<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>Antivirus Internet Security</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/" />
    <link rel="self" type="application/atom+xml" href="http://avsecure.com/atom.xml" />
    <id>tag:avsecure.com,2008-12-30://1</id>
    <updated>2008-12-30T19:32:05Z</updated>
    
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.23-en</generator>

<entry>
    <title>Trojan-GameThief.Win32.OnLineGames.tnys</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/trojan-gamethiefwin32onlinegamestnys.html" />
    <id>tag:avsecure.com,2008://1.16</id>

    <published>2008-12-30T19:19:54Z</published>
    <updated>2008-12-30T19:32:05Z</updated>

    <summary><![CDATA[This Trojan is designed to steal account data from the online game LineAge2. It is a Windows PE EXE file. It is 654848 bytes in size. Payload When launched, the Trojan displays the message shown below: &nbsp; &nbsp;The user is...]]></summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="trojangamethiefwin32onlinegamestnys" label="Trojan-GameThief.Win32.OnLineGames.tnys" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>This Trojan is designed to steal account data from the online game LineAge2. It is a Windows PE EXE file. It is 654848 bytes in size. </p>
<table class="enc_ttl" border="0" cellpadding="3" cellspacing="0" width="100%">
<tbody>
<tr>
<td klmark="virus_doctype:3"><b><a name="doc3">Payload</a></b></td></tr></tbody></table>
<p>When launched, the Trojan displays the message shown below:</p>
<p>&nbsp;</p>
<p>&nbsp;</p><p>The user is asked to enter the address of the LineAge2 gaming server, and 
his/ her user name and password. When the "Start" button is pressed, the Trojan 
sends the details entered in the "IP-Server", "Account" and "Password" fields 
via email to the address shown below:</p>
<div class="pre">***crackserver@rambler.ru</div>
<p>The Trojan then ceases running. </p>
<table class="enc_ttl" border="0" cellpadding="3" cellspacing="0" width="100%">
<tbody>
<tr>
<td klmark="virus_doctype:2"><b><a name="doc2">Removal 
instructions</a></b></td></tr></tbody></table>
<p>If your computer does not have an up-to-date antivirus, or does not have an 
antivirus solution at all, follow the instructions below to delete the malicious 
program:</p>
<ol><li class="large">Use Task Manager to terminate the malicious program's process. 
</li><li class="large">Delete the original Trojan file (the location will depend on how 
the program originally penetrated the victim machine). </li></ol>
<p>&nbsp;</p>]]>
        
    </content>
</entry>

<entry>
    <title>Trojan-Downloader.JS.Agent.sg</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/trojan-downloaderjsagentsg.html" />
    <id>tag:avsecure.com,2008://1.15</id>

    <published>2008-12-30T19:17:47Z</published>
    <updated>2008-12-30T19:19:24Z</updated>

    <summary>This Trojan downloads other files via the Internet and launches them for execution on the victim machine. It is an HTML page which contains Visual Basic Script and Java Script. It is 677 bytes in size. Payload Once the Trojan...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="trojandownloaderjsagentsg" label="Trojan-Downloader.JS.Agent.sg" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>This Trojan downloads other files via the Internet and launches them for execution on the victim machine. It is an HTML page which contains Visual Basic Script and Java Script. It is 677 bytes in size.</p>
<table class="enc_ttl" cellspacing="0" cellpadding="3" width="100%" border="0">
<tbody>
<tr>
<td klmark="virus_doctype:3"><b><a name="doc3">Payload</a></b></td></tr></tbody></table>
<p>Once the Trojan is launched, it uses a vulnerability in the ActiveX component which has the unique system registry identifier shown below:</p>
<div class="pre">{A7F05EE4-0426-454F-8013-C41E3596E9E9}</div>
<p>The vulnerability (CVE-2007-4105) is present in the "DloadDS()" library "BaiduBar.dll". The Trojan attempts to load a file via this vulnerability. The file is located on the remote server shown below:</p>
<div class="pre">http://www1.*****joy.com/S368/cabS3682.exe</div>
<p>The file will be saved to the current user's Windows temporary directory and launched for execution. </p>
<p>At the time of writing, the link was not active. </p>
<table class="enc_ttl" cellspacing="0" cellpadding="3" width="100%" border="0">
<tbody>
<tr>
<td klmark="virus_doctype:2"><b><a name="doc2">Removal instructions</a></b></td></tr></tbody></table>
<p>If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:</p>
<ol>
<li class="large">Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). 
<li class="large">Delete all files from Temporary Internet Files%. 
<li class="large">Disable the vulnerable ActiveX object (see <a href="http://support.microsoft.com/kb/240797" target="_blank">How to stop an ActiveX control from running in Internet Explorer</a> 
<li class="large">Empty the temporary directory (%Temp%).</li></ol>
<p class="large">&nbsp;</p>]]>
        
    </content>
</entry>

<entry>
    <title>Trojan-Downloader.Win32.Braidupdate.c</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/trojan-downloaderwin32braidupdatec.html" />
    <id>tag:avsecure.com,2008://1.14</id>

    <published>2008-12-30T19:15:50Z</published>
    <updated>2008-12-30T19:36:25Z</updated>

    <summary><![CDATA[Trojan-Downloader.Win32.Braidupdate.c AliasesTrojan-Downloader.Win32.Braidupdate.c&nbsp;(Kaspersky Lab) is also known as: TrojanDownloader.Win32.Braidupdate.c&nbsp;(Kaspersky Lab), Trojan.Braid&nbsp;(Doctor&nbsp;Web),&nbsp;&nbsp; TROJ_BRAIDUPDT.C&nbsp;(Trend&nbsp;Micro),&nbsp;&nbsp; TR/Dldr.Braidupda.C&nbsp;(H+BEDV),&nbsp;&nbsp; Win32:Trojano-363&nbsp;(ALWIL),&nbsp;&nbsp; Downloader.Braidupdate.C&nbsp;(Grisoft),&nbsp;&nbsp; Worm.WinUpToDate&nbsp;(ClamAV),&nbsp;&nbsp; Trj/Downloader.PO&nbsp;(Panda),&nbsp;&nbsp; Win32/TrojanDownloader.Braidupdate.C&nbsp;(Eset) This Trojan downloads another program via the Internet and launches it on the victim machine without the user's knowledge or consent. It is...]]></summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="trojandownloaderwin32braidupdatec" label="Trojan-Downloader.Win32.Braidupdate.c" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<h1 class="pagetitle">Trojan-Downloader.Win32.Braidupdate.c</h1><span klmark="virus:59097">
<p>
</p><table class="enc_ttl" border="0" cellpadding="3" cellspacing="0" width="100%">
<tbody>
<tr>
<td klmark="loc_msg:vir_aliases"><b>Aliases</b></td></tr></tbody></table><b>Trojan-Downloader.Win32.Braidupdate.c</b>&nbsp;(<a href="http://www.kaspersky.com/" klmark="loc_msg:kl_url">Kaspersky Lab</a>) is also known as: TrojanDownloader.Win32.Braidupdate.c&nbsp;(<a href="http://www.kaspersky.com/" target="_blank">Kaspersky Lab</a>), Trojan.Braid&nbsp;(<a href="http://www.drweb.com/" target="_blank">Doctor&nbsp;Web</a>),&nbsp;&nbsp; TROJ_BRAIDUPDT.C&nbsp;(<a href="http://www.trendmicro.com/" target="_blank">Trend&nbsp;Micro</a>),&nbsp;&nbsp; TR/Dldr.Braidupda.C&nbsp;(<a href="http://www.antivir.de/" target="_blank">H+BEDV</a>),&nbsp;&nbsp; Win32:Trojano-363&nbsp;(<a href="http://www.avast.com/" target="_blank">ALWIL</a>),&nbsp;&nbsp; Downloader.Braidupdate.C&nbsp;(<a href="http://www.grisoft.com/" target="_blank">Grisoft</a>),&nbsp;&nbsp; Worm.WinUpToDate&nbsp;(<a href="http://www.clamav.net/" target="_blank">ClamAV</a>),&nbsp;&nbsp; Trj/Downloader.PO&nbsp;(<a href="http://www.pandasoftware.com/" target="_blank">Panda</a>),&nbsp;&nbsp; Win32/TrojanDownloader.Braidupdate.C&nbsp;(<a href="http://www.nod32.com/" target="_blank">Eset</a>) 
<p>This Trojan downloads another program via the Internet and launches it on the victim machine without the user's knowledge or consent. It is a Windows PE EXE file. It is 79360 bytes in size. It is written in C++.</p>
<h3>Installation</h3>
<p>In order to ensure that the Trojan is launched automatically each time the system is restarted, the Trojan registers its executable file in the system registry: </p>
<div class="pre">[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />"RunWindowsUpdate" = "&lt;path to executable Trojan file&gt; "</div>
<p>
</p><table class="enc_ttl" border="0" cellpadding="3" cellspacing="0" width="100%">
<tbody>
<tr>
<td klmark="virus_doctype:3"><b><a href="" name="doc3">Payload</a></b></td></tr></tbody></table>
<p>Once launched, the Trojan creates the following system registry key:</p>
<div class="pre">[HKLM\Software\Microsoft\Windows\CurrentVersion\RunWindowsUpdate]<br />"Gid" = "026133246127060045718030656336"</div>
<p>It then sends the following request:</p>
<div class="pre">http://www.uptodate.browse*****.com/perl/uptodate.pl?action=any&amp;gid=0261332<vr>46127060045718030656336&amp;clientversion=1.0.7_ST&amp;county=&amp;cls=&amp;isof=00</vr></div>
<p>On contact with the URL shown above a parameter is added which transmits the latest version of the Trojan program. If there is no new version of the Trojan program available, the server sends the following answer: "&lt;OK&gt;". If there is a more recent version available, the server sends a link to the file containing the new version. The Trojan downloads an updated version of itself and saves it to the temporary directory under the following name:</p>
<div class="pre">%Temp%\_ps_inst.exe</div>
<p>The file is then launched for execution. </p>
<p>
</p><table class="enc_ttl" border="0" cellpadding="3" cellspacing="0" width="100%">
<tbody>
<tr>
<td klmark="virus_doctype:2"><b><a href="" name="doc2">Removal instructions</a></b></td></tr></tbody></table>
<p>If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:</p>
<ol>
<li class="large">Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). 
</li><li class="large">Delete the following system registrykeys: 
<div class="pre">[HKLM\Software\Microsoft\Windows\CurrentVersion\RunWindowsUpdate]<br />"Gid" = "026133246127060045718030656336"</div>
<div class="pre">[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />"RunWindowsUpdate" = "&lt;path to executable Trojan file&gt; "</div>
</li><li class="large">Empty the temporary directory (%Temp%). </li></ol></span>]]>
        
