<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6331323378504528188</id><updated>2012-01-10T11:36:32.257+08:00</updated><category term='Free Antivirus'/><category term='Info'/><category term='Free Trial Antivirus'/><category term='Anti Spyware'/><category term='Iframe'/><category term='TR/Drop'/><category term='Gumblar'/><category term='Virus'/><category term='Free Download'/><title type='text'>FREE ANTIVIRUS COLLECTION BLOG'S</title><subtitle type='html'>Free AntiVirus Collection, Virus Protection, Antispyware, Adware, Malware</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>26</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-7821906614070742151</id><published>2009-09-11T07:26:00.004+08:00</published><updated>2009-09-11T07:59:04.548+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TR/Drop'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Info'/><title type='text'>Virus: TR/Drop.Agent.agla - Trojan</title><content type='html'>&lt;table class="av_head" border="0" cellpadding="2" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="av_head_right" width="30%" nowrap="nowrap"&gt;Date discovered:&lt;/td&gt;&lt;td class="av_head_left" width="70%"&gt;26/02/2009&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="av_head_right" width="30%" nowrap="nowrap"&gt;Type:&lt;/td&gt;&lt;td class="av_head_left" width="70%"&gt;Trojan&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="av_head_right" width="30%" nowrap="nowrap"&gt;In the wild:&lt;/td&gt;&lt;td class="av_head_left" width="70%"&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="av_head_right" width="30%" nowrap="nowrap"&gt;Reported Infections:&lt;/td&gt;&lt;td class="av_head_left" width="70%"&gt;Low&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="av_head_right" width="30%" nowrap="nowrap"&gt;Distribution Potential:&lt;/td&gt;&lt;td class="av_head_left" width="70%"&gt;Low&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="av_head_right" width="30%" nowrap="nowrap"&gt;Damage Potential:&lt;/td&gt;&lt;td style="color: rgb(204, 0, 0);" class="av_head_left" width="70%"&gt;High&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="av_head_right" width="30%" nowrap="nowrap"&gt;Static file:&lt;/td&gt;&lt;td class="av_head_left" width="70%"&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="av_head_right" width="30%" nowrap="nowrap"&gt;File size:&lt;/td&gt;&lt;td class="av_head_left" width="70%"&gt;172.207 Bytes&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;GENERAL&lt;/span&gt;&lt;br /&gt;Aliases:&lt;br /&gt; •  Symantec: W32.SillyFDC&lt;br /&gt; •  Sophos: Mal/Generic-A&lt;br /&gt; •  Panda: W32/Lineage.KYR&lt;br /&gt; •  Eset: Win32/PSW.OnLineGames.NNU&lt;br /&gt;&lt;br /&gt;Platforms / OS:&lt;br /&gt; • Windows 2000&lt;br /&gt; • Windows XP&lt;br /&gt; • Windows 2003&lt;br /&gt;&lt;br /&gt;Side effects:&lt;br /&gt; • Downloads files&lt;br /&gt; • Drops malicious files&lt;br /&gt; • Registry modification&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;FILES&lt;/span&gt;&lt;br /&gt;It copies itself to the following locations:&lt;br /&gt; • %SYSDIR%\kva8wr.exe&lt;br /&gt; • %drive%\jbele1.com&lt;br /&gt;&lt;br /&gt;It renames the following files:&lt;br /&gt;  •  %malware execution directory% into c:\%existing file or directory%.vcd&lt;br /&gt;&lt;br /&gt;It deletes the initially executed copy of itself.&lt;br /&gt;&lt;br /&gt;It deletes the following file:&lt;br /&gt; • %SYSDIR%\drivers\cdaudio.sys&lt;br /&gt;&lt;br /&gt;It may corrupt the following file:&lt;br /&gt; • %SYSDIR%\drivers\cdaudio.sys&lt;br /&gt;&lt;br /&gt;The following files are created:&lt;br /&gt;– %drive%\autorun.inf This is a non malicious text file with the following content:&lt;br /&gt; • %code that runs malware%&lt;br /&gt;– %SYSDIR%\drivers\klif.sys Further investigation pointed out that this file is malware, too.&lt;br /&gt;&lt;br /&gt;Detected as: Rkit/Agent.4160&lt;br /&gt;– %SYSDIR%\bgotrtu0.dll Detected as: TR/Vundo&lt;br /&gt;– %SYSDIR%\uweyiwe0.dll Detected as: TR/Crypt.XPACK.Gen&lt;br /&gt;– %drive%\lot.exe&lt;br /&gt;– %SYSDIR%\ahnfgss0.dll&lt;br /&gt;– %SYSDIR%\ahnsbsb.exe&lt;br /&gt;– %SYSDIR%\ahnxsds0.dll&lt;br /&gt;&lt;br /&gt;It tries to download some files:&lt;br /&gt;– The location is the following:&lt;br /&gt; • http://hjkio.com/xhg2/**********&lt;br /&gt;– The location is the following:&lt;br /&gt; • http://kioytrfd.com/xhg2/**********&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 153); font-weight: bold;"&gt;REGISTRY&lt;/span&gt;&lt;br /&gt;One of the following values is added in order to run the process after reboot:&lt;br /&gt;&lt;br /&gt;–   [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] &lt;!--NO_BR--&gt;&lt;br /&gt;  • "kvasoft"="&lt;span class="dictionary" title="Note: %SYSDIR% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP"&gt;%SYSDIR%&lt;/span&gt;\kva8wr.exe"&lt;br /&gt;&lt;br /&gt;The following registry keys are added in order to load the service after reboot:&lt;br /&gt;–  [HKLM\SOFTWARE\System\CurrentControlSet\Services\KAVsys] &lt;!--NO_BR--&gt;&lt;br /&gt;  •     "Type"=dword:00000001&lt;br /&gt;        "Start"=dword:00000001&lt;br /&gt;        "ErrorControl"=dword:00000001&lt;br /&gt;        "ImagePath"="\??\&lt;span class="dictionary" title="Note: %SYSDIR% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP"&gt;%SYSDIR%&lt;/span&gt;\drivers\klif.sys"&lt;br /&gt;        "DisplayName"="KAVsys"&lt;br /&gt;&lt;br /&gt;The following registry keys are changed:&lt;br /&gt;Various Explorer settings:&lt;!--NO_BR--&gt;&lt;br /&gt;–  [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]&lt;br /&gt;  New value:&lt;br /&gt;  • "NoDriveTypeAutoRun"=dword:00000091&lt;br /&gt;–  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&lt;br /&gt;  Folder\Hidden\SHOWALL]&lt;br /&gt;  New value:&lt;br /&gt;  • "CheckedValue"=dword:00000000&lt;br /&gt;–  [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]&lt;br /&gt;  New value:&lt;br /&gt;  • "ShowSuperHidden"=dword:00000001&lt;br /&gt;    "Hidden"=dword:00000002&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;INJECTION&lt;/span&gt;&lt;br /&gt;One of the following values is added in order to run the process after reboot:&lt;br /&gt;&lt;br /&gt;–   [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] &lt;!--NO_BR--&gt;&lt;br /&gt;  • "kvasoft"="&lt;span class="dictionary" title="Note: %SYSDIR% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP"&gt;%SYSDIR%&lt;/span&gt;\kva8wr.exe"&lt;br /&gt;&lt;br /&gt;The following registry keys are added in order to load the service after reboot:&lt;br /&gt;–  [HKLM\SOFTWARE\System\CurrentControlSet\Services\KAVsys] &lt;!--NO_BR--&gt;&lt;br /&gt;  •     "Type"=dword:00000001&lt;br /&gt;        "Start"=dword:00000001&lt;br /&gt;        "ErrorControl"=dword:00000001&lt;br /&gt;        "ImagePath"="\??\&lt;span class="dictionary" title="Note: %SYSDIR% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP"&gt;%SYSDIR%&lt;/span&gt;\drivers\klif.sys"&lt;br /&gt;        "DisplayName"="KAVsys"&lt;br /&gt;&lt;br /&gt;The following registry keys are changed:&lt;br /&gt;Various Explorer settings:&lt;!--NO_BR--&gt;&lt;br /&gt;–  [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]&lt;br /&gt;  New value:&lt;br /&gt;  • "NoDriveTypeAutoRun"=dword:00000091&lt;br /&gt;–  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\&lt;br /&gt;  Folder\Hidden\SHOWALL]&lt;br /&gt;  New value:&lt;br /&gt;  • "CheckedValue"=dword:00000000&lt;br /&gt;–  [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]&lt;br /&gt;  New value:&lt;br /&gt;  • "ShowSuperHidden"=dword:00000001&lt;br /&gt;    "Hidden"=dword:00000002&lt;br /&gt;&lt;br /&gt;&lt;span class="av_chapter"&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;ROOTKIT TECHNOLOGY&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;strong&gt;Hides the following:&lt;/strong&gt;&lt;br /&gt;– Its own process&lt;br /&gt;&lt;strong&gt;Method used:&lt;/strong&gt;&lt;br /&gt;   • Hidden from Master File Table (MFT)&lt;br /&gt;   • Hidden from Windows API&lt;br /&gt;   • Hidden from Interrupt Descriptor Table (IDT)&lt;br /&gt;____________________________________________&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.free-av.de/en/trialpay_download/1/avira_antivir_personal__free_antivirus.html"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Avira AntiVir Free&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-7821906614070742151?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/7821906614070742151/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/09/virus-trdropagentagla-trojan.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/7821906614070742151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/7821906614070742151'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/09/virus-trdropagentagla-trojan.html' title='Virus: TR/Drop.Agent.agla - Trojan'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-5617772348209375730</id><published>2009-09-01T10:36:00.001+08:00</published><updated>2009-09-01T11:27:25.712+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Iframe'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Info'/><title type='text'>Win32:Frethem</title><content type='html'>&lt;script type="text/javascript"&gt;&lt;!-- google_ad_client = "pub-5072170890756919"; /* 728x90, created 8/31/09 */ google_ad_slot = "1501956245"; google_ad_width = 728; google_ad_height = 90; //--&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Win32:Frethem&lt;/span&gt;&lt;br /&gt;is an Internet worm which spreads via email. It uses its own SMTP engine to send itself to email addresses that it finds in the Microsoft Windows Address Book and in .dbx, .wab, .mbx, .eml, and .mdb files. The email message arrives with the following characteristics:&lt;br /&gt;&lt;br /&gt;Subject: Re: Your password!&lt;br /&gt;Message body:&lt;br /&gt;ATTENTION!&lt;br /&gt;&lt;br /&gt;You can access&lt;br /&gt;very important&lt;br /&gt;information by&lt;br /&gt;this password&lt;br /&gt;&lt;br /&gt;DO NOT SAVE&lt;br /&gt;password to disk&lt;br /&gt;use your mind&lt;br /&gt;&lt;br /&gt;now press&lt;br /&gt;cancel&lt;br /&gt;Attachment: Decrypt-password.exe and Password.txt&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;When this worm is executed, it does the following: It copies itself to the file %windir%\Taskbar.exe&lt;br /&gt;(please note: %windir% is a variable). The worm locates the Windows main installation folder (by default this is C:\Windows or C:\Winnt) and copies itself to that location. It then configures itself to start when you start Windows by adding the value:&lt;br /&gt;Task Bar %windir%\Taskbar.exe&lt;br /&gt;to the registry key:&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;&lt;br /&gt;The worm then obtains email addresses from the Microsoft Windows Address Book and from .dbx, .wab, .mbx, .eml, and .mdb files, and sends itself to those addresses. When the worm arrives by email, it uses both an IFRAME exploit and a MIME exploit, which allow the virus to be executed when you read or even preview the file. Information and a patch for MIME exploit can be found here.&lt;br /&gt;&lt;br /&gt;After sleeping for several hours, the worm copies itself to C:\Windows\All Users\Start Menu\ Programs\Startup\ Setup.exe so that it is executed each time that you start Windows.&lt;br /&gt;&lt;br /&gt;This worm exist in several variants, but none of them have any destructive payload.