<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Spyware Stop !</title>
	<link>http://spywarestop.net</link>
	<description>Keep away spyware and trojans! Everything about viruses and methods of competing against !</description>
	<pubDate>Fri, 31 Oct 2008 13:56:12 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.3</generator>
	<language>en</language>
			<item>
		<title>Avast Professional Edition 4.8</title>
		<link>http://spywarestop.net/?p=535</link>
		<comments>http://spywarestop.net/?p=535#comments</comments>
		<pubDate>Fri, 31 Oct 2008 13:56:12 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>General</category>
	<category>antivirus</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=535</guid>
		<description><![CDATA[avast! 4 Professional antivirus, anti-spyware &#038; anti-rootkit for Windows
The professional solution to great protection
avast! 4 Professional Edition represents the best antivirus protection available and can be downloaded and used free of charge for a 60-day trial period. At the end of the trial period, a license key must be purchased, which will be valid for [...]]]></description>
			<content:encoded><![CDATA[<h1>avast! 4 Professional antivirus, anti-spyware &#038; anti-rootkit for Windows</h1>
<p><span style="font-weight: bold"><img align="right" alt="krabice-pro48.gif" id="image534" src="http://spywarestop.net/wp-content/uploads/2008/10/krabice-pro48.gif" />The professional solution to great protection</span></p>
<p>avast! 4 Professional Edition represents the best antivirus protection available and can be downloaded and used free of charge for a 60-day trial period. At the end of the trial period, a license key must be purchased, which will be valid for a further 1, 2, or 3 years. avast! 4 Professional Edition comes with anti-spyware, anti-rootkit and strong self-protection built-in. It is designed to protect your valuable data and programs, as well as keep itself up-to-date and has the kind of built-in features that many vendors charge for additionally, or don&#8217;t include at all.</p>
<p><span style="font-weight: bold">All-inclusive, comprehensive protection </span>avast! 4 Professional Edition includes ANTI-SPYWARE protection, certified by the West Coast Labs Checkmark process, to protect against the latest spyware threats and ANTI-ROOTKIT DETECTION based on the best-in class GMER technology, built into the scan engine.</p>
<p><span style="font-weight: bold">Simple to use and fully automated </span>- Automatic incremental updates provide real-time protection of your system, including web surfing. We&#8217;ve made avast! antivirus as simple to use as possible, while allowing full control of your security.</p>
<p><span style="font-weight: bold">Tried and Trusted </span>- With over 60 million users of avast!, you can rest assured that you are using one of the most tried and trusted antivirus products in Windows security. avast! supports more MS Windows versions (from Windows 95 to Vista 64-bit) than any other anti-malware product.<br />
<span style="font-weight: bold">Features overview</span>:<br />
Anti-spyware built-in     Automatic updates<br />
Anti-rootkit built-in     PUSH updates<br />
Strong self-protection     Virus Chest<br />
Antivirus kernel     System integration<br />
Simple User Interface     Command-line scanner<br />
Enhanced User Interface     Integrated Virus Cleaner<br />
Resident protection     Support for 64-bit Windows<br />
Script blocker     Internationalization<br />
P2P and IM Shields     Network Shield<br />
Web Shield
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=535</wfw:commentRSS>
		</item>
		<item>
		<title>Spyware Doctor® 6 for Windows® - New Version</title>
		<link>http://spywarestop.net/?p=533</link>
		<comments>http://spywarestop.net/?p=533#comments</comments>
		<pubDate>Thu, 11 Sep 2008 10:12:01 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>General</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=533</guid>
		<description><![CDATA[Editor&#8217;s Choice Anti-Spyware
Good Spyware Protection. Used by Millions. Do not compromise your security with 2nd best!
* Recommended by experts and editors around the world as the reliable Anti-Spyware.
* FREE customer support for everybody.
* Frequent advanced updates ensure that you are always protected.
* Easiest to use with intelligent automatic protection.
