<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tech Buzz &#187; Virus</title>
	<atom:link href="http://dhanti.com/category/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://dhanti.com</link>
	<description>Review of Gadget, Laptop, Notebook, Netbook and Tablet</description>
	<lastBuildDate>Mon, 21 May 2012 14:55:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Avoiding Bredolab Virus on Facebook</title>
		<link>http://dhanti.com/avoiding-bredolab-virus-on-facebook/</link>
		<comments>http://dhanti.com/avoiding-bredolab-virus-on-facebook/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 08:55:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[Bredolab Virus]]></category>

		<guid isPermaLink="false">http://dhanti.com/?p=1338</guid>
		<description><![CDATA[Remember Bredolab virus that uses social engineering to target Faceebook member? Apparently the problem has continued, but with a more sophisticated way. In order not to invite suspicion from the user, is now spreading to include attachments, as before, but will appear as an email from admin Facebook. Contents in order to inform the user [...]]]></description>
			<content:encoded><![CDATA[<p>Remember Bredolab virus that uses social engineering to target Faceebook member? Apparently the problem has continued, but with a more sophisticated way.<br />
<span id="more-1338"></span><br />
In order not to invite suspicion from the user, is now spreading to include attachments, as before, but will appear as an email from admin Facebook.</p>
<p>Contents in order to inform the user to update the account with the convenience and security reasons while visiting the site.</p>
<p>If the update button is clicked the user will be delivered to the web log was falsified. Yet this is not a web log Facebook&#8217;s original, but to accommodate victims username and password.</p>
<p>This web log has a fake address different, for example http://www.facebook.com.xxxxx.eu/globaldirectory/LoginFacebook.php?ref=1584270691543478059651590405901802254672004589860384285&#038;email=xxxxxxx @ xxxx.com. Where xxxxx is a random character.</p>
<p>If a cursory note, fake web log is similar to the original web log Faceebok. But if tracked more closely so there are some notable differences.</p>
<p>At the time of filling the user name and password, it will open a new page that contains a link to download the tool update your account with the name [updatetool.exe] who actually is a virus / trojan that will infect your computer.</p>
<p>Subject email sent by the virus will usually be different as New login system, update your Facebook, Facebook Update Tools. The virus has a file size of around 105 KB with the name [updatetools.exe].</p>
<p>If the file is run it will create a master file with the name [C: WINDOWSsystem32sdra64.exe] and served injects some Windows process such as: C: WindowsSyste32services.exe, C: WindowsSystem32lsass.exe, C: WindowsSystem32svchost.exe, C: WindowsSystem32alg.exe, C: ProgramFilesinternet exploreriexplore.exe.</p>
<p>In order not easily be deleted by the virus, the file will be hidden even if the user is displaying hidden files. It also will create some files also will be hidden in order not easily be deleted. C: Windowssystem32lowsec, local.ds, user.ds, user.ds.lll.</p>
<p>To spread itself, the virus will send phishing emails to all addresses that have been obtained and containing a notification to users who have a Facebook account to update his account tehadap.</p>
<p>So please be careful when receiving email from the Admin Facebook though. If an email with the subject at the top should be removed immediately and do not follow the information contained in the email.</p>
]]></content:encoded>
			<wfw:commentRss>http://dhanti.com/avoiding-bredolab-virus-on-facebook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove W32/Smalltroj. VPCG Virus</title>
		<link>http://dhanti.com/how-to-remove-w32smalltroj-vpcg-virus/</link>
		<comments>http://dhanti.com/how-to-remove-w32smalltroj-vpcg-virus/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 13:09:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[Remove]]></category>

		<guid isPermaLink="false">http://dhanti.com/?p=1267</guid>
		<description><![CDATA[W32/Smalltroj. VPCG Virus is one of malware that popular at the end of this year. This virus will block access to several security websites and other websites that have been determined by the number switch, which is 209.85.225.99 Google ip public. So every time a user tries to access to certain websites, including website security [...]]]></description>
			<content:encoded><![CDATA[<p>W32/Smalltroj. VPCG Virus is one of malware that popular at the end of this year. This virus will block access to several security websites and other websites that have been determined by the number switch, which is 209.85.225.99 Google ip public. <span id="more-1267"></span></p>
<p>So every time a user tries to access to certain websites, including website security / antivirus, so that appears not you want the web but the website www.google.com.</p>
<p>Here are 9 steps to clean W32/Smalltroj. VPCG virus:</p>
<p>1. Turn off System Restore during the cleaning process take place.</p>
<p>2. Decide who will clean your computer from the network or the Internet.</p>
