<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Free Spyware Adware Worm and Virus Trojan Horse Download Removal Tools &#187; Virus</title>
	<atom:link href="http://www.softe.org/tag/virus/feed" rel="self" type="application/rss+xml" />
	<link>http://www.softe.org</link>
	<description>FREE Computer Repair</description>
	<lastBuildDate>Sun, 04 Dec 2011 21:36:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PeakProtection2010  Adware Windows 2003/XP/2000/NT/ME/98/95</title>
		<link>http://www.softe.org/peakprotection2010-adware-windows-2003xp2000ntme9895.html</link>
		<comments>http://www.softe.org/peakprotection2010-adware-windows-2003xp2000ntme9895.html#comments</comments>
		<pubDate>Sun, 04 Dec 2011 21:35:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PeakProtection2010 Adware Windows 2003/XP/2000/NT/ME/98/95]]></category>
		<category><![CDATA[adaware]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[banner]]></category>
		<category><![CDATA[melwarebytes]]></category>
		<category><![CDATA[popup]]></category>
		<category><![CDATA[spybot]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=171</guid>
		<description><![CDATA[Brief Description PeakProtection2010is spyware and adware program which lets the end PC users know of the latest spyware and virus threats in their PC&#8217; computers, much like spybot, AVG, melwarebytes and so on.PeakProtection2010 can reach the computer when the user accesses certain websites which can display banner ads and pop ups and what have you [...]]]></description>
			<content:encoded><![CDATA[<table id="table_DescripcionBreve">
<tbody>
<tr>
<td>
<h2>Brief Description<a name="BREVE"></a></h2>
</td>
<td align="right" width="1%"></td>
</tr>
<tr>
<td colspan="2"><a id="BREVE" name="BREVE"></a><em>PeakProtection2010</em>is spyware and adware program which lets the end PC users know of the latest spyware and virus threats in their PC&#8217; computers, much like spybot, AVG, melwarebytes and so on.<em>PeakProtection2010</em> can reach the computer when the user accesses certain websites which can display banner ads and pop ups and what have you which can lead to the download of this program. It can also be reached via email spam, email link and so forth.</td>
</tr>
</tbody>
</table>
<table id="table_SintomasVisibles">
<tbody>
<tr>
<td>
<h2>Visible Symptoms<a name="VISIBLES"></a></h2>
</td>
<td align="right" width="1%"></td>
</tr>
<tr>
<td colspan="2"><a id="VISIBLES" name="VISIBLES"></a><em>PeakProtection2010</em>is pretty simple to recognize.</p>
<ul>
<li>When the app runs in windows, it will display the installer like the one below.<img src="http://www.pandasecurity.com/img/enc/AdwarePeakProtection2010_img1.jpg" alt="PeakProtection2010 installation window" border="0" /></li>
<li>Once installed, the computer is restarted and the following screen is displayed where only one option can be selected:<img src="http://www.pandasecurity.com/img/enc/AdwarePeakProtection2010_img2.jpg" alt="Screen displayed by PeakProtection2010" border="0" /></li>
<li>When users click on this button, it stats scanning the system and once ended, it shows the results with the infected and restored files:<img src="http://www.pandasecurity.com/img/enc/AdwarePeakProtection2010_img3.jpg" alt="Results of the scan carried out by PeakProtection2010" border="0" /></li>
</ul>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/peakprotection2010-adware-windows-2003xp2000ntme9895.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BackDoor-EVC!8F7F8F47​013F Network Trojan and how to remove</title>
		<link>http://www.softe.org/backdoor-evc8f7f8f47%e2%80%8b013f-network-trojan-and-how-to-remove.html</link>
		<comments>http://www.softe.org/backdoor-evc8f7f8f47%e2%80%8b013f-network-trojan-and-how-to-remove.html#comments</comments>
		<pubDate>Fri, 30 Sep 2011 04:39:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[BackDoor-EVC!8F7F8F47​013F Network Trojan and how to remove]]></category>
		<category><![CDATA[back door]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[network virus]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=166</guid>
		<description><![CDATA[This backdoor Trojan  infects  files, registry, and network communication. The following registry elements have been created: HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\ HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\ HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\ HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\ HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\INPROCSERVER32\ HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\ This virus can be removed with microsoft security essentials. If your PC gets locked you are getting a black screen, you might want to run scan in safe mode. Other names to reffer [...]]]></description>
			<content:encoded><![CDATA[<p>This <strong>backdoor Trojan</strong>  infects  files, registry, and network communication.</p>
<p><strong>The following registry elements have been created:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\INPROCSERVER32\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{BF50AC63-19DA-487E-AD4A-0B452D823B59}\</li>
</ul>
<div>This virus can be removed with <strong>microsoft security essentials</strong>. If your PC gets locked you are getting a black screen, you might want to run scan in safe mode.</div>
<div>Other names to reffer to.</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/backdoor-evc8f7f8f47%e2%80%8b013f-network-trojan-and-how-to-remove.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 7 black screen ram shortage infection % of my ram wasn&#8217;t functioning properly</title>
		<link>http://www.softe.org/windows-7-black-screen-ram-shortage-infection-of-my-ram-wasnt-functioning-properly.html</link>
		<comments>http://www.softe.org/windows-7-black-screen-ram-shortage-infection-of-my-ram-wasnt-functioning-properly.html#comments</comments>
		<pubDate>Fri, 30 Sep 2011 04:29:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Windows 7 black screen ram shortage infection % of my ram wasn't functioning properly]]></category>
		<category><![CDATA[infection]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[ram]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=164</guid>
		<description><![CDATA[If your windows 7 screen turns black and you get an error stating something along the lines of ram shortage infection or a given % value was not functioning properly, here is what you do: download unhide.exe and TDssKiller Run  TDSSKiller and it will locate your infection. It will ask you to remoev the infection [...]]]></description>
