<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Free Spyware Adware Worm and Virus Trojan Horse Download Removal Tools &#187; malwarebytes</title>
	<atom:link href="http://www.softe.org/tag/malwarebytes/feed" rel="self" type="application/rss+xml" />
	<link>http://www.softe.org</link>
	<description>FREE Computer Repair</description>
	<lastBuildDate>Sun, 04 Dec 2011 21:36:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Windows 7 black screen ram shortage infection % of my ram wasn&#8217;t functioning properly</title>
		<link>http://www.softe.org/windows-7-black-screen-ram-shortage-infection-of-my-ram-wasnt-functioning-properly.html</link>
		<comments>http://www.softe.org/windows-7-black-screen-ram-shortage-infection-of-my-ram-wasnt-functioning-properly.html#comments</comments>
		<pubDate>Fri, 30 Sep 2011 04:29:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows 7 black screen ram shortage infection % of my ram wasn't functioning properly]]></category>
		<category><![CDATA[infection]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[ram]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=164</guid>
		<description><![CDATA[If your windows 7 screen turns black and you get an error stating something along the lines of ram shortage infection or a given % value was not functioning properly, here is what you do: download unhide.exe and TDssKiller Run  TDSSKiller and it will locate your infection. It will ask you to remoev the infection [...]]]></description>
			<content:encoded><![CDATA[<p>If your windows 7 screen turns black and you get an error stating something along the lines of ram shortage infection or a given % value was not functioning properly, here is what you do:</p>
<p><span style="color: #000000;"><strong>download </strong><a href="http://download.bleepingcomputer.com/grinler/unhide.exe" target="_blank">unhide.exe</a> and <a href="http://support.kaspersky.com/downloads/utils/tdsskiller.exe" target="_blank">TDssKiller</a></span><br />
Run  TDSSKiller and it will locate your infection. It will ask you to remoev the infection ans simply say yes.  IF all goes well and your PC is clean, it will ask to reboot your windows 7. Please do so.</p>
<p>It will most likely find: <strong>TrojanDownloader.OpenStream.NBF trojan</strong></p>
<p>If this does not work for you, download the latest <strong>malwarebytes</strong> and update and scan.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/windows-7-black-screen-ram-shortage-infection-of-my-ram-wasnt-functioning-properly.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>So how do you Remove Koobface the facebook worm virus</title>
		<link>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html</link>
		<comments>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html#comments</comments>
		<pubDate>Thu, 08 Sep 2011 18:50:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[So how do you Remove Koobface the facebook worm virus]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[google redirect spyware]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[windows xp]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=159</guid>
		<description><![CDATA[Koobface Virus threat is one that is taking by storm, specially because it uses a host such as facebook social network to spread the virus.  This Koobface virus finds methods to seek into the users PC and spread malware into the computer so its considered as a worm which replicates itself within your computer.  So [...]]]></description>
			<content:encoded><![CDATA[<p>Koobface Virus threat is one that is taking by storm, specially because it uses a host such as facebook social network to spread the virus.  This Koobface virus finds methods to seek into the users PC and spread malware into the computer so its considered as a worm which replicates itself within your computer.  So how does KoobFace infect your PC, well its simple really, if you use facebook, and you receive a strange email, stating something along the lines of &#8221; click here to see your face look stupid&#8221; which attracts you to click the link,  once clicked, a virus code will be downloaded to your PC which will then spread the worm to your PC and start to redirect your search results from google to malicious software and websites. Simple huh?</p>
<div>
<div id="mod_2169282">
<div id="txtd_2169282">
<div>
<div id="mod_2169300">
<h2>So how do you Remove Koobface worm virus?</h2>
