<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Tech Blogs</title>
	<atom:link href="http://www.precisesecurity.com/blogs/feed" rel="self" type="application/rss+xml" />
	<link>http://www.precisesecurity.com/blogs</link>
	<description></description>
	<lastBuildDate>Thu, 09 Feb 2012 00:49:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Virus.Win32.Virut.ce</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce</link>
		<comments>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comments</comments>
		<pubDate>Wed, 11 Feb 2009 09:26:34 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Virus.Win32.Virut.ce can infect and overwrite files to be able to execute and spread itself. Virus.Win32.Virut.ce can also block access to security websites by modifying the Windows Hosts file. It can also inject malicious iframe on web files such as .HTM, .PHP or .ASP. The Trojan will badly infect .exe and .scr files on the computer resulting to severe malfunctions. Category: Trojan Horse Risk Level: High Aliases: W32.Virut.CF W32/Virut.n PE_VIRUX.A-1 W32/Scribble-A Virus:Win32/Virut.BM Technical Details Characteristics: Virus.Win32.Virut.ce will infect executable files under MS Windows systems. The virus is [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Virus.Win32.Virut.ce can infect and overwrite files to be able to execute and spread itself. Virus.Win32.Virut.ce can also block access to security websites by modifying the Windows Hosts file. It can also inject malicious iframe on web files such as .HTM, .PHP or .ASP. The Trojan will badly infect .exe and .scr files on the computer resulting to severe malfunctions.</p>
<p><span id="more-2439"></span></p>
<p><strong>Category: </strong>Trojan Horse</p>
<p><strong>Risk Level: </strong>High</p>
<p><strong>Aliases:</strong></p>
<ul>
<li>W32.Virut.CF</li>
<li>W32/Virut.n</li>
<li>PE_VIRUX.A-1</li>
<li>W32/Scribble-A</li>
<li>Virus:Win32/Virut.BM</li>
</ul>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong><br />
Virus.Win32.Virut.ce will infect executable files under MS Windows systems. The virus is a Windows PE EXE file that is polymorphic in nature. This Trojan will embed malicious code into processes running on the compromised computer. Next, the code seizes critical system functions to trace running application and open files. Upon detecting an initiated application, it infects the main executable file. Since this is a polymorphic PE EXE virus, it will write its own code on expanded PE portion of file. This action will result to the adjustment of the program’s entry point, which leads to the execution of the virus code.</p>
<p>The virus may infect every executable item very badly. It renders the compromised file irrecoverable. Antivirus applications may attempt to remove part of the infected code but the result is catastrophic. What the virus does is irreversible.</p>
<p><strong>Distribution Method:</strong><br />
Computer users may acquire Virus.Win32.Virut.ce in various ways. Web site employing a drive-by-download method can instantly drop and execute this Trojan on visitor’s computer. Another means to spread this infection is through spam email messages and peer-to-peer network connections.</p>
<p>When it is set inside the computer, it monitors running processes and inject its code into the address space. It is intended to infect other executable files that have .exe and .scr extensions.</p>
<h2>Recommended Virus.Win32.Virut.ce Removal Procedure</h2>
<p>1. Temporarily Disable System Restore (Windows Me/XP). <a href="http://www.precisesecurity.com/how-to/ht-srxp.htm" target="_blank">[how to]</a><br />
2. Update the virus definitions.<br />
3. Reboot computer in SafeMode <a href="http://www.precisesecurity.com/how-to/ht-smode.htm" target="_blank">[how to]</a><br />
4. Run a full system scan and clean/delete all infected file(s)<br />
5. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with <a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/remove-threats-with-online-virus-scanner/" target="_blank">Online Virus Scanner</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/feed</wfw:commentRss>
		<slash:comments>91</slash:comments>
		</item>
		<item>
		<title>Spyware Protect 2009</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/30/spyware-protect-2009</link>
		<comments>http://www.precisesecurity.com/blogs/2008/12/30/spyware-protect-2009#comments</comments>
		<pubDate>Tue, 30 Dec 2008 10:31:11 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Unwanted Programs]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/30/spyware-protect-2009/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Spyware Protect 2009 is a counterfeit antispyware program that can be acquired by visiting malicious websites or via Trojan Downloader and Trojan Zlob.  Upon infection by a Trojan, it will connect to a remote server and download a copy of Spyware Protect 2009 and install it on the compromised computer. This rogue program will attempt to convince computer users to pay for the registered version of the program by displaying fabricated can results and frequent alert messages. This program will also modify Internet Explorer configuration to redirect web browser to [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Spyware Protect 2009 is a counterfeit antispyware program that can be acquired by visiting malicious websites or via Trojan Downloader and Trojan Zlob.  Upon infection by a Trojan, it will connect to a remote server and download a copy of Spyware Protect 2009 and install it on the compromised computer. This rogue program will attempt to convince computer users to pay for the registered version of the program by displaying fabricated can results and frequent alert messages.</p>
<p>This program will also modify Internet Explorer configuration to redirect web browser to another fake security websites and download another malware. To avoid this instances, it is advised to remove any Trojan and files associated with it using legit anti-malware program when symptoms were observed on computer. <span id="more-2130"></span></p>
