<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6869405707813268101</id><updated>2011-07-08T05:55:08.673-07:00</updated><title type='text'>Virus Alerts</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>25</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-8975482412135892036</id><published>2009-10-26T05:28:00.000-07:00</published><updated>2009-10-26T05:35:21.073-07:00</updated><title type='text'>Microsoft update email</title><content type='html'>Just came into one of my customers email although it looks real and like Microsoft sent it they did not. Do not click on the link or download the file.&lt;br /&gt;&lt;div class="Section1"&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt"&gt;&lt;br /&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family:'Tahoma','sans-serif';"&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:'Tahoma','sans-serif';"&gt; Microsoft Update Center [mailto:noreply@microsoft.com]&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Sent:&lt;/b&gt; Sunday, October 25, 2009 10:30 AM&lt;br /&gt;&lt;br /&gt;&lt;b&gt;To:&lt;/b&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:'Tahoma','sans-serif';"&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; Update for Microsoft Outlook&lt;/span&gt; &lt;table style="WIDTH: 100%" class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" width="100%"&gt;&lt;br /&gt;&lt;tbody&gt;&lt;tr style="HEIGHT: 16.5pt"&gt;&lt;br /&gt;&lt;td style="PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; WIDTH: 100%; PADDING-RIGHT: 0in; HEIGHT: 16.5pt; PADDING-TOP: 0in" width="100%"&gt;&lt;br /&gt;&lt;table style="WIDTH: 100%" class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" width="100%"&gt;&lt;br /&gt;&lt;tbody&gt;&lt;tr&gt;&lt;br /&gt;&lt;td style="PADDING-BOTTOM: 0in; PADDING-LEFT: 5.25pt; PADDING-RIGHT: 0in; BACKGROUND: #4b92d9; PADDING-TOP: 0in"&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;span style="color:white;"&gt;Critical Update&lt;/span&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;br /&gt;&lt;/td&gt;&lt;br /&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/td&gt;&lt;br /&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table style="WIDTH: 100%" class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" width="100%"&gt;&lt;br /&gt;&lt;tbody&gt;&lt;tr&gt;&lt;br /&gt;&lt;td style="PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; WIDTH: 100%; PADDING-RIGHT: 0in; PADDING-TOP: 0in" valign="top" width="100%"&gt;&lt;br /&gt;&lt;div style="MARGIN: 15pt 15pt 37.5pt"&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;h1&gt;&lt;span style="FONT-WEIGHT: normal"&gt;&lt;span style="font-size:100%;"&gt;Update for Microsoft Outlook / Outlook Express (KB910721)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h1&gt;&lt;br /&gt;&lt;h5 style="MARGIN-BOTTOM: 3.75pt"&gt;&lt;span style="font-size:100%;"&gt;Brief&lt;br /&gt;Description&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h5&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;Microsoft has released an&lt;br /&gt;update for Microsoft Outlook / Outlook Express. This update is critical and&lt;br /&gt;provides you with the latest version of the Microsoft Outlook / Outlook&lt;br /&gt;Express and offers the highest level of security and stability.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;h4 style="MARGIN-BOTTOM: 0.05in"&gt;Instructions&lt;o:p&gt;&lt;/o:p&gt;&lt;/h4&gt;&lt;br /&gt;&lt;div style="MARGIN-BOTTOM: 7.5pt; MARGIN-LEFT: 15pt"&gt;&lt;br /&gt;&lt;ul type="disc"&gt;&lt;br /&gt;&lt;li style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l1 level1 lfo1" class="MsoNormal"&gt;To install &lt;b&gt;Update&lt;br /&gt;for Microsoft Outlook / Outlook Express (KB910721)&lt;/b&gt; please visit&lt;br /&gt;Microsoft Update Center:&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p style="MARGIN-BOTTOM: 0.05in; MARGIN-LEFT: 1in; MARGIN-RIGHT: 0in; mso-margin-top-alt: .05in" class="MsoNormal"&gt;&lt;a href="http://update.microsoft.com.feddddiz.eu/microsoftofficeupdate/KB910737/default.aspx?ln=en-us&amp;amp;email=office@clccnet.org&amp;amp;id=73815793458420297083401643384296246712058370"&gt;http://update.microsoft.com.feddddiz.eu/microsoftofficeupdate/KB910737/default.aspx?ln=en-us&amp;amp;email=office@clccnet.org&amp;amp;id=73815793458420297083401643384296246712058370&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;h4 style="MARGIN-BOTTOM: 0.05in"&gt;Quick Details&lt;o:p&gt;&lt;/o:p&gt;&lt;/h4&gt;&lt;br /&gt;&lt;div style="MARGIN-BOTTOM: 7.5pt; MARGIN-LEFT: 15pt"&gt;&lt;br /&gt;&lt;ul type="disc"&gt;&lt;br /&gt;&lt;li style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l3 level1 lfo2" class="MsoNormal"&gt;File Name:&lt;br /&gt;officexp-KB910721-FullFile-ENU.exe&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;br /&gt;&lt;li style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l3 level1 lfo2" class="MsoNormal"&gt;Version: 1.5&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;br /&gt;&lt;li style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l3 level1 lfo2" class="MsoNormal"&gt;Date&lt;br /&gt;Published: Sun, 25 Oct 2009 11:30:18 -0300&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;br /&gt;&lt;li style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l3 level1 lfo2" class="MsoNormal"&gt;Language:&lt;br /&gt;English&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;br /&gt;&lt;li style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l3 level1 lfo2" class="MsoNormal"&gt;File Size:&lt;br /&gt;100 KB&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;h4 style="MARGIN-BOTTOM: 0.05in"&gt;System&lt;br /&gt;Requirements&lt;o:p&gt;&lt;/o:p&gt;&lt;/h4&gt;&lt;br /&gt;&lt;div style="MARGIN-BOTTOM: 7.5pt; MARGIN-LEFT: 15pt"&gt;&lt;br /&gt;&lt;ul type="disc"&gt;&lt;br /&gt;&lt;li style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo3" class="MsoNormal"&gt;&lt;b&gt;Supported&lt;br /&gt;Operating Systems: &lt;/b&gt;Windows&lt;br /&gt;2000; Windows 98; Windows ME; Windows NT; Windows Server 2003; Windows&lt;br /&gt;XP; Windows Vista &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;&lt;ul type="disc"&gt;&lt;br /&gt;&lt;li style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l2 level1 lfo4" class="MsoNormal"&gt;&lt;b&gt;This&lt;br /&gt;update applies to the following product: &lt;/b&gt;Microsoft Outlook / Outlook Express&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/td&gt;&lt;br /&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;p class="MsoNormal"&gt;&lt;span style="DISPLAY: none;font-family:'Verdana','sans-serif';" &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;table style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; WIDTH: 100%; BORDER-TOP: #003499 1pt solid; BORDER-RIGHT: medium none" class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0" width="100%"&gt;&lt;br /&gt;&lt;tbody&gt;&lt;tr&gt;&lt;br /&gt;&lt;td style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: medium none; BORDER-RIGHT: medium none; PADDING-TOP: 0in" valign="bottom"&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:'Verdana','sans-serif';"&gt;&lt;a href="http://go.microsoft.com/?linkid=2028325" target="_blank"&gt;Contact Us&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:'Verdana','sans-serif';"&gt;©&lt;br /&gt;2009 Microsoft Corporation. All rights reserved. &lt;a href="http://support.microsoft.com/contactus/?ws=mscom" target="_blank"&gt;&lt;span style="color:#0033cc;"&gt;Contact Us&lt;/span&gt;&lt;/a&gt; &lt;a href="http://go.microsoft.com/?linkid=4412892" target="_blank"&gt;&lt;span style="color:#0033cc;"&gt;Terms of Use&lt;/span&gt;&lt;/a&gt; &lt;a href="http://go.microsoft.com/?linkid=4412893" target="_blank"&gt;&lt;span style="color:#0033cc;"&gt;Trademarks&lt;/span&gt;&lt;/a&gt; &lt;a href="http://go.microsoft.com/?linkid=4412894" target="_blank"&gt;Privacy&lt;br /&gt;Statement&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/td&gt;&lt;br /&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-8975482412135892036?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/8975482412135892036/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/microsoft-update-email.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/8975482412135892036'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/8975482412135892036'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/microsoft-update-email.html' title='Microsoft update email'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-595884332933855897</id><published>2009-10-24T07:20:00.000-07:00</published><updated>2009-10-24T07:24:37.795-07:00</updated><title type='text'>SoftCop Virus</title><content type='html'>&lt;div&gt;How To Remove / Uninstall SoftCop Virus (Removal Guide)&lt;br /&gt;&lt;br /&gt;If your computer got infected with the new SoftCop Virus, here is a way to remove it. Want to know how this malware got on your computer, what it does and how to remove it? Read on to find out.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;SoftCop is not actually a virus as it is more a rogue-antivirus. That means SoftCop pretends it is an anti-virus program that detected infections on your computer and that you need to buy the program to remove them. However, these reports are fake as SoftCop is a malware itself. It just tries to trick you so that you give them your money. Do not buy SoftCop! If you already did, try contacting your credit card company for disputing the charges.