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-5617772348209375730?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/5617772348209375730/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/09/blog-post.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/5617772348209375730'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/5617772348209375730'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/09/blog-post.html' title='Win32:Frethem'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-4269877423138729335</id><published>2009-07-01T12:24:00.006+08:00</published><updated>2009-07-01T12:41:23.323+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Info'/><title type='text'>Virus: Win32:Ganda</title><content type='html'>&lt;div style="text-align: justify;"&gt;Win32:Ganda is an Internet worm which uses the social ingeneering to force the users to run the infected mail attachment.It also tries to suspend several antiviral and security programs, such as personal firewalls, on infected computer. It modifies executable files (.exe and .scr extensions) by adding a routine for Ganda's launch from a separate file. It spreads through e-mail. A part of infected mails uses "IFRAME vulnerability" of MS Internet Explorer for launching its mail attachment without user intervention. The worm creates the following files on infected computer:&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;%WINDOWS%\scandisk.exe&lt;br /&gt;%WINDOWS%\[8 random characters  a-z].exe&lt;br /&gt;%WINDOWS%\tmpworm.exe    &lt;p&gt;&lt;/p&gt;&lt;p  style="font-weight: bold; text-align: justify;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;In the registry, the worm creates inside the key&lt;br /&gt;&lt;span style="font-weight: normal;"&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;span style="font-weight: normal;"&gt; &lt;span style="font-size:100%;"&gt;the following item&lt;/span&gt;:  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: normal;"&gt;ScanDisk=%WINDOWS%\SCANDISK.exe&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify; font-family: arial; font-weight: bold;"&gt; &lt;/div&gt;&lt;p  style="text-align: justify;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;The worm is launched from the registry at every computer start. Except this, it might be launched from the modified executables, it adds a code for launchig itself from the files in the %WINDOWS% folder to the executable files. The size of modified files is increased of 567 bytes. &lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify; font-family: arial;"&gt;  &lt;/div&gt;&lt;p  style="text-align: justify;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;Note: %WINDOWS% is a folder where the Windows system is installed. It's usually "C:\Windows" on Windows 95, 98 or ME, or "C:\WinNT" on Windows NT, 2000 or XP. Those folder names are default, but user can decide for any other name at Windows system instalation. &lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify; font-family: arial; font-weight: bold;"&gt;  &lt;/div&gt;&lt;p  style="font-weight: bold; text-align: justify;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;The worm tries suspend running services named:&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-style: italic;font-family:arial;font-size:100%;"  &gt;f-secure, firewall, kaspersky, mcafee, norton, pc-cillin, sophos, symantec, trend micro, virus&lt;/span&gt;&lt;div style="text-align: justify; font-family: arial; font-weight: bold;"&gt;  &lt;/div&gt;&lt;p  style="font-weight: bold; text-align: justify;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;The worm spread through email to addresses it founds in the Windows Address Book or in the files with .dbx, .eml or .htm extensions. Infected mails are either english or swedish, depending on the system language of infected computer. Infected mail have the following features: Subject line is either empty, or it's one of the following phrases (in the english version):&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul  style="font-family:arial;"&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Catlover&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Disgusting propaganda&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;DISKRIMINERAD !!!! &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;GO USA !!!! &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;G.W Bush animation &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Is USA a UFO? &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Is USA always number one? &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;LINUX &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Nazi propaganda? &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Screensaver advice &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Spy pics &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p face="arial" style="font-weight: bold; text-align: justify;"&gt;          &lt;/p&gt;&lt;div style="text-align: justify; font-family: arial; font-weight: bold;"&gt;  &lt;/div&gt;&lt;p  style="text-align: justify;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;The attachment has size of  45056 bytes with random 2-letter name and scr extension. &lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify; font-family: arial; font-weight: bold;"&gt;  &lt;/div&gt;&lt;p  style="text-align: justify;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;The worm fakes sender address. It chooses message body randomly from 10 messages, either english and swedish.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-weight: bold; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.avast.com/eng/viruses.html"&gt;&lt;span style="font-style: italic;"&gt;Avast Viruses Info&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-4269877423138729335?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/4269877423138729335/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/07/virus-win32ganda.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4269877423138729335'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4269877423138729335'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/07/virus-win32ganda.html' title='Virus: Win32:Ganda'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-5310619280275720711</id><published>2009-06-26T22:14:00.003+08:00</published><updated>2009-06-26T22:23:07.225+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Gumblar'/><title type='text'>Virus: Gumblar.cn</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;The attackers behind a series of rapidly spreading Web site compromises have begun using a new domain to deliver their malicious code, security experts say.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;The attacks, collectively referred to as "Gumblar" by ScanSafe and "Troj/JSRedir-R" by Sophos, grew 188 percent over the course of a week, ScanSafe said late last week. The Gumblar infections accounted for 42 percent of all infections found on Web sites last week, Sophos said.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Over the weekend, the Chinese Web domain used to deliver the malicious code--gumblar.cn--stopped responding, according to Unmask Parasites, a service used to detect malicious code embedded in Web pages. The attacks' malicious payload has, however, continued to be delivered from a different source, the martuz.cn domain, Unmask Parasites said Monday in an advisory.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;"They have slightly modified the script and now inject a new version that loads malicious content from a new domain," Unmask Parasites said.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Changes to the script make it more difficult to identify and stop detection by the Google Chrome browser, Unmask Parasites said.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Gumblar was first detected in March and has spread more quickly since then, against the expectations of security experts.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;"A typical series of website compromises reaches peak within the first week or so and subsequently begins declining in intensity as detection is added by signature vendors, user awareness increases and website operators begin cleaning the affected sites," ScanSafe senior security researcher Mary Landesman, said late last week in an advisory.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;In the Gumblar attacks, the opposite is occurring, partly because Web site administrators themselves are affected by the attacks as they try to address the problem, ScanSafe said.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Sites affected include Tennis.com, Variety.com, and Coldwellbanker.com, according to ScanSafe.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;The attacks were carried out in multiple stages, beginning in March, when a number of Web sites were compromised and attack code embedded within them, ScanSafe said.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Then, in early May, as Web site operators began to clean up their sites, the attackers replaced the original malicious code with dynamically generated and heavily obfuscated JavaScript, meaning that the scripts change from page to page and are difficult for security tools to spot.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;The scripts attempt to exploit vulnerabilities in Adobe's Acrobat Reader and Flash Player to deliver code that injects malicious search results when a user searches Google on Internet Explorer, ScanSafe said.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;They also search the victim's system for FTP credentials that can be used to compromise further Web sites, the company said.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;The malicious code embedded on a user's system was previously downloaded from gumblar.cn, a Chinese domain associated with Russian and Latvian IP addresses, delivering code from servers based in the U.K., according to ScanSafe. That domain has now changed to martuz.cn.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Matthew Broersma of ZDNet UK reported from London.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;More about "&lt;a href="http://www.cbsnews.com/stories/2009/05/29/tech/cnettechnews/main5047992.shtml?source=RSSattr=SciTech_5047992"&gt;Gumblar&lt;/a&gt;"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-5310619280275720711?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/5310619280275720711/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/06/virus-gumblar.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/5310619280275720711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/5310619280275720711'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/06/virus-gumblar.html' title='Virus: Gumblar.cn'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-4903283444794711453</id><published>2009-05-31T09:37:00.004+08:00</published><updated>2009-05-31T09:49:13.322+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Download'/><category scheme='http://www.blogger.com/atom/ns#' term='Info'/><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti Spyware'/><title type='text'>Free Antivirus : a-squared Free 4.5.0.1 (Latest Version)</title><content type='html'>Security must not be a privilege. Under this motto, Emsi Software provides the Malware scanner a-squared Free completely free of charge for private use. But it is not a very limited version, it is a full tool to clean your computer from Malware. Not only Spywares, as detected by classic Anti-Spyware programs, but also especially Trojans, Backdoors, Worms, Dialers, Keyloggers and a lot of other destructive pests, which makes it dangerous to surf the web.