<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments for Nilpo.com</title>
	<link>http://www.nilpo.com</link>
	<description>Ask the Windows Guru!</description>
	<pubDate>Fri, 05 Sep 2008 23:53:09 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.1</generator>
		<item>
		<title>Comment on Removing Desktop_.ini Virus (W32.Fujacks.E) by Nilpo</title>
		<link>http://www.nilpo.com/2007/08/windows-xp/removing-desktop_ini-virus-w32fujackse/#comment-12552</link>
		<dc:creator>Nilpo</dc:creator>
		<pubDate>Fri, 05 Sep 2008 08:09:00 +0000</pubDate>
		<guid>http://www.nilpo.com/2007/08/windows-xp/removing-desktop_ini-virus-w32fujackse/#comment-12552</guid>
		<description>There are several other variants of this virus.  Their startup entries may be found under either or both of the following keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

The entry may look like any of the following:

"svohost" = "FuckJacks.exe"
"Fuckjacks" = "FuckJacks.exe"
"svcshare"="spoclsv.exe"
"logo1_.exe"="C:\WINDOWS\logo_1.exe"
"ati3evx.exe" = "C:\WINDOWS\ati3evx.exe"
"svohost" = "C:\WINDOWS\system32\FuckJacks.exe"
"System Boot Check" = "%System%\sysload3.exe"
"svchost" = "%Windir%\svchost.exe"
"EXPLORER" = "C:\Program Files\Common Files\System\wab32res.exe..."

In addition to the information found in this article, you should also look for and delete the following registry key, if it exists:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rasautol

You should also look for and delete the following registry value:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{21LYYSYS-9421-2126-L2Y1-L2Y1Y1S3Y1S4}\"StubPath" = "%System%\[RANDOM].exe"</description>
		<content:encoded><![CDATA[<p>There are several other variants of this virus.  Their startup entries may be found under either or both of the following keys:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</p>
<p>The entry may look like any of the following:</p>
<p>&#8220;svohost&#8221; = &#8220;FuckJacks.exe&#8221;<br />
&#8220;Fuckjacks&#8221; = &#8220;FuckJacks.exe&#8221;<br />
&#8220;svcshare&#8221;=&#8221;spoclsv.exe&#8221;<br />
&#8220;logo1_.exe&#8221;=&#8221;C:\WINDOWS\logo_1.exe&#8221;<br />
&#8220;ati3evx.exe&#8221; = &#8220;C:\WINDOWS\ati3evx.exe&#8221;<br />
&#8220;svohost&#8221; = &#8220;C:\WINDOWS\system32\FuckJacks.exe&#8221;<br />
&#8220;System Boot Check&#8221; = &#8220;%System%\sysload3.exe&#8221;<br />
&#8220;svchost&#8221; = &#8220;%Windir%\svchost.exe&#8221;<br />
&#8220;EXPLORER&#8221; = &#8220;C:\Program Files\Common Files\System\wab32res.exe&#8230;&#8221;</p>
<p>In addition to the information found in this article, you should also look for and delete the following registry key, if it exists:</p>
<p>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rasautol</p>
<p>You should also look for and delete the following registry value:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{21LYYSYS-9421-2126-L2Y1-L2Y1Y1S3Y1S4}\&#8221;StubPath&#8221; = &#8220;%System%\[RANDOM].exe&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Removing Desktop_.ini Virus (W32.Fujacks.E) by Prakash</title>
		<link>http://www.nilpo.com/2007/08/windows-xp/removing-desktop_ini-virus-w32fujackse/#comment-12549</link>
		<dc:creator>Prakash</dc:creator>
		<pubDate>Fri, 05 Sep 2008 06:29:07 +0000</pubDate>
		<guid>http://www.nilpo.com/2007/08/windows-xp/removing-desktop_ini-virus-w32fujackse/#comment-12549</guid>
		<description>Hi,


After trying to remove Desktop_.ini as per given instruction by you,,, virus could not remove permanantly.

“svcshare”=”%System%\Drivers\spoclsv.exe”

This value could not found in registry. What is next solution for removing Desktop_.ini virus.

