<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DjLizard.net &#187; RogueRemover</title>
	<atom:link href="http://DjLizard.net/tag/rogueremover/feed/" rel="self" type="application/rss+xml" />
	<link>http://DjLizard.net</link>
	<description>Aw dawg, this is just my whateva-whateva site.</description>
	<lastBuildDate>Mon, 22 Aug 2011 06:02:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Retarded viruses</title>
		<link>http://DjLizard.net/2007/10/10/268/</link>
		<comments>http://DjLizard.net/2007/10/10/268/#comments</comments>
		<pubDate>Wed, 10 Oct 2007 21:07:55 +0000</pubDate>
		<dc:creator>DjLizard</dc:creator>
				<category><![CDATA[Fixes]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[RogueRemover]]></category>
		<category><![CDATA[Spybot Search and Destroy]]></category>
		<category><![CDATA[Spyware]]></category>

		<guid isPermaLink="false">http://DjLizard.net/2007/10/10/268/</guid>
		<description><![CDATA[Twice in 24 hours I&#039;ve come across &#034;WinBudget&#034; which is some garbage BHO (filename matrix.dll) that gets installed somehow. A few of our customers who don&#039;t even venture that deep into the internet (and I know for a fact they don&#039;t surf porn sites or download pirated software) got infected by it somehow. I&#039;m guessing ]]></description>
			<content:encoded><![CDATA[<p>Twice in 24 hours I&#039;ve come across <strong>&#034;WinBudget&#034;</strong> which is some garbage BHO (filename matrix.dll) that gets installed <em>somehow</em>.  A few of our customers who don&#039;t even venture that deep into the internet (and I know for a fact they don&#039;t surf porn sites or download pirated software) got infected by it somehow.  I&#039;m guessing it might have been an Outlook/Outlook Express/Internet Explorer zero-day exploit or something.</p>
<p>That was ridiculously easy to remove using <a href="http://www.malwarebytes.org/rogueremover.php" class="extlink">RogueRemover</a> and Spybot, but neither were able to find the odd infection left behind:</p>
<p>If you search your drives for folders called &#039;bak&#039; you may find backup copies of executables from several popular software packages such as Adobe (several products), Nero, Apple (iTunes and Quicktime), Incredimail, Realplayer, Java, and even Norton Antivirus.  If you move the contents of each bak folder to its parent directory and overwrite, the infection is gone.  Thanks, stupid virus, for making backup copies before infecting files.</p>
<p>The best way to find these folders is like this:<br />
Start > Run > <strong>cmd.exe</strong> (to get a command prompt)<br />
<code>dir /a /b /s bak</code></p>
<p>You&#039;ll get a list of affected applications.  Go into each &#039;bak&#039; folder and move whatever is in there one level up.<br />
<code><br />
cd bak<br />
move *.* ..<br />
</code><br />
(yes you want to overwrite)</p>
<p>Thanks, WinBudget, or whatever the fuck you are.</p>
<p>Edit: I also found out that WinBudget sticks one or more entries in Internet Explorer&#039;s trusted zone list.  One is called whataboutadog (dot com) and one is whataboutarabit (sic) (dot com).</p>
<hr />
<p><small>&copy; DjLizard for <a href="http://DjLizard.net">DjLizard.net</a>, 2007. |
<a href="http://DjLizard.net/2007/10/10/268/">Permalink</a> |
<a href="http://DjLizard.net/2007/10/10/268/#comments">10 comments</a> |
Add to
<a href="http://del.icio.us/post?url=http://DjLizard.net/2007/10/10/268/&amp;title=Retarded viruses">del.icio.us</a>
<br/>
Post tags: <a href="http://DjLizard.net/tag/rogueremover/" rel="tag">RogueRemover</a>, <a href="http://DjLizard.net/tag/spybot-search-and-destroy/" rel="tag">Spybot Search and Destroy</a>, <a href="http://DjLizard.net/tag/spyware/" rel="tag">Spyware</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://DjLizard.net/2007/10/10/268/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>