<p>3. Change the name of the file [C: \ Windws \ system32 \ msvbvm60.dll] to prevent the virus active again.</p>
<p>4. Perform cleaning by using the Tools Windows Live CD Mini PE. This is due to some rootkit files masquerading as services and drivers difficult to stop. Please download the software at the address http://soft-rapidshare.com/2009/11/10/minipe-xt-v2k50903.html</p>
<p>Then boot the computer using software Mini PE Live CD. After that deleting some files iduk virus by:</p>
<p>l Click the [Mini PE2XT]<br />
l Click the [Programs]<br />
l Click the [File Management]<br />
l Click the [Windows Explorer]<br />
l Then delete the following files:</p>
<p>o C: \ Windows \ System32<br />
§ wmispqd.exe<br />
§ Wmisrwt.exe<br />
§ qxzv85.exe @<br />
§ qxzv47.exe @<br />
§ secupdat.dat<br />
o C: \ Documents and Settings \% user% \% xx%. exe, where xx is a random character (example: rllx.exe) with a file size of 6 kb.<br />
o C: \ windows \ system32 \ drivers<br />
§ Kernelx86.sys<br />
§% xx%. Sys, where xx is a random character who has a size of 40 KB (example: mojbtjlt.sys or cvxqvksf.sys)<br />
§ Ndisvvan.sys<br />
§ krndrv32.sys<br />
o C: \ Documents and Settings \% user% \ secupdat.dat<br />
o C: \ Windows \ inf<br />
§ Netsf.inf<br />
§ netsf_m.inf</p>
<p>5. Delete the registry created by the virus, by using the &#8220;Avas! Registry Editor&#8221;, how:</p>
<p>l Click the [Mini PE2XT]<br />
l Click the [Programs]<br />
l Click the [Registry Tools]<br />
l Click [Avast! Registry Editor]<br />
l If the confirmation screen appears Kelik button &#8220;Load &#8230;..&#8221;<br />
l Kemudain delete registry: (see figure 6)</p>
<p>Ø HKEY_LOCAL_MACHINE \ software \ microsoft \ windows \ currentvers<br />
on \ Run \ \ ctfmon.exe<br />
Ø HKEY_LOCAL_MACHINE \ system \ ControlSet001 \ Services \ kernelx86<br />
Ø HKEY_LOCAL_MACHINE \ system \ CurrentControlSet \ Services \ kernelx86<br />
Ø HKEY_LOCAL_MACHINE \ system \ CurrentControlSet \ Services \ passthru<br />
Ø HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ WindowsNT \ CurrentVersion \ Image File Execution Options \ ctfmon.exe<br />
Ø HKEY_LOCAL_MACHINE \ software \ microsoft \ Windows NT \ CurrentVersion \ winlogon</p>
<p>ü Change the string value to be Userinit = userinit.exe,<br />
Ø HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ SharedAccess \ Parameters \ FirewallPolicy \ DomainProfile \ AuthorizedApplications \ List<br />
ü% windir% \ system32 \ wmispqd.exe =% system% \ wmispqd.exe: *: enabled: UPnP Firewall<br />
Ø HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ SharedAccess \ Parameters \ FirewallPolicy \ DomainProfile \ AuthorizedApplications \ List<br />
ü% windir% \ system32 \ wmispqd.exe =% system% \ wmispqd.exe: *: enabled: UPnP Firewall<br />
Ø HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ SharedAccess \ Parameters \ FirewallPolicy \ StandardProfile \ AuthorizedApplications \ List<br />
ü% windir% \ system32 \ wmispqd.exe =% system% \ wmispqd.exe: *: enabled: UPnP Firewall<br />
Ø HKEY_LOCAL_MACHINE \ system \ ControlSet001 \ Services \% xx%<br />
Ø HKEY_LOCAL_MACHINE \ system \ CurrentControlSet \ Services \% xx%</p>
<p>Note:<br />
% xx% showing random characters, this key is made to run the file. SYS which has the size of 40 KB which is in the directory [C: \ Windows \ system32 \ drivers \]</p>
<p>6. Restart the computer, restore the remaining registry that changed by the virus to copy the following script in notepad and then save with the name repair.inf. Execute the following manner: right-click repair.inf | click install</p>
<p>[Version]</p>
<p>Signature = &#8220;$ Chicago $&#8221;<br />
Provider = Vaksincom</p>
<p>[DefaultInstall]<br />
AddReg = UnhookRegKey<br />
DelReg = del</p>
<p>[UnhookRegKey]</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ batfile \ shell \ open \ command ,,,&#8221;"&#8221;% 1 &#8220;&#8221;% * &#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ comfile \ shell \ open \ command ,,,&#8221;"&#8221;% 1 &#8220;&#8221;% * &#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ exefile \ shell \ open \ command ,,,&#8221;"&#8221;% 1 &#8220;&#8221;% * &#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ piffile \ shell \ open \ command ,,,&#8221;"&#8221;% 1 &#8220;&#8221;% * &#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ regfile \ shell \ open \ command,,, &#8220;regedit.exe&#8221;% 1 &#8220;&#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ scrfile \ shell \ open \ command ,,,&#8221;"&#8221;% 1 &#8220;&#8221;% * &#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon, Shell, 0, &#8220;Explorer.exe&#8221;</p>
<p>HKEY_LOCAL_MACHINE \ software \ microsoft \ ole, EnableDCOM, 0, &#8220;Y&#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center, AntiVirusDisableNotify, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center, FirewallDisableNotify, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center, AntiVirusOverride, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center, FirewallOverride, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ LSA, restrictanonymous, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet002 \ Control \ LSA, restrictanonymous, 0&#215;00010001, 0</p>
