<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Spyware Stop !</title>
	<link>http://spywarestop.net</link>
	<description>Keep away spyware and trojans! Everything about viruses and methods of competing against !</description>
	<pubDate>Mon, 16 Jul 2007 12:08:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.3</generator>
	<language>en</language>
			<item>
		<title>Trojan-Downloader.Win32.Apher.a</title>
		<link>http://spywarestop.net/?p=529</link>
		<comments>http://spywarestop.net/?p=529#comments</comments>
		<pubDate>Mon, 16 Jul 2007 12:03:03 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>General</category>
	<category>Safety Tips</category>
	<category>Product News</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>antispyware</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=529</guid>
		<description><![CDATA[Aliases:
Trojan-Downloader.Win32.Apher.a (Kaspersky Lab) is also known as: TrojanDownloader.Win32.Apher.a (Kaspersky Lab), Downloader.cfg (McAfee),   Download.Trojan (Symantec),   Trojan.Aphex.10 (Doctor Web),   Troj/WebDL (Sophos),   TrojanDownloader:Win32/Apher.A (RAV),   TROJ_APHER.A (Trend Micro),   Win32:Trojan-gen. (ALWIL),   Downloader.Apher (Grisoft),   Trojan.Downloader.Apher.A (SOFTWIN),   Trj/W32.Apher (Panda),   Win32/TrojanDownloader.Apher.A (Eset)
Description added       Aug 29 2002
Behavior                    TrojanDownloader 
Technical details:
Apher is malware virus in the wild that spreads as an attachment to spoofed e-mails [...]]]></description>
			<content:encoded><![CDATA[<p>Aliases:<br />
<strong>Trojan-Downloader.Win32.Apher.a</strong> (<em>Kaspersky Lab</em>) is also known as: <strong>TrojanDownloader.Win32.Apher.a</strong> (<em>Kaspersky Lab</em>), <strong>Downloader.cfg</strong> (<em>McAfee</em>),   <strong>Download.Trojan</strong> (<em>Symantec</em>),   <strong>Trojan.Aphex.10</strong> (<em>Doctor Web</em>),   <strong>Troj/WebDL</strong> (<em>Sophos</em>),   <strong>TrojanDownloader:Win32/Apher.A</strong> (<em>RAV</em>),   <strong>TROJ_APHER.A</strong> (<em>Trend Micro</em>),   <strong>Win32:Trojan-gen.</strong> (<em>ALWIL</em>),   <strong>Downloader.Apher</strong> (<em>Grisoft</em>),   <strong>Trojan.Downloader.Apher.A</strong> (<em>SOFTWIN</em>),   <strong>Trj/W32.Apher</strong> (<em>Panda</em>),   <strong>Win32/TrojanDownloader.Apher.A</strong> (<em>Eset</em>)</p>
<p>Description added       Aug 29 2002<br />
Behavior                    <strong>TrojanDownloader </strong><br />
Technical details:<br />
Apher is malware virus in the wild that spreads as an attachment to spoofed e-mails using a legitimate <em>Microsoft</em> address. The email text is disguised as a Kaspersky Labs Anit-virus software update.<br />
Below is a screen shot of a spoofed e-mail message infected with Apher<strong>: </strong></p>
<div style="text-align: center"><a href="http://spywarestop.net/wp-content/uploads/2007/07/оьт.jpg" target="_blank"><strong><img id="image526" title="1.jpg" alt="1.jpg" src="http://spywarestop.net/wp-content/uploads/2007/07/1.jpg" /></strong></a></div>
<div style="text-align: center"><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank"><strong>Download a new version of Panda Internet Security 2007</strong></a></div>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=529</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan.Win32.Agent.aev</title>
		<link>http://spywarestop.net/?p=525</link>
		<comments>http://spywarestop.net/?p=525#comments</comments>
		<pubDate>Wed, 04 Jul 2007 13:29:09 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=525</guid>
		<description><![CDATA[Detection added      Feb 01 2007 19:34 GMT
Update released       Feb 01 2007 21:45 GMT
Description added    May 31 2007
Behavior                 Trojan
Technical details:
This Trojan is a Windows PE EXE file. The file is 61 440 bytes in size.