* Detects, removes and blocks all types [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Editor&#8217;s Choice Anti-Spyware</strong><br />
Good Spyware Protection. Used by Millions. Do not compromise your security with 2nd best!</p>
<p>* Recommended by experts and editors around the world as the reliable Anti-Spyware.<br />
* FREE customer support for everybody.<br />
* Frequent advanced updates ensure that you are always protected.<br />
* Easiest to use with intelligent automatic protection.<br />
* Detects, removes and blocks all types of Spyware and Adware threats.<br />
* 100% Money Back Guarantee.</p>
<p>Spyware Doctor has consistently been awarded Editors&#8217; Choice, by leading PC magazines and testing laboratories all over  the world, including Sweden,  UK, Germany, US and Australia. Besides, after leading the market in 2005, Spyware Doctor was awarded the prestigious Best of the Year at the end of 2005 and then in 2006.<br />
Spyware Doctor has been downloaded over 125 million times with millions more downloads every week. People worldwide use and trust Spyware Doctor to protect their PCs from spyware, adware and other online threats.</p>
<p>Spyware Doctor continues to be awarded the highest honors by many of the world&#8217;s leading PC publications such as PC Magazine, PC World, PC Plus, PC Pro, PC Utilities, PC Authority, PC Advisor, Microdatorn, PC Choice, Computer Bild and PC Answers Magazine.</p>
<p>Did you know that numerous programs tested against Spyware Doctor detected only small fraction of Spyware and completely removed an even smaller amount? Also most of them were unable to effectively block Spyware in real time from being installed on users PC in the first place.<br />
When you are choosing Anti-Spyware make sure you choose one that is proven and has genuine awards from one or more world leading research labs such a PC World, CNET, PC Magazine, PC Authority, PC Pro Magazine, PC Answers and other trusted labs. More importantly do not use ratings from unknown review websites, as often these are designed to mislead you into purchase of affiliated, inferior or rogue product.<br />
<span style="font-weight: bold">Screenshot [+] Click to Enlarge</span></p>
<p><a title="screenshot-en.gif" class="imagelink" href="http://spywarestop.net/wp-content/uploads/2008/09/screenshot-en.gif"><img alt="screenshot-en.gif" id="image532" style="width: 412px; height: 264px" src="http://spywarestop.net/wp-content/uploads/2008/09/screenshot-en.gif" /></a><br />
Detects, removes and blocks all types of Spyware.</p>
<p>Spyware Doctor is advanced technology designed especially for people, not just experts. That is one reason why it won the People&#8217;s Choice Award in 2005, 2006, 2007 and 2008. It is automatically configured out of the box to give you optimal protection with limited interaction so all you need to do is install it for immediate and ongoing protection.<br />
Spyware Doctor has the most advanced update feature that continually improves its Spyware fighting capabilities on daily basis. As Spyware gets more complex to avoid detection by AntiSpyware programs Spyware Doctor responds with new technology to stay one step ahead.<br />
<span style="font-weight: bold">Easiest in Using</span></p>
<p>Spyware Doctor&#8217;s advanced IntelliGuard technology only alerts users on a true Spyware detection. This is significant because you should not be interrupted by cryptic questions every time you install software, add a site to your favorites or change your PC settings. Such messages can be confusing and lead to undesirable outcomes such as inoperable programs, lost favorites or even Spyware being allowed to install on the system. We&#8217;ve done the research so you do not have to.<br />
Spyware Doctor Full Version Information<br />
<span style="font-weight: bold">Current Version</span>:    6.0.0.383<br />
<span style="font-weight: bold">File Size</span>:    13,278 KB<br />
<span style="font-weight: bold">Operating System</span>:    Designed for Windows® Vista™ 32-bit, XP and 2000. Windows® 98 users .<br />
<span style="font-weight: bold">Release Date</span>:    September 1, 2008<br />
