<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>I  AM  YOUR  I.T.  GUY &#187; Virus Repair</title>
	<atom:link href="http://iamyouritguy.com/archives/tag/virus-repair/feed" rel="self" type="application/rss+xml" />
	<link>http://iamyouritguy.com</link>
	<description>iamyouritguy.com</description>
	<lastBuildDate>Thu, 03 Sep 2009 04:11:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>windowsclick removal, Google, Yahoo and MSN search result redirect to windowsclick.com. Remove windowsclick.com redirect [UACd.sys trojan]</title>
		<link>http://iamyouritguy.com/archives/54</link>
		<comments>http://iamyouritguy.com/archives/54#comments</comments>
		<pubDate>Thu, 16 Jul 2009 10:23:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Repair]]></category>
		<category><![CDATA[Windows Tutorials]]></category>

		<guid isPermaLink="false">http://iamyouritguy.com/?p=54</guid>
		<description><![CDATA[<!-- Easy AdSense V2.63 -->
<!-- Post[count: 2] -->
<div class="ezAdsense adsense adsense-leadin" style="text-align:center;margin:12px;" ><script type="text/javascript"><!--
google_ad_client = "pub-8320224863007700";
/* 468x60, created 7/21/09 */
google_ad_slot = "9002369434";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>





After
Redirect to windowsclick.com site is a result of UACd.sys trojan activity. The trojan horse may represent security risk for the infected computer and uses rootkit-specific techniques designed to hide the software presence in the system. Once infected, UACd.sys trojan blocks user access to security websites, search results in Google, Yahoo, MSN and other redirect you [...]]]></description>
			<content:encoded><![CDATA[<p>After</p>
<p><strong>Redirect to windowsclick.com site is a result of UACd.sys trojan activity.</strong> The trojan horse may represent security risk for the infected computer and uses rootkit-specific techniques designed to hide the software presence in the system. Once infected, UACd.sys trojan blocks user access to security websites, search results in Google, Yahoo, MSN and other redirect you to windowsclick.com and other non related sites.</p>
<p>The Fix:</p>
<ul>
<li>Download Avenger from <a href="http://swandog46.geekstogo.com/avenger.zip">here</a> and unzip to your desktop.</li>
<li>Run Avenger, copy,then paste the following text in Input script Box:<br />
<blockquote><p>Drivers to delete:<br />
UACd.sys</p>
<p>Files to delete:<br />
C:\WINDOWS\system32\wJQs.exe</p></blockquote>
<p>Then click on ‘Execute’.</li>
<li>You will be asked Are you sure you want to execute the current script?. Click Yes.</li>
<li>You will now be asked First step completed — The Avenger has been successfully<br />
set up to run on next boot. Reboot now?. Click Yes.</li>
</ul>
<ul>
<li>Your PC will now be rebooted.</li>
</ul>
<p>You can find a few other steps with the website link below.</p>
<p><a href="http://www.myantispyware.com/2009/01/24/how-to-remove-windowsclickcom-redirect-uacdsys-trojan/">http://www.myantispyware.com/2009/01/24/how-to-remove-windowsclickcom-redirect-uacdsys-trojan/</a></p>
<p style="text-align: left;">Please leave comment. Let me know if this post help!</p>
]]></content:encoded>
			<wfw:commentRss>http://iamyouritguy.com/archives/54/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Profile Storage Space error, virus, or malware. Repair! Fix!</title>
		<link>http://iamyouritguy.com/archives/21</link>
		<comments>http://iamyouritguy.com/archives/21#comments</comments>
		<pubDate>Fri, 10 Jul 2009 00:47:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Repair]]></category>
		<category><![CDATA[Windows Tutorials]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[current version]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[profile]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[repair]]></category>
		<category><![CDATA[space]]></category>
		<category><![CDATA[storage]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows xp]]></category>

		<guid isPermaLink="false">http://iamyouritguy.com/?p=21</guid>
		<description><![CDATA[First make sure you clean  Spyware Protect 2009 virus out of your system using Malwarebytes Anti-Malware 
Follow the following steps:
a. Ctl+Alt+Delete go to task manger, go to process tab,  find &#8220;proquota.exe&#8221; right click and end the process.
b.  Click Start, and then click Run.

