<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-8721477802794636844</atom:id><lastBuildDate>Thu, 11 Mar 2010 11:22:16 +0000</lastBuildDate><title>free trojan horse virus removal tool Spyware Removal</title><description>Is your PC slow? I will help you clean your PC Spyware Trojan Horse and Virus infections for FREE.</description><link>http://www.softe.org/</link><managingEditor>noreply@blogger.com (Mandy)</managingEditor><generator>Blogger</generator><openSearch:totalResults>52</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-6449742040699986738</guid><pubDate>Thu, 25 Feb 2010 06:07:00 +0000</pubDate><atom:updated>2010-02-24T23:06:56.311-08:00</atom:updated><title>Virus &amp; Spyware Removal</title><description>The Best Way to Remove Viruses, Spyware and other Malware from your home PC computer.&lt;br /&gt;&lt;br /&gt;The first rule of removing spyware is not trying to rely on an anti virus software, but rather using an anti spyware application instead. &lt;br /&gt;Because spyware is different from viruses, you need to use a different program to remove the spyware infection. Here are my suggestions of the top anti-spyware programs that are not only free to use, but they actually help you clean your PC. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;SpyBot Search and Destroy&lt;/span&gt;&lt;br /&gt;Freeware spyware removal and detction program for Windows.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Microsoft Windows Defender&lt;/span&gt;&lt;br /&gt;Windows Defender is a free software from Microsoft that helps protect your computer against pop-ups, slow performance, and security threats caused by spyware and other unwanted software.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;MalwareByte&lt;/span&gt;&lt;br /&gt;Malwarebytes Anti-Malware is considered to be one of the best malware spyware detection and removal software and its free.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;SpywareBlaster&lt;/span&gt;&lt;br /&gt;Free windows program which protects against spyware: prevents the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software. blocks spyware/tracking cookies in Internet Explorer and Mozilla/Firefox, restricts the actions of potentially unwanted sites in Internet Explorer.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;What is Spyware?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Spyware can be defined as computer software which is secretly installed on a personal computer to spy or take total control over the user's computer activity without his/her consent off course. A spyware can also take over the user’s activities and install additional unwanted software, re-direct the browser activity and similar actions that can make a computer prone to further attacks and virus infections.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Latest Virus Threats&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;W32.Gammima.AG!gen4&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Discovered: February 23, 2010&lt;br /&gt;Updated: February 24, 2010 5:10:48 AM&lt;br /&gt;Type: Virus&lt;br /&gt;Systems Affected: Windows XP, Windows Vista, Windows NT, Windows Server 2003, Windows 2000&lt;br /&gt;&lt;br /&gt;W32.Gammima.AG!gen4 is a heuristic detection used to detect threats associated with the W32.Gammima.AG family.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Threat Assessment&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Wild&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Wild Level: Low&lt;br /&gt;    * Number of Infections: 0 - 49&lt;br /&gt;    * Number of Sites: 0 - 2&lt;br /&gt;    * Geographical Distribution: Low&lt;br /&gt;    * Threat Containment: Easy&lt;br /&gt;    * Removal: Easy&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Damage&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Damage Level: Medium&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Distribution&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Distribution Level: Low&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-6449742040699986738?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2010/02/virus-spyware-removal.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-3428115723046553625</guid><pubDate>Fri, 29 Jan 2010 02:20:00 +0000</pubDate><atom:updated>2010-01-28T18:23:04.075-08:00</atom:updated><title>Internet Explorer CVE-2010-0249 'srcElement()' Remote Code Execution Vulnerability</title><description>Risk&lt;br /&gt;High&lt;br /&gt;Date Discovered&lt;br /&gt;January 14, 2010&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Description&lt;/span&gt;&lt;br /&gt;Internet Explorer is prone to a remote code-execution vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the user running the browser. Successful exploits will compromise the application and possibly the computer. Failed attacks will cause denial-of-service conditions.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Technologies Affected&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * Avaya Meeting Exchange - Client Registration Server&lt;br /&gt;    * Avaya Meeting Exchange - Recording Server&lt;br /&gt;    * Avaya Meeting Exchange - Streaming Server&lt;br /&gt;    * Avaya Meeting Exchange - Web Conferencing Server&lt;br /&gt;    * Avaya Meeting Exchange - Webportal&lt;br /&gt;    * Avaya Messaging Application Server&lt;br /&gt;    * Avaya Messaging Application Server MM 1.1&lt;br /&gt;    * Avaya Messaging Application Server MM 2.0&lt;br /&gt;    * Avaya Messaging Application Server MM 3.0&lt;br /&gt;    * Avaya Messaging Application Server MM 3.1&lt;br /&gt;    * Microsoft Internet Explorer 6.0&lt;br /&gt;    * Microsoft Internet Explorer 6.0 SP1&lt;br /&gt;    * Microsoft Internet Explorer 7.0&lt;br /&gt;    * Microsoft Internet Explorer 8&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Recommendations&lt;/span&gt;&lt;br /&gt;Run all software as a nonprivileged user with minimal access rights.&lt;br /&gt;To reduce the impact of latent vulnerabilities, always run nonadministrative software as an unprivileged user with minimal access rights.&lt;br /&gt;Deploy network intrusion detection systems to monitor network traffic for malicious activity.&lt;br /&gt;&lt;br /&gt;Deploy NIDS to monitor network traffic for signs of anomalous or suspicious activity. This includes but is not limited to requests that include NOP sleds and unexplained incoming and outgoing traffic. This may indicate exploit attempts or activity that results from successful exploits.&lt;br /&gt;Do not follow links provided by unknown or untrusted sources.&lt;br /&gt;Web users should be cautious about following links to sites that are provided by unfamiliar or suspicious sources. Filtering HTML from emails may help remove a possible vector for transmitting malicious links to users.&lt;br /&gt;Set web browser security to disable the execution of script code or active content.&lt;br /&gt;Since a successful exploit of this issue requires malicious code to execute in web clients, consider disabling support for script code and active content within the client browser. Note that this mitigation tactic might adversely affect legitimate websites that rely on the execution of browser-based script code.&lt;br /&gt;Implement multiple redundant layers of security.&lt;br /&gt;Memory-protection schemes (such as nonexecutable stack and heap configurations and randomly mapped memory segments) will complicate exploits of memory-corruption vulnerabilities.&lt;br /&gt;A vendor advisory and updates are available; please see the references for more information.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;References&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;    * BugSec - 21.01.10 Internet Explorer CVE-2010-0249 Remote Code Execution &lt;span style="font-weight:bold;"&gt;Vulnerability&lt;/span&gt;&lt;br /&gt;    * Microsoft - Advisory 979352 Update for Monday January 18&lt;br /&gt;    * Microsoft - Further Insight into Security Advisory 979352 and the Threat &lt;span style="font-weight:bold;"&gt;Landscape&lt;/span&gt;&lt;br /&gt;    * Microsoft - Internet Explorer Homepage&lt;br /&gt;    * Metasploit - Reproducing the 'Aurora' IE Exploit&lt;br /&gt;    * Microsoft Security Response Center - Security Advisory 979352 – Going out of &lt;span style="font-weight:bold;"&gt;Band&lt;/span&gt;&lt;br /&gt;    * Microsoft Security Response Center - Security Advisory 979352 Released&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Credits&lt;/span&gt;&lt;br /&gt;This issue was discovered in the wild; Microsoft credits Meron Sellem of BugSec.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-3428115723046553625?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2010/01/internet-explorer-cve-2010-0249.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-380257529871835533</guid><pubDate>Fri, 29 Jan 2010 02:18:00 +0000</pubDate><atom:updated>2010-01-28T18:20:30.082-08:00</atom:updated><title>Backdoor.Tidserv.K virus Trojan horse how to remove</title><description>Type: Trojan&lt;br /&gt;Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000&lt;br /&gt;&lt;br /&gt;Backdoor.Tidserv.K is a Trojan horse that opens a back door on the compromised computer.&lt;br /&gt;&lt;br /&gt;Protection&lt;br /&gt;&lt;br /&gt;    * Initial Rapid Release version January 28, 2010 revision 022&lt;br /&gt;    * Latest Rapid Release version January 28, 2010 revision 022&lt;br /&gt;    * Initial Daily Certified version January 28, 2010 revision 025&lt;br /&gt;    * Latest Daily Certified version January 28, 2010 revision 025&lt;br /&gt;    * Initial Weekly Certified release date February 3, 2010&lt;br /&gt;&lt;br /&gt;Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.&lt;br /&gt;Threat Assessment&lt;br /&gt;Wild&lt;br /&gt;&lt;br /&gt;    * Wild Level: Low&lt;br /&gt;    * Number of Infections: 0 - 49&lt;br /&gt;    * Number of Sites: 0 - 2&lt;br /&gt;    * Geographical Distribution: Low&lt;br /&gt;    * Threat Containment: Easy&lt;br /&gt;    * Removal: Easy&lt;br /&gt;&lt;br /&gt;Damage&lt;br /&gt;&lt;br /&gt;    * Damage Level: Low&lt;br /&gt;    * Payload: Opens a back door on the compromised computer.