<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Free Spyware Adware Worm and Virus Trojan Horse Download Removal Tools</title>
	<atom:link href="http://www.softe.org/feed" rel="self" type="application/rss+xml" />
	<link>http://www.softe.org</link>
	<description>FREE Computer Repair</description>
	<lastBuildDate>Sun, 04 Dec 2011 21:36:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PeakProtection2010  Adware Windows 2003/XP/2000/NT/ME/98/95</title>
		<link>http://www.softe.org/peakprotection2010-adware-windows-2003xp2000ntme9895.html</link>
		<comments>http://www.softe.org/peakprotection2010-adware-windows-2003xp2000ntme9895.html#comments</comments>
		<pubDate>Sun, 04 Dec 2011 21:35:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PeakProtection2010 Adware Windows 2003/XP/2000/NT/ME/98/95]]></category>
		<category><![CDATA[adaware]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[banner]]></category>
		<category><![CDATA[melwarebytes]]></category>
		<category><![CDATA[popup]]></category>
		<category><![CDATA[spybot]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=171</guid>
		<description><![CDATA[Brief Description PeakProtection2010is spyware and adware program which lets the end PC users know of the latest spyware and virus threats in their PC&#8217; computers, much like spybot, AVG, melwarebytes and so on.PeakProtection2010 can reach the computer when the user accesses certain websites which can display banner ads and pop ups and what have you [...]]]></description>
			<content:encoded><![CDATA[<table id="table_DescripcionBreve">
<tbody>
<tr>
<td>
<h2>Brief Description<a name="BREVE"></a></h2>
</td>
<td align="right" width="1%"></td>
</tr>
<tr>
<td colspan="2"><a id="BREVE" name="BREVE"></a><em>PeakProtection2010</em>is spyware and adware program which lets the end PC users know of the latest spyware and virus threats in their PC&#8217; computers, much like spybot, AVG, melwarebytes and so on.<em>PeakProtection2010</em> can reach the computer when the user accesses certain websites which can display banner ads and pop ups and what have you which can lead to the download of this program. It can also be reached via email spam, email link and so forth.</td>
</tr>
</tbody>
</table>
<table id="table_SintomasVisibles">
<tbody>
<tr>
<td>
<h2>Visible Symptoms<a name="VISIBLES"></a></h2>
</td>
<td align="right" width="1%"></td>
</tr>
<tr>
<td colspan="2"><a id="VISIBLES" name="VISIBLES"></a><em>PeakProtection2010</em>is pretty simple to recognize.</p>
<ul>
<li>When the app runs in windows, it will display the installer like the one below.<img src="http://www.pandasecurity.com/img/enc/AdwarePeakProtection2010_img1.jpg" alt="PeakProtection2010 installation window" border="0" /></li>
<li>Once installed, the computer is restarted and the following screen is displayed where only one option can be selected:<img src="http://www.pandasecurity.com/img/enc/AdwarePeakProtection2010_img2.jpg" alt="Screen displayed by PeakProtection2010" border="0" /></li>
<li>When users click on this button, it stats scanning the system and once ended, it shows the results with the infected and restored files:<img src="http://www.pandasecurity.com/img/enc/AdwarePeakProtection2010_img3.jpg" alt="Results of the scan carried out by PeakProtection2010" border="0" /></li>
</ul>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/peakprotection2010-adware-windows-2003xp2000ntme9895.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BackDoor-EVC!8F7F8F47​013F Network Trojan and how to remove</title>
		<link>http://www.softe.org/backdoor-evc8f7f8f47%e2%80%8b013f-network-trojan-and-how-to-remove.html</link>
		<comments>http://www.softe.org/backdoor-evc8f7f8f47%e2%80%8b013f-network-trojan-and-how-to-remove.html#comments</comments>
		<pubDate>Fri, 30 Sep 2011 04:39:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[BackDoor-EVC!8F7F8F47​013F Network Trojan and how to remove]]></category>
		<category><![CDATA[back door]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[network virus]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=166</guid>
		<description><![CDATA[This backdoor Trojan  infects  files, registry, and network communication. The following registry elements have been created: HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\ HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\ HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\ HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\ HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\INPROCSERVER32\ HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\ This virus can be removed with microsoft security essentials. If your PC gets locked you are getting a black screen, you might want to run scan in safe mode. Other names to reffer [...]]]></description>
			<content:encoded><![CDATA[<p>This <strong>backdoor Trojan</strong>  infects  files, registry, and network communication.</p>
<p><strong>The following registry elements have been created:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\INPROCSERVER32\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\</li>
</ul>
<div>This virus can be removed with <strong>microsoft security essentials</strong>. If your PC gets locked you are getting a black screen, you might want to run scan in safe mode.</div>
<div>Other names to reffer to.</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/backdoor-evc8f7f8f47%e2%80%8b013f-network-trojan-and-how-to-remove.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 7 black screen ram shortage infection % of my ram wasn&#8217;t functioning properly</title>
		<link>http://www.softe.org/windows-7-black-screen-ram-shortage-infection-of-my-ram-wasnt-functioning-properly.html</link>
		<comments>http://www.softe.org/windows-7-black-screen-ram-shortage-infection-of-my-ram-wasnt-functioning-properly.html#comments</comments>
		<pubDate>Fri, 30 Sep 2011 04:29:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows 7 black screen ram shortage infection % of my ram wasn't functioning properly]]></category>
		<category><![CDATA[infection]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[ram]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=164</guid>
		<description><![CDATA[If your windows 7 screen turns black and you get an error stating something along the lines of ram shortage infection or a given % value was not functioning properly, here is what you do: download unhide.exe and TDssKiller Run  TDSSKiller and it will locate your infection. It will ask you to remoev the infection [...]]]></description>
			<content:encoded><![CDATA[<p>If your windows 7 screen turns black and you get an error stating something along the lines of ram shortage infection or a given % value was not functioning properly, here is what you do:</p>
<p><span style="color: #000000;"><strong>download </strong><a href="http://download.bleepingcomputer.com/grinler/unhide.exe" target="_blank">unhide.exe</a> and <a href="http://support.kaspersky.com/downloads/utils/tdsskiller.exe" target="_blank">TDssKiller</a></span><br />
Run  TDSSKiller and it will locate your infection. It will ask you to remoev the infection ans simply say yes.  IF all goes well and your PC is clean, it will ask to reboot your windows 7. Please do so.</p>
<p>It will most likely find: <strong>TrojanDownloader.OpenStream.NBF trojan</strong></p>
<p>If this does not work for you, download the latest <strong>malwarebytes</strong> and update and scan.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/windows-7-black-screen-ram-shortage-infection-of-my-ram-wasnt-functioning-properly.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>So how do you Remove Koobface the facebook worm virus</title>
		<link>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html</link>
		<comments>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html#comments</comments>
		<pubDate>Thu, 08 Sep 2011 18:50:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[So how do you Remove Koobface the facebook worm virus]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[google redirect spyware]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[windows xp]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=159</guid>
		<description><![CDATA[Koobface Virus threat is one that is taking by storm, specially because it uses a host such as facebook social network to spread the virus.  This Koobface virus finds methods to seek into the users PC and spread malware into the computer so its considered as a worm which replicates itself within your computer.  So [...]]]></description>
			<content:encoded><![CDATA[<p>Koobface Virus threat is one that is taking by storm, specially because it uses a host such as facebook social network to spread the virus.  This Koobface virus finds methods to seek into the users PC and spread malware into the computer so its considered as a worm which replicates itself within your computer.  So how does KoobFace infect your PC, well its simple really, if you use facebook, and you receive a strange email, stating something along the lines of &#8221; click here to see your face look stupid&#8221; which attracts you to click the link,  once clicked, a virus code will be downloaded to your PC which will then spread the worm to your PC and start to redirect your search results from google to malicious software and websites. Simple huh?</p>
<div>
<div id="mod_2169282">
<div id="txtd_2169282">
<div>
<div id="mod_2169300">
<h2>So how do you Remove Koobface worm virus?</h2>
<div id="txtd_2169300">With  anti-malware software such as melwarebytes and spybot, you might be able to remove this worm, but sometimes this is not possible and you need to manually remove it.</p>
<div>
<div id="mod_2169358">
<div id="txtd_2169358">
<p><strong>Using The Add Remove Program in control panel:</strong></p>
<ul>
<li>Go to Add\Remove in control panel</li>
<li>Look up for the Koobface malware to remove and uninstall it.</li>
</ul>
<p>if you do not see the koobface there, go to registry and search for: ( <span style="color: #ff0000;">if you do not know how to use your registry, you might really screw up your PC for good, so take note, this step is for advanced users who have messed around with the registry and know their way around</span>.)</p>
<ul>
<li>Search for &#8220;koobface&#8221; in Mycomputer using find utility.</li>
<li>Note down Koobface file path some where.</li>
<li>Press Ctrl+Alt+Del to open &#8216;Task Manager&#8217;</li>
<li>End the &#8220;Koobface&#8221; processes.</li>
</ul>
<p><strong>End the following processes</strong></p>
<ol>
<li>%SYSTEMROOT%\bolivar28.exe</li>
<li>che07.exe</li>
<li>bolivar28.exe</li>
<li>%WinDir%\system32\nScan\ekrn.exe</li>
<li>%WinDir%\system32\nScan\ecls.exe</li>
<li>%WinDir%\system32\splm\ncsjapi32.exe</li>
<li>%WinDir%\bolivar28.exe</li>
<li>C:\Windows\fbtre6.exe</li>
</ol>
<p><strong>now change Registry Files</strong></p>
<ul>
<li>Type &#8216;regedit&#8217; in Run and press Enter.</li>
<li>The Registry Editor will appear, locate the above mentioned process files and delete them.</li>
<li>Locate &#8220;Koobface&#8221; registry entries and delete them, they are as the follows:</li>
</ul>
<ol>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Intelli Mouse Pro Version 2.0B\StubPath: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Intelli Mouse Pro Version 2.0B: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden: &#8220;2&#8243;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\nScan32\ExecuteDate: &#8220;14\8\2008&#8243;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\&#8221;systray&#8221; = &#8220;c:\windows\mstre6.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\&#8221;systray&#8221; = &#8220;C:\Windows\fbtre6.exe&#8221;</li>
<li>HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating</li>
</ol>
</div>
</div>
</div>
<div id="mod_2169659">
<div id="txtd_2169659">
<p><strong>Now you have to unregister the dll files</strong></p>
<ul>
<li>Go to start and type in &#8216;cmd&#8217; to open comman prompt.</li>
<li>First locate the following dll files using &#8216;dir&#8217; command.</li>
</ul>
<ol>
<li>%WinDir%\system32\nScan\ekrnEmon.dll</li>
<li>%WinDir%\system32\nScan\ekrnScan.dll</li>
<li>%WinDir%\system32\nScan\ekrnEpfw.dll</li>
<li>%WinDir%\system32\nScan\ekrnAmon.dll</li>
<li>%WinDir%\system32\splm\lmfunit32.dll</li>
<li>%WinDir%\system32\splm\mcaserv32.dll</li>
<li>%WinDir%\system32\splm\kbdsapi.dll</li>
</ol>
<ul>
<li>Now change the current directory using &#8216;cd&#8217; command leave a space after &#8216;cd&#8217; and then the path of dll file, which you have located above. Press enter after this.</li>
<li>Now unregister dll file by typing &#8220;directory path+&#8217;regsvr32/u&#8217;+dll file name&#8221;. Press enter, the file will be unregistered.</li>
</ul>
<p>&nbsp;</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic.tfr!k!D9296BE​1A117 Trojan Virus and how to clean</title>
		<link>http://www.softe.org/generic-tfrkd9296be%e2%80%8b1a117-trojan-virus-and-how-to-clean.html</link>
		<comments>http://www.softe.org/generic-tfrkd9296be%e2%80%8b1a117-trojan-virus-and-how-to-clean.html#comments</comments>
		<pubDate>Thu, 25 Aug 2011 21:46:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic.tfr!k!D9296BE​1A117 Trojan Virus and how to clean]]></category>
		<category><![CDATA[anti-spyware]]></category>
		<category><![CDATA[antispyware]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[panda]]></category>
		<category><![CDATA[system scan]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=157</guid>
		<description><![CDATA[This Trojan virus is simple to clean but if left untreated, it will enter into your source data applications in windows and corrupted your system. To clean, simply run your anti virus software, we suggest Microsoft Security Essentials. If your anti-spyware app closes, this means the virus has blocked access to your app. You may [...]]]></description>
			<content:encoded><![CDATA[<p>This Trojan virus is simple to clean but if left untreated, it will enter into your source data applications in windows and corrupted your system.</p>
<p>To clean, simply run your anti virus software, we suggest <strong>Microsoft Security Essentials</strong>. If your <strong>anti-spyware</strong> app closes, this means the virus has blocked access to your app. You may either do a system scan online via Panda, or try running your <strong>antispyware</strong> in safemode.</p>
<p><strong>Other Aliases from other anti virus companies<br />
</strong></p>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr bgcolor="silver">
<th align="left" bgcolor="silver"><strong>Company<br />
</strong></th>
<th align="right" bgcolor="silver"><strong>Virus Names</strong></th>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Generic19.BWBB</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">Trojan:Win32/Rodecap.A</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Malware.TUMA</td>
</tr>
</tbody>
</table>
<p><strong>The following files were analyzed:</strong></p>
<p>3766d83c6754d41c912c87b1f001fe2a1eea6747</p>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following files have been added to the system:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>%WINDIR%\cmstp.exe</li>
</ul>
<ul>
<li>%USERPROFILE%\Local Settings\Application Data\ieudinit.exe</li>
</ul>
<ul>
<li>%APPDATA%\esentutl.exe</li>
</ul>
<ul>
<li>%WINDIR%\SYSTEM32\drivers\mqtgsvc.exe</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following registry elements have been created:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\</li>
</ul>
<ul>
<li>HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following registry elements have been changed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS\LOAD = %WINDIR%\SYSTEM32\drivers\mqtgsvc.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\CMSTP = %WINDIR%\cmstp.exe /waitservice</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\IEUDINIT = C:\DOCUME~1\ADMINI~1.VMG\LOCALS~1\APPLIC~1\ieudinit.exe /waitservice</li>
</ul>
<ul>
<li>HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\ESENT UTL = C:\DOCUME~1\ADMINI~1.VMG\APPLIC~1\esentutl.exe /waitservice</li>
</ul>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/generic-tfrkd9296be%e2%80%8b1a117-trojan-virus-and-how-to-clean.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic BackDoor!djf!5D41C80E​A0DA malware Trojan Virus</title>
		<link>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html</link>
		<comments>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html#comments</comments>
		<pubDate>Wed, 20 Jul 2011 22:58:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic BackDoor!djf!5D41C80E​A0DA malware Trojan Virus]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[IRC virus]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[virus removal]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[W32/Autorun]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=154</guid>
		<description><![CDATA[These files were added to the system: %APPDATA%\services.exe %TEMP%\e3c1c08557a0d0feee33b9c9d18b4e6c129b553f.exe This Trojan will attempt to fiddle with your network conection, e.g hxxp://www.maxmind.com/app/*** Virus app&#8217;s Detection Names EMSI Software Trojan.Backdoor.Ircbot!IK avast Win32:Ruskill-F Kaspersky Backdoor.Win32.IRCBot.tjd BitDefender Backdoor.Bot.138642 Microsoft VirTool:Win32/CeeInject.gen!EI Symantec Backdoor.IRC.Bot Eset a variant of Win32/Injector.GLN trojan norman W32/Suspicious_Gen3.TYCW Sophos Mal/Generic-L Trend Micro PAK_Generic.001 vba32 Backdoor.IRCBot.tjd How to [...]]]></description>
			<content:encoded><![CDATA[<p>These files were added to the system:</p>
<ul>
<li>%APPDATA%\services.exe</li>
</ul>
<ul>
<li>%TEMP%\e3c1c08557a0d0feee33b9c9d18b4e6c129b553f.exe</li>
</ul>
<p>This Trojan will attempt to fiddle with your network conection, e.g hxxp://www.maxmind.com/app/***</p>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr bgcolor="silver">
<th align="left" bgcolor="silver"><strong>Virus app&#8217;s<br />
</strong></th>
<th align="right" bgcolor="silver"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">EMSI Software</td>
<td align="right">Trojan.Backdoor.Ircbot!IK</td>
</tr>
<tr>
<td align="left">avast</td>
<td align="right">Win32:Ruskill-F</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Backdoor.Win32.IRCBot.tjd</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Backdoor.Bot.138642</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">VirTool:Win32/CeeInject.gen!EI</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">Backdoor.IRC.Bot</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">a variant of Win32/Injector.GLN trojan</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Suspicious_Gen3.TYCW</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Mal/Generic-L</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">PAK_Generic.001</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">Backdoor.IRCBot.tjd</td>
</tr>
</tbody>
</table>
<p>How to remove <strong>Generic BackDoor!djf!5D41C80E​A0DA</strong></p>
<p>Removal should be easy given the fact that you are able to follow directions <img src='http://www.softe.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>First thing to do is disconnect your network or internet. Now you will need to reboot your PC and enter safe mode, if you do not know how to enter safe mode, please search above for &#8221; how to enter safe mode&#8221;</p>
<p>Now you will need to do a system scan using these apps below:</p>
<p>1. your favorite virus app, i suggest AVG or Microsoft security essentials<br />
2. do a system scan using Malwarebytes<br />
3. do a system scan using spybot<br />
4. do a system scan using hijackthis</p>
<p>if the virus  is not letting you do these scans, you must :</p>
<p>1.Disable System Restore on Windows ME and windows XP only.<br />
2.Update to current engine and DAT files for detection and removal.<br />
3.Run a complete system scan.</p>
<p>This should remove the threat, this threat is a low security threat but never the less it should always be cleaned before using the world wide web.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan.win32.Generic.pak!cobra.Engine</title>
		<link>http://www.softe.org/trojan-win32-generic-pakcobra-engine.html</link>
		<comments>http://www.softe.org/trojan-win32-generic-pakcobra-engine.html#comments</comments>
		<pubDate>Mon, 27 Jun 2011 19:22:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan.win32.Generic.pak!cobra.Engine]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[spybot]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[win32]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=149</guid>
		<description><![CDATA[This virus might be a google redirect trojan and it is not easy to clean, however, these are the first steps to take in trying to delete this nasty win32 virus. go to start menu, then run, now type in MSCONFIG, go to startup tab and look for a long string of command that has [...]]]></description>
			<content:encoded><![CDATA[<p>This virus might be a google redirect trojan and it is not easy to clean, however, these are the first steps to take in trying to delete this nasty win32 virus.</p>
<p>go to start menu, then run, now type in MSCONFIG, go to startup tab and look for a long string of command that has random letters and sometimes numbers, disable that line and save.</p>
<p><a href="http://www.softe.org/download"><strong>Download Malwarebytes</strong></a>, update malwarebytes then do a full system scan. if any virus is found, it will delete it.</p>
<p>Now <a href="http://www.softe.org/download"><strong>download spybot</strong></a>, do an update and a full scan, delete any melware or spyware it finds.</p>
<p>You surly must have a virus protection software, if not, download <a href="http://www.softe.org/download"><strong>Microsoft Security Essentials</strong></a>, its free, update the app then a full scan.</p>
<p>These steps above should fix and delete the <strong>Trojan.win32.Generic.pak!cobra.Engine virus</strong></p>
<p>Here are other virus trojans that are smiler to the one above and can be cleaned the same way.</p>