In the Open box, type regedit, and then click OK
Back up registry by [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_20" class="wp-caption alignnone" style="width: 310px"><a href="http://iamyouritguy.com/wp-content/uploads/2009/07/profileStorageSpaceFix1.jpg"><img class="size-medium wp-image-20" title="profileStorageSpaceFix" src="http://iamyouritguy.com/wp-content/uploads/2009/07/profileStorageSpaceFix1-300x169.jpg" alt="Profile Storage Space Fix registry location" width="300" height="169" /></a><p class="wp-caption-text">Profile Storage Space Fix registry location</p></div>
<p>First make sure you clean  Spyware Protect 2009 virus out of your system using <a href="http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html">Malwarebytes Anti-Malware </a></p>
<p>Follow the following steps:</p>
<p>a. <strong>Ctl+Alt+Delete</strong> go to task manger, go to <strong>process</strong> tab,  find &#8220;<span style="color: #ff6600;">proquota.exe</span>&#8221; right click and end the process.</p>
<p>b.  Click Start, and then click Run.</p>
<ol type="1">
<li>In the Open box, type regedit, and then click OK</li>
<li>Back up registry by clicking the File menu, click Export.</li>
<li>In the Save in box, select a location where you want to save the Registration Entries (.reg)</li>
<li>Locate by clicking on the left hand side &#8212;&gt;<strong>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System  ( <span style="color: #ff6600;">view image above<span style="color: #000000;">)</span></span></strong></li>
<li><span style="color: #ff6600;"><span style="color: #000000;">once your at the location you will see on the right side </span></span><strong><span style="color: #ff6600;"><span style="color: #000000;">&#8220;EnableProfileQuota&#8221; </span></span><span style="color: #ff6600;">right click</span></strong><strong><span style="color: #ff6600;"><span style="color: #000000;"> EnableProfileQuota </span></span></strong><span style="color: #ff6600;"><span style="color: #000000;">and select</span></span><strong><span style="color: #ff6600;"><span style="color: #000000;"> Delete</span></span></strong></li>
</ol>
<p>c. An easier way to do this is to copy the following script between the ******  to notepad save and rename the extension to .reg and execute the file.</p>
<div>*****************************************************************</div>
<p>REGEDIT4</p>
<div>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]</div>
<div>EnableProfileQuota&#8221;=-</div>
<div>&#8220;ProfileQuotaMessage&#8221;=-</div>
<div>&#8220;MaxProfileSize&#8221;=-</div>
<div>&#8220;IncludeRegInProQuota&#8221;=-</div>
<div>&#8220;WarnUser&#8221;=-</div>
<div>&#8220;WarnUserTimeout&#8221;=-<!--c2--></div>
<p><!--ec2-->*****************************************************************</p>
<p>I have made the file you can download <a href="http://iamyouritguy.com/wp-content/uploads/2009/07/profileStorageErrorRemoval.rar">profileStorageErrorRemoval</a> <a href="http://iamyouritguy.com/wp-content/uploads/2009/07/profileStorageErrorRemoval.rar">here</a> Extract the file and double click the file, click <strong>yes</strong> and then <strong>ok</strong>.</p>
]]></content:encoded>
			<wfw:commentRss>http://iamyouritguy.com/archives/21/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XP login &#8211; logoff loop —- computer virus repair</title>
		<link>http://iamyouritguy.com/archives/10</link>
		<comments>http://iamyouritguy.com/archives/10#comments</comments>
		<pubDate>Tue, 07 Jul 2009 09:53:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Repair]]></category>
		<category><![CDATA[Windows Tutorials]]></category>

		<guid isPermaLink="false">http://iamyouritguy.com/?p=10</guid>
		<description><![CDATA[Method 1:
Enter the Recovery Console if you need help and don&#8217;t know how to get into Recovery Console click here
Boot the system using the Windows XP CD-ROM. In the first screen when the Setup begins, read the instructions press “R” (in the first screen) enter the Recovery Console. Type-in the built-in Administrator password to enter [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Method 1:</strong></p>
<p><strong>Enter the <a href="http://iamyouritguy.com/archives/164">Recovery Console</a> if you need help and don&#8217;t know how to get into <a href="http://iamyouritguy.com/archives/164">Recovery Console</a> click <a href="http://iamyouritguy.com/archives/164">here</a></strong></p>
<p>Boot the system using the Windows XP CD-ROM. In the first screen when the Setup begins, read the instructions press “R” (in the first screen) enter the Recovery Console. Type-in the built-in Administrator password to enter the Console. You’ll see the prompt reading <strong>C:\Windows</strong> (Or any other drive-letter where you’ve installed XP)</p>
<p>Type the following command and press Enter.</p>
<p><strong>CD SYSTEM32</strong><br />
(If that does not work, try <strong>CHDIR SYSTEM32</strong>)</p>
<p><strong>option 1:</strong></p>
<p><strong>COPY USERINIT.EXE WSAUPDATER.EXE</strong></p>
<p><strong>option 2:</strong></p>
<p><strong>expand d:\i386\userint.exe c:\windows\system32\</strong></p>
<p><strong>if your in c:\windows\system32 then</strong></p>
<p><strong>expand d:\i386\userinint.exe</strong></p>
<p>Quit Recovery Console by typing <strong>EXIT </strong>and restart Windows.</p>
<p>You’ll be able to login successfully as you’ve created the wsaupdater.exe file (now, a copy of userinit.exe)</p>
<p>Now, change the <strong>USERINIT</strong> value in the registry and change it accordingly.</p>
<p><strong>Fixing a registry entry which causes the xp login &#8211; logoff loop</strong></p>
<p>Click Start, Run and type REGEDIT. Navigate to:</p>
<p><strong>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ WindowsNT \ CurrentVersion \ Winlogon</strong></p>
<p>In the right-pane, change the value of Userinit to “<strong>C:\WINDOWS\system32\userinit.exe,</strong>“</p>
<p>Type the above value exactly as given, including the comma &#8211; exclude the quotes. <strong>Also, change the path to userinit.exe appropriately if Windows is installed in a different drive</strong>.</p>
<p>Close Registry Editor and restart Windows.</p>
<p><strong>Method 2:</strong></p>
<p>Sometime virus scanners such as AVG and Malwarebytes eat up the infected file <a href="http://iamyouritguy.com/wp-content/uploads/2009/07/userinit.rar">userinit.exe</a> which cause this login loop. A way to fix this issue is to take out the infected hard drive. Attach the hard drive to a working Windows system via usb or placing it inside the system. Once the drive is up and running copy  the userinit.exe found in c:\windows\system32 into the drive infected drive d:\windows\system32 (d: being the infected drive letter). Reinstall the hard drive into the orginal system and boot up.</p>
<p>i have attach the <a href="http://iamyouritguy.com/wp-content/uploads/2009/07/userinit.rar">userinit.exe</a> with this blog download <a href="http://iamyouritguy.com/wp-content/uploads/2009/07/userinit.rar">here</a></p>
<p>the file is compress with <a title="winrar" href="http://download.cnet.com/3001-2250_4-10007677.html?spi=927d59c2dd7d23bf1eb2b20169fcd4e8" target="_blank">winrar</a> you can download winrar <a title="winrar" href="http://download.cnet.com/3001-2250_4-10007677.html?spi=927d59c2dd7d23bf1eb2b20169fcd4e8" target="_blank">here</a> to extract</p>
<p>Did this post help? Please comment!</p>
]]></content:encoded>
			<wfw:commentRss>http://iamyouritguy.com/archives/10/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Completetala removal “It block internet connections to some websites.”</title>
		<link>http://iamyouritguy.com/archives/6</link>
		<comments>http://iamyouritguy.com/archives/6#comments</comments>
		<pubDate>Tue, 07 Jul 2009 09:39:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Repair]]></category>
		<category><![CDATA[Windows Tutorials]]></category>

