<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Free Spyware Adware Worm and Virus Trojan Horse Download Removal Tools &#187; worm</title>
	<atom:link href="http://www.softe.org/tag/worm/feed" rel="self" type="application/rss+xml" />
	<link>http://www.softe.org</link>
	<description>FREE Computer Repair</description>
	<lastBuildDate>Sun, 04 Dec 2011 21:36:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>So how do you Remove Koobface the facebook worm virus</title>
		<link>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html</link>
		<comments>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html#comments</comments>
		<pubDate>Thu, 08 Sep 2011 18:50:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[So how do you Remove Koobface the facebook worm virus]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[google redirect spyware]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[windows xp]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=159</guid>
		<description><![CDATA[Koobface Virus threat is one that is taking by storm, specially because it uses a host such as facebook social network to spread the virus.  This Koobface virus finds methods to seek into the users PC and spread malware into the computer so its considered as a worm which replicates itself within your computer.  So [...]]]></description>
			<content:encoded><![CDATA[<p>Koobface Virus threat is one that is taking by storm, specially because it uses a host such as facebook social network to spread the virus.  This Koobface virus finds methods to seek into the users PC and spread malware into the computer so its considered as a worm which replicates itself within your computer.  So how does KoobFace infect your PC, well its simple really, if you use facebook, and you receive a strange email, stating something along the lines of &#8221; click here to see your face look stupid&#8221; which attracts you to click the link,  once clicked, a virus code will be downloaded to your PC which will then spread the worm to your PC and start to redirect your search results from google to malicious software and websites. Simple huh?</p>
<div>
<div id="mod_2169282">
<div id="txtd_2169282">
<div>
<div id="mod_2169300">
<h2>So how do you Remove Koobface worm virus?</h2>
<div id="txtd_2169300">With  anti-malware software such as melwarebytes and spybot, you might be able to remove this worm, but sometimes this is not possible and you need to manually remove it.</p>
<div>
<div id="mod_2169358">
<div id="txtd_2169358">
<p><strong>Using The Add Remove Program in control panel:</strong></p>
<ul>
<li>Go to Add\Remove in control panel</li>
<li>Look up for the Koobface malware to remove and uninstall it.</li>
</ul>
<p>if you do not see the koobface there, go to registry and search for: ( <span style="color: #ff0000;">if you do not know how to use your registry, you might really screw up your PC for good, so take note, this step is for advanced users who have messed around with the registry and know their way around</span>.)</p>
<ul>
<li>Search for &#8220;koobface&#8221; in Mycomputer using find utility.</li>
<li>Note down Koobface file path some where.</li>
<li>Press Ctrl+Alt+Del to open &#8216;Task Manager&#8217;</li>
<li>End the &#8220;Koobface&#8221; processes.</li>
</ul>
<p><strong>End the following processes</strong></p>
<ol>
<li>%SYSTEMROOT%\bolivar28.exe</li>
<li>che07.exe</li>
<li>bolivar28.exe</li>
<li>%WinDir%\system32\nScan\ekrn.exe</li>
<li>%WinDir%\system32\nScan\ecls.exe</li>
<li>%WinDir%\system32\splm\ncsjapi32.exe</li>
<li>%WinDir%\bolivar28.exe</li>
<li>C:\Windows\fbtre6.exe</li>
</ol>
<p><strong>now change Registry Files</strong></p>
<ul>
<li>Type &#8216;regedit&#8217; in Run and press Enter.</li>
<li>The Registry Editor will appear, locate the above mentioned process files and delete them.</li>
<li>Locate &#8220;Koobface&#8221; registry entries and delete them, they are as the follows:</li>
</ul>
<ol>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Intelli Mouse Pro Version 2.0B\StubPath: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Intelli Mouse Pro Version 2.0B: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden: &#8220;2&#8243;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: &#8220;%WinDir% \System32\splm\ncsjapi32.exe&#8221;</li>
<li>HKEY_USERS\Software\Microsoft\Windows\nScan32\ExecuteDate: &#8220;14\8\2008&#8243;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\&#8221;systray&#8221; = &#8220;c:\windows\mstre6.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\&#8221;systray&#8221; = &#8220;C:\Windows\fbtre6.exe&#8221;</li>