<p><a href="http://www.softe.org/wp-content/uploads/2011/06/computer-virus.jpg"><img class="alignleft size-full wp-image-152" title="computer virus" src="http://www.softe.org/wp-content/uploads/2011/06/computer-virus.jpg" alt="" width="380" height="253" /></a></p>
<p>Trojan.Win32.Generic!BT: Trojan<br />
Trojan-Spy.Win32.Zbot.gen: Trojan<br />
Exploit.PDF-JS.Gen (v): Exploit<br />
Trojan.Win32.Generic!SB.0: Trojan<br />
INF.Autorun (v): Trojan<br />
Trojan.Win32.Hiloti.gen.d (v): Trojan<br />
Trojan.Win32.Generic.pak!cobra: Trojan<br />
Trojan.Win32.Adware: Adware (General)<br />
MyWebSearch Toolbar: Potentially Unwanted Program<br />
Trojan.Win32.Malware: Trojan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/trojan-win32-generic-pakcobra-engine.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus PWS-Zbot.gen.gi!E69284FFC72E</title>
		<link>http://www.softe.org/virus-pws-zbot-gen-gie69284ffc72e.html</link>
		<comments>http://www.softe.org/virus-pws-zbot-gen-gie69284ffc72e.html#comments</comments>
		<pubDate>Mon, 20 Jun 2011 19:02:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus PWS-Zbot.gen.gi!E69284FFC72E]]></category>
		<category><![CDATA[how to clean virus]]></category>
		<category><![CDATA[me]]></category>
		<category><![CDATA[system restore]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=145</guid>
		<description><![CDATA[Other Company Detection Aliases Company Names Detection Names AVG (GriSoft) Generic23.CWM avira TR/FakeSysdef.A.1499 Kaspersky HEUR:Trojan.Win32.Generic BitDefender Gen:Variant.Kazy.26475 FortiNet W32/Krap.AON!tr Symantec Trojan.Fakeav Eset Win32/Kryptik.OYP Sophos Mal/FakeAV-IK Attempts to connect to a high risk domain that may pose a security risk.  It also creates one or more shortcuts .LNK files to provide user accessible links to start [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Other Company Detection Aliases</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Generic23.CWM</td>
</tr>
<tr>
<td align="left">avira</td>
<td align="right">TR/FakeSysdef.A.1499</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">HEUR:Trojan.Win32.Generic</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Gen:Variant.Kazy.26475</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/Krap.AON!tr</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">Trojan.Fakeav</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Kryptik.OYP</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Mal/FakeAV-IK</td>
</tr>
</tbody>
</table>
<p>Attempts to connect to a high risk domain that may pose a security risk.  It also creates one or more shortcuts .LNK files to provide user accessible links to start a program usually form the desktop or start menu.</p>
<table>
<tbody>
<tr>
<td><strong>The following registry elements have been changed:</strong></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\USE FORMSUGGEST = Yes</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\CERTIFICATEREVOCATION = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\WARNONBADCERTRECVING = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\WARNONZONECROSSING = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\ZONES\3\1601 = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\WINTRUST\TRUST PROVIDERS\SOFTWARE PUBLISHING\STATE = 146944</li>
</ul>
<table>
<tbody>
<tr>
<td><strong>The applications attempted the following network connection(s):</strong></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<ul>
<li>188.229.88.***:80</li>
</ul>
<ul>
<li>46.161.11.***:80</li>
</ul>
<ul>
<li>hxxp://searcham.org/*****</li>
</ul>
<p>&nbsp;</p>
<p>To remove this virus,</p>
<p>1.<strong>Disable System Restore Windows ME XP only</strong><strong>.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan.</p>
<p>Modifications made to the system Registry and  INI files for the purposes of hooking system startup, will be removed if cleaning with the recommended engine and DAT combination or higher.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/virus-pws-zbot-gen-gie69284ffc72e.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Profile: Fake Alert Security Tool.bt!4611C</title>
		<link>http://www.softe.org/virus-profile-fake-alert-security-tool-bt4611c.html</link>
		<comments>http://www.softe.org/virus-profile-fake-alert-security-tool-bt4611c.html#comments</comments>
		<pubDate>Mon, 20 Jun 2011 18:47:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Profile: Fake Alert Security Tool.bt!4611C]]></category>
		<category><![CDATA[fake alert]]></category>
		<category><![CDATA[security tool]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=143</guid>
		<description><![CDATA[This is a Trojan that will infect your PC, be cautious, it enumerates many system files and directories. McAfee Detection FakeAlert-SecurityTool.bt System Changes Some path values have been replaced with environment variables as the exact location may vary with different configurations. e.g. %WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000) %PROGRAMFILES% = \Program Files The [...]]]></description>
			<content:encoded><![CDATA[<p>This is a Trojan that will infect your PC, be cautious, it enumerates many system files and directories.</p>
<p>McAfee Detection	FakeAlert-SecurityTool.bt</p>
<p><strong>System Changes</strong><br />
Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</p>
<p><strong>The following registry elements have been created:</strong><br />
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\</p>
<p><strong>The following registry elements have been changed:</strong><br />
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\{92780B25-18CC-41C8-B9BE-3C9C571A8263} = 8193<br />
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\NEXTID = 8194<br />
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\PO28273LJGGI28273 = %ALLUSERSPROFILE%\Application Data\pO28273LjGgI28273\pO28273LjGgI28273.exe</p>
<p><strong>How to remove this Virus threat</strong></p>
<p>1.Disable System Restore on Windows ME and windows XP only.<br />
2.Update to current engine and DAT files for detection and removal.<br />
3.Run a complete system scan.</p>
<p>This should remove the threat, this threat is a low security threat but never the less it should always be cleaned before using the world wide web.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/virus-profile-fake-alert-security-tool-bt4611c.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Profile: BackDoor-CEP.gen how to clean</title>
		<link>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html</link>
		<comments>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html#comments</comments>
		<pubDate>Fri, 20 May 2011 06:16:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Profile: BackDoor-CEP.gen how to clean]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=140</guid>
		<description><![CDATA[Virus Profile: BackDoor-CEP.gen.cq!CF151229CE1E avast Win32:Caxnet [Trj] AVG (GriSoft) Rootkit-Pakes.BG (Trojan horse) avira TR/Koutodoor.psa Kaspersky HEUR:Trojan.Win32.Generic BitDefender Gen:Variant.Koutodoor.18 clamav Trojan.Dropper-27717 Dr.Web Trojan.MulDrop.origin F-Prot W32/Koutodoor.N.gen!Eldorado FortiNet W32/Koutodoor.KWD!tr.bdr Microsoft Trojan:Win32/Koutodoor.E Symantec Trojan.Koutodoor Eset Win32/Koutodoor.HM trojan (variant) norman W32/Suspicious_Gen2.LZIQS (trojan) panda Trj/Genetic.gen rising Trojan.Win32.Generic.1282E422 Sophos Troj/Kouto-D Trend Micro TROJ_DLOADR.SMOM vba32 Trojan.Downloader.gen.h (suspected) The following files have been added to [...]]]></description>
			<content:encoded><![CDATA[<p>Virus Profile: BackDoor-CEP.gen.cq!CF151229CE1E</p>
<p>avast	Win32:Caxnet [Trj]<br />
AVG (GriSoft)	Rootkit-Pakes.BG (Trojan horse)<br />
avira	TR/Koutodoor.psa<br />
Kaspersky	HEUR:Trojan.Win32.Generic<br />
BitDefender	Gen:Variant.Koutodoor.18<br />
clamav	Trojan.Dropper-27717<br />
Dr.Web	Trojan.MulDrop.origin<br />
F-Prot	W32/Koutodoor.N.gen!Eldorado<br />
FortiNet	W32/Koutodoor.KWD!tr.bdr<br />
Microsoft	Trojan:Win32/Koutodoor.E<br />
Symantec	Trojan.Koutodoor<br />
Eset	Win32/Koutodoor.HM trojan (variant)<br />
norman	W32/Suspicious_Gen2.LZIQS (trojan)<br />
panda	Trj/Genetic.gen<br />
rising	Trojan.Win32.Generic.1282E422<br />
Sophos	Troj/Kouto-D<br />
Trend Micro	TROJ_DLOADR.SMOM<br />
vba32	Trojan.Downloader.gen.h (suspected)</p>
<p>The following files have been added to the system:<br />
%WINDIR%\SYSTEM32\szccw.dll<br />
%TEMP%\nsd12.tmp<br />
%PROGRAMFILES%\Microsoft\ie13\Internat Explorer\target.lnk<br />
%ALLUSERSPROFILE%\Desktop\Internat Explorer.jgp<br />
%WINDIR%\SYSTEM32\drivers\fmsde.sys<br />
%PROGRAMFILES%\Microsoft\ie13\Internat Explorer\Desktop.ini<br />
	The following files were temporarily written to disk then later removed:<br />
%TEMP%\hmufctw.bat<br />
%TEMP%\nsq13.tmp<br />
%TEMP%\ygnpyvce.bat<br />
%TEMP%\nsi11.tmp<br />
%WINDIR%\SYSTEM32\mhzscp.bat<br />
%TEMP%\faxjdr.exe<br />
%TEMP%\tmp.bat<br />
%TEMP%\yxcdiz.exe<br />
%TEMP%\nsq13.tmp\System.dll<br />
%TEMP%\wcyolgo.bat<br />
%TEMP%\ftrnkqxw.bat</p>
<p>This is a Trojan detection Unlike viruses Trojans do not self replicate they are spread manually under the premise that they are beneficial. The most common installation methods involve system security exploitation unsuspecting users manually executing unknown programs. Distribution channels include email malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks and what have  you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Android/Actrack.B GPS spyware tracker</title>
		<link>http://www.softe.org/androidactrack-b-gps-spyware-tracker.html</link>
		<comments>http://www.softe.org/androidactrack-b-gps-spyware-tracker.html#comments</comments>
		<pubDate>Wed, 27 Apr 2011 18:50:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Android/Actrack.B GPS spyware tracker]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=138</guid>
		<description><![CDATA[Android/Actrack.B is pretty scary spyware which sends the victims GPS location to an external server in which they have created. This spyware basically tracks the location of the user. you must be careful not to down load this spyware as its all over the android market. After the attacker has finished configuring the software and [...]]]></description>
			<content:encoded><![CDATA[<p>Android/Actrack.B is pretty scary spyware which sends the victims GPS location to an external server in which they have created. This spyware basically tracks the location of the user.<br />
you must be careful not to down load this spyware as its all over the android market.</p>
<p>After the attacker has finished configuring the software and setting the monitoring period, Android/Actrack.B spyware will run in the background of your phone and will start to send your GPS location information to their server controlled by the vendor. So be careful not to be a victim of this latest spyware. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/androidactrack-b-gps-spyware-tracker.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google showing pharmacy links solution and fix</title>
		<link>http://www.softe.org/google-showing-pharmacy-links-solution-and-fix.html</link>
		<comments>http://www.softe.org/google-showing-pharmacy-links-solution-and-fix.html#comments</comments>
		<pubDate>Fri, 25 Mar 2011 21:17:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Google showing pharmacy links solution and fix]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[base64]]></category>
		<category><![CDATA[filezilla]]></category>
		<category><![CDATA[google index]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[server virus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=135</guid>
		<description><![CDATA[Does your website now show pharmacy ads or other none related ads? Has google indexed your pages as none relevant content? If so, this is because of a virus. Your server has been hacked due to insecure files or most likely you are using old version of joomla, wordperss or any other content management system. Don't panic, there is a fix but action must be taken asap. ]]></description>
			<content:encoded><![CDATA[<p>Does your website now show pharmacy ads or other none related ads? Has google indexed your pages as none relevant content? If so, this is because of a virus. Your server has been hacked due to insecure files or most likely you are using old version of joomla, wordperss or any other content management system. Don&#8217;t panic, there is a fix but action must be taken asap.</p>
<p>These bots have  injected &#8220;badware&#8221; i like to call it, into your server, which  gives them a backdoor entrance to your server, changing password might  slow the bots down from cracking the code, but over all you must clean  your server and files. Download a free FTP application, a good one is Filezilla, you can get it here  <a href="http://filezilla-project.org/download.php" target="_blank">http://filezilla-project.org/download.php</a><br />
make sure you check your main config files where your database info is, and make sure permissions are 744<br />
Now  download all of your files on the  server to your hard drive, then scan them with your virus software. AVG or Microsoft Security Essentials are free virus apps and work great.</p>
<p>Once your entire server has been download to your hard drive, sort the files and folders by date. Now the dates that are the most recent are the files and folders that have been altered.<br />
You might have to edit all the php files, most likely the files are index.php files and any other file that has a recent date. Edit these files with your favorite html editor and look for <strong>base64 </strong>codes, or any code that is within an iframe or a redirect code, these codes are always either on top of the source code or on the bottom right before<span style="color: #ff0000;"> <strong>?&gt;</strong></span></p>
<p>They also plant the code in  many files along with .js files, if you have more than one domain on  your server, then be sure that they will plant more threats on your  other domain files.</p>
<p>Once again,download your  entire site to your PC, and do a virus scan locally on the files and  make sure no virus files have been planted, then go through all your  folders one by one checking the date, if date is new, then open the php  file and look to see if there is a code.</p>
<p>These backdoor viruses are planted because plugins and wordperss  is not updated, make sure you  update wordpress/joomla etc.  as soon as they come out with a new version. also  update the plugins if needed, that is under the WP admin dashboard as  well.</p>
<p>Once you are sure your files are clean and everything above has been done,  go to google webmaster tools <a rel="nofollow" href="http://www.google.com/webmasters/tools/" target="_blank">www.google.com/webmasters/tools/</a><br />
and click on threats and see if your site in there says infected, if so,  you must send an email right through the tools section to google  telling them your site is now clean, if not, google will block your sites from firefox and chrome saying its infected.</p>
<p>If all goes well, your site should be backup and indexed properly within a few weeks.</p>
<p>PS: if you do not care about your files or database, its easier to just delete all files in your server and reinstall your script and create a new database.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/google-showing-pharmacy-links-solution-and-fix.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Google Redirect Virus Spyware for free</title>
		<link>http://www.softe.org/how-to-remove-google-redirect-virus-spyware-for-free.html</link>
		<comments>http://www.softe.org/how-to-remove-google-redirect-virus-spyware-for-free.html#comments</comments>
		<pubDate>Tue, 15 Mar 2011 03:30:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to Remove Google Redirect Virus Spyware for free]]></category>
		<category><![CDATA[google redirect spyware]]></category>
		<category><![CDATA[Google Redirect virus spyware]]></category>
		<category><![CDATA[malicious files]]></category>
		<category><![CDATA[MalwareBytes AntiMalware Program]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=133</guid>
		<description><![CDATA[So many people have emailed me wanting help with a nasty Google Redirect spyware that takes over their browser, so i thought i would post a quick fix.]]></description>
			<content:encoded><![CDATA[<p>So many people have emailed me wanting help with a nasty <strong>Google Redirect spyware</strong> that takes over their browser, so i thought i would post a quick fix.</p>
<p>If  you load a browser such as firefox, chrome or internet explorer, and either the page you are searching for takes you to a completely different page results, or simply it redirects you to another website that is totally erelevant to what you were looking for in the first place, then you have whats called the <strong>google redirect spyware</strong>.</p>
<p>First step is to <a href="http://www.silentrunners.org/" target="_blank">download Silent Runners</a> which will show <strong>malicious files</strong></p>
<p>Now please do the following</p>
<p>open your <strong>MalwareBytes AntiMalware Program</strong><br />
Click the Update Tab and search for updates<br />
If an update is found, it will download and install the latest version.<br />
Once the program has loaded, select &#8220;Perform Quick Scan&#8221;, then click Scan.<br />
The scan may take some time to finish, so please be patient.<br />
When the scan is complete, click OK, then Show Results to view the results.<br />
Make sure that everything is checked, and click Remove Selected- very important<br />
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.<br />
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br />
Copy and Paste the entire report in your next reply.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-google-redirect-virus-spyware-for-free.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Win32/Olmarik Trojan malware</title>
		<link>http://www.softe.org/how-to-remove-win32olmarik-trojan-malware.html</link>
		<comments>http://www.softe.org/how-to-remove-win32olmarik-trojan-malware.html#comments</comments>
		<pubDate>Wed, 09 Mar 2011 05:33:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[IRC virus]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[messaging]]></category>
		<category><![CDATA[scareware]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[W32/Autorun]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=130</guid>
		<description><![CDATA[If  your PC has been infected with the Win32/Olmarik  Trojan virus, please download Malwarebytes' Anti-Malware its a free app. Double click]]></description>
			<content:encoded><![CDATA[<p>If  your PC has been infected with the Win32/Olmarik  Trojan virus, please download Malwarebytes&#8217; Anti-Malware its a free app. Double click <strong>mbam-setup.exe</strong> and follow the directions and install it on your home PC. Make sure you click update Malwarebytes before you press the scan button.</p>
<p>What the Win32/Olmarik trojan does is it infects your PC by installing a nasty malware by falsified displaying security alerts and making the user install even more bugs. Once you click on   the alert, it will start downloading anti-spyware or anti-virus tools that are useless and will infect even more of  your file system structure and files in general. Take care of this trojan as soon as you can to prevent our PC from getting any worse.</p>
<p><img class="alignnone" title="Virus win32 trojan" src="http://farinango.info/wp-content/uploads/2010/06/virus-farinango.info_.jpg" alt="" width="400" height="365" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-win32olmarik-trojan-malware.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic Trojan BackDoor!cyh!E437DACF​F88B Virus Threat Removal</title>
		<link>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html</link>
		<comments>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html#comments</comments>
		<pubDate>Wed, 09 Mar 2011 05:22:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic BackDoor!cyh!E437DACF​F88B Virus Threat Removal]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[generic]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=128</guid>
		<description><![CDATA[Download Malwarebytes' Anti-Malware if you do now have this free software, from  here and save it to your computer.]]></description>
			<content:encoded><![CDATA[<p><strong>ystem Changes</strong></p>
<p>Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</p>
<p><strong>The following registry elements have been created:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\29AEB4A0365755F6-B862CAE984EA4D0E\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\29AEB4A0365755F6-B862CAE984EA4D0E\02F01F553A112DCE-00C9DB38C18D5FD1\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMADEVELOPERS\</li>
</ul>
<p><strong>The following files have been added to the system:</strong></p>
<p>* %WINDIR%\SYSTEM32\svhest.dll</p>
<p>* %WINDIR%\SYSTEM32\svhest.exe</p>
<p>To remove <strong>Generic Trojan BackDoor!cyh!E437DACF​F88B Virus</strong></p>
<p>Download Malwarebytes&#8217; Anti-Malware if you do now have this free software, from  <a href="http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html" target="_blank"><strong><span style="color: red;">here</span></strong></a> and save it to your computer.</p>
<ul>
<li>Double click <strong>mbam-setup.exe</strong> and install</li>
<li>At the end of the installation be sure a checkmark
<ul>
<li><strong>Update Malwarebytes&#8217; Anti-Malware</strong></li>
<li>and <strong>Launch Malwarebytes&#8217; Anti-Malware</strong></li>
<li><strong>do a full scan and allow your computer to fix your virus.<br />
</strong></li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32/Olmarik trojan virus removal</title>
		<link>http://www.softe.org/win32olmarik-trojan-virus-removal.html</link>
		<comments>http://www.softe.org/win32olmarik-trojan-virus-removal.html#comments</comments>
		<pubDate>Thu, 24 Feb 2011 22:34:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Win32/Olmarik trojan virus removal]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=125</guid>
		<description><![CDATA[To clean this nasty Win32/Olmariktrojan horse virus,