<p><strong>Aliases:</strong><br />
-</p>
<p><strong>Risk Level:</strong> Medium</p>
<p><strong>Affected System:</strong> Windows</p>
<p><strong>Common Symptoms:</strong></p>
<p>1. Internet browser or homepage will be redirected to the following websites:</p>
<ul>
<li>antiwareprotect.com</li>
<li>spyware-protect-2009.com</li>
<li>spwprotect2009.com</li>
<li>spywprotect.com</li>
<li>sysprotect.net</li>
<li>antivirus-win.com</li>
<li>spy-protect-2009.com</li>
<li>swp2009.com</li>
</ul>
<p>2. Presence of files such as filedon.exe that can be downloaded from <strong>nerogiena.com/keshu/kebab/getexe.php?h=12</strong></p>
<p><a href="http://www.precisesecurity.com/blogs/wp-content/uploads/2008/12/spyware-protect-2009a1.jpg" target="_blank"><img title="image of Spyware Protect 2009 scanner" src="http://www.precisesecurity.com/blogs/wp-content/uploads/2008/12/spyware-protect-2009a1.jpg" alt="image of Spyware Protect 2009 scanner" width="400" height="267" /></a></p>
<p><a href="http://www.precisesecurity.com/blogs/wp-content/uploads/2008/12/spyware-protect-2009b.jpg" target="_blank"><img title="image of Spyware Protect 2009 registration" src="http://www.precisesecurity.com/blogs/wp-content/uploads/2008/12/spyware-protect-2009b.jpg" alt="image of Spyware Protect 2009 registration" width="400" height="267" /></a></p>
<p>3. It will display alert messages</p>
<p><img class="alignnone size-full wp-image-4161" title="spywareprotect2009alert" src="http://www.precisesecurity.com/blogs/wp-content/uploads/2008/12/spywareprotect2009alert.jpg" alt="spywareprotect2009alert" width="284" height="278" /></p>
<p><strong>Use MBAM as Spyware Protect 2009 Removal Tool</strong><br />
1. Use <a title="Spyware Protect 2009 removal tool" href="http://www.precisesecurity.com/tools-resources/adware-tools/malwarebytes-anti-malware/">MalwareBytes AntiMalware</a> to remove Spyware Protect 2009</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2008/12/30/spyware-protect-2009/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Spy Guard 2008</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/28/spy-guard-2008</link>
		<comments>http://www.precisesecurity.com/blogs/2008/12/28/spy-guard-2008#comments</comments>
		<pubDate>Sun, 28 Dec 2008 02:48:27 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Unwanted Programs]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/28/spy-guard-2008/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Spy Guard 2008 is a variant of Vundo trojans that spreads and infects computer with Potentially Unwanted Programs. Spy Guard 2008 display fake scan results to misleads computer users to acquire the registered version of the program. Aliases: - Risk Level: Low File Size: Varies Affected System: Windows</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p><span>Spy Guard 2008 is a variant of <span>Vundo</span> <span>trojans</span> that spreads and infects computer with Potentially Unwanted Programs. Spy Guard 2008 display fake scan results to misleads computer users to acquire the registered version of the program.</span><span id="more-2113"></span></p>
<p><strong>Aliases:</strong><br />
-</p>
<p><strong>Risk Level:</strong> Low</p>
<p><strong>File Size:</strong> Varies</p>
<p><strong>Affected System:</strong> Windows</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2008/12/28/spy-guard-2008/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Lsas.Blaster.Keyloger</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger</link>
		<comments>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger#comments</comments>
		<pubDate>Tue, 23 Dec 2008 08:31:28 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Headline]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Lsas.Blaster.Keyloger is part of the rogue program System Security which display it as a threat detected. It will then prompt users to download and install the said application. Though the said threat does not really exists on the computer, this scare tactics is currently employed by rogue program for deceptive purposes. A pop-up window with message appears. Internet Explorer is infected with worm Lsas.Blaster.Keyloger. This worm is trying to send your credit card details using Internet Explorer to connect to remote host. Update: October 14, 2009 [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Lsas.Blaster.Keyloger is part of the rogue program <a href="http://www.precisesecurity.com/blogs/2008/12/23/system-security">System Security</a> which display it as a threat detected. It will then prompt users to download and install the said application. Though the said threat does not really exists on the computer, this scare tactics is currently employed by rogue program for deceptive purposes. A pop-up window with message appears.<span id="more-2080"></span></p>
<blockquote><p>Internet Explorer is infected with worm Lsas.Blaster.Keyloger. This worm is trying to send your credit card details using Internet Explorer to connect to remote host.</p></blockquote>
<p><strong>Update: October 14, 2009</strong><br />
New harmful rogue program <a href="http://www.precisesecurity.com/rogue/securitytool">Security Tool</a> is also using this <strong>Lsas.Blaster.Keyloger</strong> as a threat to scare computer users and prompts them that only a registered program can remove it from a computer.</p>
<p><strong>Risk Level:</strong> Low</p>
<p><strong>File Size:</strong> Varies</p>
<p><strong>Affected System:</strong> Windows</p>
<p><strong>Screen Shot Images:</strong><br />
Lsas.Blaster.Keyloger is a widely used fake threat. Here are some samples of different bogus security warnings that displays Lsas.Blaster.Keyloger detection.</p>
<p style="text-align: center;"><img class="size-full wp-image-6950 aligncenter" title="Lsas-Blaster-alert1" src="http://www.precisesecurity.com/blogs/wp-content/uploads/2008/12/Lsas-Blaster-alert1.jpg" alt="" width="400" height="467" /></p>
<p style="text-align: center;"><img class="size-full wp-image-6951 aligncenter" title="Lsas-Blaster-alert2" src="http://www.precisesecurity.com/blogs/wp-content/uploads/2008/12/Lsas-Blaster-alert2.jpg" alt="" width="400" height="330" /></p>