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_a8TDdqP3llE/SiHhIHggx7I/AAAAAAAABH8/HLk6gvweZM8/s1600-h/screenshot_11.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 236px; height: 170px;" src="http://4.bp.blogspot.com/_a8TDdqP3llE/SiHhIHggx7I/AAAAAAAABH8/HLk6gvweZM8/s200/screenshot_11.png" alt="" id="BLOGGER_PHOTO_ID_5341798162608736178" border="0" /&gt;&lt;/a&gt;&lt;div class="description"&gt; &lt;p&gt;a-squared removes reliably:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Trojans, Backdoors, Keyloggers, Rootkits&lt;/li&gt;&lt;li&gt;Worms, Bots&lt;/li&gt;&lt;li&gt;Dialers&lt;/li&gt;&lt;li&gt;Spyware, Adware&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://secure.element5.com/esales/checkout.html?PRODUCT%5B187060%5D=1&amp;amp;COUPON1=EMS219&amp;amp;affiliateid=200091800"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 312px; height: 40px;" src="http://www.emsisoft.com/images/logos/a-squared_anti-malware_468x60.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-4903283444794711453?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/4903283444794711453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/05/free-antivirus-squared-free-4501-latest.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4903283444794711453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4903283444794711453'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/05/free-antivirus-squared-free-4501-latest.html' title='Free Antivirus : a-squared Free 4.5.0.1 (Latest Version)'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_a8TDdqP3llE/SiHhIHggx7I/AAAAAAAABH8/HLk6gvweZM8/s72-c/screenshot_11.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-2786046042690789703</id><published>2009-05-31T09:18:00.004+08:00</published><updated>2009-05-31T09:32:54.879+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Trial Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti Spyware'/><title type='text'>Free Trial Antivirus : AVG Anti-Spyware</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://images.apphit.com/59/icon.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 32px; height: 32px;" src="http://images.apphit.com/59/icon.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;AVG Anti-Spyware 7.5.1.43&lt;/span&gt; &lt;/div&gt;Anti-Virus programs offer insufficient protection against urgently growing threats like Trojans, Worms, Dialers, Hijackers, Spyware and Keyloggers. That's where the protection of ewido anti-spyware begins and supplements existing security applications to create a complete security system - because only a complete security system works effectively.&lt;br /&gt;&lt;br /&gt; * NEW Completely renewed user interface&lt;br /&gt; * NEW Possibility to create exceptions&lt;br /&gt; * NEW Shredder for secure file deletion&lt;br /&gt; * NEW XP Antispy&lt;br /&gt; * NEW BHO Viewer&lt;br /&gt; * NEW LSP Viewer&lt;br /&gt; * Heuristics to detect unknown threats&lt;br /&gt; * Scanning and cleaning of the Windows registry&lt;br /&gt; * Support for NTFS-ADS scanning&lt;br /&gt; * Daily database updates&lt;br /&gt; * Patch proof by using strong signatures&lt;br /&gt; * Analysis tools (startup, connections and processes)&lt;br /&gt; * Intelligent online-update&lt;br /&gt; * Scan inside archives&lt;br /&gt; * Secure detection and deletion of DLL-Trojans&lt;br /&gt; * Generic crypter detection through emulation&lt;br /&gt; * Generic binder detection&lt;br /&gt; * Free E-Mail Support&lt;br /&gt; * Automatic Clean Engine&lt;br /&gt; * Quarantine for suspicious files&lt;br /&gt; * Multilingual User Interface&lt;br /&gt;&lt;br /&gt;Additional features of the Plus-Version&lt;br /&gt;&lt;br /&gt; * NEW Scheduled scans&lt;br /&gt; * Real-time monitoring of the entire system&lt;br /&gt; * Memory Scan detects active threats&lt;br /&gt; * Self-protection at kernel layer guarantees gapless monitoring&lt;br /&gt; * Automatic online-update&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_a8TDdqP3llE/SiHdCGWrxYI/AAAAAAAABH0/qfP0J9OIwN4/s1600-h/screenshot_1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 231px;" src="http://3.bp.blogspot.com/_a8TDdqP3llE/SiHdCGWrxYI/AAAAAAAABH0/qfP0J9OIwN4/s320/screenshot_1.png" alt="" id="BLOGGER_PHOTO_ID_5341793661173351810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This setup contains the free as well as the paid version of ewido anti-spyware. After the installation, a free 30-day trial version containing all the extensions of the full version will be activated. At the end of the trial, these extensions will be deactivated and the program will turn into a feature-limited freeware version. The purchased license code can be entered at any time.&lt;br /&gt;&lt;br /&gt;This product was formerly knows as Ewido Security Suite&lt;br /&gt;&lt;br /&gt;&lt;a href="http://free.avg.com/download-avg-anti-spyware-and-anti-rootkit"&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;AVG AntiSpyware&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-2786046042690789703?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/2786046042690789703/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/05/free-trial-antivirus-avg-anti-spyware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/2786046042690789703'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/2786046042690789703'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/05/free-trial-antivirus-avg-anti-spyware.html' title='Free Trial Antivirus : AVG Anti-Spyware'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_a8TDdqP3llE/SiHdCGWrxYI/AAAAAAAABH0/qfP0J9OIwN4/s72-c/screenshot_1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-1446046605940663930</id><published>2009-05-21T09:51:00.004+08:00</published><updated>2009-05-21T12:14:20.122+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Download'/><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>Free Download Antivirus: ThreatFire Antivirus</title><content type='html'>&lt;div style="text-align: justify;"&gt;PCs are under constant attack from viruses, spyware and identity theft. Every day you hear about a new threat to your PC. They're coming faster than ever before, they're getting harder to stop and traditional antivirus products are not able to keep up.&lt;br /&gt;&lt;br /&gt;Will your antivirus software catch the latest malware that just came out today? In most cases, no, because it simply does not know how to detect it yet. But ThreatFire's ActiveDefense technology does, and has proven to provide up to 243% more protection when combined with traditional AntiVirus products&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_a8TDdqP3llE/ShS1KhBFa4I/AAAAAAAABA0/H0J8RJF1j_8/s1600-h/tflogo.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 124px; height: 80px;" src="http://2.bp.blogspot.com/_a8TDdqP3llE/ShS1KhBFa4I/AAAAAAAABA0/H0J8RJF1j_8/s320/tflogo.gif" alt="" id="BLOGGER_PHOTO_ID_5338090650607119234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;If I already have antivirus software why do I need ThreatFire?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;ThreatFire is dramatically different to traditional antivirus software. Normal antivirus products usually need to have first identified and seen a threat before they can provide adequate protection against it. The protection is then provided via a signature or fingerprint update, which must first be written by an antivirus researcher. This creates a large window of time where threats are undetected and can therefore infect your PC even when you have antivirus software installed.&lt;br /&gt;&lt;br /&gt;&lt;a style="font-weight: bold;" href="http://www.threatfire.com/download/"&gt;Free Download ThreatFire&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-1446046605940663930?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/1446046605940663930/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/05/free-download-antivirus-threatfire.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/1446046605940663930'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/1446046605940663930'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/05/free-download-antivirus-threatfire.html' title='Free Download Antivirus: ThreatFire Antivirus'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_a8TDdqP3llE/ShS1KhBFa4I/AAAAAAAABA0/H0J8RJF1j_8/s72-c/tflogo.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-3959187647601773590</id><published>2009-05-06T16:14:00.005+08:00</published><updated>2009-05-22T20:35:32.054+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Info'/><title type='text'>Virus: Win32:VB-CD alias Kamasutra</title><content type='html'>The worm Win32:VB-CD [Wrm] or Win32:VB-CD2 [Wrm] is a mail worm known also as Nyxem-E, Blackmal-F, MyWife-D or Grew or (perhaps locally and usually in news) as Kamasutra.This worm spreads by e-mail and by network shares. It kills processes of miscelaneous antivirus and security programs and deletes files of them. The worm is destructive, tries to delete files of certain types every 3-rd day in month.&lt;p&gt;&lt;/p&gt; &lt;p&gt;When executed, the worm creates one of the listed files:&lt;/p&gt;    &lt;ul&gt;&lt;li&gt;%windows%\Rundll16.exe&lt;/li&gt;&lt;li&gt;%system%\New winzip file.exe&lt;/li&gt;&lt;li&gt;%system%\sample.zip&lt;/li&gt;&lt;li&gt;%system%\winzip_tmp.exe&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;and files:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;%system%\scanregw.exe&lt;/li&gt;&lt;li&gt;%system%\update.exe&lt;/li&gt;&lt;li&gt;%system%\sample.zip&lt;/li&gt;&lt;li&gt;%system%\winzip.exe&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;The worm is autostarted with Windows using the registry key &lt;/p&gt; &lt;pre style="color: rgb(204, 0, 0);"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/pre&gt; Its item „ScanRegistry” has the value “%System%\scanregw.exe /scan” &lt;p style="font-weight: bold;"&gt;The worm collects mail addresses from documents on the infected computer. The infected mail has one of the Subjects:&lt;/p&gt; &lt;pre&gt;*Hot Movie*&lt;br /&gt;A Great Video&lt;br /&gt;Arab sex DSC-00465.jpg&lt;br /&gt;eBook.pdf&lt;br /&gt;Fuckin Kama Sutra pics&lt;br /&gt;Fw:&lt;br /&gt;Fw: DSC-00465.jpg&lt;br /&gt;Fw: Funny :)&lt;br /&gt;Fw: Picturs&lt;br /&gt;Fw: Sexy&lt;br /&gt;Fwd: image.jpg&lt;br /&gt;Fwd: Photo&lt;br /&gt;give me a kiss&lt;br /&gt;Miss Lebanon 2006&lt;br /&gt;My photos&lt;br /&gt;Part 1 of 6 Video clipe&lt;br /&gt;Re:&lt;br /&gt;Re: Sex Video&lt;br /&gt;School girl fantasies gone bad&lt;br /&gt;The Best Videoclip Ever&lt;br /&gt;the file&lt;br /&gt;Word file&lt;br /&gt;You Must View This Videoclip!