<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: expand32xp.dll</title>
	<atom:link href="http://www.latest-virus.com/index.php/expand32xp-dll-2487/feed" rel="self" type="application/rss+xml" />
	<link>http://www.latest-virus.com/expand32xp-dll-2487</link>
	<description>Latest Virus information and remove instruction</description>
	<pubDate>Tue, 22 May 2012 04:00:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: admin</title>
		<link>http://www.latest-virus.com/expand32xp-dll-2487#comment-1337</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Thu, 19 Aug 2010 13:59:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.latest-virus.com/?p=2487#comment-1337</guid>
		<description>Hi,Claudio

Welcome to our website.

please remove the file in safemode and then run a whole scan.

Then Please download Combofix:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
 
And save to the desktop.

Close all other browser windows. 
 
Important-&gt; Temporarily disable your anti-virus, real-time protection before performing a scan. They can interfere with combofix or remove some of its embedded files which may cause "unpredictable results". 
 
Go to Start-&gt;Run and copy/paste: ComboFix /snapshot and hit OK. It should run Combofix.
 
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.

 When finished, it will produce a logfile located at C:\combofix.txt.
 

Post the contents of that log in your next reply with a new hijackthis log.</description>
		<content:encoded><![CDATA[<p>Hi,Claudio</p>
<p>Welcome to our website.</p>
<p>please remove the file in safemode and then run a whole scan.</p>
<p>Then Please download Combofix:<br />
<a href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe" rel="nofollow">http://download.bleepingcomputer.com/sUBs/ComboFix.exe</a></p>
<p>And save to the desktop.</p>
<p>Close all other browser windows. </p>
<p>Important-> Temporarily disable your anti-virus, real-time protection before performing a scan. They can interfere with combofix or remove some of its embedded files which may cause &#8220;unpredictable results&#8221;. </p>
<p>Go to Start->Run and copy/paste: ComboFix /snapshot and hit OK. It should run Combofix.</p>
<p>Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.</p>
<p> When finished, it will produce a logfile located at C:\combofix.txt.</p>
<p>Post the contents of that log in your next reply with a new hijackthis log.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: claudio</title>
		<link>http://www.latest-virus.com/expand32xp-dll-2487#comment-1327</link>
		<dc:creator>claudio</dc:creator>
		<pubDate>Thu, 19 Aug 2010 08:20:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.latest-virus.com/?p=2487#comment-1327</guid>
		<description>I found this virus on my computer on aug 18 2010 follows the Spybot report:
SpySheriff: [SBI $9302253C] Impostazioni (Modifica al registro, nothing done)
  HKEY_USERS\S-1-5-21-57989841-1801674531-682003330-42035\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn

Microsoft.Windows.ActiveDesktop: [SBI $99FAD8A8] Impostazioni utente (Modifica al registro, nothing done)
  HKEY_USERS\S-1-5-21-57989841-1801674531-682003330-42035\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper

Microsoft.Windows.Explorer: [SBI $1931FF4D] Impostazioni (Modifica al registro, nothing done)
  HKEY_USERS\S-1-5-21-57989841-1801674531-682003330-42035\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges

Microsoft.Windows.disableSystemRestore: [SBI $6296EC95] Impostazioni (Modifica al registro, nothing done)
  HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableSR

Virtumonde.prx: [SBI $99CC2F62] Impostazioni di avvio automatico (Xyeyeg) (Valore di registro, nothing done)
  HKEY_USERS\S-1-5-21-57989841-1801674531-682003330-42035\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Xyeyeg

Virtumonde.prx: [SBI $99CC2F62]  File di programma (File, nothing done)
  C:\WINDOWS\mluiolut.dll

Regards

Claudio</description>
		<content:encoded><![CDATA[<p>I found this virus on my computer on aug 18 2010 follows the Spybot report:<br />
SpySheriff: [SBI $9302253C] Impostazioni (Modifica al registro, nothing done)<br />
  HKEY_USERS\S-1-5-21-57989841-1801674531-682003330-42035\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn</p>
<p>Microsoft.Windows.ActiveDesktop: [SBI $99FAD8A8] Impostazioni utente (Modifica al registro, nothing done)<br />
  HKEY_USERS\S-1-5-21-57989841-1801674531-682003330-42035\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper</p>
<p>Microsoft.Windows.Explorer: [SBI $1931FF4D] Impostazioni (Modifica al registro, nothing done)<br />
  HKEY_USERS\S-1-5-21-57989841-1801674531-682003330-42035\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges</p>
<p>Microsoft.Windows.disableSystemRestore: [SBI $6296EC95] Impostazioni (Modifica al registro, nothing done)<br />
  HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableSR</p>
<p>Virtumonde.prx: [SBI $99CC2F62] Impostazioni di avvio automatico (Xyeyeg) (Valore di registro, nothing done)<br />
  HKEY_USERS\S-1-5-21-57989841-1801674531-682003330-42035\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Xyeyeg</p>
<p>Virtumonde.prx: [SBI $99CC2F62]  File di programma (File, nothing done)<br />
  C:\WINDOWS\mluiolut.dll</p>
<p>Regards</p>
<p>Claudio</p>
]]></content:encoded>
	</item>
</channel>
</rss>