<span style="font-weight: bold">Protection Against</span>:    Adware, Spyware, Keyloggers, Spyware Trojans, Hijackers, Identity Theft, Tracking Threats, Unwanted Software, Phishing, Rogue Anti-Spyware, Popups and Bad Websites.<br />
<span style="font-weight: bold">Add-ons:</span>    Free optional plug-ins are available for Spyware Doctor including Site Guard, Email Guard and Behavior Guard<br />
<span style="font-weight: bold">Trial Limitations:</span>    The trial offers time unlimited real-time protection (free spyware blocking), but does not remove threats detected during on-demand scans, updates may also differ to those supplied to registered users.<br />
<span style="font-weight: bold">Starter Edition: </span>   The Starter Edition offers full scan and removal of threats, and basic real-time protection, is available for free as part of the Google Pack.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=533</wfw:commentRSS>
		</item>
		<item>
		<title>Avira AntiVir Personal Antivirus</title>
		<link>http://spywarestop.net/?p=531</link>
		<comments>http://spywarestop.net/?p=531#comments</comments>
		<pubDate>Wed, 20 Aug 2008 10:49:27 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>General</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=531</guid>
		<description><![CDATA[Avira AntiVir Personal - FREE Antivirus is a reliable free antivirus protection, that constantly and fast scans your computer for malicious programs such as Trojans, viruses, hoaxes, backdoor programs, worms, dialers and many other things. Monitors every action executed by the user or the operating system and reacts quickly when a spiteful program is detected. [...]]]></description>
			<content:encoded><![CDATA[<p>Avira AntiVir Personal - FREE Antivirus is a reliable <strong>free antivirus protection</strong>, that constantly and fast scans your computer for malicious programs such as Trojans, viruses, hoaxes, backdoor programs, worms, dialers and many other things. Monitors every action executed by the user or the operating system and reacts quickly when a spiteful program is detected. Avira AntiVir Personal is a comprehensive, easy to use antivirus program, designed to offer reliable free of charge virus protection to home-users, for personal use only, and is not for business or commercial use. Available for Windows or UNIX.</p>
<p><span style="font-weight: bold">Advantages of Avira AntiVir:</span></p>
<p>AntiVir protection from viruses, worms and Trojans, <img align="right" alt="prd_01.png" id="image530" src="http://spywarestop.net/wp-content/uploads/2008/08/prd_01.png" /><br />
AntiDialer protection against expensive dialers,<br />
AntiRootkit protection from hidden rootkits ,<br />
Faster Scanning up to 20 per cent faster,<br />
New User Interface,<br />
AntiPhishing protection from phishing,<br />
AntiSpyware protection from spyware and adware,<br />
WebGuard protection from malicious websites,<br />
RescueSystem creates a bootable rescue CD,<br />
Enhanced email protection for POP3 and SMTP,<br />
Fast Premium update server,<br />
5 euro donation to the Auerbach Foundation,<br />
AntiSpam filters out unwanted and phishing emails,<br />
FireWall protection from hackers,<br />
GameMode uninterrupted game play,<br />
Backup-System saves your important data,<br />
AntiBot prevents dangerous bot networks,<br />
AntiDrive-by stops surfing malware downloads.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=531</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Downloader.Win32.Apher.a</title>
		<link>http://spywarestop.net/?p=529</link>
		<comments>http://spywarestop.net/?p=529#comments</comments>
		<pubDate>Mon, 16 Jul 2007 12:03:03 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>General</category>
	<category>Safety Tips</category>
	<category>Product News</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>antispyware</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=529</guid>
		<description><![CDATA[Aliases:
Trojan-Downloader.Win32.Apher.a (Kaspersky Lab) is also known as: TrojanDownloader.Win32.Apher.a (Kaspersky Lab), Downloader.cfg (McAfee),   Download.Trojan (Symantec),   Trojan.Aphex.10 (Doctor Web),   Troj/WebDL (Sophos),   TrojanDownloader:Win32/Apher.A (RAV),   TROJ_APHER.A (Trend Micro),   Win32:Trojan-gen. (ALWIL),   Downloader.Apher (Grisoft),   Trojan.Downloader.Apher.A (SOFTWIN),   Trj/W32.Apher (Panda),   Win32/TrojanDownloader.Apher.A (Eset)
