<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Free Malware Virus Spyware Help</title>
	<atom:link href="http://www.splatware.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.splatware.com</link>
	<description>Fix your PC with free virus spyware removal tools</description>
	<lastBuildDate>Fri, 30 Sep 2011 04:33:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Generic Dropper!1FE3FA763FAB Trojan and how to clean</title>
		<link>http://www.splatware.com/generic-dropper1fe3fa763fab-trojan-and-how-to-clean.html</link>
		<comments>http://www.splatware.com/generic-dropper1fe3fa763fab-trojan-and-how-to-clean.html#comments</comments>
		<pubDate>Fri, 30 Sep 2011 04:33:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Generic Dropper!1FE3FA763FAB Trojan and how to clean]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=53</guid>
		<description><![CDATA[Dropper/Malware.743370 AVG (GriSoft) Generic10.AQTP (Trojan horse) avira TR/Dropper.Gen2 Kaspersky Trojan-Dropper.Win32.Flystud.aaw BitDefender Gen:Variant.EvilEPL.5 clamav Trojan.Agent-148768 Dr.Web Trojan.Siggen2.1469 eSafe (Alladin) Suspicious file F-Prot W32/Trojan2.NJZO FortiNet W32/Autorun!worm Microsoft Backdoor:Win32/FlyAgent.E Eset Win32/FlyStudio.OHD trojan (variant) norman W32/Hupigon.DIEY rising Backdoor.Win32.ECode.se Sophos Troj/PWS-BRB Trend Micro TROJ_UNDEF.EQ vba32 Trojan.Win32.Pasta.ipb V-Buster Trojan.Shutdowner!UaIp5WA/Iv0 (trojan) Some path values have been replaced with environment variables as the [...]]]></description>
			<content:encoded><![CDATA[<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr>
<td align="right">Dropper/Malware.743370</td>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Generic10.AQTP (Trojan horse)</td>
</tr>
<tr>
<td align="left">avira</td>
<td align="right">TR/Dropper.Gen2</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Trojan-Dropper.Win32.Flystud.aaw</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Gen:Variant.EvilEPL.5</td>
</tr>
<tr>
<td align="left">clamav</td>
<td align="right">Trojan.Agent-148768</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Trojan.Siggen2.1469</td>
</tr>
<tr>
<td align="left">eSafe (Alladin)</td>
<td align="right">Suspicious file</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/Trojan2.NJZO</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/Autorun!worm</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">Backdoor:Win32/FlyAgent.E</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/FlyStudio.OHD trojan (variant)</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Hupigon.DIEY</td>
</tr>
<tr>
<td align="left">rising</td>
<td align="right">Backdoor.Win32.ECode.se</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Troj/PWS-BRB</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">TROJ_UNDEF.EQ</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">Trojan.Win32.Pasta.ipb</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Trojan.Shutdowner!UaIp5WA/Iv0 (trojan)</td>
</tr>
</tbody>
</table>
<p><em>Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</em></p>
<p>&nbsp;</p>
<p><strong>The following files were analyzed:</strong></p>
<p>21f45caf86b3fef0da76ebc889c56144616b79bd</p>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following files have been added to the system:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>%TEMP%\BClib\krnln.fne</li>
</ul>
<ul>
<li>%PROGRAMFILES%\Ycesezors\srvany.exe</li>
</ul>
<ul>
<li>%TEMP%\BClib\Exmlrpc.fne</li>
</ul>
<ul>
<li>C:\???????2.0????.rar</li>
</ul>
<ul>
<li>%TEMP%\E_4\Exmlrpc.fne</li>
</ul>
<ul>
<li>%TEMP%\BClib\dp1.fne</li>
</ul>
<ul>
<li>%TEMP%\BClib\krnln.fnr</li>
</ul>
<ul>
<li>%TEMP%\_eviip.tmp</li>
</ul>
<ul>
<li>%WINDIR%\SYSTEM32\Pzriccnss.exe</li>
</ul>
<ul>
<li>%TEMP%\E_4\krnln.fnr</li>
</ul>
<ul>
<li>%WINDIR%\SYSTEM32\Pzriccnss.dll</li>
</ul>
<ul>
<li>%TEMP%\E_4\dp1.fne</li>
</ul>
<ul>
<li>%WINDIR%\Fonts\7c1d5cd6872f50006a77be9d6d56769f.dat</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following files were temporarily written to disk then later removed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>C:\BRC_Setup.exe</li>
</ul>
<ul>
<li>%TEMP%\nsf1.tmp</li>
</ul>
<ul>
<li>C:\BRC_Setup.exe_And DeleteMe.bat</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following registry elements have been created:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\FLYSKY\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\FLYSKY\E\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\FLYSKY\E\INSTALL\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\RECOVERY\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\RISING\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\RISING\KAKA\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\SERVICES\YCESEZORS\PARAMETERS\</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following registry elements have been changed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\FLYSKY\E\INSTALL\PATH = %TEMP%\BClib\</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\CHECK_ASSOCIATIONS = NO</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\WINDOW_PLACEMENT = [binary data]</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\RECOVERY\AUTORECOVER = 2</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\LOCKED = 1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\WINRAR\ARCHISTORY\0 = [binary data]</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\WINRAR\ARCHISTORY\1 = C:\Raiden\Goat_1.5.235.1931.zip</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\WINRAR\ARCHISTORY\2 = C:\sample\Sample.zip</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\WINRAR\ARCHISTORY\3 = C:\sample\bc_amp.zip</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\WINRAR\FILELIST\FILECOLUMNWIDTHS\MTIME = 100</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\WINRAR\FILELIST\FILECOLUMNWIDTHS\NAME = 120</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\WINRAR\FILELIST\FILECOLUMNWIDTHS\SIZE = 80</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\WINRAR\FILELIST\FILECOLUMNWIDTHS\TYPE = 120</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\RISING\KAKA\PROCRUN = 0</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\SERVICES\YCESEZORS\PARAMETERS\APPLICATION = %WINDIR%\SYSTEM32\Pzriccnss.exe -s</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>To remove this infection,</p>
