<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The backdoor of me...</title>
	<atom:link href="http://fskreuz.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://fskreuz.wordpress.com</link>
	<description>Where small things change the world</description>
	<lastBuildDate>Wed, 23 Apr 2008 11:52:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='fskreuz.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>The backdoor of me...</title>
		<link>http://fskreuz.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://fskreuz.wordpress.com/osd.xml" title="The backdoor of me..." />
	<atom:link rel='hub' href='http://fskreuz.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Manual steps to remove re101.exe</title>
		<link>http://fskreuz.wordpress.com/2008/04/03/programmer-mode-my-manual-steps-to-remove-re101exe/</link>
		<comments>http://fskreuz.wordpress.com/2008/04/03/programmer-mode-my-manual-steps-to-remove-re101exe/#comments</comments>
		<pubDate>Thu, 03 Apr 2008 23:50:41 +0000</pubDate>
		<dc:creator>fskreuz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[delete re101]]></category>
		<category><![CDATA[re101]]></category>
		<category><![CDATA[re101.exe]]></category>
		<category><![CDATA[remove re101]]></category>
		<category><![CDATA[uninstall re101]]></category>

		<guid isPermaLink="false">http://fskreuz.wordpress.com/?p=3</guid>
		<description><![CDATA[http://fskreuz.wordpress.com/ This method is for those who can&#8217;t afford expensive but effective programs and have a hard time dealing with the virus, especially when it locks drive C. Until a virus scan update includes this virus, use the following steps. It is guaranteed safe since I use other removal methods as reference. Characteristics: 1.) The [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fskreuz.wordpress.com&amp;blog=3371383&amp;post=3&amp;subd=fskreuz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>http://fskreuz.wordpress.com/</p>
<p>This method is for those who can&#8217;t afford expensive but effective programs and have a hard time dealing with the virus,<br />
especially when it locks drive C. Until a virus scan update includes this virus, use the following steps.<br />
It is guaranteed safe since I use other removal methods as reference.</p>
<p>Characteristics:</p>
<p>1.) The drive C;\ or any drive may contain an &#8220;autorun&#8221; which may trigger the virus&#8217; function.<br />
To determine this, right-click on drive C:\. If the autorun is present, the first option on the right-click menu is &#8220;Autorun&#8221;<br />
2.) runs two (2) winlogon.exe<br />
3.) runs a calc.exe that when ended, runs again.<br />
4.) files are permanently hidden when you show them using the normal viewing method.<br />
5.) if you manage to edit the registry to see the hidden files, the one or more of the following files can be seen:</p>
<p>C:\WINDOWS\SYSTEM32\_re101.exe<br />
C:\re101.exe<br />
C:\Program Files\Common Files\Microsoft Shared\MSInfo\re101.exe</p>
<p>The virus may be seen in places where you copied your files from your flash drive</p>
<p>NOTE: these files are always in use and are deemed &#8220;stubborn files&#8221; since they can&#8217;t be deleted on the spot.</p>
<p>//////////////////////////////////////////////////////////////////////////<br />
!!! STEPS ON HOW TO REMOVE RE101.EXE !!!<br />
//////////////////////////////////////////////////////////////////////////</p>
<p>Note: You will need around 2 free programs to use, so above all the steps,<br />
it&#8217;s essential to have a GOOD INTERNET CONNECTION,<br />
or<br />
download the programs somewhere else and save to a flash drive.</p>
<p><strong>STEP 1:</strong><br />
Save all data from your USB flash drives to your PC. Place it in folders to recognize each.</p>
<p>After that, FORMAT your flash drives. Yes, format them, to delete all traces of the virus</p>
<p>Download PREVX CSI free scanner to confirm that the threat is re101.exe</p>
<p>Install and run the FREE scan. You don&#8217;t need a license since you only need the scan, not the clean up.</p>
<p>Run the scanner</p>
<p>The three suspected places stated above should contain the virus</p>
<p>The virus may also be seen in places where you copied your files from your flash drive<br />
and may also show up in the scan, so remember to delete them later.</p>
<p><strong>STEP 2:</strong></p>