<p>HKLM, SYSTEM \ CurrentControlSet \ Control \ LSA, restrictanonymous, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ SuperHidden, CheckedValue, 0&#215;00010001, 0</p>
<p>[del]</p>
<p>HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System, DisableRegistryTools</p>
<p>HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System, DisableCMD</p>
<p>HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer, NoFolderOptions</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run, ctfmon.exe</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ kernelx86</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet002 \ Services \ kernelx86</p>
<p>HKLM, SYSTEM \ CurrentControlSet \ Services \ kernelx86</p>
<p>HKLM, SYSTEM \ CurrentControlSet \ Services \ mojbtjlt</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ mojbtjlt</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet002 \ Services \ mojbtjlt</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ Passthru</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows NT \ SystemRestore</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows \ windowsupdate, DoNotAllowXPSP2</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows \ windowsupdate</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Image File Execution Options \ ctfmon.exe</p>
<p>7. Delete temporary files and temporary Internet files. Please use the tools ATF-Cleaner. Download these tools in http://www.atribune.org/public-beta/ATF-Cleaner.exe address.</p>
<p>8. Restore back to the host file in Windows that has been changed by the virus. You can use tools Hoster, please download at the following address http://www.softpedia.com/progDownload/Hoster-Download-27041.html</p>
<p>Click the [Restore MS Hosts File], to restore the Windows hosts file.</p>
<p>9. For optimal cleaning and prevent re-infection, anti-virus scan with up-to-date and was able to detect this virus. You can also use Norman Malware Cleaner, please download at the following address http://www.norman.com/support/support_tools/58732/en.</p>
]]></content:encoded>
			<wfw:commentRss>http://dhanti.com/how-to-remove-w32smalltroj-vpcg-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yahoo Messenger Virus Cleanup</title>
		<link>http://dhanti.com/yahoo-messenger-virus-cleanup/</link>
		<comments>http://dhanti.com/yahoo-messenger-virus-cleanup/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 13:03:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[Cleanup]]></category>
		<category><![CDATA[Remove]]></category>

		<guid isPermaLink="false">http://dhanti.com/?p=1265</guid>
		<description><![CDATA[Yahoo Messenger virus can update your antivirus like by downloading some files from websites that have been determined. No doubt, to remove him was somewhat difficult. Follow this steps for cleanup: 1. Decide who will clean your computer from the network or internet 2. Change the name of the file [C: \ Windws \ system32 [...]]]></description>
			<content:encoded><![CDATA[<p>Yahoo Messenger virus can update your antivirus like by downloading some files from websites that have been determined. No doubt, to remove him was somewhat difficult.<span id="more-1265"></span></p>
<p>Follow this steps for cleanup:<br />
1. Decide who will clean your computer from the network or internet</p>
<p>2. Change the name of the file [C: \ Windws \ system32 \ msvbvm60.dll] to [xmsvbvm60.dll] to prevent the virus reactivation during the cleaning process.</p>
<p>3. Should do the cleaning by using the Tools Windows Live CD Mini PE this is due to some master files and file rootkits masquerading as services and drivers difficult to delete these files will be hidden by the virus.</p>
<p>Then boot the computer using software Mini PE Live CD. After that deleting some files iduk virus by:</p>
<p>a. Click the [Mini PE2XT]<br />
b. Click the [Programs]<br />
c. Click the [File Management]<br />
d. Click the [Windows Explorer]<br />
e. Then delete the following files:<br />
-. C: \ Windows \ System32<br />
-. WMI% xxx.exe, where xxx indicate karater random (example: wmispqd.exe, wmisrwt.exe, wmistpl.exe, atu wmisfpj.exe) with file sizes vary depending on the variant that infects the target computer.<br />
-. % xxx%. exe @, where the% xxx% showing random characters (example: qxzv85.exe @) with sizes varying depending on the variant that infects.<br />
-. secupdat.dat<br />
-. C: \ Documents and Settings \% user% \% xx%. Exe, where xx is a random character (example: rllx.exe) with a file size of about 6 kb or 16 kb (depending on the variant that infects).<br />
-. C: \ Windows \ System32 \ drivers<br />
-. Kernelx86.sys<br />
-. % xx%. sys, where xx is a random character who has a size of about 40 KB (example: mojbtjlt.sys or cvxqvksf.sys)<br />
-. Ndisvvan.sys<br />
-. krndrv32.sys<br />
-. C: \ Documents and Settings \% user% \ secupdat.dat<br />
-. C: \ Windows \ INF<br />
-. netsf.inf<br />
-. netsf_m.inf</p>
<p>4. Remove dubah registry created by the virus, by using the &#8220;Avas! Registry Editor&#8221;, how:</p>
<p>a. Click the [Mini PE2XT]<br />
b. Click the [Programs]<br />
c. Click the [Registry Tools]<br />
d. Click [Avast! Registry Editor]<br />
e. If the confirmation screen appears Kelik button &#8220;Load &#8230;..&#8221;<br />