&lt;br /&gt;&lt;br /&gt;Distribution&lt;br /&gt;&lt;br /&gt;    * Distribution Level: Low&lt;br /&gt;&lt;br /&gt;Writeup By: Robert X Wang&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-380257529871835533?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2010/01/backdoortidservk-virus-trojan-horse-how.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-207394615295402187</guid><pubDate>Mon, 28 Dec 2009 23:08:00 +0000</pubDate><atom:updated>2009-12-28T15:09:16.395-08:00</atom:updated><title>how to remove W32/Conficker.worm.gen.d  virus</title><description>Overview -&lt;br /&gt;&lt;br /&gt;This detection is for a worm, which exploits the MS08-067 vulnerability in Microsoft Windows Server Service which may allow for remote code execution. This flaw lies in the improper handling of specially-crafted (malicious) RPC requests and was patched on October 23, 2008.&lt;br /&gt;Aliases&lt;br /&gt;&lt;br /&gt;    * Net-Worm.Win32.Kido.js [Kaspersky]&lt;br /&gt;&lt;br /&gt;    * W32.Downadup.E [Symantec)]&lt;br /&gt;&lt;br /&gt;    * W32/Confick-D [Sophos]&lt;br /&gt;&lt;br /&gt;    * Worm:Win32/Conficker.D [Microsoft]&lt;br /&gt;&lt;br /&gt;    * Worm:Win32/Conficker.gen [Ikarus]&lt;br /&gt;&lt;br /&gt;    * WORM_DOWNAD.E [Trend]&lt;br /&gt;&lt;br /&gt;Characteristics&lt;br /&gt;Characteristics -&lt;br /&gt;&lt;br /&gt;When executed, this worm connects to one of the following sites to check the date and time:&lt;br /&gt;&lt;br /&gt;    * myspace.com&lt;br /&gt;    * msn.com&lt;br /&gt;    * ebay.com&lt;br /&gt;    * cnn.com&lt;br /&gt;    * aol.com&lt;br /&gt;&lt;br /&gt;Further execution of this worm will continue only if the date is before May 3rd 2009.&lt;br /&gt;&lt;br /&gt;On successful execution, the worm drops the following file:&lt;br /&gt;&lt;br /&gt;    * %system%\RandomFileName.tmp [Already detected as W32/Conficker.sys]&lt;br /&gt;&lt;br /&gt;It creates a service with a random file name using the above file. Once the service is created, the worm deletes the above ".tmp" file.&lt;br /&gt;&lt;br /&gt;The worm then patches the following system file in the memory:&lt;br /&gt;&lt;br /&gt;    * %System%\drivers\tcpip.sys &lt;br /&gt;&lt;br /&gt;This is done to remove the limitation set on the maximum number of TCP connection attempts that can be made by the infected machine.&lt;br /&gt;&lt;br /&gt;Note:&lt;br /&gt;&lt;br /&gt;    * %System% is a variable that refers to the System folder&lt;br /&gt;      By default, this is C:\Windows\System32 for Windows XP &lt;br /&gt;&lt;br /&gt;This worm creates the following mutex to ensure only one instance of the worm is running in memory:&lt;br /&gt;&lt;br /&gt;    * Global\[Random Name]&lt;br /&gt;&lt;br /&gt;The worm Connects to one of the following URLs to find the IP address of the infected machine:&lt;br /&gt;&lt;br /&gt;    * whatsmyipaddress.com&lt;br /&gt;    * ipdragon.com&lt;br /&gt;    * findmyip.com&lt;br /&gt;    * ipaddressworld.com&lt;br /&gt;    * findmyipaddress.com&lt;br /&gt;    * myipaddress.com&lt;br /&gt;    * checkip.dyndns.com&lt;br /&gt;    * checkip.dyndns.org&lt;br /&gt;&lt;br /&gt;The worm then starts an HTTP server on a random port on the infected machine to host a copy of the worm. It then continuously scans the subnet of the infected host for vulnerable machines and executes the exploit. If the exploit is successful, the remote computer will then connect back to the http server and download a copy of the worm.&lt;br /&gt;Symptoms&lt;br /&gt;Symptoms -&lt;br /&gt;&lt;br /&gt;    * Files, registry, and network communication referenced in the characteristics section&lt;br /&gt;&lt;br /&gt;Method of Infection&lt;br /&gt;Method of Infection -&lt;br /&gt;&lt;br /&gt;This worm exploits the MS08-067 Microsoft Windows Server Service vulnerability in order to propagate. Machines should be patched and rebooted to protect against this worm re-infecting the system after cleaning.&lt;br /&gt;&lt;br /&gt;This worm may also be downloaded unintentionally by users visiting malicious sites. Distribution channels could include IRC, peer-to-peer networks, email, newsgroups postings, etc.&lt;br /&gt;Removal -&lt;br /&gt;Removal -&lt;br /&gt;&lt;br /&gt;A combination of the latest DATs and the Engine will be able to detect and remove this threat. Avert recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.&lt;br /&gt;&lt;br /&gt;Additional Windows ME/XP removal considerations&lt;br /&gt;&lt;br /&gt;&lt;a href="http://download.nai.com/products/mcafee-avert/stinger3.exe"&gt;Stinger &lt;/a&gt;- A standalone removal tool has been released to assist in detecting and repairing this threat.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-207394615295402187?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-w32confickerwormgend.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-1128093961058472648</guid><pubDate>Mon, 28 Dec 2009 23:04:00 +0000</pubDate><atom:updated>2009-12-28T15:07:22.643-08:00</atom:updated><title>how to remove Worm.Win32.Netsky virus spyware</title><description>*   Warning&lt;br /&gt;          o Most of the people follow a common spyware removal technique. They delete the directory C: \ Program Files \ Worm.Win32.Netsky using Windows Explorer and registry key HKEY_LOCAL_MACHINE \ Software \ Worm.Win32.Netsky using regedit.exe without knowing that the spyware might leave some files in Windows System directory using which it can either repair itself or start generating system error notifications usually when Windows starts. We highly recommend to try Windows Add / Remove tool to uninstall the desired malware if found, use a good spyware cleaner / remover or get help from a professional.&lt;br /&gt;&lt;br /&gt;    * Recommendation&lt;br /&gt;          o In order to clean your PC by removing Worm.Win32.Netsky infection which might require you to manually detect the malware that can be in the form of an EXE , DLL , REGISTRY KEY , BROWSER HIJACK , TOOLBAR , LSP, PROCESS and/or BROWSER PLUGIN , we recommend you to DOWNLOAD our FREE Worm.Win32.Netsky FINDER SOFTWARE. Using our FREE DETECTION TOOL not only you will be able to find Worm.Win32.Netsky tracks but this will also help you to find other spyware , adware , trojan and virus infections in your PC containing the leftovers from your previous Anti-Spyware.&lt;br /&gt;&lt;br /&gt;    * Note&lt;br /&gt;          o This Worm.Win32.Netsky info page will not only provide manual removal instructions but also help you to get information about what is and how to remove or get rid of Worm.Win32.Netsky.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Delete the following directories&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Worm.Win32.Netsky does not create any directories&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Delete the following files&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;PK_ZIP0.LOG PK_ZIP1.LOG %windir%\PK_ZIP2.LOG PK_ZIP3.LOG PK_ZIP4.LOG PK_ZIP5.LOG PK_ZIP6.LOG PK_ZIP7.LOG %windir%\PK_ZIP8.LOG %windir%\PK_ZIP9.LOG %windir%\Jammer2nd.exe %windir%\pk_zip_alg.log \Jammer2nd.exe \pk_zip_alg.log&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Delete the following cookies&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Worm.Win32.Netsky does not create any cookies&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Delete the following registry keys&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Worm.Win32.Netsky does not create any registry keys&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Delete the following registry values&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Jammer2nd Jammer2nd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-1128093961058472648?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-wormwin32netsky-virus.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-265695764095352494</guid><pubDate>Mon, 28 Dec 2009 22:53:00 +0000</pubDate><atom:updated>2009-12-28T14:55:38.955-08:00</atom:updated><title>How to Remove the Backdoor.Tidserv!inf virus spyware</title><description>How to Remove the Backdoor.Tidserv!inf Trojan, spyware&lt;br /&gt;&lt;br /&gt;What's about Backdoor.Tidserv!inf&lt;br /&gt;&lt;br /&gt;The purpose of Backdoor.Tidserv!inf trojan is installing other computer parasites on a compromised machine.&lt;br /&gt;&lt;br /&gt;It modifies Windows Registry and puts itself on startup list. Backdoor.Tidserv!inf is also able to corrupt essential system files; it should be deleted upon detection until it hadn’t done much damage.&lt;br /&gt;&lt;br /&gt;Backdoor.Tidserv!inf is dangerous infection for several reasons. This trojan is able to corrupt important system files; this way it can do much damage if it isn’t removed in time. Backdoor.Tidserv!inf also downloads and installs other malware automatically on the infected machine.&lt;br /&gt;&lt;br /&gt;Tidserv!inf trojan is difficult to spot and to remove because it runs secretly in a background and it sets itself to run every time a computer boots.&lt;br /&gt;&lt;br /&gt;How to clean the Backdoor.Tidserv!inf virus&lt;br /&gt;&lt;br /&gt;Please &lt;a href="http://www.xdelbox.com/down/XDelBox.zip"&gt;download XDelBox&lt;/a&gt; from Here to your Desktop.&lt;br /&gt;&lt;br /&gt;**Note: In the event you already have XDelBox, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**&lt;br /&gt;&lt;br /&gt;If you are using Firefox, make sure that your download settings are as follows:&lt;br /&gt;          * Tools-&gt;Options-&gt;Main tab&lt;br /&gt;          * Set to "Always ask me where to Save the files".&lt;br /&gt;&lt;br /&gt;Close any open browsers. Close/disable all antivirus,HIPS and anti-malware programs so they do not interfere with the running of XDelBox,visit here for how to temporarily disable your anti-virus and/or anti-malware programs.&lt;br /&gt;&lt;br /&gt;Run XDelBox.exe with a simple click "Start Scan" &lt;br /&gt;&lt;br /&gt;&lt;a href="http://egomoo.regace.hop.clickbank.net/?action=download"&gt;download Regace&lt;/a&gt; for other Registry repairing, cleaning errors and problems to optimize your PC. It is an amazing program that I use!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-265695764095352494?