&lt;br /&gt;&lt;/pre&gt; &lt;p style="font-weight: bold;"&gt;The infected attachment is in the file named&lt;/p&gt; &lt;pre&gt;007.pif&lt;br /&gt;04.pif&lt;br /&gt;677.pif&lt;br /&gt;document.pif&lt;br /&gt;DSC-00465.Pif&lt;br /&gt;eBook.PIF&lt;br /&gt;image04.pif&lt;br /&gt;New_Document_file.pif&lt;br /&gt;photo.pif&lt;br /&gt;School.pif&lt;br /&gt;&lt;/pre&gt; &lt;p style="font-weight: bold;"&gt;Sometimes, the attachment is MIME encoded and uses one of the names&lt;/p&gt; &lt;pre&gt;3.92315089702606E02.UUE&lt;br /&gt;Attachments00.HQX&lt;br /&gt;Attachments001.BHX&lt;br /&gt;Attachments[001].B64&lt;br /&gt;eBook.Uu&lt;br /&gt;Original Message.B64&lt;br /&gt;SeX.mim&lt;br /&gt;Sex.mim&lt;br /&gt;Video_part.mim&lt;br /&gt;WinZip.BHX&lt;br /&gt;Word_Document.hqx&lt;br /&gt;Word_Document.uu&lt;br /&gt;&lt;/pre&gt;  &lt;p&gt;In such case, special tool is needed to unpack and execute the worm.&lt;/p&gt;  &lt;p&gt;On every 3-rd day of month, the worm tries to delete data files with the extensions *.dmp, *.doc, *.mdb, *.mde, *.pdf, *.pps, *.ppt, *.psd, *.rar, *.xls, *.zip &lt;/p&gt; &lt;p&gt;&lt;i&gt;avast!&lt;/i&gt; with &lt;a href="http://www.avast.com/eng/updates.html"&gt;VPS file&lt;/a&gt; dated on or after &lt;span style="color: rgb(51, 51, 255);"&gt;17th January 2006&lt;/span&gt; is able to detect this worm.&lt;/p&gt;&lt;p&gt;_________________________________________________________&lt;/p&gt;&lt;p&gt;&lt;a href="http://lapayo.postmedia.hop.clickbank.net/"&gt;Windows Repair Kit&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-3959187647601773590?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/3959187647601773590/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/05/virus-win32vb-cd-alias-kamasutra.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/3959187647601773590'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/3959187647601773590'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/05/virus-win32vb-cd-alias-kamasutra.html' title='Virus: Win32:VB-CD alias Kamasutra'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-1425330810604821570</id><published>2009-05-02T06:43:00.005+08:00</published><updated>2009-05-02T07:19:37.416+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTI VIRUS: Panda Cloud Antivirus</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.cloudantivirus.com/App_Themes/Default/Images/freeAntivirus_en.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 97px; height: 97px;" src="http://www.cloudantivirus.com/App_Themes/Default/Images/freeAntivirus_en.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Thanks to Panda Security’s Collective Intelligence malware and goodware online database, Panda Cloud Antivirus detects more malware than traditional signature-based solutions which take longer to detect the most recent, and therefore most dangerous, variants.&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;With Panda Cloud Antivirus we introduce a new protection model based on a thin-client agent &amp;amp; server architecture which services malware protection as opposed to locally installed products. By combining local detection technologies with cloud-scanning capabilities and applying non-intrusive interception techniques on the client architecture, Panda Cloud Antivirus provides some of the best protection with a lightweight antivirus thin-client agent that barely consumes any PC resources.&lt;/span&gt;&lt;/div&gt;&lt;h1 style="text-align: center;"&gt;&lt;img id="Img_Light" title="Light" src="http://www.cloudantivirus.com/App_Themes/Default/Images/ico_light.gif" alt="Light" style="border-width: 0px; height: 36px; width: 36px;" /&gt; Light&lt;/h1&gt;                             &lt;p&gt;&lt;a href="http://www.cloudantivirus.com/"&gt;Panda Cloud Antivirus&lt;/a&gt; protects you while you browse, play or work and you won’t even notice it. It is extremely light as all the work is done in the cloud.&lt;/p&gt;&lt;div id="secure"&gt;&lt;div style="text-align: center;"&gt;                             &lt;/div&gt;&lt;h1 style="text-align: center;"&gt;&lt;img id="Img_Secure" title="Secure" src="http://www.cloudantivirus.com/App_Themes/Default/Images/ico_secure.gif" alt="Secure" style="border-width: 0px; height: 36px; width: 36px;" /&gt; Secure&lt;/h1&gt;                             &lt;p&gt;&lt;a href="http://www.cloudantivirus.com/"&gt;Panda Cloud Antivirus&lt;/a&gt; provides you with the fastest protection against the newest viruses thanks to its cloud-scanning from PandaLabs’ servers.&lt;/p&gt;&lt;h1 style="text-align: center;"&gt;&lt;img id="Img_Easy" title="Easy" src="http://www.cloudantivirus.com/App_Themes/Default/Images/ico_easy.gif" alt="Easy" style="border-width: 0px; height: 36px; width: 36px;" /&gt; Easy&lt;/h1&gt;                             &lt;p&gt;&lt;a href="http://www.cloudantivirus.com/"&gt;Panda Cloud Antivirus&lt;/a&gt; is truly install and forget. Don’t worry about updates, configuration or complicated decisions ever again.&lt;/p&gt;&lt;/div&gt;                      &lt;div id="light"&gt;&lt;div style="text-align: center;"&gt;                             &lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://blog.cloudantivirus.com/2009/04/29/welcome-to-the-panda-cloud-antivirus-beta/"&gt;Read more&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-1425330810604821570?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/1425330810604821570/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/05/free-anti-virus-panda-cloud-antivirus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/1425330810604821570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/1425330810604821570'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/05/free-anti-virus-panda-cloud-antivirus.html' title='FREE ANTI VIRUS: Panda Cloud Antivirus'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-4464691870291660637</id><published>2009-04-25T18:34:00.003+08:00</published><updated>2009-04-25T18:50:20.219+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTI VIRUS: PC Tools AntiVirus Free Edition</title><content type='html'>&lt;div id="productdesc"&gt;&lt;div style="text-align: justify;"&gt;   &lt;/div&gt;&lt;p style="text-align: justify;"&gt;With &lt;strong style="color: rgb(51, 51, 255);"&gt;PC Tools AntiVirus Free Edition&lt;/strong&gt; you are protected against the most nefarious cyber-threats attempting to gain access to your PC and personal information. Going online without protection against the latest fast-spreading virus and worms, such as Netsky, Mytob and MyDoom, can result in infections within minutes.&lt;/p&gt; &lt;div class="screenshot"&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.pctools.com/res/zoom.html?/res/images/anti-virus/screenshot.gif" onclick="window.open('/res/zoom.html?/res/images/anti-virus/screenshot.gif', '', 'resizable=1,height=200,width=200'); return false;" onmouseover="status='Download PC Tools AntiVirus Free Edition!'; return true;"&gt;&lt;img src="http://www.pctools.com/res/images/anti-virus/thumbnail.gif" alt="Screenshot" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;   &lt;div style="text-align: center;"&gt;&lt;a href="http://www.pctools.com/res/zoom.html?/res/images/anti-virus/screenshot.gif" onclick="window.open('/res/zoom.html?/res/images/anti-virus/screenshot.gif', '', 'resizable=1,height=200,width=200'); return false;" onmouseover="status='Download PC Tools AntiVirus Free Edition!'; return true;"&gt;[+] Click to Enlarge&lt;/a&gt;&lt;/div&gt;&lt;/div&gt; &lt;p&gt;Once infected, the virus will usually attempt to spread itself to your friends, family and associates by accessing your email contacts and networked PCs. The infection may also allow hackers to access files on your PC, use it to launch attacks against other computers and websites or to send mass SPAM email.&lt;/p&gt;&lt;p style="text-align: justify;"&gt;That's why &lt;b style="color: rgb(51, 51, 255);"&gt;PC Tools AntiVirus Free Edition&lt;/b&gt; provides world-leading protection, with rapid database updates, IntelliGuard™ real-time protection and comprehensive system scanning to ensure your system remains safe and virus free. PC Tools products are trusted and used by millions of people everyday to protect their home and business computers against online threats.&lt;br /&gt;&lt;/p&gt;   &lt;/div&gt;   &lt;div id="productfeaturesmain"&gt;   &lt;h2 style="color: rgb(51, 102, 255);"&gt;&lt;span style="font-size:100%;"&gt;PC Tools AntiVirus Free Edition feature highlights&lt;/span&gt;&lt;/h2&gt;   &lt;ul id="productfeatures"&gt;&lt;li&gt;Protects your PC as you are working, surfing and playing&lt;/li&gt;&lt;li&gt;Detects, quarantines, disinfects and destroys Viruses, Trojans and Worms&lt;/li&gt;&lt;li&gt;IntelliGuard™ protects your computer against threats in real-time&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Automatically checks for frequent updates against the latest threats&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Best of all it's FREE. No catches, limitations or time-limit&lt;/li&gt;&lt;/ul&gt;&lt;a href="http://www.pctools.com"&gt;PC Tools AntiVirus&lt;/a&gt;&lt;br /&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-4464691870291660637?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/4464691870291660637/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-anti-virus-pc-tools-antivirus-free.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4464691870291660637'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4464691870291660637'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-anti-virus-pc-tools-antivirus-free.html' title='FREE ANTI VIRUS: PC Tools AntiVirus Free Edition'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-4921727031462731230</id><published>2009-04-23T10:05:00.007+08:00</published><updated>2009-05-22T20:32:25.480+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti Spyware'/><title type='text'>Free Anti Virus: SuperAntiSpyware Free Edition</title><content type='html'>&lt;p style="text-align: justify;"&gt;SuperAntiSpyware, a next generation product, with its Multi-Dimensional Scanning and Process Interrogation Technology will detect spyware and remove over 1,000,000 pests such as Vundo, ZLob, SmitFraud, WinFixer, VirusRay, and VirusHeat. Repair broken Internet connections, desktops, registry editing, and task manager. The program provides complete and custom scanning of hard drives, removable drives, memory, registry, individual folders include trusting items and excluding folders for complete customization of scanning. Detect and remove spyware, adware, malware, Trojans, dialers, worms, keyloggers, and hijackers. Prevent potentially harmful software from installing or re-installing. First Chance Prevention examines over 50 critical points of your system each time your system starts up and shuts down to eliminate threats before they have a chance to infect and infiltrate your system. Our Direct Disk Access (DDA) technology sees rootkits others miss.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_a8TDdqP3llE/Se_SuYP1XtI/AAAAAAAAAtI/V-8z1BiV-UI/s1600-h/IMGSASScanningControlFull.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 246px;" src="http://4.bp.blogspot.com/_a8TDdqP3llE/Se_SuYP1XtI/AAAAAAAAAtI/V-8z1BiV-UI/s320/IMGSASScanningControlFull.gif" alt="" id="BLOGGER_PHOTO_ID_5327708578427264722" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;Version 4.25.1014 includes Smart Definitions to detect zero-day threats,Improved rootkit removal technology to handle rootkits that disable security applications,Updated Direct Registry Access (DRA) Technology.