			<content:encoded><![CDATA[<p>If your windows 7 screen turns black and you get an error stating something along the lines of ram shortage infection or a given % value was not functioning properly, here is what you do:</p>
<p><span style="color: #000000;"><strong>download </strong><a href="http://download.bleepingcomputer.com/grinler/unhide.exe" target="_blank">unhide.exe</a> and <a href="http://support.kaspersky.com/downloads/utils/tdsskiller.exe" target="_blank">TDssKiller</a></span><br />
Run  TDSSKiller and it will locate your infection. It will ask you to remoev the infection ans simply say yes.  IF all goes well and your PC is clean, it will ask to reboot your windows 7. Please do so.</p>
<p>It will most likely find: <strong>TrojanDownloader.OpenStream.NBF trojan</strong></p>
<p>If this does not work for you, download the latest <strong>malwarebytes</strong> and update and scan.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/windows-7-black-screen-ram-shortage-infection-of-my-ram-wasnt-functioning-properly.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan.win32.Generic.pak!cobra.Engine</title>
		<link>http://www.softe.org/trojan-win32-generic-pakcobra-engine.html</link>
		<comments>http://www.softe.org/trojan-win32-generic-pakcobra-engine.html#comments</comments>
		<pubDate>Mon, 27 Jun 2011 19:22:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan.win32.Generic.pak!cobra.Engine]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[spybot]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[win32]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=149</guid>
		<description><![CDATA[This virus might be a google redirect trojan and it is not easy to clean, however, these are the first steps to take in trying to delete this nasty win32 virus. go to start menu, then run, now type in MSCONFIG, go to startup tab and look for a long string of command that has [...]]]></description>
			<content:encoded><![CDATA[<p>This virus might be a google redirect trojan and it is not easy to clean, however, these are the first steps to take in trying to delete this nasty win32 virus.</p>
<p>go to start menu, then run, now type in MSCONFIG, go to startup tab and look for a long string of command that has random letters and sometimes numbers, disable that line and save.</p>
<p><a href="http://www.softe.org/download"><strong>Download Malwarebytes</strong></a>, update malwarebytes then do a full system scan. if any virus is found, it will delete it.</p>
<p>Now <a href="http://www.softe.org/download"><strong>download spybot</strong></a>, do an update and a full scan, delete any melware or spyware it finds.</p>
<p>You surly must have a virus protection software, if not, download <a href="http://www.softe.org/download"><strong>Microsoft Security Essentials</strong></a>, its free, update the app then a full scan.</p>
<p>These steps above should fix and delete the <strong>Trojan.win32.Generic.pak!cobra.Engine virus</strong></p>
<p>Here are other virus trojans that are smiler to the one above and can be cleaned the same way.</p>
<p><a href="http://www.softe.org/wp-content/uploads/2011/06/computer-virus.jpg"><img class="alignleft size-full wp-image-152" title="computer virus" src="http://www.softe.org/wp-content/uploads/2011/06/computer-virus.jpg" alt="" width="380" height="253" /></a></p>
<p>Trojan.Win32.Generic!BT: Trojan<br />
Trojan-Spy.Win32.Zbot.gen: Trojan<br />
Exploit.PDF-JS.Gen (v): Exploit<br />
Trojan.Win32.Generic!SB.0: Trojan<br />
INF.Autorun (v): Trojan<br />
Trojan.Win32.Hiloti.gen.d (v): Trojan<br />
Trojan.Win32.Generic.pak!cobra: Trojan<br />
Trojan.Win32.Adware: Adware (General)<br />
MyWebSearch Toolbar: Potentially Unwanted Program<br />
Trojan.Win32.Malware: Trojan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/trojan-win32-generic-pakcobra-engine.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus PWS-Zbot.gen.gi!E69284FFC72E</title>
		<link>http://www.softe.org/virus-pws-zbot-gen-gie69284ffc72e.html</link>
		<comments>http://www.softe.org/virus-pws-zbot-gen-gie69284ffc72e.html#comments</comments>
		<pubDate>Mon, 20 Jun 2011 19:02:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus PWS-Zbot.gen.gi!E69284FFC72E]]></category>
		<category><![CDATA[how to clean virus]]></category>
		<category><![CDATA[me]]></category>
		<category><![CDATA[system restore]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=145</guid>
		<description><![CDATA[Other Company Detection Aliases Company Names Detection Names AVG (GriSoft) Generic23.CWM avira TR/FakeSysdef.A.1499 Kaspersky HEUR:Trojan.Win32.Generic BitDefender Gen:Variant.Kazy.26475 FortiNet W32/Krap.AON!tr Symantec Trojan.Fakeav Eset Win32/Kryptik.OYP Sophos Mal/FakeAV-IK Attempts to connect to a high risk domain that may pose a security risk.  It also creates one or more shortcuts .LNK files to provide user accessible links to start [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Other Company Detection Aliases</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Generic23.CWM</td>
</tr>
<tr>
<td align="left">avira</td>
<td align="right">TR/FakeSysdef.A.1499</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">HEUR:Trojan.Win32.Generic</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Gen:Variant.Kazy.26475</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/Krap.AON!tr</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">Trojan.Fakeav</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Kryptik.OYP</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Mal/FakeAV-IK</td>
</tr>
</tbody>
</table>
<p>Attempts to connect to a high risk domain that may pose a security risk.  It also creates one or more shortcuts .LNK files to provide user accessible links to start a program usually form the desktop or start menu.</p>
<table>
<tbody>
<tr>
<td><strong>The following registry elements have been changed:</strong></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\USE FORMSUGGEST = Yes</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\CERTIFICATEREVOCATION = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\WARNONBADCERTRECVING = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\WARNONZONECROSSING = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\ZONES\3\1601 = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\WINTRUST\TRUST PROVIDERS\SOFTWARE PUBLISHING\STATE = 146944</li>
</ul>
<table>
<tbody>
<tr>