f. Kemudain delete the registry:</p>
<p>LOCAL_MACHINE_SOFTWARE ü \ microsoft \ windows \ currentverson \ Run \ \ ctfmon.exe<br />
LOCAL_MACHINE_SYSTEM ü \ ControlSet001 \ Services \ \ kernelx86<br />
LOCAL_MACHINE_SYSTEM ü \ CurrentControlSet \ Services \ \ kernelx86<br />
LOCAL_MACHINE_SYSTEM ü \ CurrentControlSet \ Services \ \ passthru<br />
LOCAL_MACHINE_SOFTWARE ü \ Microsoft \ Windows NT \ CurrentVersion \ Image File Execution Options \ ctfmon.exe<br />
LOCAL_MACHINE_SOFTWARE ü \ microsoft \ Windows NT \ CurrentVersion \ winlogon<br />
§ Change the string value to be Userinit = userinit.exe,<br />
LOCAL_MACHINE_SOFTWARE ü \ microsoft \ Windows NT \ CurrentVersion \ winlogon<br />
§ Change the string value Shell = Explorer.exe becomes<br />
LOCAL_MACHINE_SYSTEM ü \ ControlSet001 \ Services \ \% xx%<br />
LOCAL_MACHINE_SYSTEM ü \ CurrentControlSet \ Services \ \% xx%<br />
LOCAL_MACHINE_SYSTEM ü \ ControlSet002 \ Services \ SharedAccess \ Parameters \ FirewallPolicy \ DomainProfile \ AuthorizedApplications \ List \ \ C: \ windows \ system32 \% file_induk_virus%. exe (example: wmistpl.exe)<br />
LOCAL_MACHINE_SYSTEM ü \ ControlSet002 \ Services \ SharedAccess \ Parameters \ FirewallPolicy \ StandardProfile \ AuthorizedApplications \ List \ \ C: \ windows \ system32 \% file_induk_virus%. exe (example: wmistpl.exe)</p>
<p>Note:% xx% showing random characters, this key is made to run the file. SYS which has the size of 40 KB which is in the directory [C: \ Windows \ system32 \ drivers \]</p>
<p>5. Restart the computer, restore the remaining registry that changed by the virus to copy the following script in notepad and then save with the name repair.inf. Execute the following manner: right-click repair.inf | click install</p>
<p>[Version]</p>
<p>Signature = &#8220;$ Chicago $&#8221;</p>
<p>Provider = Vaksincom Oyee</p>
<p>[DefaultInstall]</p>
<p>AddReg = UnhookRegKey</p>
<p>DelReg = del</p>
<p>[UnhookRegKey]</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ batfile \ shell \ open \ command ,,,&#8221;"&#8221;% 1 &#8220;&#8221;% * &#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ comfile \ shell \ open \ command ,,,&#8221;"&#8221;% 1 &#8220;&#8221;% * &#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ exefile \ shell \ open \ command ,,,&#8221;"&#8221;% 1 &#8220;&#8221;% * &#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ piffile \ shell \ open \ command ,,,&#8221;"&#8221;% 1 &#8220;&#8221;% * &#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ regfile \ shell \ open \ command,,, &#8220;regedit.exe&#8221;% 1 &#8220;&#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ scrfile \ shell \ open \ command ,,,&#8221;"&#8221;% 1 &#8220;&#8221;% * &#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon, Shell, 0, &#8220;Explorer.exe&#8221;</p>
<p>HKEY_LOCAL_MACHINE \ software \ microsoft \ ole, EnableDCOM, 0, &#8220;Y&#8221;</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center, AntiVirusDisableNotify, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center, FirewallDisableNotify, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center, AntiVirusOverride, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center, FirewallOverride, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ LSA, restrictanonymous, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet002 \ Control \ LSA, restrictanonymous, 0&#215;00010001, 0</p>
<p>HKLM, SYSTEM \ CurrentControlSet \ Control \ LSA, restrictanonymous, 0&#215;00010001, 0</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ SuperHidden, CheckedValue, 0&#215;00010001, 0</p>
<p>SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ SuperHidden, DefaultValue, 0&#215;00010001, 0</p>
<p>SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ SuperHidden, UncheckedValue, 0&#215;00010001, 1</p>
<p>[del]</p>
<p>HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System, DisableRegistryTools</p>
<p>HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System, DisableCMD</p>
<p>HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer, NoFolderOptions</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run, ctfmon.exe</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ kernelx86</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet002 \ Services \ kernelx86</p>
<p>HKLM, SYSTEM \ CurrentControlSet \ Services \ kernelx86</p>
<p>HKLM, SYSTEM \ CurrentControlSet \ Services \ mojbtjlt</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ mojbtjlt</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet002 \ Services \ mojbtjlt</p>
<p>HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ Passthru</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows NT \ SystemRestore</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows \ windowsupdate, DoNotAllowXPSP2</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows \ windowsupdate</p>
<p>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Image File Execution Options \ ctfmon.exe</p>
<p>6. Windows registry fix to restore the computer to boot to &#8220;safe mode with command prompt&#8221; to download the file FixSafeBoot.reg (Windows XP) at the following address and then run the file the following manner:</p>
<p>o Click the [Start]<br />
o Click [Run]<br />