<li>HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating</li>
</ol>
</div>
</div>
</div>
<div id="mod_2169659">
<div id="txtd_2169659">
<p><strong>Now you have to unregister the dll files</strong></p>
<ul>
<li>Go to start and type in &#8216;cmd&#8217; to open comman prompt.</li>
<li>First locate the following dll files using &#8216;dir&#8217; command.</li>
</ul>
<ol>
<li>%WinDir%\system32\nScan\ekrnEmon.dll</li>
<li>%WinDir%\system32\nScan\ekrnScan.dll</li>
<li>%WinDir%\system32\nScan\ekrnEpfw.dll</li>
<li>%WinDir%\system32\nScan\ekrnAmon.dll</li>
<li>%WinDir%\system32\splm\lmfunit32.dll</li>
<li>%WinDir%\system32\splm\mcaserv32.dll</li>
<li>%WinDir%\system32\splm\kbdsapi.dll</li>
</ol>
<ul>
<li>Now change the current directory using &#8216;cd&#8217; command leave a space after &#8216;cd&#8217; and then the path of dll file, which you have located above. Press enter after this.</li>
<li>Now unregister dll file by typing &#8220;directory path+&#8217;regsvr32/u&#8217;+dll file name&#8221;. Press enter, the file will be unregistered.</li>
</ul>
<p>&nbsp;</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/so-how-do-you-remove-koobface-the-facebook-worm-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic BackDoor!djf!5D41C80E​A0DA malware Trojan Virus</title>
		<link>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html</link>
		<comments>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html#comments</comments>
		<pubDate>Wed, 20 Jul 2011 22:58:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic BackDoor!djf!5D41C80E​A0DA malware Trojan Virus]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[IRC virus]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[Microsoft Security Essentials]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[virus removal]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[W32/Autorun]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=154</guid>
		<description><![CDATA[These files were added to the system: %APPDATA%\services.exe %TEMP%\e3c1c08557a0d0feee33b9c9d18b4e6c129b553f.exe This Trojan will attempt to fiddle with your network conection, e.g hxxp://www.maxmind.com/app/*** Virus app&#8217;s Detection Names EMSI Software Trojan.Backdoor.Ircbot!IK avast Win32:Ruskill-F Kaspersky Backdoor.Win32.IRCBot.tjd BitDefender Backdoor.Bot.138642 Microsoft VirTool:Win32/CeeInject.gen!EI Symantec Backdoor.IRC.Bot Eset a variant of Win32/Injector.GLN trojan norman W32/Suspicious_Gen3.TYCW Sophos Mal/Generic-L Trend Micro PAK_Generic.001 vba32 Backdoor.IRCBot.tjd How to [...]]]></description>
			<content:encoded><![CDATA[<p>These files were added to the system:</p>
<ul>
<li>%APPDATA%\services.exe</li>
</ul>
<ul>
<li>%TEMP%\e3c1c08557a0d0feee33b9c9d18b4e6c129b553f.exe</li>
</ul>
<p>This Trojan will attempt to fiddle with your network conection, e.g hxxp://www.maxmind.com/app/***</p>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr bgcolor="silver">
<th align="left" bgcolor="silver"><strong>Virus app&#8217;s<br />
</strong></th>
<th align="right" bgcolor="silver"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">EMSI Software</td>
<td align="right">Trojan.Backdoor.Ircbot!IK</td>
</tr>
<tr>
<td align="left">avast</td>
<td align="right">Win32:Ruskill-F</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Backdoor.Win32.IRCBot.tjd</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Backdoor.Bot.138642</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">VirTool:Win32/CeeInject.gen!EI</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">Backdoor.IRC.Bot</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">a variant of Win32/Injector.GLN trojan</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Suspicious_Gen3.TYCW</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Mal/Generic-L</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">PAK_Generic.001</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">Backdoor.IRCBot.tjd</td>
</tr>
</tbody>
</table>
<p>How to remove <strong>Generic BackDoor!djf!5D41C80E​A0DA</strong></p>
<p>Removal should be easy given the fact that you are able to follow directions <img src='http://www.softe.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>First thing to do is disconnect your network or internet. Now you will need to reboot your PC and enter safe mode, if you do not know how to enter safe mode, please search above for &#8221; how to enter safe mode&#8221;</p>