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-backdoortidservinf-virus.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-7404500128558133918</guid><pubDate>Mon, 28 Dec 2009 22:48:00 +0000</pubDate><atom:updated>2009-12-28T14:52:40.188-08:00</atom:updated><title>How to remove Adware virus Zwunzi</title><description>what’s about Adware.Zwunzi&lt;br /&gt;&lt;br /&gt;Zwunzi or Adware.Zwunzi as detected by some antivirus program is another potentially unwanted application that will install itself as a Search plugin for Internet browser. Zwunzi toolbar search was known to infect Internet Explorer and Mozilla Firefox only.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;How to get rid of the Zwunzi Adware virus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step1: &lt;/span&gt;Please &lt;a href="http://www.xdelbox.com/down/XDelBox.zip"&gt;download XDelBox&lt;/a&gt; from Here to your Desktop.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;**Note: &lt;/span&gt;In the event you already have XDelBox, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 1:&lt;/span&gt; If you are using Firefox, make sure that your download settings are as follows:&lt;br /&gt;          * Tools-&gt;Options-&gt;Main tab&lt;br /&gt;          * Set to "Always ask me where to Save the files".&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 2:&lt;/span&gt;Close any open browsers. Close/disable all antivirus,HIPS and anti-malware programs so they do not interfere with the running of XDelBox,visit here for how to temporarily disable your anti-virus and/or anti-malware programs.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Step 3:&lt;/span&gt;Run XDelBox.exe with a simple click "Start Scan" &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 4:&lt;/span&gt;Waiting less than 5 minutes after scan finished. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 5:&lt;/span&gt;Click "Fix Checked" to remove spyware or malware threats.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step6: &lt;/span&gt;&lt;a href="http://egomoo.regace.hop.clickbank.net/?action=download"&gt;download Regace&lt;/a&gt; for other Registry repairing, cleaning errors and problems to optimize your PC. It is an amazing program that I use!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-7404500128558133918?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-adware-virus-zwunzi.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-5473448861426370149</guid><pubDate>Wed, 09 Dec 2009 06:24:00 +0000</pubDate><atom:updated>2009-12-08T22:26:20.121-08:00</atom:updated><title>How to Remove the W32.Badtrans.13312@mm Worm Virus from Your Computer</title><description>Also Known As: W32/Badtrans-A [Sophos], W32/Badtrans@MM [McAfee], BadTrans, I-Worm.Badtrans [KAV], WORM_BADTRANS.A [Trend], TROJ_BADTRANS.A [Trend], Win32.Badtrans.13312 [CA], Pws-AV Trojan, W32.Badtrans.13312@mm, Trojan.Psw.Hooker&lt;br /&gt;Type: Worm&lt;br /&gt;Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP&lt;br /&gt;CVE References: CVE-2001-0154&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Because W32.Badtrans.gen@mm affects different operating systems in different ways, how you remove this worm depends on your operating system. Follow the instructions in the order given.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;To remove the worm:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;   1. Run LiveUpdate to make sure that you have the most recent virus definitions.&lt;br /&gt;   2. Start Norton AntiVirus (NAV), and run a full system scan, making sure that NAV is set to scan all files.&lt;br /&gt;   3. Delete any files detected as W32.Badtrans.gen@mm. What you do next depends on whether NAV was able to delete files that it detected as infected with W32.Badtrans.gen@mm:&lt;br /&gt;          * If NAV was able to delete all the files that it detected as infected, do one of the following:&lt;br /&gt;                o If you are running Windows 95/98/Me, skip to the section To edit the Win.ini file.&lt;br /&gt;                o If you are running Windows NT/2000 and NAV was able to delete all the infected files, you are finished.&lt;br /&gt;          * If NAV was not able to delete all files that it detected as infected, go on to the next section and see the instructions for your operating system.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To remove files that cannot be deleted by NAV:&lt;br /&gt;Follow the instructions for your operating system only if NAV could not delete files that it detected as infected with W32.Badtrans.gen@mm.&lt;br /&gt;&lt;br /&gt;    * Windows 95/98/Me&lt;br /&gt;         1. Restart the computer in Safe Mode. For instructions on how to restart in Safe Mode, see the document How to restart Windows 9x or Windows Me in Safe Mode.&lt;br /&gt;         2. Run the scan again, and delete any files detected as W32.Badtrans.gen@mm.&lt;br /&gt;         3. When the scan is finished, skip to the section To edit the Win.ini file.&lt;br /&gt;&lt;br /&gt;    * Windows NT/2000/XP&lt;br /&gt;         1. Press Ctrl+Alt+Delete one time.&lt;br /&gt;         2. Click Task Manager.&lt;br /&gt;         3. Click the Processes tab.&lt;br /&gt;         4. Click the "Image Name" column header two times to sort the processes alphabetically.&lt;br /&gt;         5. Scroll through the list and look for inetd.exe. If you find the file, click it and then click End Process.&lt;br /&gt;         6. Scroll through the list and look for Kern32.exe. If you find the file, click it and then click End Process.&lt;br /&gt;         7. Close the Task Manager.&lt;br /&gt;         8. Right-click the My Computer icon on the Windows desktop, and click Explore.&lt;br /&gt;         9. Do one of the following:&lt;br /&gt;                o If you are running Windows NT, click the View menu and click Options.&lt;br /&gt;                o If you are running Windows 2000/XP, click the Tools menu and click Folder Options.&lt;br /&gt;        10. Click the View tab.&lt;br /&gt;        11. Do one of the following:&lt;br /&gt;                o If you are running Windows NT, click "Show all files," uncheck "Hide file extensions for known file types," and then click OK.&lt;br /&gt;                o If you are running Windows 2000/XP, click "Show hidden files and folders" and uncheck "Hide file extensions for known file types."&lt;br /&gt;        12. In the left pane of Windows Explorer, right-click drive C and then click Find (Windows NT) or Search (Windows 2000/XP).&lt;br /&gt;        13. In the In the "Named" or "Search for..." box, type--or copy and paste--the following file names:&lt;br /&gt;&lt;br /&gt;            inetd.exe  kern32.exe  hkk32.exe  hksdll.dll&lt;br /&gt;        14. Click Find Now or Search Now.&lt;br /&gt;        15. When the search is finished, write down the names and locations of the files that are displayed.&lt;br /&gt;        16. Click the Edit menu, and click Select All.&lt;br /&gt;        17. Hold down the Shift key down, and press the Delete key. Continue to hold down the Shift key until you are prompted to confirm the deletion. Click Yes. (Holding the Shift key while pressing the Delete key bypasses the Recycle Bin.)&lt;br /&gt;        18. Close Windows Explorer.&lt;br /&gt;        19. Go on to the section To edit the registry.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;To edit the registry:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;CAUTION: We strongly recommend that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify only the keys that are specified. Read the document How to back up the Windows registry for instructions.&lt;br /&gt;&lt;br /&gt;   1. Click Start, and click Run. The Run dialog box appears.&lt;br /&gt;   2. Type regedit and then click OK. The Registry Editor opens.&lt;br /&gt;   3. Navigate to the key&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\Software\Microsoft\&lt;br /&gt;      Windows\CurrentVersion\RunOnce&lt;br /&gt;   4. In the right pane, delete the value&lt;br /&gt;&lt;br /&gt;      Kernel32     KERN32.EXE&lt;br /&gt;   5. Navigate to the key&lt;br /&gt;&lt;br /&gt;      HKEY_CURRENT_USER\Software\Microsoft\&lt;br /&gt;      Windows NT\CurrentVersion\Windows&lt;br /&gt;   6. In the right pane, delete the value&lt;br /&gt;&lt;br /&gt;      run     &lt;path&gt;\Inetd.exe&lt;br /&gt;   7. Exit the Registry Editor.&lt;br /&gt;   8. Restart the computer.&lt;br /&gt;   9. Run the scan again, and delete any files detected as W32.Badtrans.13312@mm. This completes the removal procedure for users of Windows NT/2000.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;To edit the Win.ini file:&lt;/span&gt;&lt;br /&gt;If you are running Windows 95/98/Me, you must also do the following:&lt;br /&gt;&lt;br /&gt;   1. Click Start, and click Run.&lt;br /&gt;   2. Type the following and then click OK:&lt;br /&gt;&lt;br /&gt;      edit c:\windows\win.ini&lt;br /&gt;&lt;br /&gt;      NOTE: If you installed Windows in a different location, make the appropriate substitution.&lt;br /&gt;   3. In the [windows] section, locate the run= line. It will look similar to the following:&lt;br /&gt;&lt;br /&gt;      run=c:\windows\inetd.exe&lt;br /&gt;   4. Remove the text to the right of the = sign, so that the line now reads&lt;br /&gt;&lt;br /&gt;      run=&lt;br /&gt;   5. Save your changes, and exit the MS-DOS Editor.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Writeup By: Peter Ferrie&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-5473448861426370149?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-w32badtrans13312mm-worm.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-9182039697305028184</guid><pubDate>Wed, 09 Dec 2009 06:21:00 +0000</pubDate><atom:updated>2009-12-08T22:23:48.377-08:00</atom:updated><title>How to remove w32.virut.cf Virus</title><description>W32.Virut.CF (also referred to as W32/Virut.n) is a virus that will attempt to infect executable files such as .exe, .scr and other Portable Executable (PE) file formats. W32.Virut.CF will inject an iframe into the body of the web-related files such as .html, .php and .asp, in order to further harm your computer. The most challenging thing about W32.Virut.CF is the fact that it can bypass antivirus program detection and evade the scanning process by using Entry Point Obfuscation (EPO). &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;W32.Virut.CF Manual Removal Instructions&lt;/span&gt;&lt;br /&gt;Backup Reminder: Always be sure to back up your PC before making any changes.