<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: VirusHeat</title>
	<atom:link href="http://www.411-spyware.com/remove-virusheat/feed" rel="self" type="application/rss+xml" />
	<link>http://www.411-spyware.com/remove-virusheat</link>
	<description>411-Spyware.com</description>
	<lastBuildDate>Sun, 22 Nov 2009 20:58:11 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: chris</title>
		<link>http://www.411-spyware.com/remove-virusheat/comment-page-1#comment-26137</link>
		<dc:creator>chris</dc:creator>
		<pubDate>Fri, 09 May 2008 06:30:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.411-spyware.com/remove-virusheat#comment-26137</guid>
		<description>Ok. This is how I fixed a computer infected with VirusHeat (VH). 1) I ran many anti-spyware programs - starting with AVGâ€™s free version. This took care of everything except the blinking tray icon and IE loading the VH website. 2) I found a program that enables users to see what â€œthreadsâ€ are running under an EXE file, more specifically, the explorer.exe. I used the GeekSquad MRI, but you can also use something like â€œProcess Explorer.â€ Just Google it. I then noticed there was only one file that was not signed my microsoft, it was called: rtmipr.dll. It was in the windows\system32\ directory, and a file size of ~13kb. This file name was not listed under any other guides for removing VH, so I hope this helps solve the mystery file issue. 3) Download a program called â€œUnlocker,â€ this will allow you to kill the thread. Once you kill the thread, delete the file promptly. This worked for me, I hope it works for you. Good luck. Oh, and if it does work or you have a question, you may email me at: chris@ab-wd.com. Cheers!</description>
		<content:encoded><![CDATA[<p>Ok. This is how I fixed a computer infected with VirusHeat (VH). 1) I ran many anti-spyware programs &#8211; starting with <span class='bm_keywordlink_affiliate'><a href="http://www.jdoqocy.com/k0108mu2-u1HLLLMOQPHJIOLROIK" rel="nofollow">AVG</a></span>â€™s free version. This took care of everything except the blinking tray icon and IE loading the VH website. 2) I found a program that enables users to see what â€œthreadsâ€ are running under an EXE file, more specifically, the explorer.exe. I used the GeekSquad MRI, but you can also use something like â€œProcess Explorer.â€ Just Google it. I then noticed there was only one file that was not signed my microsoft, it was called: rtmipr.dll. It was in the windows\system32\ directory, and a file size of ~13kb. This file name was not listed under any other guides for removing VH, so I hope this helps solve the mystery file issue. 3) Download a program called â€œUnlocker,â€ this will allow you to kill the thread. Once you kill the thread, delete the file promptly. This worked for me, I hope it works for you. Good luck. Oh, and if it does work or you have a question, you may email me at: <a href="mailto:chris@ab-wd.com">chris@ab-wd.com</a>. Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris, at 411 Spyware</title>
		<link>http://www.411-spyware.com/remove-virusheat/comment-page-1#comment-24353</link>
		<dc:creator>Chris, at 411 Spyware</dc:creator>
		<pubDate>Fri, 18 Apr 2008 22:24:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.411-spyware.com/remove-virusheat#comment-24353</guid>
		<description>Thanks, Len.  Updated the post with your VirusHeat DLL.</description>
		<content:encoded><![CDATA[<p>Thanks, Len.  Updated the post with your VirusHeat DLL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Len Henson</title>
		<link>http://www.411-spyware.com/remove-virusheat/comment-page-1#comment-24336</link>
		<dc:creator>Len Henson</dc:creator>
		<pubDate>Fri, 18 Apr 2008 12:29:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.411-spyware.com/remove-virusheat#comment-24336</guid>
		<description>Additional dll called &quot;BUBBJ.DLL&quot; in system32 folder now identified as part of &quot;VirusHeat 4&quot; by Nod32 ver 3.0.</description>
		<content:encoded><![CDATA[<p>Additional dll called &#8220;BUBBJ.DLL&#8221; in system32 folder now identified as part of &#8220;VirusHeat 4&#8243; by Nod32 ver 3.0.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shirley Smith</title>
		<link>http://www.411-spyware.com/remove-virusheat/comment-page-1#comment-23879</link>
		<dc:creator>Shirley Smith</dc:creator>
		<pubDate>Thu, 03 Apr 2008 00:18:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.411-spyware.com/remove-virusheat#comment-23879</guid>
		<description>how often should I check for virus Heat infection.</description>
		<content:encoded><![CDATA[<p>how often should I check for virus Heat infection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shirley Smith</title>
		<link>http://www.411-spyware.com/remove-virusheat/comment-page-1#comment-23878</link>
		<dc:creator>Shirley Smith</dc:creator>
		<pubDate>Thu, 03 Apr 2008 00:10:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.411-spyware.com/remove-virusheat#comment-23878</guid>
		<description>Virus Heat and Spyware has been very information for me and fixed the the problems that I were having.</description>
		<content:encoded><![CDATA[<p>Virus Heat and Spyware has been very information for me and fixed the the problems that I were having.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
