lightbox[44379]' id='ipb-attach-url-9993-0-77534300-1337200829' href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=9993" title="notification7.png - Size: 34.83K, Downloads: 28"><img src="http://support.emsisoft.com/uploads/monthly_02_2012/post-20646-0-37013400-1329299076_thumb.png" id='ipb-attach-img-9993-0-77534300-1337200829' style='width:100;height:50' class='attach' width="100" height="50" alt="Attached Image: notification7.png" /></a></strong></span><br />
<br />
<br />
<br />
<span style='font-size: 18px;'><strong class='bbc'>(I am about to run the scans Emergency Kit and OTL to post the logs)</strong></span>]]></description>
		<pubDate>Wed, 15 Feb 2012 09:46:12 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7330-many-supposed-windows-temp-0000000xxxxxxxxxxav-detections-for-many-days/</guid>
	</item>
	<item>
		<title><![CDATA[Rootkit Trojan Can't be Automatically Removed]]></title>
		<link>http://support.emsisoft.com/topic/7325-rootkit-trojan-cant-be-automatically-removed/</link>
		<description><![CDATA[Here are the reports.<br />
<br />
Also, received error report that C:&#092;$mft is corrupt<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9975" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9975" title="Download attachment"><strong>a2scan_120212-201013.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>46.32K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">23 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9974" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9974" title="Download attachment"><strong>a2scan_120212-113509.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.08K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">32 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9977" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9977" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>63.67K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">20 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9976" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9976" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>139.48K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">22 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 14 Feb 2012 19:15:29 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7325-rootkit-trojan-cant-be-automatically-removed/</guid>
	</item>
	<item>
		<title>my pc always crash</title>
		<link>http://support.emsisoft.com/topic/7324-my-pc-always-crash/</link>
		<description><![CDATA[my laptob is always crash <br />
<br />
<br />
<strong class='bbc'><span style='color: red'>Moderator Note:</span> Please do not paste logs into a forum post. It makes navigating your forum topic easier if you attach them. Please click the "More Reply Option" button in the lower-right corner to be presented with controls for attachments.</strong>]]></description>
		<pubDate>Tue, 14 Feb 2012 19:07:26 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7324-my-pc-always-crash/</guid>
	</item>
	<item>
		<title>Rootkit.win32.Phar!E2 Help!</title>
		<link>http://support.emsisoft.com/topic/7321-rootkitwin32phare2-help/</link>
		<description><![CDATA[Got the rootkit physical drive 0 issue. Followed directions as instructed. Please inform me on what to do next. Thanks.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9968" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9968" title="Download attachment"><strong>a2scan_120213-173427.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>19.35K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">25 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9967" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9967" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>99.61K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">15 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 14 Feb 2012 00:17:05 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7321-rootkitwin32phare2-help/</guid>
	</item>
	<item>
		<title>Keep getting the same traces in every scan even after quaratining or deleting</title>
		<link>http://support.emsisoft.com/topic/7317-keep-getting-the-same-traces-in-every-scan-even-after-quaratining-or-deleting/</link>
		<description><![CDATA[Keep getting the same 36 Free Majong traces every time<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9959" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9959" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>119.67K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">18 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9960" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9960" title="Download attachment"><strong>a2scan_120209-182553.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>20.99K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">28 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9958" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9958" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>60.68K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">23 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 13 Feb 2012 18:50:10 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7317-keep-getting-the-same-traces-in-every-scan-even-after-quaratining-or-deleting/</guid>
	</item>
	<item>
		<title>Follow up from original post that got closed</title>
		<link>http://support.emsisoft.com/topic/7425-follow-up-from-original-post-that-got-closed/</link>