<p>1.<strong>Disable System Restore </strong><strong>.</strong></p>
<p>2.Update to current engine and DAT files for detection and removal.</p>
<p>3.Run a complete system scan.</p>
<p>You should be good to go.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/generic-dropper1fe3fa763fab-trojan-and-how-to-clean.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PWS-LegMir!i!BC616000​59A7 malware trojan</title>
		<link>http://www.splatware.com/pws-legmiribc616000%e2%80%8b59a7-malware-trojan.html</link>
		<comments>http://www.splatware.com/pws-legmiribc616000%e2%80%8b59a7-malware-trojan.html#comments</comments>
		<pubDate>Thu, 25 Aug 2011 21:53:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PWS-LegMir!i!BC616000​59A7 malware trojan]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=50</guid>
		<description><![CDATA[This is a high risk malware, that might show up as a trojan, this trojan will attempts to load and execute remote code in explorer process, and once this task is complete by the trojan bot, your system will not start, will effect mostly windows xp and windows 7. The applications attempted the following network [...]]]></description>
			<content:encoded><![CDATA[<p>This is a high risk malware, that might show up as a trojan, this trojan will attempts to load and execute remote code in explorer process, and once this task is complete by the trojan bot, your system will not start, will effect mostly windows xp and windows 7.<br />
The applications attempted the following network connections. hxxp://www.baidu1s4.com/1mg/***** and hxxp://www.baiduscs.com/1mg/*****</p>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr>
<td align="left">EMSI Software</td>
<td align="right">Trojan-GameThief.Win32.Magania!IK</td>
</tr>
<tr>
<td align="left">ahnlab</td>
<td align="right">Win-Trojan/MalPackedD.suspicious</td>
</tr>
<tr>
<td align="left">avast</td>
<td align="right">Win32:OnLineGames-FVL [Cryp]</td>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Dropper.Generic2.CBHP</td>
</tr>
<tr>
<td align="left">avira</td>
<td align="right">Worm/Taterf.B.258</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Packed.Win32.Klone.bq</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Gen:Variant.Taterf.20</td>
</tr>
<tr>
<td align="left">clamav</td>
<td align="right">PUA.Packed.ASPack</td>
</tr>
<tr>
<td align="left">Dr.Web</td>
<td align="right">Trojan.PWS.Wsgame.24181</td>
</tr>
<tr>
<td align="left">F-Prot</td>
<td align="right">W32/Onlinegames.FV.gen!Eldorado</td>
</tr>
<tr>
<td align="left">Microsoft</td>
<td align="right">worm:win32/taterf.b</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/PSW.OnLineGames.OUM</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">W32/Suspicious_Gen2.PCTYT</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">W32/Lineage.LOH</td>
</tr>
<tr>
<td align="left">rising</td>
<td align="right">Trojan.Win32.Fednu.cus</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">W32/Taterf-AR</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">Mal_OLGM-41</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">Trojan.Agent.01152</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Trojan.Vaklik!nvEuP1vpjFk</td>
</tr>
<tr>
<td align="left">Vet (Computer Associates)</td>
<td align="right">Win32/Frethog.IHX</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/pws-legmiribc616000%e2%80%8b59a7-malware-trojan.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/YahLover.worm!j!7​9B810C26755 Virus</title>
		<link>http://www.splatware.com/w32yahlover-wormj7%e2%80%8b9b810c26755-virus.html</link>
		<comments>http://www.splatware.com/w32yahlover-wormj7%e2%80%8b9b810c26755-virus.html#comments</comments>
		<pubDate>Thu, 21 Jul 2011 01:26:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32/YahLover.worm!j!7​9B810C26755 Virus]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[avg]]></category>
		<category><![CDATA[avira]]></category>
		<category><![CDATA[bitdefender]]></category>
		<category><![CDATA[clamay]]></category>
		<category><![CDATA[eset]]></category>
		<category><![CDATA[fortinet]]></category>
		<category><![CDATA[kaspersky]]></category>
		<category><![CDATA[norman]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=47</guid>
		<description><![CDATA[The following files have been added to the system: %WINDIR%\web\connection.dat %WINDIR%\SYSTEM32\logoneui.exe This W32 YahLover worm is a low threat virus but never the less it will harm your PC. If infected, the virus will infect system files and directories. Removing this virus should be pretty easy, simply run your PC&#8217;s virus scanner if you have [...]]]></description>
			<content:encoded><![CDATA[<p><strong>The following files have been added to the system:</strong></p>
<ul>
<li>%WINDIR%\web\connection.dat</li>
</ul>
<ul>
<li>%WINDIR%\SYSTEM32\logoneui.exe</li>
</ul>
<p>This W32 YahLover worm is a low threat virus but never the less it will harm your PC. If infected, the virus will infect system files and directories.<br />
Removing this virus should be pretty easy, simply run your PC&#8217;s virus scanner if you have one and that should clean it. If your anti virus app is out of date, make sure you update the definition file before you scan and clean.</p>
<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr bgcolor="silver">
