<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Gusano Bagel</title>
	<atom:link href="http://www.bipolarplanet.com/~void/2007/12/02/gusano-bagel/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bipolarplanet.com/~void/2007/12/02/gusano-bagel/</link>
	<description>Back off, man, I'm co-creating my reality.</description>
	<pubDate>Wed, 15 Oct 2008 23:43:34 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By:  Leslie</title>
		<link>http://www.bipolarplanet.com/~void/2007/12/02/gusano-bagel/#comment-1191</link>
		<dc:creator> Leslie</dc:creator>
		<pubDate>Sat, 26 Jan 2008 20:06:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.bipolarplanet.com/~void/2007/12/02/gusano-bagel/#comment-1191</guid>
		<description>Hey, Dmitry.  It looks as if what you got is very similar.  The file srosa.exe didn't show up in google search until several days after I posted it originally.</description>
		<content:encoded><![CDATA[<p>Hey, Dmitry.  It looks as if what you got is very similar.  The file srosa.exe didn&#8217;t show up in google search until several days after I posted it originally.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By:  dmitry</title>
		<link>http://www.bipolarplanet.com/~void/2007/12/02/gusano-bagel/#comment-1190</link>
		<dc:creator> dmitry</dc:creator>
		<pubDate>Mon, 21 Jan 2008 12:03:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.bipolarplanet.com/~void/2007/12/02/gusano-bagel/#comment-1190</guid>
		<description>Hi I had nearly the same problem two days ago with Bagel.ii downloader.
It took me whole day to figure out solution.
Symptoms:
- Norton antivirus crushes
- Google toolbar produces strange messages
- Installation of any antivirus product (Norton/Kaspersky/Panda) not working
- No visible strange process
- Safe mode not working
Working Solution:
Run windows from disk into recovery shell
delete the following files:
Windows/System32/mdelk.exe
Windows/System32/drivers/hldrrr.exe
Windows/System32/drivers/wintems.exe
Windows/System32/drivers/srosa.sys
Windows/System32/drivers/down/*

If you use google toolbar, delete googleToolbarNorifier.exe
Delete all antivirus installation (this trojan replaces main antivirus executable so if you dont remove it, when you restart it loads virus instead of antivirus :( )

Reload computer in Directory recovery mode - this mode, unlike safe mode, is working. If you have registry recovery, reset registry to date before infection to enable safe mode. If not - you loose safe mode and have to do hard work to recover it.

In safe or directory recovery mode- Install kaspersky trial or any other good and most recently updated antivirus. Perform full scan and remove all ***. Hopefully you did it :)

I hope this can help anyone with same problem
-Dmitry</description>
		<content:encoded><![CDATA[<p>Hi I had nearly the same problem two days ago with Bagel.ii downloader.<br />
It took me whole day to figure out solution.<br />
Symptoms:<br />
- Norton antivirus crushes<br />
- Google toolbar produces strange messages<br />
- Installation of any antivirus product (Norton/Kaspersky/Panda) not working<br />
- No visible strange process<br />
- Safe mode not working<br />
Working Solution:<br />
Run windows from disk into recovery shell<br />
delete the following files:<br />
Windows/System32/mdelk.exe<br />
Windows/System32/drivers/hldrrr.exe<br />
Windows/System32/drivers/wintems.exe<br />
Windows/System32/drivers/srosa.sys<br />
Windows/System32/drivers/down/*</p>
<p>If you use google toolbar, delete googleToolbarNorifier.exe<br />
Delete all antivirus installation (this trojan replaces main antivirus executable so if you dont remove it, when you restart it loads virus instead of antivirus <img src='http://www.bipolarplanet.com/~void/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> )</p>
<p>Reload computer in Directory recovery mode - this mode, unlike safe mode, is working. If you have registry recovery, reset registry to date before infection to enable safe mode. If not - you loose safe mode and have to do hard work to recover it.</p>
<p>In safe or directory recovery mode- Install kaspersky trial or any other good and most recently updated antivirus. Perform full scan and remove all ***. Hopefully you did it <img src='http://www.bipolarplanet.com/~void/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I hope this can help anyone with same problem<br />
-Dmitry</p>
]]></content:encoded>
	</item>
</channel>
</rss>