<p style="text-align: center;"><img class="size-full wp-image-6952 aligncenter" title="Lsas-Blaster-alert3" src="http://www.precisesecurity.com/blogs/wp-content/uploads/2008/12/Lsas-Blaster-alert3.jpg" alt="" width="413" height="179" /></p>
<p style="text-align: center;"><img class="size-full wp-image-6953 aligncenter" title="Lsas-Blaster-alert4" src="http://www.precisesecurity.com/blogs/wp-content/uploads/2008/12/Lsas-Blaster-alert4.jpg" alt="" width="342" height="119" /></p>
<h4>How to Remove Lsas.Blaster.Keyloger</h4>
<p><strong>Use MBAM as Lsas.Blaster.Keyloger Removal Tool:</strong><br />
1. Download <a title="Lsas.Blaster.Keyloger removal tool" href="http://www.precisesecurity.com/tools-resources/adware-tools/malwarebytes-anti-malware/" target="_blank">Malwarebytes’ Anti-Malware</a> (mbam-setup.exe) and save it on your Desktop.<br />
2. After downloading, double-click on mbam-setup.exe to install the application.<br />
3. Follow the prompts and install as “default” only<br />
4. Before the installation completes, check on the following prompts:<br />
- Update Malwarebytes’ Anti-Malware<br />
- Launch Malwarebytes’ Anti-Malware<br />
5. Click “Finish.” Program will run automatically and you will be prompt to update the program before doing a scan. Please update.<br />
6. Scan your computer thoroughly.<br />
7. When scanning is finished click on the “Show Results”<br />
8. Make sure that all detected threats are marked, click on Remove Selected.<br />
9. Restart your computer.</p>
<p><em>Note: Lsas.Blaster.Keyloger may prevent mbam-setup.exe from downloading and running. You can download and rename this program from a different computer before running it on infected system.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2008/12/23/lsasblasterkeyloger/feed</wfw:commentRss>
		<slash:comments>49</slash:comments>
		</item>
		<item>
		<title>~dulla@204 Virus</title>
		<link>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus</link>
		<comments>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus#comments</comments>
		<pubDate>Wed, 10 Dec 2008 12:00:14 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>~dulla@204 is a harmful virus that can stop operation of document applications such as Microsoft Word, Excel, Powerpoint and Adobe Acrobat. ~dulla@204 also modifies Windows Registry and adds its own key to run itself when Windows starts. When attempting to open a document file, it will display “~dulla@204”. Category: Virus Risk Level: High Technical Details Characteristics: Once executed, this virus will drop several files under Windows directory. These files bears random name like ~jmkiteyd~.exe, which is around 43kb (44032 bytes) in size. To run ~dulla@204 on [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>~dulla@204 is a harmful virus that can stop operation of document applications such as Microsoft Word, Excel, Powerpoint and Adobe Acrobat. ~dulla@204 also modifies Windows Registry and adds its own key to run itself when Windows starts. When attempting to open a document file, it will display “~dulla@204”.<span id="more-2019"></span></p>
<p><strong>Category: </strong>Virus</p>
<p><strong>Risk Level: </strong>High</p>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong></p>
<p>Once executed, this virus will drop several files under Windows directory. These files bears random name like ~jmkiteyd~.exe, which is around 43kb (44032 bytes) in size.</p>
<p>To run ~dulla@204 on every Windows start-up, it will add the following registry entries:</p>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services =”~dulla@204”</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services =”~dulla@204”</li>
<li>HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run “~jmkiteyd~.exe”</li>
</ul>
<p>When loaded, ~dulla@204 virus may infect executable files on the compromised computer as a method to propagate. The same process is applied on a network to distribute a copy of itself. Once running on the computer, ~dulla@204 will corrupt all document files by altering part of the header, which makes it irrecoverable.</p>
<p><strong>Distribution Method:</strong><br />
Computer users may acquire ~dulla@204 from malicious web sites or legitimate site that are compromised with a Trojan. Visiting these sites may download and execute ~dulla@204 without visitors notice. Once on the system, this virus will infect .EXE files. It will also look for connected computers and do the same on network-shared drives.</p>
<h2>Recommended ~dulla@204 Removal Procedure</h2>
<p>1. Temporarily Disable System Restore (Windows Me/XP). <a href="http://www.precisesecurity.com/how-to/ht-srxp.htm" target="_blank">[how to]</a><br />
2. Update the virus definition of your antivirus program.<br />
3. Reboot computer in SafeMode <a href="http://www.precisesecurity.com/how-to/ht-smode.htm" target="_blank">[how to]</a><br />
4. Use antivirus program to run a full system scan and clean/delete all infected file.<br />
To manually delete associated files, please browse Windows directory and look for files similar to ~jmkiteyd~.exe (43kb). When found, delete carefully one at a time.</p>
<p>5. Delete/Modify any values added to the registry. <a href="http://www.precisesecurity.com/how-to/ht-regedit.htm" target="_blank">[how to edit registry]</a><br />
Navigate to and delete the following registry entry:<br />
<em>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services =”~dulla@204”</em><br />
<em> HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services =”~dulla@204”</em><br />
<em> HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run “~jmkiteyd~.exe”</em></p>
<p>6. Exit registry editor and restart the computer.<br />
7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with <a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/remove-threats-with-online-virus-scanner/" target="_blank">Online Virus Scanner</a>.</p>
<p>8. Addition removal tool can be found on this web site : http://www.insa.gov.et/INSA/faces/downloads/downloads.jsp</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2008/12/10/dulla204-virus/feed</wfw:commentRss>