<th align="left" bgcolor="silver"><strong>other known names</strong></th>
<th align="right" bgcolor="silver"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">AVG (GriSoft)</td>
<td align="right">Autoit.DI</td>
</tr>
<tr>
<td align="left">avira</td>
<td align="right">Worm/AutoIt.sl.4</td>
</tr>
<tr>
<td align="left">Kaspersky</td>
<td align="right">Worm.Win32.AutoIt.sl</td>
</tr>
<tr>
<td align="left">BitDefender</td>
<td align="right">Win32.Worm.Sohanat.Y</td>
</tr>
<tr>
<td align="left">clamav</td>
<td align="right">Trojan.Autoit.gen</td>
</tr>
<tr>
<td align="left">FortiNet</td>
<td align="right">W32/AutoIt.SL!worm</td>
</tr>
<tr>
<td align="left">Eset</td>
<td align="right">Win32/AutoRun.Autoit.AA worm</td>
</tr>
<tr>
<td align="left">norman</td>
<td align="right">Sohanad.BRU (trojan)</td>
</tr>
<tr>
<td align="left">panda</td>
<td align="right">Trj/CI.A</td>
</tr>
<tr>
<td align="left">Sophos</td>
<td align="right">Mal/Generic-L</td>
</tr>
<tr>
<td align="left">vba32</td>
<td align="right">Worm.Autoit.SL</td>
</tr>
<tr>
<td align="left">V-Buster</td>
<td align="right">Worm.Autoit.Gen.3 (mutant)</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/w32yahlover-wormj7%e2%80%8b9b810c26755-virus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vundo!jc!682EAD5420CC Trojan</title>
		<link>http://www.splatware.com/vundojc682ead5420cc-trojan.html</link>
		<comments>http://www.splatware.com/vundojc682ead5420cc-trojan.html#comments</comments>
		<pubDate>Thu, 07 Jul 2011 05:03:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Vundo!jc!682EAD5420CC Trojan]]></category>
		<category><![CDATA[malwaerbytes]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=44</guid>
		<description><![CDATA[Microsoft Trojan:Win32/Vundo Symantec Trojan.Gen Trend Micro TROJ_GEN.R47C2FN System Changes Some path values have been replaced with environment variables as the exact location may vary with different configurations. e.g. %WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000) %PROGRAMFILES% = \Program Files &#160; The following files were analyzed: f7c55aabda688cf0cf8ee05ac81fd1a09e6729a0 The following files have been added to the [...]]]></description>
			<content:encoded><![CDATA[<table width="500" border="1" frame="box" rules="row" cellspacing="0" cellpadding="4">
<tbody>
<tr>
<td align="left">Microsoft</td>
<td align="right">Trojan:Win32/Vundo</td>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">Trojan.Gen</td>
</tr>
<tr>
<td align="left">Trend Micro</td>
<td align="right">TROJ_GEN.R47C2FN</td>
</tr>
</tbody>
</table>
<p><strong><span style="text-decoration: underline;">System Changes</span></strong></p>
<p><em>Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</em></p>
<p>&nbsp;</p>
<p><strong>The following files were analyzed:</strong></p>
<p>f7c55aabda688cf0cf8ee05ac81fd1a09e6729a0</p>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following files have been added to the system:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>%APPDATA%\netprotocol.exe</li>
</ul>
<ul>
<li>%APPDATA%\System.log</li>
</ul>
<ul>
<li>%APPDATA%\netprotdrvss.exe</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following registry elements have been created:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\MIME\DATABASE\CONTENT TYPE\APPLICATION/X-JAVASCRIPT\</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\MIME\DATABASE\CONTENT TYPE\TEXT/JAVASCRIPT\</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The following registry elements have been changed:</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\NETPROTOCOL = %APPDATA%\netprotocol.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\MIME\DATABASE\CONTENT TYPE\APPLICATION/X-JAVASCRIPT\CLSID = {25336920-03F9-11cf-8FD0-00AA00686F13}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\MIME\DATABASE\CONTENT TYPE\TEXT/JAVASCRIPT\CLSID = {25336920-03F9-11cf-8FD0-00AA00686F13}</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td width="35" height="35"></td>
<td><strong>The applications attempted the following network connection(s):</strong></td>
</tr>
<tr>
<td width="35"></td>
<td>
<ul>
<li>31.171.129.***:80</li>
</ul>
<ul>
<li>hxxp://blenulin.in/*****</li>
</ul>
<ul>
<li>hxxp://excipie.in/*****</li>
</ul>
<ul>
<li>hxxp://excipie.in/cle/*****</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>To remove this Trojan, please follow directions below:</p>
<p>download Malwarebytes&#8217; Anti-Malware from <a href="http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&amp;subj=dl&amp;tag=button" target="_blank"><strong><span style="color: red;">here</span></strong></a>  and  save it to your computer.</p>
<ul>
<li>Double click <strong>mbam-setup.exe</strong> and follow the directions to install.</li>
<li>At the end, be sure a checkmark is placed next to
<ul>
<li><strong>Update Malwarebytes</strong></li>
<li><strong>Launch Malwarebytes</strong></li>
</ul>
</li>
<li>then click <strong>Finish</strong>.</li>
<li>If an update is found, it will download and install the latest version.<strong></strong></li>
<li>Once the program has loaded, select <strong>Perform quick scan</strong>, then click <strong>Scan</strong>.</li>
<li>When the scan is complete, click <strong>OK</strong>, then <strong>Show Results</strong> to view the results.</li>
<li>Be sure that everything is checked, and click <strong>Remove Selected</strong>.</li>
<li>A log will be saved automatically which you can access by clicking on the <strong>Logs</strong> tab within Malwarebytes&#8217; Anti-Malware</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/vundojc682ead5420cc-trojan.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Profile Fake Alert SpyPro.gen.bb</title>
		<link>http://www.splatware.com/virus-profile-fake-alert-spypro-gen-bb.html</link>
		<comments>http://www.splatware.com/virus-profile-fake-alert-spypro-gen-bb.html#comments</comments>
		<pubDate>Mon, 20 Jun 2011 19:20:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus Profile Fake Alert SpyPro.gen.bb]]></category>
		<category><![CDATA[fake alert]]></category>
		<category><![CDATA[gen]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[spy]]></category>
		<category><![CDATA[system changes]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=41</guid>
		<description><![CDATA[This is a Trojan Horse virus which creates a fake alert Adding or modifies Shell Open registry value which Could be used to launch a program on startup. File Properties Property Values McAfee Detection FakeAlert-SpyPro.gen.bb Length 427520 bytes MD5 1e867aad6269344862040d697efa6edc SHA1 f265d862cbadd8ae275792721cec0b5d06af75e8 Other Common Detection Aliases Company Names Detection Names Symantec Trojan.Gen.2 System Changes Some [...]]]></description>
			<content:encoded><![CDATA[<p>This is a Trojan Horse virus which creates a fake alert Adding or modifies Shell Open registry value which Could be used to launch a program on startup.</p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>File Properties</strong></th>
<th align="right"><strong>Property Values</strong></th>
</tr>
<tr>
<td align="left">McAfee Detection</td>
<td align="right">FakeAlert-SpyPro.gen.bb</td>
</tr>
<tr>
<td align="left">Length</td>
<td align="right">427520 bytes</td>
</tr>
<tr>
<td align="left">MD5</td>
<td align="right">1e867aad6269344862040d697efa6edc</td>
</tr>
<tr>
<td align="left">SHA1</td>
<td align="right">f265d862cbadd8ae275792721cec0b5d06af75e8</td>
</tr>
</tbody>
</table>
<p><strong>Other Common Detection Aliases</strong></p>
<table border="1" cellspacing="0" cellpadding="4" width="500" frame="box" rules="row">
<tbody>
<tr bgcolor="silver">
<th align="left"><strong>Company Names</strong></th>
<th align="right"><strong>Detection Names</strong></th>
</tr>
<tr>
<td align="left">Symantec</td>
<td align="right">Trojan.Gen.2</td>
</tr>
</tbody>
</table>
<p><strong><span style="text-decoration: underline;">System Changes</span></strong></p>
<p><em>Some path values have been replaced with environment variables as the exact location may vary with different configurations.<br />
e.g.<br />
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)<br />
%PROGRAMFILES% = \Program Files</em></p>
<p><strong>The following registry elements have been changed:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\EXQONCZCTRUCEG\ID = 1.0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\EXQONCZCTRUCEG\KNKD = 1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\EXQONCZCTRUCEG\READY = 1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOWNLOAD\CHECKEXESIGNATURES = no</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOWNLOAD\RUNINVALIDSIGNATURES = 1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\{92780B25-18CC-41C8-B9BE-3C9C571A8263} = 8193</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\NEXTID = 8194</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\PHISHINGFILTER\ENABLED = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\PHISHINGFILTER\ENABLEDV8 = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\PHISHINGFILTER\ENABLEDV9 = 0</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\PROXYOVERRIDE</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\PROXYSERVER = http=127.0.0.1:47392</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ASSOCIATIONS\LOWRISKFILETYPES = .exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ATTACHMENTS\SAVEZONEINFORMATION = 1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\WDANDYYP = %TEMP%\fmljgiqxa\remoynoxsik.exe</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/virus-profile-fake-alert-spypro-gen-bb.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Internet Explorer ‘DC:TITLE’ PDF Information Disclosure Vulnerability</title>
		<link>http://www.splatware.com/microsoft-internet-explorer-%e2%80%98dctitle%e2%80%99-pdf-information-disclosure-vulnerability.html</link>
		<comments>http://www.splatware.com/microsoft-internet-explorer-%e2%80%98dctitle%e2%80%99-pdf-information-disclosure-vulnerability.html#comments</comments>
		<pubDate>Mon, 04 Apr 2011 21:53:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft Internet Explorer ‘DC:TITLE’ PDF Information Disclosure Vulnerability]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=38</guid>
		<description><![CDATA[Type Logic error Impact of exploitation Information disclosure User Interaction user interaction is needed Attack Vector Information disclosure Rating Medium CVE reference CVE-2009-4073, Vendor Status Unacknowledged Vulnerable systems Internet Explorer  6 SP1 Windows 2000 SP4, Internet Explorer  6 SP1, Internet Explorer  6 Microsoft Windows Server 2003 SP1, Internet Explorer  6 Windows Server 2003 SP1, Internet [...]]]></description>
			<content:encoded><![CDATA[<div>
<dl>
<dt> <strong>Type</strong> </dt>
<dd>Logic error</dd>
<dt> <strong>Impact of exploitation</strong> </dt>
<dd>Information disclosure</dd>
<dt> <strong>User Interaction</strong> </dt>
<dd>user interaction is needed</dd>
<dt> <strong>Attack Vector</strong> </dt>
<dd>Information disclosure</dd>
<dt> <strong>Rating</strong> </dt>
<dd> Medium </dd>
<dt> <strong>CVE reference</strong> </dt>
<dd>CVE-2009-4073, </dd>
<dd>
</dd>
<dt> <strong>Vendor Status</strong> </dt>
<dd>Unacknowledged</dd>
<dt> <strong>Vulnerable systems</strong> </dt>
<dd>Internet Explorer  6 SP1 Windows 2000 SP4, </dd>
<dd>Internet Explorer  6 SP1, </dd>
<dd>Internet Explorer  6 Microsoft Windows Server 2003 SP1, </dd>
<dd>Internet Explorer  6 Windows Server 2003 SP1, </dd>
<dd>Internet Explorer  6 Windows Server 2003 SP1 Itanium, </dd>
<dd>Internet Explorer  6 Windows Server 2003 SP2, </dd>
<dd>Internet Explorer  6 Windows XP Professional X64 Edition SP2, </dd>
<dd>Internet Explorer  6 Windows XP SP2, </dd>
<dd>Internet Explorer  7, </dd>
<dd>Internet Explorer  7 Windows Server 2003 SP2 Itanium, </dd>
<dd>Internet Explorer  7 Windows 2000 SP4, </dd>
<dd>Internet Explorer  7 Windows Vista SP1, </dd>
<dd>Internet Explorer  7 Windows Vista X64 Edition SP1, </dd>
<dd>Internet Explorer  7 Windows Server 2008 X64 Edition, </dd>
<dd>Internet Explorer  7 Windows Server 2008 X32 Edition, </dd>
<dd>Internet Explorer  7 Windows Server 2008 Itanium Edition, </dd>
<dd>Internet Explorer  7 Windows XP SP2, </dd>
<dd>Internet Explorer  7 Windows XP Professional X64 Edition SP2, </dd>
<dd>Internet Explorer  8, </dd>
<dt> <strong>Summary</strong> </dt>
<dd>A vulnerability in Microsoft Internet Explorer may allow for the disclosure of sensitive information.</dd>
</dl>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/microsoft-internet-explorer-%e2%80%98dctitle%e2%80%99-pdf-information-disclosure-vulnerability.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Excel Document Parsing Memory Corruption Vulnerability</title>
		<link>http://www.splatware.com/excel-document-parsing-memory-corruption-vulnerability.html</link>
		<comments>http://www.splatware.com/excel-document-parsing-memory-corruption-vulnerability.html#comments</comments>
		<pubDate>Mon, 04 Apr 2011 21:52:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Excel Document Parsing Memory Corruption Vulnerability]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=36</guid>
		<description><![CDATA[Description - A remote code execution vulnerability exists in Microsoft Office Excel as a result of memory corruption when loading Excel records. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file that includes a malformed object. An attacker who successfully exploited this vulnerability could take complete control of [...]]]></description>
			<content:encoded><![CDATA[<h4>Description -</h4>
<p>A remote code execution vulnerability exists in Microsoft Office  Excel as a result of memory corruption when loading Excel records. The  vulnerability could allow remote code execution if a user opens a  specially crafted Excel file that includes a malformed object. An  attacker who successfully exploited this vulnerability could take  complete control of an affected system. An attacker could then install  programs; view, change, or delete data; or create new accounts with full  user rights. ? The vulnerability cannot be exploited automatically  through e-mail. For an attack to be successful, a user must open an  attachment that is sent in an e-mail message. ? An attacker who  successfully exploited this vulnerability could gain the same user  rights as the local user. Users whose accounts are configured to have  fewer user rights on the system could be less impacted than users who  operate with administrative user rights.</p>
<h3>McAfee Product Mitigation &amp; Recommendations</h3>
<h4>Recommendations -</h4>
<p>The vendor has released a patch to address this issue:  http://www.microsoft.com/technet/security/bulletin/ms09-067.mspx</p>
<h4>McAfee Product Mitigation</h4>
<h5>McAfee Foundstone</h5>
<dl>
<dt>Signature:</dt>
<dd>(MS09-067) Excel Document Parsing Memory Corruption Vulnerability (972652)</dd>
<dt>Signature identifier:</dt>
<dd>7325</dd>
<dt>Release date:</dt>
<dd>11/10/2009</dd>
</dl>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/excel-document-parsing-memory-corruption-vulnerability.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Excel Featheader Record Memory Corruption Vulnerability</title>
		<link>http://www.splatware.com/excel-featheader-record-memory-corruption-vulnerability.html</link>
		<comments>http://www.splatware.com/excel-featheader-record-memory-corruption-vulnerability.html#comments</comments>
		<pubDate>Mon, 04 Apr 2011 21:52:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Excel Featheader Record Memory Corruption Vulnerability]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=34</guid>
		<description><![CDATA[Description - A remote code execution vulnerability exists in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file that includes a malformed record object. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, [...]]]></description>
			<content:encoded><![CDATA[<h4>Description -</h4>
<p>A remote code execution vulnerability exists in Microsoft Office  Excel that could allow remote code execution if a user opens a specially  crafted Excel file that includes a malformed record object. An attacker  who successfully exploited this vulnerability could take complete  control of an affected system. An attacker could then install programs;  view, change, or delete data; or create new accounts with full user  rights. ? The vulnerability cannot be exploited automatically through  e-mail. For an attack to be successful, a user must open an attachment  that is sent in an e-mail message. ? An attacker who successfully  exploited this vulnerability could gain the same user rights as the  local user. Users whose accounts are configured to have fewer user  rights on the system could be less impacted than users who operate with  administrative user rights.</p>
<h3>McAfee Product Mitigation &amp; Recommendations</h3>
<h4>Recommendations -</h4>
<p>Vendor has released patches to address this issue.  http://www.microsoft.com/technet/security/bulletin/ms09-067.mspx</p>
<h4>McAfee Product Mitigation</h4>
<h5>McAfee Foundstone</h5>
<dl>
<dt>Signature:</dt>
<dd>(MS09-067) Excel Featheader Record Memory Corruption Vulnerability (972652)</dd>
<dt>Signature identifier:</dt>
<dd>7321</dd>
<dt>Release date:</dt>
<dd>11/10/2009</dd>
</dl>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/excel-featheader-record-memory-corruption-vulnerability.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ATL COM Initialization Vulnerability</title>
		<link>http://www.splatware.com/atl-com-initialization-vulnerability.html</link>
		<comments>http://www.splatware.com/atl-com-initialization-vulnerability.html#comments</comments>
		<pubDate>Mon, 04 Apr 2011 21:51:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ATL COM Initialization Vulnerability]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=32</guid>
		<description><![CDATA[Description - A vulnerability in Microsoft Active Template Library (ATL) ActiveX Controls may allow remote code execution. The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and [...]]]></description>
			<content:encoded><![CDATA[<h4>Description -</h4>
<p>A vulnerability in Microsoft Active Template Library (ATL) ActiveX  Controls may allow remote code execution. The Active Template Library  (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1  and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1;  and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1,  and SP2, and Server 2008 Gold and SP2; does not properly restrict use of  OleLoadFromStream in instantiating objects from data streams, which  allows remote attackers to execute arbitrary code via a crafted HTML  document with an ATL (1) component or (2) control, related to ATL  headers and bypassing security policies, aka “ATL COM Initialization  Vulnerability.” An attacker could exploit this vulnerability by  constructing a specially crafted Web page. When a user views the Web  page, the vulnerability could allow remote code execution. An attacker  exploiting this vulnerability could gain the same user rights as the  logged on user.</p>
<h3>McAfee Product Mitigation &amp; Recommendations</h3>
<h4>Recommendations -</h4>
<p>The vendor has released a patch to address this issue:  http://www.microsoft.com/technet/security/bulletin/ms09-060.mspx</p>
<h4>McAfee Product Mitigation</h4>
<h5>McAfee Foundstone</h5>
<dl>
<dt>Signature:</dt>
<dd>(MS09-060) ATL COM Initialization Vulnerability (973965)</dd>
<dt>Signature identifier:</dt>
<dd>7206</dd>
<dt>Release date:</dt>
<dd>10/13/2009</dd>
</dl>
<h5>McAfee Intrushield</h5>
<dl>
<dt>Signature:</dt>
<dd>HTTP: Microsoft Visual Studio ATL Uninitialized Object Vulnerability</dd>
<dt>Signature identifier:</dt>
<dd>0×40264900</dd>
<dt>Release date:</dt>
<dd>7/6/2009</dd>
<dt>First released in:</dt>
<dd>UDS and 4.1.55.4, 5.1.25.4</dd>
</dl>
<h5>McAfee Host IPS</h5>
<dl>
<dt>Signature:</dt>
<dd>Generic Buffer Overflow Protection</dd>
<dt>Signature identifier:</dt>
<dd>428</dd>
<dt>Release date:</dt>
<dd>8/24/2000</dd>
<dt>First released in:</dt>
<dd>2.0</dd>
</dl>
<dl>
<dt>Signature:</dt>
<dd>(MS09-060) ATL COM Initialization Vulnerability (973965)</dd>
<dt>Signature identifier:</dt>
<dd>7206</dd>
<dt>Release date:</dt>
<dd>10/14/2009</dd>
</dl>
<h5>McAfee VirusScan Enterprise 8.0i (VSE8.0i) / Managed Virus Scan (MVS) Buffer Overflow Protection</h5>
<dl>
<dt>Signature:</dt>
<dd>Generic Buffer Overflow Protection</dd>
</dl>
<p>The V-Flash of October 14th will contain remedies for this issue.</p>
<dl>
<dt>Signature:</dt>
<dd>Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX  Controls for Microsoft Office Could Allow Remote Code Execution (973965)</dd>
<dt>Signature identifier:</dt>
<dd>98961</dd>
<dt>Release date:</dt>
<dd>10/14/2009</dd>
</dl>
<dl>
<dt>Release date:</dt>
<dd>10/14/2009</dd>
</dl>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/atl-com-initialization-vulnerability.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Backdoor.Tidserv.I!inf</title>
		<link>http://www.splatware.com/backdoor-tidserv-iinf.html</link>
		<comments>http://www.splatware.com/backdoor-tidserv-iinf.html#comments</comments>
		<pubDate>Mon, 04 Apr 2011 21:51:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Backdoor.Tidserv.I!inf]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=30</guid>
		<description><![CDATA[Discovered: December 3, 2009 Updated: December 3, 2009 4:38:36 PM Type: Trojan Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Backdoor.Tidserv.I!inf is a detection for legitimate system driver files that have been modified by Backdoor.Tidserv to load other malicious components. Protection Initial Rapid Release [...]]]></description>
			<content:encoded><![CDATA[<div id="tabModBdy">
<div><strong>Discovered: </strong>December 3, 2009</div>
<div><strong>Updated: </strong>December 3, 2009 4:38:36 PM</div>
<div><strong>Type: </strong>Trojan</div>
<div><strong>Systems Affected: </strong>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</div>
<p>Backdoor.Tidserv.I!inf is a detection for legitimate system driver  files that have been modified by Backdoor.Tidserv to load other  malicious components.</p>
<h3>Protection</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>December 3, 2009 revision 019</li>
<li> <strong>Latest Rapid Release version </strong>December 3, 2009 revision 019</li>
<li> <strong>Initial Daily Certified version </strong>December 3, 2009 revision 021</li>
<li> <strong>Latest Daily Certified version </strong>December 3, 2009 revision 021</li>
<li> <strong>Initial Weekly Certified release date </strong>December 9, 2009</li>
</ul>
<p>Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.</p>
<h3>Threat Assessment</h3>
<h4>Wild</h4>
<ul>
<li> <strong>Wild Level: </strong>Low</li>
<li> <strong>Number of Infections: </strong>0 – 49</li>
<li> <strong>Number of Sites: </strong>0 – 2</li>
<li> <strong>Geographical Distribution: </strong>Low</li>
<li> <strong>Threat Containment: </strong>Easy</li>
<li> <strong>Removal: </strong>Easy</li>
</ul>
<h4>Damage</h4>
<ul>
<li> <strong>Damage Level: </strong>Low</li>
<li> <strong>Modifies Files: </strong>Modifies legitimate system files.</li>
</ul>
<h4>Distribution</h4>
<ul>
<li> <strong>Distribution Level: </strong>Low</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/backdoor-tidserv-iinf.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.SillyFDC.BBX</title>
		<link>http://www.splatware.com/w32-sillyfdc-bbx.html</link>
		<comments>http://www.splatware.com/w32-sillyfdc-bbx.html#comments</comments>
		<pubDate>Mon, 04 Apr 2011 21:50:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32.SillyFDC.BBX]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=27</guid>
		<description><![CDATA[Discovered: December 2, 2009 Updated: December 3, 2009 5:45:23 AM Type: Worm Infection Length: 705,283 bytes Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 W32.SillyFDC.BBX is a worm that spreads by copying itself to removable and mapped drives. It also drops more malware, attempts [...]]]></description>
			<content:encoded><![CDATA[<div><strong>Discovered: </strong>December 2, 2009</div>
<div><strong>Updated: </strong>December 3, 2009 5:45:23 AM</div>
<div><strong>Type: </strong>Worm</div>
<div><strong>Infection Length: </strong>705,283 bytes</div>
<div><strong>Systems Affected: </strong>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</div>
<p>W32.SillyFDC.BBX is a worm that spreads by copying itself to  removable and mapped drives. It also drops more malware, attempts to  download files, lowers security settings, disables certain system  software and alters certain system settings.</p>
<h3>Protection</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>December 2, 2009 revision 025</li>
<li> <strong>Latest Rapid Release version </strong>December 2, 2009 revision 025</li>
<li> <strong>Initial Daily Certified version </strong>December 2, 2009 revision 024</li>
<li> <strong>Latest Daily Certified version </strong>December 2, 2009 revision 024</li>
<li> <strong>Initial Weekly Certified release date </strong>December 2, 2009</li>
</ul>
<p>Click <a href="http://www.symantec.com/norton/security_response/writeup.jsp?docid=2009-120305-1106-99#">here</a> for a more detailed description of Rapid Release and Daily Certified virus definitions.</p>
<h3>Threat Assessment</h3>
<h4>Wild</h4>
<ul>
<li> <strong>Wild Level: </strong>Low</li>
<li> <strong>Number of Infections: </strong>0 – 49</li>
<li> <strong>Number of Sites: </strong>0 – 2</li>
<li> <strong>Geographical Distribution: </strong>Low</li>
<li> <strong>Threat Containment: </strong>Easy</li>
<li> <strong>Removal: </strong>Easy</li>
</ul>
<h4>Damage</h4>
<ul>
<li> <strong>Damage Level: </strong>Low</li>
<li> <strong>Modifies Files: </strong>Modifies certain files, replacing them with a copy of other malware.</li>
<li> <strong>Compromises Security Settings: </strong>Lowers security settings.</li>
</ul>
<h4>Distribution</h4>
<ul>
<li> <strong>Distribution Level: </strong>Medium</li>
<li> <strong>Target of Infection: </strong>Removable drives</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/w32-sillyfdc-bbx.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adware.Zwunzi</title>
		<link>http://www.splatware.com/adware-zwunzi.html</link>
		<comments>http://www.splatware.com/adware-zwunzi.html#comments</comments>
		<pubDate>Mon, 04 Apr 2011 21:49:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Adware.Zwunzi]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=25</guid>
		<description><![CDATA[Updated: December 3, 2009 12:59:34 AM Type: Adware Name: Zwunzi Version: 1.0 build 128 Publisher: zwunzi.com Risk Impact: High Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Behavior Adware.Zwunzi is an adware program that installs itself as a Browser Search Plugin for Internet Explorer [...]]]></description>
			<content:encoded><![CDATA[<div id="tabModBdy">
<div><strong>Updated: </strong>December 3, 2009 12:59:34 AM</div>
<div><strong>Type: </strong>Adware</div>
<div><strong>Name: </strong>Zwunzi</div>
<div><strong>Version: </strong>1.0 build 128</div>
<div><strong>Publisher: </strong>zwunzi.com</div>
<div><strong>Risk Impact: </strong>High</div>
<div><strong>Systems Affected: </strong>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</div>
<h3>Behavior</h3>
<p>Adware.Zwunzi is an adware program that installs itself as a Browser Search Plugin for Internet Explorer and Mozilla Firefox.</p>
<h3>Protection</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>December 2, 2009 revision 039</li>
<li> <strong>Latest Rapid Release version </strong>December 2, 2009 revision 039</li>
<li> <strong>Initial Daily Certified version </strong>December 2, 2009 revision 050</li>
<li> <strong>Latest Daily Certified version </strong>December 2, 2009 revision 050</li>
<li> <strong>Initial Weekly Certified release date </strong>December 9, 2009</li>
</ul>
<p>Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/adware-zwunzi.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Mabezat.B!dam</title>
		<link>http://www.splatware.com/w32-mabezat-bdam.html</link>
		<comments>http://www.splatware.com/w32-mabezat-bdam.html#comments</comments>
		<pubDate>Mon, 04 Apr 2011 21:48:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[W32.Mabezat.B!dam]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=23</guid>
		<description><![CDATA[Discovered: December 2, 2009 Updated: December 2, 2009 4:38:12 PM Type: Virus Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 W32.Mabezat.B!dam is a detection for corrupted files that are infected with W32.Mabezat.B. Protection Initial Rapid Release version December 2, 2009 revision 022 Latest Rapid [...]]]></description>
			<content:encoded><![CDATA[<div id="tabModBdy">
<div><strong>Discovered: </strong>December 2, 2009</div>
<div><strong>Updated: </strong>December 2, 2009 4:38:12 PM</div>
<div><strong>Type: </strong>Virus</div>
<div><strong>Systems Affected: </strong>Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</div>
<p>W32.Mabezat.B!dam is a detection for corrupted files that are infected with W32.Mabezat.B.</p>
<h3>Protection</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>December 2, 2009 revision 022</li>