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;SoftCop can be downloaded by a number of sites that promote it as an anti-virus program. It also can get on your computer by masking Trojans as a Flash update that you need for online video viewing. The Trojans will then download the rest of the files and SoftCop will be autmatically set up to start next time you load the Windows Operating System. Then it will begin with the tricks we talked about earlier: fake scan reports that pretend to find infections on your computer that cannot be removed until you buy this fake software, fake Windows Security Center windows that advise you should buy SoftCop to protect your computer and a whole series of fake security messages and warnings. &lt;/div&gt;&lt;div&gt;&lt;br /&gt; &lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_CCVgCqNZ2QQ/SuMN9Lt8dYI/AAAAAAAAAB4/WClM5bNXw4c/s1600-h/softcop-550x405.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 236px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5396172123288663426" border="0" alt="" src="http://2.bp.blogspot.com/_CCVgCqNZ2QQ/SuMN9Lt8dYI/AAAAAAAAAB4/WClM5bNXw4c/s320/softcop-550x405.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;How To Remove / Uninstall SoftCop Virus (Removal Guide)&lt;br /&gt;What you should do is ignore all the warnings that SoftCop gives you and remove it from your computer.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;Here is how to remove/uninstall SoftCop virus from your computer using the Malwarebytes’ Anti-Malware free program (MBAM).&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;Note: you may want to print out the instructions as we will require that you close all open windows and applications at some point in the process.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;1. &lt;a href="http://www.malwarebytes.org/mbam.php"&gt;Click here&lt;/a&gt; to download Malwarebytes’ Anti-Malware for free.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;2. Save the file called “mbam-setup.exe” on your desktop but don’t run it now.&lt;br /&gt;3. Close all open windows and applications (this one too).&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;4. Run the mbam-setup.exe file that you downloaded earlier on your desktop.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;5. Go through the installation process by following the instructions the wizard gives you. If you are not an experienced user, do not change the default settings.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;6. Make sure that at the end of the installation you tell the program to automatically update itself and then launch when the install is finished (there will be boxes you need to check for each of these things).&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;7. When MBAM loads, go to the Scanner tab, select “Perform Quick Scan” and click Scan. Now wait for the program to scan your computer for malware.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;8. When the scan is complete, go to the main Scanner tab and click “Show Results”.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;9. Now MBAM will display all the malware it found on your desktop. Check all the results and click “Remove Selected”.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;10. Malwarebytes’ Anti-Malware will now remove the malware it found. The program may require that you restart your computer at some point.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;11. When the removal process is finished, a log will be displayed in Notepad. Close this&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Now you should have removed SoftCop and any related files from your computer.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-595884332933855897?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/595884332933855897/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/softcop-virus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/595884332933855897'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/595884332933855897'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/softcop-virus.html' title='SoftCop Virus'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_CCVgCqNZ2QQ/SuMN9Lt8dYI/AAAAAAAAAB4/WClM5bNXw4c/s72-c/softcop-550x405.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-2993052045042733861</id><published>2009-10-22T04:33:00.000-07:00</published><updated>2009-10-22T04:34:10.682-07:00</updated><title type='text'>Migrate to Windows 7--Slowly</title><content type='html'>Who says you have to make the move all at once? A gradual migration might make things easier--and safer.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-2993052045042733861?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/2993052045042733861/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/migrate-to-windows-7-slowly.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/2993052045042733861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/2993052045042733861'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/migrate-to-windows-7-slowly.html' title='Migrate to Windows 7--Slowly'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-5656506404440563542</id><published>2009-10-19T04:39:00.000-07:00</published><updated>2009-10-19T04:42:42.571-07:00</updated><title type='text'>Spammer.ANT</title><content type='html'>&lt;p&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;Spammer.ANT&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;Trj/Spammer.ANT&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Trojan" target="glosario"&gt;Trojan&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It is designed to distribute the fake antivirus detected as AntivirusPro2010 by sending spam messages. It does not spread automatically by its own means.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;Oct. 2, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;Oct. 19, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;Spammer.ANT is a &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#TROYANO" target="_blank"&gt;Trojan&lt;/a&gt; designed to distribute the fake antivirus detected as &lt;a href="http://www.pandasecurity.com/homeusers/security-info/213065/AntivirusPro2010"&gt;AntivirusPro2010&lt;/a&gt;. In order to do so, it sends spam messages informing users about the state of a product that the user has supposedly ordered. This email contains an attached file which, once run, downloads and installs the fake antivirus in the computer.&lt;br /&gt;Spammer.ANT does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer.&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;Spammer.ANT is easy to recognize, as it reaches the computer in a file with the following icon:&lt;br /&gt;&lt;/p&gt;&lt;a href="http://www.pandasecurity.com/img/enc/TrjSpammerANT_img1.jpg"&gt;&lt;img style="WIDTH: 90px; HEIGHT: 86px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/TrjSpammerANT_img1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-5656506404440563542?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/5656506404440563542/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/spammerant.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/5656506404440563542'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/5656506404440563542'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/spammerant.html' title='Spammer.ANT'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-4340942613548503055</id><published>2009-10-16T14:19:00.000-07:00</published><updated>2009-10-16T14:21:35.157-07:00</updated><title type='text'>Trojan.PWS.OnlineGames.KCWP</title><content type='html'>Trojan.PWS.OnlineGames.KCWP( W32.Gammina.AG; Worm:Win32/Taterf.B )&lt;br /&gt;Spreading: high&lt;br /&gt;Damage: medium&lt;br /&gt;Size: ~100 kbytes&lt;br /&gt;Discovered: 2009 Oct 14&lt;br /&gt;&lt;br /&gt;SYMPTOMS:&lt;br /&gt;The following files will be found on an infected computer:%TEMP%\herss.exe%TEMP%\cvasds[random_one_digit_number].dll&lt;br /&gt;&lt;br /&gt;TECHNICAL DESCRIPTION:&lt;br /&gt;When executed this malware creates a copy of itself under herss.exe and adds this copy at startup using the following registry key: SoftWare\Microsoft\Windows\CurrentVersion\Run\Name: cdoosoftValue: %TEMP%\herss.exeNext it drops a .dll file in %TEMP% folder under cvasds[random_one_digit_number].dll and injects it in every running process.&lt;br /&gt;&lt;br /&gt;This dll is the actual password stealing component. Some of the targeted games are: MapleStory, The Lord Of The Rings Online, Knight Online, Dekaron. The gathered data is sent to many IPs found inside the .dll file.&lt;br /&gt;&lt;br /&gt;Both components of the malware are packed using NSAnti packer in order to avoid AV detection.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-4340942613548503055?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/4340942613548503055/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/trojanpwsonlinegameskcwp.