<td><strong>The applications attempted the following network connection(s):</strong></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<ul>
<li>188.229.88.***:80</li>
</ul>
<ul>
<li>46.161.11.***:80</li>
</ul>
<ul>
<li>hxxp://searcham.org/*****</li>
</ul>
<p>&nbsp;</p>
<p>To remove this virus,</p>
<p>1.<strong>Disable System Restore Windows ME XP only</strong><strong>.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan.</p>
<p>Modifications made to the system Registry and  INI files for the purposes of hooking system startup, will be removed if cleaning with the recommended engine and DAT combination or higher.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/virus-pws-zbot-gen-gie69284ffc72e.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Profile: BackDoor-CEP.gen how to clean</title>
		<link>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html</link>
		<comments>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html#comments</comments>
		<pubDate>Fri, 20 May 2011 06:16:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Profile: BackDoor-CEP.gen how to clean]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=140</guid>
		<description><![CDATA[Virus Profile: BackDoor-CEP.gen.cq!CF151229CE1E avast Win32:Caxnet [Trj] AVG (GriSoft) Rootkit-Pakes.BG (Trojan horse) avira TR/Koutodoor.psa Kaspersky HEUR:Trojan.Win32.Generic BitDefender Gen:Variant.Koutodoor.18 clamav Trojan.Dropper-27717 Dr.Web Trojan.MulDrop.origin F-Prot W32/Koutodoor.N.gen!Eldorado FortiNet W32/Koutodoor.KWD!tr.bdr Microsoft Trojan:Win32/Koutodoor.E Symantec Trojan.Koutodoor Eset Win32/Koutodoor.HM trojan (variant) norman W32/Suspicious_Gen2.LZIQS (trojan) panda Trj/Genetic.gen rising Trojan.Win32.Generic.1282E422 Sophos Troj/Kouto-D Trend Micro TROJ_DLOADR.SMOM vba32 Trojan.Downloader.gen.h (suspected) The following files have been added to [...]]]></description>
			<content:encoded><![CDATA[<p>Virus Profile: BackDoor-CEP.gen.cq!CF151229CE1E</p>
<p>avast	Win32:Caxnet [Trj]<br />
AVG (GriSoft)	Rootkit-Pakes.BG (Trojan horse)<br />
avira	TR/Koutodoor.psa<br />
Kaspersky	HEUR:Trojan.Win32.Generic<br />
BitDefender	Gen:Variant.Koutodoor.18<br />
clamav	Trojan.Dropper-27717<br />
Dr.Web	Trojan.MulDrop.origin<br />
F-Prot	W32/Koutodoor.N.gen!Eldorado<br />
FortiNet	W32/Koutodoor.KWD!tr.bdr<br />
Microsoft	Trojan:Win32/Koutodoor.E<br />
Symantec	Trojan.Koutodoor<br />
Eset	Win32/Koutodoor.HM trojan (variant)<br />
norman	W32/Suspicious_Gen2.LZIQS (trojan)<br />
panda	Trj/Genetic.gen<br />
rising	Trojan.Win32.Generic.1282E422<br />
Sophos	Troj/Kouto-D<br />
Trend Micro	TROJ_DLOADR.SMOM<br />
vba32	Trojan.Downloader.gen.h (suspected)</p>
<p>The following files have been added to the system:<br />
%WINDIR%\SYSTEM32\szccw.dll<br />
%TEMP%\nsd12.tmp<br />
%PROGRAMFILES%\Microsoft\ie13\Internat Explorer\target.lnk<br />
%ALLUSERSPROFILE%\Desktop\Internat Explorer.jgp<br />
%WINDIR%\SYSTEM32\drivers\fmsde.sys<br />
%PROGRAMFILES%\Microsoft\ie13\Internat Explorer\Desktop.ini<br />
	The following files were temporarily written to disk then later removed:<br />
%TEMP%\hmufctw.bat<br />
%TEMP%\nsq13.tmp<br />
%TEMP%\ygnpyvce.bat<br />
%TEMP%\nsi11.tmp<br />
%WINDIR%\SYSTEM32\mhzscp.bat<br />
%TEMP%\faxjdr.exe<br />
%TEMP%\tmp.bat<br />
%TEMP%\yxcdiz.exe<br />
%TEMP%\nsq13.tmp\System.dll<br />
%TEMP%\wcyolgo.bat<br />
%TEMP%\ftrnkqxw.bat</p>
<p>This is a Trojan detection Unlike viruses Trojans do not self replicate they are spread manually under the premise that they are beneficial. The most common installation methods involve system security exploitation unsuspecting users manually executing unknown programs. Distribution channels include email malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks and what have  you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/virus-profile-backdoor-cep-gen-how-to-clean.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic Trojan BackDoor!cyh!E437DACF​F88B Virus Threat Removal</title>
		<link>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html</link>
		<comments>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html#comments</comments>
		<pubDate>Wed, 09 Mar 2011 05:22:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic BackDoor!cyh!E437DACF​F88B Virus Threat Removal]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[generic]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=128</guid>
		<description><![CDATA[Download Malwarebytes' Anti-Malware if you do now have this free software, from  here and save it to your computer.]]></description>
			<content:encoded><![CDATA[<p><strong>ystem Changes</strong></p>
<p>Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</p>
<p><strong>The following registry elements have been created:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\29AEB4A0365755F6-B862CAE984EA4D0E\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMA PROTECTOR\29AEB4A0365755F6-B862CAE984EA4D0E\02F01F553A112DCE-00C9DB38C18D5FD1\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\ENIGMADEVELOPERS\</li>
</ul>
<p><strong>The following files have been added to the system:</strong></p>
<p>* %WINDIR%\SYSTEM32\svhest.dll</p>
<p>* %WINDIR%\SYSTEM32\svhest.exe</p>
<p>To remove <strong>Generic Trojan BackDoor!cyh!E437DACF​F88B Virus</strong></p>
<p>Download Malwarebytes&#8217; Anti-Malware if you do now have this free software, from  <a href="http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html" target="_blank"><strong><span style="color: red;">here</span></strong></a> and save it to your computer.</p>
<ul>
<li>Double click <strong>mbam-setup.exe</strong> and install</li>
<li>At the end of the installation be sure a checkmark
<ul>
<li><strong>Update Malwarebytes&#8217; Anti-Malware</strong></li>
<li>and <strong>Launch Malwarebytes&#8217; Anti-Malware</strong></li>
<li><strong>do a full scan and allow your computer to fix your virus.<br />
</strong></li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/generic-trojan-backdoorcyhe437dacf%e2%80%8bf88b-virus-threat-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32/Olmarik trojan virus removal</title>
		<link>http://www.softe.org/win32olmarik-trojan-virus-removal.html</link>
		<comments>http://www.softe.org/win32olmarik-trojan-virus-removal.html#comments</comments>
		<pubDate>Thu, 24 Feb 2011 22:34:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Win32/Olmarik trojan virus removal]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=125</guid>
		<description><![CDATA[To clean this nasty Win32/Olmariktrojan horse virus,