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 1 :&lt;/span&gt; Use Registry Editor to Remove W32.Virut.CF Registry Values&lt;br /&gt;Locate and delete "W32.Virut.CF" registry entries:&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List&lt;br /&gt;&lt;br /&gt;Read more on How to Remove W32.Virut.CF Registry Entries&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-9182039697305028184?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-w32virutcf-virus.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-8089945943929563019</guid><pubDate>Wed, 09 Dec 2009 06:18:00 +0000</pubDate><atom:updated>2009-12-08T22:19:50.222-08:00</atom:updated><title>How to remove w32 ircbot.worm</title><description>&lt;span style="font-weight:bold;"&gt;Symptoms -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;If this worm is run on a system which has not yet been patched for the MS05-039 vulnerability, it may reboot. &lt;br /&gt;Method of Infection&lt;br /&gt;Method of Infection -&lt;br /&gt;&lt;br /&gt;This threat scans for MS05-039 exploitable systems.  When a vulnerable system is found, it uses a buffer overflow to write the worm file to that machine via a TFTP upload on port 8594.  Blocking this port via McAfee Desktop Firewall or McAfee Personal Firewall will prevent infection even if the buffer overflow is not prevented.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Removal -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;AVERT DATS&lt;/span&gt;&lt;br /&gt;Use specified engine and DAT files (or later) for detection and removal. In addition to the DAT version requirements for detection, the specified engine version (or greater) must also be used.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;McAfee Intrushield&lt;/span&gt;&lt;br /&gt;Sigsets released on Aug 9th, 2005 will detect this as:&lt;br /&gt;&lt;br /&gt;DCERPC: Microsoft Plug and Play Service Buffer Overflow (0x47602000)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Stinger&lt;/span&gt;&lt;br /&gt;Stinger has been updated to help detect and repair this threat.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;McAfee Managed VirusScan&lt;/span&gt;&lt;br /&gt;Buffer Overflow Protection blocks the worm from exploiting vulnerable systems.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;McAfee Entercept&lt;/span&gt;&lt;br /&gt;McAfee Entercept prevents the vulnerable system from being exploited with Level 1 protection enabled.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;McAfee VirusScan Enterprise 8.0i&lt;/span&gt;&lt;br /&gt;Buffer Overflow Protection blocks the worm from exploiting vulnerable systems.  Additionally, systems running VirusScan Enterprise with the "Prevent creation of new files in the System32 folder (.exe)" access protection rule set to "Block access" will be protected from infection, though the buffer overflow may still occur on unpatched systems.&lt;br /&gt;&lt;br /&gt;Note: this rule if set to all processes will also block legitimate updates to files in the Windows directory, such as when applying security patches, so will need to be disabled while such legitimate activity is occurring.&lt;br /&gt;&lt;br /&gt;The User-defined Detection feature of the Unwanted Programs Policy can also be used to prevent replication of the worm, by adding a detection for wintbp.exe as shown below&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-8089945943929563019?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-w32-ircbotworm.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-3368742199665361559</guid><pubDate>Wed, 09 Dec 2009 06:17:00 +0000</pubDate><atom:updated>2009-12-08T22:18:27.124-08:00</atom:updated><title>How to remove w32.spybot.worm</title><description>Also Known As: Win32.Spybot.gen [Computer Associates], Worm.P2P.SpyBot.gen [Kaspersky], W32/Spybot-Fam [Sophos], W32/Spybot.worm.gen [McAfee], WORM_SPYBOT.GEN [Trend]&lt;br /&gt;Type: Worm&lt;br /&gt;Infection Length: Varies.&lt;br /&gt;Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows Server 2003, Windows 2000&lt;br /&gt;CVE References: CVE-2001-0876, CVE-2002-1145, CVE-2003-0109, CVE-2003-0352, CVE-2003-0533, CVE-2003-0717, CVE-2003-0812, CVE-2004-0120, CVE-2005-1983, CVE-2006-2630, CVE-2007-0041, CVE-2008-4250&lt;br /&gt;&lt;br /&gt;The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.&lt;br /&gt;&lt;br /&gt;   1. Disable System Restore (Windows Me/XP).&lt;br /&gt;   2. Update the virus definitions.&lt;br /&gt;   3. Run a full system scan, and delete all files detected.&lt;br /&gt;   4. Delete the value that was added to the registry.&lt;br /&gt;   5. Delete any zero-byte files in the Startup folder.&lt;br /&gt;   6. Reenable the SharedAccess service (Windows 2000/XP only)&lt;br /&gt;&lt;br /&gt;For specific details on each of these steps, read the following instructions.&lt;br /&gt;&lt;br /&gt;1. To disable System Restore (Windows Me/XP)&lt;br /&gt;If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.&lt;br /&gt;&lt;br /&gt;Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.&lt;br /&gt;&lt;br /&gt;Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.&lt;br /&gt;&lt;br /&gt;For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:&lt;br /&gt;&lt;br /&gt;    * How to disable or enable Windows Me System Restore&lt;br /&gt;    * How to turn off or turn on Windows XP System Restore&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Note: When you are completely finished with the removal procedure and are satisfied that the threat has been removed, reenable System Restore by following the instructions in the aforementioned documents.&lt;br /&gt;&lt;br /&gt;For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article: Antivirus Tools Cannot Clean Infected Files in the _Restore Folder (Article ID: Q263455).&lt;br /&gt;&lt;br /&gt;2. To update the virus definitions&lt;br /&gt;Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:&lt;br /&gt;&lt;br /&gt;    * Running LiveUpdate, which is the easiest way to obtain virus definitions: These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to Virus Definitions (LiveUpdate).&lt;br /&gt;    * Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted daily. You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to Virus Definitions (Intelligent Updater).&lt;br /&gt;&lt;br /&gt;      The latest Intelligent Updater virus definitions can be obtained here: Intelligent Updater virus definitions. For detailed instructions read the document: How to update virus definition files using the Intelligent Updater.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. To scan for and delete the infected files&lt;br /&gt;&lt;br /&gt;   1. Start your Symantec antivirus program and make sure that it is configured to scan all the files.&lt;br /&gt;          * For Norton AntiVirus consumer products: Read the document: How to configure Norton AntiVirus to scan all files.&lt;br /&gt;          * For Symantec AntiVirus Enterprise products: Read the document: How to verify that a Symantec Corporate antivirus product is set to scan all files.&lt;br /&gt;   2. Run a full system scan.&lt;br /&gt;   3. Note any files detected, click Delete.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Important: If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, How to start the computer in Safe Mode. Once you have restarted in Safe mode, run the scan again.&lt;br /&gt;&lt;br /&gt;After the files are deleted, restart the computer in Normal mode and proceed with the next section.&lt;br /&gt;&lt;br /&gt;Warning messages may be displayed when the computer is restarted, since the threat may not be fully removed at this point. You can ignore these messages and click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:&lt;br /&gt;&lt;br /&gt;Title: [FILE PATH]&lt;br /&gt;Message body: Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4. To delete the value from the registry&lt;br /&gt;Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.&lt;br /&gt;&lt;br /&gt;   1. Click Start &gt; Run.&lt;br /&gt;   2. Type regedit&lt;br /&gt;   3. Click OK.&lt;br /&gt;&lt;br /&gt;      Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.&lt;br /&gt;&lt;br /&gt;   4. Click OK.&lt;br /&gt;&lt;br /&gt;   5. In the Registry Editor, navigate to the following subkeys:&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\&lt;br /&gt;      RunOnce&lt;br /&gt;      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\&lt;br /&gt;      RunServices&lt;br /&gt;      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\&lt;br /&gt;      RunServices&lt;br /&gt;      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\&lt;br /&gt;      RunOnce&lt;br /&gt;      HKEY_CURRENT_USER\Software\Microsoft\OLE&lt;br /&gt;&lt;br /&gt;   6. In the right pane, delete any values that refer to the file names that were detected.