<div id="txtd_2169300">With  anti-malware software such as melwarebytes and spybot, you might be able to remove this worm, but sometimes this is not possible and you need to manually remove it.</p>
<div>
<div id="mod_2169358">
<div id="txtd_2169358">
<p><strong>Using The Add Remove Program in control panel:</strong></p>
<ul>
<li>Go to Add\Remove in control panel</li>
<li>Look up for the Koobface malware to remove and uninstall it.</li>
</ul>
<p>if you do not see the koobface there, go to registry and search for: ( <span style="color: #ff0000;">if you do not know how to use your registry, you might really screw up your PC for good, so take note, this step is for advanced users who have messed around with the registry and know their way around</span>.)</p>
<ul>
<li>Search for &#8220;koobface&#8221; in Mycomputer using find utility.</li>
<li>Note down Koobface file path some where.</li>
<li>Press Ctrl+Alt+Del to open &#8216;Task Manager&#8217;</li>
<li>End the &#8220;Koobface&#8221; processes.</li>
</ul>
<p><strong>End the following processes</strong></p>
<ol>
<li>%SYSTEMROOT%\bolivar28.exe</li>
<li>che07.exe</li>
<li>bolivar28.exe</li>
<li>%WinDir%\system32\nScan\ekrn.exe</li>
<li>%WinDir%\system32\nScan\ecls.exe</li>
<li>%WinDir%\system32\splm\ncsjapi32.exe</li>
<li>%WinDir%\bolivar28.exe</li>
<li>C:\Windows\fbtre6.exe</li>
</ol>
<p><strong>now change Registry Files</strong></p>
<ul>
<li>Type &#8216;regedit&#8217; in Run and press Enter.</li>
<li>The Registry Editor will appear, locate the above mentioned process files and delete them.</li>
<li>Locate &#8220;Koobface&#8221; registry entries and delete them, they are as the follows:</li>
</ul>
<ol>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Intelli Mouse Pro Version 2.0B\StubPath: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Intelli Mouse Pro Version 2.0B: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden: &#8220;2&#8243;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\nScan32\ExecuteDate: &#8220;14\8\2008&#8243;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\&#8221;systray&#8221; = &#8220;c:\windows\mstre6.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\&#8221;systray&#8221; = &#8220;C:\Windows\fbtre6.exe&#8221;</li>
<li>HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating</li>
</ol>
</div>
</div>
</div>
<div id="mod_2169659">
<div id="txtd_2169659">
<p><strong>Now you have to unregister the dll files</strong></p>
<ul>
<li>Go to start and type in &#8216;cmd&#8217; to open comman prompt.</li>
<li>First locate the following dll files using &#8216;dir&#8217; command.</li>
</ul>
<ol>
<li>%WinDir%\system32\nScan\ekrnEmon.dll</li>
<li>%WinDir%\system32\nScan\ekrnScan.dll</li>
<li>%WinDir%\system32\nScan\ekrnEpfw.dll</li>
<li>%WinDir%\system32\nScan\ekrnAmon.dll</li>
<li>%WinDir%\system32\splm\lmfunit32.dll</li>
<li>%WinDir%\system32\splm\mcaserv32.dll</li>
<li>%WinDir%\system32\splm\kbdsapi.dll</li>
</ol>
<ul>
<li>Now change the current directory using &#8216;cd&#8217; command leave a space after &#8216;cd&#8217; and then the path of dll file, which you have located above. Press enter after this.</li>
<li>Now unregister dll file by typing &#8220;directory path+&#8217;regsvr32/u&#8217;+dll file name&#8221;. Press enter, the file will be unregistered.</li>
</ul>
<p>&nbsp;</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic BackDoor!djf!5D41C80E​A0DA malware Trojan Virus</title>
		<link>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html</link>
		<comments>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html#comments</comments>
		<pubDate>Wed, 20 Jul 2011 22:58:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic BackDoor!djf!5D41C80E​A0DA malware Trojan Virus]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[IRC virus]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[virus removal]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[W32/Autorun]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=154</guid>
		<description><![CDATA[These files were added to the system: %APPDATA%\services.exe %TEMP%\e3c1c08557a0d0feee33b9c9d18b4e6c129b553f.exe This Trojan will attempt to fiddle with your network conection, e.g hxxp://www.maxmind.com/app/*** Virus app&#8217;s Detection Names EMSI Software Trojan.Backdoor.Ircbot!IK avast Win32:Ruskill-F Kaspersky Backdoor.Win32.IRCBot.tjd BitDefender Backdoor.Bot.138642 Microsoft VirTool:Win32/CeeInject.gen!EI Symantec Backdoor.IRC.Bot Eset a variant of Win32/Injector.GLN trojan norman W32/Suspicious_Gen3.TYCW Sophos Mal/Generic-L Trend Micro PAK_Generic.001 vba32 Backdoor.IRCBot.tjd How to [...]]]></description>