Open RootRepeal, click the Drivers tab and select Scan. Right click and select Wipe File on:]]></description>
			<content:encoded><![CDATA[<p>To clean this nasty Win32/Olmariktrojan horse virus,</p>
<p>Open <strong><span style="color: green;">RootRepeal</span></strong>, click the <strong>Drivers</strong> tab and select <strong>Scan</strong>.  Right click and select <strong>Wipe File</strong> on:</p>
<p><strong>H8SRTmeyqxwbpxd.sys</strong></p>
<p>Click the <strong>Files</strong> tab and select <strong>Scan</strong>.  Right click and select <strong>Wipe File</strong> on any file that begins with the following:</p>
<p><strong>H8SRT</strong></p>
<p>Do the same for the Hidden Services tab.</p>
<p><strong><span style="color: red;">Reboot your machine</span></strong></p>
<p>Then let&#8217;s run RootRepeal again:</p>
<ul>
<li>Double click <strong>ROOTREPEAL </strong>to start the program</li>
<li>Click on the <strong>Report</strong> tab at the bottom of the program window</li>
<li>Click the <strong>SCAN </strong>button</li>
<li>In the <strong>Select Scan</strong> dialog, check:
<ul><span style="color: green;"></p>
<li><strong>Drivers</strong></li>
<li><strong>Files</strong></li>
<li><strong>Processes</strong></li>
<li><strong>SSDT</strong></li>
<li><strong>Stealth Objects</strong></li>
<li><strong>Hidden Services</strong></li>
<li><strong>Shadow SSDT</strong></li>
<p></span></ul>
</li>
<li>Click the <strong>OK</strong> button</li>
<li>In the next dialog, select <strong>all drives</strong> showing</li>
<li>Click <strong>OK</strong> to start the scan<br />
<blockquote><p><em>Note: The scan can take some time. <strong><span style="color: red;">DO NOT</span></strong> run any other programs while the scan is running</em></p></blockquote>
</li>
<li>When the scan is complete, click the<strong> SAVE REPORT</strong> button and save the report to your Desktop as <strong>RootRepeal.txt</strong></li>
<li>Go to <strong>File</strong>, then <strong>Exit</strong> to close the program</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/win32olmarik-trojan-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Downloader-CEW.q!D113​7DCFCEBA Trojan how to remove</title>
		<link>http://www.softe.org/downloader-cew-qd113%e2%80%8b7dcfceba-trojan-how-to-remove.html</link>
		<comments>http://www.softe.org/downloader-cew-qd113%e2%80%8b7dcfceba-trojan-how-to-remove.html#comments</comments>
		<pubDate>Wed, 02 Feb 2011 21:36:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Downloader-CEW.q!D113​7DCFCEBA Trojan]]></category>
		<category><![CDATA[Adobe Flash Player]]></category>
		<category><![CDATA[agent]]></category>
		<category><![CDATA[authplay.dll]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[melwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[Popup Blocker]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=120</guid>
		<description><![CDATA[Downloader-CEW.q!D113​7DCFCEBA Trojan how to remove]]></description>
			<content:encoded><![CDATA[<p><strong><br />
</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">HEUR:Trojan.Win32.Generic</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Trojan.DownLoader1.60944</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/FakeAlert.IV.gen!Eldorado</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">TrojanDownloader:Win32/Renos.LX</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Kryptik.KDM trojan (variant)</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Obfuscated.M</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">Suspicious</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Mal/FakeAV-CX</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Trojan.Codecpack.Gen.13 (mutant)</td>
</tr>
<tr>
<td align="left">Vet (Computer Associates)</td>
<td align="right">Win32/Renos.D!generic</td>
</tr>
</tbody>
</table>
<p>1.<strong>Disable System Restore windows XP only, Win 7 will not work.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan using AGG or Microsoft security or Kaspersky</p>
<p>Modifications made to the system Registry  files for the purposes of hooking system startup will be removed if cleaning with the recommended engine and DAT combination.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/downloader-cew-qd113%e2%80%8b7dcfceba-trojan-how-to-remove.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Trojan.Zlob.P virus trojan</title>
		<link>http://www.softe.org/how-to-remove-trojan-zlob-p-virus-trojan.html</link>
		<comments>http://www.softe.org/how-to-remove-trojan-zlob-p-virus-trojan.html#comments</comments>
		<pubDate>Tue, 25 Jan 2011 00:06:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to remove Trojan.Zlob.P virus trojan]]></category>
		<category><![CDATA[definition]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[safemode]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=117</guid>
		<description><![CDATA[Temporarily Disable System Restore  then update the virus definitions on your virus program then Reboot computer in SafeMode, then delete the IE temp files some Trojan.Zlob.P]]></description>
			<content:encoded><![CDATA[<p>Temporarily Disable System Restore  then update the virus definitions on your virus program then Reboot computer in SafeMode, then delete the IE temp files some <strong>Trojan.Zlob.P </strong>temp file exisit in that folder as well, you can wither search for the temp files or manually delete them.<br />
You may now download <strong>Malwarebytes </strong>from <a href="http://www.malwarebytes.org/mbam-download.php" target="_blank"><span style="color: #0000ff;"><strong>Here</strong></span></a> or <a href="http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html" target="_blank"><span style="color: #0000ff;"><strong>Here</strong></span></a></p>
<p>Update the definition and scan your computer, it will find any traces of <strong>Trojan.Zlob.P</strong> now delete and you should be good to go.<strong> </strong></p>
<p><strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-trojan-zlob-p-virus-trojan.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/RAHack!DD10EDBD56​90 Virus Removal</title>
		<link>http://www.softe.org/w32rahackdd10edbd56%e2%80%8b90-virus-removal.html</link>
		<comments>http://www.softe.org/w32rahackdd10edbd56%e2%80%8b90-virus-removal.html#comments</comments>
