<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Registry Cleaner Geeks &#187; Blog</title>
	<atom:link href="http://www.registrycleanergeeks.com/category/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.registrycleanergeeks.com</link>
	<description>Microsoft Windows Registry Cleaner Reviews, XP, Vista, Free Downloads!</description>
	<lastBuildDate>Mon, 16 Aug 2010 09:00:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Remove Trojan.Dysflink</title>
		<link>http://www.registrycleanergeeks.com/trojan/dysflink/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/dysflink/#comments</comments>
		<pubDate>Mon, 02 Aug 2010 00:45:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1751</guid>
		<description><![CDATA[Discovered: July 8, 2010 Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Dysflink you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.Bamital. If your [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1751"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>July 8, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Dysflink    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Bamital. </p>
<p>If your PC is also running slowly, you may be interested to look at <a href="http://www.registrycleanergeeks.com/registry-fix/review/">Registry Fix</a>.. Registry fix is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>Trojan.Dysflink can arrive on your PC by way of a drive by download.</p>
<p>When the Trojan itself is executed, it will copy itself as the following file:<br />
  %ProgramFiles%\qcat\qsetup.exe</p>
<p>Then the trojan will create the following file on your computer.<br />
  %ProgramFiles%\qcat\qcat.ini</p>
<p>Dysflink then searches these folders on your machine for .lnk files, which are used to represent Windows shortcuts:</p>
<p> * %UserProfile%\Desktop<br />
  * %UserProfile%\Start Menu<br />
  * %SystemDrive%\Documents and Settings\All Users\Desktop<br />
  * %SystemDrive%\Documents and Settings\All Users\Start Menu
</p>
<p>Next, Dysflink modifies all .lnk files found so that it executes whenever one of the above shortcuts is used. It also executes the original target executable of the shortcut so that the user remains unaware of its presence.</p>
<p>Note: The original .lnk files are copied to the following folder:<br />
  %ProgramFiles%\qcat\tmpdata</p>
<p>It will then attempt to steal information relating to the QQ instant messaging program, which it will then send along to the following URL:<br />
  [http://]716mm.com:81/dd/dd/qq.[REMOVED]</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Dysflink. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-070907-0225-99&#038;tabid=3" rel="nofollow">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/dysflink/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Bamital</title>
		<link>http://www.registrycleanergeeks.com/trojan/bamital/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/bamital/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 12:15:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1744</guid>
		<description><![CDATA[Discovered: July 1, 2010 Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Bamital you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.Bamital. If your [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1744"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>July 1, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Bamital    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Bamital. </p>
<p>If your PC is also running slowly, you may be interested to look at <a href="http://www.registrycleanergeeks.com/registry-fix/review/">Registry Fix</a>.. Registry fix is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>Upon the Trojan being executed, the following files are created:</p>
<p> * %UserProfile%\Templates\memory.tmp<br />
  * %UserProfile%\Local Settings\Application Data\Windows Server\<br />
  [SIX RANDOM LETTERS].dll
</p>
<p>Then it will create the following registry entries:</p>
<p> * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\<br />
  Control\Session Manager\AppCertDlls\&quot;AppSecDll&quot; = &quot;%User<br />
  Profile%\Local Settings\Application Data\Windows Server\[SIX <br />
  RANDOM LETTERS].dll&quot;<br />
  * HKEY_CURRENT_USER\Software\[TEN RANDOM <br />
  LETTERS]\&quot;[TEN RANDOM LETTERS]&quot; = &quot;[BINARY DATA]&quot;<br />
  * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\<br />
  Services\sr\Parameters\&quot;FirstRun&quot; = &quot;1&quot;</p>
<p>Then these registry entries are deleted:<br />
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\&quot;DisableSR&quot; = &quot;1&quot;</p>
<p>Then the Trojan injects itself into these processes if they are found <br />
  to be running.</p>
<p> * cmdagent.exe<br />
  * fssm32.exe<br />
  * fsorsp.exe<br />
  * avp.exe<br />
  * iexplore.exe<br />
  * firefox.exe<br />
  * opera.exe<br />
  * explorer.exe
</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Bamital. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-070108-5941-99&#038;tabid=3" rel="nofollow">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/bamital/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan Bloodhound.PDF!gen2</title>
		<link>http://www.registrycleanergeeks.com/trojan/bloodhound-pdfgen2/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/bloodhound-pdfgen2/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 12:33:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1741</guid>
		<description><![CDATA[Discovered: June 7, 2010 Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Solaris, Windows Vista, Windows NT, Windows Server 2003, Linux, Windows 2000 Recommended Action: In order to Remove Trojan Bloodhound.PDF!gen2 you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan Bloodhound.PDF!gen2. [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1741"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>June 7, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Solaris, Windows Vista, Windows NT,   Windows Server 2003, Linux, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan Bloodhound.PDF!gen2    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan Bloodhound.PDF!gen2. </p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="510">
<tbody>
<tr class="blue">
<td width="478"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>Bloodhound.PDF!gen2 is a heuristic detection for potentially malicious <br />
  files that may exploit vulnerabilities in Adobe Reader in order to <br />
  perform further malicious actions.</p>
<p>This heuristic detection is used to detect threats associated with <br />
  the following Trojan family: Trojan.Pidief.J</p>
<p>Files that are detected as Bloodhound.PDF!gen2 may be malicious. 
</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan Bloodhound.PDF!gen2. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-060801-1301-99&#038;tabid=3" rel="nofollow">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/bloodhound-pdfgen2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Pidief.J</title>
		<link>http://www.registrycleanergeeks.com/trojan/pidief-j/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/pidief-j/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 12:04:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1738</guid>
		<description><![CDATA[Discovered: June 4, 2010 Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows 2000 Recommended Action: In order to Remove Trojan.Pidief.J you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.Pidief.J. If your PC is also [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1738"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>June 4, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows   NT, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Pidief.J     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Pidief.J. </p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="510">
<tbody>
<tr class="blue">
<td width="478"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>Once executed, the Trojan attempts to exploit Adobe Flash Player, <br />
  Acrobat Reader, and Acrobat &#8216;authplay.dll&#8217; Remote Code Execution <br />
  Vulnerability (BID 40586).</p>
<p>The Trojan then downloads a bitmap file from the following URL:<br />
  [http://]google-analytics.dynalias.org/intl/images/calc[REMOVED]</p>
<p>Note: The bitmap file contains an encrypted file (detected as Backdoor.Trojan).</p>
<p>The downloaded file is extracted to %Temp%\upt.exe and executed.</p>
<p>It then creates the following files:</p>
<p> * %Windir%\EventSystem.dll (detected as Backdoor.Trojan)<br />
  * %System%\qmgr.dll (detected as Backdoor.Trojan)<br />
  * %System%\dllcache\qmgr.dll (detected as Backdoor.Trojan)<br />
  * %System%\es.ini</p>
<p>Next, it copies the file %System%\qmgr.dll to %System%\kernel64.dll.</p>
<p>It then connects to the following URL:<br />
  [http://]google-analytics.dynalias.org/ddr/ddrh[REMOVED]
</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Pidief.J. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-060601-3020-99&#038;tabid=3" rel="nofollow">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/pidief-j/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Tarodrop.J</title>
		<link>http://www.registrycleanergeeks.com/trojan/tarodrop-j/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/tarodrop-j/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 09:50:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1734</guid>
		<description><![CDATA[Discovered: June 2, 2010 Type: Trojan Systems Affected: Windows XP, Windows Vista, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Tarodrop.J you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.Tarodrop.J. If your PC is also running slowly, you may be [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1734"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>June 2, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows XP, Windows Vista, Windows Server 2003, Windows   2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Tarodrop.J     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Tarodrop.J. </p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="510">
<tbody>
<tr class="blue">
<td width="478"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>The Trojan could arrive as a .jtd extension.</p>
<p>When opened, this file will attempt to exploit the JustSystems Ichitaro Character Attributes Processing Remote Code Execution Vulnerability (BID 40472).</p>
<p>Please Note: This issue can be fixed by the Ichitaro version 1.0.1.6 update patch program.</p>
<p>The Trojan will then possibly create these files:</p>
<p> * %Temp%\update.exe (Downloader)<br />
  * %System%\PMService.exe (Downloader)<br />
  * %Temp%\[DOUBLE BYTE FILE NAME].jtd<br />
  * %Temp%\[DOUBLE BYTE FILE NAME].jtd.$$$</p>
<p>The Trojan will then create the following registry subkey in order to register itself as a service:<br />
  HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\PMSservice</p>
<p>Then it will connect to the following location on TCP port 80:<br />
  [http://]update.winsdate.com/domestic/svcho[REMOVED]</p>
<p>It may then download and execute files from the above location.</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Tarodrop.J. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-060210-4533-99&#038;tabid=3" rel="nofollow">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/tarodrop-j/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Loginck</title>
		<link>http://www.registrycleanergeeks.com/trojan/loginck/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/loginck/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 11:02:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1731</guid>
		<description><![CDATA[Discovered: May 20, 2010 Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Loginck you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.Loginck. If your [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1731"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>May 20, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows   Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Loginck     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Loginck. </p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="510">
<tbody>
<tr class="blue">
<td width="478"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>The Loginck trojan can arrive on your computer in a variety of ways.</p>
<p>Once Loginck is executed, it contacts a predetermined server and downloads a list of stored user names and passwords for gaming websites.</p>
<p><strong>Note:</strong> The Trojan does not steal these account details. They have likely been gathered by other information-stealing threats.</p>
<p>The Trojan then tried to login to each of these accounts to determine their validity.</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Loginck. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-052013-2257-99&#038;tabid=3" rel="nofollow">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/loginck/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.GootKit</title>
		<link>http://www.registrycleanergeeks.com/trojan/gootkit/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/gootkit/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 09:18:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1723</guid>
		<description><![CDATA[Discovered: May 11, 2010 Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.GootKit you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.GootKit. If your [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1723"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>May 11, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows   Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.GootKit     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.GootKit. </p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="510">
<tbody>
<tr class="blue">
<td width="478"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>This Trojan can be picked up from spammed email messages or downloaded<br /> <br />
  through the web.</p>
<p>The Trojan drops the following DLL file:<br />
  %System%\msxsltsso.dll (detected as Trojan.Gootkit)</p>
<p>It then creates the following registry entry, to activated upon windows startup.<br />
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current<br />
  Version\ShellServiceObjectDelayLoad\&quot;GootkitSSO&quot; = &quot;{FE7D5E7C-3EAF<br />
  -47BC-89EF-CD279EA619DE}&quot;</p>
<p>It registers msxsltsso.dll as a COM object by creating the following registry <br />
  entries:</p>
<p> * HKEY_CLASSES_ROOT\CLSID\{0FDB33AF-96F2-4AD6-A737-<br />
  956138C470C5}\InProcServer32\&quot;(Default)&quot; = &quot;%System%\msxsltsso.dll&quot;<br />
  * HKEY_CLASSES_ROOT\CLSID\{FE7D5E7C-3EAF-47BC-89EF-<br />
  CD279EA619DE}\InProcServer32\&quot;(Default)&quot; = &quot;%System%\msxsltsso.dll&quot;</p>
<p>It then contacts the following remote location to download a custom <br />
  Command and Control file:<br />
  [http://]78.140.15.82/boot[REMOVED]</p>
<p>The Trojan acts as a botnet based on the Command and Control file and may <br />
  perform some of the following actions:</p>
<p> * Access predetermined remote locations<br />
  * Download and execute files, some of which may be additional malware<br />
  * Gather confidential information such as: CPU information, passwords <br />
  and FTP credentials<br />
  * Injects arbitrary JavaScript code into HTML files<br />
  * List, start, stop, and remove processes and threads<br />
  * List, create, modify and delete registry subkeys<br />
  * List, create, modify and delete files<br />
  * May modify content in an FTP server, including listing, uploading, and <br />
  deleting files<br />
  * Sends mail<br />
  * Uploads files from the compromised computer, including gathered <br />
  confidential information</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.GootKit. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-051118-0604-99&#038;tabid=3" rel="nofollow">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/gootkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Yimfoca</title>
		<link>http://www.registrycleanergeeks.com/worm/w32-yimfoca/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32-yimfoca/#comments</comments>
		<pubDate>Mon, 24 May 2010 21:27:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1718</guid>
		<description><![CDATA[Discovered: May 3, 2010 Type: Worm Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Yimfoca you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of W32.Yimfoca. If your [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1718"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>May 3, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Worm</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me,   Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Yimfoca     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Yimfoca. </p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="522">
<tbody>
<tr class="blue">
<td width="490"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>Upon the worm being executed the following files are created:<br />
  %Windir%\infocard.exe<br />
  %Windir%\mds.sys<br />
  %Windir%\mdt.sys<br />
  %Windir%\winbrd.jpg</p>
<p>Then the following registry entry is created to activate when windows starts:<br />
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current<br />
  Version\Run\&quot;Firewall Administrating&quot; = &quot;%Windir%\infocard.exe&quot;</p>
<p>The worm then attempts to connect to the following URL:<br />
  [http://]browseusers.myspace.com/Browse/Brows[REMOVED]</p>
<p>Then it stop the following windows processes that disable the Microsoft Malware <br />
  Protection Service and Windows Update:</p>
<p> * MsMpSvc<br />
  * wuauserv</p>
<p>Then it attempts to connect to the following URL to download a conig file:<br />
  [http://]get.articleslinked.com/univ[REMOVED]</p>
<p>Then it connects to the following network addresses on TCP port 2345 and waits<br /> <br />
  for the IRC commands:</p>
<p> * e2doo.org<br />
  * sls.e2doo.net
</p>
<p>The worm then searches Windows on the compromised computer for anything <br />
  belonging to Yahoo! Messenger.</p>
<p>The worm spreads by sending messages that contain links to copies of the worm<br /> <br />
  to all Yahoo! Messenger contacts.</p>
<p>The following messages may be sent by the worm:</p>