&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;a href="http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE"&gt;Super Antispyware.com&lt;/a&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;a href="http://lapayo.sspykiller.hop.clickbank.net/"&gt;Anti Spyware Software&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;a href="http://download.cnet.com/SuperAntiSpyware-Free-Edition/3000-8022_4-10523889.html?tag=rbxcrdl1"&gt;CNet Download.com&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;                   &lt;script type="text/javascript"&gt;      window.addEvent('domready', function(){         var productThumbs = $$('#productThumbs span');         var imageOverlays = $$('#imageOverlay img');          for(var i=0;i&lt;productthumbs.length;i++){ imageoverlay =" function(thumb," hasvideo =" false;" hasvideo="="&gt; &lt;div style="text-align: justify;" section="pub"&gt;&lt;style type="text/css"&gt;     .pageType3000 .mediaGallery{         position:relative;         float:right;         background-color:#ededed;         margin:10px 0px 10px 15px;         width:365px;     } &lt;/style&gt;            &lt;strong&gt;From                                  &lt;a href="http://download.cnet.com/windows/superantispyware/3260-2023_4-6281995.html"&gt;SUPERAntiSpyware&lt;/a&gt;:                          &lt;/strong&gt;         &lt;p&gt;SuperAntiSpyware, a next generation product, with its Multi-Dimensional Scanning and Process Interrogation Technology will detect spyware and remove over 1,000,000 pests such as Vundo, ZLob, SmitFraud, WinFixer, VirusRay, and VirusHeat. Repair broken Internet connections, desktops, registry editing, and task manager. The program provides complete and custom scanning of hard drives, removable drives, memory, registry, individual folders include trusting items and excluding folders for complete customization of scanning. Detect and remove spyware, adware, malware, Trojans, dialers, worms, keyloggers, and hijackers. Prevent potentially harmful software from installing or re-installing. First Chance Prevention examines over 50 critical points of your system each time your system starts up and shuts down to eliminate threats before they have a chance to infect and infiltrate your system. Our Direct Disk Access (DDA) technology sees rootkits others miss.&lt;/p&gt;&lt;p&gt;&lt;a href="http://dw.com.com/redir?edId=3&amp;amp;siteId=4&amp;amp;oId=3000-8022_4-10523889&amp;amp;ontId=8022_4&amp;amp;spi=44e2f451a2b6d13716510be330745891&amp;amp;lop=link&amp;amp;tag=tdw_dltext&amp;amp;ltype=dl_dlnow&amp;amp;pid=11007953&amp;amp;mfgId=6281995&amp;amp;merId=6281995&amp;amp;pguid=TMy@UAoPjFsAAC4fTXoAAAEW&amp;amp;destUrl=http%3A%2F%2Fdownload.cnet.com%2F3001-8022_4-10523889.html%3Fspi%3D44e2f451a2b6d13716510be330745891"&gt;Download now&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Version 4.25.1014 includes Smart Definitions to detect zero-day threats,Improved rootkit removal technology to handle rootkits that disable security applications,Updated Direct Registry Access (DRA) Technology.&lt;/p&gt;&lt;div id="ads_catDiv"&gt;&lt;img src="http://i.i.com.com/cnwk.1d/Ads/common/spon-warrow.gif" width="68" height="10" /&gt;    &lt;div class="ads_catTitle"&gt;&lt;a href="http://adlog.com.com/adlog/c/r=13327&amp;amp;s=850668&amp;amp;o=20:2023:8022:&amp;amp;h=cn&amp;amp;p=2&amp;amp;b=6&amp;amp;l=en_US&amp;amp;site=4&amp;amp;pt=3000&amp;amp;nd=8022&amp;amp;pid=&amp;amp;cid=11007953&amp;amp;pp=100&amp;amp;e=3&amp;amp;rqid=01c18-ad-e449EF6C3F1A241B&amp;amp;orh=&amp;amp;oepartner=&amp;amp;epartner=&amp;amp;ppartner=&amp;amp;pdom=download.cnet.com&amp;amp;cpnmodule=&amp;amp;count=&amp;amp;ra=60.53.70.62&amp;amp;pg=TMy@UAoPjFsAAC4fTXoAAAEW&amp;amp;t=2009.04.23.02.04.28/http://download.zonealarm.com/bin/promotions/zass/20081015.html?cid=W200023" target="_top"&gt;Recommended Security&lt;/a&gt;&lt;/div&gt;    &lt;div class="ads_catCopy"&gt;ZoneAlarm Suite - Editors' Choice for PC Security.  Download Free Now!&lt;/div&gt;    &lt;div class="ads_catURLLink"&gt;&lt;a href="http://adlog.com.com/adlog/c/r=13327&amp;amp;s=850668&amp;amp;o=20:2023:8022:&amp;amp;h=cn&amp;amp;p=2&amp;amp;b=6&amp;amp;l=en_US&amp;amp;site=4&amp;amp;pt=3000&amp;amp;nd=8022&amp;amp;pid=&amp;amp;cid=11007953&amp;amp;pp=100&amp;amp;e=3&amp;amp;rqid=01c18-ad-e449EF6C3F1A241B&amp;amp;orh=&amp;amp;oepartner=&amp;amp;epartner=&amp;amp;ppartner=&amp;amp;pdom=download.cnet.com&amp;amp;cpnmodule=&amp;amp;count=&amp;amp;ra=60.53.70.62&amp;amp;pg=TMy@UAoPjFsAAC4fTXoAAAEW&amp;amp;t=2009.04.23.02.04.28/http://download.zonealarm.com/bin/promotions/zass/20081015.html?cid=W200023" target="_top"&gt;Download Now&lt;/a&gt;&lt;/div&gt;   &lt;/div&gt;&lt;/div&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-4921727031462731230?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/4921727031462731230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-anti-virussuperantispyware-free.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4921727031462731230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4921727031462731230'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-anti-virussuperantispyware-free.html' title='Free Anti Virus: SuperAntiSpyware Free Edition'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_a8TDdqP3llE/Se_SuYP1XtI/AAAAAAAAAtI/V-8z1BiV-UI/s72-c/IMGSASScanningControlFull.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-4883022401997900908</id><published>2009-04-23T09:29:00.003+08:00</published><updated>2009-04-23T09:52:32.483+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>Return of AVG's LinkScanner</title><content type='html'>&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; color: rgb(51, 51, 51);font-family:verdana,geneva;font-size:11;"  &gt;&lt;div style="margin: 0pt 0pt 10px; font-family: verdana,geneva; font-style: normal; font-variant: normal; font-weight: normal; font-size: 11px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: rgb(51, 51, 51);"&gt;&lt;div style="text-align: justify;"&gt;                         &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;When AVG Technologies slurped up Exploit Prevention Labs, it rolled the standalone LinkScanner security app into its popular antivirus offerings. While the newfound ability to rate search results and live Web pages for safety ratings lent &lt;/span&gt;&lt;a rel="nofollow" target="_blank" href="http://ct.download.com/clicks?t=185996811-7fb3b501d449cb7aba577f3cf2f11539-bf&amp;amp;brand=DOWNLOAD&amp;amp;s=5"&gt;AVG products&lt;/a&gt;  &lt;span style="color: rgb(255, 255, 255);"&gt;some extra relevancy and clout, not everyone wants to download a full-blown security app just to get a warning or go-ahead to search a Web site.&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;Thankfully, AVG Technologies has seen the error of its bundling-only ways, and has rereleased&lt;/span&gt; &lt;a rel="nofollow" target="_blank" href="http://ct.download.com/clicks?t=185996812-7fb3b501d449cb7aba577f3cf2f11539-bf&amp;amp;brand=DOWNLOAD&amp;amp;s=5"&gt;LinkScanner&lt;/a&gt; &lt;span style="color: rgb(255, 255, 255);"&gt;as a &lt;/span&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;free&lt;/span&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;, standalone add-on for Firefox or Internet Explorer once again. This is particularly sanguine news for those who noted performance bungles when using rival software like McAfee SiteAdvisor (for&lt;/span&gt; &lt;a rel="nofollow" target="_blank" href="http://ct.download.com/clicks?t=185996813-7fb3b501d449cb7aba577f3cf2f11539-bf&amp;amp;brand=DOWNLOAD&amp;amp;s=5"&gt;Firefox&lt;/a&gt; &lt;span style="color: rgb(255, 255, 255);"&gt;and &lt;/span&gt;&lt;a rel="nofollow" target="_blank" href="http://ct.download.com/clicks?t=185996814-7fb3b501d449cb7aba577f3cf2f11539-bf&amp;amp;brand=DOWNLOAD&amp;amp;s=5"&gt;IE&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;).&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify; color: rgb(255, 255, 255);"&gt;  &lt;/div&gt;&lt;p style="text-align: justify; color: rgb(255, 255, 255);"&gt;Those well-versed in the LinkScanner of yore won't see too many changes in the new LinkScanner 8.5. The usual red, yellow, and green flags emerge on Google and Yahoo search results, and on the Web page itself, to tip you off if the page in question might contain harmful or seedy elements.&lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;We're glad to see LinkScanner back on its own, and after you&lt;/span&gt; &lt;a rel="nofollow" target="_blank" href="http://ct.download.com/clicks?t=185996815-7fb3b501d449cb7aba577f3cf2f11539-bf&amp;amp;brand=DOWNLOAD&amp;amp;s=5"&gt;read up on this handy security scout&lt;/a&gt;, &lt;span style="color: rgb(255, 255, 255);"&gt;you might be, too.&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;   &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;a rel="nofollow" target="_blank" href="http://ct.download.com/clicks?t=185996816-7fb3b501d449cb7aba577f3cf2f11539-bf&amp;amp;brand=DOWNLOAD&amp;amp;s=5"&gt;Read the hands-on review of Link Scanner&lt;/a&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;a rel="nofollow" target="_blank" href="http://ct.download.com/clicks?t=185996817-7fb3b501d449cb7aba577f3cf2f11539-bf&amp;amp;brand=DOWNLOAD&amp;amp;s=5"&gt;Download LinkScanner 8.5&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;span class="email"&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;CNET Downloads Dispatch for Windows&lt;/span&gt; ( &lt;/span&gt;&lt;a rel="nofollow" target="_blank" href="http://ct.download.com/clicks?t=185996818-7fb3b501d449cb7aba577f3cf2f11539-bf&amp;amp;brand=DOWNLOAD&amp;amp;s=5"&gt;Download.com&lt;/a&gt; )&lt;a rel="nofollow" target="_blank" href="http://ct.download.com/clicks?t=185996818-7fb3b501d449cb7aba577f3cf2f11539-bf&amp;amp;brand=DOWNLOAD&amp;amp;s=5"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/p&gt;           &lt;/div&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-4883022401997900908?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/4883022401997900908/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/return-of-avgs-linkscanner.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4883022401997900908'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4883022401997900908'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/return-of-avgs-linkscanner.html' title='Return of AVG&apos;s LinkScanner'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-6940757501086620896</id><published>2009-04-17T09:32:00.004+08:00</published><updated>2009-04-17T09:41:47.751+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>Virus: Win32:Banker [Trojan Horse]</title><content type='html'>&lt;p style="text-align: justify;"&gt; Win32:Banker is a family of Trojans capable of monitoring user activity and stealing private information. Win32:Banker monitors user’s internet access. If certain websites (banking, payment system) are visited, Win32:Banker will log user’s activity. Win32:Banker will than send all the stolen details to the attacker. &lt;/p&gt;&lt;h2 style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;Description&lt;/span&gt;&lt;/h2&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Win32:Banker is a family of Trojans capable of stealing private information such as account numbers, passwords and banking credentials. Many variants can wait in the background and monitor user's internet activity. A logging procedure starts when a certain website is accessed, or if the address of an accessed website contains certain words. Many variants may supplement legitimate banking or payment system websites to get user details. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; After getting the user details, Win32:Banker will send all the information to the attacker. Data can be sent to the attacker’s e-mail, can be uploaded to the attacker’s FTP server or can be submitted to the attacker’s website. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Win32:Banker may be downloaded by a user or can be received via email, but usually it is downloaded by other Trojan-Downloaders. When Win32:Banker is launched, it may copy itself to various folders such as %WINDOWS% or %SYSTEM%. Many variants set themselves to run each time Windows starts by creating the corresponding registry entries. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Most known variants target the users of Brazilian banks. These variants may be distributed in executables with names containing the word "cartao" ("card" in English). &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; If a user’s computer is infected with Win32:Banker, it is recommended to change the logging details of user’s bank account.&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;a href="http://www.avast.com/eng/win32-banker.html"&gt;Avast&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-6940757501086620896?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/6940757501086620896/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/virus-win32banker-trojan-horse.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/6940757501086620896'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/6940757501086620896'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/virus-win32banker-trojan-horse.html' title='Virus: Win32:Banker [Trojan Horse]'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-4805189480749926003</id><published>2009-04-11T11:28:00.005+08:00</published><updated>2009-04-13T10:11:49.299+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTI VIRUS: Ansav +EA 2.0.26 Beta / 1.9.3</title><content type='html'>&lt;h2 style="text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;This antivirus helps you to identify, thwart and eliminate computer viruses and other malicious software.&lt;/span&gt;&lt;/h2&gt;&lt;center&gt;&lt;a href="http://www.friendster.com/photos/63684525/1/337375165"&gt;&lt;img src="http://photos.friendster.com/photos/52/54/63684525/1_337375165l.jpg" border="0" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;                         &lt;span id="intelliTxt"&gt;             &lt;div class="desch2"&gt;                         &lt;p&gt;Ansav is a free antivirus utility designed to identify, thwart and eliminate computer viruses and other malicious software (malware)&lt;/p&gt;&lt;p&gt;ANSAV, abbreviation from An's AntiVirus, is an application that runs on Windows XP and was made especially to handle various mallware like virus&lt;/p&gt;&lt;p&gt;, Trojan and Spyware.&lt;/p&gt;&lt;/div&gt;&lt;/span&gt;&lt;span id="intelliTxt"&gt;&lt;div class="desch2"&gt;&lt;p&gt;This is not a commercial Antivirus, ANSAV was only designed as portable software and can be undertaken without needing the installation, because ANSA&lt;span&gt;&lt;span id="intelliTxt"&gt;  &lt;/span&gt;&lt;/span&gt;V is not resident and only treats.&lt;br /&gt;&lt;/p&gt;&lt;/div&gt;&lt;/span&gt;&lt;span id="intelliTxt"&gt;&lt;div class="desch2"&gt;&lt;p&gt;At this time ANSAV could have detected various newest local virus (Indonesia Viruses) and several foreign viruses that often circulated in Indonesia, but ANSAV cannot be relied on as personal Antivirus because there are quite a few viruses that could be detected by other Antivirus softwares and were not detected by ANSAV. This was caused by the limitations of the Antivirus database (the virus definition signature)&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;span id="intelliTxt"&gt;&lt;span&gt;&lt;span id="intelliTxt"&gt; &lt;h2 style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wMVRF_LnaR0/SeAQXyriUvI/AAAAAAAAABg/9_FwXKZJ1Zc/s1600-h/Windows-Portable-Applications-Ansav_3.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 148px;" src="http://4.bp.blogspot.com/_wMVRF_LnaR0/SeAQXyriUvI/AAAAAAAAABg/9_FwXKZJ1Zc/s200/Windows-Portable-Applications-Ansav_3.png" alt="" id="BLOGGER_PHOTO_ID_5323272760479339250" border="0" /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;/span&gt;&lt;span id="intelliTxt"&gt;&lt;/span&gt;&lt;span id="intelliTxt"&gt;&lt;div class="desch2"&gt;&lt;p&gt;ANSAV was developed for Indonesian purpose (local support only) although it can detect several foreign viruses, therefore your role is to always send the sample of the newest virus that still could not be detected by ANSAV, so that ANSAV would become your main weapon to eradicate the virus, especially the local virus.&lt;/p&gt;&lt;/div&gt;&lt;/span&gt;&lt;span id="intelliTxt"&gt;&lt;/span&gt;&lt;span id="intelliTxt"&gt;&lt;div class="desch2"&gt;&lt;p&gt;Ansav contains the definitions of more than 776 viruses.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.ansav.com/"&gt;Ansav AntiVirus&lt;/a&gt;&lt;/p&gt;&lt;script type="text/javascript"&gt;&lt;!--&lt;br /&gt;google_ad_client = "pub-5072170890756919";&lt;br /&gt;/* 468x60, created 4/12/09 */&lt;br /&gt;google_ad_slot = "7351753112";&lt;br /&gt;google_ad_width = 468;&lt;br /&gt;google_ad_height = 60;&lt;br /&gt;//--&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript"&lt;br /&gt;src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;&lt;br /&gt;&lt;/script&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-4805189480749926003?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/4805189480749926003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/this-antivirus-helps-you-to-identify.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4805189480749926003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4805189480749926003'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/this-antivirus-helps-you-to-identify.html' title='FREE ANTI VIRUS: Ansav +EA 2.0.26 Beta / 1.9.3'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wMVRF_LnaR0/SeAQXyriUvI/AAAAAAAAABg/9_FwXKZJ1Zc/s72-c/Windows-Portable-Applications-Ansav_3.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-7391170216259718272</id><published>2009-04-11T11:00:00.003+08:00</published><updated>2009-04-11T11:08:46.329+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTI VIRUS: a-squared Free 4.0</title><content type='html'>Freeware! This free version is the little brother of a-squared Anti-Malware and contains only the scanner to clean infected computers. But it does not come with a background guard, Auto-Update, scheduled scans and HiJackFree.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wMVRF_LnaR0/SeAJXikbKqI/AAAAAAAAABY/aiE02TKTGis/s1600-h/securitystatus_220.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 220px; height: 158px;" src="http://4.bp.blogspot.com/_wMVRF_LnaR0/SeAJXikbKqI/AAAAAAAAABY/aiE02TKTGis/s320/securitystatus_220.png" alt="" id="BLOGGER_PHOTO_ID_5323265059573148322" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Scan your PC for infections of Trojans, Viruses, Spyware, Adware, Worms, Bots, Keyloggers and Dialers.&lt;/li&gt;&lt;li&gt;2 Cleaning Scanners in 1: Anti-Virus + Anti-Spyware&lt;/li&gt;&lt;li&gt;4 million users world wide rely on a-squared to clean their PC from Malware.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;center&gt;&lt;a href="http://www.emsisoft.com/"&gt;&lt;img src="http://www.emsisoft.com/images/logos/a-squared_icon_60x60.jpg" alt="a-squared Anti-Malware - Effective Malware Protection" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-7391170216259718272?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/7391170216259718272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-anti-virus-squared-free-40.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/7391170216259718272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/7391170216259718272'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-anti-virus-squared-free-40.html' title='FREE ANTI VIRUS: a-squared Free 4.0'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wMVRF_LnaR0/SeAJXikbKqI/AAAAAAAAABY/aiE02TKTGis/s72-c/securitystatus_220.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-4416228146725340647</id><published>2009-04-11T09:08:00.004+08:00</published><updated>2009-04-17T21:38:03.408+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>COMPUTER VIRUS</title><content type='html'>&lt;p style="text-align: justify;"&gt;A &lt;b&gt;computer virus&lt;/b&gt; is a &lt;a href="http://en.wikipedia.org/wiki/Computer_program" title="Computer program"&gt;computer program&lt;/a&gt; that can copy itself and infect a computer without the permission or knowledge of the owner. The term "virus" is also commonly but erroneously used to refer to other types of &lt;a href="http://en.wikipedia.org/wiki/Malware" title="Malware"&gt;malware&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Adware" title="Adware"&gt;adware&lt;/a&gt;, and &lt;a href="http://en.wikipedia.org/wiki/Spyware" title="Spyware"&gt;spyware&lt;/a&gt; programs that do not have the reproductive ability. A true virus can only spread from one computer to another (in some form of executable &lt;a href="http://en.wikipedia.org/wiki/Code" title="Code"&gt;code&lt;/a&gt;) when its host is taken to the target computer; for instance because a user sent it over a network or the Internet, or carried it on a removable medium such as a &lt;a href="http://en.wikipedia.org/wiki/Floppy_disk" title="Floppy disk"&gt;floppy disk&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Compact_Disc" title="Compact Disc"&gt;CD&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/DVD" title="DVD"&gt;DVD&lt;/a&gt;, or &lt;a href="http://en.wikipedia.org/wiki/USB_flash_drive" title="USB flash drive"&gt;USB drive&lt;/a&gt;. Viruses can increase their chances of spreading to other computers by infecting files on a &lt;a href="http://en.wikipedia.org/wiki/Network_file_system" title="Network file system"&gt;network file system&lt;/a&gt; or a file system that is accessed by another computer.&lt;sup id="cite_ref-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus#cite_note-0" title=""&gt;&lt;span&gt;[&lt;/span&gt;1&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;sup id="cite_ref-1" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus#cite_note-1" title=""&gt;&lt;span&gt;[&lt;/span&gt;2&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;The term "computer virus" is sometimes used as a catch-all phrase to include all types of &lt;a href="http://en.wikipedia.org/wiki/Malware" title="Malware"&gt;malware&lt;/a&gt;. Malware includes computer viruses, worms, trojan horses, most rootkits, spyware, dishonest adware, crimeware, and other malicious and unwanted software), including true viruses. Viruses are sometimes confused with &lt;a href="http://en.wikipedia.org/wiki/Computer_worm" title="Computer worm"&gt;computer worms&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Trojan_Horse_%28Computing%29" title="Trojan Horse (Computing)" class="mw-redirect"&gt;Trojan horses&lt;/a&gt;, which are technically different. A worm can exploit security vulnerabilities to spread itself to other computers without needing to be transferred as part of a host, and a Trojan horse is a program that appears harmless but has a hidden agenda. Worms and Trojans, like viruses, may cause harm to either a computer system's hosted data, functional performance, or networking throughput, when they are executed. Some viruses and other malware have symptoms noticeable to the computer user, but many are surreptitious.