		<pubDate>Fri, 14 Jan 2011 20:43:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/RAHack!DD10EDBD56​90 Virus Removal]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[RAhack]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=114</guid>
		<description><![CDATA[W32/RAHack!DD10EDBD56​90 Virus Removal Update to current engine and DAT files for detection and removal.]]></description>
			<content:encoded><![CDATA[<p><strong>Other Common Aliases</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">avast</td>
<td align="right">Win32:Allaple [Wrm]</td>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Worm/Allaple.B</td>
</tr>
<tr>
<td align="left">avira</td>
<td align="right">WORM/Allaple.Gen</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Net-Worm.Win32.Allaple.b</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Win32.Worm.Allaple.Gen</td>
</tr>
<tr>
<td align="left">clamav</td>
<td align="right">Worm.Allaple-255</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Trojan.Starman</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/RAHack.A.gen!Eldorado</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/Allaple.gen!tr</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">worm:win32/allaple.a</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">W32.Rahack.W</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Kryptik.AJD trojan (variant)</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">Allaple.gen (trojan)</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">W32/Rahack.gen.worm</td>
</tr>
<tr>
<td align="left">rising</td>
<td align="right">Worm.Win32.Allaple.a</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">W32/Allaple-F</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">WORM_ALLAPLE.IK</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">OScope.Malware-Cryptor.Win32.Allaple</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Error</td>
</tr>
<tr>
<td align="left">Vet (Computer Associates)</td>
<td align="right">Win32/Mallar.Y</td>
</tr>
</tbody>
</table>
<p><strong>The following files were analyzed:</strong></p>
<p>urdvxc.exe<br />
<strong>The following files have been added to the system:</strong></p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bzqlkhrh.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\vkjljzrn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\web server extensions\40\bin\1033\ebsjlbhn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bhrhnkht.exe</p>
<p>* %PROGRAMFILES%\Adobe\Reader 9.0\rrtkrbtl.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\elwtjnbj.exe</p>
<p>* %TEMP%\0A5A6FE619B07BBAFB1F9C1B5F798F7DF96745D9</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bnbtzwxt.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bcwvzwbh.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\ehbebsrn.exe</p>
<p>* %PROGRAMFILES%\msn\msncorefiles\tlbhnrlv.exe</p>
<p>* %PROGRAMFILES%\Microsoft Office\OFFICE11\rsrrhtck.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\nsqjttkv.exe</p>
<p>* %PROGRAMFILES%\netmeeting\rsewzjqn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\qjllsjhl.exe</p>
<p>* %COMMONPROGRAMFILES%\system\ado\tsektjkj.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\web server extensions\40\bin\brbvhsvx.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\brvrjrke.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\njbsvtll.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\tlcwjrwt.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\czjevcet.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\xrljqjzn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\web server extensions\40\bin\tjnwrhns.exe</p>
<p><strong>How to remove this virus.</strong></p>
<p>1.<strong>Disable System Restore (Windows ME/XP only)</strong><strong>.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32rahackdd10edbd56%e2%80%8b90-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/HLLP.Philis.ki!DD​08745D1471 Virus Removal</title>
		<link>http://www.softe.org/w32hllp-philis-kidd%e2%80%8b08745d1471-virus-removal.html</link>
		<comments>http://www.softe.org/w32hllp-philis-kidd%e2%80%8b08745d1471-virus-removal.html#comments</comments>
		<pubDate>Fri, 14 Jan 2011 20:33:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/HLLP.Philis.ki!DD​08745D1471 Virus Removal]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=112</guid>
		<description><![CDATA[This symptoms of this W32/HLLP.Philis.ki detection are the  registry and network communication.]]></description>
			<content:encoded><![CDATA[<p>This symptoms of this W32/HLLP.Philis.ki detection are the  registry and network communication.</p>
<p>1.<strong>Disable System Restore (Windows ME/XP only)</strong><strong>.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan.</p>
<p>Modifications  made to the system Registry and/or INI files for the purposes of  hooking system startup, will be successfully removed if cleaning with  the recommended engine and DAT combination (or higher).</p>
<table>
<tbody>
<tr>
<td><strong>The following files have been changed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>c:\Users exe File.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\AcroTextExtractor.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\AdobeCollabSync.exe</li>
</ul>
<ul>
<li>c:\Users exe File.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\AcroRd32.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\msn\msncorefiles\copymar.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\Eula.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\Reader_sl.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\AcroRd32Info.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\msn\msncorefiles\dw.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Microsoft Office\OFFICE11\EXCEL.EXE</li>
</ul>
<ul>
<li>%PROGRAMFILES%\msn\msncorefiles\setup\msnunin.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\LogTransport2.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\AcroBroker.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\PDFPrevHndlrShim.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\msn\msncorefiles\update.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\msn\msncorefiles\msn6.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Setup Files\{AC76BA86-7AD7-[private subnet]-A92000000001}\Setup.exe</li>
</ul>
<ul>