<p> * foto <img src='http://www.registrycleanergeeks.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  [http://]tusfbfotos.com/imag[REMOVED]<br />
  * foto <img src='http://www.registrycleanergeeks.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  [http://]kompnk.com/imag[REMOVED]<br />
  * foto <img src='http://www.registrycleanergeeks.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  [http://]beautyphotoson.com/imag[REMOVED]</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Yimfoca. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-050209-1610-99&#038;tabid=3" rel="nofollow">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32-yimfoca/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Ircbrute.C</title>
		<link>http://www.registrycleanergeeks.com/worm/w32-ircbrute-c/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32-ircbrute-c/#comments</comments>
		<pubDate>Tue, 18 May 2010 11:01:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1715</guid>
		<description><![CDATA[Discovered: April 20, 2010 Type: Worm Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP Recommended Action: In order to Remove W32.Ircbrute.C you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of W32.Ircbrute.C. If your [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1715"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>April 20, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Worm</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows   Server 2003, Windows Vista, Windows XP</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Ircbrute.C     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Ircbrute.C. </p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="523">
<tbody>
<tr class="blue">
<td width="491"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When this worm is executed, it continues to create these files.</p>
<p> * %SystemDrive%\Driver\Files\Desktop.ini<br />
    * %SystemDrive%\Driver\Files\DT.exe</p>
<p>Then it will assign the following registry entry to execute on the startup of Windows:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-01WE-AAX5-314CCA322142}\&quot;StubPath&quot; = &quot;%SystemDrive%\Driver\Files\DT.exe&quot;</p>
<p>The worm will then copy the following to all removable drives.</p>
<p> * %DriveLetter%\Driver\Files\DT.exe<br />
    * %DriveLetter%\Driver\Files\Desktop.ini<br />
    * %DriveLetter%\autorun.inf</p>
<p>&#8230;and then creates a backdoor to connect to these IRC servers.</p>
<p> * 4.darkogard.com<br />
    * ogard4.helldark.biz<br />
    * ogard4.ircdevils.net</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Ircbrute.C. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-042011-4346-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32-ircbrute-c/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Terred</title>
		<link>http://www.registrycleanergeeks.com/trojan/terred/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/terred/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 19:11:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1705</guid>
		<description><![CDATA[Discovered: April 9, 2010 Type: Virus Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Terred you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.Terred. Read our [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1705"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>April 9, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Virus</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows   Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Terred     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Terred. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at  <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="523">
<tbody>
<tr class="blue">
<td width="491"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>Its quite possible that this Trojan may enter your machine as a .cab <br />
  file.</p>
<p>Once the .cab file is opened, the Trojan creates a Windows Telephony <br />
  file called: %CurrentFolder%\1.dll</p>
<p>The Terred Trojan will then create the following malicious dialer <br />
  program file: %CurrentFolder%\reg.exe</p>
<p>It will then copy that file to the following location: <br />
  %Windir%\smart32.exe</p>
<p>The Trojan will then create this registry entry:<br />
  HKEY_CURRENT_USER\Alpha\&quot;Status&quot; = &quot;1&quot;</p>
<p>Then it will automatically attempt to call these high-cost <br />
  international phone numbers:</p>
<p> * 8823460777<br />
  * 17675033611<br />
  * 88213213214<br />
  * 25240221601</p>
</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Terred. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-040915-5609-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/terred/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Difupat</title>
		<link>http://www.registrycleanergeeks.com/virus/w32-difupat/</link>
		<comments>http://www.registrycleanergeeks.com/virus/w32-difupat/#comments</comments>
		<pubDate>Sun, 25 Apr 2010 18:19:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1703</guid>
		<description><![CDATA[Discovered: April 1, 2010 Type: Virus Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Difupat you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of W32.Difupat. Read our [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1703"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>April 1, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Virus</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows   Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Difupat     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Difupat. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at  <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="523">
<tbody>
<tr class="blue">
<td width="491"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When W32.Difupat is executed, it places an executable .rar file, named:<br />
  %System%\reinstall.exe</p>
<p>Then, it will delete the following file from your PC.<br />
  %ProgramFiles%\Internet Explorer\IEXPLORE.EXE</p>
<p>Then the virus replaces IEXPLORE.EXE with its own copy of the file.</p>
<p>It also places the following files on your machine.</p>
<p> * %ProgramFiles%\Internet Explorer\bootloader.dll<br />
  * %ProgramFiles%\Internet Explorer\detoured.dll<br />
  * %ProgramFiles%\Internet Explorer\funcition.dll<br />
  * %ProgramFiles%\Internet Explorer\funcition.ini<br />
  * %ProgramFiles%\Internet Explorer\install.exe<br />
  * %ProgramFiles%\Internet Explorer\pserver.exe<br />
  * %ProgramFiles%\Internet Explorer\pserver.ini<br />
  * %System%\Internet Explorer\bootloader.dll<br />
  * %System%\Internet Explorer\detoured.dll<br />
  * %System%\Internet Explorer\funcition.dll<br />
  * %System%\Internet Explorer\funcition.ini<br />
  * %System%\Internet Explorer\iexplore.exe<br />
  * %System%\Internet Explorer\install.exe<br />
  * %System%\Internet Explorer\pserver.exe<br />
  * %System%\Internet Explorer\pserver.ini</p>
<p>It will then create the following registry values in Windows Startup:</p>
<p> * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\<br />
  Winlogon\Notify\getpass\&quot;DllName&quot; = &quot;bootloader.dll&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\<br />
  Winlogon\Notify\getpass\&quot;Logon&quot; = &quot;OnEventShutDown&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\<br />
  Winlogon\Notify\getpass\&quot;Shutdown&quot; = &quot;OnEventShutDown&quot;
</p>
<p>When your PC Reboots, bootloader.dll loads the following into memory:</p>
<p> * %System%/funcition.dll<br />
  * %System%/pserver.exe
</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Difupat. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-040208-1901-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/virus/w32-difupat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Backdoor.Dawcun</title>
		<link>http://www.registrycleanergeeks.com/trojan/backdoor-dawcun/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/backdoor-dawcun/#comments</comments>
		<pubDate>Sat, 24 Apr 2010 16:34:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1700</guid>
		<description><![CDATA[Discovered: April 1, 2010 Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Backdoor.Dawcun you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Backdoor.Dawcun. Read our [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1700"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>April 1, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows   Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Backdoor.Dawcun     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Backdoor.Dawcun. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at  <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="523">
<tbody>
<tr class="blue">
<td width="491"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When Backdoor.Dawcun is executed It creates a service by adding entries to this registry   subkey so that it runs on Windows Startup.</p>
<p>  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[TROJAN<br /> <br />
  FILE NAME]</p>
<p>  It then creates the following registry subkeys so that it   restarts in safe mode:
</p>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safe<br />
    Boot\Minimal\[TROJAN   FILE NAME]</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safe<br />
    Boot\Network\[TROJAN   FILE NAME]</li>
</ul>
<p>The Backdoor.Dawcun Trojan captures registry access to   prevent modifying and deleting registry key values.</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Backdoor.Dawcun. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-040116-0914-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/backdoor-dawcun/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan Dosvine</title>
		<link>http://www.registrycleanergeeks.com/trojan/dosvine/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/dosvine/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 14:30:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1697</guid>
		<description><![CDATA[Discovered: March 31, 2010 Type: Trojan Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP Recommended Action: In order to Remove Trojan.Dosvine you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.Dosvine. Read our [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1697"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>March 31, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows   Server 2003, Windows Vista, Windows XP</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Dosvine     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Dosvine. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at  <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="512">
<tbody>
<tr class="blue">
<td width="480"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When the Dosvine Trojan is executed, it creates this file:<br />
  %System%\msconfig32.sys</p>
<p>It then creates these registry entries in Windows Startup</p>
<p> * HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\<br />
  Run\&quot;Adobe Update Manager&quot; = &quot;[PATH TO ORIGINAL EXECUTABLE]&quot;<br />
  * HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\&quot;Userinit&quot; = &quot;C:\WINDOWS\system32\userinit.<br />
  exe, [PATH TO ORIGINAL EXECUTABLE]&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current<br />
  Version\Run\&quot;Adobe Update Manager&quot; = &quot;[PATH TO ORIGINAL <br />
  EXECUTABLE]&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&quot;Userinit&quot; = &quot;C:\WINDOWS\system32\userinit.<br />
  exe, [PATH TO ORIGINAL EXECUTABLE]&quot;
</p>
<p>The Dosvine Trojan then attempts to download a config file from:<br />
  [http://]www.update-adobe.com/info[REMOVED]</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Dosvine. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-033116-1305-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/dosvine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Mebratix</title>
		<link>http://www.registrycleanergeeks.com/trojan/mebratix/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/mebratix/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 16:09:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1691</guid>
		<description><![CDATA[Discovered: March 18, 2010 Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Mebratix you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.Mebratix. Read our [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1691"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>March 18, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows   NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Mebratix     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Mebratix. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="516">
<tbody>
<tr class="blue">
<td width="484"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When Trojan.Mebratix is downloaded and executed on the host machine it copies the MBR to another location on your HDD. It then overwrites   the original MBR with its own code.
</p>
<p>&#8230;and then the trojan creates the following files.</p>
<ul>
<li>C:\Program Files\MSDN\atixi.inf</li>
<li>C:\Program   Files\MSDN\atixx.sys</li>
<li>C:\WINDOWS\inf\oem22.inf</li>
<li>C:\WINDOWS\inf\oem22.PNF</li>
<li>C:\WINDOWS\inf\oem23.inf</li>
<li>C:\WINDOWS\inf\oem23.PNF</li>
<li>C:\WINDOWS\system32\drivers\atixi.sys</li>
<li>C:\WINDOWS\system32\drivers\atixx.sys</li>
<li>C:\WINDOWS\LastGood\INF\oem22.inf</li>
<li>C:\WINDOWS\LastGood\INF\oem22.PNF</li>
<li>C:\WINDOWS\LastGood\INF\oem23.inf</li>
<li>C:\WINDOWS\LastGood\INF\oem23.PNF</li>
</ul>
<p>Be aware that it may also create the following registry entries..</p>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class<br />
      \{02EB6841-28D2-44C2-8303-584F54E6D913}</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\<br />
      ATIXI\0000</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\LastKnownGoodRecovery\<br />
      LastGood\INF</li>
</ul>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Mebratix. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-031904-4823-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/mebratix/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove JS.Sykipot</title>
		<link>http://www.registrycleanergeeks.com/trojan/js-sykipot/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/js-sykipot/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 10:31:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1688</guid>
		<description><![CDATA[Discovered: March 9, 2010 Type: Trojan Systems Affected: Windows XP, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove JS.Sykipot you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of JS.Sykipot. Read our full No Adware Review If your [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1688"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>March 9, 2010</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows XP, Windows Vista, Windows NT, Windows Server   2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove JS.Sykipot     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of JS.Sykipot. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="509">
<tbody>
<tr class="blue">
<td width="477"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>JS.Sykipot is a Trojan horse that affects Microsoft Internet Explorer.</p>
<p>When the  file is executed, it may create one of these  files:</p>
<p>* %UserProfile%\Local Settings\Temporary Internet Files\20100307.htm</p>
<p>* %UserProfile%\Local Settings\Temporary Internet Files\20100307[1].htm</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove JS.Sykipot. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-031014-2034-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/js-sykipot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Suspicious.SecTool</title>
		<link>http://www.registrycleanergeeks.com/virus/suspicious-sectool/</link>
		<comments>http://www.registrycleanergeeks.com/virus/suspicious-sectool/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 13:13:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1669</guid>
		<description><![CDATA[Discovered: February 26, 2010 Updated: February 26, 2010 12:42:12 AM Type: Virus Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP Recommended Action: In order to Remove Suspicious.SecTool you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1669"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>February 26, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">February 26, 2010 12:42:12 AM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Virus</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows   Server 2003, Windows Vista, Windows XP</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Suspicious.SecTool     you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Suspicious.SecTool. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="509">
<tbody>
<tr class="blue">
<td width="477"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>Symantec’s antivirus products contain an highly sensitive detection technology designed to detect entirely new malware threats without traditional signatures. This technology is aimed at detecting malicious software that has been intentionally mutated or morphed by attackers.</p>
<p>If one or more files on your computer have been classified as having a Suspicious.SecTool threat, this indicates that the files have suspicious characteristics and therefore might contain a new or unknown threat. However, given the sensitive nature of this detection technology, it may occasionally identify non-malicious, legitimate software programs that also share these behavioral characteristics. Therefore, it is recommended that users manually check all files detected as Suspicious.SecTool by Symantec antivirus products for potential misidentification, and submit any suspect files to Symantec Security Response for further analysis. For instructions on how to do this, read Submit Virus Samples.</p>
<p>In rare cases where a legitimate file has been misidentified and subsequently quarantined, your computer may behave abnormally or you may find that one or more applications no longer function as expected. In such rare situations, you should open the Quarantine in your Symantec antivirus product. From here, you may review the list of all files detected as Suspicious.SecTool and, if you identify a potential misidentification, restore the file from quarantine and allow it to run normally.</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Suspicious.SecTool. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-022522-2204-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/virus/suspicious-sectool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove SymbOS.Exy.E</title>