Open RootRepeal, click the Drivers tab and select Scan. Right click and select Wipe File on:]]></description>
			<content:encoded><![CDATA[<p>To clean this nasty Win32/Olmariktrojan horse virus,</p>
<p>Open <strong><span style="color: green;">RootRepeal</span></strong>, click the <strong>Drivers</strong> tab and select <strong>Scan</strong>.  Right click and select <strong>Wipe File</strong> on:</p>
<p><strong>H8SRTmeyqxwbpxd.sys</strong></p>
<p>Click the <strong>Files</strong> tab and select <strong>Scan</strong>.  Right click and select <strong>Wipe File</strong> on any file that begins with the following:</p>
<p><strong>H8SRT</strong></p>
<p>Do the same for the Hidden Services tab.</p>
<p><strong><span style="color: red;">Reboot your machine</span></strong></p>
<p>Then let&#8217;s run RootRepeal again:</p>
<ul>
<li>Double click <strong>ROOTREPEAL </strong>to start the program</li>
<li>Click on the <strong>Report</strong> tab at the bottom of the program window</li>
<li>Click the <strong>SCAN </strong>button</li>
<li>In the <strong>Select Scan</strong> dialog, check:
<ul><span style="color: green;"></p>
<li><strong>Drivers</strong></li>
<li><strong>Files</strong></li>
<li><strong>Processes</strong></li>
<li><strong>SSDT</strong></li>
<li><strong>Stealth Objects</strong></li>
<li><strong>Hidden Services</strong></li>
<li><strong>Shadow SSDT</strong></li>
<p></span></ul>
</li>
<li>Click the <strong>OK</strong> button</li>
<li>In the next dialog, select <strong>all drives</strong> showing</li>
<li>Click <strong>OK</strong> to start the scan<br />
<blockquote><p><em>Note: The scan can take some time. <strong><span style="color: red;">DO NOT</span></strong> run any other programs while the scan is running</em></p></blockquote>
</li>
<li>When the scan is complete, click the<strong> SAVE REPORT</strong> button and save the report to your Desktop as <strong>RootRepeal.txt</strong></li>
<li>Go to <strong>File</strong>, then <strong>Exit</strong> to close the program</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/win32olmarik-trojan-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Stuxnet computer malware malicious software</title>
		<link>http://www.softe.org/what-is-stuxnet-computer-malware-malicious-software.html</link>
		<comments>http://www.softe.org/what-is-stuxnet-computer-malware-malicious-software.html#comments</comments>
		<pubDate>Wed, 02 Feb 2011 22:25:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[What is Stuxnet computer malware malicious software]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[malicious software]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=123</guid>
		<description><![CDATA[Stuxnet . A computer malware spyware that attacks computer systems aimed mostly at Iran which seems the ones involved in creating the spyware threat.]]></description>
			<content:encoded><![CDATA[<p><strong>Stuxnet </strong>. A computer malware spyware that attacks computer systems aimed mostly at Iran which seems the ones involved in creating the spyware threat.</p>
<p>HOW DOES IT Stuxnet really WORK?</p>
<p>The virus is a malicious software or <strong>malware </strong>attacks widely used industrial control systems built by the German firm Siemens. Experts say the virus could be used for espionage or sabotage.</p>
<p>Siemens said that the <strong>malware </strong>is spread via infected USB memory devices thumb drive, exploiting a vulnerability in Microsoft operating system Windows that has been resolved.</p>
<p>The attacks malware software running Supervisory Control and Data Acquisition, or <strong>SCADA</strong>, systems. These systems are used to control automated installations &#8211; plant chemicals to food and energy generators.</p>
<p>Analysts said the attackers may have chosen to spread malicious software by the way of a memory unit because many SCADA systems are not connected to the Internet, but do not have USB ports.</p>
<p>Once the <strong>worm infects a system</strong>, it quickly communicates with a remote server computer can be used to steal proprietary corporate data or take control of the SCADA system, said Randy Abrams, ESET investigator, a private security company <strong>Stuxnet </strong>been studied.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/what-is-stuxnet-computer-malware-malicious-software.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Downloader-CEW.q!D113​7DCFCEBA Trojan how to remove</title>
		<link>http://www.softe.org/downloader-cew-qd113%e2%80%8b7dcfceba-trojan-how-to-remove.html</link>
		<comments>http://www.softe.org/downloader-cew-qd113%e2%80%8b7dcfceba-trojan-how-to-remove.html#comments</comments>
		<pubDate>Wed, 02 Feb 2011 21:36:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Downloader-CEW.q!D113​7DCFCEBA Trojan]]></category>
		<category><![CDATA[Adobe Flash Player]]></category>
		<category><![CDATA[agent]]></category>
		<category><![CDATA[authplay.dll]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[melwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[Popup Blocker]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=120</guid>
		<description><![CDATA[Downloader-CEW.q!D113​7DCFCEBA Trojan how to remove]]></description>
			<content:encoded><![CDATA[<p><strong><br />
</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">HEUR:Trojan.Win32.Generic</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Trojan.DownLoader1.60944</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/FakeAlert.IV.gen!Eldorado</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">TrojanDownloader:Win32/Renos.LX</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Kryptik.KDM trojan (variant)</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Obfuscated.M</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">Suspicious</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Mal/FakeAV-CX</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Trojan.Codecpack.Gen.13 (mutant)</td>
</tr>
<tr>
<td align="left">Vet (Computer Associates)</td>
<td align="right">Win32/Renos.D!generic</td>
</tr>
</tbody>
</table>
<p>1.<strong>Disable System Restore windows XP only, Win 7 will not work.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan using AGG or Microsoft security or Kaspersky</p>
<p>Modifications made to the system Registry  files for the purposes of hooking system startup will be removed if cleaning with the recommended engine and DAT combination.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/downloader-cew-qd113%e2%80%8b7dcfceba-trojan-how-to-remove.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Trojan.Zlob.P virus trojan</title>
		<link>http://www.softe.org/how-to-remove-trojan-zlob-p-virus-trojan.html</link>
		<comments>http://www.softe.org/how-to-remove-trojan-zlob-p-virus-trojan.html#comments</comments>
		<pubDate>Tue, 25 Jan 2011 00:06:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to remove Trojan.Zlob.P virus trojan]]></category>
		<category><![CDATA[definition]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[safemode]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=117</guid>
		<description><![CDATA[Temporarily Disable System Restore  then update the virus definitions on your virus program then Reboot computer in SafeMode, then delete the IE temp files some Trojan.Zlob.P]]></description>
			<content:encoded><![CDATA[<p>Temporarily Disable System Restore  then update the virus definitions on your virus program then Reboot computer in SafeMode, then delete the IE temp files some <strong>Trojan.Zlob.P </strong>temp file exisit in that folder as well, you can wither search for the temp files or manually delete them.<br />
You may now download <strong>Malwarebytes </strong>from <a href="http://www.malwarebytes.org/mbam-download.php" target="_blank"><span style="color: #0000ff;"><strong>Here</strong></span></a> or <a href="http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html" target="_blank"><span style="color: #0000ff;"><strong>Here</strong></span></a></p>
<p>Update the definition and scan your computer, it will find any traces of <strong>Trojan.Zlob.P</strong> now delete and you should be good to go.<strong> </strong></p>
<p><strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-trojan-zlob-p-virus-trojan.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/RAHack!DD10EDBD56​90 Virus Removal</title>
		<link>http://www.softe.org/w32rahackdd10edbd56%e2%80%8b90-virus-removal.html</link>
		<comments>http://www.softe.org/w32rahackdd10edbd56%e2%80%8b90-virus-removal.html#comments</comments>
		<pubDate>Fri, 14 Jan 2011 20:43:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/RAHack!DD10EDBD56​90 Virus Removal]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[RAhack]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=114</guid>
		<description><![CDATA[W32/RAHack!DD10EDBD56​90 Virus Removal Update to current engine and DAT files for detection and removal.]]></description>
			<content:encoded><![CDATA[<p><strong>Other Common Aliases</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">avast</td>
<td align="right">Win32:Allaple [Wrm]</td>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Worm/Allaple.B</td>
</tr>
<tr>
<td align="left">avira</td>
<td align="right">WORM/Allaple.Gen</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Net-Worm.Win32.Allaple.b</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Win32.Worm.Allaple.Gen</td>
</tr>
<tr>
<td align="left">clamav</td>
<td align="right">Worm.Allaple-255</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Trojan.Starman</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/RAHack.A.gen!Eldorado</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/Allaple.gen!tr</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">worm:win32/allaple.a</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">W32.Rahack.W</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Kryptik.AJD trojan (variant)</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">Allaple.gen (trojan)</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">W32/Rahack.gen.worm</td>
</tr>
<tr>
<td align="left">rising</td>
<td align="right">Worm.Win32.Allaple.a</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">W32/Allaple-F</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">WORM_ALLAPLE.IK</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">OScope.Malware-Cryptor.Win32.Allaple</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Error</td>
</tr>
<tr>
<td align="left">Vet (Computer Associates)</td>
<td align="right">Win32/Mallar.Y</td>
</tr>
</tbody>
</table>
<p><strong>The following files were analyzed:</strong></p>
<p>urdvxc.exe<br />
<strong>The following files have been added to the system:</strong></p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bzqlkhrh.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\vkjljzrn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\web server extensions\40\bin\1033\ebsjlbhn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bhrhnkht.exe</p>
<p>* %PROGRAMFILES%\Adobe\Reader 9.0\rrtkrbtl.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\elwtjnbj.exe</p>
<p>* %TEMP%\0A5A6FE619B07BBAFB1F9C1B5F798F7DF96745D9</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bnbtzwxt.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bcwvzwbh.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\ehbebsrn.exe</p>
<p>* %PROGRAMFILES%\msn\msncorefiles\tlbhnrlv.exe</p>
<p>* %PROGRAMFILES%\Microsoft Office\OFFICE11\rsrrhtck.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\nsqjttkv.exe</p>
<p>* %PROGRAMFILES%\netmeeting\rsewzjqn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\qjllsjhl.exe</p>
<p>* %COMMONPROGRAMFILES%\system\ado\tsektjkj.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\web server extensions\40\bin\brbvhsvx.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\brvrjrke.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\njbsvtll.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\tlcwjrwt.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\czjevcet.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\xrljqjzn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\web server extensions\40\bin\tjnwrhns.exe</p>
<p><strong>How to remove this virus.</strong></p>
<p>1.<strong>Disable System Restore (Windows ME/XP only)</strong><strong>.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32rahackdd10edbd56%e2%80%8b90-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/HLLP.Philis.ki!DD​08745D1471 Virus Removal</title>
		<link>http://www.softe.org/w32hllp-philis-kidd%e2%80%8b08745d1471-virus-removal.html</link>
		<comments>http://www.softe.org/w32hllp-philis-kidd%e2%80%8b08745d1471-virus-removal.html#comments</comments>
		<pubDate>Fri, 14 Jan 2011 20:33:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/HLLP.Philis.ki!DD​08745D1471 Virus Removal]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=112</guid>
		<description><![CDATA[This symptoms of this W32/HLLP.Philis.ki detection are the  registry and network communication.]]></description>
			<content:encoded><![CDATA[<p>This symptoms of this W32/HLLP.Philis.ki detection are the  registry and network communication.</p>
<p>1.<strong>Disable System Restore (Windows ME/XP only)</strong><strong>.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan.</p>
<p>Modifications  made to the system Registry and/or INI files for the purposes of  hooking system startup, will be successfully removed if cleaning with  the recommended engine and DAT combination (or higher).</p>
<table>
<tbody>
<tr>
<td><strong>The following files have been changed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>c:\Users exe File.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\AcroTextExtractor.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\AdobeCollabSync.exe</li>
</ul>
<ul>
<li>c:\Users exe File.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\AcroRd32.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\msn\msncorefiles\copymar.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\Eula.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\Reader_sl.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\AcroRd32Info.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\msn\msncorefiles\dw.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Microsoft Office\OFFICE11\EXCEL.EXE</li>
</ul>
<ul>
<li>%PROGRAMFILES%\msn\msncorefiles\setup\msnunin.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\LogTransport2.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\AcroBroker.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\PDFPrevHndlrShim.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\msn\msncorefiles\update.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\msn\msncorefiles\msn6.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Setup Files\{AC76BA86-7AD7-[private subnet]-A92000000001}\Setup.exe</li>
</ul>
<ul>
<li>c:\Users exe File.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\A3DUtility.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\winrar\winrar.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Microsoft Office\OFFICE11\WINWORD.EXE</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following files were temporarily written to disk then later removed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>%TEMP%\$$a5.bat</li>
</ul>
<ul>