    </content>
</entry>

<entry>
    <title>Trojan-Downloader_Win32_Agent.nmi</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/trojan-downloader-win32-agentnmi.html" />
    <id>tag:avsecure.com,2008://1.13</id>

    <published>2008-12-30T19:15:10Z</published>
    <updated>2008-12-30T19:15:35Z</updated>

    <summary>This Trojan downloads another program via the Internet and launches it on the victim machine without the user&apos;s knowledge or consent. It is a Windows PE EXE file. The size of infected files can range from 18KB to 47KB. Payload...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="trojandownloader_win32_agentnmi" label="Trojan-Downloader_Win32_Agent.nmi" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>This Trojan downloads another program via the Internet and launches it on the victim machine without the user's knowledge or consent. It is a Windows PE EXE file. The size of infected files can range from 18KB to 47KB.</p>
<table class="enc_ttl" cellspacing="0" cellpadding="3" width="100%" border="0">
<tbody>
<tr>
<td klmark="virus_doctype:3"><b><a name="doc3">Payload</a></b></td></tr></tbody></table>
<p>The Trojan contacts the following web site:</p>
<div class="pre">http://xanjan.cn/*****update.txt</div>
<p>There is a list of files for download located on this link. </p>
<p>This list is saved to the directory as shown below:</p>
<div class="pre">%Application Data%\update.dat</div>
<p>The links in the file are encrypted. </p>
<p>The Trojan then downloads files from the links and saves them as shown below:</p>
<div class="pre">%Application Data%\<rnd>.exe</div>
<p>&lt;rnd&gt; stands for a random string of numbers and lower case Latin letters Example: m2zpp.exe, 43m66m.exe.</p>
<p>Once the files have been downloaded, they are launched for execution, and then delete themselves. If the downloaded files are dll files, they will register themselves in the system and be launched for execution next time the system is started. </p>
<p>Once it has delivered its payload, the original Trojan deletes its body. </p>
<table class="enc_ttl" cellspacing="0" cellpadding="3" width="100%" border="0">
<tbody>
<tr>
<td klmark="virus_doctype:2"><b><a name="doc2">Removal instructions</a></b></td></tr></tbody></table>
<p>If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:</p>
<ol>
<li class="large">Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine) if it has not deleted itself. </li></ol>]]>
        
    </content>
</entry>

<entry>
    <title>Trojan-PSW.Win32.OnLineGames.lfi</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/trojan-pswwin32onlinegameslfi.html" />
    <id>tag:avsecure.com,2008://1.12</id>

    <published>2008-12-30T19:13:38Z</published>
    <updated>2008-12-30T19:14:20Z</updated>

    <summary>This malicious program is a Trojan. It is a Windows PE EXE file. It is 123873 bytes in size. Installation The Trojan copies its executable file to the Windows system directory: %System%\amvo.exe In order to ensure that the Trojan is...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="trojanpswwin32onlinegameslfi" label="Trojan-PSW.Win32.OnLineGames.lfi" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>This malicious program is a Trojan. It is a Windows PE EXE file. It is 123873 bytes in size.</p>
<h3>Installation</h3>
<p>The Trojan copies its executable file to the Windows system directory: </p>
<div class="pre">%System%\amvo.exe</div>
<p>In order to ensure that the Trojan is launched automatically each time the system is restarted, the Trojan registers its executable file in the system registry:</p>
<div class="pre">[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]<br />"amva" = "%System%\amvo.exe"</div>
<p>The Trojan also extracts the file shown below from its body:</p>
<div class="pre">%System%\amvo0.dll</div>
<p>This file is 44608 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-GameThief.Win32.WOW.ahe.</p>
<p>The Trojan also extracts the file shown below from its body:</p>
<div class="pre">%Temp%\&lt;random symbols&gt;.dll</div>
<p>This file is 31713 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-GameThief.Win32.OnLineGames.mdl.</p>
<table class="enc_ttl" cellspacing="0" cellpadding="3" width="100%" border="0">
<tbody>
<tr>
<td klmark="virus_doctype:3"><b><a name="doc3">Payload</a></b></td></tr></tbody></table>
<p>The Trojan loads the .dll file to all processes launched in the system. </p>
<p>The Trojan intercepts mouse and keyboard events if any of the processes below have been launched: </p><pre>maplestory.exe
wow.exe</pre>
<p>It sniffs traffic sent to the following addresses:</p><pre>216.107.***.53
216.107.***.51
216.107.***.52</pre>
<p>It does this in an attempt to harvest account data for the following games:</p><pre>Maple Story
World of Warcraft</pre>
<p>and some other games. The Trojan also analyses the configuration files of the games above and attempts to harvest information about gamers' accounts on the web server. </p>
<p>Harvested data is sent to the remote malicious user's site. </p>
<p>The Trojan also modifies the following system registry key parameter values: </p>
<div class="pre">[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Fol<br />der\Hidden\SHOWALL] <br />"CheckedValue" = "0"<br />[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]<br />"Hidden" = "2"<br />"ShowSuperHidden" = "0"<br />[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Pocilies\Explorer]<br />"NoDriveTypeAutoRun" = "0x91"</div>
<p>The Trojan also attempts to terminate the following processes:</p><pre>KAV
RAV
AVP
KAVSVC</pre>
<p>The Trojan also has worm functionality, making it able to propagate via removable storage media. The Trojan copies its executable file to the root of each drive as follows:</p>
<div class="pre">&lt;X&gt;:\n1deiect.com</div>
<p>&lt;X&gt; indicates the relevant disk.</p>
<p>In addition to its executable file, the Trojan also places the file shown below in the root directory of every disk:</p>
<div class="pre">&lt;x&gt;:\autorun.inf</div>
<p>This file will launch the Trojan executable file each time the user opens the infected disk using Explorer. </p>
<table class="enc_ttl" cellspacing="0" cellpadding="3" width="100%" border="0">
<tbody>
<tr>
<td klmark="virus_doctype:2"><b><a name="doc2">Removal instructions</a></b></td></tr></tbody></table>
<p>If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:</p>
<ol>
<li class="large">Delete the following file: 
<div class="pre">%System%\amvo.exe</div>
<li class="large">Reboot the computer. 
<li class="large">Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). 
<li class="large">Delete the following system registry key parameter: 
<div class="pre">[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] <br />"amva" = "%System%\amvo.exe"</div>
<li class="large">Restore the original system registry key values: 
<div class="pre">[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Fol<br />der\Hidden\SHOWALL]<br />"CheckedValue" = "0"<br />[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]<br />"Hidden" = "2"<br />"ShowSuperHidden" = "0"<br />[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Pocilies\Explorer]<br />"NoDriveTypeAutoRun" = "0x91"</div>
<li class="large">Delete the following file: 
<div class="pre">%System%\amvo0.dll</div>
<li class="large">Empty the temporary directory (%Temp%). 
<li class="large">Delete the files shown below from all removable disks: 
<div class="pre">&lt;X&gt;:\n1deiect.com</div>
<div class="pre">&lt;x&gt;:\autorun.inf</div>
<li class="large">&lt;x&gt; stands for the letter of the removable disk. </li></ol>
<p class="large">&nbsp;</p>]]>
        
    </content>
</entry>

<entry>
    <title>Trojan-PSW.Win32.OnLineGames.sxa</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/trojan-pswwin32onlinegamessxa.html" />
    <id>tag:avsecure.com,2008://1.11</id>

    <published>2008-12-30T19:11:50Z</published>
    <updated>2008-12-30T19:13:19Z</updated>