		<link>http://www.registrycleanergeeks.com/worm/symbos-exy-e/</link>
		<comments>http://www.registrycleanergeeks.com/worm/symbos-exy-e/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 09:09:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1666</guid>
		<description><![CDATA[Discovered: February 26, 2010 Type: Worm Systems Affected: Symbian OS Overview: &#160; SymbOS.Exy.E is a worm based upon the Symbian OS that propogates by utilizing the multimedia messaging service (MMS). Recommended Action: In order to Remove SymbOS.Exy.E you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1666"></span><br />
<table width="500" border="0" cellpadding="10" cellspacing="2">
<tr class="blue">
<td><strong>Discovered:</strong></td>
<td>February 26, 2010</td>
</tr>
<tr>
<td><strong>Type: </strong></td>
<td>Worm</td>
</tr>
<tr class="blue">
<td><strong>Systems Affected: </strong></td>
<td>Symbian OS</td>
</tr>
<tr>
<td>
<p><strong>Overview:</strong></p>
<p>&nbsp;</p>
</td>
<td>SymbOS.Exy.E is a worm based upon the Symbian OS that propogates by utilizing the multimedia messaging service (MMS).</td>
</tr>
</table>
<p><!--more--></p>
<table width="500" border="0" cellpadding="10" cellspacing="2">
<tr class="blue">
<td><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td><img src="/images/1.jpg" alt="" /> In order to Remove SymbOS.Exy.E    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of SymbOS.Exy.E. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="509">
<tbody>
<tr class="blue">
<td width="477"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>The SymbOS.Exy.E worm creates the following files:
  </p>
<p>* C:\sys\bin\Installer_SV.exe</p>
<p>* C:\sys\bin\LanPackage.exe</p>
<p>* C:\private\101f875a\import\[20028B98].rsc</p>
<p>* C:\private\101f875a\startup\[20028B98].dat</p>
<p>* C:\private\20028B98\SisInfo.cfg</p>
<p>* C:\private\20028B98\Source.ini</p>
<p>It also create the following temporary files, which it deletes when the threat finishes installing:</p>
<p>* C:\system\data\Local_Para.txt</p>
<p>* C:\system\data\Remote_Para.txt</p>
<p>* C:\system\data\SisInfo.cfg</p>
<p>* C:\system\data\Source.ini</p>
<p>The worm then updates itself by downloading the following temporary file:</p>
<p>C:\private\20028B98\kel.sisx</p>
<p>..and then the following processes if they are running:</p>
<p>* AppMngr</p>
<p>* TaskSpy</p>
<p>* Y-Tasks</p>
<p>* ActiveFile</p>
<p>* TaskMan</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove SymbOS.Exy.E. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-022514-4158-99&amp;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/symbos-exy-e/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Pcprotector</title>
		<link>http://www.registrycleanergeeks.com/trojan/pcprotector/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/pcprotector/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 16:59:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1660</guid>
		<description><![CDATA[Discovered: February 23, 2010 Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Pcprotector you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.Pcprotector. Read our [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1660"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>February 23, 2010</td>
</tr>
<tr>
<td width="81"></td>
<td width="373"></td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Pcprotector    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Pcprotector. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="509">
<tbody>
<tr class="blue">
<td width="477"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>The Trojan may arrive on the compromised computer as a manually install or may</p>
<p>be downloaded by other malware with the following install name:</p>
<p>Your PC Protector</p>
<p>Once executed, the Trojan creates the following files:</p>
<p>* C:\Documents and Settings\All Users\Desktop\Your PC Protector.lnk</p>
<p>* %ProgramFiles%\adc32.dll</p>
<p>* %ProgramFiles%\alggui.exe</p>
<p>* %ProgramFiles%\nuar.old</p>
<p>* %ProgramFiles%\schtml\dbsinit.exe</p>
<p>* %ProgramFiles%\schtml\images\i1.gif</p>
<p>* %ProgramFiles%\schtml\images\i2.gif</p>
<p>* %ProgramFiles%\schtml\images\i3.gif</p>
<p>* %ProgramFiles%\schtml\images\j1.gif</p>
<p>* %ProgramFiles%\schtml\images\j2.gif</p>
<p>* %ProgramFiles%\schtml\images\j3.gif</p>
<p>* %ProgramFiles%\schtml\images\jj1.gif</p>
<p>* %ProgramFiles%\schtml\images\jj2.gif</p>
<p>* %ProgramFiles%\schtml\images\jj3.gif</p>
<p>* %ProgramFiles%\schtml\images\l1.gif</p>
<p>* %ProgramFiles%\schtml\images\l2.gif</p>
<p>* %ProgramFiles%\schtml\images\l3.gif</p>
<p>* %ProgramFiles%\schtml\images\pix.gif</p>
<p>* %ProgramFiles%\schtml\images\t1.gif</p>
<p>* %ProgramFiles%\schtml\images\t2.gif</p>
<p>* %ProgramFiles%\schtml\images\Thumbs.db</p>
<p>* %ProgramFiles%\schtml\images\up1.gif</p>
<p>* %ProgramFiles%\schtml\images\up2.gif</p>
<p>* %ProgramFiles%\schtml\images\w1.gif</p>
<p>* %ProgramFiles%\schtml\images\w11.gif</p>
<p>* %ProgramFiles%\schtml\images\w2.gif</p>
<p>* %ProgramFiles%\schtml\images\w3.gif</p>
<p>* %ProgramFiles%\schtml\images\w3.jpg</p>
<p>* %ProgramFiles%\schtml\images\word.doc</p>
<p>* %ProgramFiles%\schtml\images\wt1.gif</p>
<p>* %ProgramFiles%\schtml\images\wt2.gif</p>
<p>* %ProgramFiles%\schtml\images\wt3.gif</p>
<p>* %ProgramFiles%\schtml\wispex.html</p>
<p>* %ProgramFiles%\skynet.dat</p>
<p>* %ProgramFiles%\some.dat</p>
<p>* %ProgramFiles%\svchost.exe</p>
<p>* %ProgramFiles%\wp3.dat</p>
<p>* %ProgramFiles%\wp4.dat</p>
<p>* %ProgramFiles%\Your PC Protector</p>
<p>* %ProgramFiles%\Your PC Protector\Your PC Protector.exe</p>
<p>* %Temp%\8fc</p>
<p>* %UserProfile%\Start Menu\Programs\Your PC Protector</p>
<p>* %UserProfile%\Start Menu\Programs\Your PC Protector\Your PC Protector.</p>
<p>lnk</p>
<p>* %Windir%\Temp\8fc</p>
<p>* %Windir%\Temp\a7b</p>
<p>It creates the following registry entries:</p>
<p>* HKEY_CLASSES_ROOT\CLSID\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}\&#8221;(Default)&#8221; = &#8220;ADC PlugIn&#8221;</p>
<p>* HKEY_CLASSES_ROOT\CLSID\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}\InprocServer32\&#8221;(Default)&#8221; = &#8220;%SYSTEM%\Program</p>
<p>Files\adc32.dll&#8221;</p>
<p>* HKEY_CLASSES_ROOT\CLSID\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}\InprocServer32\&#8221;ThreadingModel&#8221; = &#8220;Apartment&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Your PC Protector\Your PC</p>
<p>Protector\setdata\&#8221;scantime&#8221; = &#8220;[CURRENT TIMESTAMP]&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Your PC Protector\Your PC</p>
<p>Protector\setdata\&#8221;scantime&#8221; = &#8220;[CURRENT TIMESTAMP]&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Your PC Protector\Your PC</p>
<p>Protector\setdata\&#8221;scncnt&#8221; = &#8220;[NUMBER]&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\Adb</p>
<p>Upd\&#8221;DisplayName&#8221; = &#8220;Adobe Update Service&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\Adb</p>
<p>Upd\&#8221;ErrorControl&#8221; = &#8220;0&#215;00000001&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\Adb</p>
<p>Upd\&#8221;ImagePath&#8221; = &#8220;%SYSTEM%\Program Files\svchost.exe&#8221;"</p>
<p>* HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\Adb</p>
<p>Upd\&#8221;ObjectName&#8221; = &#8220;LocalSystem&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\Adb</p>
<p>Upd\&#8221;Start&#8221; = &#8220;0&#215;00000002&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Adb</p>
<p>Upd\&#8221;Type&#8221; = &#8220;0&#215;00000010&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Adb</p>
<p>Upd\Security\&#8221;Security&#8221; = &#8220;[DATA]&#8221;</p>
<p>It then modifies the following registry entries:</p>
<p>* HKEY_CLASSES_ROOT\exefile\shell\open\command\&#8221;(Default)&#8221; =</p>
<p>&#8220;% SYSTEM%\Program Files\alggui.exe &#8220;%1&#8243; %*&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar</p>
<p>\&#8221;Locked&#8221; = &#8220;0&#215;00000001&#8243;</p>
<p>The Trojan then prevents other applications from being executed and displays</p>
<p>the following false error messages:</p>
<p>Title: Warning!</p>
<p>Body: Running of application is impossible.</p>
<p>The file [FILE PATH AND NAME] is infected.</p>
<p>Please activate your antivirus program.</p>
<p>The Trojan may also display any of the following warning messages:</p>
<p>Title: Warning infection is detected</p>
<p>Body: Windows has found spyware infection on your computer!</p>
<p>Click here to update your Windows antivirus software&#8230;</p>
<p>Title: Security Warning</p>
<p>Body: Your computer continues to be infected with harmful viruses.</p>
<p>In order to prevent permanent loss of your information and</p>
<p>credit card data theft please activate your antivirus software.</p>
<p>Click here to enable protection.</p>
<p>Title: Security Warning</p>
<p>Body: There are critical system files on your computer that were</p>
<p>modified by malicious program.</p>
<p>It will cause unstable work of your system and permanent</p>
<p>data loss.</p>
<p>Click here to undo performed modifications and remove</p>
<p>malicious software (Highly recommended).</p>
<p>The Trojan also displays the following scan interface:</p>
<p>Title: Your PC Protector</p>
<p>Body: Scanning for viruses</p>
<p>It then displays the false results of the misleading scan:</p>
<p>Title: Warning 3 infection found</p>
<p>Body: Unwanted software (malware) or tracking cookies have been found</p>
<p>during last scan. It is highly recommended to remove it from your computer.</p>
<p>Title: Items Detected</p>
<p>Body: Your PC Protector has found infected documents or programs.</p>
<p>You can lose your personal data and infect other network computers.</p>
<p>It may also display the following fake Microsoft error messages:</p>
<p>Title: Windows Security Center</p>
<p>Body: Security Center</p>
<p>Help protect your PC</p>
<p>Title: svchost.exe</p>
<p>Body: svchost.exe has encountered a problem and needs to</p>
<p>close. We are sorry for the inconvenience.</p>
<p>The Trojan then displays the following requests for payment:</p>
<p>Title: Your PC Protector evaluation</p>
<p>Body: This version of Your PC Protector is for evaluation purposes only.</p>
<p>The removal feature is disabled. You may scan your PC to locate malware</p>
<p>threats.</p>
<p>Please purchase the full version of Your PC Protector to remove identified</p>
<p>threats.</p>
<p>Title: Bright Red Warning Symbol</p>
<p>Body: Are you sure? Your PC will not be protected against spyware.</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Pcprotector. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-022319-3715-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/pcprotector/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Xpiro.B</title>
		<link>http://www.registrycleanergeeks.com/virus/w32-xpiro-b/</link>
		<comments>http://www.registrycleanergeeks.com/virus/w32-xpiro-b/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 15:48:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1657</guid>
		<description><![CDATA[Discovered: February 23, 2010 Updated: February 23, 2010 12:57:33 PM Type: Virus Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Xpiro.B you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1657"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>February 23, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">February 23, 2010 12:57:33 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Virus</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Xpiro.B    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Xpiro.B. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="495">
<tbody>
<tr class="blue">
<td width="463"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>The virus may arrive as a file with the following file name:<br />
  %CurrentFolder%\7z.exe</p>
<p>When the virus is executed, it infects all .exe files on the compromised computer.</p>
<p>It then monitors connections to the Internet, gathering sensitive information.</p>
<p>The virus also scans the registry, gathering user names and passwords stored within it.</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Xpiro.B. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-022311-4358-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/virus/w32-xpiro-b/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Infostealer.Saluni</title>
		<link>http://www.registrycleanergeeks.com/trojan/infostealer-saluni/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/infostealer-saluni/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 10:14:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1654</guid>
		<description><![CDATA[Discovered: February 7, 2010 Updated: February 17, 2010 2:47:10 PM Type: Trojan Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP Recommended Action: In order to Remove Infostealer.Saluni you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1654"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>February 7, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">February 17, 2010 2:47:10 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Infostealer.Saluni    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Infostealer.Saluni. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="495">
<tbody>
<tr class="blue">
<td width="463"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When the Trojan is executed, it creates the following file:<br />
  %System%\kernel.exe</p>
<p>Next, the Trojan creates the following registry entry so that it executes <br />
    whenever Windows starts:<br />
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\<br />
    Run\&quot;default&quot; = &quot;%System%\kernel.exe&quot;</p>
<p>The Trojan then steals information from the compromised computer, including passwords related to the following applications:</p>
<p> * DynDNS<br />
    * Firefox<br />
    * FlashFXP<br />
    * Google<br />
    * IMVU<br />
    * Internet Explorer 7<br />
    * Internet Explorer 8<br />
    * MSN<br />
    * NO-IP<br />
    * Paypal<br />
    * Pidgin<br />
    * Steam<br />
    * Trillian<br />
    * Yahoo</p>
<p>The Trojan saves the stolen information in the following locations:</p>
<p> * %Temp%\keylog.dat<br />
    * %Temp%\Pass.dat</p>
<p>Next, it sends the stolen information to a remote location either using FTP or <br />
    in the form of an email.</p>
<p>The Trojan may display the following message:<br />
    Title:<br />
    Error<br />
    Message:<br />
    Run-time error &#8217;429&#8242;</p>
<p>It may download a configurable file from a remote server.</p>
<p>The Trojan may also cause the compromised computer to crash, displaying <br />
    a Blue Screen of Death.</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Infostealer.Saluni. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-021712-4235-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/infostealer-saluni/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Thuxeme!inf</title>
		<link>http://www.registrycleanergeeks.com/trojan/thuxemeinf/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/thuxemeinf/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 12:01:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1651</guid>
		<description><![CDATA[Discovered: February 16, 2010 Updated: February 16, 2010 2:31:25 PM Type: Trojan Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP Recommended Action: In order to Remove Trojan.Thuxeme!inf you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1651"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>February 16, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">February 16, 2010 2:31:25 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Thuxeme!inf    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Thuxeme!inf. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>This is a detection for an infected copy of the %System%\UxTheme.dll file, often created by the Trojan.Bredolab family of threats.</p>
<p>The original DLL is copied to the following file:</p>
<p>%System%\UxTheme.dll~[EIGHT RANDOM CHARACTERS].TMP</p>
<p>The purpose of this infection is to load a malicious DLL named msls51.dll.</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Thuxeme!inf. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-021614-3125-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/thuxemeinf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Changeup.B</title>
		<link>http://www.registrycleanergeeks.com/worm/w32-changeup-b/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32-changeup-b/#comments</comments>
		<pubDate>Sat, 20 Feb 2010 13:13:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1648</guid>
		<description><![CDATA[Discovered: February 10, 2010 Updated: February 11, 2010 8:44:37 AM Type: Worm Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Changeup.B you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1648"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>February 10, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">February 11, 2010 8:44:37 AM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Worm</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Changeup.B    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Changeup.B. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When executed, the worm copies itself as the following file:<br />
%SystemDrive%\VIDI\UNUK\DRG.exe</p>
<p>The worm then creates the following file:<br />
  %SystemDrive%\VIDI\UNUK\DesKTop.ini</p>
<p>It then creates the following registry entry so that it runs every time Windows starts:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-01WE-AAX2-5657QCA554112}\&quot;StubPath&quot; = &quot;%SystemDrive%\VIDI\UNUK\DRG.exe&quot;</p>
<p>The worm attempts to download files from the following network addresses:</p>
<p> * acc008.homeip.net<br />
  * acc7hr33.webhop.biz<br />
  * ogard6.ircdevils.net</p>
<p>Note: The downloaded files may be updates to the worm.</p>
<p>The worm spreads by copying itself to all removable drives as the following file: %DriveLetter%\VIDI\UNUK\DRG.exe</p>
<p>It also creates the following file: %DriveLetter%\VIDI\UNUK\DesKTop.ini</p>