o Type Regedit.exe and click the [OK]<br />
o On the &#8220;Registry Editor&#8221;, click the menu [File | Import]<br />
o Determine the file. REG you created new<br />
o Click the [Open]</p>
<p>7. Delete temporary files and temporary Internet files. Please use the tools ATF-Cleaner. Download these tools <a href="http://www.atribune.org/public-beta/ATF-Cleaner.exe" target="_blank">here</a>.</p>
<p>8. Restore back to the host file in Windows that has been changed by the virus. You can use tools Hoster, please download at the <a href="http://www.softpedia.com/progDownload/Hoster-Download-27041.html." target="_blank">following address</a>.</p>
<p>Click the [Restore MS Hosts File], to restore the Windows hosts file.</p>
<p>9. For optimal cleaning and prevent re-infection, anti-virus scan with up-to-date and was able to detect this virus.</p>
]]></content:encoded>
			<wfw:commentRss>http://dhanti.com/yahoo-messenger-virus-cleanup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Clean Virus VBS/Cryf.A</title>
		<link>http://dhanti.com/how-to-clean-virus-vbscryfa/</link>
		<comments>http://dhanti.com/how-to-clean-virus-vbscryfa/#comments</comments>
		<pubDate>Sat, 25 Jul 2009 01:46:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://dhanti.com/?p=752</guid>
		<description><![CDATA[How to clean virus vbs / Cryf.A: 1. Turn off the process that have a product name &#8220;Microsoft (r) Windows Script Host&#8221; with the way the process of select products that have a name &#8220;Microsoft (r) Windows Script Host&#8221;, right click on the processes already in the block, select [Kill Processes Selected] 2. Block viruses [...]]]></description>
			<content:encoded><![CDATA[<p>How to clean virus vbs / Cryf.A:<br />
1. Turn off the process that have a product name &#8220;Microsoft (r) Windows Script Host&#8221; with the way the process of select products that have a name &#8220;Microsoft (r) Windows Script Host&#8221;, right click on the processes already in the block, select [Kill Processes Selected]<span id="more-752"></span><br />
2. Block viruses use &#8220;Software Restriction Policies&#8221; (for Windows XP/2003/Vista/2008) with the type in the dialog box [Run] -&gt; SECPOL.MSC-&gt; Enter. Then the screen [Local Security Policy], select [Software Restriction policies], right click and select Create new policies], right-click [Additional Rule] -&gt; [New Hash Rule].<br />
3. The columns in the [File Hash], click [Browse] and select the file that will be blocked.<br />
Fix Registry to run the file [FixRegistry.exe], download the 4shared.com/file/117095567/3ea8e8ce/_4__FixRegistry. Html<br />
4. Delete files with the parent virus using a tool such as &#8220;Explorer XP (explorerxp.com / explorerxpsetup.exe)<br />
Delete the following files:<br />
•% drive%: \ Recycled \ S-1-5-21-343818398-18970151121-842a92511246-500 \ Thumbs.db<br />
svchost.vbs<br />
desktop.ini<br />
drvco nfg.drv<br />
SHELL32.dll<br />
•% drive%: \ Album Bokep \ Naughty America<br />
• C: \ windows<br />
appsys.exe<br />
Winupdt.scx<br />
appopen.scx<br />
Windowsopen.mht<br />
Windows.html<br />
R egedit.exe.lnk<br />
Help.htm<br />
• &amp; n bsp; C: \ Windows \ system \ svchost.exe<br />
• C: \ WINDOWS \ system32<br />
Taskmgr.exe.lnk<br />
CMD.exe.lnk<br />
S vchost.dls<br />
Corelsetup.scx<br />
Appsys.dls<br />
Kernel32.dls<br />
Winupdtsys.exe<br />
ssmarque.scr<br />
&amp; Bull; C: \ Program Files \ FarStone \ qbtask.exe<br />
• C: \ Program Files \ ACDsee \ Launcher.exe<br />
• C: \ Program Files \ Common Files \ NeroChkup.exe<br />
• C: \ Program Files \ ExeLauncher<br />
•% ProgramFiles% \ drivers \ VGA \ VGAdrv.lnk<br />
• C: \ Documents and Settings \% username% \ Desktop \ Local Disk (C). Dls<br />
• Flash Disk%: \&gt; Dataku Important Do not delete.lnk</p>
<p>5. Show file [TaskMgr.exe/Regedt32.exe/Regedit.exe/CMD.exe/Logoff.ex e] is hidden by the virus, I typed in the dialog box [Run] -&gt; type CMD-&gt; Enter. Then, type attrib-s-h-r-regedit.exe&gt; Enter. With the same command can be used to display the file Taskmgr.exe, cmd.exe and Logoff.exe<br />
6. For optimal cleaning and prevent infection, please re-install and scan with the antivirus is up-to-date. If you have clean, clear and delete rule block file [WSCript.exe] which was created in step no. (2), with the type SECPOL.MSC in the box [Run] from the [Start], then press Enter. On the screen [Local Security Policy], click 2x [Software Restriction policies] -&gt; Additional Rule] -&gt; delete the rule that has been made.<br />
<!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://dhanti.com/how-to-clean-virus-vbscryfa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Clean W32/Sality.AE</title>
		<link>http://dhanti.com/how-to-clean-w32salityae/</link>
		<comments>http://dhanti.com/how-to-clean-w32salityae/#comments</comments>
		<pubDate>Sat, 23 May 2009 05:36:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://dhanti.com/?p=506</guid>
		<description><![CDATA[This steps for clean W32/Sality.AE; 1. Disconnect the computer that will be cleared from the network and internet 2. Turn off System Restore during the cleaning process takes place. 3. Turn off the Autorun and Default Share. Please download the file and run the following ways: Right-click repair.inf Click install http://www.4shared.com/file/82762498/f5dc1edd/repair.html?dirPwdVerified=feea1d94 4. Turn off the [...]]]></description>