    <summary>This malicious program is a Trojan. It is a Windows PE EXE file. It is 118103 bytes in size. Installation The Trojan copies its executable file to the Windows system directory: %System%\kavo.exe In order to ensure that the Trojan is...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="trojanpswwin32onlinegamessxa" label="Trojan-PSW.Win32.OnLineGames.sxa" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>This malicious program is a Trojan. It is a Windows PE EXE file. It is 118103 bytes in size.</p>
<h3>Installation</h3>
<p>The Trojan copies its executable file to the Windows system directory: </p>
<div class="pre">%System%\kavo.exe</div>
<p>In order to ensure that the Trojan is launched automatically each time the system is restarted, the Trojan registers its executable file in the system registry:</p>
<div class="pre">[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]<br />"kava" = "%System%\kavo.exe"</div>
<p>The Trojan also extracts the file shown below from its body:</p>
<div class="pre">%System%\kavo0.dll</div>
<p>This file is 114176 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-GameThief.Win32.OnLineGames.szc.</p>
<p>The Trojan also extracts the file shown below from its body:</p>
<div class="pre">%Temp%\&lt;random symbols&gt;.dll</div>
<p>This file is 29815 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-GameThief.Win32.OnLineGames.stcw.</p>
<table class="enc_ttl" cellspacing="0" cellpadding="3" width="100%" border="0">
<tbody>
<tr>
<td klmark="virus_doctype:3"><b><a name="doc3">Payload</a></b></td></tr></tbody></table>
<p>The Trojan loads the .dll file to all processes launched in the system. </p>
<p>The Trojan intercepts mouse and keyboard events if any of the processes below have been launched: </p><pre>maplestory.exe
dekaron.exe
gc.exe
RagFree.exe
Ragexe.exe
ybclient.exe
wsm.exe 
sro_client.exe
so3d.exe
ge.exe
elementclient.exe</pre>
<p>It sniffs traffic sent to the following addresses:</p><pre>61.220.60.***
61.220.62.***
61.220.56.***
61.220.62.***
203.69.46.***
220.130.113.*** </pre>
<p>It does this in an attempt to harvest account data for the following games:</p><pre>ZhengTu
Wanmi Shijie or Perfect World
Dekaron Siwan Mojie
HuangYi Online
Rexue Jianghu
ROHAN
Seal Online
Maple Story
R2 (Reign of Revolution)
Talesweaver</pre>
<p>and some other games. The Trojan also analyses the configuration files of the games above and attempts to harvest information about gamers' accounts on the web 
<p>server. </p>
<p></p>Harvested data is sent to the remote malicious user's site. 
<p>The Trojan also modifies the following system registry key parameter values: </p>
<div class="pre">[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Fol<br />der\Hidden\SHOWALL] <br />"CheckedValue" = "0"<br />[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]<br />"Hidden" = "2"<br />"ShowSuperHidden" = "0"<br />[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Pocilies\Explorer]<br />"NoDriveTypeAutoRun" = "0x91"</div>
<p>The Trojan also attempts to terminate the following processes:</p><pre>KAV
RAV
AVP
KAVSVC</pre>
<p>The Trojan also has worm functionality, making it able to propagate via removable storage media. The Trojan copies its executable file to the root of each drive as follows:</p>
<div class="pre">&lt;X&gt;:\n6j.com</div>
<p>&lt;X&gt; indicates the relevant disk.</p>
<p>In addition to its executable file, the Trojan also places the file shown below in the root directory of every disk:</p>
<div class="pre">&lt;x&gt;:\autorun.inf</div>
<p>This file will launch the Trojan executable file each time the user opens the infected disk using Explorer. </p>
<table class="enc_ttl" cellspacing="0" cellpadding="3" width="100%" border="0">
<tbody>
<tr>
<td klmark="virus_doctype:2"><b><a name="doc2">Removal instructions</a></b></td></tr></tbody></table>
<p>If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:</p>
<ol>
<li class="large">Delete the following file: 
<div class="pre">%System%\kavo.exe</div>
<li class="large">Reboot the computer. 
<li class="large">Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). 
<li class="large">Delete the following system registry key parameter: 
<div class="pre">[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] <br />"kava" = "%System%\kavo.exe"</div>
<li class="large">Restore the original system registry key values: 
<div class="pre">[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Fol<br />der\Hidden\SHOWALL] <br />"CheckedValue" = "0"<br />[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]<br />"Hidden" = "2"<br />"ShowSuperHidden" = "0"<br />[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Pocilies\Explorer]<br />"NoDriveTypeAutoRun" = "0x91"</div>
<li class="large">Delete the following file: 
<div class="pre">%System%\kavo0.dll</div>
<li class="large">Empty the temporary directory (%Temp%). 
<li class="large">Delete the files shown below from all removable disks: 
<div class="pre">&lt;X&gt;:\n6j.com</div>
<div class="pre">&lt;x&gt;:\autorun.inf</div>
<p>&lt;x&gt; stands for the letter of the removable disk. </p></li></ol>
<p class="large">&nbsp;</p>]]>
        
    </content>
</entry>

<entry>
    <title>Trojan-Downloader.JS.Small.fi</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/trojan-downloaderjssmallfi.html" />
    <id>tag:avsecure.com,2008://1.10</id>

    <published>2008-12-30T19:08:49Z</published>
    <updated>2008-12-30T19:11:06Z</updated>

    <summary>This Trojan downloads other files via the Internet and launches them for execution on the victim machine. The program is an HTML page which contains Java Script scenarios. It is 1432 bytes in size. Payload The Trojan downloads a file...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="trojandownloaderjssmallfi" label="Trojan-Downloader.JS.Small.fi" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>This Trojan downloads other files via the Internet and launches them for execution on the victim machine. The program is an HTML page which contains Java Script scenarios. It is 1432 bytes in size.</p>
<table class="enc_ttl" cellspacing="0" cellpadding="3" width="100%" border="0">
<tbody>
<tr>
<td klmark="virus_doctype:3"><b><a name="doc3">Payload</a></b></td></tr></tbody></table>
<p>The Trojan downloads a file from the URL shown below by exploiting a vulnerability (CVE-2006-1359) in the processing of "createTextRange" in Microsoft Internet Explorer:</p>
<div class="pre">http://195.62.***.21/a.exe</div>
<p>The Trojan saves this file to its working directory as shown below:</p>
<div class="pre">%WorkDir%\a.exe</div>
<p>The downloaded file will then be launched for execution. </p>
<p>At the time of writing, the link was not active. </p>
<table class="enc_ttl" cellspacing="0" cellpadding="3" width="100%" border="0">
<tbody>
<tr>
<td klmark="virus_doctype:2"><b><a name="doc2">Removal instructions</a></b></td></tr></tbody></table>
<p>If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:</p>
<ol>
<li class="large">Use Task Manager to terminate the process shown below: 
<div class="pre">a.exe</div>
<li class="large">Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). 
<li class="large">Delete the following file: 
<div class="pre">%WorkDir%\a.exe</div>
<li class="large">Delete all files from %Temporary Internet Files%. 
<li class="large">Install the latest patches for Microsoft Internet Explorer. 
<li class="large">Update your antivirus databases and perform a full scan of the computer.</li></ol>]]>
        
    </content>
</entry>

<entry>
    <title>Bofra.A / MyDoom variant</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/bofraa-mydoom-variant.html" />
    <id>tag:avsecure.com,2008://1.9</id>

    <published>2008-12-30T19:07:01Z</published>
    <updated>2008-12-30T19:08:06Z</updated>

    <summary><![CDATA[Bofra.A / MyDoom&nbsp;variant h1 = document.getElementById("title").getElementsByTagName("h1")[0];h1.innerHTML = widont(h1.innerHTML); Exploits SHDOCVW.DLL flaw Note: Some vendors are referring to the Bofra worm as a variant of MyDoom, though even then there is disagreement as to which variant they claim it is. For...]]></summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="bofraamydoom" label="Bofra.A MyDoom" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<h1>Bofra.A / MyDoom&nbsp;variant</h1>
<script type="text/javascript">h1 = document.getElementById("title").getElementsByTagName("h1")[0];h1.innerHTML = widont(h1.innerHTML);</script>