<p>The worm creates the following file so that it runs when the above drives are accessed: %DriveLetter%\aUtOrUn.inf</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Changeup.B. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-021107-3818-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32-changeup-b/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Backdoor.Mulkerv</title>
		<link>http://www.registrycleanergeeks.com/trojan/backdoor-mulkerv/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/backdoor-mulkerv/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 13:46:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1645</guid>
		<description><![CDATA[Discovered: February 9, 2010 Updated: February 10, 2010 10:01:17 AM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Backdoor.Mulkerv you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1645"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>February 9, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">February 10, 2010 10:01:17 AM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Backdoor.Mulkerv    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Backdoor.Mulkerv. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>It has been reported that this threat is installed as the following file:<br />
  %SystemDrive%\mmsvc.cpl
  </p>
<p>When the Trojan is executed, it creates one of following services:</p>
<p> * NVMonSystem<br />
    * NPKClient<br />
    * ALGEvent</p>
<p>It then modifies the following registry entries:</p>
<p> * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;MaxHashTableSize&quot; = &quot;800&quot;<br />
    * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;MaxUserPort&quot; = &quot;FFFE&quot;<br />
    * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;TcpMaxConnectResponseRetransmissions&quot; = &quot;2&quot;<br />
    * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;TcpTimedWaitDelay&quot; = &quot;1E&quot;<br />
    * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;TCPFinWait2Delay&quot; = &quot;1E&quot;<br />
    * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;TcpMaxPortsExhausted&quot; = &quot;5&quot;<br />
    * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;TcpMaxHalfOpen&quot; = &quot;500&quot;<br />
    * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;TcpMaxHalfOpenRetried&quot; = &quot;400&quot;<br />
    * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;TcpMaxDataRetransmissions&quot; = &quot;A&quot;<br />
    * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;KeepAliveTime&quot; = &quot;493E0&quot;<br />
    * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\<br />
    Parameters\&quot;KeepAliveInterval&quot; = &quot;3E8&quot;<br />
    * HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\<br />
    Internet Settings\&quot;MaxConnectionsPer1_0Server&quot; = &quot;2&quot;<br />
    * HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\<br />
    Internet Settings\&quot;MaxConnectionsPerServer&quot; = &quot;2&quot;<br />
    * HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\<br />
    Internet Settings\&quot;MaxConnectionsPer1_0Server&quot; = &quot;2&quot;<br />
    * HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\<br />
    Internet Settings\&quot;MaxConnectionsPerServer&quot; = &quot;2&quot;</p>
<p>It then attempts to open a back door by connecting to one of following locations,<br /> <br />
    allowing a remote attacker access to the compromised computer:</p>
<p> * [RANDOM CHARACTERS].55cn90001.selfip.com<br />
    * [RANDOM CHARACTERS].59cn80801.selfip.com<br />
    * [RANDOM CHARACTERS].59cn81811.selfip.com<br />
    * [RANDOM CHARACTERS].b59e40004.selfip.com<br />
    * [RANDOM CHARACTERS].59cn80001.selfip.com<br />
    * [RANDOM CHARACTERS].55cn90002.selfip.net<br />
    * [RANDOM CHARACTERS].59cn80802.selfip.net<br />
    * [RANDOM CHARACTERS].59cn81812.selfip.net<br />
    * [RANDOM CHARACTERS].b59e40005.selfip.net<br />
    * [RANDOM CHARACTERS].59cn80002.selfip.net<br />
    * [RANDOM CHARACTERS].59cn80803.homeip.net<br />
    * [RANDOM CHARACTERS].b59e40001.homeip.net<br />
    * [RANDOM CHARACTERS].59cn80003.homeip.net<br />
    * [RANDOM CHARACTERS].59cn81813.homeip.net<br />
    * [RANDOM CHARACTERS].b59e40002.homeftp.org<br />
    * [RANDOM CHARACTERS].b59e40003.homeftp.net<br />
    * [RANDOM CHARACTERS].59cn80804.gotdns.com<br />
    * [RANDOM CHARACTERS].59cn81814.gotdns.com<br />
    * [RANDOM CHARACTERS].59cn80004.gotdns.com<br />
    * [RANDOM CHARACTERS].59cn80805.blogdns.com<br />
    * [RANDOM CHARACTERS].59cn80005.blogdns.com<br />
    * [RANDOM CHARACTERS].59cn81815.blogdns.com<br />
    * 58.221.33.164<br />
    * 58.221.33.171</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Backdoor.Mulkerv. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-021006-2252-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/backdoor-mulkerv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Wuwo</title>
		<link>http://www.registrycleanergeeks.com/trojan/wuwo/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/wuwo/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 18:49:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1642</guid>
		<description><![CDATA[Discovered: February 8, 2010 Updated: February 8, 2010 4:12:24 PM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Wuwo you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1642"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>February 8, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">February 8, 2010 4:12:24 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Wuwo    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Wuwo. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="499">
<tbody>
<tr class="blue">
<td width="467"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>This Trojan may arrive as a PDF or Microsoft Office file.</p>
<p>When the Trojan is executed, it drops the following file:</p>
<p>%Temp%\wuweb.exe</p>
<p>Next, the Trojan creates the following registry entry so that the dropped file</p>
<p>executes whenever Windows starts:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current</p>
<p>Version\Run\&#8221;wuweb&#8221; = &#8220;%Temp%\wuweb.exe&#8221;</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Wuwo. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-020815-0936-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/wuwo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Sasfis</title>
		<link>http://www.registrycleanergeeks.com/trojan/sasfis/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/sasfis/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 16:59:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1639</guid>
		<description><![CDATA[Discovered: February 2, 2010 Updated: February 2, 2010 3:05:33 PM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Sasfis you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1639"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>February 2, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">February 2, 2010 3:05:33 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Sasfis    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Spyeye. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="505">
<tbody>
<tr class="blue">
<td width="473"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When the Trojan is executed, it creates the following file:<br />
  %Temp%\1.tmp
  </p>
<p>The worm modifies the following registry entry:<br />
    HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Security\&quot;<br />
    AccessVBOM&quot; = &quot;1&quot;</p>
<p>It then opens Microsoft Word, if it is installed, and runs a VBA script that<br /> <br />
    loads %Temp%\1.tmp and executes it.</p>
<p>The Trojan then opens an instance of svchost.exe and injects itself into the <br />
    service.</p>
<p>It then copies itself as the following DLL file:<br />
    %System%\[RANDOMLY NAMED FILE]</p>
<p>Note: [RANDOMLY NAMED FILE] is a variable for the file name. It is <br />
    made up of a random four-letter file name and a random three-letter file <br />
    extension.</p>
<p>The Trojan creates the following subkey:<br />
    HKEY_CLASSES_ROOT\idid</p>
<p>The Trojan then deletes the original executable.</p>
<p>The Trojan modifies the following registry entry, so that it starts when Windows <br />
    starts:<br />
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&quot;Shell&quot; = &quot; Explorer.exe rundll32.exe %System%\[RANDOMLY NAMED FILE] [5 OR 6 RANDOM CHARA<br />
    CTERS]&quot;</p>
<p>It then connects to the following IP address using HTTP on TCP port 80:<br />
    193.104.27.91</p>
<p>The Trojan may then download and execute additional files.</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Sasfis. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-020210-5440-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/sasfis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Spyeye</title>
		<link>http://www.registrycleanergeeks.com/trojan/spyeye/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/spyeye/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 14:52:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1636</guid>
		<description><![CDATA[Discovered: February 3, 2010 Updated: February 3, 2010 3:27:14 PM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Spyeye you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1636"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>February 3, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">February 3, 2010 3:27:14 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Spyeye    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Spyeye. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="515">
<tbody>
<tr class="blue">
<td width="483"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>This threat must be manually installed on the computer. It may also be distributed by other means, such as Web Exploit Toolkits.</p>
<p>When the Trojan is executed, it drops the following configuration file, which is a</p>
<p>password-protected ZIP archive:</p>
<p>%SystemDrive%\cleansweep.exe\config.bin</p>
<p>It also drops the following file, which contains a hard-coded password to decrypt</p>
<p>the above configuration file:</p>
<p>%SystemDrive%\cleansweep.exe\cleansweep.exe</p>
<p>Next, the Trojan creates the following registry entry so that it executes whenever</p>
<p>Windows starts:</p>
<p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\</p>
<p>&#8220;cleansweep.exe&#8221; = &#8220;%SystemDrive%\cleansweep.exe\cleansweep.exe&#8221;</p>
<p>The Trojan then injects code into any currently running system processes so that</p>
<p>it can then perform the following functions:</p>
<p>* Capture network traffic</p>
<p>* Send and receive network packets in order to bypass application firewalls</p>
<p>It also provides certain rootkit capabilities, for example it can:</p>
<p>* Hide its own process on injected processes</p>
<p>* Hide and prevent access to its own binary code</p>
<p>* Hide and prevent access to its startup registry entry</p>
<p>The Trojan then steals information from the following Internet browsers:</p>
<p>* Firefox</p>
<p>* Internet Explorer</p>
<p>* Maxthon</p>
<p>It sends the stolen information back to a control server, which is specified in the</p>
<p>configuration file.</p>
<p>A remote attacker may also perform the following actions from the control server:</p>
<p>* Download and execute files</p>
<p>* Log and report keystrokes</p>
<p>* Perform certain hidden tasks on the Trojan</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Spyeye. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-020216-0135-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/spyeye/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Imaut.F</title>
		<link>http://www.registrycleanergeeks.com/worm/w32-imaut-f/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32-imaut-f/#comments</comments>
		<pubDate>Sun, 14 Feb 2010 10:48:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1633</guid>
		<description><![CDATA[Discovered: January 30, 2010 Updated: January 30, 2010 4:44:08 PM Type: Worm Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Imaut.F you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1633"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 30, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 30, 2010 4:44:08 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Worm</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Imaut.F    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Imaut.F. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="504">
<tbody>
<tr class="blue">
<td width="472"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When the worm is executed, it copies itself to the following locations:
  </p>
<p> * %System%\system3_.exe<br />
    * %Windir%\system3_.exe</p>
<p>It also creates the following file:<br />
    %System%\autorun.ini</p>
<p>Next it modifies the following registry entry so that it runs when Windows <br />
    starts:<br />
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&quot;Shell&quot; = &quot;Explorer.exe system3_.exe&quot;</p>
<p>It then changes the home and search page for Internet Explorer by setting<br /> <br />
    the following registry entries:</p>
<p> * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\&quot;Default_Page_URL&quot; = &quot;http://www.mydreamworld.50<br />
    webs.com&quot;<br />
    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\&quot;Default_Search_URL&quot; = &quot;http://www.mydreamworld.50<br />
    webs.com&quot;<br />
    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer<br />
    \Main\&quot;Search Page&quot; = &quot;http://www.mydreamworld.50webs.com&quot;<br />
    * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer<br />
    \Main\&quot;Start Page&quot; = &quot;http://www.mydreamworld.50webs.com&quot;<br />
    * HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main<br />
    \&quot;Start Page&quot; = &quot;http://www.mydreamworld.50webs.com&quot;</p>
<p>It also sets the following registry entry:<br />
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<br />
    Schedule\&quot;AtTaskMaxHours&quot; = 0</p>
<p>It may also modify the Mozilla Firefox pref.js file to change the homepage <br />
    of the Firefox browser.</p>
<p>The worm then downloads a configuration file using the following URLs:</p>
<p> * h1.ripway.com/asdb0[NUMBER BETWEEN 00 AND 50]/setting.ini<br />
    * www.balu0[NUMBER BETWEEN 00 AND 24].0catch.com/setting/<br />
    setting.ini </p>
<p>The configuration file may contain instructions to download an update of <br />
    the worm.</p>
<p>If Yahoo! Messenger is not installed on the compromised computer, the <br />
    worm will attempt to download and install it from the following location:<br />
    rd.software.yahoo.com/msgr/9/msgr9us.exe</p>
<p>The worm will end processes with the following names:</p>
<p> * game_y.exe<br />
    * cmd.exe</p>
<p>It also attempts to close application windows that have the following strings <br />
    in their title:</p>
<p> * Bkav2006<br />
    * System Configuration<br />
    * Registry<br />
    * Windows Task</p>
<p>If the worm detects an application window with a title that contains the string &quot;<br />
    [Firelion]&quot;, it will delete the following registry subkey and restart the computer:<br />
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\<br />
    Run\&quot;IEProtection&quot;</p>
<p>The worm attempts to spread by copying itself to all local and shared drive <br />
    as the following file:<br />
    %DriveLetter%\New Folder.exe</p>
<p>It will also send the following messages to contacts found in the address books <br />
    of Yahoo! Messenger and Google Talk:</p>
<p> * happy valentine day screen saver from http: //advgoogle.0catch.com/love.<br />
    scr and get new tips and tricks from URL<br />
    * happy valentine day screen saver and beautiful screen saver from lovers http: //advgoogle.0catch.com/love.scr and URL<br />
    * golden lovers rose screen saver from http: //advgoogle.0catch.com/love.scr <br />
    and see more from URL<br />
    * rose is always red ,see in http: //advgoogle.0catch.com/love.scr screen saver <br />
    from URL<br />
    * happy valentine day screen saver from http: //advgoogle.0catch.com/love.scr <br />
    and get new tips and tricks from URL<br />
    * I LOVE YOUUUUUUUUUUUUU from screensaver http: //advgoogle.0catch.<br />
    com/love.scr see more in URL<br />
    * happy valentine day screen saver from http: //advgoogle.0catch.com/love.scr <br />
    and get new tips and tricks from URL<br />
    * happy valentine day screen saver from http: //advgoogle.0catch.com/love.scr <br />
    and get new tips and tricks for lovers URL<br />
    * happy valentine day screen saver from http: //advgoogle.0catch.com/love.scr <br />
    and view secrets from private cam BIN<br />
    * asl please &amp; @CRLF &amp; I am 23 Female, Delhi (India) and you?</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Imaut.F. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-013015-3330-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32-imaut-f/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Backdoor.Tidserv.K</title>
		<link>http://www.registrycleanergeeks.com/trojan/backdoor-tidserv-k/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/backdoor-tidserv-k/#comments</comments>
		<pubDate>Fri, 12 Feb 2010 22:00:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1626</guid>
		<description><![CDATA[Discovered: January 28, 2010 Updated: January 29, 2010 3:47:48 PM Type: Trojan Systems Affected: Windows XP, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Backdoor.Tidserv.K you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Backdoor.Tidserv.K. Read our full No Adware Review [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1626"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 28, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 29, 2010 3:47:48 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows XP, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Backdoor.Tidserv.K    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Backdoor.Tidserv.K. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>This Trojan may arrive as the following file:</p>
<p>%CurrentFolder%\Surprise.exe</p>
<p>When the Trojan is executed, it creates the following mutex so that only</p>
<p>one instance of the Trojan exists on the computer:</p>
<p>{CC51461B-E32A-4883-8E97-E0706DC65415}</p>