<p>Now you will need to do a system scan using these apps below:</p>
<p>1. your favorite virus app, i suggest AVG or Microsoft security essentials<br />
2. do a system scan using Malwarebytes<br />
3. do a system scan using spybot<br />
4. do a system scan using hijackthis</p>
<p>if the virus  is not letting you do these scans, you must :</p>
<p>1.Disable System Restore on Windows ME and windows XP only.<br />
2.Update to current engine and DAT files for detection and removal.<br />
3.Run a complete system scan.</p>
<p>This should remove the threat, this threat is a low security threat but never the less it should always be cleaned before using the world wide web.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/generic-backdoordjf5d41c80e%e2%80%8ba0da-malware-trojan-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Win32/Olmarik Trojan malware</title>
		<link>http://www.softe.org/how-to-remove-win32olmarik-trojan-malware.html</link>
		<comments>http://www.softe.org/how-to-remove-win32olmarik-trojan-malware.html#comments</comments>
		<pubDate>Wed, 09 Mar 2011 05:33:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[fake security software]]></category>
		<category><![CDATA[IRC virus]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[messaging]]></category>
		<category><![CDATA[scareware]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[W32/Autorun]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=130</guid>
		<description><![CDATA[If  your PC has been infected with the Win32/Olmarik  Trojan virus, please download Malwarebytes' Anti-Malware its a free app. Double click]]></description>
			<content:encoded><![CDATA[<p>If  your PC has been infected with the Win32/Olmarik  Trojan virus, please download Malwarebytes&#8217; Anti-Malware its a free app. Double click <strong>mbam-setup.exe</strong> and follow the directions and install it on your home PC. Make sure you click update Malwarebytes before you press the scan button.</p>
<p>What the Win32/Olmarik trojan does is it infects your PC by installing a nasty malware by falsified displaying security alerts and making the user install even more bugs. Once you click on   the alert, it will start downloading anti-spyware or anti-virus tools that are useless and will infect even more of  your file system structure and files in general. Take care of this trojan as soon as you can to prevent our PC from getting any worse.</p>
<p><img class="alignnone" title="Virus win32 trojan" src="http://farinango.info/wp-content/uploads/2010/06/virus-farinango.info_.jpg" alt="" width="400" height="365" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/how-to-remove-win32olmarik-trojan-malware.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32/Olmarik trojan virus removal</title>
		<link>http://www.softe.org/win32olmarik-trojan-virus-removal.html</link>
		<comments>http://www.softe.org/win32olmarik-trojan-virus-removal.html#comments</comments>
		<pubDate>Thu, 24 Feb 2011 22:34:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Win32/Olmarik trojan virus removal]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=125</guid>
		<description><![CDATA[To clean this nasty Win32/Olmariktrojan horse virus,

Open RootRepeal, click the Drivers tab and select Scan. Right click and select Wipe File on:]]></description>
			<content:encoded><![CDATA[<p>To clean this nasty Win32/Olmariktrojan horse virus,</p>
<p>Open <strong><span style="color: green;">RootRepeal</span></strong>, click the <strong>Drivers</strong> tab and select <strong>Scan</strong>.  Right click and select <strong>Wipe File</strong> on:</p>
<p><strong>H8SRTmeyqxwbpxd.sys</strong></p>
<p>Click the <strong>Files</strong> tab and select <strong>Scan</strong>.  Right click and select <strong>Wipe File</strong> on any file that begins with the following:</p>
<p><strong>H8SRT</strong></p>
<p>Do the same for the Hidden Services tab.</p>
<p><strong><span style="color: red;">Reboot your machine</span></strong></p>
<p>Then let&#8217;s run RootRepeal again:</p>
<ul>
<li>Double click <strong>ROOTREPEAL </strong>to start the program</li>
<li>Click on the <strong>Report</strong> tab at the bottom of the program window</li>
<li>Click the <strong>SCAN </strong>button</li>
<li>In the <strong>Select Scan</strong> dialog, check:
<ul><span style="color: green;"></p>
<li><strong>Drivers</strong></li>