Payload:
During installation, the Trojan creates a file and saves its configuration to this file:
%WinDir%\cchost.ini
This Trojan is designed to send spam from a victim [...]]]></description>
			<content:encoded><![CDATA[<p>Detection added      Feb 01 2007 19:34 GMT<br />
Update released       Feb 01 2007 21:45 GMT<br />
Description added    May 31 2007<br />
Behavior                 <strong>Trojan</strong></p>
<p>Technical details:<br />
This Trojan is a<em> Windows</em> PE EXE file. The file is 61 440 bytes in size.<br />
Payload:<br />
During installation, the Trojan creates a file and saves its configuration to this file:<br />
%WinDir%\cchost.ini<br />
This Trojan is designed to send spam from a victim machine. When launched, it attempts to download, in encrypted form, the spam that will be sent:<br />
http://www.smalltool.net/remotewatch/send_****.php<br />
It also downloads a list of email addresses from the following address:<br />
http://www.smalltool.net/remotewatch/user****.php<br />
The Trojan will then send the spam it downloaded to the addresses on the list.<br />
Removal instructions:<br />
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:<br />
Use Task Manager to terminate the Trojan process.<br />
Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).<br />
Delete the following file:<br />
%WinDir%\cchost.ini<br />
Update your antivirus databases and perform a full scan of the computer (<a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a>).
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=525</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-PSW.Win32.Kuang.d</title>
		<link>http://spywarestop.net/?p=524</link>
		<comments>http://spywarestop.net/?p=524#comments</comments>
		<pubDate>Tue, 19 Jun 2007 14:08:03 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Product News</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>antivirus</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=524</guid>
		<description><![CDATA[Aliases:
Trojan-PSW.Win32.Kuang.d (Kaspersky Lab) is also known as: Trojan.PSW.Kuang.d (Kaspersky Lab), PWS-BP (McAfee),   Trojan Horse (Symantec),   Trojan.Kuang (Doctor Web),   Troj/Kuang-G (Sophos),   Backdoor:Win32/Kuang.D (RAV),   TROJ_PSW_RING0.B (Trend Micro),   TR/KuanggA.Srv (H+BEDV),   W32/Trojan.Kuang.A (FRISK),   Win32:Kuang (ALWIL),   W95/Weird (Grisoft),   Trojan.Kuang.A (SOFTWIN),   Trojan.DUNpws.Bp (ClamAV),   Trj/PSW.Kuang.D (Panda),   PSW.Kuang.D (Eset)
Description added    Mar 30 2007
Behavior                 PSW Trojan
Technical details:
This Trojan is designed to steal confidential data. [...]]]></description>
			<content:encoded><![CDATA[<p>Aliases:<br />
<strong>Trojan-PSW.Win32.Kuang.d</strong> (<em>Kaspersky Lab</em>) is also known as: <strong>Trojan.PSW.Kuang.d</strong> (<em>Kaspersky Lab</em>), <strong>PWS-BP</strong> (<em>McAfee</em>),   <strong>Trojan Horse</strong> (<em>Symantec</em>),   <strong>Trojan.Kuang</strong> (<em>Doctor Web</em>),   <strong>Troj/Kuang-G</strong> (<em>Sophos</em>),   <strong>Backdoor:Win32/Kuang.D</strong> (<em>RAV</em>),   <strong>TROJ_PSW_RING0.B</strong> (<em>Trend Micro</em>),   <strong>TR/KuanggA.Srv</strong> (<em>H+BEDV</em>),   <strong>W32/Trojan.Kuang.A</strong> (<em>FRISK</em>),   <strong>Win32:Kuang</strong> (<em>ALWIL</em>),   <strong>W95/Weird</strong> (<em>Grisoft</em>),   <strong>Trojan.Kuang.A</strong> (<em>SOFTWIN</em>),   <strong>Trojan.DUNpws.Bp</strong> (<em>ClamAV</em>),   <strong>Trj/PSW.Kuang.D</strong> (<em>Panda</em>),   <strong>PSW.Kuang.D</strong> (<em>Eset</em>)</p>
<p>Description added    Mar 30 2007<br />
Behavior                 <strong>PSW Trojan</strong><br />
