<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Virus Experts - We Make Your Digital Life Secured</title>
	<atom:link href="http://www.virusexperts.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.virusexperts.org</link>
	<description>Virusexperts.org is about how to remove and protect you digital life from viruses,worms and spyware simply ( We make your digital life secured )</description>
	<lastBuildDate>Fri, 12 Mar 2010 06:59:06 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Windows and Mac users urged to update Safari</title>
		<link>http://www.virusexperts.org/security-news/windows-and-mac-users-urged-to-update-safari/</link>
		<comments>http://www.virusexperts.org/security-news/windows-and-mac-users-urged-to-update-safari/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 06:59:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[graham cluley]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[mac users]]></category>
		<category><![CDATA[malicious]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[safari browser]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security bugs]]></category>
		<category><![CDATA[security hole]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows users]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2164</guid>
		<description><![CDATA[Apple has released version 4.0.5 of its Safari browser, fixing a number of issues with its browser for Windows and Mac OS X including &#8211; most importantly &#8211; a grand total of 16 security vulnerabilities.
 
If you dilly-dally over updating your computer, it&#8217;s possible that hackers could exploit the security bugs &#8211; including some that could [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-news/critical-security-update-for-adobe-reader-and-acrobat/' rel='bookmark' title='Permanent Link: Critical security update for Adobe Reader and Acrobat'>Critical security update for Adobe Reader and Acrobat</a></li>
<li><a href='http://www.virusexperts.org/security-news/fake-conflicker-b-infection-alert-puts-internet-users-at-risk/' rel='bookmark' title='Permanent Link: Fake Conflicker.B Infection Alert puts internet users at risk'>Fake Conflicker.B Infection Alert puts internet users at risk</a></li>
<li><a href='http://www.virusexperts.org/security-news/operation-aurora-microsoft-knew-about-internet-explorer-flaw-for-four-months/' rel='bookmark' title='Permanent Link: Operation Aurora: Microsoft knew about Internet Explorer flaw for four months'>Operation Aurora: Microsoft knew about Internet Explorer flaw for four months</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Apple has released version 4.0.5 of its Safari browser, fixing a number of issues with its browser for Windows and Mac OS X including &#8211; most importantly &#8211; a grand total of 16 security vulnerabilities.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">If you dilly-dally over updating your computer, it&#8217;s possible that hackers could exploit the security bugs &#8211; including some that could mean that simply visiting a webpage with a maliciously crafted image could lead to malicious code being automatically run on your computer.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Interestingly, one of the bugs (CVE-2009-2285) fixed in Safari 4.0.5 was announced and patched in Mac OS X 10.6.2 back in December 2009, and in Mac OS X 10.5 since January, meaning that Windows users of Safari have been vulnerable for over two months to the way their browser handles booby-trapped TIFF images.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">But it doesn&#8217;t matter whether you own a Mac or PC, if you run Safari the message is clear: It&#8217;s time to update your browser and ensure that you are protected against hackers exploiting the security holes detailed in the <a title="Link to Apple knowledgebase article" rel="nofollow" href="http://support.apple.com/kb/HT4070">security advisory</a> on Apple&#8217;s website.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Safari users should practise safe computing, and update their systems as soon as possible.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>By Graham Cluley, Sophos</strong></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"> </p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-news/critical-security-update-for-adobe-reader-and-acrobat/' rel='bookmark' title='Permanent Link: Critical security update for Adobe Reader and Acrobat'>Critical security update for Adobe Reader and Acrobat</a></li>
<li><a href='http://www.virusexperts.org/security-news/fake-conflicker-b-infection-alert-puts-internet-users-at-risk/' rel='bookmark' title='Permanent Link: Fake Conflicker.B Infection Alert puts internet users at risk'>Fake Conflicker.B Infection Alert puts internet users at risk</a></li>
<li><a href='http://www.virusexperts.org/security-news/operation-aurora-microsoft-knew-about-internet-explorer-flaw-for-four-months/' rel='bookmark' title='Permanent Link: Operation Aurora: Microsoft knew about Internet Explorer flaw for four months'>Operation Aurora: Microsoft knew about Internet Explorer flaw for four months</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/security-news/windows-and-mac-users-urged-to-update-safari/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter fights back against spam, phishing, and other malicious links</title>
		<link>http://www.virusexperts.org/security-news/twitter-fights-back-against-spam-phishing-and-other-malicious-links/</link>
		<comments>http://www.virusexperts.org/security-news/twitter-fights-back-against-spam-phishing-and-other-malicious-links/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 15:17:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[graham cluley]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[SophosLabs]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Spread]]></category>
		<category><![CDATA[Threat]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2160</guid>
		<description><![CDATA[
In a move that should be welcomed by many users, Twitter has announced that it is introducing a new feature to combat the many malicious and malware URLs that are distributed via the micro-blogging site.
 
In a blog entry posted by Del Harvey, Twitter&#8217;s Director of Trust and Safety, it was revealed that the site will [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-channel/video-of-twitter-phishing-the-bzpharma-lol-this-is-funny-attack/' rel='bookmark' title='Permanent Link: Video of Twitter phishing: The BZPharma &#8216;LOL this is funny&#8217; attack (Video)'>Video of Twitter phishing: The BZPharma &#8216;LOL this is funny&#8217; attack (Video)</a></li>
<li><a href='http://www.virusexperts.org/security-news/twitter-using-google-blacklist-to-filter-malicious-links/' rel='bookmark' title='Permanent Link: Twitter Using Google Blacklist To Filter Malicious Links'>Twitter Using Google Blacklist To Filter Malicious Links</a></li>
<li><a href='http://www.virusexperts.org/security-news/off-the-rails-twitter-passwords-and-twittertrain/' rel='bookmark' title='Permanent Link: Off The Rails: Twitter, Passwords And Twittertrain'>Off The Rails: Twitter, Passwords And Twittertrain</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter" title="Twitterpic" src="http://www.virusexperts.org/wp-content/thumbnails/2160.jpg" alt="" width="170" height="218" /></p>
<p style="text-align: justify;">In a move that should be welcomed by many users, Twitter has announced that it is introducing a new feature to combat the many malicious and malware URLs that are distributed via the micro-blogging site.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">In a <a title="Link to Twitter" rel="nofollow" href="http://blog.twitter.com/2010/03/trust-and-safety.html">blog entry</a> posted by Del Harvey, Twitter&#8217;s Director of Trust and Safety, it was revealed that the site will start using its own URL shortener (twt.tl) for Twitter messages sent privately between two users via a direct message (DM), giving it the opportunity to &#8220;detect, intercept, and prevent the spread of bad links across all of Twitter&#8221;.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">As Sophos&#8217;s Chet Wisniewski <a title="Link to Dark Reading article" rel="nofollow" href="http://www.darkreading.com/securityservices/security/attacks/showArticle.jhtml?articleID=223400097">told DarkReading</a>, the new <a href="http://twt.tl/">http://twt.tl</a> shortened url appears to be only evoked with email notifications for direct messages at this time.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Details of how Twitter is determining if a link is potentially malicious or not do not appear to have been released at this time, and it would certainly be great if Twitter would post some more information on how the system will work and what users can expect to see.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: left;">It&#8217;s also to be hoped that this new service will be rolled-out to other areas of Twitter too. We&#8217;ve seen many times in the past that phishing and spam attacks on Twitter don&#8217;t tend to restrict themselves purely to DMs, but will also often be found in the public timeline too, as the following <a title="Link to Sophos YouTube video" rel="nofollow" href="http://www.youtube.com/watch?v=cDSskvrUw_g">YouTube video</a> demonstrates:</p>
<p style="text-align: left;"> </p>
<p style="text-align: center;">
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="560" height="340" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/cDSskvrUw_g&amp;hl=en_US&amp;fs=1&amp;rel=0" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="560" height="340" src="http://www.youtube.com/v/cDSskvrUw_g&amp;hl=en_US&amp;fs=1&amp;rel=0" allowscriptaccess="always" allowfullscreen="true"></embed></object>
</p>
<p style="text-align: center;"><em>(Enjoy this video?  You can check out more on the <a title="Link to SophosLabs YouTube channel" rel="nofollow" href="http://www.youtube.com/sophoslabs">SophosLabs YouTube channel</a> and subscribe if you like)</em></p>
<p style="text-align: justify;"><em><br /></em></p>
<p style="text-align: justify;">The problem of dangerous links being distributed via Twitter has been growing for some time, with some <a href="http://www.sophos.com/pressoffice/news/articles/2010/02/security-report-2010.html">70% of people polled by Sophos reporting that they have been on the receiving end of spam and malware attacks</a> via social networks in the last year.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">The news of Twitter&#8217;s new twt.tl short url facility follows a few months after <a href="http://www.sophos.com/pressoffice/news/articles/2009/11/bit.ly-agreement.html">bit.ly announced</a> that it would protect users against visiting webpages that may contain a malware, spam or phishing threat using technology from security vendors such as Sophos.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><em>* Image source: </em><a href="http://www.flickr.com/photos/wonderferret/2680539745/"><em>wonderferret’s Flickr photostream</em></a><em> (Creative Commons) </em></p>
<p style="text-align: justify;"><em><br /></em></p>
<p style="text-align: justify;"><strong>By Graham Cluley, Sophos</strong></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong><br /></strong></p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-channel/video-of-twitter-phishing-the-bzpharma-lol-this-is-funny-attack/' rel='bookmark' title='Permanent Link: Video of Twitter phishing: The BZPharma &#8216;LOL this is funny&#8217; attack (Video)'>Video of Twitter phishing: The BZPharma &#8216;LOL this is funny&#8217; attack (Video)</a></li>
<li><a href='http://www.virusexperts.org/security-news/twitter-using-google-blacklist-to-filter-malicious-links/' rel='bookmark' title='Permanent Link: Twitter Using Google Blacklist To Filter Malicious Links'>Twitter Using Google Blacklist To Filter Malicious Links</a></li>
<li><a href='http://www.virusexperts.org/security-news/off-the-rails-twitter-passwords-and-twittertrain/' rel='bookmark' title='Permanent Link: Off The Rails: Twitter, Passwords And Twittertrain'>Off The Rails: Twitter, Passwords And Twittertrain</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/security-news/twitter-fights-back-against-spam-phishing-and-other-malicious-links/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Energizer DUO USB battery charger software allows unauthorized remote system access</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/energizer-duo-usb-battery-charger-software-allows-unauthorized-remote-system-access/</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/energizer-duo-usb-battery-charger-software-allows-unauthorized-remote-system-access/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 09:46:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[battery charger]]></category>
		<category><![CDATA[energizerduoweb]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[USB]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2151</guid>
		<description><![CDATA[
 