		<slash:comments>227</slash:comments>
		</item>
		<item>
		<title>go.google &#8211; go.yahoo</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects</link>
		<comments>http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects#comments</comments>
		<pubDate>Sun, 16 Nov 2008 09:59:24 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>go.google, go.yahoo and go.msn are browser hijacker that dominantly redirect web browser to a fake online virus scanner web sites. go.google and go.yahoo existence is a result of a Trojan infection that has a payload of modifying browser settings, disable locally installed security programs and monitor Internet activity of the infected computer. go.google, go.yahoo and go.msn web sites do not exist. It is an error page created locally that is configured to redirect to various fake security web sites. The site will run a fake online virus [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>go.google, go.yahoo and go.msn are browser hijacker that dominantly redirect web browser to a fake online virus scanner web sites. go.google and go.yahoo existence is a result of a Trojan infection that has a payload of modifying browser settings, disable locally installed security programs and monitor Internet activity of the infected computer.<span id="more-1954"></span></p>
<p>go.google, go.yahoo and go.msn web sites do not exist. It is an error page created locally that is configured to redirect to various fake security web sites. The site will run a fake online virus scanner that later detects numerous types of computer infections. It will advise visitors to clean these threats using a recommended tool. However, before the program can proceed to its scan and detect features, user must purchase first the registration key. This tactic is a clear indication of a fraud activity perpetuated by fake antivirus applications.</p>
<p><strong>Screen Shot:</strong></p>
<p style="text-align: center;"><img class="aligncenter" title="security-tool-2010" src="http://www.precisesecurity.com/wp-content/uploads/2010/04/security-tool-2010.jpg" alt="go.google.com and go.yahoo.com" width="400" height="328" /></p>
<p><strong>Category: </strong>Trojan Horse</p>
<p><strong>Risk Level: Medium</strong></p>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong><br />
go.google.com, go.yahoo.com and go.msn.com are odd Internet browser behavior that can be attributed as browser hijacker. This infection is brought about by a Trojan infection that may also cause multiple system misbehavior. The obvious sign for this type of infection on the computer is having the home page or search result be forwarded to any of the mentioned deficient domains.</p>
<p>Once the Trojan invades the system, it will drop the following malicious files to accomplish its objective:<br />
<em>C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll</em><br />
<em> C:\WINDOWS\karna.dat</em><br />
<em> C:\WINDOWS\system32\karna.dat</em><br />
<em> C:\WINDOWS\system32\dllcache\beep.sys</em><br />
<em> C:\WINDOWS\system32\wini10802.</em><br />
<em> C:\WINDOWS\system32\brastk.exe</em><br />
<em> C:\WINDOWS\system32\TDSS(four random characters).dll</em><br />
<em>C:\WINDOWS\system32\drivers\TDSSserv.sys</em><br />
<em> C:\WINDOWS\system32\drivers\TDSS(four random characters).sys</em></p>
<p>Next, it will conquer the registry to obtain start-up spot. It adds the following registry entries:<br />
<em>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata</em><br />
<em> HKEY_LOCAL_MACHINE\SOFTWARE\tdss</em><br />
<em> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\brastk</em><br />
<em> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\brastk</em></p>
<h2>Recommended go.google &#8211; go.yahoo Removal Procedure</h2>
<p>Here is a simple step-by-step procedure to remove go.google &#8211; go.yahoo virus from an infected computer. Please follow the steps carefully.</p>
<p><strong>1.</strong> Download <a href="http://www.precisesecurity.com/tools-resources/adware-tools/malwarebytes-anti-malware">Malwarebytes’ Anti-Malware</a> (mbam-setup.exe) and save it on your Desktop or any accessible location of your hard drive.</p>
<p><strong>2.</strong> After downloading, double-click on the file to install the application.</p>
<p><strong>3.</strong> Follow the prompts and install the program using the “default” settings.</p>
<p><strong>4.</strong> Before the installation completes, check on the following prompts:<br />
- Update Malwarebytes’ Anti-Malware<br />
- Launch Malwarebytes’ Anti-Malware</p>
<p><strong>5.</strong> Click <strong>Finish</strong>. Program will run automatically and you will be prompt to update the program before starting a scan. Please proceed with update to obtain the latest database necessary to detect and remove go.google &#8211; go.yahoo.</p>
<p><strong>6.</strong> Scan your computer thoroughly and completely check all files, folders and registry entries for possible infection.</p>
<p><strong>7.</strong> When scanning is finished, click on <strong>Show Results</strong>.</p>
<p><strong>8.</strong> Make sure that all detected threats are marked, click on <strong>Remove Selected</strong>.</p>
<p><strong>9.</strong> After removing items associated with go.google &#8211; go.yahoo, it will prompt to restart the computer. Click <strong>Yes</strong> to complete the cleaning process.</p>
<p><strong>10.</strong> When computer starts, open MalwareBytes Anti-Malware. Go to <strong>Quarantine</strong> tab and click on <strong>Delete All</strong> to fully remove all malicious items.</p>
<p><em>Note: go.google &#8211; go.yahoo &#8211; go.msn infection may prevent mbam-setup.exe from downloading and running. You can download and rename this program from a different computer before running it on infected system.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects/feed</wfw:commentRss>
		<slash:comments>80</slash:comments>
		</item>
		<item>
		<title>defender-review.com</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/16/defender-reviewcom</link>