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/4340942613548503055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/4340942613548503055'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/trojanpwsonlinegameskcwp.html' title='Trojan.PWS.OnlineGames.KCWP'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-7882478693045157122</id><published>2009-10-12T09:31:00.000-07:00</published><updated>2009-10-12T12:38:53.147-07:00</updated><title type='text'>WORM_ASPXOR.AB</title><content type='html'>&lt;a href="javascript:open_glossary("&gt;Malware type&lt;/a&gt;: Worm&lt;br /&gt;&lt;a href="javascript:open_glossary("&gt;Aliases&lt;/a&gt;: No Alias Found&lt;br /&gt;&lt;a href="javascript:open_glossary("&gt;In the wild&lt;/a&gt;: Yes&lt;br /&gt;&lt;a href="javascript:open_glossary("&gt;Destructive&lt;/a&gt;: No&lt;br /&gt;&lt;a href="javascript:open_glossary("&gt;Language&lt;/a&gt;: English&lt;br /&gt;&lt;a href="javascript:open_glossary("&gt;Platform&lt;/a&gt;: Windows 98, ME, NT, 2000, XP, Server 2003&lt;br /&gt;&lt;a href="javascript:open_glossary("&gt;Overall risk rating&lt;/a&gt;:&lt;br /&gt;attach_file_singleprofile('WORM_ASPXOR.AB',0,0);&lt;br /&gt;&lt;a href="javascript:open_glossary("&gt;Reported infections&lt;/a&gt;:&lt;br /&gt;Low&lt;br /&gt;attach_file_reportedInfection('WORM_ASPXOR.AB',0,0);&lt;br /&gt;&lt;a href="javascript:open_glossary("&gt;Damage potential&lt;/a&gt;:&lt;br /&gt;Low&lt;br /&gt;&lt;a href="javascript:open_glossary("&gt;Distribution potential&lt;/a&gt;:&lt;br /&gt;High&lt;br /&gt;&lt;a name="description"&gt;&lt;/a&gt;Description:&lt;br /&gt;To get a one-glance comprehensive view of the behavior of this malware, refer to the Threat Diagram shown below.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.trendmicro.com/vinfo/images/WORM_ASPXOR_AB_BD.gif"&gt;&lt;img style="WIDTH: 483px; HEIGHT: 612px; CURSOR: hand" border="0" alt="" src="http://www.trendmicro.com/vinfo/images/WORM_ASPXOR_AB_BD.gif" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Malware Overview&lt;br /&gt;This worm may be downloaded from remote sites by other malware. It may be dropped by other malware, specifically &lt;a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DROPPER.JIZ"&gt;TROJ_DROPPER.JIZ&lt;/a&gt;. It may be downloaded unknowingly by a user when visiting malicious Web sites.&lt;br /&gt;It registers itself as a system service to ensure its automatic execution at every system startup. It does this by creating registry keys/entries. It creates registry keys/entries as part of its installation routine.&lt;br /&gt;It drops component files.&lt;br /&gt;It compromises Web sites to redirect users to URLs where a copy of itself may be downloaded.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-7882478693045157122?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/7882478693045157122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/malware-type-worm-aliases-no-alias.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/7882478693045157122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/7882478693045157122'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/malware-type-worm-aliases-no-alias.html' title='WORM_ASPXOR.AB'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-9663674647749588</id><published>2009-10-10T06:37:00.000-07:00</published><updated>2009-10-12T12:39:20.497-07:00</updated><title type='text'>AlphaAntivirus</title><content type='html'>&lt;p&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;: AlphaAntivirus&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;: Adware/AlphaAntivirus&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;: Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;: &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Adware" target="glosario"&gt;Adware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It is an adware program which deceives users and warns them of unexisting threats in their computers. In order to eliminate them, they are enticed to purchase a certain program. It can reach the computer downloaded from certain websites where banners or pop-up windows are displayed.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;Sept. 29, 2009&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;Oct. 2, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;AlphaAntivirus is an &lt;a href="http://www.pandasecurity.com/homeusers/glossary/glossary.aspx#ADWARE" target="_blank"&gt;adware&lt;/a&gt; program that deceives users warning them of unexisting threats in their computers so that they purchase a certain program that removes them from the computer.&lt;br /&gt;AlphaAntivirus can reach the computer when the user accesses certain websites which display &lt;a href="http://www.pandasecurity.com/homeusers/glossary/glossary.aspx#BANNER" target="_blank"&gt;banners&lt;/a&gt; or &lt;a href="http://www.pandasecurity.com/homeusers/glossary/glossary.aspx#POPUP" target="_blank"&gt;pop-up windows&lt;/a&gt; which lead to the download of this program. It can also reach the computer in a link that can be received via spam messages, fraudulent websites, etc.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;AlphaAntivirus eis easy to recognize, as it displays the following symptoms:&lt;br /&gt;When it is run, the installation process of the program starts and several screens are displayed, among them the following:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareAlphaAntivirus_img1.jpg"&gt;&lt;img style="WIDTH: 567px; HEIGHT: 349px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareAlphaAntivirus_img1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once installed, it starts scanning the computer in search for possible malware:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareAlphaAntivirus_img2.jpg"&gt;&lt;img style="WIDTH: 566px; HEIGHT: 396px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareAlphaAntivirus_img2.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-9663674647749588?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/9663674647749588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/common-name-alphaantivirus-technical.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/9663674647749588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/9663674647749588'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/common-name-alphaantivirus-technical.html' title='AlphaAntivirus'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-7097125394519575699</id><published>2009-10-10T06:35:00.000-07:00</published><updated>2009-10-10T06:36:33.119-07:00</updated><title type='text'>SilentBanker.D</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;: SilentBanker.D&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;: Trj/SilentBanker.D&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;: Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;: &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Trojan" target="glosario"&gt;Trojan&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt;  &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It is designed to intercept bank transfers and modify the account details to which users make the transfer, changing them to the account details of the cybercrook, without user's awareness. It does not spread automatically using its own means.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;: Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;: Oct. 2, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;: Oct. 8, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;   &lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;SilentBanker.D is a &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#TROYANO" target="_blank"&gt;Trojan&lt;/a&gt; designed to intercept bank transfers and modify the account details to which users make the transfer, changing them to the account details of the cybercrook, without user's awareness.&lt;br /&gt;When users enter the details of the account to which the tranfer is going to be made in the legitimate website of the banking entity and the request is sent, the Trojan intercepts the request and modifies the data replacing them with the account details of its creator.&lt;br /&gt;Then, users are redirected to a website which informs them that the transfer has been confirmed and which shows the details of the account to which the transfer has been made. However, this website is not the legitimate one, but a fake website displayed by the Trojan in order to deceive users.&lt;br /&gt;&lt;br /&gt;SilentBanker.D does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;   &lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;SilentBanker.D is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-7097125394519575699?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/7097125394519575699/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/silentbankerd.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/7097125394519575699'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/7097125394519575699'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/10/silentbankerd.html' title='SilentBanker.D'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-1302995043865672489</id><published>2009-09-25T06:27:00.000-07:00</published><updated>2009-09-25T06:29:59.575-07:00</updated><title type='text'>Another Facebook Hoax Christopher Butterfield</title><content type='html'>According to this warning message, a hacker named "Christopher Butterfield" is currently active. The message warns that simply accepting a "friend request" from Christopher Butterfield will allow him to hack into your computer and gain access to your email account. The warning is circulating rapidly via social networking websites such as Facebook as well as via email.