<li><strong>Files</strong></li>
<li><strong>Processes</strong></li>
<li><strong>SSDT</strong></li>
<li><strong>Stealth Objects</strong></li>
<li><strong>Hidden Services</strong></li>
<li><strong>Shadow SSDT</strong></li>
<p></span></ul>
</li>
<li>Click the <strong>OK</strong> button</li>
<li>In the next dialog, select <strong>all drives</strong> showing</li>
<li>Click <strong>OK</strong> to start the scan<br />
<blockquote><p><em>Note: The scan can take some time. <strong><span style="color: red;">DO NOT</span></strong> run any other programs while the scan is running</em></p></blockquote>
</li>
<li>When the scan is complete, click the<strong> SAVE REPORT</strong> button and save the report to your Desktop as <strong>RootRepeal.txt</strong></li>
<li>Go to <strong>File</strong>, then <strong>Exit</strong> to close the program</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/win32olmarik-trojan-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/RAHack!DD10EDBD56​90 Virus Removal</title>
		<link>http://www.softe.org/w32rahackdd10edbd56%e2%80%8b90-virus-removal.html</link>
		<comments>http://www.softe.org/w32rahackdd10edbd56%e2%80%8b90-virus-removal.html#comments</comments>
		<pubDate>Fri, 14 Jan 2011 20:43:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/RAHack!DD10EDBD56​90 Virus Removal]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[RAhack]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=114</guid>
		<description><![CDATA[W32/RAHack!DD10EDBD56​90 Virus Removal Update to current engine and DAT files for detection and removal.]]></description>
			<content:encoded><![CDATA[<p><strong>Other Common Aliases</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">avast</td>
<td align="right">Win32:Allaple [Wrm]</td>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Worm/Allaple.B</td>
</tr>
<tr>
<td align="left">avira</td>
<td align="right">WORM/Allaple.Gen</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Net-Worm.Win32.Allaple.b</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Win32.Worm.Allaple.Gen</td>
</tr>
<tr>
<td align="left">clamav</td>
<td align="right">Worm.Allaple-255</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Trojan.Starman</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/RAHack.A.gen!Eldorado</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/Allaple.gen!tr</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">worm:win32/allaple.a</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">W32.Rahack.W</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Kryptik.AJD trojan (variant)</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">Allaple.gen (trojan)</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">W32/Rahack.gen.worm</td>
</tr>
<tr>
<td align="left">rising</td>
<td align="right">Worm.Win32.Allaple.a</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">W32/Allaple-F</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">WORM_ALLAPLE.IK</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">OScope.Malware-Cryptor.Win32.Allaple</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Error</td>
</tr>
<tr>
<td align="left">Vet (Computer Associates)</td>
<td align="right">Win32/Mallar.Y</td>
</tr>
</tbody>
</table>
<p><strong>The following files were analyzed:</strong></p>
<p>urdvxc.exe<br />
<strong>The following files have been added to the system:</strong></p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bzqlkhrh.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\vkjljzrn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\web server extensions\40\bin\1033\ebsjlbhn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bhrhnkht.exe</p>
<p>* %PROGRAMFILES%\Adobe\Reader 9.0\rrtkrbtl.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\elwtjnbj.exe</p>
<p>* %TEMP%\0A5A6FE619B07BBAFB1F9C1B5F798F7DF96745D9</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bnbtzwxt.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\bcwvzwbh.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\ehbebsrn.exe</p>
<p>* %PROGRAMFILES%\msn\msncorefiles\tlbhnrlv.exe</p>
<p>* %PROGRAMFILES%\Microsoft Office\OFFICE11\rsrrhtck.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\nsqjttkv.exe</p>
<p>* %PROGRAMFILES%\netmeeting\rsewzjqn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\qjllsjhl.exe</p>