		<comments>http://www.precisesecurity.com/blogs/2008/11/16/defender-reviewcom#comments</comments>
		<pubDate>Sun, 16 Nov 2008 02:42:15 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Hijacker]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/16/defender-reviewcom/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>defender-review.com is a counterfeit security web site. It highlights fake reviews about the counterfeit programs called Personal Defender 2009 and Perfect Defender 2009. Attackers behind rogue security application put-up this web site to promote rogue program. It also helps in misleading users and hides the actual goal of stealing money from its victims. defender-review.com produces uplifting information about the promoted product. In fact, these security applications are worthless and have no capability to protect the PC against virus attack. Current Status: Inactive Domain Registrant: Registrant: [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>defender-review.com is a counterfeit security web site. It highlights fake reviews about the counterfeit programs called <a href="http://www.precisesecurity.com/blogs/2008/10/30/personal-defender-2009">Personal Defender 2009</a> and <a href="http://www.precisesecurity.com/blogs/2008/12/02/perfect-defender-2009">Perfect Defender 2009</a>.<span id="more-1948"></span></p>
<p>Attackers behind rogue security application put-up this web site to promote rogue program. It also helps in misleading users and hides the actual goal of stealing money from its victims. defender-review.com produces uplifting information about the promoted product. In fact, these security applications are worthless and have no capability to protect the PC against virus attack.</p>
<p><strong>Current Status: </strong>Inactive</p>
<p><strong>Domain Registrant:</strong></p>
<blockquote><p>Registrant:<br />
kim white hostmaster@defender-review.com +1.6093472366<br />
PersonalDefender Inc<br />
702 broadway avenue<br />
egg harbor township,NJ,US 08234</p>
<p>Domain Name:defender-review.com<br />
Record last updated at 2008-10-29 13:58:08<br />
Record created on 2008/10/29<br />
Record expired on 2009/10/29</p>
<p>Domain servers in listed order:<br />
ns1.pdefzone.com   ns2.pdefzone.com</p></blockquote>
<p><strong>Risk Level:</strong> Medium</p>
<p><strong>Affected System:</strong> Windows</p>
<p><strong>Screen Shot Image:</strong></p>
<p style="text-align: center;"><img class="aligncenter" style="border: 0px currentColor;" title="defender-review.com" src="http://www.precisesecurity.com/images/threats/defender-review-com.jpg" alt="" width="500" height="377" border="0" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2008/11/16/defender-reviewcom/feed</wfw:commentRss>
		<slash:comments>92</slash:comments>
		</item>
		<item>
		<title>&#8220;Video ActiveX Object Error&#8221; now in Macintosh</title>
		<link>http://www.precisesecurity.com/blogs/2007/11/01/video-activex-object-error-now-in-macintosh</link>
		<comments>http://www.precisesecurity.com/blogs/2007/11/01/video-activex-object-error-now-in-macintosh#comments</comments>
		<pubDate>Thu, 01 Nov 2007 08:58:28 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[asides]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2007/11/01/video-activex-object-error-now-in-macintosh/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Have you visited movie websites, particularly porn ones and encounters an error &#8220;Video ActiveX Object Error;&#8221; did it prompt you to download and install a file to be able to display the video? If you have installed the video codec called MacCodec then you may have been infected with OSX.RSPlug.A. The PC-based fake codec used to trick users is now available on Mac systems. It has been described by Intego as: A malicious Trojan Horse has been found on several pornography web sites, claiming to install a video [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Have you visited movie websites, particularly porn ones and encounters an error &#8220;Video ActiveX Object Error;&#8221; did it prompt you to download and install a file to be able to display the video?<span id="more-1012"></span> If you have installed the video codec called <a href="http://www.precisesecurity.com/blogs/2007/11/01/maccodec">MacCodec</a> then you may have been infected with <a href="http://www.precisesecurity.com/threats/osxrspluga">OSX.RSPlug.A</a>.</p>
<p>The PC-based fake codec used to trick users is now available on Mac systems. It has been described by Intego as:</p>
<blockquote><p>A malicious Trojan Horse has been found on several pornography web sites, claiming to install a video codec necessary to view free pornographic videos on Macs. A great deal of spam has been posted to many Mac forums, in an attempt to lead users to these sites. When the users arrive on one of the web sites, they see still photos from reputed porn videos, and if they click on the stills, thinking they can view the videos, they arrive on a web page that says the following:</p>
<p><em><strong>Quicktime Player is unable to play movie file.<br />
Please click here to download new version of codec.</strong></em></p>
<p>After the page loads, a disk image (.dmg) file automatically downloads to the user’s Mac. If the user has checked Open “Safe” Files After Downloading in Safari’s General preferences (or similar settings in other browsers), the disk image will mount, and the installer package it contains will launch Installer. If not, and the user wishes to install this codec, they double-click the disk image to mount it, then double-click the package file, named install.pkg.</p>
<p>If the user then proceeds with installation, the Trojan horse installs; installation requires an administrator’s password, which grants the Trojan horse full root privileges. No video codec is installed, and if the user returns to the web site, they will simply come to the same page and receive a new download.</p></blockquote>
<p>Below are the images for the fake warnings:</p>
<p><img src="http://www.precisesecurity.com/images/threats/maccodec-error1.gif" alt="" /></p>