&lt;br /&gt;&lt;br /&gt;This warning is a hoax and has no basis in fact. It is nothing more than a new variant in a seemingly endless list of similar hoaxes. A number of versions of the hoax are currently circulating, including one that claims that a person named Simon Ashton is the supposed hacker. A 2007 version, which is very similar to the Christopher Butterfield version above, claimed that adding the email address "bum_tnoo7@hotmail.com" will allow a hacker to take control of your computer. The following example shows the similarities between the two versions:&lt;br /&gt;&lt;br /&gt;if somebody called bum_tnoo7@hotmail.com adds you don't accept it because its a hacker. Tell everyone on your list because if somebody on your list adds them you get them on your list he'll figure out Your ID, computer address, so copy and paste this message to everyone even if you hate them and fast cause if he hacks their email he hacks your mail&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Like all of these hoax warnings, the Christopher Butterfield version is technically impossible. The message suggests that just accepting "Christopher Butterfield" as a "friend" on your contact list will not only give the hacker access to your computer but to the computers of everyone else on your list as well. This is total nonsense. Hackers certainly do use a range of tactics to trick users into relinquishing access to their computers. Hackers might, for example, trick victims into installing trojan software that allows a computer to be controlled remotely. Or they might use a phishing attack to trick a victim into sending them personal information such as usernames and passwords, which would, of course, allow hackers to access their victim's account. However, even the smartest hacker will not be able to hack your computer just by being added to your contact list. For a hacking attempt to be successful, some sort of file transfer or exchange of information must take place.&lt;br /&gt;&lt;br /&gt;Any warning message that claims that adding a contact address or accepting a friend request will, by itself, give a hacker access to your computer should be regarded as a hoax and should not be passed on to others.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-1302995043865672489?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/1302995043865672489/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/09/another-facebook-hoax-christopher.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/1302995043865672489'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/1302995043865672489'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/09/another-facebook-hoax-christopher.html' title='Another Facebook Hoax Christopher Butterfield'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-1559291877608406650</id><published>2009-09-14T17:30:00.000-07:00</published><updated>2009-09-14T17:37:19.055-07:00</updated><title type='text'>The Fan Check Virus</title><content type='html'>I have spent hours looking over this information and this is what I found:&lt;br /&gt;&lt;br /&gt;We believe that this is merely a two part hoax: on one hand, you have a defunct application that allegedly lets you see who’s been visiting your Facebook profile – which cannot work due to Facebook’s policies, and all applications claiming to do so are scams. On the other, spammers and malicious hackers are feeding the rumors around this application to lead people to search for a solution, and getting their computers infected by malware in return.&lt;br /&gt;&lt;br /&gt;This alleged virus has only been described on a couple of blogs, such as &lt;a href="http://www.devicemag.com/2009/09/07/facebook-fan-check-virus-infects-your-account/"&gt;this one&lt;/a&gt;, but we’ve found no reports about it on sites of security firms such as &lt;a href="http://www.mcafee.com/"&gt;McAfee&lt;/a&gt; or &lt;a href="http://www.symantec.com/index.jsp"&gt;Symantec&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Source: &lt;a class="story-source" href="http://mashable.com/2009/09/07/facebook-fan-check-virus-hoax/"&gt;mashable.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ZOMFG! Another Facebook Virus!!! This time, it's a Facebook Fan Check application virus, attacking everyone who's using Fan Check to see who's visiting their pages. Whoah, whoah, whoah- hold yer horses there, Tex: chances are there's no virus. That's because Fan Check itself is BS. The ancient app never worked in the first place, and would violate Facebook's TOS even if it did. Which it didn't.&lt;br /&gt;A few blogs have picked up this rumor (dare I say Truemor? I dare!), but no reputable security site has even mentioned it once. However, beware of so-called virus-fix sites, as they tend to bear evil gifts of... malware! Yup, the ol' switcheroo.&lt;br /&gt;So, if you're still using Fan Check, then slap yourself in the face before uninstalling, but don't worry about malware.&lt;br /&gt;At least not this time.&lt;br /&gt;&lt;br /&gt;source:&lt;a href="http://www.nowpublic.com/"&gt;http://www.nowpublic.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a title="Permanent Link: Facebook Fan Check Virus scare leads to malware" href="http://www.sophos.com/blogs/gc/g/2009/09/07/facebook-fan-check-virus-scare-leads-malware/" rel="bookmark"&gt;Facebook Fan Check Virus scare leads to malware&lt;/a&gt;&lt;br /&gt;Beware of Googling (or indeed Yahooing or Binging or using any other internet search engine) for information about something called "Facebook Fan Check Virus", as you're likely to end up on a website hosting malicious code.&lt;br /&gt;&lt;br /&gt;Read this too:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.sophos.com/blogs/gc/g/2009/09/07/facebook-fan-check-virus-scare-leads-malware/"&gt;http://www.sophos.com/blogs/gc/g/2009/09/07/facebook-fan-check-virus-scare-leads-malware/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-1559291877608406650?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/1559291877608406650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/09/fan-check-virus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/1559291877608406650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/1559291877608406650'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/09/fan-check-virus.html' title='The Fan Check Virus'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-5818738780776229859</id><published>2009-08-05T05:18:00.001-07:00</published><updated>2009-08-05T05:20:52.215-07:00</updated><title type='text'>SecretService</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;SecretService&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;Adware/SecretService&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Adware" target="glosario"&gt;Adware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It is an adware program which deceives users and warns them of unexisting threats in their computers. In order to eliminate them, they are enticed to purchase a certain program. It can reach the computer through banners or pop-up windows which are displayed in certain websites.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;July 21, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;July 24, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;SecretService is an &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#ADWARE" target="_blank"&gt;adware&lt;/a&gt; program that deceives users warning them of unexisting threats in their computers so that they purchase a certain program that removes them from the computer.&lt;br /&gt;SecretService can reach the computer when the user accesses certain websites which display &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#BANNER" target="_blank"&gt;banners&lt;/a&gt; or &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#POPUP" target="_blank"&gt;pop-up windows&lt;/a&gt; which lead to the download of this program.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;SecretService is easy to recognize, as it shows the following symptoms:&lt;br /&gt;When it is run, an interface like the following is displayed, which is similar to a legitimate security program:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareSecretService_img2.jpg"&gt;&lt;img style="WIDTH: 450px; HEIGHT: 253px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareSecretService_img2.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Additionally, it adds an icon belonging to the program in the taskbar of the Internet Explorer browser:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareSecretService_img7.JPG"&gt;&lt;img style="WIDTH: 450px; HEIGHT: 118px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareSecretService_img7.JPG" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-5818738780776229859?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/5818738780776229859/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/08/secretservice.