<h2>Exploits SHDOCVW.DLL flaw</h2>
<p>Note: Some vendors are referring to the Bofra worm as a variant of MyDoom, though even then there is disagreement as to which variant they claim it is. For example, Symantec (who also calls the widely known Bagle worm the Beagle worm) initially dubbed the Bofra worm as MyDoom.AH then later changed their name to MyDoom.AI). Bofra.A is a mass-mailing email worm that arrives without an attachment and infects when the user clicks on an enticing link contained in the Bofra worm's message. The email link claims to point to an adult video or webcam photos. </p>
<p>Specifically, Bofra.A exploits a vulnerability in certain versions of SHDOCVW.DLL, a Windows operating system file that renders the IFRAME, FRAME, and EMBED HTML tags. 
<p>The vulnerable versions of SHDOCVW.DLL are found on Windows Xp (SP1 and below) and 2000 systems. Windows XP SP2 is not affected. 
<p>The vulnerability was first discovered on October 23, 2004 with first public release of exploit code on November 1, 2004. Bofra.A was discovered on November 8, 2004. 
<p>The From address in the email is spoofed and portions of the header may also be forged. The Subject line of the email will be one of the following: 
<ul>funny photos :) <br />hello <br />hey! <br />blank <br />random characters</ul>
<p>The Message Body varies and may be either of the following: 
<ul><a href=""><font color="#3366cc">FREE ADULT VIDEO! SIGN UP NOW!</font></a> <br />Look at my <a href=""><font color="#3366cc">homepage</font></a> with my last webcam photos</ul>
<p>The links point to a webpage on the infected host (via TCP port 1639) that exploits the SHDOCVW.DLL vulnerability and results in a buffer overflow condition in Internet Explorer. This allows shell code to execute, causing the local machine to download and execute the malicious file, thus becoming another infected host (and making the download site a perpetually moving target). 
<p>The Bofra worm searches the newly infected system for email addresses, sending the email to those found, thus repeating the process. 
<p>A second variant of the worm masquerades as a PayPal notice, claiming that PayPal has charged $175 to your account and providing a link to find 'details'. Of course, clicking the link infects the recipient's computer. <!--/gc--></p>]]>
        
    </content>
</entry>

<entry>
    <title>Storm Worm</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/storm-worm.html" />
    <id>tag:avsecure.com,2008://1.8</id>

    <published>2008-12-30T19:04:24Z</published>
    <updated>2008-12-30T20:49:59Z</updated>

    <summary>also known as Trojan-Downloader.Win32.Small.dam, Trojan.Downloader-647, Trojan.DL.Tibs.Gen!Pac13, Email-Worm.Win32.Zhelatin.a (Kaspersky), Downloader-BAI (McAfee), Troj/Dorf-Fam (Sophos), Trojan.Peacomm (Symantec), TROJ_SMALL.EDW (Trend Micro), Win32/Nuwar.N@MM (Microsoft). Type: Email worm, Trojan, Downloader Discovered: January 19, 2007 Method of Propagation: The Storm worm spreads via email, using a variety...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="stormworm" label="Storm Worm" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>also known as Trojan-Downloader.Win32.Small.dam, Trojan.Downloader-647, Trojan.DL.Tibs.Gen!Pac13, Email-Worm.Win32.Zhelatin.a (Kaspersky), Downloader-BAI (McAfee), Troj/Dorf-Fam (Sophos), Trojan.Peacomm (Symantec), TROJ_SMALL.EDW (Trend Micro), Win32/Nuwar.N@MM (Microsoft).</p>
<div class="pDsc"><span class="pCo">Type: </span>Email worm, Trojan, Downloader</div>
<div class="pDsc"><span class="pCo">Discovered: </span>January 19, 2007</div>
<div class="pDsc"><span class="pCo">Method of Propagation: </span>The Storm worm spreads via email, using a variety of subject lines and message text that may masquerade as news articles or other current events. For example, subject lines in the Storm email may be named one of the following: 
<p>A killer at 11, he's free at 21 and kill again! <br />U.S. Secretary of State Condoleezza Rice has kicked German Chancellor <br />Angela Merkel <br />British Muslims Genocide <br />Naked teens attack home director. <br />230 dead as storm batters Europe. <br />Radical Muslim drinking enemies's blood. <br />Chinese missile shot down Russian satellite <br />Saddam Hussein alive! <br />Venezuelan leader: "Let's the War beginning". <br />Fidel Castro dead.</p></div>
<div class="pDsc">
<p>The attachment carried by the Storm worm may be named one of the following: 
</p><p>FullVideo.exe <br />Full Story.exe <br />Video.exe <br />Read More.exe <br />FullClip.exe <br />GreetingPostcard.exe <br />MoreHere.exe <br />FlashPostcard.exe <br />GreetingCard.exe <br />ClickHere.exe <br />ReadMore.exe <br />FlashPostcard.exe <br />FullNews.exe</p></div>
<div class="pDsc"><span class="pCo">Symptoms of Infection: </span>
<p>Note: There are dozens of variants of the Storm worm. The following technical details may not apply to each of them. To determine whether a Storm worm infection is present, scan your systems with up-to-date <a href="http://antivirus.about.com/cs/beforeyoubuy/tp/aatpavwin.htm">antivirus software</a>.</p></div>
<div class="pDsc" id="pDscE">
<p><b>System Impact:</b> <br />The Storm email worm may drop the the file 'wincom32.exe' into the Windows system directory (typically, C:\Windows\System under Windows 95/98/ME, C:\Winnt\System32 under Windows NT/2000, and C:\Windows\System32 under Windows XP. 
</p><p>The Storm worm loads the dropped wincom32.exe as a device driver by modifying the registry as follows: <br />HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wincom32 
</p><p>This device driver injects a module into the services.exe process, sets up a peer-to-peer filesharing network on infected systems, and opens and listens for commands on UDP port 4000, 7871, and 11271. 
</p><p>The Storm worm then downloads files from various remote IP addresses and executes those files on the local system. 
</p><p><b>Removal Notes:</b> <br />The Storm worm is rootkit enabled and may hide files and processes associated with it and other malware it downloads. To remove the worm and other installed malware, scan the system using up-to-date antivirus software.</p></div><!--/gc-->]]>
        
    </content>
</entry>

<entry>
    <title>Troj/Pushdo-Gen</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/trojpushdo-gen.html" />
    <id>tag:avsecure.com,2008://1.7</id>

    <published>2008-12-30T19:01:55Z</published>
    <updated>2008-12-30T19:39:05Z</updated>

    <summary>Troj/Pushdo-Gen is a family of Trojans for the Windows platform.When members of Troj/Pushdo-Gen are installed they drop and run a further file in memory, usually detected as Troj/Pushu-Gen or Mal/Basine-C. This may then drop further files, including some of the...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="trojpushdogen" label="Troj/Pushdo-Gen" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>Troj/Pushdo-Gen is a family of Trojans for the Windows platform.<br /><br />When members of Troj/Pushdo-Gen are installed they drop and run a further file in memory, usually detected as Troj/Pushu-Gen or Mal/Basine-C. This may then drop further files, including some of the following:<br /><br />&lt;Windows&gt;\system32\drivers\ip6fw.sys<br />&lt;Windows&gt;\system32\drivers\netdtect.sys<br />&lt;System&gt;\drivers\runtime.sys<br />&lt;System&gt;\drivers\secdrv.sys<br /><br />These files are used to provide stealthing for the Trojan.<br /><br />The dropped file in memory will also often attempt to inject further code into Internet Explorer. </p>]]>
        
    </content>
</entry>

<entry>
    <title>W32/Netsky-P Worm</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/w32netsky-p-worm.html" />
    <id>tag:avsecure.com,2008://1.6</id>

    <published>2008-12-30T19:00:36Z</published>
    <updated>2008-12-30T19:05:58Z</updated>