<p><img style="width: 345px; height: 281px;" src="http://www.precisesecurity.com/images/threats/maccodec-error2.gif" alt="" width="345" height="281" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2007/11/01/video-activex-object-error-now-in-macintosh/feed</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>Spyware.Cyberlog-x</title>
		<link>http://www.precisesecurity.com/blogs/2006/10/16/spywarecyberlog-x-removal</link>
		<comments>http://www.precisesecurity.com/blogs/2006/10/16/spywarecyberlog-x-removal#comments</comments>
		<pubDate>Mon, 16 Oct 2006 13:57:24 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Unwanted Programs]]></category>

		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/10/16/spywarecyberlog-x-removal/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Spyware.Cyberlog-x is a detection for a program that was developed to steal sensitive data from compromised computer. It used to log key strokes, record screen shot images, monitor Internet activities and steal user name and passwords. On the other hand, Spyware.Cyberlog-x is a threat detected by fake anti-spyware product that is normally bundled with different Trojans. This malware is utilizing fake Media Codecs as a way of persuading victims to install the rogue program. Risk Level: Medium Affected System: Windows Common Symptoms: 1. Fake security [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Spyware.Cyberlog-x is a detection for a program that was developed to steal sensitive data from compromised computer. It used to log key strokes, record screen shot images, monitor Internet activities and steal user name and passwords.<span id="more-495"></span></p>
<p>On the other hand, Spyware.Cyberlog-x is a threat detected by fake anti-spyware product that is normally bundled with different Trojans. This malware is utilizing fake Media Codecs as a way of persuading victims to install the rogue program.</p>
<p><strong>Risk Level:</strong> Medium</p>
<p><strong>Affected System:</strong> Windows</p>
<p><strong>Common Symptoms:</strong><br />
1. Fake security programs will pop-up a system tray messages stating that Spyware.Cyberlog-x is detected. The alert will have the following text:</p>
<blockquote><p><strong>Critical System Warning!</strong><br />
Your system is probably infected with the latest version of Spyware.Cyberlog-x.<br />
Type: Spyware<br />
Infection Length: 266,129 bytes<br />
Risk: High<br />
Systems Affected: Windows 95, 98, 2000, NT, 2003 Server, Windows XP, Windows Vista<br />
Behavior: Spyware.Cyberlog-x is a spyware program that monitors user activity, log keystrokes, and tracks Web sites visited.<br />
Symptoms: Low Internet connection speed<br />
Low system performance<br />
Security center alerts<br />
Strange pop up windows<br />
Protection: Click OK to download antispyware software.</p></blockquote>
<p style="text-align: center;"><img class="size-full wp-image-7636 aligncenter" title="Spyware-Cyberlog-x" src="http://www.precisesecurity.com/blogs/wp-content/uploads/2006/10/Spyware-Cyberlog-x.jpg" alt="" width="439" height="278" /></p>
<p>2. From the same rogue security application, additional taskbar alert will be shown emerging from the task bar.</p>
<ul>
<li>System Alert: Trojan-Spy.Win32@mx. Type: Spyware/Trojan.</li>
<li>Critical System Error! System Detected virus activities. They may cause critical system failure&#8230;</li>
</ul>
<p style="text-align: center;"><img class="aligncenter" src="http://precisesecurity.com/images/virusburst.gif" alt="Spyware.Cyberlog-x" width="551" height="138" /></p>
<h2>Recommended Spyware.Cyberlog-x Removal Tool</h2>
<p>Here is a simple step-by-step procedure to remove Spyware.Cyberlog-x virus from an infected computer. Please follow the steps carefully.</p>
<p><strong>1.</strong> Download <a href="http://www.precisesecurity.com/tools-resources/adware-tools/malwarebytes-anti-malware">Malwarebytes’ Anti-Malware</a> (mbam-setup.exe) and save it on your Desktop or any accessible location of your hard drive.</p>
<p><strong>2.</strong> After downloading, double-click on the file to install the application.</p>
<p><strong>3.</strong> Follow the prompts and install the program using the “default” settings.</p>
<p><strong>4.</strong> Before the installation completes, check on the following prompts:<br />
- Update Malwarebytes’ Anti-Malware<br />
- Launch Malwarebytes’ Anti-Malware</p>
<p><strong>5.</strong> Click <strong>Finish</strong>. Program will run automatically and you will be prompt to update the program before starting a scan. Please proceed with update to obtain the latest database necessary to detect and remove Spyware.Cyberlog-x.</p>
<p><strong>6.</strong> Scan your computer thoroughly and completely check all files, folders and registry entries for possible infection.</p>
<p><strong>7.</strong> When scanning is finished, click on <strong>Show Results</strong>.</p>
<p><strong>8.</strong> Make sure that all detected threats are marked, click on <strong>Remove Selected</strong>.</p>
<p><strong>9.</strong> After removing items associated with Spyware.Cyberlog-x, it will prompt to restart the computer. Click <strong>Yes</strong> to complete the cleaning process.</p>
<p><strong>10.</strong> When computer starts, open MalwareBytes Anti-Malware. Go to <strong>Quarantine</strong> tab and click on <strong>Delete All</strong> to fully remove all malicious items.</p>
<p><em>Note: Spyware.Cyberlog-x may prevent mbam-setup.exe from downloading and running. You can download and rename this program from a different computer before running it on infected system.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2006/10/16/spywarecyberlog-x-removal/feed</wfw:commentRss>
		<slash:comments>86</slash:comments>
		</item>
		<item>
		<title>Trojan.Zlob.K</title>
		<link>http://www.precisesecurity.com/blogs/2006/04/22/trojanzlobk-removal-blogs</link>
		<comments>http://www.precisesecurity.com/blogs/2006/04/22/trojanzlobk-removal-blogs#comments</comments>