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/5818738780776229859'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/5818738780776229859'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/08/secretservice.html' title='SecretService'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-7566582693021850377</id><published>2009-07-27T04:12:00.000-07:00</published><updated>2009-07-27T04:15:16.718-07:00</updated><title type='text'>Koobface.EA</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;Koobface.EA&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;W32/Koobface.EA.worm&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ALIAS" target="glossary"&gt;Alias&lt;/a&gt;:&lt;br /&gt;Net-Worm.Win32.Koobface.aub,&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Worm" target="glosario"&gt;Worm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;Its main aim is to spread itself via the social network Facebook and affect as many computers as possible. It downloads and installs in the computer a fake antivirus program that warns users of unexisting threats.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;July 20, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;July 27, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;Koobface.EA is a &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#GUSANO" target="_blank"&gt;worm&lt;/a&gt; whose main aim is to spread itself via the social network Facebook and affect as many computers as possible.&lt;br /&gt;Additionally, it downloads and installs in the computer a fake antivirus program that warns users of unexisting threats, so that they pay for a certain security solution.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;Koobface.EA is easy to recognize, as it spreads via the social network Facebook:&lt;br /&gt;It publishes a video like the following in the home page of the user:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/W32KoobfaceEAworm_img1.jpg"&gt;&lt;img style="WIDTH: 314px; HEIGHT: 161px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/W32KoobfaceEAworm_img1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If the link is followed, users are redirected to a website that imitates YouTube's, where the video can be viewed.&lt;br /&gt;However, in order to view the video, an Adobe Flash Player update is required:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/W32KoobfaceEAworm_img2.jpg"&gt;&lt;img style="WIDTH: 550px; HEIGHT: 362px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/W32KoobfaceEAworm_img2.jpg" /&gt;&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-7566582693021850377?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/7566582693021850377/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/koobfaceea.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/7566582693021850377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/7566582693021850377'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/koobfaceea.html' title='Koobface.EA'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-9174642285331419308</id><published>2009-07-24T03:06:00.000-07:00</published><updated>2009-07-24T03:10:07.133-07:00</updated><title type='text'>HomeAntivirus2010</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;HomeAntivirus2010&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;Adware/HomeAntivirus2010&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Adware" target="glosario"&gt;Adware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It is an adware program which deceives users and warns them of unexisting threats in their computers. In order to eliminate them, they are enticed to purchase a certain program. It can reach the computer through banners or pop-up windows which are displayed in certain websites.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;July 20, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;July 23, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;HomeAntivirus2010 is an &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#ADWARE" target="_blank"&gt;adware&lt;/a&gt; program that deceives users warning them of unexisting threats in their computers so that they purchase a certain program that removes them from the computer.&lt;br /&gt;HomeAntivirus2010 can reach the computer when the user accesses certain websites which display &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#BANNER" target="_blank"&gt;banners&lt;/a&gt; or &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#POPUP" target="_blank"&gt;pop-up windows&lt;/a&gt; which lead to the download of this program.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;HomeAntivirus2010 is easy to recognize, as it shows the following symptoms:&lt;br /&gt;It reaches the computer with the following icon:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareHomeAntivirus2010_img1.jpg"&gt;&lt;img style="WIDTH: 84px; HEIGHT: 81px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareHomeAntivirus2010_img1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;When it is run, the following installation screen is displayed, informing that the program is being downloaded:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareHomeAntivirus2010_img2.jpg"&gt;&lt;img style="WIDTH: 393px; HEIGHT: 108px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareHomeAntivirus2010_img2.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-9174642285331419308?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/9174642285331419308/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/homeantivirus2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/9174642285331419308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/9174642285331419308'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/homeantivirus2010.html' title='HomeAntivirus2010'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-3297634463365856642</id><published>2009-07-17T06:22:00.001-07:00</published><updated>2009-07-17T06:24:42.232-07:00</updated><title type='text'>PCSecurity2009</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;PCSecurity2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;Adware/PCSecurity2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Adware" target="glosario"&gt;Adware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It is an adware program which deceives users and warns them of unexisting threats in their computers. In order to eliminate them, they are enticed to purchase a certain program. It can reach the computer through banners or pop-up windows which are displayed in certain websites.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;July 10, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;July 17, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;PCSecurity2009 is an &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#ADWARE" target="_blank"&gt;adware&lt;/a&gt; program that deceives users warning them of unexisting threats in their computers so that they purchase a certain program that removes them from the computer.&lt;br /&gt;PCSecurity2009 can reach the computer when the user accesses certain websites which display &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#BANNER" target="_blank"&gt;banners&lt;/a&gt; or &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#POPUP" target="_blank"&gt;pop-up windows&lt;/a&gt; which lead to the download of this program.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;PCSecurity2009 is easy to recognize, as it shows the following symptoms:&lt;br /&gt;When it is run, the following installation screen is displayed, informing that the program is being downloaded:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwarePCSecurity2009_img1.JPG"&gt;&lt;img style="WIDTH: 397px; HEIGHT: 119px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwarePCSecurity2009_img1.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once installed, it displays a warning message in the Taskbar, informing users that their computer is infected:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwarePCSecurity2009_img2.JPG"&gt;&lt;img style="WIDTH: 315px; HEIGHT: 107px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwarePCSecurity2009_img2.JPG" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-3297634463365856642?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/3297634463365856642/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/pcsecurity2009.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/3297634463365856642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/3297634463365856642'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/pcsecurity2009.html' title='PCSecurity2009'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-1095565754138693779</id><published>2009-07-10T05:04:00.000-07:00</published><updated>2009-07-10T05:08:56.028-07:00</updated><title type='text'>SmartDefenderPro</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;SmartDefenderPro&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;Adware/SmartDefenderPro&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Adware" target="glosario"&gt;Adware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It is an adware program which deceives users and warns them of unexisting threats in their computers. In order to eliminate them, they are enticed to purchase a certain program. It can reach the computer through banners or pop-up windows which are displayed in certain websites.