Technical details:<br />
This <strong>Trojan</strong> is designed to steal confidential data. It is a <em>Windows</em> PE EXE file. The file is 7,680 bytes in size. It is not packed in any way. It is written in C++.<br />
Installation:<br />
When launched, the Trojan copies itself to the Windows system directory:<br />
%System%/ .exe<br />
It then creates a file in the same place called .cfg.<br />
The Trojan also adds the following parameter to the system registry:<br />
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8221; .task&#8221; = &#8220;%System%/ .exe&#8221;<br />
This ensures that the Trojan will be launched each time Windows is booted on the victim machine.<br />
Payload:<br />
This Trojan tracks the user&#8217;s actions on the victim machine.<br />
It can:<br />
log keystrokes;<br />
record windows opened;<br />
provides the option to indicate a specific window within which activity will be tracked.<br />
The Trojan opens a random TCP port. It will attempt to connect to a mail server and send the harvested data.<br />
Removal instructions:<br />
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:<br />
Use Task Manager to terminate the Trojan process.<br />
Delete the following files:<br />
%System%/ .exe<br />
%System%/ .cfg<br />
Delete the following registry value:<br />
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8221; .task&#8221;<br />
Update your antivirus databases and perform a full scan of the computer (<strong><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a></strong>).
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=524</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Clicker.Win32.Bitdefener</title>
		<link>http://spywarestop.net/?p=523</link>
		<comments>http://spywarestop.net/?p=523#comments</comments>
		<pubDate>Tue, 12 Jun 2007 14:32:38 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Product News</category>
	<category>Adware and Spyware Software</category>
	<category>worm</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=523</guid>
		<description><![CDATA[Aliases:
Trojan-Clicker.Win32.Bitdefener (Kaspersky Lab) is also known as: TrojanClicker.Win32.Bitdefener (Kaspersky Lab), Crackerbox (McAfee),   Trojan Horse (Symantec),   Trojan.CrackBox.109 (Doctor Web),   Troj/Crackerb (Sophos),   Trojan:Win32/Fender (RAV),   TROJ_FENDER.A (Trend Micro),   TR/Bitdefener (H+BEDV),   Win32:Trojan-gen. (ALWIL),   Trojan Horse (Panda),   Win32/TrojanClicker.Bitdefener (Eset)
Description added    Feb 16 2007
Behavior                 TrojanClicker
Technical details:
This Trojan opens a variety of links without the knowledge or consent of the user. It [...]]]></description>
			<content:encoded><![CDATA[<p>Aliases:<br />
<strong>Trojan-Clicker.Win32.Bitdefener</strong> (<em>Kaspersky Lab</em>) is also known as: <strong>TrojanClicker.Win32.Bitdefener</strong> (<em>Kaspersky</em> <em>Lab</em>), <strong>Crackerbox</strong> (<em>McAfee</em>),   <strong>Trojan Horse</strong> (<em>Symantec</em>),   <strong>Trojan.CrackBox.109</strong> (<em>Doctor Web</em>),   <strong>Troj/Crackerb</strong> (<em>Sophos</em>),   <strong>Trojan:Win32/Fender</strong> (<em>RAV</em>),   <strong>TROJ_FENDER.A</strong> (<em>Trend Micro</em>),   <strong>TR/Bitdefener</strong> (<em>H+BEDV</em>),   <strong>Win32:Trojan-gen.</strong> (<em>ALWIL</em>),   <strong>Trojan Horse</strong> (<em>Panda</em>),   <strong>Win32/TrojanClicker.Bitdefener</strong> (<em>Eset</em>)</p>
<p>Description added    Feb 16 2007<br />
Behavior                 <strong>TrojanClicker</strong></p>
<p>Technical details:<br />