			<content:encoded><![CDATA[<p>This steps for clean W32/Sality.AE;<br />
1. Disconnect the computer that will be cleared from the network and internet<br />
2. Turn off System Restore during the cleaning process takes place.<br />
3. Turn off the Autorun and Default Share. Please download the file and run the following ways:<span id="more-506"></span></p>
<ul>
<li>Right-click repair.inf</li>
</ul>
<ul>
<li>Click install</li>
</ul>
<ul>
<li>http://www.4shared.com/file/82762498/f5dc1edd/repair.html?dirPwdVerified=feea1d94</li>
</ul>
<p>4. Turn off the active application program in memory so that the cleaning process faster, especially programs that are in the startup list.<br />
5. We suggest using the removal scan tools with the first extension of the removal tools with an extension other [for example: CMD] in order not to re-infection by W32/Sality.AE. In the example below, the file name &#8220;Norman_Malware_Cleaner.exe&#8221; in the rename to &#8220;Norman_Malware_Cleaner.cmd&#8221; so that the infection does not Sality. (see figure 4).</p>
<p style="text-align: left;"><img class="aligncenter size-full wp-image-507" title="img4" src="http://dhanti.com/wp-content/uploads/2009/05/img4.jpg" alt="img4" width="379" height="67" />File &#8220;Norman_Malware_Cleaner.exe&#8221; which has been rename the extension to &#8220;Norman_Malware_Cleaner.cmd,&#8221; blue box</p>
<p>Always use the latest Norman Malware Cleaner to clean and eradicate new viruses. Download Norman Malware Cleaner from the latest &#8221;</p>
<p><a href="http://download.norman.no/public/Norman_Malware_Cleaner.exe">http://download.norman.no/public/Norman_Malware_Cleaner.exe</a></p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-508" title="sality_html_" src="http://dhanti.com/wp-content/uploads/2009/05/sality_html_.jpg" alt="sality_html_" width="304" height="226" /></p>
<p>Note:</p>
<p>So that removal is not infected by W32/Sality.AE, should change the extension of the removal tools will be another extension [eg: CMD] (see image above)</p>
<p>Sality.AE  try infected to have the file extension EXE and SCR, and COM, the files that have been repeatedly in the infection by this virus will sometimes damaged if cleaned by antivirus programs, so if there is a program error after the scan by should re-install the antivirus program.</p>
<p>6. So that the computer that is infected W32/Sality.AE can booting &#8220;safe mode&#8221;, please restore the registry has been changed by the virus.</p>
<p>Please download the following files and then run on the OS that is infected W32/Sality.AE.</p>
<p>http://www.4shared.com/file/82761423/934fb170/_2__Sality.htmldirPwdVerified=feea1d94</p>
<p>7. Fix registry change on the other by a virus, please download the following tools and run the file in the following manner:</p>
<p>Right-click repair.inf</p>
<p>Click install</p>
<p>http://www.4shared.com/file/82874724/f485f1dd/repair.html?dirPwdVerified=3b1f2fa9</p>
<p>8. Restart the computer and re-scan using the removal tools to ensure your computer has been clean from viruses.</p>
<p>9. For optimal cleaning and prevent re-infection should install and scan with the antivirus that can detect Sality well.<br />
<!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://dhanti.com/how-to-clean-w32salityae/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disable Autorun on Microsoft Windows 7</title>
		<link>http://dhanti.com/disable-autorun-on-microsoft-windows-7/</link>
		<comments>http://dhanti.com/disable-autorun-on-microsoft-windows-7/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 02:59:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Operating System]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://dhanti.com/?p=268</guid>
		<description><![CDATA[What is the relationship Conficker with Windows 7? Worm Conficker or Kido or Downadup can spread to the computer via a removable storage device such as USB drives or flash. Meanwhile, Microsoft, Tuesday (28 / 4) and said that his side will change the way of a USB flash drive or system Windows 7 at [...]]]></description>
			<content:encoded><![CDATA[<p>What is the relationship Conficker with Windows 7? Worm Conficker or Kido or Downadup can spread to the computer via a removable storage device such as USB drives or flash. Meanwhile, Microsoft, Tuesday (28 / 4) and said that his side will change the way of a USB flash drive or system Windows 7 at the latest, version of Release Candidate (RC).<span id="more-268"></span></p>
<p>As a result of the changes, Microsoft makes most of flash can not appear automatically display the program using the Windows feature called as Autorun. In a blog posting Microsoft (blogs.technet.com), Microsoft explained that if the infected flash inserted in the machine based on Windows 7, the task Autorun will not be displayed.</p>