			<content:encoded><![CDATA[<p>These files were added to the system:</p>
<ul>
<li>%APPDATA%\services.exe</li>
</ul>
<ul>
<li>%TEMP%\e3c1c08557a0d0feee33b9c9d18b4e6c129b553f.exe</li>
</ul>
<p>This Trojan will attempt to fiddle with your network conection, e.g hxxp://www.maxmind.com/app/***</p>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr bgcolor="silver">
<th align="left" bgcolor="silver"><strong>Virus app&#8217;s<br />
</strong></th>
<th align="right" bgcolor="silver"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">EMSI Software</td>
<td align="right">Trojan.Backdoor.Ircbot!IK</td>
</tr>
<tr>
<td align="left">avast</td>
<td align="right">Win32:Ruskill-F</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Backdoor.Win32.IRCBot.tjd</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Backdoor.Bot.138642</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">VirTool:Win32/CeeInject.gen!EI</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">Backdoor.IRC.Bot</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">a variant of Win32/Injector.GLN trojan</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Suspicious_Gen3.TYCW</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Mal/Generic-L</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">PAK_Generic.001</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">Backdoor.IRCBot.tjd</td>
</tr>
</tbody>
</table>
<p>How to remove <strong>Generic BackDoor!djf!5D41C80E​A0DA</strong></p>
<p>Removal should be easy given the fact that you are able to follow directions <img src='http://www.softe.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>First thing to do is disconnect your network or internet. Now you will need to reboot your PC and enter safe mode, if you do not know how to enter safe mode, please search above for &#8221; how to enter safe mode&#8221;</p>
<p>Now you will need to do a system scan using these apps below:</p>
<p>1. your favorite virus app, i suggest AVG or Microsoft security essentials<br />
2. do a system scan using Malwarebytes<br />
3. do a system scan using spybot<br />
4. do a system scan using hijackthis</p>
<p>if the virus  is not letting you do these scans, you must :</p>
<p>1.Disable System Restore on Windows ME and windows XP only.<br />
2.Update to current engine and DAT files for detection and removal.<br />
3.Run a complete system scan.</p>
<p>This should remove the threat, this threat is a low security threat but never the less it should always be cleaned before using the world wide web.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan.win32.Generic.pak!cobra.Engine</title>
		<link>http://www.softe.org/trojan-win32-generic-pakcobra-engine.html</link>
		<comments>http://www.softe.org/trojan-win32-generic-pakcobra-engine.html#comments</comments>
		<pubDate>Mon, 27 Jun 2011 19:22:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan.win32.Generic.pak!cobra.Engine]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[spybot]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[win32]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=149</guid>
		<description><![CDATA[This virus might be a google redirect trojan and it is not easy to clean, however, these are the first steps to take in trying to delete this nasty win32 virus. go to start menu, then run, now type in MSCONFIG, go to startup tab and look for a long string of command that has [...]]]></description>
			<content:encoded><![CDATA[<p>This virus might be a google redirect trojan and it is not easy to clean, however, these are the first steps to take in trying to delete this nasty win32 virus.</p>
<p>go to start menu, then run, now type in MSCONFIG, go to startup tab and look for a long string of command that has random letters and sometimes numbers, disable that line and save.</p>
<p><a href="http://www.softe.org/download"><strong>Download Malwarebytes</strong></a>, update malwarebytes then do a full system scan. if any virus is found, it will delete it.</p>
<p>Now <a href="http://www.softe.org/download"><strong>download spybot</strong></a>, do an update and a full scan, delete any melware or spyware it finds.</p>
<p>You surly must have a virus protection software, if not, download <a href="http://www.softe.org/download"><strong>Microsoft Security Essentials</strong></a>, its free, update the app then a full scan.</p>
<p>These steps above should fix and delete the <strong>Trojan.win32.Generic.pak!cobra.Engine virus</strong></p>
<p>Here are other virus trojans that are smiler to the one above and can be cleaned the same way.</p>
<p><a href="http://www.softe.org/wp-content/uploads/2011/06/computer-virus.jpg"><img class="alignleft size-full wp-image-152" title="computer virus" src="http://www.softe.org/wp-content/uploads/2011/06/computer-virus.jpg" alt="" width="380" height="253" /></a></p>
<p>Trojan.Win32.Generic!BT: Trojan<br />
Trojan-Spy.Win32.Zbot.gen: Trojan<br />
Exploit.PDF-JS.Gen (v): Exploit<br />
Trojan.Win32.Generic!SB.0: Trojan<br />
INF.Autorun (v): Trojan<br />
Trojan.Win32.Hiloti.gen.d (v): Trojan<br />
Trojan.Win32.Generic.pak!cobra: Trojan<br />
Trojan.Win32.Adware: Adware (General)<br />
MyWebSearch Toolbar: Potentially Unwanted Program<br />
Trojan.Win32.Malware: Trojan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/trojan-win32-generic-pakcobra-engine.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Win32/Olmarik Trojan malware</title>
		<link>http://www.softe.org/how-to-remove-win32olmarik-trojan-malware.html</link>
		<comments>http://www.softe.org/how-to-remove-win32olmarik-trojan-malware.html#comments</comments>
		<pubDate>Wed, 09 Mar 2011 05:33:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[IRC virus]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[messaging]]></category>
		<category><![CDATA[scareware]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[W32/Autorun]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=130</guid>
		<description><![CDATA[If  your PC has been infected with the Win32/Olmarik  Trojan virus, please download Malwarebytes' Anti-Malware its a free app. Double click]]></description>
			<content:encoded><![CDATA[<p>If  your PC has been infected with the Win32/Olmarik  Trojan virus, please download Malwarebytes&#8217; Anti-Malware its a free app. Double click <strong>mbam-setup.exe</strong> and follow the directions and install it on your home PC. Make sure you click update Malwarebytes before you press the scan button.</p>
<p>What the Win32/Olmarik trojan does is it infects your PC by installing a nasty malware by falsified displaying security alerts and making the user install even more bugs. Once you click on   the alert, it will start downloading anti-spyware or anti-virus tools that are useless and will infect even more of  your file system structure and files in general. Take care of this trojan as soon as you can to prevent our PC from getting any worse.</p>
<p><img class="alignnone" title="Virus win32 trojan" src="http://farinango.info/wp-content/uploads/2010/06/virus-farinango.info_.jpg" alt="" width="400" height="365" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-win32olmarik-trojan-malware.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Stuxnet computer malware malicious software</title>
		<link>http://www.softe.org/what-is-stuxnet-computer-malware-malicious-software.html</link>
		<comments>http://www.softe.org/what-is-stuxnet-computer-malware-malicious-software.html#comments</comments>
		<pubDate>Wed, 02 Feb 2011 22:25:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[What is Stuxnet computer malware malicious software]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[malicious software]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=123</guid>
		<description><![CDATA[Stuxnet . A computer malware spyware that attacks computer systems aimed mostly at Iran which seems the ones involved in creating the spyware threat.]]></description>
			<content:encoded><![CDATA[<p><strong>Stuxnet </strong>. A computer malware spyware that attacks computer systems aimed mostly at Iran which seems the ones involved in creating the spyware threat.</p>
<p>HOW DOES IT Stuxnet really WORK?</p>
<p>The virus is a malicious software or <strong>malware </strong>attacks widely used industrial control systems built by the German firm Siemens. Experts say the virus could be used for espionage or sabotage.</p>
<p>Siemens said that the <strong>malware </strong>is spread via infected USB memory devices thumb drive, exploiting a vulnerability in Microsoft operating system Windows that has been resolved.</p>
<p>The attacks malware software running Supervisory Control and Data Acquisition, or <strong>SCADA</strong>, systems. These systems are used to control automated installations &#8211; plant chemicals to food and energy generators.</p>
<p>Analysts said the attackers may have chosen to spread malicious software by the way of a memory unit because many SCADA systems are not connected to the Internet, but do not have USB ports.</p>
<p>Once the <strong>worm infects a system</strong>, it quickly communicates with a remote server computer can be used to steal proprietary corporate data or take control of the SCADA system, said Randy Abrams, ESET investigator, a private security company <strong>Stuxnet </strong>been studied.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/what-is-stuxnet-computer-malware-malicious-software.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Downloader-CEW.q!D113​7DCFCEBA Trojan how to remove</title>
		<link>http://www.softe.org/downloader-cew-qd113%e2%80%8b7dcfceba-trojan-how-to-remove.html</link>
		<comments>http://www.softe.org/downloader-cew-qd113%e2%80%8b7dcfceba-trojan-how-to-remove.html#comments</comments>
		<pubDate>Wed, 02 Feb 2011 21:36:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Downloader-CEW.q!D113​7DCFCEBA Trojan]]></category>
		<category><![CDATA[Adobe Flash Player]]></category>
		<category><![CDATA[agent]]></category>
		<category><![CDATA[authplay.dll]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[melwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[Popup Blocker]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=120</guid>
		<description><![CDATA[Downloader-CEW.q!D113​7DCFCEBA Trojan how to remove]]></description>
			<content:encoded><![CDATA[<p><strong><br />
</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">HEUR:Trojan.Win32.Generic</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Trojan.DownLoader1.60944</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/FakeAlert.IV.gen!Eldorado</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">TrojanDownloader:Win32/Renos.LX</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Kryptik.KDM trojan (variant)</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Obfuscated.M</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">Suspicious</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Mal/FakeAV-CX</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Trojan.Codecpack.Gen.13 (mutant)</td>
</tr>
<tr>
<td align="left">Vet (Computer Associates)</td>
<td align="right">Win32/Renos.D!generic</td>
</tr>
</tbody>
</table>
<p>1.<strong>Disable System Restore windows XP only, Win 7 will not work.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan using AGG or Microsoft security or Kaspersky</p>
<p>Modifications made to the system Registry  files for the purposes of hooking system startup will be removed if cleaning with the recommended engine and DAT combination.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/downloader-cew-qd113%e2%80%8b7dcfceba-trojan-how-to-remove.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Trojan.Zlob.P virus trojan</title>
		<link>http://www.softe.org/how-to-remove-trojan-zlob-p-virus-trojan.html</link>
		<comments>http://www.softe.org/how-to-remove-trojan-zlob-p-virus-trojan.html#comments</comments>
		<pubDate>Tue, 25 Jan 2011 00:06:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to remove Trojan.Zlob.P virus trojan]]></category>
		<category><![CDATA[definition]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[safemode]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=117</guid>
		<description><![CDATA[Temporarily Disable System Restore  then update the virus definitions on your virus program then Reboot computer in SafeMode, then delete the IE temp files some Trojan.Zlob.P]]></description>
			<content:encoded><![CDATA[<p>Temporarily Disable System Restore  then update the virus definitions on your virus program then Reboot computer in SafeMode, then delete the IE temp files some <strong>Trojan.Zlob.P </strong>temp file exisit in that folder as well, you can wither search for the temp files or manually delete them.<br />
You may now download <strong>Malwarebytes </strong>from <a href="http://www.malwarebytes.org/mbam-download.php" target="_blank"><span style="color: #0000ff;"><strong>Here</strong></span></a> or <a href="http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html" target="_blank"><span style="color: #0000ff;"><strong>Here</strong></span></a></p>
<p>Update the definition and scan your computer, it will find any traces of <strong>Trojan.Zlob.P</strong> now delete and you should be good to go.<strong> </strong></p>
<p><strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-trojan-zlob-p-virus-trojan.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove CoolWebSearch.olehelp Malware</title>
		<link>http://www.softe.org/how-to-remove-coolwebsearch-olehelp-malware.html</link>
		<comments>http://www.softe.org/how-to-remove-coolwebsearch-olehelp-malware.html#comments</comments>
		<pubDate>Wed, 08 Dec 2010 22:18:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to remove CoolWebSearch.olehelp Malware]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[infected]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malwarebytes]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=104</guid>
		<description><![CDATA[Is your PC infected with the CoolWebSearch.olehelp Malware? Let me help you remove this nasty browser hijacker.]]></description>
			<content:encoded><![CDATA[<p>Is your PC infected with the CoolWebSearch.olehelp Malware? Let me help you remove this nasty browser hijacker.</p>
<p><strong>CoolWebSearch</strong> or short for CWS is a pretty harsh hijacker which attacks firefox or chrome and even internet explorer browsers. One thing to take note is that if this threat is not stopped, it will keep growing like a nasty virus as its knowing coolwebsearch keeps coming up with a newer threat every week. This Malware goes adn alters your homepage on your browser and or might redirect your homepage or any other website y ou visit to another website that might contain a virus or malware. The good news is, its pretty easy to remove this virus.</p>
<p>To remove this nasty browser hijacker malware, simply download <strong>Malwarebytes </strong>Anti Malware by <a href="http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&amp;subj=dl&amp;tag=button" target="_blank">clicking here and save it to your desktop</a>. Run and install the free application. Now run Malwarebytes and make sure you update the program first before you scan your PC. Scan your PC now and it will remove CoolWebSearch.olehelp Malware and your PC will be save once again.</p>
<p><img class="alignnone" src="http://images.betanews.com/screenshots/1186760019-1.gif" alt="" width="551" height="424" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-coolwebsearch-olehelp-malware.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Microsoft Security Essentials Trojan Virus Manual Removal</title>
		<link>http://www.softe.org/fake-microsoft-security-essentials-trojan-virus-manual-removal.html</link>
		<comments>http://www.softe.org/fake-microsoft-security-essentials-trojan-virus-manual-removal.html#comments</comments>
		<pubDate>Tue, 16 Nov 2010 00:12:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Fake Microsoft Security Essentials Trojan Virus Manual Removal]]></category>
		<category><![CDATA[combfix]]></category>
		<category><![CDATA[fake]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=97</guid>
		<description><![CDATA[Although it is possible to manually remove the Fake Microsoft Security Essentials Alert Trojan  Virus, it can also damage your system if you are not familiar with how to use the registry, as advanced spyware are able to automatically repair themselves if not completely deleted.]]></description>
			<content:encoded><![CDATA[<p>Although it is possible to manually remove the <strong>Fake Microsoft Security Essentials Alert Trojan</strong> Virus, it can also damage your system if you are not familiar with how to use the registry, as advanced spyware are able to automatically repair themselves if not completely deleted. so in other words, manual spyware removal is recommended for experienced users only. For other users, we recommend using Malwarebytes or other malware spyware removal software such as <strong>Combofix</strong>.  Malwarebytes deletes and protects from malicious running trojan  files and registry entries for free.  Malwarebytes will help you to remove Fake Microsoft Security Essentials Alert Virus.</p>
<p><strong>Stop the Fake Microsoft Security Essentials Alert Trojan processes below by pressing CTRL + Alt + Delete:</strong></p>
<p>antispy.exe<br />
defender.exe<br />
tmp.exe<br />
hotfix.exe</p>
<p><strong>Remove these Fake Microsoft Security Essentials Alert Trojan Registry Entries:<br />
Click start menu and type &#8220;regedit&#8221;</strong></p>
<p>HKEY_CURRENT_USER\Software\PAV<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings &#8220;WarnonBadCertRecving&#8221; = &#8220;0?<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings &#8220;WarnOnPostRedirect&#8221; = &#8220;0?<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#8220;tmp&#8221;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce &#8220;SelfdelNT&#8221;<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon &#8220;Shell&#8221; = &#8220;%UserProfile%\Application Data\antispy.exe&#8221;<br />