<li>%TEMP%\049E09EA0D36D974DB4B1DF0A56D2AC2E1507FAF</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following registry elements have been created:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\DOWNLOADMANAGER\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\SOFT\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\SOFT\DOWNLOADWWW\</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following registry elements have been changed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS\LOAD = %WINDIR%\rundl132.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\SOFT\DOWNLOADWWW\AUTO = 49</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The applications attempted the following network connection(s):</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>hxxp://www.17aa.com/ic4/*****</li>
</ul>
<ul>
<li>222.186.12.**:80</li>
</ul>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32hllp-philis-kidd%e2%80%8b08745d1471-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Chrome 10.0.628.0 has tracking spyware</title>
		<link>http://www.softe.org/google-chrome-10-0-628-0-has-tracking-spyware.html</link>
		<comments>http://www.softe.org/google-chrome-10-0-628-0-has-tracking-spyware.html#comments</comments>
		<pubDate>Mon, 10 Jan 2011 22:07:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Google Chrome 10.0.628.0 has tracking spyware]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[doubleclick]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[mediaplex]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[tracking]]></category>
		<category><![CDATA[win32]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=110</guid>
		<description><![CDATA[So for those of you who always want to install beta software from another company rather then the company who created the app in the first place, then this is what you get.]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone" title="google chrome logo" src="http://www.inquisitr.com/wp-content/google-chrome-os.jpg" alt="" width="357" height="255" /></p>
<p>So for those of you who always want to install beta software from another company rather then the company who created the app in the first place, then this is what you get. I installed Google Chrome version 10.0.628.0 which is a beta version published by a third party company and after using it for a few weeks, i then did a spybot scan and found out that this version of chrome is not good at all. It found the following tracking cookies which can harm ones comptuer.</p>
<p><strong>Win32.PornPopUp: Tracking cookie (Chrome: Chrome)<br />
MediaPlex: Tracking cookie (Chrome: Chrome)<br />
Adbrit: Tracking cookie (Chrome: Chrome)<br />
DoubleCLick: Tracking cookie (Chrome: Chrome) doubleclick.net</strong></p>
<p>so if you are using a beta version of chrome, uninstall it asap and install the real version from google. <a href="http://www.google.com/chrome" target="_blank">Click here to download google chrome</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/google-chrome-10-0-628-0-has-tracking-spyware.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/RAHack Worm/Allaple.A Virus Removal</title>
		<link>http://www.softe.org/w32rahack-wormallaple-a-virus-removal.html</link>
		<comments>http://www.softe.org/w32rahack-wormallaple-a-virus-removal.html#comments</comments>
		<pubDate>Fri, 17 Dec 2010 00:45:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/RAHack Worm/Allaple.A Virus Removal]]></category>
		<category><![CDATA[combfix]]></category>
		<category><![CDATA[melwarebytes]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=108</guid>
		<description><![CDATA[Although this is a low threat virus, the removal of W32/RAHack Worm/Allaple.A Virus  can be a pest but i have found that COMBFIX will remove this threat from your PC. Simply download CombFix by clicking here]]></description>
			<content:encoded><![CDATA[<p><strong>Other Common Detection Aliases</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Worm/Allaple.A</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">worm:win32/allaple.a</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">W32.Rahack.W</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">Allaple.gen</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">W32/Rahack.gen</td>
</tr>
</tbody>
</table>
<p><em>some of the path values that have been replaced with environment variables as the location may vary with different configurations for example.</p>
<p>%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</em></p>
<p><strong>The following files were scanned:</strong></p>
<p>urdvxc.exe</p>
<p><strong>REMOVAL</strong></p>
<p>Although this is a low threat virus, the removal of W32/RAHack Worm/Allaple.A Virus  can be a pest but i have found that COMBFIX will remove this threat from your PC. Simply <a href="http://www.bleepingcomputer.com/download/anti-virus/combofix" target="_blank">download CombFix by clicking</a> here, save it to your desktop, double click and and press next a few times and let the program scan your PC and clean it. Very simple really, might take some time and make sure you close all browsers and applications before you run CombFix.</p>
<p>Or you may just use MelwareBytes to remove the W32/RAHack virus. I would scan with both apps just to make sure. Good luck</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32rahack-wormallaple-a-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove CoolWebSearch.olehelp Malware</title>
		<link>http://www.softe.org/how-to-remove-coolwebsearch-olehelp-malware.html</link>
		<comments>http://www.softe.org/how-to-remove-coolwebsearch-olehelp-malware.html#comments</comments>
		<pubDate>Wed, 08 Dec 2010 22:18:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to remove CoolWebSearch.olehelp Malware]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[infected]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malwarebytes]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=104</guid>
		<description><![CDATA[Is your PC infected with the CoolWebSearch.olehelp Malware? Let me help you remove this nasty browser hijacker.]]></description>
			<content:encoded><![CDATA[<p>Is your PC infected with the CoolWebSearch.olehelp Malware? Let me help you remove this nasty browser hijacker.</p>
<p><strong>CoolWebSearch</strong> or short for CWS is a pretty harsh hijacker which attacks firefox or chrome and even internet explorer browsers. One thing to take note is that if this threat is not stopped, it will keep growing like a nasty virus as its knowing coolwebsearch keeps coming up with a newer threat every week. This Malware goes adn alters your homepage on your browser and or might redirect your homepage or any other website y ou visit to another website that might contain a virus or malware. The good news is, its pretty easy to remove this virus.</p>
<p>To remove this nasty browser hijacker malware, simply download <strong>Malwarebytes </strong>Anti Malware by <a href="http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&amp;subj=dl&amp;tag=button" target="_blank">clicking here and save it to your desktop</a>. Run and install the free application. Now run Malwarebytes and make sure you update the program first before you scan your PC. Scan your PC now and it will remove CoolWebSearch.olehelp Malware and your PC will be save once again.</p>
<p><img class="alignnone" src="http://images.betanews.com/screenshots/1186760019-1.gif" alt="" width="551" height="424" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-coolwebsearch-olehelp-malware.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.SillyFDC.BDO worm clean with Webroot Spy Sweeper</title>
		<link>http://www.softe.org/w32-sillyfdc-bdo-worm-clean-with-webroot-spy-sweeper.html</link>
		<comments>http://www.softe.org/w32-sillyfdc-bdo-worm-clean-with-webroot-spy-sweeper.html#comments</comments>
		<pubDate>Wed, 01 Dec 2010 07:28:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32.SillyFDC.BDO worm clean with Webroot Spy Sweeper]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[spy sweeper]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[webroot]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=101</guid>
		<description><![CDATA[I was able to capture this W32.SillyFDC.BDO worm on my test machine and run a few tests to see which software did the best cleaning and its safe to say Spy Sweeper by Webroot was the winner. ]]></description>
			<content:encoded><![CDATA[<p>W32.SillyFDC.BDO is a new discovered worm that spreads by copying itself to removable drives such as external hard drivers, USB flash drivers, etc.</p>
<p>I was able to capture this <strong>W32.SillyFDC.BDO worm</strong> on my test machine and run a few tests to see which software did the best cleaning and its safe to say<strong> Spy Sweeper</strong> by <strong>Webroot </strong>was the winner.<br />
Webroot AntiVirus 2010 with Spy  Sweeper is one of the best apps that will  protect your PC from virus threats,  spyware, adware, worms and Trojans malware. One great thing i found about spy sweeper is that it protects your PC real time without bottle necking or slowing down your net speed or even your PC&#8217;s resources. Unlike Norton which really takes away a good portion of your memory and hogs your system resources.</p>
<p><strong>W32.SillyFDC.BDO worm</strong><br />
When executed this worm copies itself as the following files:</p>
<ul>
<li>%SystemDrive%\services.exe</li>
<li>%Windir%\services.exe</li>
</ul>
<p>It then creates the following registry entry so that it runs every time Windows starts:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;ServiceControlApp&#8221; = &#8220;%SystemDrive%\services.exe&#8221;</p>
<p>The worm also modifies the following registry entries:</p>
<ul>
<li>HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;ShowSuperHidden&#8221; = &#8220;0&#8243;</li>
<li>HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;HideFileExt&#8221; = &#8220;1&#8243;</li>
</ul>
<p><strong>To clean this threat, simply run Webroot Spy Sweeper</strong></p>
<p>Clean this threat manually:</p>
<ol>
<li>Disable System Restore (Windows Me/XP).</li>
<li>Update the virus definitions.</li>
<li>Run a full system scan.</li>
<li>Delete any values added to the registry.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32-sillyfdc-bdo-worm-clean-with-webroot-spy-sweeper.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Microsoft Security Essentials Trojan Virus Manual Removal</title>
		<link>http://www.softe.org/fake-microsoft-security-essentials-trojan-virus-manual-removal.html</link>
		<comments>http://www.softe.org/fake-microsoft-security-essentials-trojan-virus-manual-removal.html#comments</comments>
		<pubDate>Tue, 16 Nov 2010 00:12:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Fake Microsoft Security Essentials Trojan Virus Manual Removal]]></category>
		<category><![CDATA[combfix]]></category>
		<category><![CDATA[fake]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=97</guid>
		<description><![CDATA[Although it is possible to manually remove the Fake Microsoft Security Essentials Alert Trojan  Virus, it can also damage your system if you are not familiar with how to use the registry, as advanced spyware are able to automatically repair themselves if not completely deleted.]]></description>
			<content:encoded><![CDATA[<p>Although it is possible to manually remove the <strong>Fake Microsoft Security Essentials Alert Trojan</strong> Virus, it can also damage your system if you are not familiar with how to use the registry, as advanced spyware are able to automatically repair themselves if not completely deleted. so in other words, manual spyware removal is recommended for experienced users only. For other users, we recommend using Malwarebytes or other malware spyware removal software such as <strong>Combofix</strong>.  Malwarebytes deletes and protects from malicious running trojan  files and registry entries for free.  Malwarebytes will help you to remove Fake Microsoft Security Essentials Alert Virus.</p>
<p><strong>Stop the Fake Microsoft Security Essentials Alert Trojan processes below by pressing CTRL + Alt + Delete:</strong></p>
<p>antispy.exe<br />
defender.exe<br />
tmp.exe<br />
hotfix.exe</p>
<p><strong>Remove these Fake Microsoft Security Essentials Alert Trojan Registry Entries:<br />
Click start menu and type &#8220;regedit&#8221;</strong></p>
<p>HKEY_CURRENT_USER\Software\PAV<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings &#8220;WarnonBadCertRecving&#8221; = &#8220;0?<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings &#8220;WarnOnPostRedirect&#8221; = &#8220;0?<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#8220;tmp&#8221;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce &#8220;SelfdelNT&#8221;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon &#8220;Shell&#8221; = &#8220;%UserProfile%\Application Data\antispy.exe&#8221;<br />
<strong>Remove these Fake Microsoft Security Essentials Alert Trojan files:</strong><br />
%UserProfile%\Application Data\PAV\<br />
%UserProfile%\Application Data\antispy.exe<br />
%UserProfile%\Application Data\defender.exe<br />
%UserProfile%\Application Data\tmp.exe<br />
%UserProfile%\Application Data\hotfix.exe<br />
%UserProfile%\Local Settings\Temp\[random characters].bat</p>
<p>For Vista/7:<br />
%UserProfile%\AppData\Local\antispy.exe<br />
%UserProfile%\AppData\Local\defender.exe<br />
%UserProfile%\AppData\Local\tmp.exe<br />
%UserProfile%\AppData\Local\hotfix.exe</p>
<p>C:\END<br />
It is impossible to list all file names and locations of modern parasites. You can identify remaining parasites, other Fake Microsoft Security Essentials Alert Trojan infected files and get help in Fake Microsoft Security Essentials Alert Trojan removal by using free Malwarebytes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/fake-microsoft-security-essentials-trojan-virus-manual-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/Autorun.worm.zf.gen!F342CDD8894F Virus</title>
		<link>http://www.softe.org/w32autorun-worm-zf-genf342cdd8894f-virus.html</link>
		<comments>http://www.softe.org/w32autorun-worm-zf-genf342cdd8894f-virus.html#comments</comments>
		<pubDate>Wed, 27 Oct 2010 18:14:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/Autorun.worm.zf.gen!F342CDD8894F Virus]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[W32/Autorun]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=94</guid>
		<description><![CDATA[Viruses are self replicating which are often spread by a network or by transmission to a removable medium e.g writable CD, or USB drive. Viruses may also spread by infecting files on a network system or a file system that is shared by another users computer. Company Names Detection Names AVG (GriSoft) Packed.AutoIt Kaspersky Worm.Win32.Autoit.xl [...]]]></description>
			<content:encoded><![CDATA[<p>Viruses are self replicating which are often spread by a network or by  transmission to a removable medium e.g writable  CD, or USB drive. Viruses may also spread by infecting files on a  network system or a file system that is shared by another users computer.</p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Packed.AutoIt</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Worm.Win32.Autoit.xl</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Backdoor.Generic.434041</td>
</tr>
<tr>
<td align="left">ClamAV</td>
<td align="right">Trojan.Autoit-70</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Win32.HLLW.Autoruner.based</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/AutoIt.M.gen!Eldorado</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/AutoIt.A!worm</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">Worm:Win32/Autorun.XK</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">W32.Harakit</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Packed.Autoit.B.Gen (application)</td>
</tr>
<tr>
<td align="left">Norman</td>