    <summary>W32/Netsky-P is a mass-mailing worm which spreads by emailing itself to addresses harvested from files on the local drives. The worm will also copy itself to various peer-to-peer shared folders as the following files: 1001 Sex and more.rtf.exe3D Studio Max...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Computer Viruses" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="w32netskyp" label="W32/Netsky-P" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>W32/Netsky-P is a mass-mailing worm which spreads by emailing itself to addresses harvested from files on the local drives. </p>
<p>The worm will also copy itself to various peer-to-peer shared folders as the following files: </p>
<p><tt>1001 Sex and more.rtf.exe<br />3D Studio Max 6 3dsmax.exe<br />ACDSee 10.exe<br />Adobe Photoshop 10 crack.exe<br />Adobe Photoshop 10 full.exe<br />Adobe Premiere 10.exe<br />Ahead Nero 8.exe<br />Altkins Diet.doc.exe<br />American Idol.doc.exe<br />Arnold Schwarzenegger.jpg.exe<br />Best Matrix Screensaver new.scr<br />Britney sex xxx.jpg.exe<br />Britney Spears and Eminem porn.jpg.exe<br />Britney Spears blowjob.jpg.exe<br />Britney Spears cumshot.jpg.exe<br />Britney Spears fuck.jpg.exe<br />Britney Spears full album.mp3.exe<br />Britney Spears porn.jpg.exe<br />Britney Spears Sexy archive.doc.exe<br />Britney Spears Song text archive.doc.exe<br />Britney Spears.jpg.exe<br />Britney Spears.mp3.exe<br />Clone DVD 6.exe<br />Cloning.doc.exe<br />Cracks &amp; Warez Archiv.exe<br />Dark Angels new.pif<br />Dictionary English 2004 - France.doc.exe<br />DivX 8.0 final.exe<br />Doom 3 release 2.exe<br />E-Book Archive2.rtf.exe<br />Eminem blowjob.jpg.exe<br />Eminem full album.mp3.exe<br />Eminem Poster.jpg.exe<br />Eminem sex xxx.jpg.exe<br />Eminem Sexy archive.doc.exe<br />Eminem Song text archive.doc.exe<br />Eminem Spears porn.jpg.exe<br />Eminem.mp3.exe<br />Full album all.mp3.pif<br />Gimp 1.8 Full with Key.exe<br />Harry Potter 1-6 book.txt.exe<br />Harry Potter 5.mpg.exe<br />Harry Potter all e.book.doc.exe<br />Harry Potter e book.doc.exe<br />Harry Potter game.exe<br />Harry Potter.doc.exe<br />How to hack new.doc.exe<br />Internet Explorer 9 setup.exe<br />Kazaa Lite 4.0 new.exe<br />Kazaa new.exe<br />Keygen 4 all new.exe<br />Learn Programming 2004.doc.exe<br />Lightwave 9 Update.exe<br />Magix Video Deluxe 5 beta.exe<br />Matrix.mpg.exe<br />Microsoft Office 2003 Crack best.exe<br />Microsoft WinXP Crack full.exe<br />MS Service Pack 6.exe<br />netsky source code.scr<br />Norton Antivirus 2005 beta.exe<br />Opera 11.exe<br />Partitionsmagic 10 beta.exe<br />Porno Screensaver britney.scr<br />RFC compilation.doc.exe<br />Ringtones.doc.exe<br />Ringtones.mp3.exe<br />Saddam Hussein.jpg.exe<br />Screensaver2.scr<br />Serials edition.txt.exe<br />Smashing the stack full.rtf.exe<br />Star Office 9.exe<br />Teen Porn 15.jpg.pif<br />The Sims 4 beta.exe<br />Ulead Keygen 2004.exe<br />Visual Studio Net Crack all.exe<br />Win Longhorn re.exe<br />WinAmp 13 full.exe<br />Windows 2000 Sourcecode.doc.exe<br />Windows 2003 crack.exe<br />Windows XP crack.exe<br />WinXP eBook newest.doc.exe<br />XXX hardcore pics.jpg.exe</tt> </p>
<p>W32/Netsky-P harvests email addresses from files with the following extensions:<br />PL, HTM, HTML, EML, TXT, PHP, ASP, VBS, RTF, UIN, SHTM, CGI, DHTM, ADB, TBB, DBX, SHT, OFT, MSG, JSP, WSH, XML. </p>
<p>The worm has a trigger date of 24 March 2004, at which time it will attempt to mass mail. </p>
<p>Emails have the following characteristics (note that not all variations listed): </p>
<p><b>Subject lines:</b> constructed from the following groups of strings - </p>
<p>Re: Re:<br />Re: Encrypted Mail<br />Re: Extended Mail<br />Re: Status<br />Re: Notify<br />Re: SMTP Server<br />Re: Mail Server<br />Re: Delivery Server<br />Re: Bad Request<br />Re: Failure<br />Re: Thank you for delivery<br />Re: Test<br />Re: Administration<br />Re: Message Error<br />Re: Error<br />Re: Extended Mail System<br />Re: Secure SMTP Message<br />Re: Protected Mail Request<br />Re: Protected Mail System<br />Re: Protected Mail Delivery<br />Re: Secure delivery<br />Re: Delivery Protection<br />Re: Mail Authentification </p>
<p><b>Message texts:</b> chosen from - </p>
<p>Please confirm my request.<br />ESMTP [Secure Mail System #334]: Secure message is attached.<br />Partial message is available.<br />Waiting for a Response. Please read the attachment.<br />First part of the secure mail is available.<br />For more details see the attachment.<br />For further details see the attachment.<br />Your requested mail has been attached.<br />Protected Mail System Test.<br />Secure Mail System Beta Test.<br />Forwarded message is available.<br />Delivered message is attached.<br />Encrypted message is available.<br />Please read the attachment to get the message.<br />Follow the instructions to read the message.<br />Please authenticate the secure message.<br />Protected message is attached.<br />Waiting for authentification.<br />Protected message is available.<br />Bad Gateway: The message has been attached.<br />SMTP: Please confirm the attached message.<br />You got a new message.<br />Now a new message is available.<br />New message is available.<br />You have received an extended message. Please read the instructions. </p>
<p><b>Attachment description: </b>chosen from - </p>
<p>Your details.<br />Your document.<br />I have received your document. The corrected document is attached.<br />I have attached your document.<br />Your document is attached to this mail.<br />Authentication required.<br />Requested file.<br />See the file.<br />Please read the important document.<br />Please confirm the document.<br />Your file is attached.<br />Please read the document.<br />Your document is attached.<br />Please read the attached file!<br />Please see the attached file for details. </p>
<p>followed by - </p>
<p>&lt;attached filename&gt;: </p>
<p>+++ Attachment: No Virus found<br />+++ MessageLabs AntiVirus - www.messagelabs.com<br />+++ Attachment: No Virus found<br />+++ Bitdefender AntiVirus - www.bitdefender.com<br />+++ Attachment: No Virus found<br />+++ MC-Afee AntiVirus - www.mcafee.com<br />+++ Attachment: No Virus found<br />+++ Kaspersky AntiVirus - www.kaspersky.com<br />+++ Attachment: No Virus found<br />+++ Panda AntiVirus - www.pandasoftware.com<br />++++ Attachment: No Virus found<br />++++ Norman AntiVirus - www.norman.com<br />++++ Attachment: No Virus found<br />++++ F-Secure AntiVirus - www.f-secure.com<br />++++ Attachment: No Virus found<br />++++ Norton AntiVirus - www.symantec.de </p>
<p><b>Attached file:</b> </p>
<p>&lt;filename&gt;_ &lt;recipient_name&gt;.&lt;extension&gt; </p>
<p>&lt;filename&gt; chosen from: </p>
<p>document_all<br />message<br />excel document<br />word document<br />screensaver<br />application<br />website<br />product<br />letter<br />information<br />details<br />document </p>
<p>&lt;extension&gt; chosen from: </p>
<p>EXE<br />SCR<br />PIF<br />ZIP </p>
<p>W32/Netsky-P attempts to delete registry entries which may be set by variants of the W32/Mydoom and W32/Bagle worms. </p>
<p>W32/Netsky-P also creates a number of the TMP files in the Windows folder: base64.tmp, zip1.tmp, zip2.tmp, zip3.tmp, zipped.tmp. <b>NOTE: The information contained in this analysis may be considered offensive by some customers.</b> </p>
<p>W32/Netsky-P is a mass-mailing worm which spreads by emailing itself to addresses harvested from files on the local drives. </p>
<p>The worm copies itself to the Windows folder as FVProtect.exe and adds the following registry entry to run itself whenever the user logs on to the computer: </p>
<p>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Norton Antivirus AV<br />= &lt;Windows&gt;\FVProtect.exe </p>
<p>The worm will also copy itself to various peer-to-peer shared folders as the following files: </p>
<p><tt>1001 Sex and more.rtf.exe<br />3D Studio Max 6 3dsmax.exe<br />ACDSee 10.exe<br />Adobe Photoshop 10 crack.exe<br />Adobe Photoshop 10 full.exe<br />Adobe Premiere 10.exe<br />Ahead Nero 8.exe<br />Altkins Diet.doc.exe<br />American Idol.doc.exe<br />Arnold Schwarzenegger.jpg.exe<br />Best Matrix Screensaver new.scr<br />Britney sex xxx.jpg.exe<br />Britney Spears and Eminem porn.jpg.exe<br />Britney Spears blowjob.jpg.exe<br />Britney Spears cumshot.jpg.exe<br />Britney Spears fuck.jpg.exe<br />Britney Spears full album.mp3.exe<br />Britney Spears porn.jpg.exe<br />Britney Spears Sexy archive.doc.exe<br />Britney Spears Song text archive.doc.exe<br />Britney Spears.jpg.exe<br />Britney Spears.mp3.exe<br />Clone DVD 6.exe<br />Cloning.doc.exe<br />Cracks &amp; Warez Archiv.exe<br />Dark Angels new.pif<br />Dictionary English 2004 - France.doc.exe<br />DivX 8.0 final.exe<br />Doom 3 release 2.exe<br />E-Book Archive2.rtf.exe<br />Eminem blowjob.jpg.exe<br />Eminem full album.mp3.exe<br />Eminem Poster.jpg.exe<br />Eminem sex xxx.jpg.exe<br />Eminem Sexy archive.doc.exe<br />Eminem Song text archive.doc.exe<br />Eminem Spears porn.jpg.exe<br />Eminem.mp3.exe<br />Full album all.mp3.pif<br />Gimp 1.8 Full with Key.exe<br />Harry Potter 1-6 book.txt.exe<br />Harry Potter 5.mpg.exe<br />Harry Potter all e.book.doc.exe<br />Harry Potter e book.doc.exe<br />Harry Potter game.exe<br />Harry Potter.doc.exe<br />How to hack new.doc.exe<br />Internet Explorer 9 setup.exe<br />Kazaa Lite 4.0 new.exe<br />Kazaa new.exe<br />Keygen 4 all new.exe<br />Learn Programming 2004.doc.exe<br />Lightwave 9 Update.exe<br />Magix Video Deluxe 5 beta.exe<br />Matrix.mpg.exe<br />Microsoft Office 2003 Crack best.exe<br />Microsoft WinXP Crack full.exe<br />MS Service Pack 6.exe<br />netsky source code.scr<br />Norton Antivirus 2005 beta.exe<br />Opera 11.exe<br />Partitionsmagic 10 beta.exe<br />Porno Screensaver britney.scr<br />RFC compilation.doc.exe<br />Ringtones.doc.exe<br />Ringtones.mp3.exe<br />Saddam Hussein.jpg.exe<br />Screensaver2.scr<br />Serials edition.txt.exe<br />Smashing the stack full.rtf.exe<br />Star Office 9.exe<br />Teen Porn 15.jpg.pif<br />The Sims 4 beta.exe<br />Ulead Keygen 2004.exe<br />Visual Studio Net Crack all.exe<br />Win Longhorn re.exe<br />WinAmp 13 full.exe<br />Windows 2000 Sourcecode.doc.exe<br />Windows 2003 crack.exe<br />Windows XP crack.exe<br />WinXP eBook newest.doc.exe<br />XXX hardcore pics.jpg.exe</tt> </p>
<p>W32/Netsky-P harvests email addresses from files with the following extensions:<br />PL, HTM, HTML, EML, TXT, PHP, ASP, VBS, RTF, UIN, SHTM, CGI, DHTM, ADB, TBB, DBX, SHT, OFT, MSG, JSP, WSH, XML. </p>
<p>The worm has a trigger date of 24 March 2004, at which time it will attempt to mass mail. </p>
<p>Emails have the following characteristics (note that not all variations listed): </p>
<p><b>Subject lines:</b> constructed from the following groups of strings -<br />Re: Re:<br />Re: Encrypted Mail<br />Re: Extended Mail<br />Re: Status<br />Re: Notify<br />Re: SMTP Server<br />Re: Mail Server<br />Re: Delivery Server<br />Re: Bad Request<br />Re: Failure<br />Re: Thank you for delivery<br />Re: Test<br />Re: Administration<br />Re: Message Error<br />Re: Error<br />Re: Extended Mail System<br />Re: Secure SMTP Message<br />Re: Protected Mail Request<br />Re: Protected Mail System<br />Re: Protected Mail Delivery<br />Re: Secure delivery<br />Re: Delivery Protection<br />Re: Mail Authentification </p>
<p><b>Message texts:</b> chosen from - </p>
<p>Please confirm my request.<br />ESMTP [Secure Mail System #334]: Secure message is attached.<br />Partial message is available.<br />Waiting for a Response. Please read the attachment.<br />First part of the secure mail is available.<br />For more details see the attachment.<br />For further details see the attachment.<br />Your requested mail has been attached.<br />Protected Mail System Test.<br />Secure Mail System Beta Test.<br />Forwarded message is available.<br />Delivered message is attached.<br />Encrypted message is available.<br />Please read the attachment to get the message.<br />Follow the instructions to read the message.<br />Please authenticate the secure message.<br />Protected message is attached.<br />Waiting for authentification.<br />Protected message is available.<br />Bad Gateway: The message has been attached.<br />SMTP: Please confirm the attached message.<br />You got a new message.<br />Now a new message is available.<br />New message is available.<br />You have received an extended message. Please read the instructions. </p>
<p><b>Attachment description: </b>chosen from - </p>
<p>Your details.<br />Your document.<br />I have received your document. The corrected document is attached.<br />I have attached your document.<br />Your document is attached to this mail.<br />Authentication required.<br />Requested file.<br />See the file.<br />Please read the important document.<br />Please confirm the document.<br />Your file is attached.<br />Please read the document.<br />Your document is attached.<br />Please read the attached file!<br />Please see the attached file for details. </p>
<p>followed by - </p>
<p>&lt;attached filename&gt;: </p>
<p>+++ Attachment: No Virus found<br />+++ MessageLabs AntiVirus - www.messagelabs.com<br />+++ Attachment: No Virus found<br />+++ Bitdefender AntiVirus - www.bitdefender.com<br />+++ Attachment: No Virus found<br />+++ MC-Afee AntiVirus - www.mcafee.com<br />+++ Attachment: No Virus found<br />+++ Kaspersky AntiVirus - www.kaspersky.com<br />+++ Attachment: No Virus found<br />+++ Panda AntiVirus - www.pandasoftware.com<br />++++ Attachment: No Virus found<br />++++ Norman AntiVirus - www.norman.com<br />++++ Attachment: No Virus found<br />++++ F-Secure AntiVirus - www.f-secure.com<br />++++ Attachment: No Virus found<br />++++ Norton AntiVirus - www.symantec.de </p>
<p><b>Attached file:</b> </p>
<p>&lt;filename&gt;_ &lt;recipient_name&gt;.&lt;extension&gt; </p>
<p>&lt;filename&gt; chosen from: </p>
<p>document_all<br />message<br />excel document<br />word document<br />screensaver<br />application<br />website<br />product<br />letter<br />information<br />details<br />document </p>
<p>&lt;extension&gt; chosen from: </p>
<p>EXE<br />SCR<br />PIF<br />ZIP </p>
<p>W32/Netsky-P attempts to delete registry entries which may be set by variants of the W32/Mydoom and W32/Bagle worms. </p>
<p>W32/Netsky-P also creates a number of the TMP files in the Windows folder: base64.tmp, zip1.tmp, zip2.tmp, zip3.tmp, zipped.tmp. </p>]]>
        