Description added       Aug 29 2002
Behavior                    TrojanDownloader 
Technical details:
Apher is malware virus in the wild that spreads as an attachment to spoofed e-mails [...]]]></description>
			<content:encoded><![CDATA[<p>Aliases:<br />
<strong>Trojan-Downloader.Win32.Apher.a</strong> (<em>Kaspersky Lab</em>) is also known as: <strong>TrojanDownloader.Win32.Apher.a</strong> (<em>Kaspersky Lab</em>), <strong>Downloader.cfg</strong> (<em>McAfee</em>),   <strong>Download.Trojan</strong> (<em>Symantec</em>),   <strong>Trojan.Aphex.10</strong> (<em>Doctor Web</em>),   <strong>Troj/WebDL</strong> (<em>Sophos</em>),   <strong>TrojanDownloader:Win32/Apher.A</strong> (<em>RAV</em>),   <strong>TROJ_APHER.A</strong> (<em>Trend Micro</em>),   <strong>Win32:Trojan-gen.</strong> (<em>ALWIL</em>),   <strong>Downloader.Apher</strong> (<em>Grisoft</em>),   <strong>Trojan.Downloader.Apher.A</strong> (<em>SOFTWIN</em>),   <strong>Trj/W32.Apher</strong> (<em>Panda</em>),   <strong>Win32/TrojanDownloader.Apher.A</strong> (<em>Eset</em>)</p>
<p>Description added       Aug 29 2002<br />
Behavior                    <strong>TrojanDownloader </strong><br />
Technical details:<br />
Apher is malware virus in the wild that spreads as an attachment to spoofed e-mails using a legitimate <em>Microsoft</em> address. The email text is disguised as a Kaspersky Labs Anit-virus software update.<br />
Below is a screen shot of a spoofed e-mail message infected with Apher<strong>: </strong></p>
<div style="text-align: center"><a href="http://spywarestop.net/wp-content/uploads/2007/07/оьт.jpg" target="_blank"><strong><img id="image526" title="1.jpg" alt="1.jpg" src="http://spywarestop.net/wp-content/uploads/2007/07/1.jpg" /></strong></a></div>
<div style="text-align: center"><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank"><strong>Download a new version of Panda Internet Security 2007</strong></a></div>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=529</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan.Win32.Agent.aev</title>
		<link>http://spywarestop.net/?p=525</link>
		<comments>http://spywarestop.net/?p=525#comments</comments>
		<pubDate>Wed, 04 Jul 2007 13:29:09 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=525</guid>
		<description><![CDATA[Detection added      Feb 01 2007 19:34 GMT
Update released       Feb 01 2007 21:45 GMT
Description added    May 31 2007
Behavior                 Trojan
Technical details:
This Trojan is a Windows PE EXE file. The file is 61 440 bytes in size.
Payload:
During installation, the Trojan creates a file and saves its configuration to this file:
%WinDir%\cchost.ini
This Trojan is designed to send spam from a victim [...]]]></description>
			<content:encoded><![CDATA[<p>Detection added      Feb 01 2007 19:34 GMT<br />
Update released       Feb 01 2007 21:45 GMT<br />
Description added    May 31 2007<br />
Behavior                 <strong>Trojan</strong></p>
<p>Technical details:<br />
This Trojan is a<em> Windows</em> PE EXE file. The file is 61 440 bytes in size.<br />
Payload:<br />
During installation, the Trojan creates a file and saves its configuration to this file:<br />
%WinDir%\cchost.ini<br />
This Trojan is designed to send spam from a victim machine. When launched, it attempts to download, in encrypted form, the spam that will be sent:<br />
http://www.smalltool.net/remotewatch/send_****.php<br />
It also downloads a list of email addresses from the following address:<br />
http://www.smalltool.net/remotewatch/user****.php<br />
The Trojan will then send the spam it downloaded to the addresses on the list.<br />
Removal instructions:<br />
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:<br />
Use Task Manager to terminate the Trojan process.<br />
Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).<br />
Delete the following file:<br />
%WinDir%\cchost.ini<br />
Update your antivirus databases and perform a full scan of the computer (<a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a>).