<li> <strong>Latest Rapid Release version </strong>December 2, 2009 revision 022</li>
<li> <strong>Initial Daily Certified version </strong>December 2, 2009 revision 024</li>
<li> <strong>Latest Daily Certified version </strong>December 2, 2009 revision 024</li>
<li> <strong>Initial Weekly Certified release date </strong>December 9, 2009</li>
</ul>
<p>Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.</p>
<h3>Threat Assessment</h3>
<h4>Wild</h4>
<ul>
<li> <strong>Wild Level: </strong>Low</li>
<li> <strong>Number of Infections: </strong>0 – 49</li>
<li> <strong>Number of Sites: </strong>0 – 2</li>
<li> <strong>Geographical Distribution: </strong>Low</li>
<li> <strong>Threat Containment: </strong>Easy</li>
<li> <strong>Removal: </strong>Easy</li>
</ul>
<h4>Damage</h4>
<ul>
<li> <strong>Damage Level: </strong>Medium</li>
</ul>
<h4>Distribution</h4>
<ul>
<li> <strong>Distribution Level: </strong>Low</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/w32-mabezat-bdam.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan.Vundo!gen2</title>
		<link>http://www.splatware.com/trojan-vundogen2.html</link>
		<comments>http://www.splatware.com/trojan-vundogen2.html#comments</comments>
		<pubDate>Mon, 04 Apr 2011 21:22:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan.Vundo!gen2]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=18</guid>
		<description><![CDATA[Discovered: December 2, 2009 Updated: December 2, 2009 11:57:16 AM Type: Trojan Systems Affected: Windows XP, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Trojan.Vundo!gen2 is a heuristic detection used to detect threats associated with the following family: Trojan.Vundo Protection Initial Rapid Release version December 2, 2009 revision 008 Latest Rapid Release version December [...]]]></description>
			<content:encoded><![CDATA[<div></div>
<div id="tabModBdy">
<div><strong>Discovered: </strong>December 2, 2009</div>
<div><strong>Updated: </strong>December 2, 2009 11:57:16 AM</div>
<div><strong>Type: </strong>Trojan</div>
<div><strong>Systems Affected: </strong>Windows XP, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</div>
<p>Trojan.Vundo!gen2 is a heuristic detection used to detect threats associated with the following family:<br />
Trojan.Vundo</p>
<p><strong> </strong></p>
<h3>Protection</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>December 2, 2009 revision 008</li>
<li> <strong>Latest Rapid Release version </strong>December 2, 2009 revision 008</li>
<li> <strong>Initial Daily Certified version </strong>December 2, 2009 revision 024</li>
<li> <strong>Latest Daily Certified version </strong>December 2, 2009 revision 024</li>
<li> <strong>Initial Weekly Certified release date </strong>December 2, 2009</li>
</ul>
<p>Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.</p>
<h3>Threat Assessment</h3>
<h4>Wild</h4>
<ul>
<li> <strong>Wild Level: </strong>Low</li>
<li> <strong>Number of Infections: </strong>0 – 49</li>
<li> <strong>Number of Sites: </strong>0 – 2</li>
<li> <strong>Geographical Distribution: </strong>Low</li>
<li> <strong>Threat Containment: </strong>Easy</li>
<li> <strong>Removal: </strong>Easy</li>
</ul>
<h4>Damage</h4>
<ul>
<li> <strong>Damage Level: </strong>Medium</li>
</ul>
<h4>Distribution</h4>
<ul>
<li> <strong>Distribution Level: </strong>Low</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/trojan-vundogen2.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan.Vundo!gen1</title>
		<link>http://www.splatware.com/trojan-vundogen1.html</link>
		<comments>http://www.splatware.com/trojan-vundogen1.html#comments</comments>
		<pubDate>Mon, 04 Apr 2011 21:21:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan.Vundo!gen1]]></category>

		<guid isPermaLink="false">http://www.splatware.com/?p=16</guid>
		<description><![CDATA[Posted on December 3rd, 2009 by admin Discovered: December 1, 2009 Updated: December 2, 2009 6:13:59 AM Type: Trojan Systems Affected: Windows XP, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 Trojan.Vundo!gen1 is a heuristic detection used to detect threats associated with the following family: Trojan.Vundo Protection Initial Rapid Release version pending Latest Rapid [...]]]></description>
			<content:encoded><![CDATA[<div>Posted on December 3rd, 2009 by admin</div>
<div id="tabModBdy">
<div><strong>Discovered: </strong>December 1, 2009</div>
<div><strong>Updated: </strong>December 2, 2009 6:13:59 AM</div>
<div><strong>Type: </strong>Trojan</div>
<div><strong>Systems Affected: </strong>Windows XP, Windows Vista, Windows NT, Windows Server 2003, Windows 2000</div>
<p>Trojan.Vundo!gen1 is a heuristic detection used to detect threats associated with the following family:<br />
Trojan.Vundo</p>
<p><strong> </strong></p>
<h3>Protection</h3>
<ul>
<li> <strong>Initial Rapid Release version </strong>pending</li>
<li> <strong>Latest Rapid Release version </strong>pending</li>
<li> <strong>Initial Daily Certified version </strong>December 1, 2009 revision 025</li>
<li> <strong>Latest Daily Certified version </strong>December 1, 2009 revision 025</li>
<li> <strong>Initial Weekly Certified release date </strong>December 2, 2009</li>
</ul>
<p>Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.</p>
<h3>Threat Assessment</h3>
<h4>Wild</h4>
<ul>
<li> <strong>Wild Level: </strong>Low</li>
<li> <strong>Number of Infections: </strong>0 – 49</li>
<li> <strong>Number of Sites: </strong>0 – 2</li>
<li> <strong>Geographical Distribution: </strong>Low</li>
<li> <strong>Threat Containment: </strong>Easy</li>
<li> <strong>Removal: </strong>Easy</li>
</ul>
<h4>Damage</h4>
<ul>
<li> <strong>Damage Level: </strong>Medium</li>
</ul>
<h4>Distribution</h4>
<ul>
<li> <strong>Distribution Level: </strong>Low</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.splatware.com/trojan-vundogen1.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

