<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><entry xmlns='http://www.w3.org/2005/Atom' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-8991886823560509637.post-2524252170889565794</id><published>2008-04-20T16:40:00.006+05:30</published><updated>2008-04-20T18:05:20.331+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='Email Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><title type='text'>Worm.Win32.Netsky Removal Process</title><content type='html'>Worm.Win32.Netsky is a new rogue anti-spyware program trojan, which is part of a fake malicious software engineered by Internet hackers. Worm.Win32.Netsky-related  anti-spyware is a fake anti-spyware program. Do NOT purchase Worm.Win32.Netsky related spyware under any circumstances since it is a fake anti-spyware software.&lt;br /&gt;&lt;br /&gt;The following process will help you remove it from your system easily and safely.&lt;br /&gt;&lt;br /&gt;Worm.Win32.Netsky Manual Removal Process:&lt;br /&gt;&lt;br /&gt;1. Click on the Start Menu button, then click on the Control Panel option, and then Double-click on the Add or Remove Programs icon.&lt;br /&gt;2. Locate Worm.Win32.Netsky and double-click on it to uninstall Worm.Win32.Netsky. Follow the screen step-by-step screen instructions to complete uninstallation of Worm.Win32.Netsky.&lt;br /&gt;3. Restart the computer.&lt;br /&gt;4. When it has completed uninstalling you can close Add or Remove Programs and your Control Panel.&lt;br /&gt;5. Close all programs.&lt;br /&gt;6. Stop Worm.Win32.Netsky process. If you do not know how to stop a running process, click here to read more.&lt;br /&gt;7. Delete the following infected files from your system.&lt;br /&gt;EasyAV.exe&lt;br /&gt;EasyAV&lt;br /&gt;secound_document4.pif&lt;br /&gt;e-mail3.pif&lt;br /&gt;approved_file7.pif&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Remove Worm.Win32.Netsky with SmithfraudFix&lt;/span&gt;:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ixqTI_Y_NPk/SAs3ebb2XCI/AAAAAAAAAU8/z9AawKpFY2Q/s1600-h/Fix01b.png"&gt;&lt;img style="cursor: pointer; width: 386px; height: 196px;" src="http://1.bp.blogspot.com/_ixqTI_Y_NPk/SAs3ebb2XCI/AAAAAAAAAU8/z9AawKpFY2Q/s320/Fix01b.png" alt="" id="BLOGGER_PHOTO_ID_5191303991374797858" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ixqTI_Y_NPk/SAs3u7b2XDI/AAAAAAAAAVE/LYzUXPnsyww/s1600-h/Fix02b.png"&gt;&lt;img style="cursor: pointer; width: 387px; height: 179px;" src="http://3.bp.blogspot.com/_ixqTI_Y_NPk/SAs3u7b2XDI/AAAAAAAAAVE/LYzUXPnsyww/s320/Fix02b.png" alt="" id="BLOGGER_PHOTO_ID_5191304274842639410" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ixqTI_Y_NPk/SAs3ebb2XCI/AAAAAAAAAU8/z9AawKpFY2Q/s1600-h/Fix01b.png"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;1.  Download SmithfraudFix tool and save it to your desktop.&lt;br /&gt;2.  Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)&lt;br /&gt;3.   Double-click SmitfraudFix.exe&lt;br /&gt;4   Select 2 and hit Enter to delete infect files.&lt;br /&gt;5.   You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.&lt;br /&gt;6.   The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.&lt;br /&gt;7.    A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Restore Trusted and Restricted site zone&lt;/span&gt;&lt;br /&gt;1. To restore Trusted and Restricted site zone, select 3 and hit Enter.&lt;br /&gt;2. You will be prompted: Restore Trusted Zone ? answer Y (yes) and hit Enter to delete trusted zone.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Search&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;1. Select&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;1&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.tx&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;(Disclaimers: These instructions are free and not guaranteed to work. Please use it at your own risks. We are not responsible for any damages.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8991886823560509637-2524252170889565794?l=anoop-aravindan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anoop-aravindan.blogspot.com/feeds/2524252170889565794/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=8991886823560509637&amp;postID=2524252170889565794&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8991886823560509637/posts/default/2524252170889565794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8991886823560509637/posts/default/2524252170889565794'/><link rel='alternate' type='text/html' href='http://anoop-aravindan.blogspot.com/2008/04/wormwin32netsky-removal-process.html' title='Worm.Win32.Netsky Removal Process'/><author><name>ANP</name><uri>http://www.blogger.com/profile/07302279874343047585</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='05471471967247670627'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ixqTI_Y_NPk/SAs3ebb2XCI/AAAAAAAAAU8/z9AawKpFY2Q/s72-c/Fix01b.png' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry>