<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Free Spyware Adware Worm and Virus Trojan Horse Download Removal Tools &#187; threat</title>
	<atom:link href="http://www.softe.org/tag/threat/feed" rel="self" type="application/rss+xml" />
	<link>http://www.softe.org</link>
	<description>FREE Computer Repair</description>
	<lastBuildDate>Sun, 04 Dec 2011 21:36:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Virus Profile: Fake Alert Security Tool.bt!4611C</title>
		<link>http://www.softe.org/virus-profile-fake-alert-security-tool-bt4611c.html</link>
		<comments>http://www.softe.org/virus-profile-fake-alert-security-tool-bt4611c.html#comments</comments>
		<pubDate>Mon, 20 Jun 2011 18:47:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Profile: Fake Alert Security Tool.bt!4611C]]></category>
		<category><![CDATA[fake alert]]></category>
		<category><![CDATA[security tool]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=143</guid>
		<description><![CDATA[This is a Trojan that will infect your PC, be cautious, it enumerates many system files and directories. McAfee Detection FakeAlert-SecurityTool.bt System Changes Some path values have been replaced with environment variables as the exact location may vary with different configurations. e.g. %WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000) %PROGRAMFILES% = \Program Files The [...]]]></description>
			<content:encoded><![CDATA[<p>This is a Trojan that will infect your PC, be cautious, it enumerates many system files and directories.</p>
<p>McAfee Detection	FakeAlert-SecurityTool.bt</p>
<p><strong>System Changes</strong><br />
Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</p>
<p><strong>The following registry elements have been created:</strong><br />
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\</p>
<p><strong>The following registry elements have been changed:</strong><br />
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\{92780B25-18CC-41C8-B9BE-3C9C571A8263} = 8193<br />
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\NEXTID = 8194<br />
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\PO28273LJGGI28273 = %ALLUSERSPROFILE%\Application Data\pO28273LjGgI28273\pO28273LjGgI28273.exe</p>
<p><strong>How to remove this Virus threat</strong></p>
<p>1.Disable System Restore on Windows ME and windows XP only.<br />
2.Update to current engine and DAT files for detection and removal.<br />
3.Run a complete system scan.</p>
<p>This should remove the threat, this threat is a low security threat but never the less it should always be cleaned before using the world wide web.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/virus-profile-fake-alert-security-tool-bt4611c.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Profile: BackDoor-CEP.gen how to clean</title>
		<link>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html</link>
		<comments>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html#comments</comments>
		<pubDate>Fri, 20 May 2011 06:16:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Profile: BackDoor-CEP.gen how to clean]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=140</guid>
		<description><![CDATA[Virus Profile: BackDoor-CEP.gen.cq!CF151229CE1E avast Win32:Caxnet [Trj] AVG (GriSoft) Rootkit-Pakes.BG (Trojan horse) avira TR/Koutodoor.psa Kaspersky HEUR:Trojan.Win32.Generic BitDefender Gen:Variant.Koutodoor.18 clamav Trojan.Dropper-27717 Dr.Web Trojan.MulDrop.origin F-Prot W32/Koutodoor.N.gen!Eldorado FortiNet W32/Koutodoor.KWD!tr.bdr Microsoft Trojan:Win32/Koutodoor.E Symantec Trojan.Koutodoor Eset Win32/Koutodoor.HM trojan (variant) norman W32/Suspicious_Gen2.LZIQS (trojan) panda Trj/Genetic.gen rising Trojan.Win32.Generic.1282E422 Sophos Troj/Kouto-D Trend Micro TROJ_DLOADR.SMOM vba32 Trojan.Downloader.gen.h (suspected) The following files have been added to [...]]]></description>
			<content:encoded><![CDATA[<p>Virus Profile: BackDoor-CEP.gen.cq!CF151229CE1E</p>
<p>avast	Win32:Caxnet [Trj]<br />
AVG (GriSoft)	Rootkit-Pakes.BG (Trojan horse)<br />
avira	TR/Koutodoor.psa<br />
Kaspersky	HEUR:Trojan.Win32.Generic<br />
BitDefender	Gen:Variant.Koutodoor.18<br />
clamav	Trojan.Dropper-27717<br />
Dr.Web	Trojan.MulDrop.origin<br />
F-Prot	W32/Koutodoor.N.gen!Eldorado<br />
FortiNet	W32/Koutodoor.KWD!tr.bdr<br />
Microsoft	Trojan:Win32/Koutodoor.E<br />
Symantec	Trojan.Koutodoor<br />
Eset	Win32/Koutodoor.HM trojan (variant)<br />
norman	W32/Suspicious_Gen2.LZIQS (trojan)<br />
panda	Trj/Genetic.gen<br />
rising	Trojan.Win32.Generic.1282E422<br />
Sophos	Troj/Kouto-D<br />
Trend Micro	TROJ_DLOADR.SMOM<br />
vba32	Trojan.Downloader.gen.h (suspected)</p>
<p>The following files have been added to the system:<br />
%WINDIR%\SYSTEM32\szccw.dll<br />
%TEMP%\nsd12.tmp<br />
%PROGRAMFILES%\Microsoft\ie13\Internat Explorer\target.lnk<br />
%ALLUSERSPROFILE%\Desktop\Internat Explorer.jgp<br />
%WINDIR%\SYSTEM32\drivers\fmsde.sys<br />
%PROGRAMFILES%\Microsoft\ie13\Internat Explorer\Desktop.ini<br />
	The following files were temporarily written to disk then later removed:<br />
%TEMP%\hmufctw.bat<br />
%TEMP%\nsq13.tmp<br />
%TEMP%\ygnpyvce.bat<br />
%TEMP%\nsi11.tmp<br />
%WINDIR%\SYSTEM32\mhzscp.bat<br />
%TEMP%\faxjdr.exe<br />
%TEMP%\tmp.bat<br />
%TEMP%\yxcdiz.exe<br />
%TEMP%\nsq13.tmp\System.dll<br />
%TEMP%\wcyolgo.bat<br />
%TEMP%\ftrnkqxw.bat</p>