<strong>Remove these Fake Microsoft Security Essentials Alert Trojan files:</strong><br />
%UserProfile%\Application Data\PAV\<br />
%UserProfile%\Application Data\antispy.exe<br />
%UserProfile%\Application Data\defender.exe<br />
%UserProfile%\Application Data\tmp.exe<br />
%UserProfile%\Application Data\hotfix.exe<br />
%UserProfile%\Local Settings\Temp\[random characters].bat</p>
<p>For Vista/7:<br />
%UserProfile%\AppData\Local\antispy.exe<br />
%UserProfile%\AppData\Local\defender.exe<br />
%UserProfile%\AppData\Local\tmp.exe<br />
%UserProfile%\AppData\Local\hotfix.exe</p>
<p>C:\END<br />
It is impossible to list all file names and locations of modern parasites. You can identify remaining parasites, other Fake Microsoft Security Essentials Alert Trojan infected files and get help in Fake Microsoft Security Essentials Alert Trojan removal by using free Malwarebytes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/fake-microsoft-security-essentials-trojan-virus-manual-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Trojan Horse Generic.17 16 15 14.DYJ</title>
		<link>http://www.softe.org/how-to-remove-trojan-horse-generic-17-16-15-14-dyj.html</link>
		<comments>http://www.softe.org/how-to-remove-trojan-horse-generic-17-16-15-14-dyj.html#comments</comments>
		<pubDate>Mon, 10 May 2010 18:17:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to remove Trojan Horse Generic]]></category>
		<category><![CDATA[generic]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=21</guid>
		<description><![CDATA[If you have gotten a virus in your PC called Trojan Horse Generic with a number next to it such as .17 or 16 or 15 or 14, this simply means you have downloaded an illegal software from a torrent.  The risk level of this virus is not that great but still needs to be removed asap.

Trojan horse Generic 14.DYJ is a detection for a trojan that applies a Rootkit technology to remain itself hidden from system so as to avoid being detected by antivirus application. Trojan horse Generic 14.DYJ can hook itself into Windows registry and create a backdoor to allow a remote attacker gain full access on victims computer.

Damage Level: Medium

Systems Affected: Windows XP, Vista, 7

To remove this virus, you will need to download Rkill

Downloads:
rkill.exe – Download from BleepingComputer.com – 257kb
rkill.com – Download from BleepingComputer.com – 257kb
rkill.scr – Download from BleepingComputer.com – 257kb
rkill.pif – Download from BleepingComputer.com – 257kb

After you have finished with Rkill, do not reboot your PC, make sure you also have MalwareBytes installed on your PC, you will need to run this next.

Click here to download MalwareBytes

Now run Malwarebytes and this should fix your virus. You may run quick scan, and make sure you update malwarebytes before you scan and clean. Good luck
]]></description>
			<content:encoded><![CDATA[<p>If you have gotten a virus in your PC called Trojan Horse Generic with a number next to it such as .17 or 16 or 15 or 14, this simply means you have downloaded an illegal software from a torrent.  The risk level of this virus is not that great but still needs to be removed asap.</p>
<div>
<p>Trojan horse Generic 14.DYJ is a detection for a trojan that applies  a Rootkit technology to remain itself hidden from system so as to avoid  being detected by antivirus application. Trojan horse Generic 14.DYJ  can hook itself into Windows registry and create a backdoor to allow a  remote attacker gain full access on victims computer.</p>
<p><strong>Damage Level:</strong> Medium</p>
<p><strong>Systems Affected:</strong> Windows XP, Vista, 7</p>
<p>To remove this virus, you will need to download Rkill</p>
<p><strong>Downloads:</strong><br />
<a href="http://download.bleepingcomputer.com/grinler/rkill.scr" target="_blank">Download from BleepingComputer.com – 257kb</a></p>
<p>After you have finished with Rkill, do not reboot your PC, make sure you also have <strong>MalwareBytes</strong> installed on your PC, you will need to run this next.</p>
<p><strong><a href="http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&amp;subj=dl&amp;tag=button" target="_blank">Click here to download MalwareBytes</a></strong></p>
<p>Now run Malwarebytes and this should fix your virus. You may run quick scan, and make sure you update malwarebytes before you scan and clean. Good luck<strong><br />
</strong></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-trojan-horse-generic-17-16-15-14-dyj.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