Prakash</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>After trying to remove Desktop_.ini as per given instruction by you,,, virus could not remove permanantly.</p>
<p>“svcshare”=”%System%\Drivers\spoclsv.exe”</p>
<p>This value could not found in registry. What is next solution for removing Desktop_.ini virus.</p>
<p>Prakash</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Force Files to Download Instead of Opening by Nilpo</title>
		<link>http://www.nilpo.com/2007/11/apache/force-files-to-download-instead-of-opening/#comment-11730</link>
		<dc:creator>Nilpo</dc:creator>
		<pubDate>Mon, 25 Aug 2008 18:08:25 +0000</pubDate>
		<guid>http://www.nilpo.com/2007/11/apache/force-files-to-download-instead-of-opening/#comment-11730</guid>
		<description>No problem at all.  I'm glad you found this tip helpful!</description>
		<content:encoded><![CDATA[<p>No problem at all.  I&#8217;m glad you found this tip helpful!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Force Files to Download Instead of Opening by Rob</title>
		<link>http://www.nilpo.com/2007/11/apache/force-files-to-download-instead-of-opening/#comment-11719</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Mon, 25 Aug 2008 15:57:05 +0000</pubDate>
		<guid>http://www.nilpo.com/2007/11/apache/force-files-to-download-instead-of-opening/#comment-11719</guid>
		<description>Hey,
Thanks for the tip! I have been trying to get this result for a few hours now. I have set up HTML email signatures for everyone in my office with a link to download our Vcards, but the vcfs keft displaying in the browser. Thank you very much!</description>
		<content:encoded><![CDATA[<p>Hey,<br />
Thanks for the tip! I have been trying to get this result for a few hours now. I have set up HTML email signatures for everyone in my office with a link to download our Vcards, but the vcfs keft displaying in the browser. Thank you very much!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cannot Change Desktop Wallpaper by Nilpo</title>
		<link>http://www.nilpo.com/2008/03/windows-xp/cannot-change-desktop-wallpaper/#comment-11108</link>
		<dc:creator>Nilpo</dc:creator>
		<pubDate>Fri, 15 Aug 2008 17:22:32 +0000</pubDate>
		<guid>http://www.nilpo.com/2008/03/windows-xp/cannot-change-desktop-wallpaper/#comment-11108</guid>
		<description>Link fixed.  Thank you.</description>
		<content:encoded><![CDATA[<p>Link fixed.  Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cannot Change Desktop Wallpaper by gtsamis</title>
		<link>http://www.nilpo.com/2008/03/windows-xp/cannot-change-desktop-wallpaper/#comment-11103</link>
		<dc:creator>gtsamis</dc:creator>
		<pubDate>Fri, 15 Aug 2008 17:09:36 +0000</pubDate>
		<guid>http://www.nilpo.com/2008/03/windows-xp/cannot-change-desktop-wallpaper/#comment-11103</guid>
		<description>Your link to the reg file is not working...</description>
		<content:encoded><![CDATA[<p>Your link to the reg file is not working&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Creating a Catchall Subdomain in Apache by Apache &#187; Blog Archive &#187; Creating a Catchall Subdomain in Apache</title>
		<link>http://www.nilpo.com/2007/07/apache/creating-a-catchall-subdomain-in-apache/#comment-10656</link>
		<dc:creator>Apache &#187; Blog Archive &#187; Creating a Catchall Subdomain in Apache</dc:creator>
		<pubDate>Sun, 10 Aug 2008 00:07:02 +0000</pubDate>
		<guid>http://www.nilpo.com/2007/07/apache/creating-a-catchall-subdomain-in-apache/#comment-10656</guid>
		<description>[...] More &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] More &#8230; [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scripting the Clipboard Contents in WSH by Nilpo</title>
		<link>http://www.nilpo.com/2007/08/windows-xp/scripting-the-clipboard-contents-in-wsh/#comment-9319</link>
		<dc:creator>Nilpo</dc:creator>
		<pubDate>Sun, 27 Jul 2008 07:09:38 +0000</pubDate>
		<guid>http://www.nilpo.com/2007/08/windows-xp/scripting-the-clipboard-contents-in-wsh/#comment-9319</guid>
		<description>I agree completely.  Unfortunately, since VBScript and WSH are no longer being actively developed it doesn't appear we'll be seeing that feature added.</description>
		<content:encoded><![CDATA[<p>I agree completely.  Unfortunately, since VBScript and WSH are no longer being actively developed it doesn&#8217;t appear we&#8217;ll be seeing that feature added.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scripting the Clipboard Contents in WSH by GL</title>
		<link>http://www.nilpo.com/2007/08/windows-xp/scripting-the-clipboard-contents-in-wsh/#comment-8755</link>
		<dc:creator>GL</dc:creator>
		<pubDate>Tue, 22 Jul 2008 18:25:55 +0000</pubDate>
		<guid>http://www.nilpo.com/2007/08/windows-xp/scripting-the-clipboard-contents-in-wsh/#comment-8755</guid>
		<description>Thanks for the code snippet. If the people at Microsoft would just use their own software for 15 minutes they would see that a wscript get/set clipboard data fn. would be a commonly needed operation.</description>
		<content:encoded><![CDATA[<p>Thanks for the code snippet. If the people at Microsoft would just use their own software for 15 minutes they would see that a wscript get/set clipboard data fn. would be a commonly needed operation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Removing VirtuMonde Virus by Virtumonde Removal</title>
		<link>http://www.nilpo.com/2007/08/windows-xp/removing-virtumonde-virus/#comment-4223</link>
		<dc:creator>Virtumonde Removal</dc:creator>
		<pubDate>Thu, 24 Apr 2008 19:20:05 +0000</pubDate>
		<guid>http://www.nilpo.com/2007/08/windows-xp/removing-virtumonde-virus/#comment-4223</guid>
		<description>combofix is good stuff. I use it all the time in the field.  For Virtumonde and the Vundo threat I like to do a system restore first if the computer was recently infected.  Then after the restore run spybot, ad-aware, vundofix, highjackthis and then combofix if needed.</description>
		<content:encoded><![CDATA[<p>combofix is good stuff. I use it all the time in the field.  For Virtumonde and the Vundo threat I like to do a system restore first if the computer was recently infected.  Then after the restore run spybot, ad-aware, vundofix, highjackthis and then combofix if needed.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