    </content>
</entry>

<entry>
    <title>F-Secure Anti-Virus 2009</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/f-secure-anti-virus-2009.html" />
    <id>tag:avsecure.com,2008://1.5</id>

    <published>2008-12-30T18:13:17Z</published>
    <updated>2008-12-30T18:17:49Z</updated>

    <summary>An average of ten new viruses and spyware are found each day and the rate continues to grow. There is also a new breed of threats on the Internet, such as carefully planned targeted attacks that can pass through conventional...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Antivirus Software" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="fsecureantivirus2009" label="F-Secure Anti-Virus 2009" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>An average of ten new viruses and spyware are found each day and the rate continues to grow. There is also a new breed of threats on the Internet, such as carefully planned targeted attacks that can pass through conventional security solutions unnoticed, possibly taking over your computer for illegal purposes.</p>
<p>F-Secure Anti-Virus 2009 comes with F-Secure DeepGuard™ 2.0, introducing network-based instant recognition of both safe and malicious software, which is able to protect you in 60 seconds from the first confirmation of a new threat. No other antivirus vendor has such "in-the-cloud" real-time protection network deployed globally.<br />With F-Secure® Anti-Virus 2009, you can open e-mail attachments and use your computer without any fear of virus infections, spyware intrusion or malicious programs that can take over your computer. In addition, F-Secure DeepGuard™ 2.0 provides instant protection against new threats with real-time protection network that shortcuts the hours it typically takes to send out database updates.</p>
<li><strong>Quicker where it matters <br /></strong>NEW! Quick and easy installation, faster boot-up times and faster scanning and cleaning of files. <br />
<li><strong>Protects your computer against viruses, worms and unknown attacks</strong> <br />With daily automatically updated virus protection from world-renowned F-Secure Data Security Laboratory and F-Secure DeepGuard 2.0 technology that instantly protects you against zero-day attacks and other future threats, you can safely use your computer, now and tomorrow. <br />
<li><strong>Detects and removes spyware from your computer</strong> <br />F-Secure Anti-Virus detects and removes secretly installed software from your computer better than ever before, ensuring that your system is running smoothly and clean of spyware. <br />
<li><strong>Fastest Protection</strong> <br />F-Secure is one of the leading antivirus vendors when it comes to reaction times and update delivery times during virus outbreaks. </li>
<p>&nbsp;</p>
<p><font style="FONT-SIZE: 1.56em"><strong>F-Secure Anti-Virus 2009</strong></font></p>
<p>Advanced Virus Protection for Your Online Life<br />With F-Secure® Anti-Virus™ 2009, you can use your computer without any<br />fear of virus infections, spyware intrusion or malicious programs that can take<br />over your computer. F-Secure Anti-Virus has been designed to automate all key<br />tasks required to keep your computer and data safe from viruses. It's so easy<br />all you have to do is install and forget it.<br />DeepGuard 2.0 - Protect Yourself Against the Unknown<br />Fast-spreading hidden attacks designed by money-driven online criminals are a<br />major problem on the Internet. F-Secure Anti-Virus 2009 comes with updated<br />DeepGuard 2.0 technology that automatically protects you against anything<br />that might be a sign of danger in your computer. The new version also<br />introduces instant recognition of both safe and potentially bad software which<br />makes the technology virtually unnoticeable and more accurate than ever.<br />Protect your Privacy with Antispyware<br />Spyware can secretly track your surfing habits and profile your shopping<br />preferences. It can even hijack your web browser or abuse your Internet<br />connection by sending data to a third party. F-Secure Anti-Virus protects your<br />privacy by detecting and removing such software from your computer.<br />The Fastest Protection with Automatic Updates<br />Antivirus software is only as good as the capability of antivirus software<br />manufacturer to provide a timely cure for new virus outbreaks. F-Secure<br />Anti-Virus Research Team updates virus definition databases several times a<br />day to ensure that customers have 24-hour protection against new,<br />fast-spreading viruses. This is why F-Secure products constantly rank at the top<br />when compared with competing products.</p>
<p>Protects your computer against<br />viruses, worms and other attacks<br />With daily automatically updated<br />virus protection from the<br />world-renowned F-Secure Data<br />Security Laboratory and F-Secure<br />DeepGuard technology that<br />protects you against zero-day<br />attacks and other future threats, you<br />can safely use your computer, now<br />and tomorrow.<br />Detects and removes spyware from<br />your computer<br />F-Secure Anti-Virus removes secretly<br />installed software from your<br />computer, ensuring that your system<br />is running smoothly and clean of<br />spyware.<br />Fastest Protection<br />F-Secure is one of the leading<br />antivirus vendors when it comes to<br />reaction times and update delivery<br />times during virus outbreaks.</p>
<p>Protection Against Unknown Threats and Rootkits<br />Modern malware can break into your computer even if you have<br />up-to-date security components installed. F-Secure DeepGuard™ detects<br />and prevents any suspicious activity that might indicate a danger in<br />your computer. Rootkits are also detected and removed.<br />Scans E-mail and Web Traffic<br />POP3, IMAP and SMTP traffic are scanned for viruses so that you do<br />not have to worry about infected e-mails. Web Traffic Scanning<br />protects you against web sites that can infect your computer even if you<br />do not download anything from them.<br />Easy to Install and Use<br />F-Secure Anti-Virus is extremely easy to install and use. As the software<br />is highly automated, you do not have to understand the complexities of<br />data security.<br />The Fastest Protection Against Virus Outbreaks<br />Immediate reaction times and fast cures during new and emerging<br />threats ensured by F-Secure Research Team working 24 hours a day.<br />Security News<br />Get information about new viruses and their behavior immediately, as<br />well as the instructions on how to avoid the infection and a confirmation<br />whether your computer is already protected against the latest threat.<br />Multiple Scanning Engines<br />F-Secure Anti-Virus uses multiple scanning engines, bringing you the very<br />best in detection and disinfection. Each scanning engine specializes in<br />detecting a different type of malware. It is like having several antivirus<br />products running in your computer at the same time!<br />Software in your Language<br />F-Secure Anti-Virus has a clear user interface, including an easily<br />accessible electronic manual. Both the software and electronic manual<br />are available in your language.</p>
<p>F-Secure Anti-Virus is a great product that offers many of the standard functions associated with antivirus software, but also goes above and beyond the bar set by others with efforts by F-Secure to educate the people that use F-Secure Anti-Virus on general security practices as well as specific threats.</p>
<p>F-Secure Anti-Virus is one of the most effective antivirus programs on the market. Its heuristic scanner is considered by many to be one of the fastest and most complete on the market.</p>
<p>We did have some problems with its on-access scanner though. The test system we used is a pretty fast system. Intel Pentium D 2.8GHz with 1GB of RAM. The on-access scanner would sometimes bring this system to a halt when opening programs or moving files. </p>
<p>F-Secure Anti-Virus comes with the standard protection you would expect from any modern antivirus suite. Both on-access and on-demand scanners are included as well as a spyware scanner that runs with both. An email scanner is also included for those of us using local email clients like Outlook or Thunderbird.</p>
<p>One feature we especially liked about F-Secure Anti-Virus was the integrated news on the home menu. The Security News section is full of useful information about which new security threats are out and whether you are protected from each threat. <br /></p>]]>
        