This <strong>Trojan</strong> opens a variety of links without the knowledge or consent of the user. It is a <em>Windows</em> PE EXE file. It is 40,960 bytes in size. It is written in Visual Basic.</p>
<p>Payload:<br />
Once launched, the Trojan will periodically open the following links without the user’s knowledge or consent:</p>
<p>http://www.mp3.com/****seuq<br />
http://artists.mp3s.com/artist_stats/239/****seuq.html<br />
http://artists.mp3s.com/artist_calendar/239/23****.html<br />
http://play.mp3.com/cgi-bin/play/play.cgi/****</p>
<p>Removal instructions:<br />
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:<br />
1.Use Task Manager to terminate the Trojan process:<br />
2.Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).<br />
3.Update your antivirus databases and perform a full scan of the computer (<strong><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a></strong>). <br />
 
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=523</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Proxy.Win32.Cidra.d</title>
		<link>http://spywarestop.net/?p=522</link>
		<comments>http://spywarestop.net/?p=522#comments</comments>
		<pubDate>Wed, 30 May 2007 14:48:10 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=522</guid>
		<description><![CDATA[Aliases:
Trojan-Proxy.Win32.Cidra.d (Kaspersky Lab) is also known as: TrojanProxy.Win32.Cidra.d (Kaspersky Lab), Proxy-Cidra (McAfee),   Trojan.Download.Inor.B (Symantec),   BackDoor.Cidra (Doctor Web),   Troj/Cidra-D (Sophos),   TrojanDownloader:Win32/Cjdra (RAV),   TROJ_CIDRA.D (Trend Micro),   TR/Cidra.D (H+BEDV),   Win32:Cidra-B (ALWIL),   Trojan.Cidra.D (SOFTWIN),   Worm.Cidra.D (ClamAV),   Bck/Cidra.B (Panda),   Win32/TrojanProxy.Cidra.D (Eset)
Description added Feb 19 2007
Behavior TrojanProxy
Technical details:This Trojan program turns the victim machine into a proxy server. It is a [...]]]></description>
			<content:encoded><![CDATA[<p>Aliases:<br />
<strong>Trojan-Proxy.Win32.Cidra.d</strong> (<em>Kaspersky Lab</em>) is also known as: <strong>TrojanProxy.Win32.Cidra.d</strong> (<em>Kaspersky Lab</em>), <strong>Proxy-Cidra</strong> (<em>McAfee</em>),   Trojan.Download.Inor.B (<em>Symantec</em>),   <strong>BackDoor.Cidra</strong> (<em>Doctor</em> <em>Web</em>),   <strong>Troj/Cidra-D</strong> (<em>Sophos</em>),   TrojanDownloader:Win32/Cjdra (<em>RAV</em>),   <strong>TROJ_CIDRA.D</strong> (<em>Trend Micro</em>),   <strong>TR/Cidra.D</strong> (<em>H+BEDV</em>),   <strong>Win32:Cidra-B</strong> (<em>ALWIL</em>),   <strong>Trojan.Cidra.D</strong> (<em>SOFTWIN</em>),   <strong>Worm.Cidra.D</strong> (<em>ClamAV</em>),   <strong>Bck/Cidra.B</strong> (<em>Panda</em>),   <strong>Win32/TrojanProxy.Cidra.D</strong> (<em>Eset</em>)</p>
<p>Description added Feb 19 2007<br />
Behavior <strong>TrojanProxy</strong><br />
Technical details:This <strong>Trojan</strong> program turns the victim machine into a proxy server. It is a <em>Windows</em> PE EXE file. It is 27,136 bytes in size. It is packed using UPX. The unpacked file is approximately 60KB in size.<br />
Installation:<br />
The Trojan adds the following parameter to the Window system registry in order to ensure that its executable file will be launched automatically:<br />
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;UsbD&#8221; = &#8221;</p>
<p>Payload:<br />
The Trojan creates a SOCKS proxy server on a randomly chosen TCP port. The number of the open port and the victim machine’s network address will then be sent to the remote malicious user’s site. The remote malicious user will then be able to use the victim machine without the user’s knowledge or consent.<br />