&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;Most personal computers are now connected to the Internet and to &lt;a href="http://en.wikipedia.org/wiki/Local_area_network" title="Local area network"&gt;local area networks&lt;/a&gt;, facilitating the spread of malicious code. Today's viruses may also take advantage of network services such as the &lt;a href="http://en.wikipedia.org/wiki/World_Wide_Web" title="World Wide Web"&gt;World Wide Web&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/E-mail" title="E-mail"&gt;e-mail&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Instant_Messaging" title="Instant Messaging" class="mw-redirect"&gt;Instant Messaging&lt;/a&gt;, and &lt;a href="http://en.wikipedia.org/wiki/File_sharing" title="File sharing"&gt;file sharing&lt;/a&gt; systems to spread.&lt;/p&gt;&lt;h3 style="color: rgb(192, 192, 192);" id="siteSub"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus"&gt;&lt;span style="font-size:78%;"&gt;From Wikipedia&lt;/span&gt;&lt;/a&gt;&lt;/h3&gt;&lt;code&gt;&lt;/code&gt;&lt;center&gt;&lt;a href="https://secure.element5.com/esales/checkout.html?PRODUCT%5B187060%5D=1&amp;amp;COUPON1=EMS219&amp;amp;affiliateid=200091800"&gt;&lt;img src="http://www.emsisoft.com/images/logos/a-squared_anti-malware_468x60.jpg" alt="a-squared Anti-Malware - Effective Malware Protection" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-4416228146725340647?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/4416228146725340647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/computer-virus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4416228146725340647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/4416228146725340647'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/computer-virus.html' title='COMPUTER VIRUS'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-3551610660517354186</id><published>2009-04-08T18:17:00.005+08:00</published><updated>2009-04-10T13:30:05.666+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTIVIRUS: C.O.M.O.D.O</title><content type='html'>&lt;h3 style="color: red;"&gt;FREE ANTIVIRUS SOFTWARE - NO LICENSE FEES EVER&lt;/h3&gt;&lt;h3 style="color: red;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://personalfirewall.comodo.com/style/images/cis_comodo_logo.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 174px; height: 88px;" src="http://personalfirewall.comodo.com/style/images/cis_comodo_logo.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;/h3&gt; &lt;p&gt;Comodo Internet Security is the all-in-one security software that keeps your computer completely safe from viruses and internet threats. The software is free for life and incorporates Comodo Firewall and Comodo Antivirus. If required, either product can be installed individually during setup.&lt;/p&gt;&lt;p&gt;&lt;a href="http://ahotolus.blogspot.com/2009/04/free-antivirus-comodo.html"&gt;Comodo Antivirus&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-3551610660517354186?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/3551610660517354186/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-antivirus-comodo.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/3551610660517354186'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/3551610660517354186'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-antivirus-comodo.html' title='FREE ANTIVIRUS: C.O.M.O.D.O'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-6148732284780150726</id><published>2009-04-08T09:14:00.006+08:00</published><updated>2009-04-17T23:26:47.179+08:00</updated><title type='text'>Conficker worm might originate in China</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_wMVRF_LnaR0/Sd7b6KoT9YI/AAAAAAAAABQ/Nrlhx8nrppI/s1600-h/800px-Conficker.svg_610x431.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 226px;" src="http://4.bp.blogspot.com/_wMVRF_LnaR0/Sd7b6KoT9YI/AAAAAAAAABQ/Nrlhx8nrppI/s320/800px-Conficker.svg_610x431.jpg" alt="" id="BLOGGER_PHOTO_ID_5322933601930835330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Updated at 9:13 p.m. PDT with information provided by BKIS stating that its free version of BKAV antivirus software can remove the worm from any infected computer.&lt;br /&gt;&lt;br /&gt;There's been a lot of fuss about the Conficker worm. And here's the a $250,000 question: what is the origin of the virus?&lt;br /&gt;&lt;br /&gt;$250,000 is the amount of money Microsoft is putting up as a reward for any information leading to an arrest related to the case. Folks at BKIS, a Vietnamese security firm that makes the BKAV antivirus software, announced Monday that they found clues that the virus may have originated in China. Previously, there were rumors that it might have been from Russia or Europe.&lt;br /&gt;&lt;br /&gt;The firm's conclusion is based on its analysis of the virus' coding. It found that Conficker's code is closely related to that of the notorious Nimda, a virus that wreaked havoc on the Net and e-mail in 2001. At that time, BKIS determined that Nimda was made in China, based on the firm's own data.&lt;br /&gt;&lt;br /&gt;It's important to note that the origin of Nimda was never verified. Though Nimda contained text indicating that it may have originated from China, that is in no way hard evidence.&lt;br /&gt;&lt;br /&gt;Even if this finding by BKIS is credible, it's hardly good news, as it does little to help the authorities lay their hands on whomever is responsible for creating the virus. What it does is narrow in on where to block the return of the virus.&lt;br /&gt;&lt;a href="http://news.cnet.com/8301-1009_3-10206754-83.html?tag=mncol;txt"&gt;Read more&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a href="https://secure.element5.com/esales/checkout.html?PRODUCT%5B187060%5D=1&amp;amp;COUPON1=EMS219&amp;amp;affiliateid=200091800"&gt;&lt;/a&gt;&lt;a href="https://secure.element5.com/esales/checkout.html?PRODUCT%5B187060%5D=1&amp;amp;COUPON1=EMS219&amp;amp;affiliateid=200091800"&gt;&lt;img src="http://www.mamutu.com/images/logos/mamutu/mamutu_468x60.gif" alt="Mamutu - Behavior Based Malware Blocking" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-6148732284780150726?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/6148732284780150726/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/conficker-worm-might-originate-in-china.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/6148732284780150726'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/6148732284780150726'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/conficker-worm-might-originate-in-china.html' title='Conficker worm might originate in China'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wMVRF_LnaR0/Sd7b6KoT9YI/AAAAAAAAABQ/Nrlhx8nrppI/s72-c/800px-Conficker.svg_610x431.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-6581319132643878891</id><published>2009-04-05T17:08:00.007+08:00</published><updated>2009-05-01T21:45:52.949+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>VIRUS: Win32:Confi (Confiker, Downup, Downadup and Kido)</title><content type='html'>&lt;h1 style="color: rgb(51, 51, 255);"&gt;&lt;span style="font-size:100%;"&gt;Win32:Confi is a mass spreading worm&lt;/span&gt;&lt;/h1&gt;&lt;span style="font-weight: bold;"&gt;Summary&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Type                    : Worm&lt;br /&gt;Aliases                 : W32/Downadup, Net-Worm, Win32.Kodo, W32/Confoker&lt;br /&gt;Platform              : Windows&lt;br /&gt;Known locations : %WINDIR%\system32, recycle bin&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size:100%;"&gt;Description&lt;/span&gt;&lt;/h2&gt; &lt;p&gt; Win32:Confi exploits a security hole in Windows (&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx" target="_blank" title="security hole in Windows"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx&lt;/a&gt; ) to propagate itself over networks. After infecting a machine, Confi creates a service with a randomly generated name and tries to infect other computers in the same subnet. It also drops itself into any removable media (USB sticks) plugged into the infected machine. When the attempt to exploit neighbouring computers fails, the worm runs a brute-force attack against weak passwords. Filesystem operations above the Win32:Confi files are not accessible for common users (not even for administrators), because the worm removes the rights and ownership from its files. &lt;/p&gt; &lt;h2&gt;&lt;span style="font-size:100%;"&gt;Detection/Removal&lt;/span&gt;&lt;/h2&gt;  Manually download the corresponding patch from MS (Confi blocks access to some anti-malware sites). &lt;a href="http://www.avast.com/eng/updates.html"&gt;Update avast! VPS to the latest version&lt;/a&gt;. Unplug the LAN cable. Schedule the boot time scan and move all Win32:Confi files to the virus chest. After rebooting, install the MS patch. Reconnect the LAN cable and everything should be fine.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.avast.com/"&gt;Avast Home Edition&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a href="http://www.emsisoft.com/"&gt;&lt;img src="http://www.emsisoft.com/images/logos/a-squared_anti-malware_230x60.jpg" alt="a-squared Anti-Malware - Effective Malware Protection" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-6581319132643878891?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/6581319132643878891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/virus-win32confi-confiker-downup.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/6581319132643878891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/6581319132643878891'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/virus-win32confi-confiker-downup.html' title='VIRUS: Win32:Confi (Confiker, Downup, Downadup and Kido)'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-5727787640065723185</id><published>2009-04-04T12:56:00.008+08:00</published><updated>2009-04-10T13:44:21.832+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTI VIRUS: BitDefender Free</title><content type='html'>Yooo...another FREE ANTI VIRUS :&lt;span style="color: rgb(204, 0, 0);"&gt; &lt;/span&gt;&lt;span style="color: rgb(153, 0, 0); font-weight: bold;"&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;Bit&lt;/span&gt;&lt;span style="color: rgb(204, 204, 204);"&gt;Defender&lt;/span&gt; Free Edition.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;It is FREE Antivirus for All &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 0, 0); font-weight: bold;"&gt;Bit&lt;span style="color: rgb(204, 204, 204);"&gt;Defender&lt;/span&gt; Free Edition&lt;/span&gt; is your chance to use one of the world's most effective antivirus engines for free!&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 0, 0);"&gt;Bit&lt;span style="color: rgb(204, 204, 204);"&gt;Defender&lt;/span&gt; Free Edition&lt;/span&gt; uses the same ICSA Labs certified scanning engines found in other BitDefender products, allowing you to enjoy basic virus protection for no cost at all.