<p>* %COMMONPROGRAMFILES%\system\ado\tsektjkj.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\web server extensions\40\bin\brbvhsvx.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\brvrjrke.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\njbsvtll.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\tlcwjrwt.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\czjevcet.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\stationery\xrljqjzn.exe</p>
<p>* %COMMONPROGRAMFILES%\microsoft shared\web server extensions\40\bin\tjnwrhns.exe</p>
<p><strong>How to remove this virus.</strong></p>
<p>1.<strong>Disable System Restore (Windows ME/XP only)</strong><strong>.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32rahackdd10edbd56%e2%80%8b90-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/RAHack Worm/Allaple.A Virus Removal</title>
		<link>http://www.softe.org/w32rahack-wormallaple-a-virus-removal.html</link>
		<comments>http://www.softe.org/w32rahack-wormallaple-a-virus-removal.html#comments</comments>
		<pubDate>Fri, 17 Dec 2010 00:45:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/RAHack Worm/Allaple.A Virus Removal]]></category>
		<category><![CDATA[combfix]]></category>
		<category><![CDATA[melwarebytes]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=108</guid>
		<description><![CDATA[Although this is a low threat virus, the removal of W32/RAHack Worm/Allaple.A Virus  can be a pest but i have found that COMBFIX will remove this threat from your PC. Simply download CombFix by clicking here]]></description>
			<content:encoded><![CDATA[<p><strong>Other Common Detection Aliases</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Worm/Allaple.A</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">worm:win32/allaple.a</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">W32.Rahack.W</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">Allaple.gen</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">W32/Rahack.gen</td>
</tr>
</tbody>
</table>
<p><em>some of the path values that have been replaced with environment variables as the location may vary with different configurations for example.</p>
<p>%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</em></p>
<p><strong>The following files were scanned:</strong></p>
<p>urdvxc.exe</p>
<p><strong>REMOVAL</strong></p>
<p>Although this is a low threat virus, the removal of W32/RAHack Worm/Allaple.A Virus  can be a pest but i have found that COMBFIX will remove this threat from your PC. Simply <a href="http://www.bleepingcomputer.com/download/anti-virus/combofix" target="_blank">download CombFix by clicking</a> here, save it to your desktop, double click and and press next a few times and let the program scan your PC and clean it. Very simple really, might take some time and make sure you close all browsers and applications before you run CombFix.</p>
<p>Or you may just use MelwareBytes to remove the W32/RAHack virus. I would scan with both apps just to make sure. Good luck</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32rahack-wormallaple-a-virus-removal.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.SillyFDC.BDO worm clean with Webroot Spy Sweeper</title>
		<link>http://www.softe.org/w32-sillyfdc-bdo-worm-clean-with-webroot-spy-sweeper.html</link>
		<comments>http://www.softe.org/w32-sillyfdc-bdo-worm-clean-with-webroot-spy-sweeper.html#comments</comments>
		<pubDate>Wed, 01 Dec 2010 07:28:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32.SillyFDC.BDO worm clean with Webroot Spy Sweeper]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[spy sweeper]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[webroot]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=101</guid>
		<description><![CDATA[I was able to capture this W32.SillyFDC.BDO worm on my test machine and run a few tests to see which software did the best cleaning and its safe to say Spy Sweeper by Webroot was the winner. ]]></description>
			<content:encoded><![CDATA[<p>W32.SillyFDC.BDO is a new discovered worm that spreads by copying itself to removable drives such as external hard drivers, USB flash drivers, etc.</p>
<p>I was able to capture this <strong>W32.SillyFDC.BDO worm</strong> on my test machine and run a few tests to see which software did the best cleaning and its safe to say<strong> Spy Sweeper</strong> by <strong>Webroot </strong>was the winner.<br />