		<guid isPermaLink="false">http://iamyouritguy.com/?p=6</guid>
		<description><![CDATA[Completetala is a virus that may induce computer users to download fake antispyware application from a illegitimate Microsoft Security Center website. Completetala annoys user by pop-up with message “hehehehehheheheh!!!!!”
Aliases:
-
Risk Level: Medium
File Size: Varies
Affected System: Windows
Common Symptoms:
1. It can block internet connections to some websites
How to remove…
1. Download Malwarebytes’ Anti-Malware (mbam-setup.exe) and save it on your Desktop.
2. [...]]]></description>
			<content:encoded><![CDATA[<p>Completetala is a virus that may induce computer users to download fake <a href="http://www.precisesecurity.com/blogs/2008/11/02/completetala/" target="_top">antispyware</a> application from a illegitimate Microsoft <a href="http://www.precisesecurity.com/blogs/2008/11/02/completetala/" target="_top">Security Center</a> website. Completetala annoys user by pop-up with message “hehehehehheheheh!!!!!”</p>
<p><strong>Aliases:</strong><br />
-</p>
<p><strong>Risk Level:</strong> Medium</p>
<p><strong>File Size:</strong> Varies</p>
<p><strong>Affected System:</strong> Windows</p>
<p><strong>Common Symptoms:</strong><br />
1. It can block internet connections to some websites</p>
<p><strong>How to remove…</strong></p>
<p><strong>1.</strong> Download <a href="http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm">Malwarebytes’ Anti-Malware</a> (mbam-setup.exe) and save it on your Desktop.<br />
<strong>2. </strong>After downloading, double-click on mbam-setup.exe to install the application.<br />
<strong>3.</strong> Follow the prompts and install as “default” only<br />
<strong>4. </strong>Before the installation completes, check on the following prompts:<br />
- Update Malwarebytes’ Anti-Malware<br />
- Launch Malwarebytes’ Anti-Malware<br />
<strong>5. </strong>Click “Finish.” Program will run automatically and you will be prompt to update the program before doing a scan. Please update.<br />
<strong>6.</strong> Scan your <a href="http://www.precisesecurity.com/blogs/2008/11/02/completetala/" target="_top">computer</a> thoroughly.<br />
<strong>7.</strong> When scanning is finished click on the “Show Results”<br />
<strong>8.</strong> Make sure that all detected threats are marked, click on Remove Selected.<br />
<strong>9.</strong> Restart your computer.</p>
<p>If that does not fix the problem. Try to empty the hosts file the file is under Windows/system32/drivers/etc.</p>
<p>To empty “hosts” file. Do this</p>
<p>a) Close the broswer<br />
b) Open C:\Windows\system32\drivers\etc\hosts file with <a href="http://www.precisesecurity.com/blogs/2008/11/02/completetala/" target="_top">notepad</a>.<br />
c) remove all the text<br />
d) Save the file</p>
<p>Now open the browser and browse internet. It should work fine.</p>
<p style="text-align: left;">Please leave comment. Let me know if this post help!</p>
]]></content:encoded>
			<wfw:commentRss>http://iamyouritguy.com/archives/6/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