<p>It then creates a copy of itself in the following location:</p>
<p>%Windir%\system32\spool\prtprocs\[RANDOM NAME ONE].tmp</p>
<p>Next, the Trojan creates the following file:</p>
<p>%Temp%\[RANDOM NAME TWO].tmp</p>
<p>It then registers itself as a service by creating the following registry subkey:</p>
<p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[</p>
<p>RANDOM NAME THREE]</p>
<p>The Trojan then deletes the above registry subkey as well as the following</p>
<p>files:</p>
<p>* %CurrentFolder%\Surprise.exe</p>
<p>* %Windir%\system32\spool\prtprocs\[RANDOM NAME ONE].tmp</p>
<p>* %Temp%\[RANDOM NAME TWO].tmp</p>
<p>Note: The Trojan then enters a dormant state and will be removed from</p>
<p>the computer if the computer is restarted at this time.</p>
<p>The Trojan resumes executing if either of the following processes are</p>
<p>executed:</p>
<p>* spoolsv.exe</p>
<p>* svchost.exe</p>
<p>It also tests the name of any new processes that are started and executes</p>
<p>if the process name contains any of the following strings:</p>
<p>* avant</p>
<p>* browser</p>
<p>* chrome</p>
<p>* explore</p>
<p>* firefox</p>
<p>* netscape</p>
<p>* opera</p>
<p>* safari</p>
<p>The Trojan then monitors Internet access to the following sites:</p>
<p>* abmr.net</p>
<p>* adbureau.net</p>
<p>* adrevolver.com</p>
<p>* aol.com</p>
<p>* aolcdn.com</p>
<p>* ask.com</p>
<p>* atdmt.com</p>
<p>* bing.com</p>
<p>* blinkx.com</p>
<p>* doubleclick.net</p>
<p>* everesttech.net</p>
<p>* fimserve.com</p>
<p>* google</p>
<p>* google-analytics.com</p>
<p>* img.youtube.com</p>
<p>* live.com</p>
<p>* msn.com</p>
<p>* othersonline.com</p>
<p>* powerset.com</p>
<p>* search.aol.com</p>
<p>* search.yahoo.com</p>
<p>* tribalfusion.com</p>
<p>* upload.wikimedia.org</p>
<p>* www.ask.com</p>
<p>* www.bing.com</p>
<p>* www.google.</p>
<p>* yahoo.com</p>
<p>* yieldmanager.com</p>
<p>* yimg.com</p>
<p>It may then download and execute a file from one of the following locations.</p>
<p>It may also send information to the following locations:</p>
<p>* https://d45648675.cn</p>
<p>* https://d92378523.cn</p>
<p>* https://91.212.226.62</p>
<p>* http://b11335599.cn</p>
<p>* http://b00882244.cn</p>
<p>* http://m3131313.cn</p>
<p>* http://mfdclk001.org</p>
<p>* https://a57990057.cn</p>
<p>* https://a58990058.cn</p>
<p>* https://212.117.174.178</p>
<p>* http://c36996639.cn</p>
<p>* http://c58446658.cn</p>
<p>* http://m2121212.cn</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Backdoor.Tidserv.K. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-012818-0918-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/backdoor-tidserv-k/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Ircbrute.B</title>
		<link>http://www.registrycleanergeeks.com/worm/w32-ircbrute-b/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32-ircbrute-b/#comments</comments>
		<pubDate>Fri, 12 Feb 2010 09:24:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1623</guid>
		<description><![CDATA[Discovered: January 27, 2010 Updated: January 27, 2010 12:27:36 PM Type: Worm Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Ircbrute.B you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1623"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 27, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 27, 2010 12:27:36 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Worm</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Ircbrute.B    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Ircbrute.B. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="498">
<tbody>
<tr class="blue">
<td width="466"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>When the worm executes, it creates the following files:</p>
<p>* %SystemDrive%\RESTORE\[SID]\Desktop.ini</p>
<p>* %SystemDrive%\RESTORE\[SID]\ise32.exe</p>
<p>Next, the worm creates the following registry entry so that it executes whenever Windows starts:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C967120}\&#8221;StubPath&#8221; = &#8220;%SystemDrive%\RESTORE\[SID]\ise32.exe&#8221;</p>
<p>The worm then copies itself to all removable drives as the following files:</p>
<p>* %DriveLetter%\RESTORE\[SID]\Desktop.ini</p>
<p>* %DriveLetter%\RESTORE\[SID]\ise32.exe</p>
<p>It also creates the following file so that it runs when the above drives are accessed:</p>
<p>%DriveLetter%\autorun.inf</p>
<p>The worm also opens a back door on the compromised computer by connecting to the following IRC server on TCP port 9890:</p>
<p>travo892.dyndns.org</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Ircbrute.B. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-012711-2418-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32-ircbrute-b/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Arbormen</title>
		<link>http://www.registrycleanergeeks.com/virus/w32-arbormen/</link>
		<comments>http://www.registrycleanergeeks.com/virus/w32-arbormen/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 18:02:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1620</guid>
		<description><![CDATA[Discovered: January 26, 2010 Updated: January 27, 2010 8:23:01 AM Type: Virus Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Arbormen you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1620"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 26, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 27, 2010 8:23:01 AM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Virus</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2">
<p><img src="/images/1.jpg" alt="" /> In order to Remove W32.Arbormen    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Arbormen. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></p>
<p>If your PC is also running slowly, you may be interested to look at our <a href="http://www.registrycleanergeeks.com/regcure/review/">Regcure Review</a>. Regcure is proven to improve the performance of your computer.</p>
</td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="498">
<tbody>
<tr class="blue">
<td width="466"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When the virus executes, it attempts to inject code into processes with the name &quot;explorer&quot; and processes with the window name &quot;TibiaClient&quot;</p>
<p>It then searches for .exe and .scr files to infect them.</p>
<p>The virus avoids infecting files under the following paths:</p>
<p> * %Windir%<br />
  * %UserProfile%\Application Data<br />
  * %UserProfile%\Movie Maker<br />
  * %UserProfile%\Local Settings\Application Data<br />
  * %ProgramFiles%\Internet Explorer<br />
  * %ProgramFiles%\Outlook Express<br />
  * %ProgramFiles%\MSN Gaming Zone<br />
  * %ProgramFiles%\NetMeeting<br />
  * %ProgramFiles%\Windows Media Player<br />
  * %ProgramFiles%\Windows NT<br />
  * %ProgramFiles%\Windows Update<br />
  * %ProgramFiles%\Common Files
</p>
<p>The virus then attempts to download files from and send information about the compromised computer to the following location:<br />
  m-net.arbornet.org/~hglwfk/?a=***</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Arbormen. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-012705-5603-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/virus/w32-arbormen/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Zimuse</title>
		<link>http://www.registrycleanergeeks.com/worm/w32-zimuse/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32-zimuse/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 17:10:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1617</guid>
		<description><![CDATA[Discovered: January 23, 2010 Updated: January 27, 2010 7:12:55 AM Type: Worm Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Zimuse you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1617"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 23, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 27, 2010 7:12:55 AM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Worm</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Zimuse    you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Zimuse. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="498">
<tbody>
<tr class="blue">
<td width="466"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>Once executed, the worm drops the following files:</p>
<p> * %ProgramFiles%\Dump\Dump.exe<br />
  * %System%\drivers\Mseu.sys<br />
  * %System%\drivers\Mstart.sys<br />
  * %System%\ainf.inf<br />
  * %System%\mseus.exe<br />
  * %System%\tokset.dll</p>
<p>It drops the following nonmalicious files into C:\IQTEST and then opens an <br />
  Explorer window and displays the C:\IQTEST folder contents:</p>
<p> * C:\IQTEST\Iqtest.exe (clean version of the IQ test)<br />
  * C:\IQTEST\Readme.txt</p>
<p>The program c:\iqtest\Iqtest.exe is a clean program that looks like this:</p>
<p>The worm then deletes itself.</p>
<p>After a predetermined number of days the worm copies itself as zipsetup.exe to <br />
  the following drives and to the first 9 physical drives:</p>
<p> * C:<br />
  * D:<br />
  * E:<br />
  * F:<br />
  * G:<br />
  * H:<br />
  * I:<br />
  * J:</p>
<p>The worm creates the following registry entry, so that it runs every time Windows <br />
  starts:<br />
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current<br />
  Version\Run\&quot;Dump&quot; = &quot;%ProgramFiles%\Dump\Dump.exe&quot;</p>
<p>It creates new services with the following characteristics:<br />
  Service Name: Mseu<br />
  Display Name: Mseu<br />
  Startup Type: Automatic<br />
  Image Path: System32\Mseus.exe</p>
<p>Service Name: Mstart<br />
  Display Name: Mstart<br />
  Startup Type: Automatic<br />
  Image Path: \??\C:\WINDOWS\system32\Drivers\MSTART.SYS</p>
<p>Service Name: UnzipService<br />
  Display Name: UnzipService<br />
  Startup Type: Automatic</p>
<p>Service Name: Self Extract Service<br />
  Display Name: Self Extract Service<br />
  Startup Type: Automatic</p>
<p>The worm creates the services by adding entries to the following registry subkeys:</p>
<p> * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mseu<br />
  * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<br />
  MSTART<br />
  * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<br />
  UnzipService</p>
<p>It spreads through removable drives as the file zipsetup.exe and it is also <br />
  shared online as the following program:<br />
  IqTest.exe</p>
<p>It also copies the following file so that it runs when the removable devices <br />
  are accessed:<br />
  %DriveLetter%\autorun.inf</p>
<p>After a predetermined amount of time the threat will attempt to delete the <br />
  following files:</p>
<p> * C:\System Volume Information<br />
  * D:\System Volume Information<br />
  * E:\System Volume Information<br />
  * F:\System Volume Information<br />
  * G:\System Volume Information<br />
  * H:\System Volume Information<br />
  * I:\System Volume Information<br />
  * J:\System Volume Information<br />
  * C:\Documents and Settings\Administrator\My Documents<br />
  * D:\Documents and Settings\Administrator\My Documents<br />
  * E:\Documents and Settings\Administrator\My Documents<br />
  * F:\Documents and Settings\Administrator\My Documents<br />
  * G:\Documents and Settings\Administrator\My Documents<br />
  * H:\Documents and Settings\Administrator\My Documents<br />
  * I:\Documents and Settings\Administrator\My Documents<br />
  * J:\Documents and Settings\Administrator\My Documents<br />
  * C:\Users\Administrator<br />
  * D:\Users\Administrator<br />
  * E:\Users\Administrator<br />
  * F:\Users\Administrator<br />
  * G:\Users\Administrator<br />
  * H:\Users\Administrator<br />
  * I:\Users\Administrator<br />
  * J:\Users\Administrator<br />
  * C:\Documents and Settings<br />
  * D:\Documents and Settings<br />
  * E:\Documents and Settings<br />
  * F:\Documents and Settings<br />
  * G:\Documents and Settings<br />
  * H:\Documents and Settings<br />
  * I:\Documents and Settings<br />
  * J:\Documents and Settings<br />
  * C:\Users<br />
  * D:\Users<br />
  * E:\Users<br />
  * F:\Users<br />
  * G:\Users<br />
  * H:\Users<br />
  * I:\Users<br />
  * J:\Users<br />
  * C:\BOOT.INI<br />
  * C:\BOOT.INI<br />
  * C:\NTDETECT.COM<br />
  * C:\NTDETECT.COM<br />
  * C:\NTLDR<br />
  * C:\NTLDR<br />
  * C:\HYBERFILE.SYS<br />
  * C:\HYBERFILE.SYS<br />
  * C:\BOOTMGR<br />
  * C:\BOOTMGR<br />
  * C:\BOOTMGR.BAK<br />
  * C:\BOOTMGR.BAK<br />
  * C:\BOOTSECT<br />
  * C:\BOOTSECT<br />
  * C:\BOOTSECT.BAK<br />
  * C:\BOOTSECT.BAK</p>
<p>The threat also deletes all system restore points by deleting the following <br />
  folders:</p>
<p> * C:\System Volume Information<br />
  * D:\System Volume Information<br />
  * E:\System Volume Information<br />
  * F:\System Volume Information<br />
  * G:\System Volume Information<br />
  * H:\System Volume Information<br />
  * I:\System Volume Information<br />
  * J:\System Volume Information</p>
<p>It will also attempt to overwrite the beginning of the disk in order to overwrite<br /> <br />
  the master boot record (MBR), thereby not allowing the compromised <br />
  computer to be restarted.</p>
<p>When restarted, the system may display the message &quot;Operating System not <br />
  found&quot;.</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Zimuse. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-012301-1138-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32-zimuse/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Fujacks.CC</title>
		<link>http://www.registrycleanergeeks.com/virus/w32-fujacks-cc/</link>
		<comments>http://www.registrycleanergeeks.com/virus/w32-fujacks-cc/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 11:54:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1612</guid>
		<description><![CDATA[Discovered: January 21, 2010 Updated: January 22, 2010 7:44:49 AM Type: Virus Systems Affected: Windows XP, Windows Vista, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Fujacks.CC you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of W32.Fujacks.CC. Read our full No [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1612"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 21, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 22, 2010 7:44:49 AM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Virus</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows XP, Windows Vista, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Fujacks.CC   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Fujacks.CC. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When executed, the virus copies itself as the following file:<br />
  %Temp%\gb+[RANDOM NUMBER]\syshost.exe
  </p>
<p>It also creates the following files:</p>
<p> * %Temp%\gb+[RANDOM NUMBER]\tmpgb.exe<br />
    * %Temp%\gb+[RANDOM NUMBER]\goodby.dat<br />
    * %Windir%\directx9d.ini</p>
<p>Next, the virus searches for .exe files in order to infect them but excludes any paths that contain the following words:</p>
<p> * nrestore<br />
    * Symantec<br />
    * windows</p>
<p>It also excludes any folders with the following names:</p>
<p> * Documents and Settings<br />
    * Recycler<br />
    * System Volume Information</p>
<p>It also excludes the following folders:</p>
<p> * %ProgramFiles%<br />
    * %Windir%</p>
<p>The virus then adds random data to the beginning of files with the following file extensions, which may render them unusable:</p>
<p> * .cdr<br />
    * .cdx<br />
    * .db<br />
    * .doc<br />
    * .dwg<br />
    * .gdb<br />
    * .md<br />
    * .ppt<br />
    * .ps<br />
    * .tab<br />
    * .vs<br />
    * .wor<br />
    * .xls</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Fujacks.CC. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-012204-2943-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/virus/w32-fujacks-cc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove VBS.Runauto.H</title>
		<link>http://www.registrycleanergeeks.com/worm/vbs-runauto-h/</link>
		<comments>http://www.registrycleanergeeks.com/worm/vbs-runauto-h/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 16:18:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1609</guid>
		<description><![CDATA[Discovered: January 19, 2010 Updated: January 19, 2010 2:32:59 PM Type: Worm Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove VBS.Runauto.H you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1609"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 19, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 19, 2010 2:32:59 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Worm</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove VBS.Runauto.H   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of VBS.Runauto.H. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="504">
<tbody>
<tr class="blue">
<td width="472"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>When the worm is executed, it creates the following file:</p>
<p>%System%\n.vbe</p>
<p>The worm creates the following registry entry, so that it starts when Windows</p>
<p>starts:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current</p>
<p>Version\Run\&#8221;dpzProtect&#8221; = &#8220;%System%\n.vbe&#8221;</p>
<p>It them modifies the following registry entry, so that it starts when Windows</p>
<p>starts:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current</p>
<p>Version\Winlogon\&#8221;Userinit&#8221; = &#8220;%System%\userinit.exe,%System%\wscript.</p>
<p>exe %System%\n.vbe&#8221;</p>
<p>The worm also modifies the following registry entries:</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\&#8221;</p>
<p>Window Title&#8221; = &#8220;Protected by DespoterZ&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Policies\Explorer\&#8221;NoSMHelp&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Policies\Explorer\&#8221;NoStartMenuMFUprogramsList&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Policies\Explorer\&#8221;NoSMMyDocs&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Policies\Explorer\&#8221;NoRecentDocsMenu&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Policies\Explorer\&#8221;NoSMMyPictures&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Policies\Explorer\&#8221;NoStartMenuMyMusic&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Policies\Explorer\&#8221;NoFolderOptions&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Policies\System\&#8221;DisableTaskMgr&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Policies\System\&#8221;DisableRegistryTools&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current</p>