		<description><![CDATA[MY PC is infected and I need assistance.  It's a virus that tries to open my thunder bird email with a false certificate and send spam out using my contacts list.  Attached are the files requested in the starting point instructions.  Please let me know what the next steps are.  Thanks!<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9946" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9946" title="Download attachment"><strong>a2scan_120212-152251.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>34.41K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">29 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9947" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9947" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>62.3K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">18 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9948" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9948" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>106.98K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>]]></description>
		<pubDate>Sun, 12 Feb 2012 22:44:40 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7425-follow-up-from-original-post-that-got-closed/</guid>
	</item>
	<item>
		<title>cloud av 2012</title>
		<link>http://support.emsisoft.com/topic/7297-cloud-av-2012/</link>
		<description><![CDATA[I have the cloud 2012 virus, after a scan i found out that i have rootkits too. I have scanned with OTL but didnt get the extras.txt log.<br />
<br />
Any help would be appreciated. Thanks<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9939" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9939" title="Download attachment"><strong>a2scan_120212-173353.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.58K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">33 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9938" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9938" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>57.81K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">28 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sun, 12 Feb 2012 18:56:49 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7297-cloud-av-2012/</guid>
	</item>
	<item>
		<title>Emsisoft﻿ Internet security pack</title>
		<link>http://support.emsisoft.com/topic/7302-emsisoft%ef%bb%bf-internet-security-pack/</link>
		<description><![CDATA[here is the result of the test<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9935" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9935" title="Download attachment"><strong>Emsisoft Anti-Malware and Online Armor test.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>2.3K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">55 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sun, 12 Feb 2012 07:27:37 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7302-emsisoft%ef%bb%bf-internet-security-pack/</guid>
	</item>
	<item>
		<title>Virus.Win32.Tdss!E2</title>
		<link>http://support.emsisoft.com/topic/7288-viruswin32tdsse2/</link>
		<description><![CDATA[Need to remove a rootkit virus  Virus.Win32.Tdss!E2.  This was detected during Deep Scan.  It was not detected during the Smart Scan.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9925" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9925" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>31.4K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9924" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9924" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>50.91K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">22 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9923" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9923" title="Download attachment"><strong>a2scan_120211-082322.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.19K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sat, 11 Feb 2012 18:17:01 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7288-viruswin32tdsse2/</guid>
	</item>
	<item>
		<title>Not again?!?</title>
		<link>http://support.emsisoft.com/topic/7279-not-again/</link>
		<description><![CDATA[It seems I just finished getting the Trojan crypt off my computer ( <a href='http://support.emsisoft.com/topic/7126-trojan-crypt-rootkit-found-by-anti-malware-software-how-do-i-remove-it/' class='bbc_url' title=''>link </a>to that thread) and now I have another rootkit showing up in my emsisoft scan. <img src='http://support.emsisoft.com/public/style_emoticons/default/angry.png' class='bbc_emoticon' alt=':angry:' /> ugh ugh ughhhhh<br />
<br />
I don't know, maybe they are getting on the computer when I use google chrome? Seems like that was the browser I was using the other day when I got trojan crypt, and now today was using it again.... grrr...<br />
<br />
I attached scans. to get started..<br />
<br />
Working on the Emergency kit scan, but it's taking a while. will upload when done.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9897" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9897" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>103.38K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9896" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9896" title="Download attachment"><strong>emsisoft scan.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>864bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">24 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Fri, 10 Feb 2012 20:24:04 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7279-not-again/</guid>
	</item>
	<item>
		<title>Trojan-Dropper.Win32.Sirefef!E2</title>
		<link>http://support.emsisoft.com/topic/7272-trojan-dropperwin32sirefefe2/</link>