<td align="right">Suspicious_Gen2.BFSNZ (trojan)</td>
</tr>
<tr>
<td align="left">Panda</td>
<td align="right">Trj/CI.A</td>
</tr>
<tr>
<td align="left">Rising</td>
<td align="right">Trojan.Win32.Generic.520A2FD6</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Sus/Tiotua-A (suspicious)</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">TROJ_GEN.R99C1HD</td>
</tr>
<tr>
<td align="left">Vba32</td>
<td align="right">Trojan.Autoit.F</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Trojan.Autoit.Gen!Pac</td>
</tr>
</tbody>
</table>
<p>The applications attempted the following network connections.</p>
<p>77.55.21.***:80<br />
95.211.21.***:82<br />
95.211.21.***:80<br />
72.233.89.***:80<br />
hxxp://95.211.21.184:89/*****<br />
194.71.107.**:80<br />
95.211.21.***:89<br />
209.190.24.**:80<br />
95.211.21.***:85</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32autorun-worm-zf-genf342cdd8894f-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skintrim.gen.k!72FD33EC8D39 Trojan Horse Virus</title>
		<link>http://www.softe.org/skintrim-gen-k72fd33ec8d39-trojan-horse-virus.html</link>
		<comments>http://www.softe.org/skintrim-gen-k72fd33ec8d39-trojan-horse-virus.html#comments</comments>
		<pubDate>Wed, 27 Oct 2010 18:03:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Skintrim.gen.k!72FD33EC8D39 Trojan Horse Virus]]></category>
		<category><![CDATA[email virus]]></category>
		<category><![CDATA[IRC virus]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=91</guid>
		<description><![CDATA[This is a Trojan Horse which most might think its a virus,  unlike viruses Trojanhorses  do not self replicate but rather are spread manually often under the premise that they are beneficial . The most common installation methods involve system or security exploitation and unsuspecting one can manually executing unknown programs. The way these Trojans [...]]]></description>
			<content:encoded><![CDATA[<p>This is a Trojan Horse which most might think its a virus,  unlike viruses Trojanhorses  do not  self replicate but rather are spread manually often under the premise that  they are beneficial . The most common installation methods  involve system or security exploitation and unsuspecting one can manually  executing unknown programs. The way these Trojans are spread is via e-mail,  Web pages, Internet Relay Chat, peer-to-peer  networks and so on.</p>
<h2>Indication of Infection</h2>
<p>This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.</p>
<p><em>Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/skintrim-gen-k72fd33ec8d39-trojan-horse-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>rogue.defensecenter base.dat Trojan Virus Clean</title>
		<link>http://www.softe.org/rogue-defensecenter-base-dat-trojan-virus-clean.html</link>
		<comments>http://www.softe.org/rogue-defensecenter-base-dat-trojan-virus-clean.html#comments</comments>
		<pubDate>Wed, 20 Oct 2010 18:41:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[rogue.defensecenter base.dat Trojan Virus Clean]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=88</guid>
		<description><![CDATA[Security experts advise the use of legitimate anti malware applications such as MalwareBytes or SpyBot to clean your PC.]]></description>
			<content:encoded><![CDATA[<p>A virus Defense Center will be  installed on computers without user permission through the use of Trojan  that automatically downloads and runs on the target machine. Advocacy  Center emulates an anti-virus program, and detecting the threats that  exist on the computer to trick users about the current security status. A  system for recording the program will continue and insists that the  activation of the Center for Defense or the registration code is  necessary to eliminate all threats detected. It is not surprising to  learn that this security program malicious attempt to convince users to  buy and do anything, including what the affected computer to a hostage.  Only allow users to remove Advocacy Center after the licensed version is  purchased. Automatic removal prohibited it did not include an entry in  Windows Add / Remove Programs. Manual Advocacy Center to get rid of it  may be impossible for non-technical users as most of the files are  hidden and buried in the files of the system.</p>
<p>Security experts  advise the use of legitimate anti malware applications such as MalwareBytes or SpyBot to clean your PC.</p>
<table border="0">
<tbody>
<tr>
<td>Type</td>
<td>Rogue</td>
</tr>
<tr>
<td>Sub-Type</td>
<td>FakeAV</td>
</tr>
<tr>
<td>Aliases</td>
<td>Defense Center</td>
</tr>
<tr>
<td>OS Affected</td>
<td>Windows</td>
</tr>
<tr>
<td>Detected By</td>
<td>MalwareBytes</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/rogue-defensecenter-base-dat-trojan-virus-clean.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic Downloader.g Virus Trojan</title>
		<link>http://www.softe.org/generic-downloader-g-virus-trojan.html</link>
		<comments>http://www.softe.org/generic-downloader-g-virus-trojan.html#comments</comments>
		<pubDate>Wed, 22 Sep 2010 01:00:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic Downloader.g Virus Trojan]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=86</guid>
		<description><![CDATA[Unlike viruses, trojans do not self replicate. They are handwritten, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer, etc.]]></description>
			<content:encoded><![CDATA[<h2>Description</h2>
<p>Unlike viruses, trojans do not self replicate. They are handwritten,  often under the premise that they are beneficial or wanted. The most  common installation methods involve system or security exploitation, and  unsuspecting users manually executing unknown programs. Distribution  channels include email, malicious or hacked web pages, Internet Relay  Chat (IRC), peer-to-peer, etc.</p>
<h2>Indication of Infection</h2>
<ul>
<li>
<ul>
<li>Presence of above mentioned files and registry keys.</li>
<li>Presence of above mentioned activities.</li>
<li>It connects to the the following sites and downloads malicious files
<ul>
<li>[removed]eaarc.com/down/update10h.rar</li>
<li>[removed]eaard.com/down/hou.rar</li>
<li>[removed]eaarb.com/down/hou.rar</li>
</ul>
</li>
</ul>
</li>
</ul>
<p><strong>File Information – </strong></p>
<p>MD5 &#8211; 05f964429ecfe93cfee5f03a4ab92f5b<br />
SHA1 &#8211; 8c801922f21423f7062fd638cea0072e6c23d5dc</p>
<p><strong>Aliases – </strong></p>
<p>Kaspersky  &#8211; Trojan-Downloader.Win32.Agent.fdt<br />
Microsoft &#8211; TrojanDownloader:Win32/Agent.ZAL<br />
NOD32 &#8211; Win32/Mefir.AA<br />
Symantec – Downloader</p>
<p><strong>Characteristics -</strong></p>
<p>&#8220;<strong>Generic Downloader.g</strong>&#8221; is a trojan detection which downloads files from the site &#8220;korea[removed].com&#8221; and executes on the user machine.</p>
<p><strong>Upon execution, the Trojan copies a file into the following locations</p>
<p></strong></p>
<ul>
<li>
<ul>
<li>%Windir%\system32\notepod.exe</li>
</ul>
</li>
</ul>
<p><strong>And drops the following files</strong></p>
<ul>
<li>
<ul>
<li>%Windir%\system32\odbcwyp32.dll [Detected as Generic.Downloader.g]</li>
<li>%Windir%\system32\disk.ico</li>
<li>%Windir%\config\systemprofile\Cookies\system@koreaard[1].txt</li>
<li>%Windir%\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8WEL7ODI\hou[1].htm</li>
</ul>
</li>
</ul>
<p><strong>The following registry keys have been added</strong></p>
<ul>
<li>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\notepod.exe</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\notepod.exe\shell</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\notepod.exe\shell\open<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\notepod.exe\shell\open\command</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP\Enum</li>
</ul>
</li>
</ul>
<p><strong>The following registry values have been added</strong></p>
<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\notepod.exe\shell\open\command]<br />
= &#8220;&#8221;%Windir%\system32%\notepod.exe&#8221; &#8220;%1&#8243;&#8221;</p>
<p><strong>The above registry entry confirms that, the Trojan changes the file  notepad.exe into notepod.exe.<br />
When ever user tries to open any notepad application, the trojan will executes immediately.</strong></p>
<ul>
<li>
<ul>
<li>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RSVP\0000\Control]<br />
NewlyCreated = 0&#215;00000000</li>
<li>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RSVP\0000]<br />
Service = &#8220;RSVP&#8221;<br />
Legacy = 0&#215;00000001<br />
ConfigFlags = 0&#215;00000000<br />
Class = &#8220;LegacyDriver&#8221;<br />
ClassGUID = &#8220;{8ECC055D-047F-11D1-A537-0000F8753ED1}&#8221;<br />
DeviceDesc = &#8220;QoS RSVP&#8221;</li>
<li>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RSVP]<br />
NextInstance = 0&#215;00000001</li>
<li>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]<br />
ProxyEnable = 0&#215;00000000</li>
</ul>
</li>
</ul>
<p><strong>The following registry Values have been modified</strong></p>
<ul>
<li>
<ul>
<li>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent\]<br />
= 0x0000000D</li>
<li>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RSVP\]<br />
Start = 0&#215;00000002</li>
<li>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RSVP\]<br />
ErrorControl = 0&#215;00000000</li>
</ul>
</li>
</ul>
<p><strong>The following file has been modified</strong></p>
<ul>
<li>
<ul>
<li>%Windir%\system32\rsvp.exe</li>
</ul>
</li>
</ul>
<p><strong>The following folders have been added</p>
<p></strong></p>
<ul>
<li>
<ul>
<li>%Windir%\Web\webdc</li>
<li>%Windir%\Web\webhp</li>
<li>%Windir%\Web\webpf</li>
<li>%Windir%\Web\webpt</li>
<li>%Windir%\Web\webxs</li>
</ul>
</li>
</ul>
<p>[Note : %WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/generic-downloader-g-virus-trojan.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/RAHack!F5BCF5719797 Virus Threat Low Risk</title>
		<link>http://www.softe.org/w32rahackf5bcf5719797-virus-threat-low-risk.html</link>
		<comments>http://www.softe.org/w32rahackf5bcf5719797-virus-threat-low-risk.html#comments</comments>
		<pubDate>Wed, 22 Sep 2010 00:56:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/RAHack!F5BCF5719797 Virus Threat]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=84</guid>
		<description><![CDATA[Viruses are self replicating They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. Viruses may also spread by infecting files on a network file system or a file system that is shared by another computer.
Indication of Infection]]></description>
			<content:encoded><![CDATA[<p><strong>Description</strong><br />
Viruses are self replicating They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. Viruses may also spread by infecting files on a network file system or a file system that is shared by another computer.<br />
Indication of Infection</p>
<p>This symptoms of this detection are the files registry and network communication referenced in the characteristics section.</p>
<p><strong>Methods of Infection</strong><br />
Viruses are self replicating. They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. Viruses may also spread by infecting files on a network file system or a file system that is shared by another computer.</p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">Avast</td>
<td align="right">Win32:Allaple [Wrm]</td>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Worm/Allaple.B</td>
</tr>
<tr>
<td align="left">Avira</td>
<td align="right">WORM/Allaple.Gen</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Net-Worm.Win32.Allaple.b</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Win32.Worm.Allaple.Gen</td>
</tr>
<tr>
<td align="left">ClamAV</td>
<td align="right">Worm.Allaple-308</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Trojan.Starman</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/RAHack.A.gen!Eldorado</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/Allaple.gen!tr</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">worm:win32/allaple.a</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">W32.Rahack.W</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Kryptik.AJD trojan (variant)</td>
</tr>
<tr>
<td align="left">Norman</td>
<td align="right">Allaple.gen (trojan)</td>
</tr>
<tr>
<td align="left">Panda</td>
<td align="right">W32/Rahack.gen.worm</td>
</tr>
<tr>
<td align="left">Rising</td>
<td align="right">Worm.Win32.Allaple.a</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">W32/Allaple-F</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">WORM_ALLAPLE.IK</td>
</tr>
<tr>
<td align="left">Vba32</td>
<td align="right">OScope.Malware-Cryptor.Win32.Allaple</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Error</td>
</tr>
<tr>
<td align="left">Vet (Computer Associates)</td>
<td align="right">Win32/Mallar</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32rahackf5bcf5719797-virus-threat-low-risk.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>how to celan W32/VBMania@MM Virus Worm</title>
		<link>http://www.softe.org/how-to-celan-w32vbmaniamm-virus-worm.html</link>
		<comments>http://www.softe.org/how-to-celan-w32vbmaniamm-virus-worm.html#comments</comments>
		<pubDate>Wed, 15 Sep 2010 19:33:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[how to celan W32/VBMania@MM Virus Worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=82</guid>
		<description><![CDATA[This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it&#8217;s quite common for viruses to do nothing more than spread from one system to another. Characteristics - This Virus has [...]]]></description>
			<content:encoded><![CDATA[<p>This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it&#8217;s quite common for viruses to do nothing more than spread from one system to another.</p>
<p><strong>Characteristics -</strong></p>
<p>This Virus has been seen in large spam runs with the subject line: &#8220;Here you have&#8221;.</p>
<p><strong>When executed, the following files are dropped:</strong></p>
<p>    * %WINDIR%\system\Administrator CV 2010.exe<br />
    * %WINDIR%\system\updates.exe<br />
    * %WINDIR%\Administrator CV 2010.exe<br />
    * %WINDIR%\autorun.inf<br />
    * %WINDIR%\autorun2.inf<br />
    * %WINDIR%\csrss.exe<br />
    * %WINDIR%\vb.vbs<br />
    * %DIR%\Administrator CV 2010.exe<br />
    * %WINDIR%\tryme1.exe<br />
    * %WINDIR%\im.exe<br />
    * %WINDIR%\csrss.exe<br />
    * %WINDIR%\vb.vbs<br />
    * %TEMP%\~DF1DC7.tmp<br />
    * %WINDIR%\ie.exe<br />
    * %WINDIR%\rd.exe<br />
    * %WINDIR%\re.exe<br />
    * %WINDIR%\system\updates.exe<br />
    * %WINDIR%\SYSTEM32\SendEmail.dll<br />
    * %WINDIR%\gc.exe<br />
    * %WINDIR%\hst.iq<br />
    * %WINDIR%\ff.exe<br />
    * %WINDIR%\op.exe<br />
    * %WINDIR%\pspv.exe<br />
    * %WINDIR%\re.iq<br />
    * %WINDIR%\ff.dlm<br />
    * %APPDATA%\addons.dat</p>
<p>Where %WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)</p>
<p><strong>The following files were temporarily written to disk then later removed:</strong></p>
<p>    * %WINDIR%\ff.iq<br />
    * %WINDIR%\ie.iq<br />
    * %WINDIR%\SendEmail.iq<br />
    * %WINDIR%\w.iq<br />
    * %WINDIR%\m.iq<br />
    * %WINDIR%\gc.iq<br />
    * %WINDIR%\SYSTEM32\drivers\etc\hosts<br />
    * %WINDIR%\pspv.iq<br />
    * %WINDIR%\w.exe<br />
    * %WINDIR%\tryme.iq<br />
    * %WINDIR%\im.iq<br />
    * %WINDIR%\rd.iq<br />
    * %TEMP%\~DFAFA.tmp<br />
    * %WINDIR%\m.exe<br />
    * %WINDIR%\SendEmail.dll<br />
    * %WINDIR%\b.bat<br />
    * %WINDIR%\op.iq</p>
<p><strong>The following file was modified:</strong></p>
<p>    * %WINDIR%\SYSTEM32\wbem\logs\wbemprox.log</p>