    </content>
</entry>

<entry>
    <title>AVG Anti-Virus 8 &amp; Anti-Spyware</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/avg-anti-virus-anti-spyware.html" />
    <id>tag:avsecure.com,2008://1.4</id>

    <published>2008-12-30T18:05:56Z</published>
    <updated>2008-12-30T18:12:44Z</updated>

    <summary>Antivirus and antispyware protection for Windows from the world&apos;s most trusted security company. Use the Internet with confidence in your home or small office. Easy to download, install and use Protection against viruses, spyware, adware, worms and trojans Real-time security...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Antivirus Software" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="antispyware" label="Anti-Spyware" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="avgantivirus" label="AVG Anti-Virus" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p><strong>Antivirus and antispyware protection for Windows from the world's most trusted security company. Use the Internet with confidence in your home or small office.</strong></p><strong>
<li>Easy to download, install and use 
<li>Protection against viruses, spyware, adware, worms and trojans 
<li>Real-time security while you surf and chat online 
<li>Top-quality protection that does not slow your system down 
<li>Free support and service around the clock and across the globe 
<li>Compatible with <b>Windows Vista</b> and Windows XP</li>
<p>&nbsp;</p>
<p>Integrated protection</p>
<ul>
<li><b>Anti-Virus:</b>&nbsp;protection against viruses, worms and trojans 
<li><b>Anti-Spyware:</b>&nbsp;protection against spyware, adware and identity-theft 
<li><b>Anti-Rootkit:</b>&nbsp;protection against hidden threats (rootkits) 
<li><b>Web Shield&nbsp;&amp;&nbsp;LinkScanner:</b>&nbsp;protection against malicious websites </li></ul>
<h2 class="prdhdr shield">Easy-to-use, automated protection</h2>
<p>Real-time protection, automatic updates, low-impact background scanning for on-line threats, and instant quarantining or removal of infected files ensures maximum protection. Every interaction between your computer and the Internet is monitored, so nothing can get onto your system without your knowledge. AVG scans in real time:</p>
<ul>
<li>All files including documents, pictures and applications 
<li>E-mails (all major email clients supported) 
<li>Instant messaging and P2P communications 
<li>File downloads and online transactions such as shopping and banking 
<li>Search results and any other links you click on </li></ul>
<h2 class="prdhdr world">Internet use with peace of mind</h2>
<p>The new web shield checks every web page at the moment you click on the link to ensure you're not hit by a stealthy drive-by download or any other exploits. All links on search results pages in Google, Yahoo, and MSN are analyzed and their current threat level is reported in real time before you click on the link and visit the site.</p>
<h2 class="prdhdr tick_alt">The best Windows protection - trusted by millions of users</h2>
<p>AVG's award-winning antivirus technology protects millions of users and is certified by major antivirus testing organizations (VB100%, ICSA, West Coast Labs Checkmark). </p>
<h2 class="prdhdr save">No hidden costs</h2>
<p>When you purchase an AVG product, <b>everything you need is included</b> in the price for the full license duration - technical support, virus updates, and new program versions. All users of paid AVG products also qualify for <b>generous discounts</b> on subscription renewals and product upgrades.</p>
<h2 class="prdhdr lic">Flexible licensing</h2>
<ul>
<li>AVG Anti-Virus can be purchased online in license packs for 1-10 computers. 
<li>One or two year subscriptions available.</li></ul>
<p>&nbsp;</p></strong>]]>
        
    </content>
</entry>

<entry>
    <title>BitDefender Antivirus 2009</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/bitdefender-antivirus-2009.html" />
    <id>tag:avsecure.com,2008://1.3</id>

    <published>2008-12-30T17:59:22Z</published>
    <updated>2008-12-30T18:04:22Z</updated>