		<description><![CDATA[Hello everyone. I have a big problem with persistent trojans. I had run MalwarBytes and Ad-Aware, but the trojans appears again and again. I've installed Emsisoft Anti-Malware and it found 7 trojans. I took them to quarantine, but it wasn`t possible to take one of them: Trojan-Dropper.Win32.Sirefef!E2<br />
<br />
When I've tried to take it to quarantine, the software told me "C:&#092;Windows&#092;System32&#092;Drivers&#092;tdx.sys - Rootkits can't be automatically removed. Ask to http:/support.emisoft.com"<br />
<br />
I have followed the instructions in the "START HERE" section of the forum, attaching the required files.<br />
<br />
Thank you very much.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9878" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9878" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>290.44K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">168 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9877" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9877" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>64.07K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">27 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9876" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9876" title="Download attachment"><strong>a2scan_120210-014208.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>6.4K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">28 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Fri, 10 Feb 2012 09:32:15 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7272-trojan-dropperwin32sirefefe2/</guid>
	</item>
	<item>
		<title>PC Keeps Turning Off During Full Scan</title>
		<link>http://support.emsisoft.com/topic/7252-pc-keeps-turning-off-during-full-scan/</link>
		<description><![CDATA[I have EmsiSoft Anti-Malware running on Full Scan and keeps turning off my computer 1/2 way through.  I can't even see which file it stops on before the PC powers off.  I'm running Windows 7 Ultimate 32 bit OS, Service Pack 1, Intel Pentium R 3.8 mhz, 3 gb memory.  Updated EmsiSoft Antimalware to the latest updates.<br />
<br />
Please help!<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9857" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9857" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>33.26K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9856" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9856" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>17.01K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">22 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9855" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9855" title="Download attachment"><strong>a2scan_120208-172309.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>956bytes</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Thu, 09 Feb 2012 01:11:48 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7252-pc-keeps-turning-off-during-full-scan/</guid>
	</item>
	<item>
		<title>Someone is hacking me</title>
		<link>http://support.emsisoft.com/topic/7245-someone-is-hacking-me/</link>
		<description><![CDATA[<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9850" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9850" title="Download attachment"><strong>a2scan_120208-194913.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>7.31K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">27 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9851" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9851" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>71.79K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">22 downloads</span><a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9852" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9852" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>28.26K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">23 downloads</span>]]></description>
		<pubDate>Wed, 08 Feb 2012 20:28:37 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7245-someone-is-hacking-me/</guid>
	</item>
	<item>
		<title>cannot clean infected PC</title>
		<link>http://support.emsisoft.com/topic/7235-cannot-clean-infected-pc/</link>
		<description><![CDATA[Did deep scan and could not quarentine most of trojans<br />
Log attached/Also attached EEk log,OTL.txt & Extra.txt.<br />
Help to clean appreciated.<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9838" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9838" title="Download attachment"><strong>a2scan_120207-171928.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.12K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">17 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9837" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9837" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>171.47K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">20 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9840" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9840" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>43.18K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">18 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9839" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/rtf.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9839" title="Download attachment"><strong>Emsisoft scan7.2.12.rtf</strong></a> &nbsp;&nbsp;<span class='desc'><strong>5.13K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">21 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 08 Feb 2012 11:31:09 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7235-cannot-clean-infected-pc/</guid>
	</item>
	<item>
		<title>Rootkit found</title>