The Trojan will also periodically send an HTTP request to o.cjdra.com. In response it will get a URL to which it will then attempt to connect.<br />
Removal instructions:<br />
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:<br />
Use Task Manager to terminate the Trojan process.<br />
Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).<br />
Delete the following key from the system registry:<br />
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;UsbD&#8221; = &#8221;<br />
Update your antivirus databases and perform a full scan of the computer (<strong><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a></strong>).</p>
<p> 
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=522</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Proxy.Win32.Xorpix.ar</title>
		<link>http://spywarestop.net/?p=521</link>
		<comments>http://spywarestop.net/?p=521#comments</comments>
		<pubDate>Mon, 21 May 2007 12:45:07 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=521</guid>
		<description><![CDATA[Detection added        Oct 12 2006 08:46 GMT
Update released        Oct 12 2006 09:54 GMT
Description added     Mar 23 2007
Behavior                  TrojanProxy 
Technical details:
This Trojan program makes it possible for a remote malicious user to use the victim machine as a proxy server. It is a Windows PE EXE file. The file is approximately 17KB in size. It is [...]]]></description>
			<content:encoded><![CDATA[<p>Detection added        Oct 12 2006 08:46 GMT<br />
Update released        Oct 12 2006 09:54 GMT<br />
Description added     Mar 23 2007<br />
Behavior                  <strong>TrojanProxy </strong></p>
<p>Technical details:<br />
This <strong>Trojan</strong> program makes it possible for a remote malicious user to use the victim machine as a proxy server. It is a <em>Windows</em> PE EXE file. The file is approximately 17KB in size. It is packed using UPack. The unpacked file is approximately 258KB in size.</p>
<p>Installation:<br />
Onced launched, the <strong>Trojan</strong> drops the file shown below to %Documents and Settings%\%All Users%\Common Documents%\Settings.</p>
<p>arm32.dll — the attribute &#8216;hidden&#8217; is assigned to this file<br />
The <strong>Trojan</strong> ensures that its library will be loaded when the Winlogon process starts (on system boot):</p>
<p>[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\arm32reg]<br />
 &#8221;Asynchronous&#8221;=&#8221;dword: 0&#215;00000001&#8243;<br />
 &#8221;DllName&#8221;=&#8221;%Documents and Settings%\%All Users%\%Common Documents%\Settings\arm32.dll&#8221;<br />
 &#8221;Startup&#8221;=&#8221;arm32reg&#8221;<br />
 &#8221;Impersonate&#8221;=&#8221;dword: 0&#215;00000001&#8243;<br />
The <strong>Trojan</strong> constantly checks that this key is present in the registry, and will restore it if the key is manually deleted.</p>
<p>Payload:<br />
The <strong>Trojan</strong> downloads a configuration file from the remote malicious user&#8217;s site, and saves it to the following folder:</p>
<p>%Documents and Settings%\%All Users%\%Common Documents%\Settings\desktop.ini<br />
The Trojan launches the iexplore.exe process and injects its code into this process. This process will open a random TCP port. The remote malicious user will then be notified of the open port number.<br />
This enables the remote malicious user to work as if from the victim machine within a network.</p>
<p>Removal instructions:<br />
Use <em>Kaspersky Anti-Virus 6.0</em> to delete the <strong>Trojan</strong>. Update your antivirus databases and perform a full scan of the computer (<strong><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a></strong>).