&lt;br /&gt;&lt;br /&gt;   7. Navigate to the subkeys:&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger&lt;br /&gt;&lt;br /&gt;   8. In the right pane, reset the original value, if known:&lt;br /&gt;&lt;br /&gt;      "Start" = "4"&lt;br /&gt;&lt;br /&gt;   9. Navigate to the subkey:&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa&lt;br /&gt;&lt;br /&gt;  10. In the right pane, reset the original value, if known:&lt;br /&gt;&lt;br /&gt;      "restrictanonymous" = "1"&lt;br /&gt;&lt;br /&gt;  11. Navigate to the subkey:&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\&lt;br /&gt;      parameters&lt;br /&gt;      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\&lt;br /&gt;      parameters&lt;br /&gt;&lt;br /&gt;  12. In the right pane, reset the original values, if known:&lt;br /&gt;&lt;br /&gt;      "AutoShareWks" = "0"&lt;br /&gt;      "AutoShareServer" = "0"&lt;br /&gt;&lt;br /&gt;  13. Navigate to the subkey:&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate&lt;br /&gt;&lt;br /&gt;  14. In the right pane, reset the original value, if known:&lt;br /&gt;&lt;br /&gt;      "DoNotAllowXPSP2" = "1"&lt;br /&gt;&lt;br /&gt;  15. Navigate to the subkey:&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE&lt;br /&gt;&lt;br /&gt;  16. In the right pane, reset the original value, if known:&lt;br /&gt;&lt;br /&gt;      "EnableDCOM" = "N"&lt;br /&gt;&lt;br /&gt;  17. Navigate to and delete the following subkeys, if present:&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BoolTern&lt;br /&gt;      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_BOOLTERN&lt;br /&gt;      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rdriv&lt;br /&gt;      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_RDRIV&lt;br /&gt;&lt;br /&gt;  18. Exit the Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5. To delete the zero-byte files from the Startup folder&lt;br /&gt;Follow the instructions for your version of Windows:&lt;br /&gt;&lt;br /&gt;Note: There may be legitimate files on your system that start with "tftp." Delete only the zero-byte files from the Startup folder.&lt;br /&gt;&lt;br /&gt;To delete zero-byte files in Windows 95/98/Me/NT/2000&lt;br /&gt;&lt;br /&gt;   1. On the Windows taskbar, click Start &gt; Find (or b) &gt; Files or Folders.&lt;br /&gt;   2. Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.&lt;br /&gt;   3. In the "Named" or "Search for..." box, type, or copy and paste, the following file name:&lt;br /&gt;&lt;br /&gt;      tftp*.*&lt;br /&gt;&lt;br /&gt;   4. Click Find Now or Search Now.&lt;br /&gt;   5. Delete the files that are zero bytes in size and contained within any folder whose name ends with "Startup."&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To delete zero-byte files in Windows XP&lt;br /&gt;&lt;br /&gt;   1. On the Windows taskbar, click Start &gt; Search.&lt;br /&gt;   2. Click All files and folders.&lt;br /&gt;   3. In the "All or part of the file name" box, type, or copy and paste, the following file name:&lt;br /&gt;&lt;br /&gt;      tftp*.*&lt;br /&gt;&lt;br /&gt;   4. Make sure that "Look in" is set to "Local Hard Drives" or to (C:).&lt;br /&gt;   5. Click More advanced options.&lt;br /&gt;   6. Check Search system folders.&lt;br /&gt;   7. Check Search subfolders.&lt;br /&gt;   8. Click Search.&lt;br /&gt;   9. Delete the files that are zero-bytes in size and contained within any folder whose name ends with "Startup."&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;6. To reenable the SharedAccess service (Windows 2000/XP only)&lt;br /&gt;The SharedAccess service is responsible for maintaining Internet Connection Sharing and the Windows Firewall/Internet Connection Firewall applications in Windows. (The presence and names of these applications vary depending on the operating system and service pack you are using.) To protect your computer and maintain network functionality, re-enable this service if you are using any of these programs.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Windows XP Service Pack 2&lt;br /&gt;If you are running Windows XP with Service Pack 2 and are using the Windows Firewall, the operating system will alert you when the SharedAccess service is stopped, by displaying an alert balloon saying that your Firewall status is unknown. Perform the following steps to ensure that the Windows Firewall is re-enabled:&lt;br /&gt;&lt;br /&gt;   1. Click Start &gt; Control Panel.&lt;br /&gt;&lt;br /&gt;   2. Double-click the Security Center.&lt;br /&gt;&lt;br /&gt;   3. Ensure that the Firewall security essential is marked ON.&lt;br /&gt;&lt;br /&gt;      Note: If the Firewall security essential is marked on, your Windows Firewall is on and you do not need to continue with these steps.&lt;br /&gt;&lt;br /&gt;      If the Firewall security essential is not marked on, click the "Recommendations" button.&lt;br /&gt;&lt;br /&gt;   4. Under "Recommendations," click Enable Now. A window appears telling you that the Windows Firewall was successfully turned on.&lt;br /&gt;&lt;br /&gt;   5. Click Close, and then click OK.&lt;br /&gt;&lt;br /&gt;   6. Close the Security Center.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Windows 2000 or Windows XP Service Pack 1 or earlier&lt;br /&gt;Complete the following steps to re-enable the SharedAccess service:&lt;br /&gt;&lt;br /&gt;   1. Click Start &gt; Run.&lt;br /&gt;   2. Type services.msc&lt;br /&gt;&lt;br /&gt;      Then click OK.&lt;br /&gt;&lt;br /&gt;   3. Do one of the following:&lt;br /&gt;          * Windows 2000: Under the Name column, locate the "Internet Connection Sharing (ICS)" service and double-click it.&lt;br /&gt;          * Windows XP: Under the Named column, locate the "Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS)" service and double-click it.&lt;br /&gt;&lt;br /&gt;   4. Under "Startup Type:", select "Automatic" from the drop-down menu.&lt;br /&gt;&lt;br /&gt;   5. Under "Service Status:", click the Start button.&lt;br /&gt;&lt;br /&gt;   6. Once the service has completed starting, click OK.&lt;br /&gt;&lt;br /&gt;   7. Close the Services window.&lt;br /&gt;&lt;br /&gt;Writeup By: Douglas Knowles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-3368742199665361559?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-w32spybotworm.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-3689334963667252580</guid><pubDate>Wed, 09 Dec 2009 06:14:00 +0000</pubDate><atom:updated>2009-12-08T22:16:15.110-08:00</atom:updated><title>How to remove w32.downadup.b</title><description>W32.Downadup.B is a worm that propagates and infects computers by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability.  W32.Downadup.B will reduce security settings of compromised computer by ending security-related process and blocks them from accessing computer security websites.&lt;br /&gt;&lt;br /&gt;Alias:&lt;br /&gt;&lt;br /&gt;    * Worm:W32/Downadup.AL &lt;br /&gt;    * Win32/Conficker.B&lt;br /&gt;    * W32/Confick-D&lt;br /&gt;    * WORM_DOWNAD.AD&lt;br /&gt;    * Net-Worm.Win32.Kido.ih&lt;br /&gt;    * Conficker.D&lt;br /&gt;&lt;br /&gt;Damage Level: High&lt;br /&gt;&lt;br /&gt;Systems Affected: Windows&lt;br /&gt;W32.Downadup.B Removal Tool&lt;br /&gt;&lt;br /&gt;1. &lt;a href="http://www.bdtools.net/"&gt;Download the Downadup removal tool&lt;/a&gt; and save it on Desktop.&lt;br /&gt;&lt;br /&gt;2. Double click on downloaded file, chose “Extract all files…” from the File menu, and follow the wizard’s instructions. You can use any other archiver, like WinZip. This will create a folder called bd_rem_tool.&lt;br /&gt;&lt;br /&gt;3. Double click on the file “bd_rem_tool_gui.exe” (or just “bd_rem_tool_gui”). Make sure that all files have been extracted from the zip archive, because all the contents are required for the removal tool to run. Follow the tool’s instructions.&lt;br /&gt;&lt;br /&gt;4. If you have Restricted Acccess (not Admin) on Windows Vista and XP, right click the “bd_rem_tool_gui” program and choose “Run as Administrator”. Enter the computer Administrator Username and Password when prompted.&lt;br /&gt;&lt;br /&gt;5. Reboot your computer when scanning is finished.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-3689334963667252580?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-w32downadupb.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-4964632109854478166</guid><pubDate>Wed, 09 Dec 2009 06:12:00 +0000</pubDate><atom:updated>2009-12-08T22:13:49.397-08:00</atom:updated><title>how to remove w32.ackantta.b@mm</title><description>W32.Ackantta.B@mm is a self-replicating computer worm. It spreads by exploiting vulnerabilities in operating systems. Usually, it creates a copy of itself and infects numerous files on compromised system. Then W32.Ackantta.B@mm gathers emails from the infected computer and mass-mail itself as an email attachment with scam messages. This worm has been designed only to spread without making damage to the system. However, it is strongly recommended to remove it from the system as soon as possible after detection.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;W32.Ackantta.B@mm manual removal:&lt;/span&gt;&lt;br /&gt;Kill processes:&lt;br /&gt;javale.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Delete registry values:&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”SunJava Updater v7″ = “%System%\javale.exe”&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Firewall Policy\StandardProfile\AuthorizedApplications\List\%System%\”javale.exe” = “%System%\javale.exe:*:Enabled:Explorer”&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\”javastation1.1″ = “02″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\”ultrasparc1.1″ = “25″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\”CheckExeSignatures” = “0×1″&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\”RunInvalidSignatures” = “no”&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\”LowRiskFileTypes” =&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Delete files:&lt;/span&gt;&lt;br /&gt;javale.exe&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-4964632109854478166?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-w32ackanttabmm.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-616322665450823470</guid><pubDate>Wed, 09 Dec 2009 06:11:00 +0000</pubDate><atom:updated>2009-12-08T22:12:10.781-08:00</atom:updated><title>How to remove W32.SillyFDC</title><description>&lt;span style="font-weight:bold;"&gt;Description:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;W32.SillyFDC is a common detection process for files that are infected with W32.Silly. It propagates by copying and renaming itself on removable media devices and root of local and remote drives. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt; HOW TO REMOVE W32.SillyFDC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1. Temporarily Disable System Restore (Windows Me/XP). [how to]&lt;br /&gt;2. Download Ewido Micro Scanner and save it to your Desktop. Do not scan yet&lt;br /&gt;&lt;br /&gt;3. Reboot computer in SafeMode [how to]&lt;br /&gt;&lt;br /&gt;4. End malicious Process&lt;br /&gt;&lt;br /&gt;- Press Ctlr+Alt+Del&lt;br /&gt;&lt;br /&gt;- Click Process tab&lt;br /&gt;&lt;br /&gt;- End the process if present: password_viewer.exe, CALC, calc, mscalc.exe, startupfolder, config_&lt;br /&gt;startupfolder.com, config_.com&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;5. Delete the autorun files&lt;br /&gt;&lt;br /&gt;- Go to Start &gt; Run, type "cmd"&lt;br /&gt;&lt;br /&gt;- At the command prompt, type "cd\", this will bring you to C:\&lt;br /&gt;&lt;br /&gt;- Type "attrib" (C:\&gt;attrib), it will display files with attributes. Take note on attribute of autorun.inf. Usually it has SHR.&lt;br /&gt;&lt;br /&gt;- Type “attrib -s -h -r C:\autorun.inf”, it will remove System, Hidden and Read-Only attribute&lt;br /&gt;&lt;br /&gt;- Type "edit autorun.inf" it will open DOS Editor and display contents as follows&lt;br /&gt;&lt;br /&gt;=======================&lt;br /&gt;&lt;br /&gt;[autorun]&lt;br /&gt;open=file.exe&lt;br /&gt;shell\Open\Command=file.exe&lt;br /&gt;shell\open\Default=1&lt;br /&gt;shell\Explore\Command=file.exe&lt;br /&gt;shell\Autoplay\command=file.exe&lt;br /&gt;&lt;br /&gt;=======================&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;take note of the file/path that it runs. Ex: open=file.exe where file.exe is the filename of the file that autoruns.&lt;br /&gt;&lt;br /&gt;- Exit DOS Editor.&lt;br /&gt;&lt;br /&gt;- Back at the command prompt type "attrib -s -h -r file.exe", where file.exe is the file that was called on DOS editor to autorun. Ex: C:\&gt;attrib -s -h -r file.exe.  If it is located on different directory include the path. Ex: C:\&gt;attrib -s -h -r c:\Windows\file.exe&lt;br /&gt;&lt;br /&gt;- Type "del file.exe". If it is located on different directory include the path.&lt;br /&gt;&lt;br /&gt;Ex: C:\&gt;del c:\Windows\file.exe&lt;br /&gt;&lt;br /&gt;- Type "del autorun.inf"&lt;br /&gt;&lt;br /&gt;- Type "del c:\Windows\autorun.inf&lt;br /&gt;&lt;br /&gt;- Type "del c:\Windows\password_viewer.exe&lt;br /&gt;&lt;br /&gt;- Type "del c:\Douments and Settings\(Your User Name)\Local Settings\Application Data\Microsoft\CD Burning\autorun.inf&lt;br /&gt;&lt;br /&gt;- Exit command prompt by typing "exit"&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;6. Run Disc Cleanup&lt;br /&gt;&lt;br /&gt;- Go to Start &gt; All Programs &gt; Accessories &gt;System Tools, click Disc Cleanup&lt;br /&gt;&lt;br /&gt;- Check the following: Downloaded Program Files, Temporary Internet Files&lt;br /&gt;, Offline Webpage, Recycle Bin and Temporary Files.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;7. View hidden files and folders.&lt;br /&gt;&lt;br /&gt;- Open Windows Explorer&lt;br /&gt;&lt;br /&gt;- Go to Tools &gt; Folder Options&lt;br /&gt;&lt;br /&gt;- Go to View Tab&lt;br /&gt;&lt;br /&gt;- Mark "Show hidden files and folders"&lt;br /&gt;&lt;br /&gt;- Click Apply, then OK&lt;br /&gt;&lt;br /&gt;Note: If unable to change the settings, please click here.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;8. Update and scan with your installed AntiVirus. Quarantine/Delete infected files&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;9. Search and delete other files.&lt;br /&gt;&lt;br /&gt;- Go to Start &gt; Search&lt;br /&gt;&lt;br /&gt;- Find and delete files : password_viewer.exe, calc.exe (not the one located on \system32\calc.exe), mscalc.exe, startupfolder.exe, config_.exe, startupfolder.com and config_.com&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;10. Scan with Ewido&lt;br /&gt;&lt;br /&gt;- Double click the downloaded Ewido_Micro&lt;br /&gt;&lt;br /&gt;- It will download Signature Database before scanning&lt;br /&gt;- When update is completed, disconnect computer from Internet (Turn Off Modem or unplug RJ45 jack)&lt;br /&gt;- Click “Start scan” to begin. It may take time for the process to finished&lt;br /&gt;- Click “Remove Infection” to delete infected files.&lt;br /&gt;&lt;br /&gt;- Restart computer and do another scan with Ewido&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;11. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with Online Virus Scanner.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-616322665450823470?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-w32sillyfdc.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-1932781079501438837</guid><pubDate>Wed, 09 Dec 2009 06:03:00 +0000</pubDate><atom:updated>2009-12-08T22:07:24.734-08:00</atom:updated><title>How to Remove The Sasser worm - W32.Sasser.Worm</title><description>&lt;span style="font-weight:bold;"&gt;What is the Sasser worm?&lt;/span&gt;&lt;br /&gt;The Sasser worm infects machines via network connections. It can attack entire networks of computers or one single computer connected to the Internet. The worm exploits a known windows vulnerability that is easily patched, however few systems seem to have this patch installed. It attacks Windows 2000 and Windows XP machines along with Windows NT and Windows Server 2003. &lt;br /&gt;&lt;br /&gt;   1. Disconnect your computer from the local area network or Internet.&lt;br /&gt;   2. Click Start &gt; Run, type:&lt;br /&gt;      shutdown -i&lt;br /&gt;&lt;br /&gt;      and press Enter.&lt;br /&gt;      In the Remote Shutdown Dialog that opens, change 20 seconds to:&lt;br /&gt;      9999&lt;br /&gt;      and click OK.&lt;br /&gt;   3. Reconnect the network/Internet connection, click Start &gt; Windows Update to install all necessary patches automatically.&lt;br /&gt;   4. Terminate the running process.&lt;br /&gt;&lt;br /&gt;      Press CTRL+ALT+DEL to open Windows Task Manager, then select the Processes tab. Scroll down the list and search for the following processes:&lt;br /&gt;          * avserve.exe&lt;br /&gt;          * avserve2.exe&lt;br /&gt;          * skynetave.exe&lt;br /&gt;          * any process with a name consisting of four or five digits, followed by _up.exe (eg 64354_up.exe).&lt;br /&gt;&lt;br /&gt;      If you find any such process, click it, and then click End Process. Exit the Task Manager&lt;br /&gt;   5. Disable System Restore (Windows XP)&lt;br /&gt;   6. Remove the registry entires.&lt;br /&gt;      Click Start &gt; Run, type 'regedit' and click Ok.&lt;br /&gt;&lt;br /&gt;      Navigate to the following key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;&lt;br /&gt;      In the right pane, delete the following entries:&lt;br /&gt;&lt;br /&gt;      "avserve.exe"="%Windir%\avserve.exe"&lt;br /&gt;      "avserve2.exe"="%Windir%\avserve2.exe"&lt;br /&gt;      "skynetave.exe"= "%Windows%\skynetave.exe"&lt;br /&gt;      Close the Registry Editor.&lt;br /&gt;   7. Search for and delete the following files:&lt;br /&gt;&lt;br /&gt;      avserve.exe&lt;br /&gt;      avserve2.exe&lt;br /&gt;      skynetave.exe&lt;br /&gt;   8. Update your antivirus tools virus definition and run a thorough scan on your system.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-1932781079501438837?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/how-to-remove-sasser-worm-w32sasserworm.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-4551518362608481251</guid><pubDate>Fri, 04 Dec 2009 02:33:00 +0000</pubDate><atom:updated>2009-12-03T18:51:41.843-08:00</atom:updated><title>Complete List of Free spyware virus melware antivirus  Removal Tools to clean your PC</title><description>Running two anti virus products on the same computer can cause system instability, degraded performance and maybe the inability to identify a virus correctly. I have even heard of a case where someone managed to install as many as 3 anti virus on his computer and yet no problems. I would say he is just plain lucky and one day the anti virus will conflict and give so much trouble that he will not be able to recover Windows from the crash. It is very important that any previously installed anti virus software is uninstalled from your system before proceeding with the installation of the next anti virus that you would like to install.&lt;br /&gt;&lt;br /&gt;The standard method of uninstalling an anti virus is from Add or Remove Programs but sometimes the uninstaller process would hang and you will not be able to remove the anti virus from your system. When this happen, you can try using the removal tool provided by the anti virus company to remove the installed anti virus. I always have a list of uninstallers for anti virus software on my USB flash drive. Here I am sharing with you guys my list and perhaps it could help you uninstall an anti virus program that you are having trouble uninstalling..&lt;br /&gt;&lt;br /&gt;Most of the uninstallers below are very straight forward. Just download, run the file and click a button to proceed with the uninstaller. Some is a little more complicated and requires more steps which I have noted.&lt;br /&gt;&lt;br /&gt;1. &lt;span style="font-weight:bold;"&gt;Avast &lt;/span&gt; &lt;a href="http://files.avast.com/files/eng/aswclear.exe"&gt;Download avast! Uninstall Utility&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2. &lt;span style="font-weight:bold;"&gt;AVG &lt;/span&gt;Download AVG Remover &lt;a href="http://download.avg.com/filedir/util/avg_arm_sup_____.dir/avgremover.exe"&gt;32-bit&lt;/a&gt; |&lt;a href="http://www.avg.com/filedir/util/avg_arv_sup_____.dir/avgremoverx64.exe"&gt; 64-bit&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3. &lt;span style="font-weight:bold;"&gt;Avira &lt;/span&gt;&lt;a href="http://dl.antivir.de/down/windows/registrycleaner.zip"&gt;Download Avira RegCleaner&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;4. &lt;span style="font-weight:bold;"&gt;BitDefender &lt;/span&gt;Download BitDefender Uninstall Tool &lt;a href="http://www.bitdefender.com/files/KnowledgeBase/file/BitDefender_Uninstall_Tool.exe"&gt;32-bit&lt;/a&gt; | &lt;a href="http://www.bitdefender.com/files/KnowledgeBase/file/BitDefender_Uninstall_Tool_x64.exe"&gt;64-bit&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;5. &lt;span style="font-weight:bold;"&gt;Computer Associates&lt;/span&gt;Download CA SupportBridge for &lt;a href="http://homeofficekb.ca.com/CIDocument.asp?KDId=3125&amp;Preview=0&amp;Return=0&amp;GUID=DF325E0AA0AB4264AF47E4BEA49F571B"&gt;2008 &lt;/a&gt;| &lt;a href="http://homeofficekb.ca.com/CIDocument.asp?KDId=3226&amp;Preview=0&amp;Return=0&amp;GUID=96BF3B21F46C426F89D3ED40BDD236C3"&gt;2009 &lt;/a&gt;products&lt;br /&gt;&lt;br /&gt;6. &lt;span style="font-weight:bold;"&gt;ESET &lt;/span&gt;&lt;a href="http://www.nod32.nl/download/tool/nod32removal.exe"&gt;Download NOD32Removal&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;7.