<p>While in the other removable media, such as CDs and DVDs can still use the Autorun feature. In addition, several flash &#8216;smart&#8217; software that has also u3 can still shown as DVD drive, and use the Autorun feature. Changes made to Microsoft this will be shown in the features of Windows 7 RC that plan will be published in the upcoming month of May. Microsoft also plans to make changes in Windows Vista and Windows XP. Autorun functionality in Windows is never be wrong over the spread of malware that comes from the flashdisk.</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://dhanti.com/disable-autorun-on-microsoft-windows-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Eliminate Coutsonif.A Virus on Yahoo Messenger and Skype</title>
		<link>http://dhanti.com/eliminate-coutsonifa-virus-on-yahoo-messenger-and-skype/</link>
		<comments>http://dhanti.com/eliminate-coutsonifa-virus-on-yahoo-messenger-and-skype/#comments</comments>
		<pubDate>Tue, 28 Apr 2009 02:21:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://dhanti.com/?p=256</guid>
		<description><![CDATA[Attack Coutsonif.A virus threatens Yahoo Messenger and Skype should warning. This virus spreads by sending itself to all contacts in the address of the application from the infected computer. Message at a glance like a message in general. But do not click the link to a given, though sent by your friend. The message was [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://dhanti.com/wp-content/uploads/2009/04/coutsonif1.jpg" alt="coutsonif1" title="coutsonif1" width="285" height="201" class="aligncenter size-full wp-image-257" /><br />
Attack Coutsonif.A virus threatens Yahoo Messenger and Skype should warning. This virus spreads by sending itself to all contacts in the address of the application from the infected computer.<span id="more-256"></span></p>
<p>Message at a glance like a message in general. But do not click the link to a given, though sent by your friend. The message was not sent by your colleagues, but by viruses that have infected your computer colleagues.</p>
<p>Well, if already infected, then it will automatically create a random file name with the extension. Tmp and. Exe that will be stored in the directory [C: \ Documents and Settings \% username% \ Local Settings \ Temp] with the name of the different .</p>
<p><strong>Steps to eliminate Coutsonif.A Virus:</strong></p>
<p>1. Disable &#8216;System Restore&#8217; during the cleaning process.<br />
2. Disable Windows autorun, so the virus can not be activated automatically when the access to the drive / flash disk.<br />
Click the button &#8216;start&#8217;<br />
Click &#8216;run&#8217;<br />
Type &#8216;GPEDIT.MSC&#8217;, without quotes. Then the screen will display &#8216;Group Policy&#8217;<br />
On the &#8216;Computer Configuration and User Configuration,&#8217; click &#8216;Administrative templates&#8217;<br />
Click &#8216;System&#8217;<br />
Right click on &#8216;Turn On Autoplay&#8217;, select &#8216;Properties&#8217;. Then the screen will appear &#8216;on Tun Autoplay propeties&#8217;<br />
Tabulation on &#8216;Settings&#8217;, select&#8217; Enabled &#8216;<br />
On the &#8216;Tun off Autoplay on&#8217; select &#8216;All drives&#8217;<br />
Click &#8216;Ok&#8217;</p>
<p>3. Turn off the virus, use the tools&#8217; security task manager &#8216;and delete the file [sysmgr.exe, vshost.exe, winservices.exe, *. tmp]</p>
<p>Just a note,. Tmp files that have indicated the extension TMP [example: 5755.tmp]. Right-click on the file and select &#8216;Remove&#8217;, select the option &#8216;Move files to Quarantine.</p>
<p>4. Repair registry that has been modified by the virus. To speed up the process of elimination, please copy the script below on the notepad program and save it with the name repair.inf. Run the file in the following manner: repair.inf Right-click, and select install.</p>
<p>[Version]<br />
Signature=&#8221;$Chicago$&#8221;<br />
Provider=Vaksincom Oyee</p>
<p>[DefaultInstall]<br />
AddReg=UnhookRegKey<br />
DelReg=del</p>
<p>[UnhookRegKey]</p>
<p>HKLM, Software\CLASSES\batfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\comfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\exefile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\piffile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\regfile\shell\open\command,,,&#8221;regedit.exe &#8220;%1&#8243;&#8221;<br />
HKLM, Software\CLASSES\scrfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, &#8220;Explorer.exe&#8221;<br />
HKCU, SessionInformation, ProgramCount, 0&#215;00010001,3<br />
HKCU, AppEvents\Schemes\Apps\Explorer\BlockedPopup\.current,,,&#8221;C:\WINDOWS\media\Windows XP Pop-up Blocked.wav&#8221;<br />
HKCU, AppEvents\Schemes\Apps\Explorer\EmptyRecycleBin\.Current,,,&#8221;C:\Windows\media\Windows XP Recycle.wav&#8221;<br />
HKCU, AppEvents\Schemes\Apps\Explorer\Navigating\.Current,,,&#8221;C:\Windows\media\Windows XP Start.wav&#8221;<br />
HKCU, AppEvents\Schemes\Apps\Explorer\SecurityBand\.current,,,&#8221;C:\WINDOWS\media\Windows XP Information Bar.wav&#8221;</p>
<p>[del]</p>
<p>HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Microsoft(R) System Manager<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, bMaxUserPortWindows Service help<br />
HKLM, SYSTEM\CurrentControlSet\Services\Tcpip\Parameters, MaxUserPort</p>
<p>5. Remove virus file below:</p>
<p>C:\vshost.exe [all drive]</p>
<p>C:\autorun.inf [all drive]</p>
<p>C:\RECYCLER\S-1-5-21-9949614401-9544371273-983011715-7040\winservices.exe</p>