<p>The malware has been known to randomly delete certain existing executables and replaces the current host file.</p>
<p><strong>Registry changes are made like the ones below to prevent certain system tools from running. This is a subset of the complete changes :</strong></p>
<p>    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\00hoeav.com<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\0w.com<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.ExE<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.ExE<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.ExE<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.ExE<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\6.bat<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\6fnlpetp.exe<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\6x8be16.cmd<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2cmd.ExE<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2free.ExE<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2service.ExE<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2upd.ExE<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\abk.bat<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adobe Gamma Loader.exe<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\algsrvs.exe<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\algssl.exe<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\angry.bat<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aNtIaRP.ExE<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antihost.exe<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aNtS.ExE<br />
    * HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apu-0607g.xml<br />
    * HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS SCRIPT HOST\<br />
      HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS SCRIPT HOST\SETTINGS\</p>
<p><strong>The following registry element was modified:</strong></p>
<p>    * HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\LOCKED = 1</p>
<p>The following registry key was added to get past the outlook security message prompt</p>
<p>    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\12.0\Outlook\Security\ObjectModelGuard = 0&#215;00000002</p>
<p>Connections to the following resources are attempted:</p>
<p>    * hxxp://members.multimania.co.uk/yahoophoto/*****<br />
    * 213.131.252.***:80</p>
<p><strong>This virus will search and ternminate processes and services belonging to various security products.  It searches for the following strings of any running process or service:</strong></p>
<p>    * &#8216;wscsvc&#8217;<br />
    * &#8216;MpsSvc&#8217;<br />
    * &#8216;WinDefend&#8217;<br />
    * &#8216;wuauserv&#8217;<br />
    * &#8216;AntiVirWebService&#8217;<br />
    * &#8216;McNaiAnn&#8217;<br />
    * &#8216;Avast! Antivirus&#8217;<br />
    * &#8216;aswUpdSv&#8217;<br />
    * &#8216;avast! Mail Scanner&#8217;<br />
    * &#8216;avast! Web Scanner&#8217;<br />
    * &#8216;AntiVirService&#8217;<br />
    * &#8216;AntiVirMailGuard&#8217;<br />
    * &#8216;AntiVirSchedulerService&#8217;<br />
    * &#8216;McShield&#8217;<br />
    * &#8216;AntiVirFirewallService&#8217;<br />
    * &#8216;mfefire&#8217;<br />
    * &#8216;McNASvc&#8217;<br />
    * &#8216;Mc0obeSv&#8217;<br />
    * &#8216;McMPFSvc&#8217;<br />
    * &#8216;McProxy&#8217;<br />
    * &#8216;Mc0DS&#8217;<br />
    * &#8216;mcmscsvc&#8217;<br />
    * &#8216;McAfee SiteAdvisor Service&#8217;<br />
    * &#8216;mfevtp&#8217;<br />
    * &#8216;Avgfws9&#8242;<br />
    * &#8216;AVG Security Toolbar Service&#8217;<br />
    * &#8216;avg9wd&#8217;<br />
    * &#8216;AVGIDSAgent&#8217;<br />
    * PAVFNSVR&#8217;<br />
    * &#8216;Gwmsrv&#8217;<br />
    * &#8216;PSHost&#8217;<br />
    * &#8216;PSIMSVC&#8217;<br />
    * &#8216;PAVSRV&#8217;<br />
    * &#8216;PavPrSrv&#8217;<br />
    * &#8216;PskSvcRetail&#8217;<br />
    * &#8216;Panda Software Controller&#8217;<br />
    * &#8216;TPSrv&#8217;<br />
    * SfCtlCom&#8217;<br />
    * &#8216;TmProxy&#8217;<br />
    * &#8216;TMBMServer&#8217;<br />
    * Arrakis3&#8242;<br />
    * &#8216;LIVESRV&#8217;<br />
    * &#8216;scan&#8217;<br />
    * &#8216;VSSERV&#8217;<br />
    * sdAuxService&#8217;<br />
    * &#8216;sdCoreService&#8217;<br />
    * &#8216;AVP&#8217;<br />
    * rescue32<br />
    * vzkrnl<br />
    * hcomm<br />
    * hrule<br />
    * cll<br />
    * hum<br />
    * iffs<br />
    * fssync<br />
    * msvcm80<br />
    * msvcp80<br />
    * msvcr80<br />
    * mzvkb<br />
    * com<br />
    * rescuec<br />
    * rvins32<br />
    * vemu<br />
    * curi<br />
    * vgcc<br />
    * msvr<br />
    * vgserv<br />
    * vgcc32<br />
    * sSvc<br />
    * meworkService<br />
    * Mgr<br />
    * erUI<br />
    * shs<br />
    * skMgr<br />
    * 360rp<br />
    * 360s<br />
    * febo<br />
    * 360<br />
    * rSwp<br />
    * oRun<br />
    * oRunKiller<br />
    * vMoni<br />
    * CCen<br />
    * meworkservice<br />
    * GFUp<br />
    * IceSwor<br />
    * rmor<br />
    * v32<br />
    * VPFW<br />
    * kissvc<br />
    * ilmon<br />
    * KPfwSvc<br />
    * KRegE<br />
    * KVSrv<br />
    * KVWSC<br />
    * Mmsk<br />
    * psvc<br />
    * PFW<br />
    * vservice<br />
    * rfwm<br />
    * rfwPro<br />
    * rfwsrv<br />
    * Rfws<br />
    * SREngL<br />
    * oruns<br />
    * orunsc<br />
    * reg<br />
    * ini<br />
    * bin<br />
    * 8be16<br />
    * 00hoe<br />
    * 6fnlpe<br />
    * lky<br />
    * m2nl<br />
    * rcuk<br />
    * whi<br />
    * msiz<br />
    * wscn<br />
    * 32krn<br />
    * 32kui<br />
    * swBoo<br />
    * isp<br />
    * shServ<br />
    * Vis<br />
    * shWebSv<br />
    * shM<br />
    * iSv<br />
    * shLogV<br />
    * swRegSvr<br />
    * shSkPcc<br />
    * swUp<br />
    * shQuick<br />
    * shEnhc<br />
    * shPopWz<br />
    * sche<br />
    * shUp<br />
    * vgine<br />
    * vgrssvc<br />
    * vgsc<br />
    * vgupsvc<br />
    * vgemc<br />
    * vgw<br />
    * svc<br />
    * vgrs<br />
    * vgn<br />
    * vno<br />
    * ify<br />
    * vsc<br />
    * vgu<br />
    * vcen<br />
    * min<br />
    * licmgr<br />
    * ekrn<br />
    * vconfig<br />
    * ilc<br />
    * gui<br />
    * preup<br />
    * wsc<br />
    * ool<br />
    * gen<br />
    * subwiz<br />
    * Survey<br />
    * seccen<br />
    * uisc<br />
    * vsserv<br />
    * IEShow<br />
    * unins<br />
    * iss<br />
    * licreg<br />
    * VCm<br />
    * VRep<br />
    * fIns<br />
    * VRi<br />
    * Msg<br />
    * VServer<br />
    * FPro<br />
    * fpsc<br />
    * yproc<br />
    * FPWin<br />
    * fssf<br />
    * llC<br />
    * user<br />
    * ump<br />
    * mcregwiz<br />
    * mcup<br />
    * mgr<br />
    * ppins<br />
    * mcinfo<br />
    * mgh<br />
    * mcmnh<br />
    * mcinsup<br />
    * McShiel<br />
    * mcvsm<br />
    * McVSEscn<br />
    * mcvsf<br />
    * scln<br />
    * vfin<br />
    * VP32<br />
    * VPCC<br />
    * VPM<br />
    * PW32<br />
    * VW32<br />
    * ICLO<br />
    * ICMON<br />
    * ICSUPP95<br />
    * ICSUPPN<br />
    * mserv<br />
    * FRW<br />
    * ckice<br />
    * zone<br />
    * vsmon<br />
    * WrC<br />
    * cle<br />
    * ner3<br />
    * ner<br />
    * MooLive<br />
    * lock<br />
    * own2000<br />
    * Sphin<br />
    * VSHWIN32<br />
    * VSECOMR<br />
    * WEBSC<br />
    * VCONSOL<br />
    * VSS<br />
    * 2free<br />
    * 2service<br />
    * 2up<br />
    * 2cm<br />
    * vEmSrv<br />
    * vmr<br />
    * vMU<br />
    * VSCons<br />
    * vse<br />
    * vSn<br />
    * vSub<br />
    * VSubmi<br />
    * vUM<br />
    * vUserUp<br />
    * vvl<br />
    * CEmRep<br />
    * Ins<br />
    * Lsp<br />
    * ccessIns<br />
    * ller<br />
    * unp_<br />
    * UPS<br />
    * ker<br />
    * UUp<br />
    * F5Serv<br />
    * FrzS<br />
    * e2k<br />
    * obe G<br />
    *  Lo<br />
    * WIN<br />
    * vcim<br />
    * VENGINE<br />
    * PSHos<br />
    * vFnSvr<br />
    * VSRV51<br />
    * PsC<br />
    * rlS<br />
    * PsImSvc<br />
    * PSC<br />
    * pskmssvc<br />
    * vRepor<br />
    * vsche<br />
    * PSrv<br />
    * WEBPRO</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-celan-w32vbmaniamm-virus-worm.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TSPY_AGENT.WWCJ Virus Worm</title>
		<link>http://www.softe.org/tspy_agent-wwcj-virus-worm.html</link>
		<comments>http://www.softe.org/tspy_agent-wwcj-virus-worm.html#comments</comments>
		<pubDate>Tue, 20 Jul 2010 18:26:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[TSPY_AGENT.WWCJ Virus Worm]]></category>
		<category><![CDATA[agent]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=78</guid>
		<description><![CDATA[potential for damage, information stealing, or both, that it possesses. Specifically, it is capable of monitoring affected users browsing habits to steal sensitive information. This spy software can be downloaded from certain remote sites. Check if the following applications are installed on the affected system to steal login credentials: * Ftpcommander * SmartFTP * Steam [...]]]></description>
			<content:encoded><![CDATA[<p>potential for damage, information stealing, or both, that it possesses.  Specifically, it is capable of monitoring affected users browsing habits  to steal sensitive information.</p>
<p>This spy software can be downloaded from certain  remote sites.</p>
<p>Check if the following applications are installed  on the affected system to steal login credentials:</p>
<p>*  Ftpcommander<br />
* SmartFTP<br />
* Steam (an online gaming platform)</p>
<p>It also oversees the relevant users&#8217; browsing habits to steal sensitive  information.</p>
<p>Save the information gathered in a text file  using the file name () Name of the team. Txt and upload to a specific  Web site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/tspy_agent-wwcj-virus-worm.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove BackDoor.SmallX.VX virus trojan</title>
		<link>http://www.softe.org/how-to-remove-backdoor-smallx-vx-virus-trojan.html</link>
		<comments>http://www.softe.org/how-to-remove-backdoor-smallx-vx-virus-trojan.html#comments</comments>
		<pubDate>Tue, 13 Jul 2010 20:02:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[how to remove BackDoor.SmallX.VX virus trojan]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=75</guid>
		<description><![CDATA[Backdoor.smallX.VX is a nasty virus that enters the PC adn opens system back doors in Windows XP and Vista and could enter windows 7, once in your computer, the virus starts to download countless packed malware threats and gives distant hackers access to the infected machine via open ports. Stopzilla says to use their app [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.softe.org/wp-content/uploads/2010/07/computer-virus-bugs-clip-art7674.jpg"><img class="alignleft  size-full wp-image-76" title="computer-virus-bugs-clip-art7674" src="http://www.softe.org/wp-content/uploads/2010/07/computer-virus-bugs-clip-art7674.jpg" alt="" width="300" height="300" /></a><span style="font-family: Verdana,Arial,Helvetica,sans-serif; color: #333333; font-size: x-small;"><strong>Backdoor.smallX.VX</strong> is a nasty virus that enters the PC adn opens system back doors in Windows XP and Vista and could enter windows 7, once in your computer, the virus starts to download countless packed malware threats and gives distant hackers  access to the infected machine via open ports.</span></p>
<p><span style="font-family: Verdana,Arial,Helvetica,sans-serif; color: #333333; font-size: x-small;">Stopzilla says to use their app to remove this threat, but you can simply use </span>http://www.malwarebytes.org to remove this threat. Make sure you first download this app, update it, disconnect your PC from the internet, then run malwarebytes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-backdoor-smallx-vx-virus-trojan.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>So what is the best Virus protection application?</title>
		<link>http://www.softe.org/so-what-is-the-best-virus-protection-application.html</link>
		<comments>http://www.softe.org/so-what-is-the-best-virus-protection-application.html#comments</comments>
		<pubDate>Thu, 08 Jul 2010 21:41:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[what is the best Virus protection application]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=58</guid>
		<description><![CDATA[With millions of downloads and thousands of positive reviews on software security blogs around the world wide web,  It has been one great adventure for Microsoft Security Essentials, the top virus security app of 2009 and 2010 in my opinion and millions of others .]]></description>
			<content:encoded><![CDATA[<div>With millions of downloads and thousands of positive reviews on software security blogs around  the world wide web,  It has been one great adventure for <strong>Microsoft  Security Essentials</strong>, the top virus security app of 2009 and 2010 in my opinion and millions of others .</div>
<p>In AV Comparative&#8217;s most recent report  on malware removal, <strong>Microsoft  Security Essentials </strong>was the <em>only free antivirus</em> app rated TOP in comparison to  Norton,  Kaspersky, Mcafee.  <strong>Microsoft  Security Essentials</strong> also beat out technician  favorite ESET which managed only an Advanced rating.</p>
<p>So not only has <strong>Microsoft  Security Essentials </strong>beaten  free competitors like AVG, Avira, and  Avast, it also posted test scores equal to or better than a dozen  anti-virus programs you&#8217;d have to pay for and that includes the heavy bottle necking Norton and Mcafee which slow down your PC in a big way.</p>
<p>So if you are in it to win it, i suggest you grab yourself a cup of coffee,  go to Microsoft.com and downlaod <strong>Microsoft  Security Essentials</strong>, it will sure put a smile on your face. <img src='http://www.softe.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://www.softe.org/wp-content/uploads/2010/07/Microsoft-Security-Essentials-Beta.png" target="_blank"><img class="alignnone size-full wp-image-59" title="Microsoft-Security-Essentials-Beta" src="http://www.softe.org/wp-content/uploads/2010/07/Microsoft-Security-Essentials-Beta.png" alt="" width="542" height="447" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/so-what-is-the-best-virus-protection-application.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability</title>
		<link>http://www.softe.org/microsoft-internet-explorer-uninitialized-memory-corruption-vulnerability.html</link>
		<comments>http://www.softe.org/microsoft-internet-explorer-uninitialized-memory-corruption-vulnerability.html#comments</comments>
		<pubDate>Wed, 07 Jul 2010 09:15:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=55</guid>
		<description><![CDATA[A vulnerability exists in Microsoft Internet Explorer that could allow remote code execution. The vulnerability is in the way Internet Explorer accesses an object that has not been correctly initialized or deleted. T]]></description>
			<content:encoded><![CDATA[<dl>
<dt> <strong>Type</strong> </dt>
<dd>Logic error</dd>
<dt> <strong>Impact of exploitation</strong> </dt>
<dd>Remote Code Execution</dd>
<dt> <strong>User Interaction</strong> </dt>
<dd>no user interaction is needed</dd>
<dt> <strong>Attack Vector</strong> </dt>
<dd>Website with malicious content</dd>
<dt> <strong>Rating</strong> </dt>
<dd> Medium </dd>
</dl>
<h4>Description</h4>