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=521</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Spy.HTML.Bankfraud.qe</title>
		<link>http://spywarestop.net/?p=519</link>
		<comments>http://spywarestop.net/?p=519#comments</comments>
		<pubDate>Fri, 11 May 2007 12:00:29 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=519</guid>
		<description><![CDATA[Detection added         Sep 21 2006 10:19 GMT
Update released         Sep 21 2006 13:46 GMT
Description added      Oct 24 2006
Behavior                   TrojanSpy
Technical details:
This Trojan program uses spoofing technology, and is a fake HTML page. It is designed to steal confidential information from clients of Bank of America.
It arrives as an email which appears to be an important message:

The email [...]]]></description>
			<content:encoded><![CDATA[<p>Detection added         Sep 21 2006 10:19 GMT<br />
Update released         Sep 21 2006 13:46 GMT<br />
Description added      Oct 24 2006<br />
Behavior                   <strong>TrojanSpy</strong></p>
<p>Technical details:<br />
This <strong>Trojan</strong> program uses spoofing technology, and is a fake HTML page. It is designed to steal confidential information from clients of Bank of America.<br />
It arrives as an email which appears to be an important message:</p>
<div style="text-align: center"><a href="http://spywarestop.net/wp-content/uploads/2007/05/2.jpg" target="_blank"><img id="image515" title="Trojan-Spy.HTML.Bankfraud.qe" alt="Trojan-Spy.HTML.Bankfraud.qe" src="http://spywarestop.net/wp-content/uploads/2007/05/1.jpg" /></a></div>
<p>The email contains a link which uses the Frame Spoof Vulnerability in <em>Internet Explorer</em>.<br />
The Frame Spoof Vulnerability is detailed in<em> Microsoft</em> Security Bulletin(MS04-004) and is present in versions 5.x and 6.x of Microsoft Internet Explorer. Microsoft published a document describing the vulnerability and how to recognize such fake links.<br />
Once the user enters the site, and enters his/ her account details, they will be sent to the remote malicious user, who may then have full access to the user&#8217;s account.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=519</wfw:commentRSS>
		</item>
		<item>
		<title>Virus.MSAccess.Lovely</title>
		<link>http://spywarestop.net/?p=514</link>
		<comments>http://spywarestop.net/?p=514#comments</comments>
		<pubDate>Fri, 27 Apr 2007 12:25:13 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=514</guid>
		<description><![CDATA[Aliases:
Virus.MSAccess.Lovely (Kaspersky Lab) is also known as: Macro.Access.Lovely (Kaspersky Lab), A97M/Lovely (McAfee),   A97M.Accessiv.D (Symantec),   A97M.Lovely (Doctor Web),   AM97/AccessiV-E (Sophos),   A97M/Lovely.A (RAV),   A97M_JETDB-1 (Trend Micro),   A97M/Tox.A (H+BEDV),   A97M/AccessiV.D (FRISK),   A97M.Lovely.A (SOFTWIN),   A97M/Lovely (Panda),   MACRO (Eset)
Description added       Mar 07 2000
Behavior                    Macro Virus
Technical details:
This virus infects MS Access databases. While infecting the virus replaces in databases the Autoexec [...]]]></description>
			<content:encoded><![CDATA[<p>Aliases:<br />
<strong>Virus.MSAccess.Lovely</strong> (<em>Kaspersky Lab</em>) is also known as: <strong>Macro.Access.Lovely</strong> (<em>Kaspersky Lab</em>), <strong>A97M/Lovely</strong> (<em>McAfee</em>),   <strong>A97M.Accessiv.D</strong> (<em>Symantec</em>),   <strong>A97M.Lovely</strong> (<em>Doctor Web</em>),   <strong>AM97/AccessiV-E</strong> (<em>Sophos</em>),   <strong>A97M/Lovely.A</strong> (<em>RAV</em>),   <strong>A97M_JETDB-1</strong> (<em>Trend Micro</em>),   <strong>A97M/Tox.A</strong> (<em>H+BEDV</em>),   <strong>A97M/AccessiV.D</strong> (<em>FRISK</em>),   <strong>A97M.Lovely.A</strong> (<em>SOFTWIN</em>),   <strong>A97M/Lovely</strong> (<em>Panda</em>),   <strong>MACRO</strong> (<em>Eset</em>)</p>