&lt;span style="font-weight:bold;"&gt; F-Secure&lt;/span&gt; &lt;a href="ftp://ftp.f-secure.com/support/tools/uitool/UITool3-420.zip"&gt;Download F-Secure Removal Tool&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;8. &lt;span style="font-weight:bold;"&gt;Kaspersky &lt;/span&gt;&lt;a href="http://support.kaspersky.com/downloads/products2009/kavremover9.zip"&gt;Download Kaspersky Anti-Virus Remover&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;9. &lt;span style="font-weight:bold;"&gt;McAfee &lt;/span&gt;&lt;a href="http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe"&gt;Download McAfee Consumer Product Removal Tool&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;10. &lt;span style="font-weight:bold;"&gt;Windows Live OneCare &lt;/span&gt;&lt;a href="http://download.microsoft.com/download/4/c/b/4cb845e7-1076-437b-852a-7842a8ab13c8/OneCareCleanUp.exe"&gt;Download Windows Live OneCare Cleanup Tool&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;11. &lt;span style="font-weight:bold;"&gt;Norton / Symantec &lt;/span&gt;&lt;a href="ftp://ftp.symantec.com/public/english_us_canada/removal_tools/Norton_Removal_Tool.exe"&gt;Download Norton Removal Tool&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;12. &lt;span style="font-weight:bold;"&gt;G DATA &lt;/span&gt;&lt;a href="http://www.gdata.de/typo3conf/ext/dam_frontend/pushfile.php?docID=925"&gt;Download G DATA AV-Cleaner&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;13. &lt;span style="font-weight:bold;"&gt;Panda Security &lt;/span&gt;&lt;a href="http://www.pandasecurity.com/resources/sop/UNINSTALLER_09.exe"&gt;Download Panda Security Uninstaller&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;14. &lt;span style="font-weight:bold;"&gt;Trend Micro &lt;/span&gt;&lt;a href="http://solutionfile.trendmicro.com/solutionfile/TIS/TISTOOL/SupportTool_32-bit.exe"&gt;Download Trend Micro Diagnostic Toolkit 32-bit&lt;/a&gt; | &lt;a href="http://solutionfile.trendmicro.com/solutionfile/TIS/TISTOOL/SupportTool_64-bit.exe"&gt;64-bit&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;15. &lt;span style="font-weight:bold;"&gt;AppRemover &lt;/span&gt;&lt;a href="http://www.appremover.com/"&gt;Download AppRemover &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-4551518362608481251?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/comprehensive-list-of-uninstallers-or.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-249333981676530543</guid><pubDate>Fri, 04 Dec 2009 02:31:00 +0000</pubDate><atom:updated>2009-12-03T18:32:56.132-08:00</atom:updated><title>Blocking Unwanted Parasites with a Hosts File</title><description>&lt;span style="font-weight:bold;"&gt;What a host file does&lt;/span&gt;&lt;br /&gt;The &lt;span style="font-weight:bold;"&gt;Hosts file&lt;/span&gt; contains the mappings of IP addresses to host names, this file is loaded into memory at startup then Windows checks the Hosts file before it queries any DNS servers, which enables it to override addresses in the DNS. This prevents access to the listed sites by redirecting any connection attempts back to the local (your) machine. Another feature of the HOSTS file is its ability to block other applications from connecting to the Internet, providing the entry exists.&lt;br /&gt;&lt;br /&gt;You can use a HOSTS file to block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and even most hijackers. This is accomplished by blocking the connection(s) that supplies these little gems.&lt;br /&gt;&lt;br /&gt;Example - the following entry 127.0.0.1 ad.doubleclick.net blocks all files supplied by that DoubleClick Server to the web page you are viewing. This also prevents the server from tracking your movements. Why? ... because in certain cases "Ad Servers" like Doubleclick (and many others) will try to open a separate connection on the webpage you are viewing.&lt;br /&gt;&lt;br /&gt;For XP SP2 users you should see a Security Center prompt about allowing this connection. [screenshot]&lt;br /&gt;Simply click No and continue. Yes the prompts can be annoying but at least you'll know, however you should not see these prompts if these entries are included in the HOSTS file.&lt;br /&gt;Note: this prompt only occurs if (example) *.doubleclick.net is included in the "Restricted Zone".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-249333981676530543?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/blocking-unwanted-parasites-with-hosts.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-188071922290137034</guid><pubDate>Fri, 04 Dec 2009 02:22:00 +0000</pubDate><atom:updated>2009-12-03T18:22:31.341-08:00</atom:updated><title>UAE Blackberry update was spyware</title><description>An update for Blackberry users in the United Arab Emirates could allow unauthorised access to private information and e-mails.&lt;br /&gt;&lt;br /&gt;The update was prompted by a text from UAE telecoms firm Etisalat, suggesting it would improve performance.&lt;br /&gt;&lt;br /&gt;Instead, the update resulted in crashes or drastically reduced battery life.&lt;br /&gt;&lt;br /&gt;Blackberry maker Research in Motion (RIM) said in a statement the update was not authorised, developed, or tested by RIM.&lt;br /&gt;&lt;br /&gt;Etisalat is a major telecommunications firm based in the UAE, with 145,000 Blackberry users on its books.&lt;br /&gt;&lt;br /&gt;In the statement, RIM told customers that "Etisalat appears to have distributed a telecommunications surveillance application... independent sources have concluded that it is possible that the installed software could then enable unauthorised access to private or confidential information stored on the user's smartphone".&lt;br /&gt;&lt;br /&gt;It adds that "independent sources have concluded that the Etisalat update is not designed to improve performance of your BlackBerry Handheld, but rather to send received messages back to a central server".&lt;br /&gt;&lt;br /&gt;The concern over this unauthorised access only came to light when users started reporting problems with their handsets.&lt;br /&gt;&lt;br /&gt;After downloading the update, users across the country noticed significantly reduced battery life, poor reception and in some cases, handsets stopped working altogether.&lt;br /&gt;&lt;br /&gt;Users have complained that the firm's customer service is unable to provide information on the problem. Initial advice led many users to simply buy new batteries.&lt;br /&gt;&lt;br /&gt;'Surveillance solutions'&lt;br /&gt;&lt;br /&gt;The update has now been identified as an application developed by American firm SS8. The California-based company describes itself as a provider of "lawful electronic intercept and surveillance solutions".&lt;br /&gt;&lt;br /&gt;It is not clear why Etisalat wanted to include the software in the download.&lt;br /&gt;&lt;br /&gt;The firm issued a brief statement last week, calling the problem a "slight technical fault", saying that the "upgrades were required for service enhancements".&lt;br /&gt;&lt;br /&gt;Etisalat told BBC News that it stands by last week's statement and has not yet responded to further requests for comment.&lt;br /&gt;&lt;br /&gt;"There may be a good reason they wanted to install the software," said one Blackberry user in Dubai who did not want to be named.&lt;br /&gt;&lt;br /&gt;"But my biggest problem is that my phone won't work. If you call customer service you either can't get through, or they don't know what to tell you. I don't know what to do."&lt;br /&gt;&lt;br /&gt;RIM has now issued its own update allowing users to remove the application. Customers of the country's rival service, Du, have not been affected.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-188071922290137034?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/uae-blackberry-update-was-spyware.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-6417800408537142443</guid><pubDate>Fri, 04 Dec 2009 02:20:00 +0000</pubDate><atom:updated>2009-12-03T18:20:12.530-08:00</atom:updated><title>Packed.Generic.270</title><description>Discovered: November 29, 2009&lt;br /&gt;Updated: November 30, 2009 5:58:30 AM&lt;br /&gt;Type: Trojan, Virus&lt;br /&gt;Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000&lt;br /&gt;&lt;br /&gt;Packed.Generic.270 is a heuristic detection for files that may have been obfuscated or encrypted in order to conceal them from antivirus software.&lt;br /&gt;&lt;br /&gt;This heuristic detection is used to detect threats associated with the following families:&lt;br /&gt;&lt;br /&gt;    * Infostealer.Banker.C&lt;br /&gt;    * Trojan.Dropper&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Protection&lt;br /&gt;&lt;br /&gt;    * Initial Rapid Release version November 29, 2009 revision 048&lt;br /&gt;    * Latest Rapid Release version November 29, 2009 revision 048&lt;br /&gt;    * Initial Daily Certified version November 30, 2009 revision 004&lt;br /&gt;    * Latest Daily Certified version November 30, 2009 revision 004&lt;br /&gt;    * Initial Weekly Certified release date December 2, 2009&lt;br /&gt;&lt;br /&gt;Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.&lt;br /&gt;Threat Assessment&lt;br /&gt;Wild&lt;br /&gt;&lt;br /&gt;    * Wild Level: Low&lt;br /&gt;    * Number of Infections: 0 - 49&lt;br /&gt;    * Number of Sites: 0 - 2&lt;br /&gt;    * Geographical Distribution: Low&lt;br /&gt;    * Threat Containment: Easy&lt;br /&gt;    * Removal: Easy&lt;br /&gt;&lt;br /&gt;Damage&lt;br /&gt;&lt;br /&gt;    * Damage Level: Low&lt;br /&gt;&lt;br /&gt;Distribution&lt;br /&gt;&lt;br /&gt;    * Distribution Level: Low&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-6417800408537142443?