<p>Version\&#8221;RegisteredOwner&#8221; = &#8220;Microsoft&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current</p>
<p>Version\&#8221;RegisteredOrganization&#8221; = &#8220;.&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current</p>
<p>Version\Winlogon\&#8221;LegalNoticeCaption&#8221; = &#8220;&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current</p>
<p>Version\Winlogon\&#8221;LegalNoticeText&#8221; = &#8220;&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current</p>
<p>Version\Explorer\Advanced\Folder\Hidden\SHOWALL\&#8221;CheckedValue&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current</p>
<p>Version\Explorer\Advanced\Folder\SuperHidden\&#8221;UncheckedValue&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current</p>
<p>Version\Winlogon\&#8221;Shell&#8221; = &#8220;explorer.exe&#8221;</p>
<p>The worm deletes the following files:</p>
<p>* %System%\VirusRemoval.vbs</p>
<p>* %System%\neo.vbe</p>
<p>* %System%\amvo.exe</p>
<p>* %System%\avpo.exe</p>
<p>* %System%\winlogons.exe</p>
<p>* %System%\ssvichosst.exe</p>
<p>* %System%\tmp.exe</p>
<p>* %System%\scvhost.exe</p>
<p>* %System%\explorer.exe</p>
<p>* %System%\service.exe</p>
<p>* %System%\soundmix.exe</p>
<p>* %System%\regsvr.exe</p>
<p>* %DriveLetter%\ravmon.exe</p>
<p>* %DriveLetter%\sxs.exe</p>
<p>* %DriveLetter%\winfile.exe</p>
<p>* %DriveLetter%\run.wsh</p>
<p>The worm then deletes all files with file names that start with &#8220;autorun&#8221; in the</p>
<p>root folder of all removable drives, all .inf and .scr files in the root folder of all</p>
<p>fixed drives, and all .vbe files in the root and %Windir% folder of all drives</p>
<p>except drive A.</p>
<p>It then copies the following files to all available removable drives except A:</p>
<p>* %DriveLetter%\n.vbe</p>
<p>* %DriveLetter%\autorun.inf</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove VBS.Runauto.H. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-011912-2913-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/vbs-runauto-h/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Ramnit</title>
		<link>http://www.registrycleanergeeks.com/virus/w32-ramnit/</link>
		<comments>http://www.registrycleanergeeks.com/virus/w32-ramnit/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 17:00:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1606</guid>
		<description><![CDATA[Discovered: January 19, 2010 Updated: January 20, 2010 12:08:42 AM Type: Virus Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Ramnit you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1606"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 19, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 20, 2010 12:08:42 AM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Virus</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Ramnit   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Ramnit. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>Once executed, the worm creates the following folder:</p>
<p>%ProgramFiles%\MNetwork</p>
<p>It then creates the following mutex so only one instance of the worm is running:</p>
<p>Ghiyhjmnklowqq</p>
<p>The worm spreads by encrypting and then appending itself to files with the following extensions:</p>
<p>* DLL</p>
<p>* EXE</p>
<p>* HTM</p>
<p>When an infected file, detected as W32.Ramnit!inf, is executed, it drops a copy of the worm executable file with the following file name and executes it:</p>
<p>%CurrentFolder%\[INFECTED FILE NAME]Srv.exe</p>
<p>The worm also spreads by copying itself to the recycle bin on the removable drive and creates the following file so that it executes whenever the drive is accessed:</p>
<p>%DriveLetter%\autorun.ini</p>
<p>The worm attempts to connect to the following remote location:</p>
<p>rmnzerobased.com</p>
<p>It attempts to download a .dll file and register it.</p>
<p>Note: At the time of writing, the file was unavailable.</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Ramnit. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-011922-2056-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/virus/w32-ramnit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Pilleuz.B</title>
		<link>http://www.registrycleanergeeks.com/worm/w32-pilleuz-b/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32-pilleuz-b/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 13:11:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1603</guid>
		<description><![CDATA[Discovered: January 19, 2010 Updated: January 19, 2010 5:21:37 PM Type: Worm Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Pilleuz.B you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1603"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 19, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 19, 2010 5:21:37 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Worm</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Pilleuz.B   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Pilleuz.B. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>When the worm is executed, it creates the following files:</p>
<p>* %SystemDrive%\RECYCLER\[SID]\nissan.exe</p>
<p>* %SystemDrive%\RECYCLER\[SID]\Desktop.ini</p>
<p>* %DriveLetter%\RECYCLER\[SID]\csrxx.exe (W32.IRCBot)</p>
<p>* %DriveLetter%\SLATKO\torta.exe</p>
<p>* %DriveLetter%\SLATKO\Desktop.ini</p>
<p>* %DriveLetter%\autorun.inf</p>
<p>It then creates the following registry entry, so that it starts when Windows starts:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&#8221;Taskman&#8221; = &#8220;C:\RECYCLER\[SID]\nissan.exe&#8221;</p>
<p>The worm then opens a back door and connects to the following domains on UDP port 25000:</p>
<p>* sandra.prichaonica.com</p>
<p>* pica.banjalucke-ljepotice.ru</p>
<p>* l33t.brand-clothes.net</p>
<p>The worm also copies itself to the shared folder of the following file-sharing programs:</p>
<p>* Ares</p>
<p>* BearShare</p>
<p>* iMesh</p>
<p>* Shareaza</p>
<p>* Kazaa</p>
<p>* DC++</p>
<p>* eMule</p>
<p>* LimeWire</p>
<p>It then monitors browsing activities, logging passwords stored in the browsers.</p>
<p>The worm will send messages through Microsoft instant messaging programs, such as MSN Messenger and Windows Live Messenger, that include a link to download the worm.</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Pilleuz.B. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-011915-4635-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32-pilleuz-b/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Imalag.C</title>
		<link>http://www.registrycleanergeeks.com/virus/w32-imalag-c/</link>
		<comments>http://www.registrycleanergeeks.com/virus/w32-imalag-c/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 11:59:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1600</guid>
		<description><![CDATA[Discovered: January 18, 2010 Updated: January 19, 2010 7:00:10 AM Type: Virus Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Imalag.C you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1600"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 18, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 19, 2010 7:00:10 AM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Virus</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Imalag.C   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Imalag.C. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>When executed, the virus attempts to infect the following file:</p>
<p>%Windir%\explorer.exe</p>
<p>It then attempts to download files from the following URLs:</p>
<p>* [http://]irannew.narod.ru/pe[REMOVED]</p>
<p>* [http://]iraqnew.hotbox.ru/pe[REMOVED]</p>
<p>* [http://]irannew.narod.ru/pl[REMOVED]</p>
<p>* [http://]iraqnew.hotbox.ru/pl[REMOVED]</p>
<p>The virus then searches the compromised computer for other .exe files, which it then infects.</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Imalag.C. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-011905-5436-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/virus/w32-imalag-c/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Selfish.B</title>
		<link>http://www.registrycleanergeeks.com/virus/w32-selfish-b/</link>
		<comments>http://www.registrycleanergeeks.com/virus/w32-selfish-b/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 14:23:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1595</guid>
		<description><![CDATA[Discovered: January 13, 2010 Updated: January 13, 2010 3:23:21 PM Type: Virus Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Selfish.B you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1595"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 13, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">January 13, 2010 3:23:21 PM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Virus</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Selfish.B   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Selfish.B. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When an infected executable is started, it copies the original executable to the following location and executes it:<br />
  %CurrentFolder%\_[VIRUS FILE NAME].exe</p>
<p>Next, the virus scans the hard drive and infects any executable that it finds.</p>
<p>It then connects to a MySQL database hosted at the following location:<br />
  remote-mysql3.servage.net</p>
<p>The virus then updates this database in order to record the infection of the compromised computer.</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Selfish.B. Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-011312-0006-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/virus/w32-selfish-b/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Spyrat</title>
		<link>http://www.registrycleanergeeks.com/worm/w32-spyrat/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32-spyrat/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 11:21:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1592</guid>
		<description><![CDATA[Discovered: January 12, 2010 Updated: January 12, 2010 12:27:03 PM Type: Worm Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Spyrat you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1592"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 12, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">January 12, 2010 12:27:03 PM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Worm</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Spyrat   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Spyrat. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="501">
<tbody>
<tr class="blue">
<td width="469"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>Note: This worm is generated by the Spy-Net RAT toolkit, and as a result the <br />
  files and registry entries can be determined by the attacker. The files, registry <br />
  entries, processes, and mutexes listed below are default values presented by <br />
  the toolkit.</p>
<p>When the worm is executed, it creates the following files:</p>
<p> * %Temp%\UuU.uUu<br />
  * %Temp%\XX&#8211;XX&#8211;XX.txt<br />
  * %Temp%\XxX.xXx<br />
  * C:\Dir\install\server.exe</p>
<p>It then creates the following registry entry, so that it starts when Windows <br />
  starts:<br />
  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\<br />
  Policies\Explorer\Run\&quot;Policies&quot; = &quot;c:\dir\install\server.exe&quot;</p>
<p>The worm then opens a back door using a predetermined port and IP address, <br />
  allowing an attacker to perform the following actions on the compromised <br />
  computer:</p>
<p> * Read, write, and execute files<br />
  * Steal stored passwords<br />
  * Issue commands<br />
  * Activate and view a webcam, if present<br />
  * Log keystrokes<br />
  * Create a HTTP proxy to route traffic through the compromised computer</p>
<p>The worm may also create a rootkit that hides any registry entries or files <br />
  that begin with the &quot;SPY_NET_RAT&quot; string.</p>
<p>The threat may also inject itself into the iexplorer.exe process, or another <br />
  predetermined process, so that it starts when the process starts.</p>
<p>It also creates a mutex named ***MUTEX*** (or another value determined <br />
  by the attacker) to prevent multiple instances of the threat from running.</p>
<p>The worm spreads by copying itself to removable drives and the share folders <br />
  of file-sharing programs, such as Limewire and Bearshare.</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Spyrat. Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-011211-1602-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32-spyrat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Hydraq</title>
		<link>http://www.registrycleanergeeks.com/trojan/hydraq/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/hydraq/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 22:17:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1588</guid>
		<description><![CDATA[Discovered: January 11, 2010 Updated: January 11, 2010 2:59:20 PM Type: Trojan Systems Affected: Windows 2000, Windows Server 2003, Windows Vista, Windows XP Recommended Action: In order to Remove Trojan.Hydraq you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Trojan.Hydraq.. Read our full No [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1588"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 11, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 11, 2010 2:59:20 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 2000, Windows Server 2003, Windows Vista, Windows XP</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Hydraq  you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Hydraq.. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="502">
<tbody>
<tr class="blue">
<td width="470"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>This Trojan may arrive in an email or it may be dropped or downloaded by</p>
<p>another threat.</p>
<p>When executed, the threat creates one of the following files:</p>
<p>%Temp%\c_1758.nls</p>
<p>%Temp%\[RANDOM FILE NAME]</p>
<p>It then creates a service with the following characteristic:</p>
<p>Service name: RaS[FOUR RANDOM CHARACTERS]</p>
<p>The Trojan creates the following registry subkey in order to register the</p>
<p>above service:</p>
<p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\</p>
<p>RaS[FOUR RANDOM CHARACTERS]</p>
<p>Next, the Trojan modifies the following registry entry:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\&#8221;netsvcs&#8221; = &#8220;36 00 74 00 6F 00 34 00 00</p>
<p>The Trojan then opens a back door and allow a remote attacker to perform</p>
<p>the following actions on the compromised computer:</p>
<p>* Adjust token privileges.</p>
<p>* Check status, control, and end processes and services</p>
<p>* Download a remote file, save it as %Temp%\mdm.exe, and then execute it.</p>
<p>* Create, modify, and delete registry subkeys.</p>
<p>* Retrieve a list of logical drives.</p>
<p>* Read, write, execute, copy, change attributes, and delete files.</p>
<p>* Reboot and shut down the computer.</p>
<p>* Uninstall itself by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ra</p>
<p>S[FOUR RANDOM CHARACTERS] subkey.</p>
<p>* clear all system event logs.</p>
<p>* Check if %System%\acelpvc.dll is present. If so, load it and call its Entry</p>
<p>Main() export.</p>
<p>* Check if %System%\VedioDriver.dll is present.</p>
<p>* Open, read, and delete the %System%\drivers\etc\networks.ics file.</p>
<p>* Retrieve the CPU speed by checking the HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\</p>
<p>CentralProcessor\0\&#8221;~MHz&#8221; registry value.</p>
<p>It then connects to one of the following domains using port 443 and</p>
<p>sends any information gathered:</p>
<p>* yahooo.8866.org</p>
<p>* sl1.homelinux.org</p>
<p>* 360.homeunix.com</p>
<p>The Trojan then redirects the computer to the following domain:</p>
<p>* li107-40.members.linode.com</p>
<p>* ftp2.homeunix.com</p>
<p>* update.ourhobby.com</p>
<p>The Trojan also stores configuration information in the following registry entries:</p>
<p>* HKEY_LOCAL_MACHINE\Software\Sun\1.1.2\&#8221;IsoTp&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\Software\Sun\1.1.2\&#8221;AppleTlk&#8221;</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Hydraq. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-011114-1830-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/hydraq/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Zbot</title>
		<link>http://www.registrycleanergeeks.com/trojan/zbot/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/zbot/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 15:22:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1584</guid>
		<description><![CDATA[Discovered: January 10, 2010 Updated: January 10, 2010 4:35:14 PM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Zbot you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1584"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 10, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">January 10, 2010 4:35:14 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Trojan</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Zbot   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Zbot. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="504">
<tbody>
<tr class="blue">
<td width="472"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>When the Trojan executes, it may create one of the following copies of itself:</p>
<p>* %System%\sdra64.exe</p>
<p>* %System%\oembios.exe</p>
<p>* %System%\ntos.exe</p>
<p>It may also create the following files:</p>
<p>* %System%\wsnpoem\audio.dll</p>
<p>* %System%\wsnpoem\video.dll</p>
<p>* %System%\sysproc64\sysproc86.sys</p>
<p>* %System%\sysproc64\sysproc32.sys</p>
<p>It also drops the following encrypted configuration file:</p>
<p>%System%\lowsec\local.ds</p>
<p>The configuration file specifies to the Trojan where it can download further</p>
<p>instructions and updates.</p>
<p>It may then create one of the following registry entries so that it executes</p>
<p>when Windows starts:</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion</p>
<p>\Run\&#8221;userinit&#8221; = &#8220;%System%\sdra64.exe&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion</p>
<p>\Run\&#8221;userinit&#8221; = &#8220;%System%\oembios.exe&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion</p>
<p>\Run\&#8221;userinit&#8221; = &#8220;%System%\ntos.exe&#8221;</p>