		<link>http://support.emsisoft.com/topic/7227-rootkit-found/</link>
		<description><![CDATA[C:\WINDOWS\System32\Drivers\WRkm.sys Emsisoft Anti-Malware says that Rootkits can't be removed automatically. Please the experts<br />
in the Emsisoft forum. Are are the prescribed files:<br />
<br />
<br />
<span style='color: #ff0000'><strong class='bbc'>&lt; INLINE LOGS REMOVED BY MODERATOR &gt;</strong></span>]]></description>
		<pubDate>Tue, 07 Feb 2012 23:19:41 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7227-rootkit-found/</guid>
	</item>
	<item>
		<title>Virus Controls Keyboard and Disables Asquared</title>
		<link>http://support.emsisoft.com/topic/7225-virus-controls-keyboard-and-disables-asquared/</link>
		<description><![CDATA[I'm sorry if someone has already posted something like this before, but I couldn't find one. So, a Windows XP computer got the "System Check" virus which was removed. Asquared Anti-malware and Online Armor werer then installed on the computer. After a hour or so whenever I would go to the taskbar to the start menu, clock, etc. the mouse would select something immediately and open it. When the computer was connected to the internet, Firefox would go to random pages constantly. I also noticed that Asquared's guard and the firewall was off and I couldn't turn it back on. (The computer was not connected to the internet at this point) I ran a deep scan with Asquared and nothing came up. I restarted the computer and the blue screen of "Disk Check" came up. (Didn't before) But before I could do anything, after about 3 seconds a "key" was pressed to stop the disk check. I didn't press anything on the keyboard. I knew it had to be some form of Malware. I tried pressing F8 to get into safe boot BUT when I get to the screen it would show up for a second then "Start normally" would be highlighted  and selected. I tried different keyboards and it happened. I couldn't open anything because it would be closed, and I could only start the Task Manager. I didn't see anything out of the ordinary in processes but cpu and memory were at 100% used...and nothing was running.<br />
<br />
Anyways, eventually I booted into safemode (By starting 'msconfig') and the problems persisted. I finally removed the "Virus" by finally getting asquared's guard to start again in safe mode. I ran a deep scan and this time a few "medium" level trojans were found. I can't remember what they were (I'm not going to work on the computer again till this Saturday) but they did consist of "DX" in the name and they were .exe. I removed them but the computer was still sluggish and firefox and other programs wouldn't run. I ended up manually going to the .temp folder where Asquared found the medium level trojans and moving ALL of them to Asquared's quarantine. (There were many more malicious sounding names in notepad files and .exe's that asquared didn't find anything bad in) After deleting them in Asqaured the compuer was fine again. NOTE: I tried running TDSS Killer and it wouldn't start.<br />
<br />
I want to know if anyone knows what this virus is and why asquared was disabled and couldn't find them. Also, did this virus have to do with System Check? Thank you for your time and sorry if someone has posted this before. <img src='http://support.emsisoft.com/public/style_emoticons/default/tongue.png' class='bbc_emoticon' alt=':P' /><br />
<br />
Oh! And also is it possible this virus could come back again if the computer was connected back to the internet? (Since Asquared and the firewall were disabled by it.)]]></description>
		<pubDate>Tue, 07 Feb 2012 17:11:33 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7225-virus-controls-keyboard-and-disables-asquared/</guid>
	</item>
	<item>
		<title>Firefox; Google redirect - virus in user32.dll</title>
		<link>http://support.emsisoft.com/topic/7224-firefox-google-redirect-virus-in-user32dll/</link>
		<description><![CDATA[Hi,<br />
<br />
Been having this problem for a while...tries various solutions. No fix.<br />
<br />
At least Emisoft Anti-Malware detects and quarantines files, but the problem persists.<br />
"C:\WINDOWS\SYSWOW64\USER32.DLL    Quarantined by rule    Virus.Win32.Bamital.AMN!E1"<br />
<br />
Best Regards,<br />
<br />
aklimamba<div id='attach_wrap' class=''>
	<h4>Attached Files</h4>
	<ul>
		
			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9818" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9818" title="Download attachment"><strong>a2scan_120207-150237.txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>1.24K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">19 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9819" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9819" title="Download attachment"><strong>Extras.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>32.94K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">34 downloads</span>
			</li>
		

			<li class='attachment'>
				<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9820" title="Download attachment"><img src="http://support.emsisoft.com/public/style_extra/mime_types/txt.gif" alt="Attached File" /></a>
&nbsp;<a href="http://support.emsisoft.com/index.php?app=core&module=attach&section=attach&attach_id=9820" title="Download attachment"><strong>OTL.Txt</strong></a> &nbsp;&nbsp;<span class='desc'><strong>55.7K</strong></span>
&nbsp;&nbsp;<span class="desc lighter">16 downloads</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 07 Feb 2012 16:00:08 +0000</pubDate>
		<guid>http://support.emsisoft.com/topic/7224-firefox-google-redirect-virus-in-user32dll/</guid>
	</item>
</channel>
</rss>