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/packedgeneric270.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-6460259913453890170</guid><pubDate>Fri, 04 Dec 2009 02:19:00 +0000</pubDate><atom:updated>2009-12-03T18:19:53.984-08:00</atom:updated><title>Packed.Generic.271</title><description>Discovered: November 30, 2009&lt;br /&gt;Updated: November 30, 2009 11:18:21 AM&lt;br /&gt;Type: Trojan, Virus&lt;br /&gt;Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000&lt;br /&gt;&lt;br /&gt;Packed.Generic.271 is a heuristic detection for files that may have been obfuscated or encrypted in order to conceal them from antivirus software.&lt;br /&gt;&lt;br /&gt;This heuristic detection is used to detect threats associated with the following families:&lt;br /&gt;&lt;br /&gt;    * Infostealer.Banker.C&lt;br /&gt;    * Downloader&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Protection&lt;br /&gt;&lt;br /&gt;    * Initial Rapid Release version November 30, 2009 revision 005&lt;br /&gt;    * Latest Rapid Release version November 30, 2009 revision 005&lt;br /&gt;    * Initial Daily Certified version November 30, 2009 revision 004&lt;br /&gt;    * Latest Daily Certified version November 30, 2009 revision 004&lt;br /&gt;    * Initial Weekly Certified release date December 2, 2009&lt;br /&gt;&lt;br /&gt;Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.&lt;br /&gt;Threat Assessment&lt;br /&gt;Wild&lt;br /&gt;&lt;br /&gt;    * Wild Level: Low&lt;br /&gt;    * Number of Infections: 0 - 49&lt;br /&gt;    * Number of Sites: 0 - 2&lt;br /&gt;    * Geographical Distribution: Low&lt;br /&gt;    * Threat Containment: Easy&lt;br /&gt;    * Removal: Easy&lt;br /&gt;&lt;br /&gt;Damage&lt;br /&gt;&lt;br /&gt;    * Damage Level: Low&lt;br /&gt;&lt;br /&gt;Distribution&lt;br /&gt;&lt;br /&gt;    * Distribution Level: Low&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-6460259913453890170?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/packedgeneric271.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-3947558980571275393</guid><pubDate>Fri, 04 Dec 2009 02:19:00 +0000</pubDate><atom:updated>2009-12-03T18:19:30.885-08:00</atom:updated><title>AntivirusSystemPro</title><description>Updated: November 30, 2009 3:32:18 PM&lt;br /&gt;Type: Misleading Application&lt;br /&gt;Name: Antivirus System Pro&lt;br /&gt;Risk Impact: Medium&lt;br /&gt;Systems Affected: Windows XP, Windows Vista, Windows NT, Windows Server 2003, Windows 2000&lt;br /&gt;&lt;br /&gt;Behavior&lt;br /&gt;AntivirusSystemPro is a misleading application that may give exaggerated reports of threats on the computer.&lt;br /&gt;&lt;br /&gt;Protection&lt;br /&gt;&lt;br /&gt;    * Initial Rapid Release version November 30, 2009 revision 017&lt;br /&gt;    * Latest Rapid Release version November 30, 2009 revision 025&lt;br /&gt;    * Initial Daily Certified version November 30, 2009 revision 022&lt;br /&gt;    * Latest Daily Certified version November 30, 2009 revision 040&lt;br /&gt;    * Initial Weekly Certified release date December 2, 2009&lt;br /&gt;&lt;br /&gt;Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-3947558980571275393?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/antivirussystempro.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-4256449892484978028</guid><pubDate>Fri, 04 Dec 2009 02:18:00 +0000</pubDate><atom:updated>2009-12-03T18:19:05.519-08:00</atom:updated><title>Trojan.Vundo!gen2</title><description>Discovered: December 2, 2009&lt;br /&gt;Updated: December 2, 2009 11:57:16 AM&lt;br /&gt;Type: Trojan&lt;br /&gt;Systems Affected: Windows XP, Windows Vista, Windows NT, Windows Server 2003, Windows 2000&lt;br /&gt;&lt;br /&gt;Trojan.Vundo!gen2 is a heuristic detection used to detect threats associated with the following family:&lt;br /&gt;Trojan.Vundo&lt;br /&gt;&lt;br /&gt;Protection&lt;br /&gt;&lt;br /&gt;    * Initial Rapid Release version December 2, 2009 revision 008&lt;br /&gt;    * Latest Rapid Release version December 2, 2009 revision 008&lt;br /&gt;    * Initial Daily Certified version December 2, 2009 revision 024&lt;br /&gt;    * Latest Daily Certified version December 2, 2009 revision 024&lt;br /&gt;    * Initial Weekly Certified release date December 2, 2009&lt;br /&gt;&lt;br /&gt;Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.&lt;br /&gt;Threat Assessment&lt;br /&gt;Wild&lt;br /&gt;&lt;br /&gt;    * Wild Level: Low&lt;br /&gt;    * Number of Infections: 0 - 49&lt;br /&gt;    * Number of Sites: 0 - 2&lt;br /&gt;    * Geographical Distribution: Low&lt;br /&gt;    * Threat Containment: Easy&lt;br /&gt;    * Removal: Easy&lt;br /&gt;&lt;br /&gt;Damage&lt;br /&gt;&lt;br /&gt;    * Damage Level: Medium&lt;br /&gt;&lt;br /&gt;Distribution&lt;br /&gt;&lt;br /&gt;    * Distribution Level: Low&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-4256449892484978028?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/trojanvundogen2.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-6797819719489885761</guid><pubDate>Fri, 04 Dec 2009 02:18:00 +0000</pubDate><atom:updated>2009-12-03T18:18:17.380-08:00</atom:updated><title>W32.Mabezat.B!dam</title><description>Discovered: December 2, 2009&lt;br /&gt;Updated: December 2, 2009 4:38:12 PM&lt;br /&gt;Type: Virus&lt;br /&gt;Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000&lt;br /&gt;&lt;br /&gt;W32.Mabezat.B!dam is a detection for corrupted files that are infected with W32.Mabezat.B.&lt;br /&gt;&lt;br /&gt;Protection&lt;br /&gt;&lt;br /&gt;    * Initial Rapid Release version December 2, 2009 revision 022&lt;br /&gt;    * Latest Rapid Release version December 2, 2009 revision 022&lt;br /&gt;    * Initial Daily Certified version December 2, 2009 revision 024&lt;br /&gt;    * Latest Daily Certified version December 2, 2009 revision 024&lt;br /&gt;    * Initial Weekly Certified release date December 9, 2009&lt;br /&gt;&lt;br /&gt;Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.&lt;br /&gt;Threat Assessment&lt;br /&gt;Wild&lt;br /&gt;&lt;br /&gt;    * Wild Level: Low&lt;br /&gt;    * Number of Infections: 0 - 49&lt;br /&gt;    * Number of Sites: 0 - 2&lt;br /&gt;    * Geographical Distribution: Low&lt;br /&gt;    * Threat Containment: Easy&lt;br /&gt;    * Removal: Easy&lt;br /&gt;&lt;br /&gt;Damage&lt;br /&gt;&lt;br /&gt;    * Damage Level: Medium&lt;br /&gt;&lt;br /&gt;Distribution&lt;br /&gt;&lt;br /&gt;    * Distribution Level: Low&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-6797819719489885761?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/w32mabezatbdam.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-9001093729395452007</guid><pubDate>Fri, 04 Dec 2009 02:17:00 +0000</pubDate><atom:updated>2009-12-03T18:17:53.301-08:00</atom:updated><title>Adware.Zwunzi</title><description>Updated: December 3, 2009 12:59:34 AM&lt;br /&gt;Type: Adware&lt;br /&gt;Name: Zwunzi&lt;br /&gt;Version: 1.0 build 128&lt;br /&gt;Publisher: zwunzi.com&lt;br /&gt;Risk Impact: High&lt;br /&gt;Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000&lt;br /&gt;&lt;br /&gt;Behavior&lt;br /&gt;Adware.Zwunzi is an adware program that installs itself as a Browser Search Plugin for Internet Explorer and Mozilla Firefox.&lt;br /&gt;&lt;br /&gt;Protection&lt;br /&gt;&lt;br /&gt;    * Initial Rapid Release version December 2, 2009 revision 039&lt;br /&gt;    * Latest Rapid Release version December 3, 2009 revision 036&lt;br /&gt;    * Initial Daily Certified version December 2, 2009 revision 050&lt;br /&gt;    * Latest Daily Certified version December 2, 2009 revision 050&lt;br /&gt;    * Initial Weekly Certified release date December 9, 2009&lt;br /&gt;&lt;br /&gt;Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-9001093729395452007?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/adwarezwunzi.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-8721477802794636844.post-3688551073006878530</guid><pubDate>Fri, 04 Dec 2009 02:17:00 +0000</pubDate><atom:updated>2009-12-03T18:17:25.583-08:00</atom:updated><title>W32.SillyFDC.BBX</title><description>Discovered: December 2, 2009&lt;br /&gt;Updated: December 3, 2009 5:45:23 AM&lt;br /&gt;Type: Worm&lt;br /&gt;Infection Length: 705,283 bytes&lt;br /&gt;Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000&lt;br /&gt;&lt;br /&gt;W32.SillyFDC.BBX is a worm that spreads by copying itself to removable and mapped drives. It also drops more malware, attempts to download files, lowers security settings, disables certain system software and alters certain system settings.&lt;br /&gt;&lt;br /&gt;Protection&lt;br /&gt;&lt;br /&gt;    * Initial Rapid Release version December 2, 2009 revision 025&lt;br /&gt;    * Latest Rapid Release version December 2, 2009 revision 025&lt;br /&gt;    * Initial Daily Certified version December 2, 2009 revision 024&lt;br /&gt;    * Latest Daily Certified version December 2, 2009 revision 024&lt;br /&gt;    * Initial Weekly Certified release date December 2, 2009&lt;br /&gt;&lt;br /&gt;Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.&lt;br /&gt;Threat Assessment&lt;br /&gt;Wild&lt;br /&gt;&lt;br /&gt;    * Wild Level: Low&lt;br /&gt;    * Number of Infections: 0 - 49&lt;br /&gt;    * Number of Sites: 0 - 2&lt;br /&gt;    * Geographical Distribution: Low&lt;br /&gt;    * Threat Containment: Easy&lt;br /&gt;    * Removal: Easy&lt;br /&gt;&lt;br /&gt;Damage&lt;br /&gt;&lt;br /&gt;    * Damage Level: Low&lt;br /&gt;    * Modifies Files: Modifies certain files, replacing them with a copy of other malware.&lt;br /&gt;    * Compromises Security Settings: Lowers security settings.&lt;br /&gt;&lt;br /&gt;Distribution&lt;br /&gt;&lt;br /&gt;    * Distribution Level: Medium&lt;br /&gt;    * Target of Infection: Removable drives&lt;br /&gt;&lt;br /&gt;Writeup By: Fergal Ladley and Jarrad Shearer&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8721477802794636844-3688551073006878530?l=www.softe.org' alt='' /&gt;&lt;/div&gt;</description><link>http://www.softe.org/2009/12/w32sillyfdcbbx.html</link><author>noreply@blogger.com (Mandy)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item></channel></rss>