<p>The Trojan may also make modifications to the following registry entries:</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&#8221;Userinit&#8221; = &#8220;%System%\userinit.exe, %System%\sdra64.exe&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&#8221;Userinit&#8221; = &#8220;%System%\userinit.exe, %System%\oembios.exe&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&#8221;Userinit&#8221; = &#8220;%System%\userinit.exe, %</p>
<p>System%\ntos.exe</p>
<p>It then attempts to gather the following information from the compromised</p>
<p>computer:</p>
<p>* Operating system version</p>
<p>* Presence of Windows XP Service Pack 2</p>
<p>* Language of the operating system</p>
<p>* Saved passwords in PStore</p>
<p>It attempts to create malicious threads in all running processes except</p>
<p>for CSRSS.EXE. It does this by hooking the following system functions</p>
<p>of NTDLL.DLL:</p>
<p>* NtCreateThread</p>
<p>* LdrLoadDll</p>
<p>* LdrGetProcedureAddress</p>
<p>It also deletes cookies in the Internet Explorer URL cache so that users</p>
<p>will have to re-enter passwords when visiting banking Web sites.</p>
<p>It attempts to hook the functions from various DLLs to take control</p>
<p>of network functionality and to steal sensitive information:</p>
<p>From WININET.DLL</p>
<p>* HttpSendRequestW</p>
<p>* HttpSendRequestA</p>
<p>* HttpSendRequestExW</p>
<p>* HttpSendRequestExA</p>
<p>* InternetReadFile</p>
<p>* InternetReadFileExW</p>
<p>* InternetReadFileExA</p>
<p>* InternetQueryDataAvailable</p>
<p>* InternetCloseHandle</p>
<p>From WS2_32.DLL and WSOCK32.DLL</p>
<p>* send</p>
<p>* sendto</p>
<p>* closesocket</p>
<p>* WSASend</p>
<p>* WSASendTo</p>
<p>From USER32.DLL</p>
<p>* GetMessageW</p>
<p>* GetMessageA</p>
<p>* PeekMessageW</p>
<p>* PeekMessageA</p>
<p>* GetClipboardData</p>
<p>After hooking the DLLs, it filters the network traffic for specific</p>
<p>keywords related to banking, social networking and Web email sites.</p>
<p>The keywords are specified in the encrypted configuration file.</p>
<p>The stolen information is then stored in the following file:</p>
<p>%System%\lowsec\user.ds.</p>
<p>It transmits the stolen data to URLs specified in the configuration file.</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Zbot. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-011016-3514-99&amp;tabid=3">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/zbot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Backdoor.Tidserv.J</title>
		<link>http://www.registrycleanergeeks.com/trojan/backdoor-tidserv-j/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/backdoor-tidserv-j/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 15:14:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1581</guid>
		<description><![CDATA[Discovered: January 8, 2010 Updated: January 8, 2010 4:50:06 PM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Backdoor.Tidserv.J you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1581"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 8, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">January 8, 2010 4:50:06 PM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Trojan</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Backdoor.Tidserv.J   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Backdoor.Tidserv.J. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="499">
<tbody>
<tr class="blue">
<td width="467"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When the Trojan is executed, it creates the following mutex so that only one copy of the threat is running on the computer at any time:<br />
  0430BC64-6833-4845-A192-D9ADFCFDFC43</p>
<p>Next the Trojan copies itself to the following location:<br />
  %Temp%\H8SRT[RANDOM HEXADECIMAL DIGITS FILE NAME ONE].tmp</p>
<p>It then drops the following file:<br />
  %Temp%\H8SRT[RANDOM HEXADECIMAL DIGITS FILE NAME TWO].tmp</p>
<p>It also modifies %System%\msvcrt.dll and saves it to the following location:<br />
  %Temp%\H8SRT[RANDOM HEXADECIMAL DIGITS FILE NAME THREE].tmp</p>
<p>The Trojan then creates the following files:</p>
<p> * %Windir%\system32\H8SRT[TEN RANDOM CHARACTERS].dll (Trojan.Vundo)<br />
  * %Windir%\system32\H8SRT[TEN RANDOM CHARACTERS].dat<br />
  * %Windir%\system32\drivers\H8SRT[TEN RANDOM CHARACTERS].sys</p>
<p>Next, the Trojan registers itself as a service by creating the following registry subkey:<br />
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\H8SRTd.sys</p>
<p>It also creates the following registry subkey:<br />
  HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT</p>
<p>It then modifies the following registry entries:</p>
<p> * HKEY_CURRENT_USER\Software\Mozilla\&quot;affid&quot; = &quot;&quot;<br />
  * HKEY_CURRENT_USER\Software\Mozilla\&quot;subid&quot; = &quot;nk[TWO DIGITS]&quot;</p>
<p>Next it injects malicious code into the svchost.exe process.</p>
<p>The injected code attempts to contact a controlling server using the following URLs:</p>
<p> * [http://]searchyields.org/css/crcmds/ma[REMOVED]<br />
  * [http://]searchphoto.org/css/crcmds/ma[REMOVED]<br />
  * [http://]readersfind.org/css/crcmds/ma[REMOVED]<br />
  * [http://]gotunderway.cn/css/crcmds/ma[REMOVED]<br />
  * [http://]eventuallygot.cn/css/crcmds/ma[REMOVED]</p>
<p>The Trojan contains back door functionality that allows it to download additional components based on instructions received from the above servers.</p>
<p>Next, the Trojan may download and execute the following file:<br />
  [http://]ruledout.cn/setup/setu[REMOVED]</p>
<p>The Trojan hooks the following kernel APIs:</p>
<p> * IofCallDriver<br />
  * IofCompleteRequest<br />
  * ZwEnumerateKey<br />
  * ZwFlushInstructionCache</p>
<p>It also has rootkit functionality in order to hide files, directories, and registry subkeys with names starting with the following characters:<br />
  H8SRT</p>
<p>The Trojan checks the current geographic location and does not execute some of its functionality if it is in any of the following locations:</p>
<p> * Azerbaijan<br />
  * Belarus<br />
  * Czech Republic<br />
  * Kazakhstan<br />
  * Kyrgyzstan<br />
  * Poland<br />
  * Russia<br />
  * Ukraine<br />
  * Uzbekistan</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Backdoor.Tidserv.J. Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-010800-2311-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/backdoor-tidserv-j/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Backdoor.Samkams.B</title>
		<link>http://www.registrycleanergeeks.com/trojan/backdoor-samkams-b/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/backdoor-samkams-b/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 13:49:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1576</guid>
		<description><![CDATA[Discovered: January 6, 2010 Updated: January 6, 2010 2:28:45 PM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Backdoor.Samkams.B you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1576"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 6, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">January 6, 2010 2:28:45 PM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Trojan</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Backdoor.Samkams.B  you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Backdoor.Samkams.B. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="499">
<tbody>
<tr class="blue">
<td width="467"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When the Trojan is executed, it creates the following files:</p>
<p> * %System%\windex.exe<br />
  * %System%\winup.exe</p>
<p>It then creates the following registry entry, so that it starts when Windows starts:<br />
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current</p>
<p>Version\policies\Explorer\Run\&quot;CommonService&quot; = &quot;%System%\winup.exe&quot;</p>
<p>The threat creates the following mutexes:</p>
<p> * RMTAA<br />
  * MAIN</p>
<p>It then opens a back door and connects to the following URL, allowing a </p>
<p>remote attacker to perform unauthorized actions on the compromised <br />
  computer: [http://]www1.vmnat.com</p>
<p>The threat may connect to one of the following URLs to send information <br />
  to </p>
<p>the remote attacker:</p>
<p> * [http://]www1.vmnat.com/httpdocs/mm/[LOCAL HOST NAME]:[<br />
  LOCAL MAC ADDRESS]/Cmw[REMOVED]<br />
  * [http://]www1.vmnat.com/httpdocs/mm/[LOCAL HOST NAME]:[<br />
  LOCAL MAC ADDRESS]/Dfw[REMOVED]<br />
  * [http://]www1.vmnat.com/httpdocs/mm/[LOCAL HOST NAME]:[<br />
  LOCAL MAC ADDRESS]/Ufw[REMOVED]<br />
  * [http://]www1.vmnat.com/httpdocs/mm/[LOCAL HOST NAME]:[<br />
  LOCAL MAC ADDRESS]/Ccmw[REMOVED]<br />
  * [http://]www1.vmnat.com/httpdocs/mm/[LOCAL HOST NAME]:<br />
  [LOCAL MAC ADDRESS]/Trb[REMOVED]<br />
  * [http://]www1.vmnat.com/cgi-bin/Clnpp[REMOVED]<br />
  * [http://]www1.vmnat.com/cgi-bin/Rwpq[REMOVED]<br />
  * [http://]www1.vmnat.com/cgi-bin/Owpq[REMOVED]<br />
  * [http://]www1.vmnat.com/cgi-bin/Dwpq[REMOVED]<br />
  * [http://]www1.vmnat.com/cgi-bin/Trpq[REMOVED]</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Backdoor.Samkams.B. Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-010612-1816-99&#038;tabid=3">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/backdoor-samkams-b/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Rixobot</title>
		<link>http://www.registrycleanergeeks.com/worm/w32-rixobot/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32-rixobot/#comments</comments>
		<pubDate>Mon, 11 Jan 2010 10:12:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1573</guid>
		<description><![CDATA[Discovered: January 5, 2010 Updated: January 5, 2010 6:52:53 PM Type: Worm Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP Recommended Action: In order to Remove W32.Rixobot you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1573"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>January 5, 2010</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">January 5, 2010 6:52:53 PM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Worm</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Rixobot  you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Rixobot.. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="508">
<tbody>
<tr class="blue">
<td width="476"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>This program must be manually installed.</p>
<p>When the program is executed, it creates the following folders:</p>
<p> * %ProgramFiles%\Zwunzi<br />
  * C:\Documents and Settings\All Users\Application Data\Zwunzi</p>
<p>It drops the following files:</p>
<p> * %ProgramFiles%\Zwunzi\uninstall.exe</p>
<p>  * %ProgramFiles%\Zwunzi\zwunzi.dll<br />
  * %ProgramFiles%\Zwunzi\zwunzi.exe<br />
  * C:\Documents and Settings\All Users\Application Data\Zwunzi\zwunzi128<br />
  .exe</p>
<p>Then, the program creates the following registry entries:</p>
<p> * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current</p>
<p>  Version\Uninstall\Zwunzi\&quot;DisplayName&quot; = &quot;Zwunzi 1.0 build 128&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current<br />
  Version\Uninstall\Zwunzi\&quot;UninstallString&quot; = &quot;%ProgramFiles%\Zwunzi\uninstall.</p>
<p>  exe&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Zwunzi\&quot;Cid&quot; = &quot;466705c153<br />
  4b4aee8c896579946b055f&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Zwunzi\&quot;DllPath = &quot;%Progra</p>
<p>  mFiles%\Zwunzi\zwunzi.dll&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Zwunzi\&quot;Initial&quot; = &quot;1&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Zwunzi\&quot;Partner&quot; = &quot;ZWUN</p>
<p>  ZI128&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Zwunzi\&quot;Primary&quot; = &quot;f403&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Zwunzi\&quot;ShowBarSign&quot; = &quot;<br />
  0&quot;</p>
<p>  * HKEY_LOCAL_MACHINE\SOFTWARE\Zwunzi\&quot;ShowToolbarButto<br />
  n&quot; = &quot;0&quot;<br />
  * HKEY_LOCAL_MACHINE\SOFTWARE\Zwunzi\&quot;Src&quot; = &quot;zwunzi&quot;</p>
<p>  * HKEY_LOCAL_MACHINE\SOFTWARE\Zwunzi\&quot;Version&quot; = &quot;1001<br />
  c&quot;</p>
<p>The program creates a new service with the following characteristics:<br />
  Service Name: Zwunzi Service<br />
  Display Name: Zwunzi Service</p>
<p>  Startup Type: Automatic</p>
<p>It registers the service by creating the following registry subkeys:</p>
<p> * HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root<br />
  \LEGACY_ZWUNZI_SERVICE<br />
  * HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\<br />
  LEGACY_ZWUNZI_SERVICE\0000</p>
<p>  * HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\L<br />
  EGACY_ZWUNZI_SERVICE\0000\Control<br />
  * HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Z<br />
  wunzi Service<br />
  * HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Zw<br />
  unzi Service\Enum</p>
<p>  * HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Z<br />
  wunzi Service\Security<br />
  * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Ro<br />
  ot\LEGACY_ZWUNZI_SERVICE<br />
  * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Ro<br />
  ot\LEGACY_ZWUNZI_SERVICE\0000</p>
<p>  * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Roo<br />
  t\LEGACY_ZWUNZI_SERVICE\0000\Control<br />
  * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services<br />
  \Zwunzi Service<br />
  * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<br />
  Zwunzi Service\Enum</p>
<p>  * HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<br />
  Zwunzi Service\Security</p>
<p>The program is installed as a Browser Search Plugin for Internet Explorer <br />
  and Mozilla Firefox and redirects user searches to the following location:<br />
  zwunzi.com</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Rixobot. Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please click here for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32-rixobot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Noobert</title>
		<link>http://www.registrycleanergeeks.com/worm/w32-noobert/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32-noobert/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 14:57:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1564</guid>
		<description><![CDATA[Discovered: December 23, 2009 Updated: December 23, 2009 1:03:39 PM Type: Worm Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Noobert you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1564"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>December 23, 2009</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">December 23, 2009 1:03:39 PM</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>Worm</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Noobert   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Noobert. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="508">
<tbody>
<tr class="blue">
<td width="476"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>When the worm executes, it decrypts the host file, saves it to the following location, and executes it:</p>
<p>%Temp%\NOO[RANDOM CHARACTERS]</p>
<p>Next, it copies %System%\ctfmon.exe to the following location:</p>
<p>%System%\ctfmon.dll</p>
<p>The worm then infects all .scr and .exe files on the compromised computer.</p>
<p>It also randomly deletes files with the extensions, depending on how long the computer has been turned on:</p>
<ul>
<li>.avi</li>
<li>.xls</li>
<li>.jpg</li>
<li>.doc</li>
</ul>
<p>The worm modifies the following files in order to disable Windows File Protection:</p>
<ul>
<li>%System%\SFC_OS.dll</li>
<li>%System%\dllcache\SFC_OS.dll</li>
</ul>
<p>It also disables Windows File Protection by modifying the following registry entry:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&#8221;SFCDisable&#8221; = &#8220;1&#8243;</p>
<p>The worm spreads through the eMule file-sharing network.</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can remove W32.Noobert. Click the link below for your free download &amp; scan your PC now.</p>
<p><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a rel="nofollow" href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-122312-1738-99&amp;tabid=3" target="_blank">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32-noobert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Gord</title>
		<link>http://www.registrycleanergeeks.com/trojan/gord/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/gord/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 14:53:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1561</guid>
		<description><![CDATA[Discovered: December 17, 2009 Updated: December 17, 2009 5:25:39 PM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Solaris, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Linux, Windows 2000 Recommended Action: In order to Remove Trojan.Gord you need to Download the ‘No Adware’ remover software. Based on our testing this was [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1561"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>December 17, 2009</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">December 17, 2009 5:25:39 PM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Trojan</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 98, Windows 95, Windows XP, Solaris, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Linux, Windows 2000</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Gord   you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Trojan.Gord. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="508">
<tbody>
<tr class="blue">
<td width="476"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>Trojan.Gord is a Mozilla XUL application which may overwrite Firefox&#8217;s default XUL overlay configuration file.</p>
<p>  The Trojan may be found in the configuration path for Mozilla Firefox.</p>
<p>  It may also create the following file:<br />
  %CurrentFolder%\_cfg.js</p>
<p>  The  Trojan then monitors queries to popular search engines and modifies the  returned results with data obtained from an external domain.</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Gord. Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a rel="nofollow" href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-121713-1223-99&#038;tabid=3" target="_blank">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/gord/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Infostealer.Kenzero</title>
		<link>http://www.registrycleanergeeks.com/trojan/infostealerkenzero/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/infostealerkenzero/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 17:12:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1498</guid>
