<body><script type="text/javascript"> function setAttributeOnload(object, attribute, val) { if(window.addEventListener) { window.addEventListener("load", function(){ object[attribute] = val; }, false); } else { window.attachEvent('onload', function(){ object[attribute] = val; }); } } </script> <iframe src="http://www.blogger.com/navbar.g?targetBlogID=1900656735212751576&amp;blogName=Free+Antispyware+and+Computer+Securit...&amp;publishMode=PUBLISH_MODE_FTP&amp;navbarType=BLUE&amp;layoutType=CLASSIC&amp;homepageUrl=http%3A%2F%2Fwww.splatware.com%2F&amp;searchRoot=http%3A%2F%2Fblogsearch.google.com%2F" marginwidth="0" marginheight="0" scrolling="no" frameborder="0" height="30px" width="100%" id="navbar-iframe" title="Blogger Navigation and Search"></iframe> <div></div>
Computer security
 
   
 

Your FREE guide to antispyware and security software


Confused by which virus protection software to use? Are you Trying to untangle two factor authentication?

Is your e-mail spam driving you crazy?

Is your personal computer slowing down?

Do you get annoying pop-ups while surfing the web or simply using your computer and need a popup blocker that WORKS?

i will personally help you once and for all stop your computer from Spyware Adware Computer Worms and Virus Trojan Horse Bugs once and for all without spending a dime.

 


Virus Profile: W32/Checkout!91d0b88a

This worm spreads via MSN Messenger. When installed it sends the following message to contact list recipients and send a zip file named img1756.zip.
* look @ my cute new puppy :-D
* look @ this picture of me, when I was a kid
* I just took this picture with my webcam, like it?
* check it, i shaved my head
* have u seen my new hair?
* what the fuck, did you see this?
* hey man, did you take this picture?
Upon execution, it creates a copy of itself into the Windows folder and also drop a zip file:

* %WINDIR%\img1756.zip (W32/Checkout zipped)
* %WINDIR%\svchost.exe (W32/Checkout)

(Where %WINDIR% is the Windows folder; e.g. C:\Windows)

It also drops a a.bat file to stop the following services. The .bat file is deleted after execution.

* Security Center
* winvnc4

Adds the following values to the registry:

* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Microsoft Genuine Logon" = "svchost.exe"