<p>A vulnerability exists in Microsoft Internet Explorer that could allow  remote code execution. The vulnerability is in the way Internet Explorer  accesses an object that has not been correctly initialized or deleted.  The vulnerability can be exploited by creating a specially crafted Web  page. When the Web page is viewed, the vulnerability could allow remote  code execution.</p>
<h4>Recommendations -</h4>
<p>The vendor has released an update to address this  issue  http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/microsoft-internet-explorer-uninitialized-memory-corruption-vulnerability.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Display Folder Size in Windows Explorer</title>
		<link>http://www.softe.org/how-to-display-folder-size-in-windows-explorer.html</link>
		<comments>http://www.softe.org/how-to-display-folder-size-in-windows-explorer.html#comments</comments>
		<pubDate>Wed, 07 Jul 2010 09:11:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to Display Folder Size in Windows Explorer]]></category>
		<category><![CDATA[windows 7]]></category>
		<category><![CDATA[windows xp]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=52</guid>
		<description><![CDATA[One major issue that windows operating system has is the fact that it does not show the folder size in windows explorer, only file size.]]></description>
			<content:encoded><![CDATA[<p>One major issue that windows operating system has is the fact that it does not show the folder size in windows explorer, only file size.</p>
<p><a href="http://www.softe.org/wp-content/uploads/2010/07/folder-size-windows7.jpg"><img class="alignnone size-full wp-image-53" title="folder-size-windows7" src="http://www.softe.org/wp-content/uploads/2010/07/folder-size-windows7.jpg" alt="" width="500" height="358" /></a></p>
<p><strong>Folder Size for Windows</strong> is a  free addon for Windows XP/Vista  that adds a new column to the Windows Explorer details view to displays the sizes of files and folders.</p>
<p><strong><a href="http://sourceforge.net/projects/foldersize/" target="_blank"><strong>Download  Folder Size in Windows</strong></a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-display-folder-size-in-windows-explorer.html/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Adobe Flash Player authplay.dll Remote Code Execution Vulnerability</title>
		<link>http://www.softe.org/adobe-flash-player-authplay-dll-remote-code-execution-vulnerability.html</link>
		<comments>http://www.softe.org/adobe-flash-player-authplay-dll-remote-code-execution-vulnerability.html#comments</comments>
		<pubDate>Tue, 29 Jun 2010 00:46:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Adobe Flash Player authplay.dll Remote Code Execution Vulnerability]]></category>
		<category><![CDATA[Adobe Flash Player]]></category>
		<category><![CDATA[authplay.dll]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=50</guid>
		<description><![CDATA[Adobe Reader Flash Player  and Acrobat have been recently reported to be prone to a remote code execution vulnerability.]]></description>
			<content:encoded><![CDATA[<p>Adobe Reader Flash Player  and Acrobat have been recently reported to be prone to a  remote code execution vulnerability. The Adobe.com Company  has reported that this vulnerability is being exploited rapidly.  This These are the versions of Adobe Flash Player that are in high risk of this threat, 10.0.45.2, 9.0.262 and earlier <strong>Flash Player</strong> 10.0.x and 9.0.x versions for Windows Solaris Linux  Macintosh and Adobe Reader, Acrobat 9.3.2 and Macintosh and UNIX</p>
<div>
<h3>How to clean this threat</h3>
<div>
<h4>Run all software as a nonprivileged  user with minimal access rights.</h4>
<p>To reduce the impact of latent vulnerabilities, run applications  with the minimal amount of privileges required for functionality.</p>
</div>
<div>
<h4>Deploy network intrusion detection systems to  monitor network traffic for malicious activity.</h4>
<p>Deploy NIDS to monitor network traffic for signs of anomalous or  suspicious activity. This includes but is not limited to requests that  include NOP sleds and unexplained incoming and outgoing traffic. This  may indicate exploit attempts or activity that results from a successful  exploit.</p>
</div>
<div>
<h4>Do not accept or execute  files from untrusted or unknown sources.</h4>
<p>To limit exposure to these and other latent vulnerabilities, never  handle files that originate from unfamiliar or untrusted sources.</p>
</div>
<div>
<h4>Do not follow links provided by unknown or  untrusted sources.</h4>
<p>To reduce the likelihood of attacks, never visit sites of  questionable integrity or follow links provided by unfamiliar or  untrusted sources.</p>
</div>
<h4>Implement multiple redundant layers of  security.</h4>
<p>As an added precaution, deploy memory-protection schemes (such as  nonexecutable stack/heap configuration and randomly mapped memory  segments). This may complicate exploits of memory-corruption  vulnerabilities.</p>
</div>
<div>Updates for Adobe Flash Player are available; please  see the references for more information.  Currently we are not aware of any vendor-supplied patches for Adobe  Reader or Adobe Acrobat. If you feel we are in error or if you are aware  of more recent information, please mail us at: vuldb@securityfocus.com.</div>
<div>
<h3>References</h3>
<p>Symantec  &#8211; Analysis of a Zero-day Exploit for Adobe Flash and Reader</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/adobe-flash-player-authplay-dll-remote-code-execution-vulnerability.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PopupMaster 1.2.4 Firefox Popup Blocker addon</title>
		<link>http://www.softe.org/popupmaster-1-2-4-firefox-popup-blocker-addon.html</link>
		<comments>http://www.softe.org/popupmaster-1-2-4-firefox-popup-blocker-addon.html#comments</comments>
		<pubDate>Mon, 21 Jun 2010 19:28:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PopupMaster 1.2.4 Firefox Popup Blocker addon]]></category>
		<category><![CDATA[Popup Blocker]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=45</guid>
		<description><![CDATA[I have read one to many times that people with todays web and browisng technology are still experiencing unwanted popups while surfing the web.]]></description>
			<content:encoded><![CDATA[<p>I have read one to many times that people with todays web and browisng technology are still experiencing unwanted popups while surfing the web. I myself get one or two popups a month but that is expected. I use Firefox mostly and have found a great plugin to prevent 90% of the popups.</p>
<p>PopupMaster places the popup blocker icon in the status bar, regardless  of site settings. PopupMaster contains no functionality to block popups.  It simply forces Firefox to always show the popup-blocker icon in the  status bar. Great little app written by yellow5.us</p>
<p>Click here to <a href="https://addons.mozilla.org/en-US/firefox/addon/1788/" target="_blank">download and install the PopupMaster 1.2.4 Firefox Popup Blocker addon</a></p>
<p><a href="http://www.softe.org/wp-content/uploads/2010/06/firefox-popup-blocker.png"><img class="alignnone size-full wp-image-48" title="firefox popup blocker" src="http://www.softe.org/wp-content/uploads/2010/06/firefox-popup-blocker.png" alt="" width="402" height="362" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/popupmaster-1-2-4-firefox-popup-blocker-addon.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The older version of quicktime cannot be removed quicktime.msi</title>
		<link>http://www.softe.org/the-older-version-of-quicktime-cannot-be-removed-quicktime-msi.html</link>
		<comments>http://www.softe.org/the-older-version-of-quicktime-cannot-be-removed-quicktime-msi.html#comments</comments>
		<pubDate>Tue, 08 Jun 2010 23:25:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[quicktime cannot be removed]]></category>
		<category><![CDATA[itunes]]></category>
		<category><![CDATA[quicktime]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=41</guid>
		<description><![CDATA[You may be having this problem by trying to install itunes or simply quicktime. Here is a simple way to fix this solution.]]></description>
			<content:encoded><![CDATA[<p>You may be having this problem by trying to install itunes or simply quicktime.</p>
<p>Here is a simple way to fix this solution.</p>
<p><strong> Download the Windows Installer CleanUp  Utility</strong></p>
<p><a onclick="pageTracker._trackPageview  ('/outgoing/http_support_microsoft_com_default_aspx_scid_kb_en_us_290301');" rel="nofollow" href="http://support.microsoft.com/default.aspx?scid=kb;en-us;290301" target="_blank">http://support.microsoft.com/default&#8230;b;en-us;290301</a></p>
<p>Run the CleanUp utility and look for any string that has quicktime as a title.<br />
Select the entries and click remove and exit out of the program.</p>
<p>You should now be able to reinstall quick time or itunes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/the-older-version-of-quicktime-cannot-be-removed-quicktime-msi.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows live quicktime control host stopped working solution</title>
		<link>http://www.softe.org/windows-live-quicktime-control-host-stopped-working-solution.html</link>
		<comments>http://www.softe.org/windows-live-quicktime-control-host-stopped-working-solution.html#comments</comments>
		<pubDate>Tue, 08 Jun 2010 23:14:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows live quicktime control host stopped working solution]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[quicktime]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=37</guid>
		<description><![CDATA[First thing to do is Re-download and re-install them from MS and see if that fixes the error.]]></description>
			<content:encoded><![CDATA[<p>The error comes from MS Windows Live or Photo Gallery.<br />
First thing to do is Re-download and re-install them from MS and see if that fixes the error. here is the link <a href="http://download.live.com/photogallery" target="_blank">http://download.live.com/photogallery</a></p>
<p>If this does not work, remove windows live photo gallery from your PC and the problem should be fixed.</p>
<p>Another thing you might want to try is to uninstall quicktime and reinstall quick time, this might work for some people.</p>
<p>This bug seems to only occur on windows 7 64x opertating systems only and i assume this bug will be fixed on the next windows service pack.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/windows-live-quicktime-control-host-stopped-working-solution.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 7 will not shut down!</title>
		<link>http://www.softe.org/windows-7-will-not-shut-down.html</link>
		<comments>http://www.softe.org/windows-7-will-not-shut-down.html#comments</comments>
		<pubDate>Fri, 04 Jun 2010 04:43:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows 7 will not shut down]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=33</guid>
		<description><![CDATA[To check if a particular program is slowing the machine when you switch on or shut down, e.g. an antivirus program, go to Control Panel > All Control Panel Items > Performance Information and Tools > Advanced ]]></description>
			<content:encoded><![CDATA[<p>To check if a particular program is slowing the machine when you switch on or shut down, e.g. an antivirus program, go to Control Panel &gt; All Control Panel Items &gt;  Performance Information and Tools &gt; Advanced Tools (in the left pane). On this screen the problem is sometimes shown. If not, click View Performance Details in Event Log (Event Viewer). Events in the 100 series are boot events and I believe those in the 200 series are shut down events.</p>
<p>These can be followed up by double-clicking them, then clicking Event Log Online at the bottom.  In XP and Vista, Microsoft’s Process Explorer is a boon. I haven‘t tried it in Win7 but I see no reason why it shouldn‘t work.</p>
<p>One other thing that can be done is disabled CTxfihlp.exe in  msconfig, that should also fix the issue.</p>
<p><a href="http://www.softe.org/wp-content/uploads/2010/06/msconfig.jpg"><img class="alignnone size-full wp-image-35" title="msconfig" src="http://www.softe.org/wp-content/uploads/2010/06/msconfig.jpg" alt="" width="470" height="310" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/windows-7-will-not-shut-down.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is scareware?</title>
		<link>http://www.softe.org/what-is-scareware.html</link>
		<comments>http://www.softe.org/what-is-scareware.html#comments</comments>
		<pubDate>Tue, 11 May 2010 02:16:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[What is scareware?]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[infected]]></category>
		<category><![CDATA[rogueware]]></category>
		<category><![CDATA[scareware]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=29</guid>
		<description><![CDATA[Scareware also known as rogueware which is a   fake security software is a legitimately looking application that is delivered to the end user through illegal traffic acquisition tactics ]]></description>
			<content:encoded><![CDATA[<p><strong>Scareware </strong>also known as <strong>rogueware </strong>which is a  <strong> fake security software</strong> is a legitimately looking application that is  delivered to the end user through illegal traffic acquisition tactics  starting from <strong>compromised web sites</strong> to ultimately attempt to trick the user  into believing their computer is already infected with malware, and that  purchasing the application will help them get rid of it.</p>
<p>Upon execution, certain scareware releases will not only prevent  legitimate security software from loading, but it will also prevent it  from reaching its update locations in an attempt to ensure that the end  user will not be able to get the latest signatures database. Moreover,  it will also attempt to make its removal a time-consuming process by  blocking system tools and third party applications from executing.</p>
<p>Here is a list of scareware sites below:</p>
<ul>
<li>antivirus-live-pro.org (Antivirus  Pro Scareware)</li>
<li>internetantivirusplus.com (Fake Antivirus)</li>
<li>mybestantivirusplus.com</li>
<li>securesoftwarebill.com (Rogue System Security Antivirus)</li>
<li>yourantimalware.com</li>
<li>totalsurfguard.com</li>
<li>systemsecuritysupport.com</li>
<li>stabilitysuite.com</li>
<li>powersystemstability.com</li>
<li>onlinecentersupport.net</li>
<li>identitysecuritysuite.com</li>
<li>etotalsecurity.com</li>
<li>defenseinteractive.com</li>
<li>defenseinteractive.com</li>
<li>antispyinteractive.com</li>
<li>antispyavailable.com</li>
<li>protectionsystem.org(Like Antivirus  Pro Scareware)</li>
<li>realbestantivirusplus.com</li>
</ul>
<p>Remember these sites are active and are scaring people into buying or  installing there product, you should<strong> not go</strong> to these sites.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/what-is-scareware.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Trojan horse crypt.UZD</title>
		<link>http://www.softe.org/how-to-remove-trojan-horse-crypt-uzd.html</link>
		<comments>http://www.softe.org/how-to-remove-trojan-horse-crypt-uzd.html#comments</comments>
		<pubDate>Mon, 10 May 2010 18:34:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to remove Trojan horse crypt.UZD]]></category>
		<category><![CDATA[crypt]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[uzd]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=27</guid>
		<description><![CDATA[If you do not have Malwarebytes please download from Here Double Click mbam-setup.exe to install the application.

    * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select "Perform Quick Scan", then click Scan.
    * The scan may take some time to finish,so please be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    * Copy&#038;Paste the entire report in your next reply.

Next step would be to download OTL.  Click here to download OTL


    * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    * When the window appears, underneath Output at the top change it to Minimal Output.
    * Under the Standard Registry box change it to All.
    * Check the boxes beside LOP Check and Purity Check.
    * Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
          o When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
          o Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.]]></description>
			<content:encoded><![CDATA[<p>If you do not have Malwarebytes  please download from <a href="http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&amp;subj=dl&amp;tag=button" target="_blank"><!--coloro:blue--><!--/coloro--><strong>Here</strong><!--colorc--><!--/colorc--></a></p>
<p>Double Click mbam-setup.exe to install the application.</p>
<ul>
<li>Make  sure a checkmark is placed next to <strong>Update Malwarebytes&#8217; Anti-Malware</strong> and <strong>Launch Malwarebytes&#8217; Anti-Malware</strong>, then click Finish.</li>
<li>If  an update is found, it will download and install the latest version.</li>
<li>Once  the program has loaded, select &#8220;<strong>Perform Quick Scan</strong>&#8220;, then click <strong>Scan</strong>.</li>
<li>The  scan may take some time to finish,so please be patient.</li>
<li>When  the scan is complete, click OK, then Show Results to view the results.</li>
<li>Make  sure that <strong>everything is checked</strong>, and click <strong>Remove Selected</strong>.</li>
<li>When  disinfection is completed, a log will open in Notepad and you may be  prompted to Restart.(See Extra Note)</li>
<li>The log is automatically  saved by MBAM and can be viewed by clicking the Logs tab in MBAM.</li>
<li>Copy&amp;Paste  the entire report in your next reply.</li>
</ul>
<p>Next step would be to download OTL.  <a href="http://oldtimer.geekstogo.com/OTL.exe" target="_blank">Click here to download OTL</a></p>
<ul>
<li>Double  click on the icon to run it. Make sure all other windows are closed  and to let it run uninterrupted.</li>
<li>When the window appears,  underneath <span style="text-decoration: underline;"><strong>Output</strong></span> at the top change it to <strong>Minimal  Output</strong>.</li>
<li>Under the <strong>Standard Registry</strong> box change it to <strong>All</strong>.</li>
<li>Check  the boxes beside <strong>LOP Check</strong> and <strong>Purity Check</strong>.</li>
<li>Click  the <span style="text-decoration: underline;">Run Scan</span> button. Do not change any settings unless otherwise  told to do so. The scan wont take long.
<ul>
<li>When the scan  completes, it will open two notepad windows. <strong>OTL.Txt</strong> and <strong>Extras.Txt</strong>.  These are saved in the same location as OTL.</li>
<li>Please copy <strong>(Edit-&gt;Select  All, Edit-&gt;Copy)</strong> the contents of these files, one at a time, and  post it with your next reply.</li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-trojan-horse-crypt-uzd.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Trojan Horse Generic.17 16 15 14.DYJ</title>
		<link>http://www.softe.org/how-to-remove-trojan-horse-generic-17-16-15-14-dyj.html</link>
		<comments>http://www.softe.org/how-to-remove-trojan-horse-generic-17-16-15-14-dyj.html#comments</comments>
		<pubDate>Mon, 10 May 2010 18:17:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to remove Trojan Horse Generic]]></category>
		<category><![CDATA[generic]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=21</guid>
		<description><![CDATA[If you have gotten a virus in your PC called Trojan Horse Generic with a number next to it such as .17 or 16 or 15 or 14, this simply means you have downloaded an illegal software from a torrent.  The risk level of this virus is not that great but still needs to be removed asap.

Trojan horse Generic 14.DYJ is a detection for a trojan that applies a Rootkit technology to remain itself hidden from system so as to avoid being detected by antivirus application. Trojan horse Generic 14.DYJ can hook itself into Windows registry and create a backdoor to allow a remote attacker gain full access on victims computer.

Damage Level: Medium

Systems Affected: Windows XP, Vista, 7

To remove this virus, you will need to download Rkill

Downloads:
rkill.exe – Download from BleepingComputer.com – 257kb
rkill.com – Download from BleepingComputer.com – 257kb
rkill.scr – Download from BleepingComputer.com – 257kb
rkill.pif – Download from BleepingComputer.com – 257kb

After you have finished with Rkill, do not reboot your PC, make sure you also have MalwareBytes installed on your PC, you will need to run this next.

Click here to download MalwareBytes

Now run Malwarebytes and this should fix your virus. You may run quick scan, and make sure you update malwarebytes before you scan and clean. Good luck
]]></description>
			<content:encoded><![CDATA[<p>If you have gotten a virus in your PC called Trojan Horse Generic with a number next to it such as .17 or 16 or 15 or 14, this simply means you have downloaded an illegal software from a torrent.  The risk level of this virus is not that great but still needs to be removed asap.</p>
<div>
<p>Trojan horse Generic 14.DYJ is a detection for a trojan that applies  a Rootkit technology to remain itself hidden from system so as to avoid  being detected by antivirus application. Trojan horse Generic 14.DYJ  can hook itself into Windows registry and create a backdoor to allow a  remote attacker gain full access on victims computer.</p>
<p><strong>Damage Level:</strong> Medium</p>
<p><strong>Systems Affected:</strong> Windows XP, Vista, 7</p>
<p>To remove this virus, you will need to download Rkill</p>
<p><strong>Downloads:</strong><br />
<a href="http://download.bleepingcomputer.com/grinler/rkill.scr" target="_blank">Download from BleepingComputer.com – 257kb</a></p>
<p>After you have finished with Rkill, do not reboot your PC, make sure you also have <strong>MalwareBytes</strong> installed on your PC, you will need to run this next.</p>
<p><strong><a href="http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&amp;subj=dl&amp;tag=button" target="_blank">Click here to download MalwareBytes</a></strong></p>
<p>Now run Malwarebytes and this should fix your virus. You may run quick scan, and make sure you update malwarebytes before you scan and clean. Good luck<strong><br />
</strong></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-trojan-horse-generic-17-16-15-14-dyj.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SONAR.ProcessHijack.2 Trojan Virus</title>
		<link>http://www.softe.org/sonar-processhijack-2-trojan-virus.html</link>
		<comments>http://www.softe.org/sonar-processhijack-2-trojan-virus.html#comments</comments>
		<pubDate>Wed, 05 May 2010 09:34:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SONAR.ProcessHijack.2 Trojan Virus]]></category>
		<category><![CDATA[hijack]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=9</guid>
		<description><![CDATA[Discovered: May 4, 2010
Updated: May 4, 2010 10:56:26 PM
Type: Trojan, Virus
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP
SONAR.ProcessHijack.2 is a heuristic detection that is designed to detect new malware based on how it launches new processes. Malware will commonly launch and hijack trusted Windows processes like svchost.exe in order to perform malicious actions.

Antivirus Protection Dates

    * Initial Rapid Release version pending
    * Latest Rapid Release version pending
    * Initial Daily Certified version pending
    * Latest Daily Certified version May 4, 2010 revision 048
    * Initial Weekly Certified release date pending

Threat Assessment
Wild

    * Wild Level: Low
    * Number of Infections: 0 - 49
    * Number of Sites: 0 - 2
    * Geographical Distribution: Low
    * Threat Containment: Easy
    * Removal: Easy

Damage

    * Damage Level: Low

Distribution

    * Distribution Level: Low]]></description>
			<content:encoded><![CDATA[<div id="tabModBdy">
<div><strong>Discovered: </strong>May 4, 2010</div>
<div><strong>Updated: </strong>May 4, 2010 10:56:26 PM</div>
<div><strong>Type: </strong>Trojan, Virus</div>
<div><strong>Systems Affected: </strong>Windows 2000, Windows 95, Windows 98,  Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP</div>
<p>SONAR.ProcessHijack.2 is a heuristic detection that is designed  to detect new malware based on how it launches new processes. Malware  will commonly launch and hijack trusted Windows processes like  svchost.exe in order to perform malicious actions.</p>
<h3>Antivirus Protection Dates</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>pending</li>
<li> <strong>Latest Rapid Release version </strong>pending</li>
<li> <strong>Initial Daily Certified version </strong>pending</li>
<li> <strong>Latest Daily Certified version </strong>May 4, 2010 revision 048</li>
<li> <strong>Initial Weekly Certified release date </strong>pending</li>
</ul>
<h3>Threat Assessment</h3>
<h4>Wild</h4>
<ul>
<li> <strong>Wild Level: </strong>Low</li>
<li> <strong>Number of Infections: </strong>0 &#8211; 49</li>
<li> <strong>Number of Sites: </strong>0 &#8211; 2</li>
<li> <strong>Geographical Distribution: </strong>Low</li>
<li> <strong>Threat Containment: </strong>Easy</li>
<li> <strong>Removal: </strong>Easy</li>
</ul>
<h4>Damage</h4>
<ul>
<li> <strong>Damage Level: </strong>Low</li>
</ul>
<h4>Distribution</h4>
<ul>
<li> <strong>Distribution Level: </strong>Low</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/sonar-processhijack-2-trojan-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Palevo.B Worm instant messaging clients</title>
		<link>http://www.softe.org/w32-palevo-b-worm-instant-messaging-clients.html</link>
		<comments>http://www.softe.org/w32-palevo-b-worm-instant-messaging-clients.html#comments</comments>
		<pubDate>Wed, 05 May 2010 09:31:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32.Palevo.B Worm]]></category>
		<category><![CDATA[messaging]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=6</guid>
		<description><![CDATA[Discovered: May 4, 2010
Updated: May 4, 2010 11:27:56 AM
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP

W32.Palevo.B is a worm that spreads through instant messaging clients.
Antivirus Protection Dates

    * Initial Rapid Release version May 4, 2010 revision 009
    * Latest Rapid Release version May 4, 2010 revision 020
    * Initial Daily Certified version May 4, 2010 revision 048
    * Latest Daily Certified version May 4, 2010 revision 048
    * Initial Weekly Certified release date May 5, 2010

Threat Assessment
Wild

    * Wild Level: Low
    * Number of Infections: 0 - 49
    * Number of Sites: 0 - 2
    * Geographical Distribution: Low
    * Threat Containment: Easy
    * Removal: Easy

Damage

    * Damage Level: Low
    * Payload: Spreads through instant messaging programs.

Distribution

    * Distribution Level: Medium

]]></description>
			<content:encoded><![CDATA[<div id="tabModBdy">
<div><strong>Discovered: </strong>May 4, 2010</div>
<div><strong>Updated: </strong>May 4, 2010 11:27:56 AM</div>
<div><strong>Type: </strong>Worm</div>
<div><strong>Systems Affected: </strong>Windows 2000, Windows 95, Windows 98,  Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP</div>
<p>W32.Palevo.B is a worm that spreads through instant messaging  clients.</p>
<h3>Antivirus Protection Dates</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>May 4, 2010 revision 009</li>
<li> <strong>Latest Rapid Release version </strong>May 4, 2010 revision 020</li>
<li> <strong>Initial Daily Certified version </strong>May 4, 2010 revision  048</li>
<li> <strong>Latest Daily Certified version </strong>May 4, 2010 revision 048</li>
<li> <strong>Initial Weekly Certified release date </strong>May 5, 2010</li>
</ul>
<h3>Threat Assessment</h3>
<h4>Wild</h4>
<ul>
<li> <strong>Wild Level: </strong>Low</li>
<li> <strong>Number of Infections: </strong>0 &#8211; 49</li>
<li> <strong>Number of Sites: </strong>0 &#8211; 2</li>
<li> <strong>Geographical Distribution: </strong>Low</li>
<li> <strong>Threat Containment: </strong>Easy</li>
<li> <strong>Removal: </strong>Easy</li>
</ul>
<h4>Damage</h4>
<ul>
<li> <strong>Damage Level: </strong>Low</li>
<li> <strong>Payload: </strong>Spreads through instant messaging programs.</li>
</ul>
<h4>Distribution</h4>
<ul>
<li> <strong>Distribution Level: </strong>Medium</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32-palevo-b-worm-instant-messaging-clients.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability II</title>
		<link>http://www.softe.org/hello-world.html</link>
		<comments>http://www.softe.org/hello-world.html#comments</comments>
		<pubDate>Wed, 05 May 2010 04:42:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Internet Explorer Memory Corruption]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Memory Corruption]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=1</guid>
		<description><![CDATA[Description -

A remote code execution vulnerability exists in some versions of Microsoft Internet Explorer. The flaw can occur during processing of objects that have not been properly initialized or have been deleted. An attacker may exploit this flaw via a specially-crafted web page. Successful exploitation may result in remote code execution.
Recommendations -

The vendor has released an update to address this issue: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx]]></description>
			<content:encoded><![CDATA[<h4>Description -</h4>
<p>A remote code execution vulnerability exists in some  versions of Microsoft Internet Explorer.  The flaw can occur during processing of objects that have not been  properly initialized or have been deleted.  An attacker may exploit this  flaw via a specially-crafted web page.  Successful exploitation may  result in remote code execution.</p>
<h4>Recommendations -</h4>
<p>The vendor has released an update to address this  issue:  http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/hello-world.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

