<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Removal Tool? No.</title>
	<atom:link href="http://blog.threatfire.com/2008/06/removal-tool-no.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.threatfire.com/2008/06/removal-tool-no.html</link>
	<description>ThreatFire™ AntiVirus protects when others can&#039;t</description>
	<lastBuildDate>Sun, 14 Mar 2010 19:21:30 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: kannadi</title>
		<link>http://blog.threatfire.com/2008/06/removal-tool-no.html/comment-page-1#comment-37</link>
		<dc:creator>kannadi</dc:creator>
		<pubDate>Mon, 30 Jun 2008 15:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://newblog.threatfire.com/2008/06/removal-tool-no/#comment-37</guid>
		<description>&lt;b&gt;Latest Update on &quot;Macrosoft Corporation&#039;s DriveGuard.exe&quot;&lt;/b&gt;&lt;br/&gt;&lt;br/&gt;Earlier today, I had submitted sample of this file to &lt;br/&gt;&lt;a HREF=&quot;https://www.webimmune.net/scanfile.asp&quot; REL=&quot;nofollow&quot;&gt; McAfee&#039;s Virus Sample Upload Site&lt;/a&gt; &lt;br/&gt;McAfee has communicated me saying this is a new detection named &lt;b&gt;&quot;w32/autorun.worm.c&quot;.&lt;/b&gt;&lt;br/&gt;Their current release of DAT v5327 does not have detection or cure for this file.&lt;br/&gt;They promise a future release of the DAT file will cover this virus too.&lt;br/&gt;&lt;br/&gt;But they have sent me an EXTRA.DAT which in turn started detection and deletion of this menace.</description>
		<content:encoded><![CDATA[<p><b>Latest Update on &#8220;Macrosoft Corporation&#8217;s DriveGuard.exe&#8221;</b></p>
<p>Earlier today, I had submitted sample of this file to <br /><a HREF="https://www.webimmune.net/scanfile.asp" REL="nofollow"> McAfee&#8217;s Virus Sample Upload Site</a> <br />McAfee has communicated me saying this is a new detection named <b>&#8220;w32/autorun.worm.c&#8221;.</b><br />Their current release of DAT v5327 does not have detection or cure for this file.<br />They promise a future release of the DAT file will cover this virus too.</p>
<p>But they have sent me an EXTRA.DAT which in turn started detection and deletion of this menace.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kannadi</title>
		<link>http://blog.threatfire.com/2008/06/removal-tool-no.html/comment-page-1#comment-36</link>
		<dc:creator>kannadi</dc:creator>
		<pubDate>Sun, 29 Jun 2008 21:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://newblog.threatfire.com/2008/06/removal-tool-no/#comment-36</guid>
		<description>Hi&lt;br/&gt;&lt;br/&gt;Thanks for the information.&lt;br/&gt;But does it solve the problem?&lt;br/&gt;I have serious doubt about that.&lt;br/&gt;Because I had deleted the file from Program Files few days back. But I see some serious problem with my machine.&lt;br/&gt;When I use any Internet connection in India with a Public IP, any trace route show the first hop at an Australian IP!&lt;br/&gt;&lt;br/&gt;See a sample here:&lt;br/&gt;&lt;br/&gt;Tracing route to www.yahoo-ht3.akadns.net [87.248.113.14]&lt;br/&gt;over a maximum of 30 hops:&lt;br/&gt;&lt;br/&gt;  1   412 ms   224 ms   239 ms  97.238.1.14&lt;br/&gt;  2   218 ms   239 ms   219 ms  220.224.135.65&lt;br/&gt;  3   218 ms   239 ms   319 ms  192.168.2.26&lt;br/&gt;  4     *        *        *     Request timed out.&lt;br/&gt;  5     *        *        *     Request timed out.&lt;br/&gt;  6     *        *        *     Request timed out.&lt;br/&gt;  7     *        *        *     Request timed out.&lt;br/&gt;  8     *        *        *     Request timed out.&lt;br/&gt;  9     *        *        *     Request timed out.&lt;br/&gt; 10     *        *        *     Request timed out.&lt;br/&gt; 11     *        *        *     Request timed out.&lt;br/&gt; 12     *        *        *     Request timed out.&lt;br/&gt; 13   591 ms   539 ms   459 ms  f1.us.www.vip.ird.yahoo.com [87.248.113.14]&lt;br/&gt;&lt;br/&gt;Why is it so?&lt;br/&gt;&lt;br/&gt;I wonder why no Anti Virus company has come up with a solution for this.&lt;br/&gt;&lt;br/&gt;Another very serious observation:&lt;br/&gt;&lt;br/&gt;I have noticed this software (&lt;i&gt;Macrosoft Corporation&lt;/i&gt;&#039;s &lt;b&gt;DriveGuard.exe&lt;/b&gt;) presence soon after a Windows Update!!!&lt;br/&gt;&lt;br/&gt;Is there something very fishy?</description>