		<pubDate>Sat, 22 Apr 2006 04:55:13 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/04/22/trojanzlobk-removal-blogs/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Zlob.K is a Trojan horse that may download and execute remote files and redirect Internet Explorer home page and search page to a different address. It may add encryption key to certain folders to hide associated files or any stolen data from the compromised computer. Category: Trojan Horse Risk Level: Low Aliases: TROJ_ZLOB.MU Trojan-Downloader.Win32.Zlob.s Downloader-XC Trojan.Zlob.B Technical Details Characteristics: Since Trojan.Zlob.K is a downloader, its goal is to download additional malware. It will communicate to predefined web sites, fetch malicious data, and run them on [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Zlob.K is a Trojan horse that may download and execute remote files and redirect Internet Explorer home page and search page to a different address. It may add encryption key to certain folders to hide associated files or any stolen data from the compromised computer. <span id="more-224"></span></p>
<p><strong>Category: </strong>Trojan Horse</p>
<p><strong>Risk Level: </strong>Low</p>
<p><strong>Aliases:</strong></p>
<ul>
<li>TROJ_ZLOB.MU</li>
<li>Trojan-Downloader.Win32.Zlob.s</li>
<li>Downloader-XC</li>
<li>Trojan.Zlob.B</li>
</ul>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong><br />
Since Trojan.Zlob.K is a downloader, its goal is to download additional malware. It will communicate to predefined web sites, fetch malicious data, and run them on the infected computer.</p>
<p>Once activated, the Trojan may drop the following files:<br />
<em>%System%\ncompat.tlb</em><br />
<em> %System%\interf.tlb</em><br />
<em> %System%\hp[RANDOM CHARACTERS].tmp</em></p>
<p>Then, it will add the following registry entry so that it executes on every Windows start-up:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\&#8221;nvctrl.exe&#8221; = &#8220;nvctrl.exe&#8221;</p>
<p>To gain automatic start-up when running Windows Explorer, this Trojan will set the following registry entry:<br />
<em>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run</em><br />
<em> notepad.exe</em><br />
<em> msmsgs.exe</em></p>
<p>Additional registry entry that calls the application file msmsgs.exe is added. This will also allow Trojan.Zlob.K to run on every Windows start-up.<br />
<em>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon</em><br />
<em> Shell = “msmsgs.exe”</em></p>
<p>Lastly, the Trojan will hide malicious activities by injecting codes into legitimate file Explorer.exe.</p>
<p><strong>Distribution Method:</strong><br />
Trojan.Zlob.K may arrive on target computer by means of another Trojan infection.</p>
<h2>Recommended Trojan.Zlob.K Removal Procedure</h2>
<p>1. Temporarily Disable System Restore (Windows Me/XP). <a href="http://www.precisesecurity.com/how-to/ht-srxp.htm" target="_blank">[how to]</a><br />
2. Update the virus definitions.<br />
3. Reboot computer in SafeMode <a href="http://www.precisesecurity.com/how-to/ht-smode.htm" target="_blank">[how to]</a><br />
4. Run a full system scan and clean/delete all infected file(s)<br />
5. Delete/Modify any values added to the registry. <a href="http://www.precisesecurity.com/how-to/ht-regedit.htm" target="_blank">[how to edit registry]</a><br />
Navigate to and delete the following registry entry:<br />
<em>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\&#8221;nvctrl.exe&#8221;</em><br />
<em> = &#8220;nvctrl.exe&#8221;</em></p>
<p>6. Exit registry editor and restart the computer.<br />
7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with <a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/remove-threats-with-online-virus-scanner/" target="_blank">Online Virus Scanner</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2006/04/22/trojanzlobk-removal-blogs/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Trojan.Galapoper.A</title>
		<link>http://www.precisesecurity.com/blogs/2006/04/20/trojangalapopera-removal-blogs</link>
		<comments>http://www.precisesecurity.com/blogs/2006/04/20/trojangalapopera-removal-blogs#comments</comments>
		<pubDate>Thu, 20 Apr 2006 09:16:51 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/04/20/trojangalapopera-removal-blogs/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Galapoper.A is a computer infection that when executed will communicate to a remote server to download additional risks onto target system. This Trojan may also steal user’s data and send it to an attacker using HTTP POST protocol or email communication. Trojan.Galapoper.A and its variants habitually download Trojans from other groups of Downloaders, which may result to additional infections. Category: Trojan Horse Risk Level: Low Aliases: Trojan-Downloader.TIBS Trojan.Galapoper.A Trojan-Downloader.Win32.Tibs.il Tibs WORM_NUCRP.GEN Mal/TibsPak, Mal/HckPk-A, Troj/Tibs-Fam TrojanDownloader:Win32/Vxidl.gen!A Trojan-Downloader.Win32.Tibs Win-Trojan/Tibs.7346.DN Technical Details Characteristics: When executed, Trojan.Galapoper.A will avoid [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Galapoper.A is a computer infection that when executed will communicate to a remote server to download additional risks onto target system. This Trojan may also steal user’s data and send it to an attacker using HTTP POST protocol or email communication. Trojan.Galapoper.A and its variants habitually download Trojans from other groups of Downloaders, which may result to additional infections.<span id="more-219"></span></p>
<p><strong>Category: </strong>Trojan Horse</p>
<p><strong>Risk Level: </strong>Low</p>
<p><strong>Aliases:</strong></p>
<ul>
<li>Trojan-Downloader.TIBS</li>
<li>Trojan.Galapoper.A</li>
<li>Trojan-Downloader.Win32.Tibs.il</li>
<li>Tibs</li>
<li>WORM_NUCRP.GEN</li>
<li>Mal/TibsPak, Mal/HckPk-A, Troj/Tibs-Fam</li>
<li>TrojanDownloader:Win32/Vxidl.gen!A</li>
<li>Trojan-Downloader.Win32.Tibs</li>
<li>Win-Trojan/Tibs.7346.DN</li>
</ul>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong><br />
When executed, Trojan.Galapoper.A will avoid antivirus detection by applying a method of obfuscation. IT also performs the following set of operations:</p>