Webroot AntiVirus 2010 with Spy  Sweeper is one of the best apps that will  protect your PC from virus threats,  spyware, adware, worms and Trojans malware. One great thing i found about spy sweeper is that it protects your PC real time without bottle necking or slowing down your net speed or even your PC&#8217;s resources. Unlike Norton which really takes away a good portion of your memory and hogs your system resources.</p>
<p><strong>W32.SillyFDC.BDO worm</strong><br />
When executed this worm copies itself as the following files:</p>
<ul>
<li>%SystemDrive%\services.exe</li>
<li>%Windir%\services.exe</li>
</ul>
<p>It then creates the following registry entry so that it runs every time Windows starts:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;ServiceControlApp&#8221; = &#8220;%SystemDrive%\services.exe&#8221;</p>
<p>The worm also modifies the following registry entries:</p>
<ul>
<li>HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;ShowSuperHidden&#8221; = &#8220;0&#8243;</li>
<li>HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&#8221;HideFileExt&#8221; = &#8220;1&#8243;</li>
</ul>
<p><strong>To clean this threat, simply run Webroot Spy Sweeper</strong></p>
<p>Clean this threat manually:</p>
<ol>
<li>Disable System Restore (Windows Me/XP).</li>
<li>Update the virus definitions.</li>
<li>Run a full system scan.</li>
<li>Delete any values added to the registry.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32-sillyfdc-bdo-worm-clean-with-webroot-spy-sweeper.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/Autorun.worm.zf.gen!F342CDD8894F Virus</title>
		<link>http://www.softe.org/w32autorun-worm-zf-genf342cdd8894f-virus.html</link>
		<comments>http://www.softe.org/w32autorun-worm-zf-genf342cdd8894f-virus.html#comments</comments>
		<pubDate>Wed, 27 Oct 2010 18:14:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/Autorun.worm.zf.gen!F342CDD8894F Virus]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[W32/Autorun]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=94</guid>
		<description><![CDATA[Viruses are self replicating which are often spread by a network or by transmission to a removable medium e.g writable CD, or USB drive. Viruses may also spread by infecting files on a network system or a file system that is shared by another users computer. Company Names Detection Names AVG (GriSoft) Packed.AutoIt Kaspersky Worm.Win32.Autoit.xl [...]]]></description>
			<content:encoded><![CDATA[<p>Viruses are self replicating which are often spread by a network or by  transmission to a removable medium e.g writable  CD, or USB drive. Viruses may also spread by infecting files on a  network system or a file system that is shared by another users computer.</p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Packed.AutoIt</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Worm.Win32.Autoit.xl</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Backdoor.Generic.434041</td>
</tr>
<tr>
<td align="left">ClamAV</td>
<td align="right">Trojan.Autoit-70</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Win32.HLLW.Autoruner.based</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/AutoIt.M.gen!Eldorado</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/AutoIt.A!worm</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">Worm:Win32/Autorun.XK</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">W32.Harakit</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/Packed.Autoit.B.Gen (application)</td>
</tr>
<tr>
<td align="left">Norman</td>
<td align="right">Suspicious_Gen2.BFSNZ (trojan)</td>
</tr>
<tr>
<td align="left">Panda</td>
<td align="right">Trj/CI.A</td>
</tr>
<tr>
<td align="left">Rising</td>
<td align="right">Trojan.Win32.Generic.520A2FD6</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Sus/Tiotua-A (suspicious)</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">TROJ_GEN.R99C1HD</td>
</tr>
<tr>
<td align="left">Vba32</td>
<td align="right">Trojan.Autoit.F</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Trojan.Autoit.Gen!Pac</td>
</tr>
</tbody>
</table>
<p>The applications attempted the following network connections.</p>
<p>77.55.21.***:80<br />
95.211.21.***:82<br />
95.211.21.***:80<br />
72.233.89.***:80<br />
hxxp://95.211.21.184:89/*****<br />
194.71.107.**:80<br />
95.211.21.***:89<br />
209.190.24.**:80<br />
95.211.21.***:85</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32autorun-worm-zf-genf342cdd8894f-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TSPY_AGENT.WWCJ Virus Worm</title>
		<link>http://www.softe.org/tspy_agent-wwcj-virus-worm.html</link>
		<comments>http://www.softe.org/tspy_agent-wwcj-virus-worm.html#comments</comments>