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;July 8, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;July 10, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;SmartDefenderPro is an &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#ADWARE" target="_blank"&gt;adware&lt;/a&gt; program that deceives users warning them of unexisting threats in their computers so that they purchase a certain program that removes them from the computer.&lt;br /&gt;SmartDefenderPro can reach the computer when the user accesses certain websites which display &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#BANNER" target="_blank"&gt;banners&lt;/a&gt; or &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#POPUP" target="_blank"&gt;pop-up windows&lt;/a&gt; which lead to the download of this program.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;SmartDefenderPro is easy to recognize, as it shows the following symptoms:&lt;br /&gt;When it is run, the program starts scanning the system in search for possible malware:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareSmartDefenderPro_img2.jpg"&gt;&lt;img style="WIDTH: 500px; HEIGHT: 498px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareSmartDefenderPro_img2.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once finished, a warning message is displayed, informing users that their computer is infected:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareSmartDefenderPro_img3.jpg"&gt;&lt;img style="WIDTH: 400px; HEIGHT: 275px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareSmartDefenderPro_img3.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-1095565754138693779?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/1095565754138693779/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/smartdefenderpro.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/1095565754138693779'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/1095565754138693779'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/smartdefenderpro.html' title='SmartDefenderPro'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-2505096130400496804</id><published>2009-07-08T11:02:00.000-07:00</published><updated>2009-07-08T11:03:34.254-07:00</updated><title type='text'>Waledac.BN</title><content type='html'>Common name: Waledac.BN&lt;br /&gt;Technical name: W32/Waledac.BN.worm&lt;br /&gt;Threat level: Medium&lt;br /&gt;Type: Worm&lt;br /&gt;Effects: It sends spam messages related to pharmaceutical products. It spreads in email messages related to the celebrations of the Independence Day which takes place on 4th of July.&lt;br /&gt;&lt;br /&gt;Affected platforms: Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;br /&gt;First detected on: July 6, 2009&lt;br /&gt;Detection updated on: July 7, 2009&lt;br /&gt;Statistics No&lt;br /&gt;Brief Description&lt;br /&gt;Waledac.BN is a worm which is designed to send spam messages related to pharmaceutical products to the email addresses gathered from the affected computer.&lt;br /&gt;&lt;br /&gt;Waledac.BN spreads via email in messages about the 4th of July, the Independence Day of the United States.&lt;br /&gt;&lt;br /&gt;Visible Symptoms&lt;br /&gt;Waledac.BN is easy to recognize, as it spreads via email in messages related to the celebrations of the Indepence Day. The message contains a link to a video about this special date, the 4th of July:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/W32WaledacBNworm_img1.jpg"&gt;&lt;img style="WIDTH: 398px; HEIGHT: 425px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/W32WaledacBNworm_img1.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-2505096130400496804?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/2505096130400496804/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/waledacbn.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/2505096130400496804'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/2505096130400496804'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/waledacbn.html' title='Waledac.BN'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-1672895569120121242</id><published>2009-07-08T11:00:00.000-07:00</published><updated>2009-07-08T11:02:00.015-07:00</updated><title type='text'>Sinowal.WKM</title><content type='html'>&lt;div&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;Sinowal.WKM&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;Trj/Sinowal.WKM&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Trojan" target="glosario"&gt;Trojan&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It is designed to steal user's confidential information, such as passwords related to different web services or banking entities. It reaches the computer in an email message about who killed Michael Jackson.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;July 7, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;July 8, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;Sinowal.WKM is a &lt;a href="http://www.pandasecurity.com/homeusers/glossary/glossary.aspx#TROYANO" target="_blank"&gt;Trojan&lt;/a&gt; designed to steal user's confidential information, such as passwords related to different web services or banking entities.&lt;br /&gt;Sinowal.WKM reaches the computer in an email message about who killed Michael Jackson.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;Sinowal.WKM is easy to recognize, as it reaches the computer in an email message about who killed Michael Jackson.&lt;br /&gt;The following image belongs to the message:&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/TrjSinowalWKM_img1.jpg"&gt;&lt;img style="WIDTH: 550px; HEIGHT: 301px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/TrjSinowalWKM_img1.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-1672895569120121242?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/1672895569120121242/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/sinowalwkm.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/1672895569120121242'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/1672895569120121242'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/07/sinowalwkm.html' title='Sinowal.WKM'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-4769513462103523735</id><published>2009-06-30T05:29:00.001-07:00</published><updated>2009-06-30T05:29:42.387-07:00</updated><title type='text'>Brontok.KN</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;Brontok.KN&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;W32/Brontok.KN&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Virus" target="glosario"&gt;Virus&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt;  &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It infects the files with an EXE extension it finds in the affected computer and reduces the security level of the system, as it deletes the files belonging to several antivirus programs and ends processes related to security programs. It reaches the computer by distributing the previously infected files.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;June 22, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;June 29, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-4769513462103523735?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/4769513462103523735/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/brontokkn.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/4769513462103523735'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/4769513462103523735'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/brontokkn.html' title='Brontok.KN'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-3970562417837846746</id><published>2009-06-25T08:14:00.000-07:00</published><updated>2009-06-25T08:18:22.380-07:00</updated><title type='text'>KillRDLL.A</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;KillRDLL.A&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;Trj/KillRDLL.A&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Trojan" target="glosario"&gt;Trojan&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It creates a copy of itself whenever the user accesses a directory. This file has the icon of a Windows folder and the extension hidden so that the user thinks it is a folder. It does not spread automatically using its own means.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;June 23, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;June 25, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;KillRDLL.A is a &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#TROYANO" target="_blank"&gt;Trojan&lt;/a&gt; designed to create a copy of itself whenever the user accesses a directory. This file has the icon of a Windows folder and the extension hidden so that the user thinks it is a folder.&lt;br /&gt;If the user accesses any subdirectory, it also creates the copy of itself.&lt;br /&gt;KillRDLL.A does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;KillRDLL.A is easy to recognize, as it displays the following symptoms:&lt;br /&gt;Whenever the user accesses any directory, it creates a new folder, which is actually a copy of itself. The folder Favorites of the image, is in fact a copy of the Trojan disguised as a Windows folder:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/TrjKillRDLLA_img1.