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=525</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-PSW.Win32.Kuang.d</title>
		<link>http://spywarestop.net/?p=524</link>
		<comments>http://spywarestop.net/?p=524#comments</comments>
		<pubDate>Tue, 19 Jun 2007 14:08:03 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Product News</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>antivirus</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=524</guid>
		<description><![CDATA[Aliases:
Trojan-PSW.Win32.Kuang.d (Kaspersky Lab) is also known as: Trojan.PSW.Kuang.d (Kaspersky Lab), PWS-BP (McAfee),   Trojan Horse (Symantec),   Trojan.Kuang (Doctor Web),   Troj/Kuang-G (Sophos),   Backdoor:Win32/Kuang.D (RAV),   TROJ_PSW_RING0.B (Trend Micro),   TR/KuanggA.Srv (H+BEDV),   W32/Trojan.Kuang.A (FRISK),   Win32:Kuang (ALWIL),   W95/Weird (Grisoft),   Trojan.Kuang.A (SOFTWIN),   Trojan.DUNpws.Bp (ClamAV),   Trj/PSW.Kuang.D (Panda),   PSW.Kuang.D (Eset)
Description added    Mar 30 2007
Behavior                 PSW Trojan
Technical details:
This Trojan is designed to steal confidential data. [...]]]></description>
			<content:encoded><![CDATA[<p>Aliases:<br />
<strong>Trojan-PSW.Win32.Kuang.d</strong> (<em>Kaspersky Lab</em>) is also known as: <strong>Trojan.PSW.Kuang.d</strong> (<em>Kaspersky Lab</em>), <strong>PWS-BP</strong> (<em>McAfee</em>),   <strong>Trojan Horse</strong> (<em>Symantec</em>),   <strong>Trojan.Kuang</strong> (<em>Doctor Web</em>),   <strong>Troj/Kuang-G</strong> (<em>Sophos</em>),   <strong>Backdoor:Win32/Kuang.D</strong> (<em>RAV</em>),   <strong>TROJ_PSW_RING0.B</strong> (<em>Trend Micro</em>),   <strong>TR/KuanggA.Srv</strong> (<em>H+BEDV</em>),   <strong>W32/Trojan.Kuang.A</strong> (<em>FRISK</em>),   <strong>Win32:Kuang</strong> (<em>ALWIL</em>),   <strong>W95/Weird</strong> (<em>Grisoft</em>),   <strong>Trojan.Kuang.A</strong> (<em>SOFTWIN</em>),   <strong>Trojan.DUNpws.Bp</strong> (<em>ClamAV</em>),   <strong>Trj/PSW.Kuang.D</strong> (<em>Panda</em>),   <strong>PSW.Kuang.D</strong> (<em>Eset</em>)</p>
<p>Description added    Mar 30 2007<br />
Behavior                 <strong>PSW Trojan</strong><br />
Technical details:<br />
This <strong>Trojan</strong> is designed to steal confidential data. It is a <em>Windows</em> PE EXE file. The file is 7,680 bytes in size. It is not packed in any way. It is written in C++.<br />
Installation:<br />
When launched, the Trojan copies itself to the Windows system directory:<br />
%System%/ .exe<br />
It then creates a file in the same place called .cfg.<br />
The Trojan also adds the following parameter to the system registry:<br />
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8221; .task&#8221; = &#8220;%System%/ .exe&#8221;<br />
This ensures that the Trojan will be launched each time Windows is booted on the victim machine.<br />
Payload:<br />
This Trojan tracks the user&#8217;s actions on the victim machine.<br />
It can:<br />
log keystrokes;<br />
record windows opened;<br />
provides the option to indicate a specific window within which activity will be tracked.<br />
The Trojan opens a random TCP port. It will attempt to connect to a mail server and send the harvested data.<br />
Removal instructions:<br />
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:<br />
Use Task Manager to terminate the Trojan process.<br />
Delete the following files:<br />
%System%/ .exe<br />
%System%/ .cfg<br />
Delete the following registry value:<br />
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8221; .task&#8221;<br />
Update your antivirus databases and perform a full scan of the computer (<strong><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a></strong>).