<li>c:\Users exe File.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Adobe\Reader 9.0\Reader\A3DUtility.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\winrar\winrar.exe</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Microsoft Office\OFFICE11\WINWORD.EXE</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following files were temporarily written to disk then later removed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>%TEMP%\$$a5.bat</li>
</ul>
<ul>
<li>%TEMP%\049E09EA0D36D974DB4B1DF0A56D2AC2E1507FAF</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following registry elements have been created:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\DOWNLOADMANAGER\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\SOFT\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\SOFT\DOWNLOADWWW\</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following registry elements have been changed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS\LOAD = %WINDIR%\rundl132.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\SOFT\DOWNLOADWWW\AUTO = 49</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The applications attempted the following network connection(s):</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>hxxp://www.17aa.com/ic4/*****</li>
</ul>
<ul>
<li>222.186.12.**:80</li>
</ul>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32hllp-philis-kidd%e2%80%8b08745d1471-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/RAHack Worm/Allaple.A Virus Removal</title>
		<link>http://www.softe.org/w32rahack-wormallaple-a-virus-removal.html</link>
		<comments>http://www.softe.org/w32rahack-wormallaple-a-virus-removal.html#comments</comments>
		<pubDate>Fri, 17 Dec 2010 00:45:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/RAHack Worm/Allaple.A Virus Removal]]></category>
		<category><![CDATA[combfix]]></category>
		<category><![CDATA[melwarebytes]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=108</guid>
		<description><![CDATA[Although this is a low threat virus, the removal of W32/RAHack Worm/Allaple.A Virus  can be a pest but i have found that COMBFIX will remove this threat from your PC. Simply download CombFix by clicking here]]></description>
			<content:encoded><![CDATA[<p><strong>Other Common Detection Aliases</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Worm/Allaple.A</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">worm:win32/allaple.a</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">W32.Rahack.W</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">Allaple.gen</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">W32/Rahack.gen</td>
</tr>
</tbody>
</table>
<p><em>some of the path values that have been replaced with environment variables as the location may vary with different configurations for example.</p>
<p>%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</em></p>
<p><strong>The following files were scanned:</strong></p>
<p>urdvxc.exe</p>
<p><strong>REMOVAL</strong></p>
<p>Although this is a low threat virus, the removal of W32/RAHack Worm/Allaple.A Virus  can be a pest but i have found that COMBFIX will remove this threat from your PC. Simply <a href="http://www.bleepingcomputer.com/download/anti-virus/combofix" target="_blank">download CombFix by clicking</a> here, save it to your desktop, double click and and press next a few times and let the program scan your PC and clean it. Very simple really, might take some time and make sure you close all browsers and applications before you run CombFix.</p>
<p>Or you may just use MelwareBytes to remove the W32/RAHack virus. I would scan with both apps just to make sure. Good luck</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32rahack-wormallaple-a-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/Autorun.worm.zf.gen!F342CDD8894F Virus</title>
		<link>http://www.softe.org/w32autorun-worm-zf-genf342cdd8894f-virus.html</link>
		<comments>http://www.softe.org/w32autorun-worm-zf-genf342cdd8894f-virus.html#comments</comments>
		<pubDate>Wed, 27 Oct 2010 18:14:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/Autorun.worm.zf.gen!F342CDD8894F Virus]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[W32/Autorun]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=94</guid>
		<description><![CDATA[Viruses are self replicating which are often spread by a network or by transmission to a removable medium e.g writable CD, or USB drive. Viruses may also spread by infecting files on a network system or a file system that is shared by another users computer. Company Names Detection Names AVG (GriSoft) Packed.AutoIt Kaspersky Worm.Win32.Autoit.xl [...]]]></description>
			<content:encoded><![CDATA[<p>Viruses are self replicating which are often spread by a network or by  transmission to a removable medium e.g writable  CD, or USB drive. Viruses may also spread by infecting files on a  network system or a file system that is shared by another users computer.</p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Packed.AutoIt</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Worm.Win32.Autoit.xl</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Backdoor.Generic.434041</td>
</tr>
<tr>
<td align="left">ClamAV</td>
<td align="right">Trojan.Autoit-70</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Win32.HLLW.Autoruner.based</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/AutoIt.M.gen!Eldorado</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/AutoIt.A!worm</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">Worm:Win32/Autorun.XK</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">W32.Harakit</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Packed.Autoit.B.Gen (application)</td>
</tr>
<tr>
<td align="left">Norman</td>
<td align="right">Suspicious_Gen2.BFSNZ (trojan)</td>
</tr>
<tr>
<td align="left">Panda</td>
<td align="right">Trj/CI.A</td>
</tr>
<tr>
<td align="left">Rising</td>
<td align="right">Trojan.Win32.Generic.520A2FD6</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Sus/Tiotua-A (suspicious)</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">TROJ_GEN.R99C1HD</td>
</tr>
<tr>
<td align="left">Vba32</td>
<td align="right">Trojan.Autoit.F</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Trojan.Autoit.Gen!Pac</td>
</tr>
</tbody>
</table>
<p>The applications attempted the following network connections.</p>
<p>77.55.21.***:80<br />
95.211.21.***:82<br />
95.211.21.***:80<br />
72.233.89.***:80<br />