    <summary><![CDATA[Superior Proactive Protection from Viruses, Spyware, and other e-Threats...that won't slow you down! &nbsp; Confidently download, share and open files from friends, family, co-workers - and even total strangers! Improved: Scans all web, e-mail and instant messaging traffic for viruses...]]></summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Antivirus Software" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="bitdefenderantivirus2009" label="BitDefender Antivirus 2009" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>Superior Proactive Protection from Viruses, Spyware, and other e-Threats...that won't slow you down! </p>
<p>&nbsp;</p>
<p><strong>Confidently download, share and open files from friends, family, co-workers - and even total strangers!</strong> </p>
<ul id="redsquare">
<li><b>Improved:</b> Scans all web, e-mail and instant messaging traffic for viruses and spyware, in real-time 
<li>Proactively protects against new virus outbreaks using advanced heuristics </li></ul>
<p><br /><br /><b>Protect your identity: shop, bank, listen, watch privately and securely</b> </p>
<ul id="redsquare">
<li>Blocks attempted identity theft (phishing) 
<li><b>Improved:</b> Prevents personal information from leaking via e-mail, web or instant messaging </li></ul>
<p><br /><br /><b>Guard your conversations with top-of-the line encryption</b> </p>
<ul id="redsquare">
<li><b><sup><span style="COLOR: #ab2e36">NEW</span></sup></b>Instant Messaging Encryption </li></ul>
<p><br /><br /><b>Play safe, play seamlessly!</b> </p>
<ul id="redsquare">
<li><b>Improved:</b> Reduces the system load and avoids requesting user interaction during games </li></ul>
<p><br /><br /><b>Get fine-tuned performance from your computer !</b> </p>
<ul id="redsquare">
<li>Uses few system resources 
<li><b><sup><span style="COLOR: #ab2e36">NEW</span></sup></b>Laptop mode prolongs battery life 
<li><b>Improved:</b> Scans all web, e-mail and instant messaging traffic for viruses and spyware, in real-time 
<li>Proactively protects against new virus outbreaks using advanced heuristics </li></ul><a name="more_features"></a>
<h2>Features and Benefits</h2>
<div align="right">&nbsp;</div>
<p><b>Family network protection</b><br />Manage the security of your home network from a single location. BitDefender software from other computers in the network can be remotely configured, while tasks such as scans, backups tune-ups and updates can be run on-demand or scheduled to run during off-hours. <br /><br /><b>Hassle - Free Hourly Updates </b><br />Hourly updates ensure that you are protected against the latest threats without pushing a button. Lost program files are not a problem either. In the rare event of file damage due to PC problems, BitDefender automatically repairs and updates itself.<br /><br /></p>
<p itxtvisited="1">For those seeking the best antivirus software for the money AND an "install and forget" proposition, BitDefender is the right choice. Not only does it protect your computer and files, but BitDefender is easy to use, light on your computer and, maybe most importantly, light on your pocketbook.</p>
<p itxtvisited="1">No matter how technically capable any piece of software may be, the productivity enhancement it offers is only effective if people use it. This is especially true in antivirus software. The primary reasons people fail to protect their computers from a variety of malware are the cost and the 'burden' of installing and maintaining antivirus software. The best protection in the world is worthless if people find it cumbersome and distracting to use.</p>
<p itxtvisited="1">The same holds true for price. This is the beauty of BitDefender: It provides comprehensive protection, takes up little space on your computer, costs less and requires little maintenance. </p>
<p class="underheader" itxtvisited="1">You might think antivirus software that's this easy to use and this inexpensive might not be as effective as products with bigger brand names and bigger price tags, but you would be wrong. AV-Test.org is among the most prestigious, independent research laboratories in the world for testing antivirus software. In recent tests, BitDefender received their highest rating for having removed 98% of all viruses and spyware in their rigorous tests. In addition, BitDefender has received the highest ratings for effectiveness by Virus Bulletin (VB100%) and AV Comparatives.org, and was certified by ICSA, Checkvir.com and West Coast Labs for its ability to detect viruses and virus replication while minimizing false positives (detecting viruses that are not there).</p>
<p itxtvisited="1">One of the key features BitDefender has developed is a virtual machine that runs invisibly in the background on your computer where it tests suspicious code, which is code that looks like a virus but doesn't currently match any of the known virus signatures. In this way, BitDefender can protect your computer from viruses no one has reported yet. In the same tests by AV-Test.org, BitDefender scored higher than Kaspersky, Norton, Computer Associates (CA) and McAfee on its proactive detection of viruses and other malware with this heuristic approach. BitDefender scans somewhat slower than some of its competitors, due (we believe) to this virtual machine running. Naturally, there's going to be a price for this type of protection, but other products like ESET's NOD32 have done a better job at minimizing it.</p>
<p itxtvisited="1">Although BitDefender is great at removing viruses and spyware, it excels at protecting your system from incoming viruses. The new BitDefender can actually strip viruses from your incoming HTML stream before the virus makes it to your browser. We think every new computer should be outfitted with this kind of protection.</p>
<p class="underheader" itxtvisited="1">In the spirit of "install and forget" software, BitDefender doesn't go in for the blinking red and green lights to notify you of its activity. Instead, a tiny red and black icon appears in the lower-right corner of your desktop, just above the system tray. This unobtrusive icon is the scan activity monitor. A green line indicates when files are being scanned for viruses and spyware. You can remove the monitor by going into the configuration settings.</p>
<p itxtvisited="1">The antispyware section of BitDefender includes Privacy Protection. This feature is disabled by default, but turning this feature ON is recommended. In the Advanced Setting link, you can enter your credit card numbers or other private information, and if any Windows application attempts to send these over the Internet, it stops and requires your active permission. Otherwise, BitDefender will refuse any program that attempts to send your personal information over the Internet.</p>
<p itxtvisited="1">BitDefender is the only antivirus software reviewed with a gamer mode. With gamer mode enabled, online gamers are protected without sacrificing much performance. Since online gamers are notorious for disabling firewalls and other protection to optimize performance, this could be a lifesaver for the family computer used for online gaming by members of your household.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Kaspersky Anti-Virus 2009</title>
    <link rel="alternate" type="text/html" href="http://avsecure.com/2008/12/kaspersky-anti-virus-2009.html" />
    <id>tag:avsecure.com,2008://1.2</id>

    <published>2008-12-30T17:51:03Z</published>
    <updated>2008-12-30T18:04:47Z</updated>

    <summary>Kaspersky Anti-Virus 2009 provides the basic tools needed to protect your PC. Installation of a separate firewall and anti-spam filter is recommended. Virus Essential Protection Protects from viruses, Trojans and worms Blocks spyware and adware Scans files in real time...</summary>
    <author>
        <name>AV Secure</name>
        
    </author>
    
        <category term="Antivirus Software" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="kasperskyantivirus2009" label="Kaspersky Anti-Virus 2009" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-US" xml:base="http://avsecure.com/">
        <![CDATA[<p>Kaspersky Anti-Virus 2009 provides the basic tools needed to protect your PC. Installation of a separate firewall and anti-spam filter is recommended.</p>
<h2>Virus Essential Protection</h2>
<ul>
<li>Protects from viruses, Trojans and worms 
<li>Blocks spyware and adware 
<li>Scans files in real time (on access) and on demand 
<li>Scans email messages (regardless of email client) 
<li>Scans Internet traffic (regardless of browser) 
<li>Protects instant messengers (ICQ, MSN) 
<li>Provides proactive protection from unknown threats 
<li>Scans Java and Visual Basic scripts </li></ul>
<h2>Preventive Protection from Viruses</h2>
<ul>
<li>Scans operating system and installed applications for vulnerabilities 
<li>Analyzes and closes Internet Explorer vulnerabilities 
<li>Disables links to malware sites 
<li>Detects viruses based on the packers used to compress code 
<li>Global threat monitoring (Kaspersky Security Network) </li></ul>
<h2>Advanced Protection &amp; Recovery</h2>
<ul>
<li>The program can be installed on infected computers 
<li>Self-protection from being disabled or stopped 
<li>Restores correct system settings after removing malicious software 
<li>Tools for creating a rescue disk </li></ul>
<h2>Data &amp; Identity Theft Protection</h2>
<ul>
<li>Disables links to fake (phishing) websites 
<li>Blocks all types of keyloggers </li></ul>
<h2>Usability</h2>
<ul>
<li>Automatic configuration during installation 
<li>Wizards for common tasks 
<li>Visual reports with charts and diagrams 
<li>Alerts provide all the information necessary for informed user decisions 
<li>Automatic or interactive mode 
<li>Round-the-clock technical support 
<li>Automatic database updates </li></ul>
<p>Kaspersky Labs has been one of the best antivirus software developers in the world for over a decade and now Kaspersky Anti-Virus 2009 only strengthens that reputation. Founded by Natalia and Eugene Kaspersky in 1997, this Russian company is often the first to find and identify new viruses. Long used in Russia and Europe, Kaspersky is now making inroads in the North American market. Kaspersky Anti-Virus 2009 is one of the most effective antivirus packages in the world today and boasts a great interface with easy to use and intuitive controls. </p>
<p>Kaspersky Labs has always been known for its ability to effectively detect and remove viruses as well as or better than any software program on the market. Like BitDefender, Kaspersky was able to remove over 98% of all viruses it encountered in the most recent&nbsp; objective tests of AV-test.org. Kaspersky is also certified by all of the major virus/malware testing laboratories. Tests confirm Kaspersky's effectiveness. It found every virus on the test computer. </p>
<p>Although Kaspersky is excellent at detecting viruses and malware, it could use some work in the detection of spyware. Independent tests by AV-test.org showed that Kaspersky allowed 8% of adware/spyware to go undetected. Furthermore, Kaspersky's proactive/heuristic engine failed to meet the high standards set by BitDefender, NOD32, F-Secure, Panda and some others. </p>
<p>Like other software with proactive/heuristic engines to detect malware before their signatures are available, Kaspersky's scan is relatively slow. The time and resources demanded by these proactive/heuristic engines slows these scans, and relatively slow scans may be the price we pay for this level of protection. Of the antivirus software packages reviewed, only NOD32 scored high on both proactive detection and scan speed.&nbsp; <br /></p>
<p>Kaspersky's feature set is one of its strongest assets. While BitDefender's interface is primarily an enable/disable feature set, Kaspersky is the software-tweakers dream with controls for nearly all of its features. Like most of the antivirus packages in our review, Kaspersky protects your computer from spyware as well as viruses. Scanning for both viruses and spyware simultaneously is far more efficient in terms of time and resources than stopping to do both separately.&nbsp;Kaspersky scans email and port 80 traffic (port 80 is the port that receives web traffic and must be open while browsing the web) so that this excellent software can detect and block online viruses, Trojans, and various other malware before they can cause you trouble. </p>
<p>Kaspersky also has a proactive defense for your computer. Kaspersky watches for unwanted adware, dialers, rootkits, remote access utilities and locks specific registry keys that malicious code may target to damage your computer. Furthermore, Kaspersky now includes protection from viruses while using IM and ICQ. </p>
<p>Kaspersky, in its ever-vigilance against viruses and other malware, now helps you create a rescue disc in the case that your computer is hit by some malicious code that makes your system unbootable. Although this effort to prepare users for the computer equivalent of Armageddon is commendable, the process is tedious and difficult. If you downloaded your operating system or the system disc is lost or unavailable, this feature will be unavailable to you. <br /></p>]]>
        
    </content>
</entry>

</feed>