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=524</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Clicker.Win32.Bitdefener</title>
		<link>http://spywarestop.net/?p=523</link>
		<comments>http://spywarestop.net/?p=523#comments</comments>
		<pubDate>Tue, 12 Jun 2007 14:32:38 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Product News</category>
	<category>Adware and Spyware Software</category>
	<category>worm</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=523</guid>
		<description><![CDATA[Aliases:
Trojan-Clicker.Win32.Bitdefener (Kaspersky Lab) is also known as: TrojanClicker.Win32.Bitdefener (Kaspersky Lab), Crackerbox (McAfee),   Trojan Horse (Symantec),   Trojan.CrackBox.109 (Doctor Web),   Troj/Crackerb (Sophos),   Trojan:Win32/Fender (RAV),   TROJ_FENDER.A (Trend Micro),   TR/Bitdefener (H+BEDV),   Win32:Trojan-gen. (ALWIL),   Trojan Horse (Panda),   Win32/TrojanClicker.Bitdefener (Eset)
Description added    Feb 16 2007
Behavior                 TrojanClicker
Technical details:
This Trojan opens a variety of links without the knowledge or consent of the user. It [...]]]></description>
			<content:encoded><![CDATA[<p>Aliases:<br />
<strong>Trojan-Clicker.Win32.Bitdefener</strong> (<em>Kaspersky Lab</em>) is also known as: <strong>TrojanClicker.Win32.Bitdefener</strong> (<em>Kaspersky</em> <em>Lab</em>), <strong>Crackerbox</strong> (<em>McAfee</em>),   <strong>Trojan Horse</strong> (<em>Symantec</em>),   <strong>Trojan.CrackBox.109</strong> (<em>Doctor Web</em>),   <strong>Troj/Crackerb</strong> (<em>Sophos</em>),   <strong>Trojan:Win32/Fender</strong> (<em>RAV</em>),   <strong>TROJ_FENDER.A</strong> (<em>Trend Micro</em>),   <strong>TR/Bitdefener</strong> (<em>H+BEDV</em>),   <strong>Win32:Trojan-gen.</strong> (<em>ALWIL</em>),   <strong>Trojan Horse</strong> (<em>Panda</em>),   <strong>Win32/TrojanClicker.Bitdefener</strong> (<em>Eset</em>)</p>
<p>Description added    Feb 16 2007<br />
Behavior                 <strong>TrojanClicker</strong></p>
<p>Technical details:<br />
This <strong>Trojan</strong> opens a variety of links without the knowledge or consent of the user. It is a <em>Windows</em> PE EXE file. It is 40,960 bytes in size. It is written in Visual Basic.</p>
<p>Payload:<br />
Once launched, the Trojan will periodically open the following links without the user’s knowledge or consent:</p>
<p>http://www.mp3.com/****seuq<br />
http://artists.mp3s.com/artist_stats/239/****seuq.html<br />
http://artists.mp3s.com/artist_calendar/239/23****.html<br />
http://play.mp3.com/cgi-bin/play/play.cgi/****</p>
<p>Removal instructions:<br />
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:<br />
1.Use Task Manager to terminate the Trojan process:<br />
2.Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).<br />
3.Update your antivirus databases and perform a full scan of the computer (<strong><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a></strong>). <br />
 
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=523</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Proxy.Win32.Cidra.d</title>
		<link>http://spywarestop.net/?p=522</link>
		<comments>http://spywarestop.net/?p=522#comments</comments>
		<pubDate>Wed, 30 May 2007 14:48:10 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=522</guid>
		<description><![CDATA[Aliases:
Trojan-Proxy.Win32.Cidra.d (Kaspersky Lab) is also known as: TrojanProxy.Win32.Cidra.d (Kaspersky Lab), Proxy-Cidra (McAfee),   Trojan.Download.Inor.B (Symantec),   BackDoor.Cidra (Doctor Web),   Troj/Cidra-D (Sophos),   TrojanDownloader:Win32/Cjdra (RAV),   TROJ_CIDRA.D (Trend Micro),   TR/Cidra.D (H+BEDV),   Win32:Cidra-B (ALWIL),   Trojan.Cidra.D (SOFTWIN),   Worm.Cidra.D (ClamAV),   Bck/Cidra.B (Panda),   Win32/TrojanProxy.Cidra.D (Eset)
Description added Feb 19 2007
Behavior TrojanProxy
Technical details:This Trojan program turns the victim machine into a proxy server. It is a [...]]]></description>
			<content:encoded><![CDATA[<p>Aliases:<br />