hxxp://95.211.21.184:89/*****<br />
194.71.107.**:80<br />
95.211.21.***:89<br />
209.190.24.**:80<br />
95.211.21.***:85</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32autorun-worm-zf-genf342cdd8894f-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skintrim.gen.k!72FD33EC8D39 Trojan Horse Virus</title>
		<link>http://www.softe.org/skintrim-gen-k72fd33ec8d39-trojan-horse-virus.html</link>
		<comments>http://www.softe.org/skintrim-gen-k72fd33ec8d39-trojan-horse-virus.html#comments</comments>
		<pubDate>Wed, 27 Oct 2010 18:03:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Skintrim.gen.k!72FD33EC8D39 Trojan Horse Virus]]></category>
		<category><![CDATA[email virus]]></category>
		<category><![CDATA[IRC virus]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=91</guid>
		<description><![CDATA[This is a Trojan Horse which most might think its a virus,  unlike viruses Trojanhorses  do not self replicate but rather are spread manually often under the premise that they are beneficial . The most common installation methods involve system or security exploitation and unsuspecting one can manually executing unknown programs. The way these Trojans [...]]]></description>
			<content:encoded><![CDATA[<p>This is a Trojan Horse which most might think its a virus,  unlike viruses Trojanhorses  do not  self replicate but rather are spread manually often under the premise that  they are beneficial . The most common installation methods  involve system or security exploitation and unsuspecting one can manually  executing unknown programs. The way these Trojans are spread is via e-mail,  Web pages, Internet Relay Chat, peer-to-peer  networks and so on.</p>
<h2>Indication of Infection</h2>
<p>This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.</p>
<p><em>Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/skintrim-gen-k72fd33ec8d39-trojan-horse-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TSPY_AGENT.WWCJ Virus Worm</title>
		<link>http://www.softe.org/tspy_agent-wwcj-virus-worm.html</link>
		<comments>http://www.softe.org/tspy_agent-wwcj-virus-worm.html#comments</comments>
		<pubDate>Tue, 20 Jul 2010 18:26:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[TSPY_AGENT.WWCJ Virus Worm]]></category>
		<category><![CDATA[agent]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=78</guid>
		<description><![CDATA[potential for damage, information stealing, or both, that it possesses. Specifically, it is capable of monitoring affected users browsing habits to steal sensitive information. This spy software can be downloaded from certain remote sites. Check if the following applications are installed on the affected system to steal login credentials: * Ftpcommander * SmartFTP * Steam [...]]]></description>
			<content:encoded><![CDATA[<p>potential for damage, information stealing, or both, that it possesses.  Specifically, it is capable of monitoring affected users browsing habits  to steal sensitive information.</p>
<p>This spy software can be downloaded from certain  remote sites.</p>
<p>Check if the following applications are installed  on the affected system to steal login credentials:</p>
<p>*  Ftpcommander<br />
* SmartFTP<br />
* Steam (an online gaming platform)</p>
<p>It also oversees the relevant users&#8217; browsing habits to steal sensitive  information.</p>
<p>Save the information gathered in a text file  using the file name () Name of the team. Txt and upload to a specific  Web site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/tspy_agent-wwcj-virus-worm.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove BackDoor.SmallX.VX virus trojan</title>
		<link>http://www.softe.org/how-to-remove-backdoor-smallx-vx-virus-trojan.html</link>
		<comments>http://www.softe.org/how-to-remove-backdoor-smallx-vx-virus-trojan.html#comments</comments>
		<pubDate>Tue, 13 Jul 2010 20:02:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[how to remove BackDoor.SmallX.VX virus trojan]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=75</guid>
		<description><![CDATA[Backdoor.smallX.VX is a nasty virus that enters the PC adn opens system back doors in Windows XP and Vista and could enter windows 7, once in your computer, the virus starts to download countless packed malware threats and gives distant hackers access to the infected machine via open ports. Stopzilla says to use their app [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.softe.org/wp-content/uploads/2010/07/computer-virus-bugs-clip-art7674.jpg"><img class="alignleft  size-full wp-image-76" title="computer-virus-bugs-clip-art7674" src="http://www.softe.org/wp-content/uploads/2010/07/computer-virus-bugs-clip-art7674.jpg" alt="" width="300" height="300" /></a><span style="font-family: Verdana,Arial,Helvetica,sans-serif; color: #333333; font-size: x-small;"><strong>Backdoor.smallX.VX</strong> is a nasty virus that enters the PC adn opens system back doors in Windows XP and Vista and could enter windows 7, once in your computer, the virus starts to download countless packed malware threats and gives distant hackers  access to the infected machine via open ports.</span></p>
<p><span style="font-family: Verdana,Arial,Helvetica,sans-serif; color: #333333; font-size: x-small;">Stopzilla says to use their app to remove this threat, but you can simply use </span>http://www.malwarebytes.org to remove this threat. Make sure you first download this app, update it, disconnect your PC from the internet, then run malwarebytes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-backdoor-smallx-vx-virus-trojan.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Trojan Horse Generic.17 16 15 14.DYJ</title>
		<link>http://www.softe.org/how-to-remove-trojan-horse-generic-17-16-15-14-dyj.html</link>
		<comments>http://www.softe.org/how-to-remove-trojan-horse-generic-17-16-15-14-dyj.html#comments</comments>
		<pubDate>Mon, 10 May 2010 18:17:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to remove Trojan Horse Generic]]></category>
		<category><![CDATA[generic]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=21</guid>
		<description><![CDATA[If you have gotten a virus in your PC called Trojan Horse Generic with a number next to it such as .17 or 16 or 15 or 14, this simply means you have downloaded an illegal software from a torrent.  The risk level of this virus is not that great but still needs to be removed asap.