<p>C:\Documents and Settings\%user%\Local Settings\Temp</p>
<p>A415.tmp [acak]</p>
<p>034.exe [acak]</p>
<p>Lady_Eats_Her_Shit&#8211;www.youtube.com</p>
<p>C:\WINDOWS\system32\sysmgr.exe</p>
<p>C:\WINDOWS\TEMP\5755.tmp</p>
<p>C:\windows\system32\crypts.dll</p>
<p>C:\windows\system32\msvcrt2.dll</p>
<p>6. For optimal cleaning and prevent reinfection, please use the antivirus can detect and eradicate this virus up to date. You can also download tools in Norman Malware Cleaner http://download.norman.no/public/Norman_Malware_Cleaner.exe</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://dhanti.com/eliminate-coutsonifa-virus-on-yahoo-messenger-and-skype/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How Computer Viruses Work by Type</title>
		<link>http://dhanti.com/how-computer-viruses-work-by-type/</link>
		<comments>http://dhanti.com/how-computer-viruses-work-by-type/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 03:24:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://dhanti.com/?p=165</guid>
		<description><![CDATA[Virus is a computer program that has the ability to destroy files or damage the computer system. The virus has various types of work and have a different, Following types of viruses and how to work each virus: 1. Files Virus This virus has a job that is infection applications or documents that are in [...]]]></description>
			<content:encoded><![CDATA[<p>Virus is a computer program that has the ability to destroy files or damage the computer system. The virus has various types of work and have a different, Following types of viruses and how to work each virus:<span id="more-165"></span></p>
<p>1. Files Virus<br />
This virus has a job that is infection applications or documents that are in your computer.<br />
When an infected application is executed, the virus will spread this way infected all files or documents that are accessed by the application.</p>
<p>2. Boot Sector Virus<br />
I have this virus that is working hard infected boot sector (boot sector is a region in the first hard drive is accessed when the computer is turned on).<br />
If the boot sector virus is active, users will not be able booting computer normally.</p>
<p>3. E-mail Virus<br />
This virus has a job that is spread through e-mail (usually in the form of file attachments / attachment).<br />
The virus has a characteristic form of a special extension. Scr,. Exe,. Pif, or. Bat.<br />
When the virus is active, then he will submit himself to the various e-mail address listed in the user&#8217;s address book.</p>
<p>4. Multipartite Virus<br />
This virus has a job that is infectedcomputer files at once on the hard disk boot sector.<br />
This type of virus will cause many problems because of the damage caused fatal.</p>
<p>5. Virus Polimorfis<br />
This virus has a unique way of working that this virus can change the code itself (change shape) when spread itself to other computers<br />
Virus type more difficult to detect because it has such a nature ..</p>
<p>6. Virus invisible (stealth virus)<br />
This virus has a job that he is able to Hide itself with how to create a file that seems infected file is not infected.</p>
<p>7. Macro virus<br />
This virus has a job that is infected Microsoft Office applications, such as Word and Excel.<br />
Documents are usually infected by a macro virus will modify the existing command in Microsoft Office such as the &#8220;Save&#8221; to spread itself when the command is executed.</p>
]]></content:encoded>
			<wfw:commentRss>http://dhanti.com/how-computer-viruses-work-by-type/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Variant Conflicker WORM_DOWNAD.E, Spread Detected Via P2P</title>
		<link>http://dhanti.com/variant-conflicker-worm_downade-spread-detected-via-p2p/</link>
		<comments>http://dhanti.com/variant-conflicker-worm_downade-spread-detected-via-p2p/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 02:18:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://dhanti.com/?p=62</guid>
		<description><![CDATA[Conflicker of new variants detected by TrendMicro, Attack P2P network. Variant Conflicker is named WORM_DOWNAD.E. Virus increase the traffic to be P2P from Korea. WORM_DOWNAD.E how to make working with the file name and search at random on the service computer service that connects to the Internet. WORM_DOWNAD.E trying to penetrate a service that portend [...]]]></description>
			<content:encoded><![CDATA[<p>Conflicker of new variants detected by TrendMicro, Attack P2P network. Variant Conflicker is named WORM_DOWNAD.E. Virus increase the traffic to be P2P from Korea. WORM_DOWNAD.E how to make working with the file name and search at random on the service computer service that connects to the Internet.<span id="more-62"></span> WORM_DOWNAD.E trying to penetrate a service that portend myspace.com, msn.com, ebay.com, cnn.com and aol.com</p>
<p>For security for the computer user, you should always protect computer and update the latest patch. Because the spread of the virus type of Worm is very fast, not even difficult to be detected.</p>
<p><!--adsense--></p>
]]></content:encoded>
			<wfw:commentRss>http://dhanti.com/variant-conflicker-worm_downade-spread-detected-via-p2p/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