<p>This is a Trojan detection Unlike viruses Trojans do not self replicate they are spread manually under the premise that they are beneficial. The most common installation methods involve system security exploitation unsuspecting users manually executing unknown programs. Distribution channels include email malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks and what have  you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic Trojan BackDoor!cyh!E437DACF​F88B Virus Threat Removal</title>
		<link>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html</link>
		<comments>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html#comments</comments>
		<pubDate>Wed, 09 Mar 2011 05:22:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic BackDoor!cyh!E437DACF​F88B Virus Threat Removal]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[generic]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=128</guid>
		<description><![CDATA[Download Malwarebytes' Anti-Malware if you do now have this free software, from  here and save it to your computer.]]></description>
			<content:encoded><![CDATA[<p><strong>ystem Changes</strong></p>
<p>Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</p>
<p><strong>The following registry elements have been created:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\29AEB4A0365755F6-B862CAE984EA4D0E\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\29AEB4A0365755F6-B862CAE984EA4D0E\02F01F553A112DCE-00C9DB38C18D5FD1\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMADEVELOPERS\</li>
</ul>
<p><strong>The following files have been added to the system:</strong></p>
<p>* %WINDIR%\SYSTEM32\svhest.dll</p>
<p>* %WINDIR%\SYSTEM32\svhest.exe</p>
<p>To remove <strong>Generic Trojan BackDoor!cyh!E437DACF​F88B Virus</strong></p>
<p>Download Malwarebytes&#8217; Anti-Malware if you do now have this free software, from  <a href="http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html" target="_blank"><strong><span style="color: red;">here</span></strong></a> and save it to your computer.</p>
<ul>
<li>Double click <strong>mbam-setup.exe</strong> and install</li>
<li>At the end of the installation be sure a checkmark
<ul>
<li><strong>Update Malwarebytes&#8217; Anti-Malware</strong></li>
<li>and <strong>Launch Malwarebytes&#8217; Anti-Malware</strong></li>
<li><strong>do a full scan and allow your computer to fix your virus.<br />
</strong></li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.SillyFDC.BDO worm clean with Webroot Spy Sweeper</title>
		<link>http://www.softe.org/w32-sillyfdc-bdo-worm-clean-with-webroot-spy-sweeper.html</link>
		<comments>http://www.softe.org/w32-sillyfdc-bdo-worm-clean-with-webroot-spy-sweeper.html#comments</comments>
		<pubDate>Wed, 01 Dec 2010 07:28:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32.SillyFDC.BDO worm clean with Webroot Spy Sweeper]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[spy sweeper]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[webroot]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=101</guid>
		<description><![CDATA[I was able to capture this W32.SillyFDC.BDO worm on my test machine and run a few tests to see which software did the best cleaning and its safe to say Spy Sweeper by Webroot was the winner. ]]></description>
			<content:encoded><![CDATA[<p>W32.SillyFDC.BDO is a new discovered worm that spreads by copying itself to removable drives such as external hard drivers, USB flash drivers, etc.</p>
<p>I was able to capture this <strong>W32.SillyFDC.BDO worm</strong> on my test machine and run a few tests to see which software did the best cleaning and its safe to say<strong> Spy Sweeper</strong> by <strong>Webroot </strong>was the winner.<br />
Webroot AntiVirus 2010 with Spy  Sweeper is one of the best apps that will  protect your PC from virus threats,  spyware, adware, worms and Trojans malware. One great thing i found about spy sweeper is that it protects your PC real time without bottle necking or slowing down your net speed or even your PC&#8217;s resources. Unlike Norton which really takes away a good portion of your memory and hogs your system resources.</p>
<p><strong>W32.SillyFDC.BDO worm</strong><br />
When executed this worm copies itself as the following files:</p>
<ul>
<li>%SystemDrive%\services.exe</li>
<li>%Windir%\services.exe</li>
</ul>
<p>It then creates the following registry entry so that it runs every time Windows starts:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;ServiceControlApp&#8221; = &#8220;%SystemDrive%\services.exe&#8221;</p>
<p>The worm also modifies the following registry entries:</p>
<ul>
<li>HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;ShowSuperHidden&#8221; = &#8220;0&#8243;</li>
<li>HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;HideFileExt&#8221; = &#8220;1&#8243;</li>
</ul>
<p><strong>To clean this threat, simply run Webroot Spy Sweeper</strong></p>
<p>Clean this threat manually:</p>
<ol>
<li>Disable System Restore (Windows Me/XP).</li>
<li>Update the virus definitions.</li>
<li>Run a full system scan.</li>
<li>Delete any values added to the registry.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32-sillyfdc-bdo-worm-clean-with-webroot-spy-sweeper.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Palevo.B Worm instant messaging clients</title>
		<link>http://www.softe.org/w32-palevo-b-worm-instant-messaging-clients.html</link>
		<comments>http://www.softe.org/w32-palevo-b-worm-instant-messaging-clients.html#comments</comments>
		<pubDate>Wed, 05 May 2010 09:31:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32.Palevo.B Worm]]></category>
		<category><![CDATA[messaging]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=6</guid>
		<description><![CDATA[Discovered: May 4, 2010
Updated: May 4, 2010 11:27:56 AM
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP

W32.Palevo.B is a worm that spreads through instant messaging clients.
Antivirus Protection Dates

    * Initial Rapid Release version May 4, 2010 revision 009
    * Latest Rapid Release version May 4, 2010 revision 020
    * Initial Daily Certified version May 4, 2010 revision 048
    * Latest Daily Certified version May 4, 2010 revision 048
    * Initial Weekly Certified release date May 5, 2010

Threat Assessment
Wild

    * Wild Level: Low
    * Number of Infections: 0 - 49
    * Number of Sites: 0 - 2
    * Geographical Distribution: Low
    * Threat Containment: Easy
    * Removal: Easy

Damage

    * Damage Level: Low
    * Payload: Spreads through instant messaging programs.

Distribution

    * Distribution Level: Medium

]]></description>
			<content:encoded><![CDATA[<div id="tabModBdy">
<div><strong>Discovered: </strong>May 4, 2010</div>
<div><strong>Updated: </strong>May 4, 2010 11:27:56 AM</div>
<div><strong>Type: </strong>Worm</div>
<div><strong>Systems Affected: </strong>Windows 2000, Windows 95, Windows 98,  Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP</div>
<p>W32.Palevo.B is a worm that spreads through instant messaging  clients.</p>
<h3>Antivirus Protection Dates</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>May 4, 2010 revision 009</li>
<li> <strong>Latest Rapid Release version </strong>May 4, 2010 revision 020</li>
<li> <strong>Initial Daily Certified version </strong>May 4, 2010 revision  048</li>
<li> <strong>Latest Daily Certified version </strong>May 4, 2010 revision 048</li>
<li> <strong>Initial Weekly Certified release date </strong>May 5, 2010</li>
</ul>
<h3>Threat Assessment</h3>
<h4>Wild</h4>
<ul>
<li> <strong>Wild Level: </strong>Low</li>
<li> <strong>Number of Infections: </strong>0 &#8211; 49</li>
<li> <strong>Number of Sites: </strong>0 &#8211; 2</li>
<li> <strong>Geographical Distribution: </strong>Low</li>
<li> <strong>Threat Containment: </strong>Easy</li>
<li> <strong>Removal: </strong>Easy</li>
</ul>
<h4>Damage</h4>
<ul>
<li> <strong>Damage Level: </strong>Low</li>
<li> <strong>Payload: </strong>Spreads through instant messaging programs.</li>
</ul>
<h4>Distribution</h4>
<ul>
<li> <strong>Distribution Level: </strong>Medium</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32-palevo-b-worm-instant-messaging-clients.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