Trojan horse Generic 14.DYJ is a detection for a trojan that applies a Rootkit technology to remain itself hidden from system so as to avoid being detected by antivirus application. Trojan horse Generic 14.DYJ can hook itself into Windows registry and create a backdoor to allow a remote attacker gain full access on victims computer.

Damage Level: Medium

Systems Affected: Windows XP, Vista, 7

To remove this virus, you will need to download Rkill

Downloads:
rkill.exe – Download from BleepingComputer.com – 257kb
rkill.com – Download from BleepingComputer.com – 257kb
rkill.scr – Download from BleepingComputer.com – 257kb
rkill.pif – Download from BleepingComputer.com – 257kb

After you have finished with Rkill, do not reboot your PC, make sure you also have MalwareBytes installed on your PC, you will need to run this next.

Click here to download MalwareBytes

Now run Malwarebytes and this should fix your virus. You may run quick scan, and make sure you update malwarebytes before you scan and clean. Good luck
]]></description>
			<content:encoded><![CDATA[<p>If you have gotten a virus in your PC called Trojan Horse Generic with a number next to it such as .17 or 16 or 15 or 14, this simply means you have downloaded an illegal software from a torrent.  The risk level of this virus is not that great but still needs to be removed asap.</p>
<div>
<p>Trojan horse Generic 14.DYJ is a detection for a trojan that applies  a Rootkit technology to remain itself hidden from system so as to avoid  being detected by antivirus application. Trojan horse Generic 14.DYJ  can hook itself into Windows registry and create a backdoor to allow a  remote attacker gain full access on victims computer.</p>
<p><strong>Damage Level:</strong> Medium</p>
<p><strong>Systems Affected:</strong> Windows XP, Vista, 7</p>
<p>To remove this virus, you will need to download Rkill</p>
<p><strong>Downloads:</strong><br />
<a href="http://download.bleepingcomputer.com/grinler/rkill.scr" target="_blank">Download from BleepingComputer.com – 257kb</a></p>
<p>After you have finished with Rkill, do not reboot your PC, make sure you also have <strong>MalwareBytes</strong> installed on your PC, you will need to run this next.</p>
<p><strong><a href="http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&amp;subj=dl&amp;tag=button" target="_blank">Click here to download MalwareBytes</a></strong></p>
<p>Now run Malwarebytes and this should fix your virus. You may run quick scan, and make sure you update malwarebytes before you scan and clean. Good luck<strong><br />
</strong></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-trojan-horse-generic-17-16-15-14-dyj.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SONAR.ProcessHijack.2 Trojan Virus</title>
		<link>http://www.softe.org/sonar-processhijack-2-trojan-virus.html</link>
		<comments>http://www.softe.org/sonar-processhijack-2-trojan-virus.html#comments</comments>
		<pubDate>Wed, 05 May 2010 09:34:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SONAR.ProcessHijack.2 Trojan Virus]]></category>
		<category><![CDATA[hijack]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=9</guid>
		<description><![CDATA[Discovered: May 4, 2010
Updated: May 4, 2010 10:56:26 PM
Type: Trojan, Virus
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP
SONAR.ProcessHijack.2 is a heuristic detection that is designed to detect new malware based on how it launches new processes. Malware will commonly launch and hijack trusted Windows processes like svchost.exe in order to perform malicious actions.

Antivirus Protection Dates

    * Initial Rapid Release version pending
    * Latest Rapid Release version pending
    * Initial Daily Certified version pending
    * Latest Daily Certified version May 4, 2010 revision 048
    * Initial Weekly Certified release date pending

Threat Assessment
Wild

    * Wild Level: Low
    * Number of Infections: 0 - 49
    * Number of Sites: 0 - 2
    * Geographical Distribution: Low
    * Threat Containment: Easy
    * Removal: Easy

Damage

    * Damage Level: Low

Distribution

    * Distribution Level: Low]]></description>
			<content:encoded><![CDATA[<div id="tabModBdy">
<div><strong>Discovered: </strong>May 4, 2010</div>
<div><strong>Updated: </strong>May 4, 2010 10:56:26 PM</div>
<div><strong>Type: </strong>Trojan, Virus</div>
<div><strong>Systems Affected: </strong>Windows 2000, Windows 95, Windows 98,  Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP</div>
<p>SONAR.ProcessHijack.2 is a heuristic detection that is designed  to detect new malware based on how it launches new processes. Malware  will commonly launch and hijack trusted Windows processes like  svchost.exe in order to perform malicious actions.</p>
<h3>Antivirus Protection Dates</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>pending</li>
<li> <strong>Latest Rapid Release version </strong>pending</li>
<li> <strong>Initial Daily Certified version </strong>pending</li>
<li> <strong>Latest Daily Certified version </strong>May 4, 2010 revision 048</li>
<li> <strong>Initial Weekly Certified release date </strong>pending</li>
</ul>
<h3>Threat Assessment</h3>
<h4>Wild</h4>
<ul>
<li> <strong>Wild Level: </strong>Low</li>
<li> <strong>Number of Infections: </strong>0 &#8211; 49</li>
<li> <strong>Number of Sites: </strong>0 &#8211; 2</li>
<li> <strong>Geographical Distribution: </strong>Low</li>
<li> <strong>Threat Containment: </strong>Easy</li>
<li> <strong>Removal: </strong>Easy</li>
</ul>
<h4>Damage</h4>
<ul>
<li> <strong>Damage Level: </strong>Low</li>
</ul>
<h4>Distribution</h4>
<ul>
<li> <strong>Distribution Level: </strong>Low</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/sonar-processhijack-2-trojan-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