<p>Next, the virus files are hidden caused by the virus so you must edit the registry to see the files especially the hidden autorun on drive C.<br />
Ordinary method of seeing hidden files is hi-jacked so what ever you do using this method is useless</p>
<p>Do these to see hidden files via registry:</p>
<p>Go to start -&gt; run -&gt; type &#8220;regedit&#8221;</p>
<p>At the explorer side bar, go here:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows<br />
\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL</p>
<p><em>Method 1:</em><br />
Look at the “CheckedValue” key…<br />
it should look something like this: 0&#215;000000 (0)<br />
if the value in the parenthesis is &#8220;0&#8243;, right click the value and select modify. Change value data to &#8220;1&#8243;</p>
<p>if the said instructions does not look like any of those in the registry, do the following:</p>
<p><em>Method 2:</em><br />
This should be a DWORD key. If it isn’t,  delete the key.<br />
Create a new key called “CheckedValue” as a DWORD (hexadecimal) with a value of 1.<br />
The “Show hidden files &amp; folders” check box should now work normally.</p>
<p>After step 2, you should see all hidden files, including the virus.</p>
<p><strong>STEP 3:</strong></p>
<p>&gt;&gt;To delete the hidden autorun:</p>
<p>Go to start -&gt; run -&gt; type &#8220;cmd&#8221;<br />
This will open MS-DOS mode. Type in:</p>
<p>cd C:\<br />
this will forward you to drive C</p>
<p>dir /a:h<br />
this will display hidden files</p>
<p>del /a:h autorun*.*<br />
this will delete any autorun files on drive C</p>
<p>to confirm deletion of the autorun, type again:</p>
<p>dir /a:h<br />
this will display hidden files. If autorun is deleted, it will not show up anymore</p>
<p><strong>STEP 4:</strong></p>
<p>Download Dr. Delete from the internet. Any version will do but preferrably, I use version 1.<br />
It forces deletion of programs on start-up.It is essential to use this in the removal of the components of the virus.</p>
<p>Install it on any folder, preferrably program files folder. But its is an rar SFX installer (self-extracting)<br />
offering no shortcut implementation so better install on the desktop for convenience</p>
<p>Run the program (The one with the &#8220;three blocks&#8221; icon)</p>
<p>Then type these and delete one after the other:</p>
<p>C:\WINDOWS\SYSTEM32\_re101.exe<br />
C:\re101.exe<br />
C:\Program Files\Common Files\Microsoft Shared\MSInfo\re101.exe</p>
<p>Note that the virus may also be seen in places where you copied your files from your flash drive.<br />
Remember to delete them too.</p>
<p>After you are done, restart the computer.</p>
<p>To confirm its removal, the above said characteristics will not be seen anymore. If not, you missed a part of the removal process.</p>
<p>If done, you may now hide the hidden files using the normal hiding process.</p>
<p>&#8212;-By AmmiL D.&#8212;-<br />
4th year high school student, University of the Philippines Cebu</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/fskreuz.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/fskreuz.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fskreuz.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fskreuz.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fskreuz.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fskreuz.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fskreuz.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fskreuz.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fskreuz.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fskreuz.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fskreuz.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fskreuz.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fskreuz.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fskreuz.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fskreuz.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fskreuz.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fskreuz.wordpress.com&amp;blog=3371383&amp;post=3&amp;subd=fskreuz&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy"></div>]]></content:encoded>
			<wfw:commentRss>http://fskreuz.wordpress.com/2008/04/03/programmer-mode-my-manual-steps-to-remove-re101exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/705fedc62b2198fbf92f9cda72c1db05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">fskreuz</media:title>
		</media:content>
	</item>
	</channel>
</rss>