<p>Description added       Mar 07 2000<br />
Behavior                    <strong>Macro Virus</strong><br />
Technical details:<br />
This virus infects MS Access databases. While infecting the virus replaces in databases the Autoexec script and copies to database additional form named &#8220;Jo&#8221;. This form contains a module with one function &#8220;Jg&#8221;.<br />
When infected database is opened the virus searches for all databases in the current directory and infects them. While searching the virus uses the &#8220;*.MDB&#8221; mask.<br />
Before infecting the virus changes several system parameters: disables viewing macros by using hot-keys and on error while executing macros. The virus does not have any payload procedure.<br />
The virus contains the &#8220;copyright&#8221; text:<br />
Copyright (C) 1998 by FlyShadow ~^^~ - Lovely
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=514</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Spy.Win32.KeyLogger.p</title>
		<link>http://spywarestop.net/?p=512</link>
		<comments>http://spywarestop.net/?p=512#comments</comments>
		<pubDate>Fri, 20 Apr 2007 13:44:52 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=512</guid>
		<description><![CDATA[Aliases:
Trojan-Spy.Win32.KeyLogger.p (Kaspersky Lab) is also known as: TrojanSpy.Win32.KeyLogger.p (Kaspersky Lab), Keylogger.Trojan (Symantec),   Trojan.KeyProbe (Doctor Web),   TrojanSpy:Win32/KeyLogger.P (RAV),   TROJ_KEYLOGGER.P (Trend Micro),   Win32:Trojan-gen. (ALWIL),   Trojan.Spy.KeyLogger.P (SOFTWIN),   Trojan Horse.LC (Panda),   Win32/Spy.KeyLogger.P (Eset)
Description added        Mar 22 2007
Behavior                     TrojanSpy
Technical details:
This Trojan tracks the user&#8217;s keystrokes, and is designed to steal confidential information. It is a Windows PE EXE file. It [...]]]></description>
			<content:encoded><![CDATA[<p>Aliases:<br />
<strong>Trojan-Spy.Win32.KeyLogger.p</strong> (<em>Kaspersky Lab</em>) is also known as: <strong>TrojanSpy.Win32.KeyLogger.p</strong> (<em>Kaspersky Lab</em>), <strong>Keylogger.Trojan</strong> (<em>Symantec</em>),   <strong>Trojan.KeyProbe</strong> (<em>Doctor Web</em>),   <strong>TrojanSpy:Win32/KeyLogger.P</strong> (<em>RAV</em>),   <strong>TROJ_KEYLOGGER.P</strong> (<em>Trend Micro</em>),   <strong>Win32:Trojan-gen.</strong> (<em>ALWIL</em>),   <strong>Trojan.Spy.KeyLogger.P</strong> (<em>SOFTWIN</em>),   <strong>Trojan</strong> <strong>Horse.LC</strong> (<em>Panda</em>),   <strong>Win32/Spy.KeyLogger.P</strong> (<em>Eset</em>)</p>
<p>Description added        Mar 22 2007<br />
Behavior                     <strong>TrojanSpy</strong><br />
Technical details:<br />
This <strong>Trojan</strong> tracks the user&#8217;s keystrokes, and is designed to steal confidential information. It is a <em>Windows</em> PE EXE file. It is 136,192 bytes in size. It is not packed in any way. It is written in Visual C++.</p>
<div style="text-align: center"><img id="image510" src="http://spywarestop.net/wp-content/uploads/2007/04/1.jpg" /></div>
<p>Installation:<br />
When launched, the <strong>Trojan</strong> displays the following dialogue box:<br />
The user is then required to enter certain paramters, including the following: Directory, password, file name and startup key name. The resulting Trojan file, called KeyProbe.exe (43 520 bytes in size) which functions in resident mode, will be dropped to the specified folder.<br />
The <strong>Trojan</strong> creates the following registry key:[HKLM\Software\Rosebud Technologies LTD\Key Probe]<br />
It also adds the following values to the system registry:</p>
<p>[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Key Probe&#8221; = &#8220;%WinDir%\KeyProbe.exe&#8221;<br />
This ensures that the <strong>Trojan</strong> will be launched each time Windows is booted on the victim machine.</p>