		<pubDate>Tue, 20 Jul 2010 18:26:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[TSPY_AGENT.WWCJ Virus Worm]]></category>
		<category><![CDATA[agent]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=78</guid>
		<description><![CDATA[potential for damage, information stealing, or both, that it possesses. Specifically, it is capable of monitoring affected users browsing habits to steal sensitive information. This spy software can be downloaded from certain remote sites. Check if the following applications are installed on the affected system to steal login credentials: * Ftpcommander * SmartFTP * Steam [...]]]></description>
			<content:encoded><![CDATA[<p>potential for damage, information stealing, or both, that it possesses.  Specifically, it is capable of monitoring affected users browsing habits  to steal sensitive information.</p>
<p>This spy software can be downloaded from certain  remote sites.</p>
<p>Check if the following applications are installed  on the affected system to steal login credentials:</p>
<p>*  Ftpcommander<br />
* SmartFTP<br />
* Steam (an online gaming platform)</p>
<p>It also oversees the relevant users&#8217; browsing habits to steal sensitive  information.</p>
<p>Save the information gathered in a text file  using the file name () Name of the team. Txt and upload to a specific  Web site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/tspy_agent-wwcj-virus-worm.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Palevo.B Worm instant messaging clients</title>
		<link>http://www.softe.org/w32-palevo-b-worm-instant-messaging-clients.html</link>
		<comments>http://www.softe.org/w32-palevo-b-worm-instant-messaging-clients.html#comments</comments>
		<pubDate>Wed, 05 May 2010 09:31:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32.Palevo.B Worm]]></category>
		<category><![CDATA[messaging]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.softe.org/?p=6</guid>
		<description><![CDATA[Discovered: May 4, 2010
Updated: May 4, 2010 11:27:56 AM
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP

W32.Palevo.B is a worm that spreads through instant messaging clients.
Antivirus Protection Dates

    * Initial Rapid Release version May 4, 2010 revision 009
    * Latest Rapid Release version May 4, 2010 revision 020
    * Initial Daily Certified version May 4, 2010 revision 048
    * Latest Daily Certified version May 4, 2010 revision 048
    * Initial Weekly Certified release date May 5, 2010

Threat Assessment
Wild

    * Wild Level: Low
    * Number of Infections: 0 - 49
    * Number of Sites: 0 - 2
    * Geographical Distribution: Low
    * Threat Containment: Easy
    * Removal: Easy

Damage

    * Damage Level: Low
    * Payload: Spreads through instant messaging programs.

Distribution

    * Distribution Level: Medium

]]></description>
			<content:encoded><![CDATA[<div id="tabModBdy">
<div><strong>Discovered: </strong>May 4, 2010</div>
<div><strong>Updated: </strong>May 4, 2010 11:27:56 AM</div>
<div><strong>Type: </strong>Worm</div>
<div><strong>Systems Affected: </strong>Windows 2000, Windows 95, Windows 98,  Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP</div>
<p>W32.Palevo.B is a worm that spreads through instant messaging  clients.</p>
<h3>Antivirus Protection Dates</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>May 4, 2010 revision 009</li>
<li> <strong>Latest Rapid Release version </strong>May 4, 2010 revision 020</li>
<li> <strong>Initial Daily Certified version </strong>May 4, 2010 revision  048</li>
<li> <strong>Latest Daily Certified version </strong>May 4, 2010 revision 048</li>
<li> <strong>Initial Weekly Certified release date </strong>May 5, 2010</li>
</ul>
<h3>Threat Assessment</h3>
<h4>Wild</h4>
<ul>
<li> <strong>Wild Level: </strong>Low</li>
<li> <strong>Number of Infections: </strong>0 &#8211; 49</li>
<li> <strong>Number of Sites: </strong>0 &#8211; 2</li>
<li> <strong>Geographical Distribution: </strong>Low</li>
<li> <strong>Threat Containment: </strong>Easy</li>
<li> <strong>Removal: </strong>Easy</li>
</ul>
<h4>Damage</h4>
<ul>
<li> <strong>Damage Level: </strong>Low</li>
<li> <strong>Payload: </strong>Spreads through instant messaging programs.</li>
</ul>
<h4>Distribution</h4>
<ul>
<li> <strong>Distribution Level: </strong>Medium</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.softe.org/w32-palevo-b-worm-instant-messaging-clients.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