<ul>
<li>Inform an attacker of computer infection through email</li>
<li>Create a copy of itself to various locations of the compromised system</li>
<li>Drop a number of infected and clean files</li>
<li>Communicate to predefined web sites to execute more malware</li>
<li>Disable any installed antivirus, firewall, and other security-related software</li>
<li>Steal sensitive information and send the gathered data to a remote attacker via email or HTTP POST protocol</li>
</ul>
<p><strong>Distribution Method:</strong><br />
This Trojan will arrive on computer with filename “zhopaizdupla.exe.” It is dropped by another Trojan infection that is usually obtained from malicious web sites and unsecured peer-to-peer connection.</p>
<h2>Recommended Trojan.Galapoper.A Removal Procedure</h2>
<p>1. Temporarily Disable System Restore (Windows Me/XP). <a href="http://www.precisesecurity.com/how-to/ht-srxp.htm" target="_blank">[how to]</a><br />
2. Update the virus definitions.<br />
3. Reboot computer in SafeMode <a href="http://www.precisesecurity.com/how-to/ht-smode.htm" target="_blank">[how to]</a><br />
4. Run a full system scan and clean/delete all infected file(s)<br />
5. Delete/Modify any values added to the registry. <a href="http://www.precisesecurity.com/how-to/ht-regedit.htm" target="_blank">[how to edit registry]</a><br />
Navigate to and delete the following registry entry:<br />
<em>HKEY_CURRENT_USER = &#8220;WindowsSubVersion&#8221; = &#8220;[VALUE]&#8220;</em></p>
<p>6. Exit registry editor and restart the computer.<br />
7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with <a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/remove-threats-with-online-virus-scanner/" target="_blank">Online Virus Scanner</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2006/04/20/trojangalapopera-removal-blogs/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Trojan.Zlob.J</title>
		<link>http://www.precisesecurity.com/blogs/2006/04/06/trojanzlobj-removal-blogs</link>
		<comments>http://www.precisesecurity.com/blogs/2006/04/06/trojanzlobj-removal-blogs#comments</comments>
		<pubDate>Thu, 06 Apr 2006 14:02:15 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/04/06/trojanzlobj-removal-blogs/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Zlob.J is a member of a Zlob family that refers to a large group of malware involving in malicious acts like modifying Internet browsers, redirect home page and search results, install fake security applications, and execute arbitrary file from a remote server. Trojan.Zlob.J also allows a remote attacker to access the compromised computer. Thus, the attacker may perform malicious actions and steal sensitive data from the infected system. Category: Trojan Horse Risk Level: Medium Technical Details Characteristics: Upon execution, Trojan.Zlob.J will drop the following harmful [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Zlob.J is a member of a Zlob family that refers to a large group of malware involving in malicious acts like modifying Internet browsers, redirect home page and search results, install fake security applications, and execute arbitrary file from a remote server. Trojan.Zlob.J also allows a remote attacker to access the compromised computer. Thus, the attacker may perform malicious actions and steal sensitive data from the infected system.<span id="more-183"></span></p>
<p><strong>Category: </strong>Trojan Horse</p>
<p><strong>Risk Level: </strong>Medium</p>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong><br />
Upon execution, Trojan.Zlob.J will drop the following harmful files:<br />
<em>%System%\ld[RANDOM CHARACTERS].tmp</em><br />
<em> %System%\dfrgsrv.exe</em></p>
<p>To gain automatic start-up spot, the Trojan will modify Windows registry and add the following entry:<br />
<em>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run</em><br />
<em> &#8220;wininet.dll&#8221; = &#8220;dfrgsrv.exe&#8221;</em></p>
<p>Alternative start-up method is to inject malicious code into the following Windows process that runs when Windows starts:<br />
<em>winlogon.exe</em></p>
<p>Once running on the compromised system, Trojan.Zlob.J will monitor Internet activities and may modify settings of the home page.<br />
Lastly, the Trojan will establish an HTTP connection to specified URL and performs the following actions:</p>
<ul>
<li>Ping the remote computer</li>
<li>Send a status report regarding the infected system</li>
<li>Download and execute remote files, which upgrade itself</li>
</ul>
<p><strong>Distribution Method:</strong><br />
Trojan.Zlob.J uses the web primarily to spread a copy of itself. Malicious web sites, infected web pages and unsafe file-sharing networks are the top sources of this Trojan. Once inside the computer, it may contaminate other files locally but will never spread on neighboring computers.</p>
<h2>Recommended Trojan.Zlob.J Removal Procedure</h2>
<p>1. Temporarily Disable System Restore (Windows Me/XP). <a href="http://www.precisesecurity.com/how-to/ht-srxp.htm" target="_blank">[how to]</a><br />
2. Update the virus definitions.<br />
3. Reboot computer in SafeMode <a href="http://www.precisesecurity.com/how-to/ht-smode.htm" target="_blank">[how to]</a><br />
4. Run a full system scan and clean/delete all infected file(s)<br />
5. Delete/Modify any values added to the registry. <a href="http://www.precisesecurity.com/how-to/ht-regedit.htm" target="_blank">[how to edit registry]</a><br />
Navigate to and delete the following registry entry:<br />
<em>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run</em> <em> &#8220;wininet.dll&#8221; = &#8220;dfrgsrv.exe&#8221;</em><em></em><em></em></p>
<p>6. Exit registry editor and restart the computer.<br />
7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with <a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/remove-threats-with-online-virus-scanner/" target="_blank">Online Virus Scanner</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2006/04/06/trojanzlobj-removal-blogs/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