<strong>Trojan-Proxy.Win32.Cidra.d</strong> (<em>Kaspersky Lab</em>) is also known as: <strong>TrojanProxy.Win32.Cidra.d</strong> (<em>Kaspersky Lab</em>), <strong>Proxy-Cidra</strong> (<em>McAfee</em>),   Trojan.Download.Inor.B (<em>Symantec</em>),   <strong>BackDoor.Cidra</strong> (<em>Doctor</em> <em>Web</em>),   <strong>Troj/Cidra-D</strong> (<em>Sophos</em>),   TrojanDownloader:Win32/Cjdra (<em>RAV</em>),   <strong>TROJ_CIDRA.D</strong> (<em>Trend Micro</em>),   <strong>TR/Cidra.D</strong> (<em>H+BEDV</em>),   <strong>Win32:Cidra-B</strong> (<em>ALWIL</em>),   <strong>Trojan.Cidra.D</strong> (<em>SOFTWIN</em>),   <strong>Worm.Cidra.D</strong> (<em>ClamAV</em>),   <strong>Bck/Cidra.B</strong> (<em>Panda</em>),   <strong>Win32/TrojanProxy.Cidra.D</strong> (<em>Eset</em>)</p>
<p>Description added Feb 19 2007<br />
Behavior <strong>TrojanProxy</strong><br />
Technical details:This <strong>Trojan</strong> program turns the victim machine into a proxy server. It is a <em>Windows</em> PE EXE file. It is 27,136 bytes in size. It is packed using UPX. The unpacked file is approximately 60KB in size.<br />
Installation:<br />
The Trojan adds the following parameter to the Window system registry in order to ensure that its executable file will be launched automatically:<br />
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;UsbD&#8221; = &#8221;</p>
<p>Payload:<br />
The Trojan creates a SOCKS proxy server on a randomly chosen TCP port. The number of the open port and the victim machine’s network address will then be sent to the remote malicious user’s site. The remote malicious user will then be able to use the victim machine without the user’s knowledge or consent.<br />
The Trojan will also periodically send an HTTP request to o.cjdra.com. In response it will get a URL to which it will then attempt to connect.<br />
Removal instructions:<br />
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:<br />
Use Task Manager to terminate the Trojan process.<br />
Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).<br />
Delete the following key from the system registry:<br />
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;UsbD&#8221; = &#8221;<br />
Update your antivirus databases and perform a full scan of the computer (<strong><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a></strong>).</p>
<p> 
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=522</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Proxy.Win32.Xorpix.ar</title>
		<link>http://spywarestop.net/?p=521</link>
		<comments>http://spywarestop.net/?p=521#comments</comments>
		<pubDate>Mon, 21 May 2007 12:45:07 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=521</guid>
		<description><![CDATA[Detection added        Oct 12 2006 08:46 GMT
Update released        Oct 12 2006 09:54 GMT
Description added     Mar 23 2007
Behavior                  TrojanProxy 
Technical details:
This Trojan program makes it possible for a remote malicious user to use the victim machine as a proxy server. It is a Windows PE EXE file. The file is approximately 17KB in size. It is [...]]]></description>
			<content:encoded><![CDATA[<p>Detection added        Oct 12 2006 08:46 GMT<br />
Update released        Oct 12 2006 09:54 GMT<br />
Description added     Mar 23 2007<br />
Behavior                  <strong>TrojanProxy </strong></p>
<p>Technical details:<br />
This <strong>Trojan</strong> program makes it possible for a remote malicious user to use the victim machine as a proxy server. It is a <em>Windows</em> PE EXE file. The file is approximately 17KB in size. It is packed using UPack. The unpacked file is approximately 258KB in size.</p>
<p>Installation:<br />
Onced launched, the <strong>Trojan</strong> drops the file shown below to %Documents and Settings%\%All Users%\Common Documents%\Settings.</p>
<p>arm32.dll — the attribute &#8216;hidden&#8217; is assigned to this file<br />
The <strong>Trojan</strong> ensures that its library will be loaded when the Winlogon process starts (on system boot):</p>