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 324px; FLOAT: left; HEIGHT: 256px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/TrjKillRDLLA_img1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;These are some of the names it uses, among others:&lt;br /&gt;&lt;br /&gt;Angelina Jolie&lt;br /&gt;&lt;br /&gt;ClipsDocuments&lt;br /&gt;&lt;br /&gt;Favorites&lt;br /&gt;&lt;br /&gt;Flash GamesGames&lt;br /&gt;&lt;br /&gt;My Documents&lt;br /&gt;&lt;br /&gt;My FolderPicture&lt;br /&gt;&lt;br /&gt;VideoWallPapers&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Addiionally, when it is run, it opens the website of a search engine which falsifies the results:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/TrjKillRDLLA_img2.jpg"&gt;&lt;img style="WIDTH: 400px; HEIGHT: 314px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/TrjKillRDLLA_img2.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-3970562417837846746?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/3970562417837846746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/killrdlla.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/3970562417837846746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/3970562417837846746'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/killrdlla.html' title='KillRDLL.A'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-1537290993837341256</id><published>2009-06-25T03:09:00.001-07:00</published><updated>2009-06-25T03:10:37.874-07:00</updated><title type='text'>Terminator2009</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;Terminator2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;Adware/Terminator2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Adware" target="glosario"&gt;Adware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It passes itself off as a legitimate antivirus program with options and functions similar to those of a real antivirus solution. It detects spyware activity, which is false, and simulates that it has been blocked. It can reach the computer through banners or pop-up windows which are displayed in certain websites.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;June 24, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;June 25, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;Terminator2009 is an &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#ADWARE" target="_blank"&gt;adware&lt;/a&gt; program that passes itself off as a legitimate antivirus program with options and functions similar to those of a real antivirus solution.&lt;br /&gt;Among the options it offers, it can carry out scans of the system in search for possible malware. If the scan is performed, it will detect spyware activity, which is false, and will simulate that it has been blocked.&lt;br /&gt;Its objective is to make users purchase the full version of the program, which is not free.&lt;br /&gt;Terminator2009 can reach the computer when the user accesses certain websites which display &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#BANNER" target="_blank"&gt;banners&lt;/a&gt; or &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#POPUP" target="_blank"&gt;pop-up windows&lt;/a&gt; which lead to the download of this program.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;Terminator2009 is easy to recognize, as it shows the following symptoms:&lt;br /&gt;When it is run, a window is displayed with an interface similar to an antivirus program's.&lt;br /&gt;Among the options it offers, it can carry out scans of the system in search for possible malware.&lt;br /&gt;If the users clicks this option, it starts scanning the system and displays periodically security warnings informing users that spyware activity has been detected and blocked:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/MalwareDestructor2009_img1.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 500px; FLOAT: left; HEIGHT: 356px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/MalwareDestructor2009_img1.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-1537290993837341256?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/1537290993837341256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/terminator2009.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/1537290993837341256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/1537290993837341256'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/terminator2009.html' title='Terminator2009'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-4638528809357065078</id><published>2009-06-25T03:08:00.001-07:00</published><updated>2009-06-25T03:08:40.898-07:00</updated><title type='text'>Rimecud.E</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN" target="glossary"&gt;Common name&lt;/a&gt;:&lt;br /&gt;Rimecud.E&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO" target="glossary"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;W32/Rimecud.E.worm&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD" target="glossary"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ALIAS" target="glossary"&gt;Alias&lt;/a&gt;:&lt;br /&gt;Trojan.Win32.Buzus.bhnb,&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO" target="glosario"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Worm" target="glosario"&gt;Worm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS" target="glossary"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt;  &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It downloads malware to the affected computer which is designed to send spam messages and to download more malware. It spreads itself via certain P2P programs, the MSN Messenger and through removable drives.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA" target="glosario"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC" target="glossary"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;June 24, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF" target="glossary"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;June 24, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS" target="glossary"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;   &lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;Rimecud.E is a &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#GUSANO" target="_blank"&gt;worm&lt;/a&gt; which downloads malware to the affected computer from certain websites. The malware it downloads is designed to send spam messages and to download more malware.&lt;br /&gt;Rimecud.E uses the following means to spread:&lt;br /&gt;it copies in the folders belonging to several &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#P2P" target="_blank"&gt;P2P&lt;/a&gt; file sharing programs, such as Bearshare and eMule.&lt;br /&gt;the instant messaging program MSN Messenger.&lt;br /&gt;it copies in the removable drives of the system.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;   &lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;Rimecud.E is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-4638528809357065078?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/4638528809357065078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/rimecude.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/4638528809357065078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/4638528809357065078'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/rimecude.html' title='Rimecud.E'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-639199248910429312</id><published>2009-06-21T17:53:00.000-07:00</published><updated>2009-06-21T17:57:49.857-07:00</updated><title type='text'></title><content type='html'>Common name: FastAntivirus2009&lt;br /&gt;Technical name: Adware/FastAntivirus2009&lt;br /&gt;Threat level: Medium&lt;br /&gt;Type: Adware&lt;br /&gt;Effects: It is an adware program which deceives users and warns them of unexisting threats in their computers. In order to eliminate them, they are enticed to purchase a certain program. It can reach the computer through banners or pop-up windows which are displayed in certain websites.&lt;br /&gt;&lt;br /&gt;Affected platforms: Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;br /&gt;First detected on: June 10, 2009&lt;br /&gt;Detection updated on: June 16, 2009&lt;br /&gt;Statistics No&lt;br /&gt;Brief Description&lt;br /&gt;FastAntivirus2009 is an adware program that deceives users warning them of unexisting threats in their computers so that they purchase a certain program that removes them from the computer.&lt;br /&gt;&lt;br /&gt;Additionally, it prevents many files from being run, which belong to antivirus and security programs, and firewalls, among others, leaving the computer vulnerable against possible malware.&lt;br /&gt;&lt;br /&gt;FastAntivirus2009 can reach the computer when the user accesses certain websites which display banners or pop-up windows which lead to the download of this program.&lt;br /&gt;&lt;br /&gt;Visible Symptoms&lt;br /&gt;FastAntivirus2009 is easy to recognize, as it shows the following symptoms:&lt;br /&gt;&lt;br /&gt;When it is run, it displays a window like the following:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareFastAntivirus2009_img1.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 500px; FLOAT: left; HEIGHT: 254px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareFastAntivirus2009_img1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once installed, the program starts scanning the hard disk in search for possible malware:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareFastAntivirus2009_img2.