Overview
The software available for the Energizer DUO USB battery charger contains a backdoor that allows unauthorized remote system access.
 
 

I. Description
Energizer DUO is a USB battery charger. An optional Windows application that allows the user to view the battery charging status has been available on the Energizer website. The installer for the Energizer DUO software places [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/microsoft%c2%ae-windows%c2%ae-malicious-software-removal-tool-kb890830-v2-12-7142009/' rel='bookmark' title='Permanent Link: Microsoft® Windows® Malicious Software Removal Tool (KB890830) v2.12 &#8211; (7/14/2009)'>Microsoft® Windows® Malicious Software Removal Tool (KB890830) v2.12 &#8211; (7/14/2009)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter" title="energizerduoweb" src="http://www.virusexperts.org/wp-content/thumbnails/2151.jpg" alt="" width="300" height="350" /></p>
<p> </p>
<h4><a name="overview">Overview</a></h4>
<p>The software available for the Energizer DUO USB battery charger contains a backdoor that allows unauthorized remote system access.</p>
<p> </p>
<p> </p>
<p style="text-align: justify;"><a name="description"></a></p>
<h4><a name="description">I. Description</a></h4>
<p>Energizer DUO is a USB battery charger. An optional Windows application that allows the user to view the battery charging status has been available on the Energizer website. The installer for the Energizer DUO software places the file <tt>UsbCharger.dll</tt> in the application&#8217;s directory and <tt>Arucer.dll</tt> in the Windows system32 directory. When the Energizer UsbCharger software executes, it utilizes the <tt>UsbCharger.dll</tt> component for providing USB communication capabilities. <tt>UsbCharger.dll</tt> executes <tt>Arucer.dll</tt> via the Windows <tt>rundll32.exe</tt> mechanism, and it also configures <tt>Arucer.dll</tt> to execute automatically when Windows starts by creating an entry in the <tt>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</tt> registry key.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><tt>Arucer.dll</tt> is a backdoor that allows unauthorized remote system access via accepting connections on <tt>7777/tcp</tt>. Note that Windows XP SP2 and later systems include a firewall by default. Upon running the Energizer UsbCharger software for the first time, a dialog similar to the following is displayed:<br /> <img class="aligncenter" src="http://www.virusexperts.org/wp-content/uploads/HLIC/c6303cc191d07c13280fec97a9b2a232.gif" alt="" width="434" height="312" /><br /> If the user selects &#8220;Unblock,&#8221; then the system will be at risk. Also note that if the application is unblocked, this will cause Windows to add <tt>rundll32.exe</tt> to the Windows Firewall exceptions list. This means that any DLL that is executed through the <tt>rundll32.exe</tt> mechanism will be excluded from the Windows Firewall, regardless of the DLL or port used.</p>
<p style="text-align: justify;"> </p>
<p>The backdoor capabilities include the ability to list directories, send and receive files, and execute programs. The hash information for the file is:<br /> <tt>MD5: 1070be3e60a1868d2cd62fc90d76c861</tt><br /> <tt>SHA1: </tt><tt>d102b1d2538d8771be85403272e5a22a4b3f81ad</tt></p>
<p>The file details for <tt>Arucer.dll</tt> are:</p>
<p><tt>--a-- W32i   DLL CHS         1.0.0.1 shp     28,672 05-10-2007 arucer.dll</tt><br /> <tt> Language        0x0804 (Chinese (PRC))</tt><br /> <tt> CharSet         0x04b0 Unicode</tt><br /> <tt> OleSelfRegister Disabled</tt><br /> <tt> CompanyName</tt><br /> <tt> FileDescription Arucer DLL</tt><br /> <tt> InternalName    Arucer</tt><br /> <tt> OriginalFilenam Arucer.DLL</tt><br /> <tt> ProductName     Arucer Dynamic Link Library</tt><br /> <tt> ProductVersion  1, 0, 0, 1</tt><br /> <tt> FileVersion     1, 0, 0, 1</tt><br /> <tt> LegalCopyright  ???? (C) 2006</tt><br /> <tt> LegalTrademarks</tt></p>
<p><tt> VS_FIXEDFILEINFO:</tt><br /> <tt> Signature:      feef04bd</tt><br /> <tt> Struc Ver:      00010000</tt><br /> <tt> FileVer:        00010000:00000001 (1.0:0.1)</tt><br /> <tt> ProdVer:        00010000:00000001 (1.0:0.1)</tt><br /> <tt> FlagMask:       0000003f</tt><br /> <tt> Flags:          00000000</tt><br /> <tt> OS:             00000004 Win32</tt><br /> <tt> FileType:       00000002 Dll</tt><br /> <tt> SubType:        00000000</tt><br /> <tt> FileDate:       00000000:00000000</tt></p>
<p> </p>
<p style="text-align: justify;"><a name="impact"></a></p>
<h4><a name="impact">II. Impact</a></h4>
<p>An attacker is able to remotely control a system, including the ability to list directories, send and receive files, and execute programs. The backdoor operates with the privileges of the logged-on user.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><a name="solution"></a></p>
<h4><a name="solution">III. Solution</a></h4>
<p><strong>Remove the Energizer UsbCharger software</strong></p>
<p style="text-align: justify;">Removing the Energizer UsbCharger software will also remove the registry value that causes the backdoor to execute automatically when Windows starts. The <tt>Arucer.dll</tt> file will remain in the system32 directory, but the mechanisms for executing the code in the DLL will not be present.</p>
<p style="text-align: justify;"> </p>
<p><strong>Remove the Arucer.dll file</strong></p>
<p>The backdoor component of the Energizer UsbCharger software can be removed by deleting the <tt>Arucer.dll </tt>file from the Windows system32 directory. Because the backdoor hosted by rundll32.exe continues to run after the software has been uninstalled, the Windows may need to be restarted before this file can be removed.</p>
<p style="text-align: justify;"> </p>
<p><strong>Remove &#8220;Run DLL as an App&#8221; exclusion from the Windows Firewall</strong></p>
<p>If the user unblocks Run DLL as an App (rundll32.exe) from the Windows Firewall, the exclusion will remain after the Energizer UsbCharger software has been uninstalled. To restore the firewall to the previous state, the &#8220;Run a DLL as an App&#8221; entry should be removed from the exclusions list.</p>
<p style="text-align: justify;"> </p>
<p><strong>Block or restrict network access</strong></p>
<p>Blocking access to <tt>7777/tcp</tt> can mitigate this vulnerability by preventing network connectivity to the backdoor. This may be achieved with network perimeter devices or host-based software firewalls. The Energizer UsbCharger software does not automatically add an exception to the Windows Firewall for <tt>7777/tcp</tt> or the backdoor application. Therefore, the first time that Energizer UsbCharger is executed, the user will be prompted that &#8220;Run a DLL as an APP&#8221; has been blocked by the Windows Firewall.</p>
<p style="text-align: justify;"> </p>
<p>The following Snort rules can be used to detect network traffic related to this backdoor:</p>
<p><tt>alert tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777 (msg:"Arucer Command Execution"; flow:established; content:"|C2 E5 E5 E5 9E DD A4 A3 D4 A6 D4 D3 D1 C8 A0 A7 A1 D3 C8 D1 87 D7 87 C8 A7 A6 D4 A3 C8 D3 D1 D3 D2 D1 A0 DC DD A4 D2 D4 D5 98 E5|"; classtype:trojan-activity; sid:1000004; rev:2;)</tt></p>
<p><tt>alert tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777 (msg:"Arucer DIR Listing"; flow:established; content:"|C2 E5 E5 E5 9E D5 D4 D2 D1 A1 D7 A3 A6 C8 D2 A6 A7 D3 C8 D1 84 D7 D7 C8 DD D2 A6 D2 C8 D2 A7 A7 D2 D7 A4 D6 D7 A3 D4 DC A3 98 E5|"; classtype:trojan-activity; sid:1000005; rev:2;)</tt></p>
<p><tt>alert tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777 (msg:"Arucer WRITE FILE command"; flow: established; content:"|C2 E5 E5 E5 9E DC DD A1 DC D0 DD A3 A6 C8 A1 D5 A4 D7 C8 D1 83 D4 86 C8 A7 DD D1 D4 C8 D7 D6 D7 A4 A7 D6 D0 D2 A0 D2 A6 DD 98 E5|"; classtype:trojan-activity; sid:1000006; rev:2;)</tt></p>
<p><tt>alert tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777 (msg:"Arucer READ FILE Command"; flow:established; content:"|C2 E5 E5 E5 9E A3 D3 A6 D1 D6 A0 D4 A4 C8 D4 D0 D0 D4 C8 D1 D5 D5 D5 C8 A4 D1 DD D6 C8 A6 D6 D3 D4 DC D3 DC A4 A0 A6 D1 D4 98 E5|"; classtype:trojan-activity; sid:1000007; rev:2;)</tt></p>
<p><tt>alert tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777 (msg:"Arucer NOP Command"; flow:established; content:"|C2 E5 E5 E5 9E D2 DD D6 A0 A4 A6 A7 A3 C8 A0 A3 DD A7 C8 D1 DC DD 80 C8 A4 D5 D0 DC C8 A3 D5 A7 D0 A7 A1 D4 D7 D3 D1 D4 A0 98 E5|"; classtype:trojan-activity; sid:1000008; rev:2;)</tt></p>
<p><tt>alert tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777 (msg:"Arucer FIND FILE Command"; flow:established; content:"|C2 E5 E5 E5 9E A0 A4 D2 A4 D7 A0 A7 D2 C8 D4 A0 D1 DC C8 D1 81 D0 83 C8 A7 D1 A1 DD C8 A1 D3 D3 D1 D0 A7 D2 D1 D1 D5 A0 D6 98 E5|"; classtype:trojan-activity; sid:1000009; rev:2;)</tt></p>
<p><tt>alert tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777 (msg:"Arucer YES Command"; flow:established; content:"|C2 E5 E5 E5 9E A0 D7 A4 A6 D0 D5 DD DC C8 D6 DD D7 D5 C8 D1 D6 83 80 C8 DD A4 D1 A1 C8 A4 D2 D5 D7 DD A3 A4 A1 DD A6 D7 DD 98 E5|"; classtype:trojan-activity; sid:1000010; rev:2;)</tt></p>
<p><tt>alert tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777 (msg:"Arucer ADD RUN ONCE Command"; flow:established; content:"|C2 E5 E5 E5 9E D6 DD D1 A0 A7 A0 D7 A6 C8 A3 DC A0 A4 C8 D1 83 D3 87 C8 DC D1 A0 A3 C8 A6 DC A1 D7 A1 A4 D0 DD A3 A1 D4 D6 98 E5|"; classtype:trojan-activity; sid:1000011; rev:2;)</tt></p>
<p><tt>alert tcp $EXTERNAL_NET any -&gt; $HOME_NET 7777 (msg:"Arucer DEL FILE Command"; flow:established; content:"|C2 E5 E5 E5 9E D1 A3 D1 A3 D5 A1 DD DD C8 A0 D2 D4 D0 C8 D1 87 D4 83 C8 A7 D6 D4 D4 C8 D3 D4 A0 D0 D6 D5 A6 D7 A6 DD A3 A6 98 E5|"; classtype:trojan-activity; sid:1000012; rev:2;</tt></p>
<p> </p>
<h3 style="text-align: justify;">Systems Affected</h3>
<p><a name="systems" href="http://www.kb.cert.org" target="_blank"></a></p>
<p><a name="systems" href="http://www.kb.cert.org" target="_blank"><br /></a></p>
<p> </p>
<p><strong>Source : <a href="http://www.kb.cert.org">www.kb.cert.org</a></strong></p>
<p> </p>
<p> </p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/microsoft%c2%ae-windows%c2%ae-malicious-software-removal-tool-kb890830-v2-12-7142009/' rel='bookmark' title='Permanent Link: Microsoft® Windows® Malicious Software Removal Tool (KB890830) v2.12 &#8211; (7/14/2009)'>Microsoft® Windows® Malicious Software Removal Tool (KB890830) v2.12 &#8211; (7/14/2009)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/energizer-duo-usb-battery-charger-software-allows-unauthorized-remote-system-access/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Removal tool for Oficla.H!dll, Win32.Fregee.av (reader_s.exe, file1.exe) Trojan</title>
		<link>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-oficla-hdll-win32-fregee-av-reader_s-exe-file1-exe-trojan/</link>
		<comments>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-oficla-hdll-win32-fregee-av-reader_s-exe-file1-exe-trojan/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 23:03:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Removal Tips,Tools and Videos]]></category>
		<category><![CDATA[file1.exe]]></category>
		<category><![CDATA[Mal/Generic-A]]></category>
		<category><![CDATA[manual removal]]></category>
		<category><![CDATA[Oficla.H!dll]]></category>
		<category><![CDATA[reader_s.exe]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[repair tool]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[trojan removal tool]]></category>
		<category><![CDATA[virusexperts]]></category>
		<category><![CDATA[virusexperts.org]]></category>
		<category><![CDATA[Win32.Fregee.av]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2131</guid>
		<description><![CDATA[
 