		<description><![CDATA[Discovered: November 27, 2009 Updated: November 28, 2009 1:10:06 PM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Infostealer.Kenzero you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1498"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>November 27, 2009</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">November 28, 2009 1:10:06 PM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Trojan</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Infostealer.Kenzero you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Infostealer.Kenzero.. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="500">
<tbody>
<tr class="blue">
<td width="468"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>The malicious file typically arrives as an installation file for certain computer games.</p>
<p>When the Trojan is executed, it threat takes a screenshot of desktop and saves it as the following:<br />
    %Systemdrive%\[RANDOM LETTERS]\[RANDOM LETTERS].bmp</p>
<p>Then the Trojan converts the saved .bmp file to a JPEG file and saves it as the following:<br />
    %SystemDrive%\[RANDOM LETTERS]\[RANDOM LETTERS].jpg</p>
<p>Next it sends the screenshot to the following FTP site:<br />
    [ftp://]ftp96.heteml.jp/web/img/us[REMOVED]
  </p>
<p>It connects to the following URLs to obtain global IP address and the host name of the infected machine:</p>
<p> * [http://]cplayer.dreamhosters.com/getho[REMOVED]<br />
    * [http://]checkip.dyndns.org[REMOVED]</p>
<p>Then, it displays a form and requests the user to fill it with the following information:</p>
<p> * first name<br />
    * family name<br />
    * email address<br />
    * password<br />
    * first name in game<br />
    * family name in game<br />
    * gender<br />
    * birth date<br />
    * company name<br />
    * telephone number<br />
    * zip code<br />
    * address
  </p>
<p>It also steals the following information from the compromised machine:</p>
<p> * computer name<br />
    * domain name<br />
    * OS type<br />
    * time<br />
    * clipboard</p>
<p>Then the Trojan sends the stolen information to the following URL:<br />
    [http://]p3p.jp/en[REMOVED]/
  </p>
<p>When the Trojan exits, it displays the following URL with the gathered information using default browser:<br />
    [http://]p3p.jp/entry/user/[RANDOM [REMOVED]</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Infostealer.Kenzero. Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a rel="nofollow" href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-112708-3058-99&#038;tabid=3" target="_blank">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/infostealerkenzero/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Sipem!inf</title>
		<link>http://www.registrycleanergeeks.com/trojan/w32sipeminf/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/w32sipeminf/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 11:04:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1496</guid>
		<description><![CDATA[Discovered: November 27, 2009 Updated: November 27, 2009 10:10:59 AM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Sipem!inf you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1496"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>November 27, 2009</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">November 27, 2009 10:10:59 AM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Trojan</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Sipem!inf you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Sipem!inf.. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="500">
<tbody>
<tr class="blue">
<td width="468"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>W32.Sipem!inf is a detection for files that are infected by W32.Sipem.</p>
<p>When the infected file executes, it drops a .sys file in the %Temp% folder and loads it as a service.</p>
<p>Next, it hooks the following processes in order to reinfect the file whenever the computer restarts:</p>
<p> * ExitProcess<br />
    * ExitWindowsEx</p>
<p>It also hooks the CreateFileW process in order to drop and execute a .dll file in the following folder:<br />
    %Temp%</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Sipem!inf. Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a rel="nofollow" href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-112710-1059-99&#038;tabid=3" target="_blank">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/w32sipeminf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Pykspa.E</title>
		<link>http://www.registrycleanergeeks.com/worm/w32pykspae/</link>
		<comments>http://www.registrycleanergeeks.com/worm/w32pykspae/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 21:06:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1493</guid>
		<description><![CDATA[Discovered: November 20, 2009 Updated: November 20, 2009 7:54:48 PM Type: Worm Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove W32.Pykspa.E you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1493"></span></p>
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>November 20, 2009</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">November 20, 2009 7:54:48 PM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Worm</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove W32.Pykspa.E you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of W32.Pykspa.E.. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="500">
<tbody>
<tr class="blue">
<td width="468"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>Once executed, the worm copies itself to the following files:</p>
<p>* %System%\[RANDOM FILE NAME].exe</p>
<p>* %Temp%\[RANDOM FILE NAME].exe</p>
<p>The worm creates the following registry entries, so that it runs every time</p>
<p>Windows starts:</p>
<p>* HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion</p>
<p>\policies\Explorer\Run\&#8221;[RANDOM FILE NAME]&#8221; = &#8220;[RANDOM FILE</p>
<p>NAME].exe&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion</p>
<p>\policies\Explorer\Run\&#8221;[RANDOM FILE NAME]&#8221; = &#8220;%Temp%\(ramdom).exe&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\</p>
<p>Run\&#8221;[RANDOM FILE NAME]&#8221; = &#8220;%Temp%\[RANDOM FILE NAME].exe&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\</p>
<p>Run\&#8221;[RANDOM FILE NAME]&#8221; = &#8220;(ramdom).exe&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\</p>
<p>RunOnce\&#8221;[RANDOM FILE NAME]&#8221; = &#8220;%Temp%\[RANDOM FILE</p>
<p>NAME].exe .&#8221;</p>
<p>* HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\</p>
<p>RunOnce\&#8221;[RANDOM FILE NAME]&#8221; = &#8220;[RANDOM FILE NAME].exe .&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Run\&#8221;[RANDOM FILE NAME]&#8221; = &#8220;%Temp%\[RANDOM FILE NAME].exe&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Run\&#8221;[RANDOM FILE NAME]&#8221; = &#8220;[RANDOM FILE NAME].exe&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>RunOnce\&#8221;[RANDOM FILE NAME]&#8221; = &#8220;[RANDOM FILE NAME].exe .&#8221;</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>RunOnce\&#8221;[RANDOM FILE NAME]&#8221; = &#8220;%Temp%\[RANDOM FILE</p>
<p>NAME].exe .&#8221;</p>
<p>It modifies the following registry entries to bypass the Windows firewall:</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Security</p>
<p>Center\&#8221;FirewallDisableNotify&#8221; = &#8220;1&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Security</p>
<p>Center\&#8221;FirewallOverride&#8221; = &#8220;1&#8243;</p>
<p>The worm modifies the following registry entries in order to lower security</p>
<p>settings:</p>
<p>* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion</p>
<p>\Policies\System\&#8221;DisableRegistryTools&#8221; = &#8220;1&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current</p>
<p>Version\policies\system\&#8221;DisableRegistryTools&#8221; = &#8220;1&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Security</p>
<p>Center\&#8221;UpdatesDisableNotify&#8221; = &#8220;1&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current</p>
<p>Version\policies\system\&#8221;EnableLUA&#8221; = &#8220;0&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Security</p>
<p>Center\&#8221;AntiVirusDisableNotify&#8221; = &#8220;1&#8243;</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Security</p>
<p>Center\&#8221;AntiVirusOverride&#8221; = &#8220;1&#8243;</p>
<p>It then modifies the following registry entry to alter Explorer settings:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current</p>
<p>Version\policies\Explorer\&#8221;NoDriveTypeAutoRun&#8221; = &#8220;1&#8243;</p>
<p>The worm modifies the following registry entry in order to hide its presence:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current</p>
<p>Version\Explorer\Advanced\Folder\Hidden\SHOWALL\&#8221;CheckedValue&#8221;</p>
<p>= &#8220;145&#8243;</p>
<p>It also modifies the following registry entry to alter Explorer settings:</p>
<p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</p>
<p>Policies\Explorer\&#8221;NoDriveTypeAutoRun&#8221; = &#8220;181&#8243;</p>
<p>The worm then deletes registry entries to prevent the compromised computer</p>
<p>f<br />
rom restarting in safe mode.</p>
<p>The worm gathers credentials from different Web sites along with information</p>
<p>regarding the user&#8217;s Skype account and then sends the confidential information</p>
<p>back to the remote attacker.</p>
<p>The worm supports 18 different languages schemes, depending on the platform&#8217;s</p>
<p>language configuration.</p>
<p>In order to spread, it will try to send Skype IM messages to the user&#8217;s contacts.</p>
<p>The messages may have the following characteristics:</p>
<p>* crazy bitch</p>
<p>* do you have camera on skype?</p>
<p>* from where are you?</p>
<p>* hello</p>
<p>* hello again</p>
<p>* hi</p>
<p>* how are you</p>
<p>* I know what you did</p>
<p>* I saw you last week. I would like to speak with you</p>
<p>* I saw you photo. I would like to speak with you</p>
<p>* I watching you long time. I would like to speak with you</p>
<p>* idiot</p>
<p>* is it really your web site?</p>
<p>* now everyone know <img src='http://www.registrycleanergeeks.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>* piece of shit</p>
<p>* pudge women <img src='http://www.registrycleanergeeks.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>* so what do you think?</p>
<p>* what are you doing</p>
<p>* what are you doing in my contacts?</p>
<p>* what are you?</p>
<p>* what do you think about that?</p>
<p>* what is in that link on your skype?</p>
<p>* what is there?</p>
<p>* why dont you speak</p>
<p>* you skype version is old</p>
<p>The worm may spread by sending a URL pointing to a copy of itself to the</p>
<p>user&#8217;s contacts.</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove W32.Pykspa.E. Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a rel="nofollow" href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-112015-3449-99&amp;tabid=3" target="_blank">click here</a> for manual removal instructions.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/worm/w32pykspae/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Backdoor.Revird</title>
		<link>http://www.registrycleanergeeks.com/trojan/backdoorrevird/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/backdoorrevird/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 17:41:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1487</guid>
		<description><![CDATA[Discovered: November 14, 2009 Updated: November 14, 2009 2:34:17 AM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Backdoor.Revird you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1487"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>November 14, 2009</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">November 14, 2009 2:34:17 AM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Trojan</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Backdoor.Revird  you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of Backdoor.Revird .. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="504">
<tbody>
<tr class="blue">
<td width="472"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>Once executed, the Trojan creates the following files:</p>
<p> * %System%\nwwwks.dll<br />
  * %System%\rdisk.dll<br />
  * %System%\skeys.dll<br />
  * %System%\SvcHost.DLL.exe<br />
  * %System%\SvcHost.DLL.log</p>
<p>It then creates the following folder:<br />
  %SystemDrive%\drivers\own\</p>
<p>The Trojan registers the file %System%\nwwwsk.dll as a new service with the following characteristics, so that it runs every time Windows starts:<br />
  Service Name: Gateway Service For Netware<br />
  Display Name: Gateway Service for Netware<br />
  Startup Type: Automatic</p>
<p>It creates the service by adding entries to the following registry subkey:<br />
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWC<br />
  workstation</p>
<p>The Trojan opens a back door on the compromised computer allowing a <br />
  remote attacker to perform some of the following actions:</p>
<p> * Download, upload, delete and execute files<br />
  * List, stop, and start processes and services.</p>
<p>It gathers the following information on the compromised computer:</p>
<p> * Available Network Resources<br />
  * Computer Name<br />
  * Drives connected and type of drive.<br />
  * Free Space on each drive<br />
  * Operating System and Version<br />
  * Processor Type<br />
  * System Memory<br />
  * System uptime<br />
  * User Name.</p>
<p>The Trojan copies all files with the following extensions to the %SystemDrive%\drivers\own\ folder and sends them to a predetermined <br />
  remote location:</p>
<p> * .doc<br />
  * .pdf<br />
  * .ppt<br />
  * .rar<br />
  * .zip
</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Backdoor.Revird . Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a rel="nofollow" href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-111401-0512-99&#038;tabid=3" target="_blank">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/backdoorrevird/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Trojan.Avalanec</title>
		<link>http://www.registrycleanergeeks.com/trojan/avalanec/</link>
		<comments>http://www.registrycleanergeeks.com/trojan/avalanec/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 16:11:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.registrycleanergeeks.com/?p=1489</guid>
		<description><![CDATA[Discovered: November 13, 2009 Updated: November 13, 2009 12:04:28 PM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Recommended Action: In order to Remove Trojan.Avalanec you need to Download the ‘No Adware’ remover software. Based on our testing this was the best [...]]]></description>
			<content:encoded><![CDATA[<p><span id="more-1489"></span><br />
<table border="0" cellspacing="2" cellpadding="10" width="500">
<tbody>
<tr class="blue">
<td width="81"><strong>Discovered:</strong></td>
<td width="373"><strong> </strong>November 13, 2009</td>
</tr>
<tr>
<td width="81"><strong>Updated:</strong></td>
<td width="373">
<p align="left">November 13, 2009 12:04:28 PM</p>
</td>
</tr>
<tr class="blue">
<td><strong>Type: </strong></td>
<td>
<p align="left">Trojan</p>
</td>
</tr>
<tr>
<td><strong>Systems Affected: </strong></td>
<td>
<p align="left">Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</p>
</td>
</tr>
<tr class="blue">
<td colspan="2"><strong>Recommended Action:</strong></td>
</tr>
<tr>
<td colspan="2"><img src="/images/1.jpg" alt="" /> In order to Remove Trojan.Avalanec  you need to <a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><strong>Download the ‘No Adware’ remover software</strong></a>. Based on our testing this was the best peforming remover of  Trojan.Avalanec.. Read our full <a href="/spyware/no-adware-review/">No Adware Review</a></td>
</tr>
</tbody>
</table>
<p><a rel="nofollow" href="/go/s/noadware.php" target="_blank"><img class="alignleft" src="/images/no-adware-review-sml.png" alt="No Adware Review" /></a></p>
<table border="0" cellspacing="4" cellpadding="12" width="510">
<tbody>
<tr class="blue">
<td width="478"><strong>Technical Details:</strong></td>
</tr>
<tr>
<td>
<p>When the Trojan is executed, it copies itself to the following location:<br />
  %System%\sysservice.exe</p>
<p>It also creates the following configuration file:<br />
  %System%\sysservice.dll</p>
<p>Next, the Trojan creates the following registry entry so that it executes whenever <br />
  Windows starts:<br />
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current<br />
  Version\Run\&quot;Microsoft Startup Manager&quot; = &quot;%System%\sysservice.exe&quot;</p>
<p>It also creates the following registry entry in order to add itself to the list of <br />
  applications authorized by the Windows firewall:<br />
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Shared<br />
  Access\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\<br />  &quot;%System%\sysservice.exe&quot; = &quot;%System%\sysservice.exe:*:Enabled:DNS client&quot;</p>
<p>The Trojan then connects to one of the following locations and downloads an<br /> <br />
  updated configuration file and back door commands:</p>
<p> * [http://]www.kfw8f23.net/bn/file[REMOVED]<br />
  * [http://]www.g43gwef.com/bn/file[REMOVED]<br />
  * [http://]www.avrergq.com/bn/file[REMOVED]<br />
  * [http://]www.hwrgtwer.net/bn/file[REMOVED]<br />
  * [http://]www.vgerferge.com/bn/file[REMOVED]</p>
<p>It may then perform the following actions on the compromised computer:</p>
<p> * Update the configuration information<br />
  * Report details about the compromised computer to a remote attacker<br />
  * Update itself<br />
  * Download a file and execute it<br />
  * Act as a proxy</p>
</p>
</td>
</tr>
<tr class="blue">
<td><strong>Action Steps: </strong></td>
</tr>
<tr>
<td><strong><img src="/images/1.jpg" alt="" /> FREE SCAN: </strong>NoAdware can Remove Trojan.Avalanec. Click the link below for your free download &amp; scan your PC now.</p>
<p align="left"><a rel="nofollow" href="http://www.registrycleanergeeks.com/go/s/noadware.php" target="_blank"><img src="/images/1.png" border="0" alt="" /></a></p>
<p>Please <a rel="nofollow" href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-111310-4825-99&#038;tabid=3" target="_blank">click here</a> for manual removal instructions.</p>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.registrycleanergeeks.com/trojan/avalanec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