		<content:encoded><![CDATA[<p>Hi</p>
<p>Thanks for the information.<br />But does it solve the problem?<br />I have serious doubt about that.<br />Because I had deleted the file from Program Files few days back. But I see some serious problem with my machine.<br />When I use any Internet connection in India with a Public IP, any trace route show the first hop at an Australian IP!</p>
<p>See a sample here:</p>
<p>Tracing route to <a href="http://www.yahoo-ht3.akadns.net" rel="nofollow">http://www.yahoo-ht3.akadns.net</a> [87.248.113.14]<br />over a maximum of 30 hops:</p>
<p>  1   412 ms   224 ms   239 ms  97.238.1.14<br />  2   218 ms   239 ms   219 ms  220.224.135.65<br />  3   218 ms   239 ms   319 ms  192.168.2.26<br />  4     *        *        *     Request timed out.<br />  5     *        *        *     Request timed out.<br />  6     *        *        *     Request timed out.<br />  7     *        *        *     Request timed out.<br />  8     *        *        *     Request timed out.<br />  9     *        *        *     Request timed out.<br /> 10     *        *        *     Request timed out.<br /> 11     *        *        *     Request timed out.<br /> 12     *        *        *     Request timed out.<br /> 13   591 ms   539 ms   459 ms  f1.us.www.vip.ird.yahoo.com [87.248.113.14]</p>
<p>Why is it so?</p>
<p>I wonder why no Anti Virus company has come up with a solution for this.</p>
<p>Another very serious observation:</p>
<p>I have noticed this software (<i>Macrosoft Corporation</i>&#8217;s <b>DriveGuard.exe</b>) presence soon after a Windows Update!!!</p>
<p>Is there something very fishy?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HosurOnline.Com</title>
		<link>http://blog.threatfire.com/2008/06/removal-tool-no.html/comment-page-1#comment-34</link>
		<dc:creator>HosurOnline.Com</dc:creator>
		<pubDate>Fri, 27 Jun 2008 13:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://newblog.threatfire.com/2008/06/removal-tool-no/#comment-34</guid>
		<description>DriveGuard.exe is a virus - Trojen -spyware and its spread by micro-soft.tripod.com. This trojen reaches your computer from unknown source, even if you run any anti-virus, say Kaspersky or McAfee (Internet security suite).&lt;br/&gt;&lt;br/&gt;This trojen generates a file called &quot;verupdate.tmp&quot; in the temp folder of the computer and it runs as a system process collecting datas along with the main file driveguard.exe.&lt;br/&gt;&lt;br/&gt;After collecting datas it generates a jpg file at internet temp folder and connects to the said tripod site as a process of IE and executes a CGI file at micro-soft.tripod.com. Even though the file has jpg extension, its not a picture file but an exe file.&lt;br/&gt;&lt;br/&gt;To remove this, go to task manager, stop the running services of this trojen and then delete it from the program files folder.&lt;br/&gt;&lt;br/&gt;It labels itself as windriveguard.exe in the latest varients.</description>
		<content:encoded><![CDATA[<p>DriveGuard.exe is a virus &#8211; Trojen -spyware and its spread by micro-soft.tripod.com. This trojen reaches your computer from unknown source, even if you run any anti-virus, say Kaspersky or McAfee (Internet security suite).</p>
<p>This trojen generates a file called &#8220;verupdate.tmp&#8221; in the temp folder of the computer and it runs as a system process collecting datas along with the main file driveguard.exe.</p>
<p>After collecting datas it generates a jpg file at internet temp folder and connects to the said tripod site as a process of IE and executes a CGI file at micro-soft.tripod.com. Even though the file has jpg extension, its not a picture file but an exe file.</p>
<p>To remove this, go to task manager, stop the running services of this trojen and then delete it from the program files folder.</p>
<p>It labels itself as windriveguard.exe in the latest varients.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