<p>[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\arm32reg]<br />
 &#8221;Asynchronous&#8221;=&#8221;dword: 0&#215;00000001&#8243;<br />
 &#8221;DllName&#8221;=&#8221;%Documents and Settings%\%All Users%\%Common Documents%\Settings\arm32.dll&#8221;<br />
 &#8221;Startup&#8221;=&#8221;arm32reg&#8221;<br />
 &#8221;Impersonate&#8221;=&#8221;dword: 0&#215;00000001&#8243;<br />
The <strong>Trojan</strong> constantly checks that this key is present in the registry, and will restore it if the key is manually deleted.</p>
<p>Payload:<br />
The <strong>Trojan</strong> downloads a configuration file from the remote malicious user&#8217;s site, and saves it to the following folder:</p>
<p>%Documents and Settings%\%All Users%\%Common Documents%\Settings\desktop.ini<br />
The Trojan launches the iexplore.exe process and injects its code into this process. This process will open a random TCP port. The remote malicious user will then be notified of the open port number.<br />
This enables the remote malicious user to work as if from the victim machine within a network.</p>
<p>Removal instructions:<br />
Use <em>Kaspersky Anti-Virus 6.0</em> to delete the <strong>Trojan</strong>. Update your antivirus databases and perform a full scan of the computer (<strong><a href="http://www.regnow.com/softsell/nph-softsell.cgi?item=7277-43&#038;affiliate=73214" target="_blank">download a new version of Panda Internet Security 2007</a></strong>).
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=521</wfw:commentRSS>
		</item>
		<item>
		<title>Trojan-Spy.HTML.Bankfraud.qe</title>
		<link>http://spywarestop.net/?p=519</link>
		<comments>http://spywarestop.net/?p=519#comments</comments>
		<pubDate>Fri, 11 May 2007 12:00:29 +0000</pubDate>
		<dc:creator>spywarestop</dc:creator>
		
	<category>Safety Tips</category>
	<category>Best Software</category>
	<category>Adware and Spyware Software</category>
	<category>spyware remove</category>
	<category>trojan</category>
	<category>Malware Descriptions</category>
		<guid isPermaLink="false">http://spywarestop.net/?p=519</guid>
		<description><![CDATA[Detection added         Sep 21 2006 10:19 GMT
Update released         Sep 21 2006 13:46 GMT
Description added      Oct 24 2006
Behavior                   TrojanSpy
Technical details:
This Trojan program uses spoofing technology, and is a fake HTML page. It is designed to steal confidential information from clients of Bank of America.
It arrives as an email which appears to be an important message:

The email [...]]]></description>
			<content:encoded><![CDATA[<p>Detection added         Sep 21 2006 10:19 GMT<br />
Update released         Sep 21 2006 13:46 GMT<br />
Description added      Oct 24 2006<br />
Behavior                   <strong>TrojanSpy</strong></p>
<p>Technical details:<br />
This <strong>Trojan</strong> program uses spoofing technology, and is a fake HTML page. It is designed to steal confidential information from clients of Bank of America.<br />
It arrives as an email which appears to be an important message:</p>
<div style="text-align: center"><a href="http://spywarestop.net/wp-content/uploads/2007/05/2.jpg" target="_blank"><img id="image515" title="Trojan-Spy.HTML.Bankfraud.qe" alt="Trojan-Spy.HTML.Bankfraud.qe" src="http://spywarestop.net/wp-content/uploads/2007/05/1.jpg" /></a></div>
<p>The email contains a link which uses the Frame Spoof Vulnerability in <em>Internet Explorer</em>.<br />
The Frame Spoof Vulnerability is detailed in<em> Microsoft</em> Security Bulletin(MS04-004) and is present in versions 5.x and 6.x of Microsoft Internet Explorer. Microsoft published a document describing the vulnerability and how to recognize such fake links.<br />
Once the user enters the site, and enters his/ her account details, they will be sent to the remote malicious user, who may then have full access to the user&#8217;s account.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://spywarestop.net/?feed=rss2&amp;p=519</wfw:commentRSS>
		</item>
	</channel>
</rss>