Sample Submitted By Sven Berger 
 
 
 

 
Severity Level : 6/10
 
Alias:

Mal/Generic-A, Mal / Oficla-A [Sophos]
SpyAgent-br.dll [McAfee]
Trojan.Win32.Fregee.av [Kaspersky Lab]
Trojan:Win32/Oficla.H!dll [Microsoft]

 
reader_s.exe VirusTotal Report : (Click Here)
file1.exe VirusTotal Report : (Click Here)
 
File System Modifications
The following files were created in the system:
 

%system%\onyc.ffo
%system%\ reader_s.exe
%UserProfile%\reader_s.exe
%UserProfile%\Local Settings\Temp\?.tmp
%UserProfile%\Local Settings\Temp\file1.exe

 
Note: 

%system% is a variable that refers to the System folder. By default, this is &#8220;C:\Windows\System&#8221; (Windows [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-generic-malware-slm-807dc390-win32-suspectcrc-trjci-a-mso-exe-usbflash-com-keylogger/' rel='bookmark' title='Permanent Link: Removal tool for Generic.Malware.SL!!M.807DC390 (mso.exe, usbflash.com) Keylogger'>Removal tool for Generic.Malware.SL!!M.807DC390 (mso.exe, usbflash.com) Keylogger</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-dybalom-gd-trojan-and-key-logger-not-detected-yet/' rel='bookmark' title='Permanent Link: Removal tool for Dybalom.gd Trojan and Key logger not detected yet'>Removal tool for Dybalom.gd Trojan and Key logger not detected yet</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-magania-bzmw-wormwin32taterf-btrojan-win32-inhoo-trojan/' rel='bookmark' title='Permanent Link: Removal tool for Magania.bzmw (Taterf.B,Win32.Inhoo) Trojan'>Removal tool for Magania.bzmw (Taterf.B,Win32.Inhoo) Trojan</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="border: 0px none; margin: 0px; padding: 0px; text-align: center;"><img class="aligncenter size-full wp-image-2145" title="Win32.Fregee.av_logo" src="http://www.virusexperts.org/wp-content/uploads/2010/03/Win32.Fregee.av_logo.png" alt="" width="250" height="250" /></p>
<p style="border: 0px none ; margin: 0px; padding: 0px; text-align: center;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px; text-align: center;">Sample Submitted By <strong>Sven Berger</strong><span id="PresenceContainer"><strong> </strong></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span id="more-2131"></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span style="color: #ff0000;"><strong><span style="color: #000000;">Severity Level :</span> 6/10</strong></span></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3><strong>Alias:</strong></h3>
<ul>
<li>Mal/Generic-A, Mal / Oficla-A <span style="color: #ff0000;"><strong>[Sophos]</strong></span></li>
<li>SpyAgent-br.dll <span style="color: #ff0000;"><strong>[McAfee]</strong></span></li>
<li>Trojan.Win32.Fregee.av<strong> <span style="color: #ff0000;">[Kaspersky Lab]</span></strong></li>
<li>Trojan:Win32/Oficla.H!dll<strong> <span style="color: #ff0000;">[Microsoft]</span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p><strong><span style="color: #ff0000;">reader_s.exe</span> VirusTotal Report : (<a href="http://www.virustotal.com/analisis/854c257fbfcdedb965c57ac865a8f30bc774f749230289d9880a0c78f37df199-1268072809" target="_blank">Click Here</a>)</strong></p>
<p><strong><span style="color: #ff0000;">file1.exe</span> </strong><strong>VirusTotal Report : (<a href="http://www.virustotal.com/analisis/6be4ccdf4ba8ff4d4ad29d245d5e1c1a98f947f89fe0fb304c72595e8ee51d13-1267179278" target="_blank">Click Here</a>)</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>File System Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">The following files were created in the system:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<ul>
<li><strong>%system%\<span style="color: #ff0000;">onyc.ffo</span><br /></strong></li>
<li><strong>%system%\</strong><strong> <span style="color: #ff0000;">reader_s.exe</span><br /></strong></li>
<li><strong>%UserProfile%\<span style="color: #ff0000;">reader_s.exe</span></strong></li>
<li><strong>%UserProfile%\Local Settings\Temp\<span style="color: #ff0000;">?.tmp</span></strong></li>
<li><strong>%UserProfile%\Local Settings\Temp\<span style="color: #ff0000;">file1.exe</span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><span style="color: #ff0000;"><strong>Note: </strong></span></p>
<ul>
<li><strong>%system%</strong> is a variable that refers to the System folder. By default, this is <strong>&#8220;C:\Windows\System&#8221;</strong> (Windows 95/98/Me), <strong>&#8220;C:\Winnt\System32&#8243;</strong> (Windows NT/2000), or<strong> &#8220;C:\Windows\System32&#8243;</strong> (Windows XP).</li>
<li><strong>?</strong> = Random file name.</li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>Memory Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">There were new processes created in the system:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<table style="margin-bottom: 25px;" border="0" cellspacing="0" cellpadding="5" width="452">
<tbody>
<tr>
<td>
<h3>Process Name</h3>
</td>
<td>
<h3>Process Filename</h3>
</td>
</tr>
<tr>
<td><span style="color: #ff0000;"><strong>reader_s.exe</strong></span></td>
<td><strong>%system%\<span style="color: #ff0000;"> </span></strong><span style="color: #ff0000;"><strong>reader_s.exe</strong></span></td>
</tr>
<tr>
<td><span style="color: #ff0000;"><strong>onyc.ffo</strong></span></td>
<td><strong>%system%\<span style="color: #ff0000;">onyc.ffo</span></strong></td>
</tr>
<tr>
<td><strong><span style="color: #ff0000;"><br /></span></strong></td>
<td></td>
</tr>
</tbody>
</table>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3>Registry Modifications</h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;">The newly created or modified Registry Value is:</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<ul>
<li><strong>[</strong><strong>HKCR\idid</strong><strong>] </strong></li>
<li><strong>[</strong><strong>HKLM\SOFTWARE\AGprotect</strong><strong>] </strong></li>
<li><strong>[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</strong><strong>&gt;</strong><strong><span style="color: #ff0000;">“reader_s” =</span></strong><strong> %system%\<span style="color: #ff0000;">reader_s.exe</span></strong></li>
<li><strong>[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</strong><strong>&gt;</strong><strong><span style="color: #ff0000;">“reader_s” =</span></strong><strong> %system%\<span style="color: #ff0000;">reader_s.exe</span></strong></li>
<li><strong>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]</strong><strong>&gt;</strong><strong><span style="color: #ff0000;">“Shell” =</span></strong><strong> explorer.exe <span style="color: #ff0000;">rundll32.exe onyc.ffo hgikqnb</span><span style="color: #ff0000;"> </span></strong></li>
</ul>
<p> </p>
<h3 style="border: 0px none ; margin: 0px; padding: 0px;"><strong>For auto removal :</strong></h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong><br /> </strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Download Fregee.av, Trojan.Win32.Fregee.av Trojan removal tool that provided by VirusExperts.org you can download it from <a title="Oficla.Hdll-Win32.Fregee.av_Removal" href="http://www.virusexperts.org/wp-content/uploads/2010/03/Oficla.Hdll-Win32.Fregee.av_Trojan_Removal_virusexperts.org_.zip" target="_blank">Here</a>.</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<h3 style="border: 0px none ; margin: 0px; padding: 0px;"><strong>For manual removal First download these tools:</strong></h3>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong><br /> </strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;">1- <strong>RRT</strong> : Registry, Task Manager and Folder Options Repair Tool <strong>(<a href="http://www.sergiwa.com/download/security/RRT.zip" target="_blank">Click Here</a>).</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;">2- <strong>KillBox </strong>: Kill the Process if your Access Denied <strong>(<a href="http://killbox.net/downloads/KillBox.exe" target="_blank">Click Here</a>)</strong>.</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;">3- <strong>Task Manager Enabler</strong> : <strong>(<a href="http://www.kellys-korner-xp.com/regs_edits/taskmanager.reg" target="_blank">Click Here</a>)</strong>.</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;">4- <strong>Registry Enabler</strong> : <strong>(<a href="http://www.kellys-korner-xp.com/regs_edits/disableregistrytoolsundo.reg" target="_blank">Click Here</a>)</strong>.</p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Now Follow these instructions :</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong><br /> </strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Recommend Removal from Safe Mode</strong></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;">To Start in Safe mode Restart your Computer, Press F8 Repeatedly, when your Screen turns on, Select Safe mode, press enter.</p>
<div style="font-family: Verdana,sans-serif;">The Infected Files Can be Seen in these folders and names also Running in Tasks<br /> End the Following Active Process Before Removal</div>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Kill these Process, by using <span style="color: #000000;">Killbox</span> <br /> </strong></p>
<ul style="font-family: Verdana,sans-serif;">
<li><span style="font-size: x-small;"><span style="color: black;"> </span></span><strong><span style="color: #ff0000;">reader_s.exe</span></strong></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"><strong>Delete These Files</strong></p>
<ul style="font-family: Verdana,sans-serif;">
</ul>
<ul>
<li><strong>%system%\<span style="color: #ff0000;">reader_s.exe<br /></span></strong></li>
<li><strong>%system%\</strong><strong><span style="color: #ff0000;"> </span><span style="color: #ff0000;">onyc.ffo<br /></span></strong></li>
<li><strong>%UserProfile%\Local Settings\Temp\<span style="color: #ff0000;">?.tmp</span></strong><strong><span style="color: #ff0000;"><br /></span></strong></li>
<li><strong>%UserProfile%\Local Settings\Temp\<span style="color: #ff0000;">file1.exe</span><span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;"> </span></strong><strong><span style="color: #ff0000;"> </span></strong></li>
</ul>
<ul style="font-family: Verdana,sans-serif;">
</ul>
<p><br class="spacer_" /></p>
<ul style="font-family: Verdana,sans-serif;">
[ No Exact Information about Files, search above related files in Program files Folder ] If you have any of these files in running process from task manger, end the process before removal.
</ul>
<ul style="font-family: Verdana,sans-serif;">
<span style="color: #ff0000;">Note: if task manager is disabled, Download Task Manager Enabler and </span><span style="color: #ff0000;">Open it with Regedit.exe [%system32\regedit.exe], then it Confirms Add to registry Yes or No, Confirm Yes, then click Ok.</span></p>
<p> </p>
<p> </p>
</ul>
<div style="font-family: Verdana,sans-serif;"><span style="font-size: small;"><strong>Remove Registry </strong></span><span style="font-size: small;"><strong>Entries</strong></span></div>
<div style="font-family: Verdana,sans-serif;"><span style="font-size: small;"><strong><br /> </strong></span></div>
<p><span style="color: #000000;">Click Start, Run,Type regedit,Click OK.</span></p>
<p><br class="spacer_" /></p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<div><span style="color: #ff0000;">Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor.</span></div>
<div><span style="color: #ff0000;"><br /> </span></div>
<ul>
<li><span style="color: #000000;">Download this <span style="color: #3366ff;"><a style="color: #b45f06;" href="http://securityresponse.symantec.com/avcenter/UnHookExec.inf">UnHookExec.inf</a></span>, [ Right Click - Save Target As/Linked Content As ]</span><br /> <span style="color: #000000;">and then continue with the removal. Save it to your Windows desktop. Do not run it at this time, download it only.</span> </li>
<li><span style="color: #000000;">After booting into the Safe Mode or VGA Mode.</span></li>
<li><span style="color: #000000;">Right-click the UnHookExec.inf file and click Install. [This is a small file. It does not display any notice or boxes when you run it].</span></li>
<li><span style="color: #000000;">Or Download Regfile to enable Registry editor and </span><span style="color: #000000;">Open it withma Registry editor.</span></li>
</ul>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<div style="font-family: Verdana,sans-serif; text-align: left;"><span style="color: #000000;"><strong>Delete These Entries</strong></span></div>
<div style="font-family: Verdana,sans-serif; text-align: left;">
<ul>
</ul>
<ul>
<li style="text-align: left;"><span style="color: #000000;"><strong>HKEY_CLASSES_ROOT\idid</strong></span></li>
<li style="text-align: left;"><span style="color: #000000;"><strong>HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect</strong></span></li>
</ul>
</div>
<div style="font-family: Verdana,sans-serif; text-align: left;"><span style="color: #000000;"><strong>Go to These Entries</strong></span></div>
<div style="font-family: Verdana,sans-serif; text-align: left;"><span style="color: #000000;"><strong><br /></strong></span></div>
<div style="font-family: Verdana,sans-serif; text-align: left;">
<div style="font-family: Verdana,sans-serif;">
<ul>
<li><span style="color: #000000;"><strong>HKEY_LOCAL_MACHINE</strong></span><span style="color: #000000;"><strong>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</strong></span><span style="color: #000000;"> </span></li>
</ul>
</div>
<div style="font-family: Verdana,sans-serif;">
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>Delete file Keys from the right side</strong></span></div>
</div>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>The Key “<span style="color: #ff0000;">reader_s</span></strong></span><span style="color: #000000;"><strong><span style="color: #ff0000;"> </span>” with value </strong></span><span style="color: #000000;"><strong>“</strong></span><span style="color: #000000;"><strong><span style="color: #ff0000;"> </span></strong></span><strong><span style="color: #ff0000;">%system%\reader_s.exe</span><span style="color: #ff0000;"> </span></strong><span style="color: #000000;"><strong>”</strong></span></div>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /></strong></span></div>
</div>
<div style="font-family: Verdana,sans-serif;">
<ul>
<li><span style="color: #000000;"><strong>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</strong></span><span style="color: #000000;"><strong><strong> </strong></strong></span></li>
</ul>
</div>
<div style="font-family: Verdana,sans-serif;">
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>Delete file Keys from the right side</strong></span></div>
</div>
<div style="font-family: Verdana,sans-serif;">
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>The Key “<span style="color: #ff0000;">reader_s</span></strong></span><span style="color: #000000;"><strong><span style="color: #ff0000;"> </span>” with value </strong></span><span style="color: #000000;"><strong>“</strong></span><span style="color: #000000;"><strong><span style="color: #ff0000;"> </span></strong></span><strong><span style="color: #ff0000;">%system%\reader_s.exe</span><span style="color: #ff0000;"> </span></strong><span style="color: #000000;"><strong>”</strong></span></div>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /></strong></span></div>
<p><span style="color: #000000;"><strong> </strong></span></p>
</div>
<div style="font-family: Verdana,sans-serif;">
<div style="font-family: Verdana,sans-serif; text-align: center;">
<ul>
<li style="text-align: left;"><span style="color: #000000;"><strong>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon</strong></span><span style="color: #000000;"><strong><strong> </strong></strong></span></li>
</ul>
</div>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>Edit <span style="color: #ff0000;">(Don&#8217;t Delete)</span> file Keys from the right side</strong></span></div>
</div>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>The Key “</strong></span><span style="color: #ff0000;"><strong>Shell</strong></span><span style="color: #000000;"><strong><span style="color: #ff0000;"> </span>” to value </strong></span><span style="color: #000000;"><strong>“</strong></span><span style="color: #000000;"><strong><span style="color: #ff0000;">Explorer.exe</span></strong></span><strong><span style="color: #ff0000;"> </span></strong><span style="color: #000000;"><strong>”</strong></span></div>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /></strong></span></div>
<div style="color: black; font-family: Verdana,sans-serif;">Exit the Registry Editor,</div>
<div style="color: black; font-family: Verdana,sans-serif;">Restart your Computer.</div>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<p style="border: 0px none ; margin: 0px; padding: 0px;"> </p>
<div style="font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>For any help contact us.</strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong>VirusExperts.org TEAM</strong></span></div>
<div style="color: #b45f06; font-family: Verdana,sans-serif;"><span style="color: #000000;"><strong><br /> </strong></span></div>
<div id="_mcePaste" style="overflow: hidden; left: -10000px; width: 1px; position: absolute; top: 741px; height: 1px;">%Temp%\cvasds0.dll <br /> %Temp%\cvasds1.dll <br /> %Temp%\cvasds2.dll</div>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-generic-malware-slm-807dc390-win32-suspectcrc-trjci-a-mso-exe-usbflash-com-keylogger/' rel='bookmark' title='Permanent Link: Removal tool for Generic.Malware.SL!!M.807DC390 (mso.exe, usbflash.com) Keylogger'>Removal tool for Generic.Malware.SL!!M.807DC390 (mso.exe, usbflash.com) Keylogger</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-dybalom-gd-trojan-and-key-logger-not-detected-yet/' rel='bookmark' title='Permanent Link: Removal tool for Dybalom.gd Trojan and Key logger not detected yet'>Removal tool for Dybalom.gd Trojan and Key logger not detected yet</a></li>
<li><a href='http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-magania-bzmw-wormwin32taterf-btrojan-win32-inhoo-trojan/' rel='bookmark' title='Permanent Link: Removal tool for Magania.bzmw (Taterf.B,Win32.Inhoo) Trojan'>Removal tool for Magania.bzmw (Taterf.B,Win32.Inhoo) Trojan</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/removal-tips-tools-and-videos/removal-tool-for-oficla-hdll-win32-fregee-av-reader_s-exe-file1-exe-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hackers exploit Oscar film awards to spread scareware</title>
		<link>http://www.virusexperts.org/security-news/hackers-exploit-oscar-film-awards-to-spread-scareware/</link>
		<comments>http://www.virusexperts.org/security-news/hackers-exploit-oscar-film-awards-to-spread-scareware/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 22:23:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[FAKEAV]]></category>
		<category><![CDATA[film awards]]></category>
		<category><![CDATA[graham cluley]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[malicious]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[malicious script]]></category>
		<category><![CDATA[oscar film]]></category>
		<category><![CDATA[oscars]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[security threats]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[SophosLabs]]></category>
		<category><![CDATA[Spread]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Threat]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2122</guid>
		<description><![CDATA[ 
Last night saw Kathryn Bigelow&#8217;s hard-hitting film &#8220;The Hurt Locker&#8221;, about a bomb disposal team in Iraq, scoop the major gongs at the Academy Awards. It shouldn&#8217;t probably be any surprise to hear that movie buffs around the world used the internet to keep track of who won which Oscars, and &#8211; sadly -that hackers [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-news/facebook-unnamed-app-hackers-poison-search-results/' rel='bookmark' title='Permanent Link: Facebook unnamed app: Hackers poison search results'>Facebook unnamed app: Hackers poison search results</a></li>
<li><a href='http://www.virusexperts.org/security-news/fake-conflicker-b-infection-alert-puts-internet-users-at-risk/' rel='bookmark' title='Permanent Link: Fake Conflicker.B Infection Alert puts internet users at risk'>Fake Conflicker.B Infection Alert puts internet users at risk</a></li>
<li><a href='http://www.virusexperts.org/security-news/facebook-fan-check-virus-scare-leads-to-malware/' rel='bookmark' title='Permanent Link: Facebook Fan Check Virus scare leads to malware'>Facebook Fan Check Virus scare leads to malware</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Last night saw Kathryn Bigelow&#8217;s hard-hitting film &#8220;The Hurt Locker&#8221;, about a bomb disposal team in Iraq, scoop the major gongs at the Academy Awards. It shouldn&#8217;t probably be any surprise to hear that movie buffs around the world used the internet to keep track of who won which Oscars, and &#8211; sadly -that hackers would try and exploit the event.</p>
<p style="text-align: justify;"> </p>
<p>Internet users searching for phrases like</p>
<blockquote>
<p><tt>Oscars 2010 winners</tt></p>
<p> </p>
</blockquote>
<p style="text-align: justify;">may be putting the security of their computers at risk today, as some of the results returned by search engines can point to malicious webpages.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">By using SEO (search engine optimisation) techniques, hackers have created webpages that are stuffed with content which appears to be related to the 2010 Oscars, but are really designed to infect your computer.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: center;"><img class="aligncenter" title="Malicious Oscar-related search results" src="http://www.sophos.com/blogs/gc/images/blogs/gc/2010/03/oscar-search-results.jpg" alt="Malicious Oscar-related search results" /></p>
<p>As you can see, information about the Oscars ceremony and award winners has been one of the hottest search topics overnight.</p>
<p> </p>
<p>Clicking on the dangerous links takes you to a page which pretends to scan your computer for security threats, trying to trick you into downloading malicious code and hand over your credit card details.</p>
<p> </p>
<p style="text-align: center;"><img class="aligncenter" src="http://www.sophos.com/blogs/gc/images/blogs/gc/2010/03/oscar-scareware.jpg" alt="Oscar scareware" /></p>
<p style="text-align: justify;">As Fraser Howard <a href="http://www.sophos.com/blogs/sophoslabs/v/post/8867">recently described on the SophosLabs blog</a>, victims are redirected a number of times upon visiting from a search engine, before being taken to a webpage hosting a malicious script.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Sophos detects the malicious scripts as <a href="http://www.sophos.com/security/analyses/viruses-and-spyware/malfakeavjsa.html">Mal/FakeAVJs-A</a>, and the fake anti-virus itself as <a href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojfakeavaxs.html">Troj/FakeAV-AXS</a>.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Fake anti-virus attacks (also known as scareware) are nothing new, and it&#8217;s very common for hackers to exploit hot topics in an attempt to bring a steady stream of traffic to their infected webpages.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>By Graham Cluley, Sophos</strong></p>
<p style="text-align: justify;"><strong><br /></strong></p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-news/facebook-unnamed-app-hackers-poison-search-results/' rel='bookmark' title='Permanent Link: Facebook unnamed app: Hackers poison search results'>Facebook unnamed app: Hackers poison search results</a></li>
<li><a href='http://www.virusexperts.org/security-news/fake-conflicker-b-infection-alert-puts-internet-users-at-risk/' rel='bookmark' title='Permanent Link: Fake Conflicker.B Infection Alert puts internet users at risk'>Fake Conflicker.B Infection Alert puts internet users at risk</a></li>
<li><a href='http://www.virusexperts.org/security-news/facebook-fan-check-virus-scare-leads-to-malware/' rel='bookmark' title='Permanent Link: Facebook Fan Check Virus scare leads to malware'>Facebook Fan Check Virus scare leads to malware</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/security-news/hackers-exploit-oscar-film-awards-to-spread-scareware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IE8 Security Review (Video)</title>
		<link>http://www.virusexperts.org/security-channel/ie8-security-review-video/</link>
		<comments>http://www.virusexperts.org/security-channel/ie8-security-review-video/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 10:15:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Channel]]></category>
		<category><![CDATA[IE8]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2113</guid>
		<description><![CDATA[
 
Features: What&#8217;s new in Internet Explorer 8 ?
Stay safer online
Browse with more confidence knowing Internet Explorer 8 helps protect you from evolving online threats right out of the box . The new SmartScreen filter and other built-in security features help you stay safe by protecting against deceptive and malicious websites which can compromise your data, [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-channel/video-of-twitter-phishing-the-bzpharma-lol-this-is-funny-attack/' rel='bookmark' title='Permanent Link: Video of Twitter phishing: The BZPharma &#8216;LOL this is funny&#8217; attack (Video)'>Video of Twitter phishing: The BZPharma &#8216;LOL this is funny&#8217; attack (Video)</a></li>
<li><a href='http://www.virusexperts.org/security-channel/president-obama-wants-you-to-protect-your-computer-video/' rel='bookmark' title='Permanent Link: President Obama Wants You to Protect Your Computer (Video)'>President Obama Wants You to Protect Your Computer (Video)</a></li>
<li><a href='http://www.virusexperts.org/security-channel/case-conficker-know-more-about-confickerdownadupdownup-and-kido-worm-video/' rel='bookmark' title='Permanent Link: Case Conficker ( Know More About Conficker,Downadup,Downup and Kido Worm ) (Video)'>Case Conficker ( Know More About Conficker,Downadup,Downup and Kido Worm ) (Video)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><p><a href="http://www.virusexperts.org/security-channel/ie8-security-review-video/"><em>Click here to view the embedded video.</em></a></p></p>
<p style="text-align: center;"> </p>
<h2>Features: What&#8217;s new in Internet Explorer 8 ?</h2>
<h5>Stay safer online</h5>
<p style="text-align: justify;">Browse with more confidence knowing Internet Explorer 8 helps protect you from evolving online threats right out of the box . The new SmartScreen filter and other built-in security features help you stay safe by protecting against deceptive and malicious websites which can compromise your data, privacy, and identity.</p>
<p style="text-align: justify;"> </p>
<p><strong><a onclick="javascript:globaltracking.onclicktrack('asc_IE8_Supertabs_LearnmoreSt');location.href=this.href;return false;" href="http://www.microsoft.com/nz/windows/internet-explorer/features/stay-safer-online.aspx" target="_blank">Learn more</a></strong></p>
<ul>
</ul>
<p style="text-align: center;"> </p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-channel/video-of-twitter-phishing-the-bzpharma-lol-this-is-funny-attack/' rel='bookmark' title='Permanent Link: Video of Twitter phishing: The BZPharma &#8216;LOL this is funny&#8217; attack (Video)'>Video of Twitter phishing: The BZPharma &#8216;LOL this is funny&#8217; attack (Video)</a></li>
<li><a href='http://www.virusexperts.org/security-channel/president-obama-wants-you-to-protect-your-computer-video/' rel='bookmark' title='Permanent Link: President Obama Wants You to Protect Your Computer (Video)'>President Obama Wants You to Protect Your Computer (Video)</a></li>
<li><a href='http://www.virusexperts.org/security-channel/case-conficker-know-more-about-confickerdownadupdownup-and-kido-worm-video/' rel='bookmark' title='Permanent Link: Case Conficker ( Know More About Conficker,Downadup,Downup and Kido Worm ) (Video)'>Case Conficker ( Know More About Conficker,Downadup,Downup and Kido Worm ) (Video)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/security-channel/ie8-security-review-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New ClamAV for Windows Powered By ( immunet and sourcefire )</title>
		<link>http://www.virusexperts.org/protection-tools/new-clamav-for-windows-powered-by-immunet-and-sourcefire/</link>
		<comments>http://www.virusexperts.org/protection-tools/new-clamav-for-windows-powered-by-immunet-and-sourcefire/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 23:23:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Protection Tools]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[ClamAV]]></category>
		<category><![CDATA[clamav for windows]]></category>
		<category><![CDATA[Cloud-based]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[Free]]></category>
		<category><![CDATA[immunet]]></category>
		<category><![CDATA[immunity]]></category>
		<category><![CDATA[Protect]]></category>
		<category><![CDATA[Protection]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[sourcefire inc]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2108</guid>
		<description><![CDATA[

 
The new ClamAV for Windows is the result of a partnership between Immunet Corporation (http://www.immunet.com) and Sourcefire, Inc. (http://www.sourcefire.com). It is designed to provide the ClamAV community with a free Windows-specific Anti-Virus (AV) solution using an advanced Cloud-based protection mechanism.  You can use ClamAV For Windows as a stand-alone, host-based AV solution, or in conjunction [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/protection-tools/immunet-protect-%e2%80%93-free-anti-virus-protection-from-the-social-cloud-windows/' rel='bookmark' title='Permanent Link: Immunet Protect – Free Anti-Virus Protection From The Social Cloud (Windows)'>Immunet Protect – Free Anti-Virus Protection From The Social Cloud (Windows)</a></li>
<li><a href='http://www.virusexperts.org/security-news/pandas-cloud-antivirus-leaves-beta-behind/' rel='bookmark' title='Permanent Link: Panda&#8217;s Cloud Antivirus leaves beta behind'>Panda&#8217;s Cloud Antivirus leaves beta behind</a></li>
<li><a href='http://www.virusexperts.org/protection-tools/kaspersky-anti-virus-internet-security-2010-v900313-beta/' rel='bookmark' title='Permanent Link: Kaspersky Anti-Virus &#038; Internet Security 2010 V9.0.0.313 Beta'>Kaspersky Anti-Virus &#038; Internet Security 2010 V9.0.0.313 Beta</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><img class="aligncenter" title="ClamAV" src="http://www.virusexperts.org/wp-content/uploads/HLIC/0a9bbdc1730b8cb3ecb9c68c84309266.gif" alt="" width="140" height="136" /></p>
<p style="text-align: justify;"><a href="http://www.immunet.com"><img class="aligncenter" title="clamav" src="https://www.immunet.com/images/clamav-thumb.png" alt="" width="300" height="164" /></a></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">The new ClamAV for Windows is the result of a partnership between Immunet Corporation (<a href="http://www.immunet.com/" target="_blank">http://www.immunet.com</a>) and Sourcefire, Inc. (<a href="http://www.sourcefire.com/" target="_blank">http://www.sourcefire.com</a>). It is designed to provide the ClamAV community with a free Windows-specific Anti-Virus (AV) solution using an advanced Cloud-based protection mechanism.  You can use ClamAV For Windows as a stand-alone, host-based AV solution, or in conjunction with your pre-installed AV solution to provide enhanced detection for the latest malware threats.</p>
<p> </p>
<p style="text-align: justify;">Say goodbye to the days of watching AV software drain your memory and processing speed. Immunet’s unique Cloud-based technologies allow the ClamAV application to leverage the power of the Cloud to drive the AV engine. When you use ClamAV for Windows, you save system resources for the tasks they really want to run, like games and business applications.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">ClamAV for Windows utilizes advanced Cloud-based and community-based detection methods. Developed by Immunet, these detection methods leverage the computers of your friends, family and a worldwide global community to harness their collective knowledge for securing your PC. Every time someone in this collective community encounters a threat, everyone else in the community gains protection from that same threat in real time. You no longer have to rely on the isolated security of your current Anti-Virus vendor. You are able to protect your friends and family while being better protected yourself. This is exactly what we designed ClamAV for Windows to do. By providing a fast and light layer of virus detection, and linking everyone in a global community, we harness a security sum that is far greater than its individual parts, we call this <em>Collective Immunity</em>.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Immunet placed ClamAV into their Cloud infrastructure alongside their Ethos detection engine, and several other detection technologies.  By combining all these technologies, and utilizing the power of community-based detection, we feel we have the most effective Anti-Virus technology on the market. And it only gets better with every user that installs and utilizes our technology.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>Download New ClamAV :</strong></p>
<ul>
<li><a href="http://www.clamav.net/win32/clam-latest-32.exe">ClamAV for Windows 32 bit</a></li>
<li><a href="http://www.clamav.net/win32/clam-latest-64.exe">ClamAV for Windows 64 bit</a></li>
</ul>
<p> </p>
<h4>Minimum System Requirements</h4>
<ol>
<li>Windows XP SP2, Windows Vista SP1, Windows 7 </li>
<li>A working Internet connection </li>
</ol>
<h4>Optional Requirements</h4>
<ol>
<li>A Facebook account</li>
<li>A Twitter account </li>
</ol>
<p> </p>
<p> </p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/protection-tools/immunet-protect-%e2%80%93-free-anti-virus-protection-from-the-social-cloud-windows/' rel='bookmark' title='Permanent Link: Immunet Protect – Free Anti-Virus Protection From The Social Cloud (Windows)'>Immunet Protect – Free Anti-Virus Protection From The Social Cloud (Windows)</a></li>
<li><a href='http://www.virusexperts.org/security-news/pandas-cloud-antivirus-leaves-beta-behind/' rel='bookmark' title='Permanent Link: Panda&#8217;s Cloud Antivirus leaves beta behind'>Panda&#8217;s Cloud Antivirus leaves beta behind</a></li>
<li><a href='http://www.virusexperts.org/protection-tools/kaspersky-anti-virus-internet-security-2010-v900313-beta/' rel='bookmark' title='Permanent Link: Kaspersky Anti-Virus &#038; Internet Security 2010 V9.0.0.313 Beta'>Kaspersky Anti-Virus &#038; Internet Security 2010 V9.0.0.313 Beta</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/protection-tools/new-clamav-for-windows-powered-by-immunet-and-sourcefire/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Panda Cloud Antivirus 1.0.1</title>
		<link>http://www.virusexperts.org/protection-tools/panda-cloud-antivirus-1-0-1/</link>
		<comments>http://www.virusexperts.org/protection-tools/panda-cloud-antivirus-1-0-1/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 09:29:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Protection Tools]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[cloud antivirus]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[panda]]></category>
		<category><![CDATA[pandasoftware]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2102</guid>
		<description><![CDATA[Panda released a new version of Panda Cloud Antivirus, version 1.0.1. This version is basically a cumulative-fix release which incorporates Hotfix-1, Hotfix-2 and some small additional improvements.
 
The most notable improvement is that we have gotten rid of the initial account registration which used to be mandatory for first-time installs. Panda Cloud Antivirus will not ask [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/protection-tools/free-cloud-antivirus-0-08-81-beta2-from-panda/' rel='bookmark' title='Permanent Link: Free Cloud Antivirus 0.08.81 Beta2 from Panda'>Free Cloud Antivirus 0.08.81 Beta2 from Panda</a></li>
<li><a href='http://www.virusexperts.org/protection-tools/cloud-antivirus-1-0-final-release/' rel='bookmark' title='Permanent Link: Cloud Antivirus 1.0 Final Release'>Cloud Antivirus 1.0 Final Release</a></li>
<li><a href='http://www.virusexperts.org/security-news/pandas-cloud-antivirus-leaves-beta-behind/' rel='bookmark' title='Permanent Link: Panda&#8217;s Cloud Antivirus leaves beta behind'>Panda&#8217;s Cloud Antivirus leaves beta behind</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Panda released a new version of Panda Cloud Antivirus, version 1.0.1. This version is basically a cumulative-fix release which incorporates Hotfix-1, Hotfix-2 and some small additional improvements.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">The most notable improvement is that we have gotten rid of the initial account registration which used to be mandatory for first-time installs. Panda Cloud Antivirus will not ask for account during install anymore. Only if you want to participate in the <a href="http://www.cloudantivirus.com/forum">Cloud Antivirus Support Forums</a> will you need to create an account.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>I have Cloud Antivirus 1.0 already installed. Do I need to download &amp; install this version?</strong><br /> Not really. This new version incorporates hotfixes which you probably already have installed anyway. To check if you have them installed, simply browse to “C:\Documents and Settings\All Users” (XP) and you should see a subdirectory called “HF_PCA_somenumber”.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>I have the hotfixes installed but I still have some problems with Panda Cloud Antivirus. Should I install this version?</strong><br /> Yes you might want to give it a try. Below you can find some more detail of what this version fixes which is not included in the existing hotfixes. In order to install this version on top of the one you already have, first uninstall your current version, then reboot and finally download &amp; install the new version from <a onclick="javascript:pageTracker._trackPageview('/outbound/article/acs.pandasoftware.com');" href="http://acs.pandasoftware.com/cloud/CloudAntivirus.exe">http://acs.pandasoftware.com/cloud/CloudAntivirus.exe</a>.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>What’s the changelog of this version 1.0.1?</strong></p>
<ol style="text-align: justify;">
<li>Preactivated version does not require account creation during install</li>
<li>Fix for certain conditions of stuck quick &amp; full scan</li>
<li>Improved cloud-heuristic detection for unknown malware &#8211; From HF_2</li>
<li>Improved prevalence algorithms for priorization of new malware &#8211; From HF_2</li>
<li>Fix of problems scanning certain files in system directories &#8211; From HF_1</li>
<li>Fix for loss of connectivity after malware disinfection involving LSP &#8211; From HF_1</li>
<li style="text-align: center;">Improved cloud-heuristic detection &#8211; From HF_1</li>
</ol>
<p style="text-align: center;"><img title="pca101" src="http://www.virusexperts.org/wp-content/uploads/HLIC/4de5c0d2a001ce8098a9c3d49d11f65e.png" alt="pca101" width="434" height="351" /></p>
<p style="text-align: center;"> </p>
<p style="text-align: center;"> </p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-2103" title="cloudav-w7" src="http://www.virusexperts.org/wp-content/uploads/2010/03/cloudav-w7-300x225.jpg" alt="" width="300" height="225" /></p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/protection-tools/free-cloud-antivirus-0-08-81-beta2-from-panda/' rel='bookmark' title='Permanent Link: Free Cloud Antivirus 0.08.81 Beta2 from Panda'>Free Cloud Antivirus 0.08.81 Beta2 from Panda</a></li>
<li><a href='http://www.virusexperts.org/protection-tools/cloud-antivirus-1-0-final-release/' rel='bookmark' title='Permanent Link: Cloud Antivirus 1.0 Final Release'>Cloud Antivirus 1.0 Final Release</a></li>
<li><a href='http://www.virusexperts.org/security-news/pandas-cloud-antivirus-leaves-beta-behind/' rel='bookmark' title='Permanent Link: Panda&#8217;s Cloud Antivirus leaves beta behind'>Panda&#8217;s Cloud Antivirus leaves beta behind</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/protection-tools/panda-cloud-antivirus-1-0-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Check your password — is it strong?</title>
		<link>http://www.virusexperts.org/protection-tools/check-your-password-%e2%80%94-is-it-strong/</link>
		<comments>http://www.virusexperts.org/protection-tools/check-your-password-%e2%80%94-is-it-strong/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 05:53:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Protection Tools]]></category>
		<category><![CDATA[Help]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Protect]]></category>
		<category><![CDATA[Test]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2098</guid>
		<description><![CDATA[
Your online accounts, computer files, and personal information are more secure when you use strong passwords to help protect them.
 
Test the strength of your passwords: Click Here
 
Powered by Microsoft



Related posts:Free Sophos Endpoint Assessment Free Online Test
Could Hotmail Password Theft be Due to a Trojan?
The password dilemma (Podcast)


<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/protection-tools/free-sophos-endpoint-assessment-free-online-test/' rel='bookmark' title='Permanent Link: Free Sophos Endpoint Assessment Free Online Test'>Free Sophos Endpoint Assessment Free Online Test</a></li>
<li><a href='http://www.virusexperts.org/security-news/could-hotmail-password-theft-be-due-to-a-trojan/' rel='bookmark' title='Permanent Link: Could Hotmail Password Theft be Due to a Trojan?'>Could Hotmail Password Theft be Due to a Trojan?</a></li>
<li><a href='http://www.virusexperts.org/security-channel/the-password-dilemma/' rel='bookmark' title='Permanent Link: The password dilemma (Podcast)'>The password dilemma (Podcast)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a title="password strong checker" href="https://www.microsoft.com/protect/fraud/passwords/checker.aspx" target="_blank"><img class="aligncenter size-full wp-image-2099" title="msonline_safty" src="http://www.virusexperts.org/wp-content/uploads/2010/03/msonline_safty.png" alt="" width="304" height="73" /></a></p>
<p>Your online accounts, computer files, and personal information are more secure when you use strong passwords to help protect them.</p>
<p> </p>
<p><strong>Test the strength of your passwords: <a title="password strong checker" href="https://www.microsoft.com/protect/fraud/passwords/checker.aspx" target="_blank">Click Here</a></strong></p>
<p> </p>
<p><strong>Powered by Microsoft</strong></p>
<p><strong><br /></strong></p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/protection-tools/free-sophos-endpoint-assessment-free-online-test/' rel='bookmark' title='Permanent Link: Free Sophos Endpoint Assessment Free Online Test'>Free Sophos Endpoint Assessment Free Online Test</a></li>
<li><a href='http://www.virusexperts.org/security-news/could-hotmail-password-theft-be-due-to-a-trojan/' rel='bookmark' title='Permanent Link: Could Hotmail Password Theft be Due to a Trojan?'>Could Hotmail Password Theft be Due to a Trojan?</a></li>
<li><a href='http://www.virusexperts.org/security-channel/the-password-dilemma/' rel='bookmark' title='Permanent Link: The password dilemma (Podcast)'>The password dilemma (Podcast)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/protection-tools/check-your-password-%e2%80%94-is-it-strong/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Video of Twitter phishing: The BZPharma &#8216;LOL this is funny&#8217; attack (Video)</title>
		<link>http://www.virusexperts.org/security-channel/video-of-twitter-phishing-the-bzpharma-lol-this-is-funny-attack/</link>
		<comments>http://www.virusexperts.org/security-channel/video-of-twitter-phishing-the-bzpharma-lol-this-is-funny-attack/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 06:00:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Channel]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[graham cluley]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[SophosLabs]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Spread]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[youtube]]></category>
		<category><![CDATA[youtube video]]></category>

		<guid isPermaLink="false">http://www.virusexperts.org/?p=2091</guid>
		<description><![CDATA[Twitter users are being warned about a widespread phishing attack spreading across the system, designed to steal the usernames and passwords of unsuspecting members.
 
Messages include

Lol. this is me?? lol , this is funny. Lol. this you??

followed by a link in the form of

http://example.com/?rid=http://twitter.verify.bzpharma.net/login

where &#8216;example.com&#8217; can vary. As we have seen many variations of the URL [...]

<h3>
Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-news/twitter-fights-back-against-spam-phishing-and-other-malicious-links/' rel='bookmark' title='Permanent Link: Twitter fights back against spam, phishing, and other malicious links'>Twitter fights back against spam, phishing, and other malicious links</a></li>
<li><a href='http://www.virusexperts.org/security-channel/stalkdaily-messages-bombard-twitter-users/' rel='bookmark' title='Permanent Link: StalkDaily messages bombard Twitter users (Video)'>StalkDaily messages bombard Twitter users (Video)</a></li>
<li><a href='http://www.virusexperts.org/security-channel/paypal-scam-phishing-attack-in-action-video/' rel='bookmark' title='Permanent Link: Paypal SCAM (phishing-attack) In Action (Video)'>Paypal SCAM (phishing-attack) In Action (Video)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Twitter users are being warned about a widespread phishing attack spreading across the system, designed to steal the usernames and passwords of unsuspecting members.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Messages include</p>
<blockquote style="text-align: justify;">
<p><tt>Lol. this is me??</tt><br /> <tt>lol , this is funny.</tt><br /> <tt>Lol. this you??</tt></p>
</blockquote>
<p style="text-align: justify;">followed by a link in the form of</p>
<blockquote style="text-align: justify;">
<p><tt>http://example.com/?rid=http://twitter.verify.bzpharma.net/login</tt></p>
</blockquote>
<p style="text-align: justify;">where &#8216;example.com&#8217; can vary. As we have seen many variations of the URL in its entirety, you would be wise to avoid clicking on any links which refer to bzpharma.net at the very least.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: left;">Watch this <a title="Link to Sophos YouTube video" rel="nofollow" href="http://www.youtube.com/watch?v=cDSskvrUw_g">YouTube video</a> for more details:</p>
<p style="text-align: center;">
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="560" height="340" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/cDSskvrUw_g&amp;hl=en_US&amp;fs=1&amp;rel=0" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="560" height="340" src="http://www.youtube.com/v/cDSskvrUw_g&amp;hl=en_US&amp;fs=1&amp;rel=0" allowscriptaccess="always" allowfullscreen="true"></embed></object>
</p>
<p style="text-align: justify;"><em>(Enjoy this video?  You can check out more on the <a title="Link to SophosLabs YouTube channel" rel="nofollow" href="http://www.youtube.com/sophoslabs">SophosLabs YouTube channel</a> and subscribe if you like)</em></p>
<p style="text-align: justify;"><em><br /></em></p>
<p style="text-align: justify;">Although Twitter has urged users to be vigilant about the threat being distributed via private direct messages, it&#8217;s clear that dangerous links are also being posted in public feeds. This means that you can stumble across the links even if you aren&#8217;t sent it directly, or even if you are not a signed-up user of Twitter.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">It appears what is happening is that the messages are being shared more widely because of third-party services like GroupTweet which extend the standard Twitter direct message (DM) functionality and allow private messages to be sent to multiple users *and* optionally made public.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">As a result, as you can see in the video above, we have found Twitter accounts that have warned their followers about the phishing attack, only to subsequently fall victim to it themselves!</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Regardless of how you come to click on the dangerous link, if you do enter your username and password on the fake Twitter login page your details will be phished and placed in the hands of hackers.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: center;"><img class="aligncenter" title="Twitter phishing website on bzpharma.net" src="http://www.sophos.com/blogs/gc/images/blogs/gc/2010/02/twitter-phishing-website.jpg" alt="Twitter phishing website on bzpharma.net" width="550" /></p>
<p style="text-align: justify;">The page then displays a &#8220;fail whale&#8221; screen, claiming that Twitter is over capacity, before taking you back to the real Twitter main page. As a result, compromised Twitter users may not realise that their login details have been stolen.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Interestingly, the bzpharma.net site doesn&#8217;t just appear to have been set up for Twitter phishing. It appears to also have been created for stealing the online identities of the Bebo social networking site too:</p>
<p style="text-align: justify;"> </p>
<p style="text-align: center;"><img class="aligncenter" title="Bebo phishing page on bzpharma.net" src="http://www.sophos.com/blogs/gc/images/blogs/gc/2010/02/bebo-phishing-small.jpg" alt="Bebo phishing page on bzpharma.net" /></p>
<p style="text-align: justify;">If you have been tricked by the phishing attack and accidentally handed over your username and password, change your password immediately.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">We&#8217;re going to see many more attacks against social networks in the future I&#8217;m afraid.  Last month, Sophos published its <a href="http://www.sophos.com/security-report-2010">Security Threat Report</a> revealing that there had been an <a href="http://www.sophos.com/pressoffice/news/articles/2010/02/security-report-2010.html">astonishing 70% rise</a> in the number of users reporting spam and malware attacks via social networks in the last year.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>Update:</strong> The phishing campaign appears to be bearing fruit for the hackers as they are now distributing spam selling herbal viagra from the compromised accounts. <a href="http://www.sophos.com/blogs/gc/g/2010/02/22/spam-wave-hits-twitter-bigger-sex-longer/">Learn more now</a>.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>By Graham Cluley, Sophos</strong></p>
<p style="text-align: justify;"> </p>


<br /><h3><p>Related posts:</h3><ol><li><a href='http://www.virusexperts.org/security-news/twitter-fights-back-against-spam-phishing-and-other-malicious-links/' rel='bookmark' title='Permanent Link: Twitter fights back against spam, phishing, and other malicious links'>Twitter fights back against spam, phishing, and other malicious links</a></li>
<li><a href='http://www.virusexperts.org/security-channel/stalkdaily-messages-bombard-twitter-users/' rel='bookmark' title='Permanent Link: StalkDaily messages bombard Twitter users (Video)'>StalkDaily messages bombard Twitter users (Video)</a></li>
<li><a href='http://www.virusexperts.org/security-channel/paypal-scam-phishing-attack-in-action-video/' rel='bookmark' title='Permanent Link: Paypal SCAM (phishing-attack) In Action (Video)'>Paypal SCAM (phishing-attack) In Action (Video)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.virusexperts.org/security-channel/video-of-twitter-phishing-the-bzpharma-lol-this-is-funny-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