<div style="text-align: center"><img id="image511" src="http://spywarestop.net/wp-content/uploads/2007/04/2.jpg" /></div>
<p>Payload:<br />
The <strong>Trojan</strong> logs keystrokes Harvested data will be written to a log file called log.txt.<br />
It is possible to configure the <strong>Trojan spy</strong> while it is running by pressing Shift five times and entering a password:<br />
Removal instructions:<br />
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:<br />
Use Task Manager to terminate the <strong>Trojan</strong> process and delete the Trojan file:<br />
&#8220;%WinDir%\KeyProbe.exe&#8221;<br />
Delete the following registry key:<br />
[HKLM\Software\Rosebud Technologies LTD\Key Probe]<br />
Delete the following values from the system registry:<br />
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Key Probe&#8221;<br />
Delete the original <strong>Trojan</strong> file (the location will depend on how the program originally penetrated the victim machine).<br />
Update your antivirus databases and perform a full scan of the computer (<strong><a title="download here" href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a></strong>).
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=512</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Spy.Win32.Goldun.gu</title>
		<link>http://spywarestop.net/?p=509</link>
		<comments>http://spywarestop.net/?p=509#comments</comments>
		<pubDate>Thu, 12 Apr 2007 11:49:33 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=509</guid>
		<description><![CDATA[Detection added         Jan 19 2006 07:31 GMT
Update released         Jan 19 2006 08:45 GMT
Description added      Jan 20 2006
Behavior                   TrojanSpy
 
Technical details:
This Trojan spy program is designed to steal confidential financial information.
The Trojan itself is a Windows PE EXE file approximately 25KB in size, packed using FSG. The unpacked file is approximately 110KB in size.
Installation:
When installing itself to the [...]]]></description>
			<content:encoded><![CDATA[<p>Detection added         Jan 19 2006 07:31 GMT<br />
Update released         Jan 19 2006 08:45 GMT<br />
Description added      Jan 20 2006<br />
Behavior                   <strong>TrojanSpy</strong></p>
<p> </p>
<p>Technical details:<br />
This <strong>Trojan</strong> spy program is designed to steal confidential financial information.<br />
The <strong>Trojan</strong> itself is a <em>Windows</em> PE EXE file approximately 25KB in size, packed using FSG. The unpacked file is approximately 110KB in size.</p>
<p>Installation:<br />
When installing itself to the system, the <strong>Trojan</strong> creates the following files in the <em>Windows</em> system directory:</p>
<p>%System%\winprint.dll<br />
%System%\eps32sys.sys<br />
TrojanSpy.Win32.Goldun.gu creates the following entries in the system registry:<br />
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winprint]<br />
&#8220;DllName&#8221; = &#8220;winprint.dll&#8221;<br />
&#8220;Startup&#8221; = &#8220;winprint&#8221;<br />
&#8220;Impersonate&#8221; = &#8220;1&#8243;<br />
&#8220;Asynchronous&#8221; = &#8220;1&#8243;<br />
&#8220;MaxWait&#8221; = &#8220;1&#8243;<br />
Payload:<br />
<strong>TrojanSpy.Win32.Goldun.gu</strong> attempts to steal logins, passwords and other account information associated with e-gold online bank.</p>
<p>Removal instructions:<br />
Delete the <strong>Trojan&#8217;s</strong> installation key from the system registry:<br />
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winprint]<br />
Delete the following files:<br />
%System%\winprint.dll<br />
%System%\eps32sys.sys<br />
Reboot the computer.<br />
Perform a full scan of the computer (<strong><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007 here</a></strong>)
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=509</wfw:commentRSS>
		</item>
	</channel>
</rss>