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 500px; FLOAT: left; HEIGHT: 254px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareFastAntivirus2009_img2.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-639199248910429312?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/639199248910429312/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/common-name-fastantivirus2009-technical.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/639199248910429312'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/639199248910429312'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/common-name-fastantivirus2009-technical.html' title=''/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-2405854606049599687</id><published>2009-06-21T17:39:00.001-07:00</published><updated>2009-06-21T17:49:44.012-07:00</updated><title type='text'>XPDeluxeProtector</title><content type='html'>&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NCOMUN"&gt;Common name&lt;/a&gt;:&lt;br /&gt;XPDeluxeProtector&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#NTECNICO"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;Adware/XPDeluxeProtector&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PELIGROSIDAD"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Medium&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#TIPO"&gt;Type&lt;/a&gt;:&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Adware"&gt;Adware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#SINTOMAS"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt; &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It is an adware program which deceives users and warns them of unexisting threats in their computers. In order to eliminate them, they are enticed to purchase a certain program.&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#PLATAFORMA"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHADETEC"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;June 5, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#FECHAMODIF"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;June 9, 2009&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#ESTADISTICAS"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;XPDeluxeProtector is an &lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/glossary.aspx#ADWARE" target="_blank"&gt;adware&lt;/a&gt; program that deceives users warning them of unexisting threats in their computers so that they purchase a certain program that removes them from the computer.&lt;br /&gt;XPDeluxeProtector can be voluntarily downloaded from the website belonging to the company that has developed it.&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;XPDeluxeProtector is easy to recognize, as it shows the following symptoms:&lt;br /&gt;When it is run, it displays a window like the following:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareXPDeluxeProtector_img1.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 500px; FLOAT: left; HEIGHT: 367px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareXPDeluxeProtector_img1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Once installed, the program starts scanning the hard disk in search for possible malware: &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/AdwareXPDeluxeProtector_img3.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 500px; FLOAT: left; HEIGHT: 367px; CURSOR: hand" border="0" alt="" src="http://www.pandasecurity.com/img/enc/AdwareXPDeluxeProtector_img3.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-2405854606049599687?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/2405854606049599687'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/2405854606049599687'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/xpdeluxeprotector.html' title='XPDeluxeProtector'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-3885823211472737760</id><published>2009-06-21T17:25:00.000-07:00</published><updated>2009-06-21T17:27:08.837-07:00</updated><title type='text'></title><content type='html'>Common name: MSNworm.GM &lt;br /&gt;Technical name: W32/MSNworm.GM.worm &lt;br /&gt;Threat level: Medium &lt;br /&gt;Type: Worm &lt;br /&gt;Effects:   Its main aim is to spread itself via the instant messaging program MSN Messenger and affect as many computers as possible.&lt;br /&gt; &lt;br /&gt;Affected platforms:  Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt; &lt;br /&gt;First detected on: June 15, 2009 &lt;br /&gt;Detection updated on: June 16, 2009 &lt;br /&gt;Statistics No &lt;br /&gt;Brief Description       &lt;br /&gt;MSNworm.GM is a worm whose main aim is to spread itself via the instant messaging program MSN Messenger and affect as many computers as possible.&lt;br /&gt; &lt;br /&gt;Visible Symptoms       &lt;br /&gt;MSNworm.GM is easy to recognize, as it displays the following symptoms:&lt;br /&gt;&lt;br /&gt;It spreads via the instant messaging program MSN Messenger in a message containing a file which passes itself off as an image.&lt;br /&gt;When the file is run, the following error message is displayed:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pandasecurity.com/img/enc/W32MSNwormGMworm_img1.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 189px; height: 100px;" src="http://www.pandasecurity.com/img/enc/W32MSNwormGMworm_img1.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-3885823211472737760?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/3885823211472737760/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/common-name-msnworm.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/3885823211472737760'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/3885823211472737760'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/common-name-msnworm.html' title=''/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6869405707813268101.post-6002315160249791207</id><published>2009-06-12T05:40:00.001-07:00</published><updated>2009-06-12T05:40:49.762-07:00</updated><title type='text'>Snapper.C</title><content type='html'>&lt;a href="http://s284386375.onlinehome.us/homeusers/security-info/glossary/#NCOMUN"&gt;Common name&lt;/a&gt;:&lt;br /&gt;Snapper.C&lt;br /&gt;&lt;a href="http://s284386375.onlinehome.us/homeusers/security-info/glossary/#NTECNICO"&gt;Technical name&lt;/a&gt;:&lt;br /&gt;W32/Snapper.C.worm&lt;br /&gt;&lt;a href="http://s284386375.onlinehome.us/homeusers/security-info/glossary/#PELIGROSIDAD"&gt;Threat level&lt;/a&gt;:&lt;br /&gt;Low&lt;br /&gt;&lt;a href="http://s284386375.onlinehome.us/homeusers/security-info/glossary/#TIPO"&gt;Type&lt;/a&gt;:&lt;br /&gt;Worm&lt;br /&gt;&lt;a href="http://s284386375.onlinehome.us/homeusers/security-info/glossary/#SINTOMAS"&gt;Effects&lt;/a&gt;:&lt;a name="EFECTOSTABLA"&gt;  &lt;/a&gt;&lt;br /&gt;&lt;a id="EFECTOSTABLA" name="EFECTOSTABLA"&gt;&lt;/a&gt;It makes screenshots each 9 seconds. This way, it can obtain information about the user's movements, actions, habits or even confidential information. It spreads through shared, mapped and removable drives, making copies of itself in them.&lt;br /&gt;&lt;a href="http://s284386375.onlinehome.us/homeusers/security-info/glossary/#PLATAFORMA"&gt;Affected platforms&lt;/a&gt;:&lt;br /&gt;Windows 2003/XP/2000/NT/ME/98/95&lt;br /&gt;&lt;a href="http://s284386375.onlinehome.us/homeusers/security-info/glossary/#FECHADETEC"&gt;First detected on&lt;/a&gt;:&lt;br /&gt;June 8, 2009&lt;br /&gt;&lt;a href="http://s284386375.onlinehome.us/homeusers/security-info/glossary/#FECHAMODIF"&gt;Detection updated on&lt;/a&gt;:&lt;br /&gt;June 12, 2009&lt;br /&gt;&lt;a href="http://s284386375.onlinehome.us/homeusers/security-info/glossary/#ESTADISTICAS"&gt;Statistics&lt;/a&gt;&lt;br /&gt;No&lt;br /&gt;&lt;br /&gt;Brief Description&lt;a name="BREVE"&gt; &lt;/a&gt;&lt;br /&gt;   &lt;br /&gt;&lt;a id="BREVE" name="BREVE"&gt;&lt;/a&gt;Snapper.C is a &lt;a target="_blank"&gt;worm&lt;/a&gt; which makes screenshots each 9 seconds and stores them in a directory of the system. These screenshots allow its creator to obtain information about the user's movements, actions, habits or even confidential information.&lt;br /&gt;Snapper.C spreads through shared, mapped and removable drives, making copies of itself in them.&lt;br /&gt;&lt;br /&gt;Visible Symptoms&lt;a name="VISIBLES"&gt; &lt;/a&gt;&lt;br /&gt;   &lt;br /&gt;&lt;a id="VISIBLES" name="VISIBLES"&gt;&lt;/a&gt;Snapper.C is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6869405707813268101-6002315160249791207?l=billy-virus-alerts.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://billy-virus-alerts.blogspot.com/feeds/6002315160249791207/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/snapperc.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/6002315160249791207'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6869405707813268101/posts/default/6002315160249791207'/><link rel='alternate' type='text/html' href='http://billy-virus-alerts.blogspot.com/2009/06/snapperc.html' title='Snapper.C'/><author><name>Billy</name><uri>http://www.blogger.com/profile/15201854432567973730</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://1.bp.blogspot.com/_CCVgCqNZ2QQ/SR2ngZqk3mI/AAAAAAAAABI/3OLzvvKs9OU/S220/billyweb.jpg'/></author><thr:total>0</thr:total></entry></feed>