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 0, 0);"&gt;Bit&lt;span style="color: rgb(204, 204, 204);"&gt;Defender&lt;/span&gt; Free Edition&lt;/span&gt; is your chance to use one of the world's most effective antivirus engines for free!&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 193px; height: 35px;" src="http://3.bp.blogspot.com/_wMVRF_LnaR0/Sdbp4Gt2cmI/AAAAAAAAABI/kKteQsM-IUg/s320/bitdefenderlogo.png" alt="" id="BLOGGER_PHOTO_ID_5320697159869690466" border="0" /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 0, 0);"&gt;Bit&lt;span style="color: rgb(204, 204, 204);"&gt;Defender&lt;/span&gt; Free Edition&lt;/span&gt; is an on-demand virus scanner, which is best used in a system recovery or forensics role. If you are on an "always-on" Internet connection, we strongly advise you to consider using &lt;a href="http://www.bitdefender.com/site/view/comp.html?itxt_link=complexprod" style="font-weight: bold; font-size: 12px;" class="link1"&gt;a more complex antivirus solution.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://ahotolus.blogspot.com/2009/04/free-anti-virus-bitdefender-free.html"&gt;&lt;span style="font-weight: bold; color: rgb(153, 0, 0);"&gt;Bit&lt;/span&gt;&lt;/a&gt;&lt;a href="http://ahotolus.blogspot.com/2009/04/free-anti-virus-bitdefender-free.html"&gt;Defender AntiVirus&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-5727787640065723185?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/5727787640065723185/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-anti-virus-bitdefender-free.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/5727787640065723185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/5727787640065723185'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-anti-virus-bitdefender-free.html' title='FREE ANTI VIRUS: BitDefender Free'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wMVRF_LnaR0/Sdbp4Gt2cmI/AAAAAAAAABI/kKteQsM-IUg/s72-c/bitdefenderlogo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-5460828917828955897</id><published>2009-04-04T12:22:00.007+08:00</published><updated>2009-04-10T14:18:44.248+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTI VIRUS : ClamWin Antivirus</title><content type='html'>This is another &lt;span style="font-weight: bold;"&gt;Free AntiVirus&lt;/span&gt;, really truly free. ClamWin is a Free Antivirus program for &lt;span style="color: rgb(51, 51, 255);"&gt;Microsoft Windows 98/Me/2000/XP/2003 and Vista.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ClamWin Free Antivirus&lt;/span&gt; comes with an easy installer and open source code. You may download and use it absolutely free of charge. It features:&lt;br /&gt;&lt;br /&gt;* High detection rates for viruses and spyware;&lt;br /&gt;* Scanning Scheduler;&lt;br /&gt;* Automatic downloads of regularly updated Virus Database.&lt;br /&gt;* Standalone virus scanner and right-click menu integration to Microsoft Windows Explorer;&lt;br /&gt;* Addin to Microsoft Outlook to remove virus-infected attachments automatically.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://downloads.sourceforge.net/clamwin/clamwin-0.94.1-setup.exe"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 98px;" src="http://2.bp.blogspot.com/_a8TDdqP3llE/Sdbiwha770I/AAAAAAAAAks/PXRQ15-4MQs/s200/clamwin_logo.png" alt="" id="BLOGGER_PHOTO_ID_5320689333017767746" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;The latest version of Clamwin Free Antivirus is 0.94.1&lt;/span&gt;&lt;br /&gt;Please note that ClamWin Free Antivirus does not include an on-access real-time scanner. You need to manually scan a file in order to detect a virus or spyware.&lt;br /&gt;&lt;br /&gt;ClamWin Free Antivirus is based on ClamAV engine and uses GNU General Public License by the Free Software Foundation, and is free (as in freedom) software. To find out more about GNU GPL, please visit the following link: Philosophy of the GNU Project - Free Software Foundation.&lt;br /&gt;ClamWin Free Antivirus uses ClamAV Scanning Engine.&lt;br /&gt;&lt;a style="font-weight: bold; color: rgb(0, 0, 153);" href="http://sourceforge.net/projects/clamwin/"&gt;Donwload ClamWin Free Antivirus&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-5460828917828955897?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/5460828917828955897/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-anti-virus-clamwin-antivirus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/5460828917828955897'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/5460828917828955897'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/free-anti-virus-clamwin-antivirus.html' title='FREE ANTI VIRUS : ClamWin Antivirus'/><author><name>C Sulo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_a8TDdqP3llE/SQeXlDPlRrI/AAAAAAAAATk/LMLqsnEAMnk/S220/photoku.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_a8TDdqP3llE/Sdbiwha770I/AAAAAAAAAks/PXRQ15-4MQs/s72-c/clamwin_logo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-3417457436498089680</id><published>2009-04-02T10:42:00.003+08:00</published><updated>2009-04-04T14:37:05.072+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTI VIRUS: RISING Free Edition Antivirus</title><content type='html'>&lt;div style="text-align: left;"&gt;This is one of my favorites free anti virus.&lt;br /&gt;&lt;/div&gt;Rising Antivirus Free Edition 2009 protects your computers against              all types of viruses, Trojans, worms, rootkits and other malicious              programs. Ease of use and Smartupdate technology make it an "install              and forget" product and entitles you to focus on your own jobs              with your computer. RISING Antivirus powerful engine has been certified              by Virus Bulletin,Checkmark, TUV.              &lt;p style="text-align: justify;"&gt;Rising Antivirus Free Edition 2009 is a solution with &lt;span style="color: rgb(255, 102, 0);"&gt;no cost to                personal users.&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 182px; height: 60px;" src="http://2.bp.blogspot.com/_wMVRF_LnaR0/SdQmY7m41QI/AAAAAAAAAA8/fwc0CDbMZnk/s320/rising+logo.gif" alt="" id="BLOGGER_PHOTO_ID_5319919269590914306" border="0" /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;RISING Free Anti Virus was upgrade now. &lt;/p&gt;&lt;p style="text-align: justify;"&gt;The latest Rising Antivirus Free Edition has the same                              service and function as &lt;a href="http://www.rising-global.com/products/Rising-Antivirus-2009.html"&gt;Rising                              Antivirus 2009&lt;/a&gt; paid version, but there are some                              differences which need users to know:&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;                        &lt;span style="font-weight: bold;"&gt;1. Information centre service:&lt;/span&gt;&lt;br /&gt;                        Rising Antivirus Free Edition has Information centre                              window in its main interface, and this window drive                              users get latest news of RISING. But Rising Antivirus                              2009 paid version not;&lt;br /&gt;                        &lt;span style="font-weight: bold;"&gt;2. Update Service:&lt;/span&gt;&lt;br /&gt;                        RISING paid version product gets update through high                              speed update server each day, but Rising Antivirus                              Free Edition product does not;&lt;br /&gt;                        &lt;span style="font-weight: bold;"&gt;3. Technical support:&lt;/span&gt;&lt;br /&gt;                        RISING provides fast response technical support to                              each paid version product user; but the support to                              RISING free version product user may be limited;&lt;br /&gt;                        4. Users buy Rising Antivirus paid version can get                              a &lt;span style="font-weight: bold;"&gt;Rising Firewall &lt;/span&gt;with same service life in FREE;                              but Rising Antivirus Free version users could not.&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;a href="http://www.freerav.com/"&gt;RISING Antivirus Free Edition&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-3417457436498089680?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/3417457436498089680/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/rising-free-edition-antivirus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/3417457436498089680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/3417457436498089680'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/rising-free-edition-antivirus.html' title='FREE ANTI VIRUS: RISING Free Edition Antivirus'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_wMVRF_LnaR0/SdQmY7m41QI/AAAAAAAAAA8/fwc0CDbMZnk/s72-c/rising+logo.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-6572909421949681647</id><published>2009-04-02T09:55:00.003+08:00</published><updated>2009-04-04T14:39:07.855+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTI VIRUS: AVG Anti Virus Free Edition</title><content type='html'>&lt;p&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 151px; height: 50px;" src="http://2.bp.blogspot.com/_wMVRF_LnaR0/SdQg9UpilQI/AAAAAAAAAA0/oaRxbEeMh18/s400/avg+logo+brand.gif" alt="" id="BLOGGER_PHOTO_ID_5319913297718449410" border="0" /&gt;&lt;/p&gt; AVG Anti-Virus Free Edition - trusted by 80 million users&lt;span style="font-weight: bold;"&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Antivirus and antispyware protection for Windows available to download for free.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;img src="http://free.avg.com/stc/img/box_afe_mr_l.jpg" alt="AVG Anti-Virus Free Edition" class="mleft mright" /&gt;&lt;/div&gt;&lt;ul class="check"&gt;&lt;li&gt;Award-winning antivirus and antispyware&lt;/li&gt;&lt;li&gt;Real-time safe internet surfing and searching&lt;/li&gt;&lt;li&gt;Quality proven by 80 million of users&lt;/li&gt;&lt;li&gt;Easy to download, install and use&lt;/li&gt;&lt;li&gt;Protection against viruses and spyware&lt;/li&gt;&lt;li&gt;Compatible with Windows 7, &lt;b&gt;Windows Vista&lt;/b&gt; and Windows XP&lt;/li&gt;&lt;/ul&gt;Note : &lt;i&gt;AVG Anti-Virus Free Edition is only &lt;span style="color: rgb(204, 0, 0);"&gt;available for single computer use for home and non commercial use.&lt;span style="color: rgb(0, 0, 0);"&gt; &lt;span style="color: rgb(255, 255, 255);"&gt;It is a basic protection against viruses and spyware&lt;/span&gt;. &lt;a href="http://free.avg.com/"&gt;AVG Free Edition&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-6572909421949681647?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/6572909421949681647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/avg-anti-virus-free-edition.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/6572909421949681647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/6572909421949681647'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/avg-anti-virus-free-edition.html' title='FREE ANTI VIRUS: AVG Anti Virus Free Edition'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_wMVRF_LnaR0/SdQg9UpilQI/AAAAAAAAAA0/oaRxbEeMh18/s72-c/avg+logo+brand.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-8551873809315678931</id><published>2009-04-01T22:03:00.003+08:00</published><updated>2009-04-04T14:42:15.629+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTI VIRUS: Avira AntiVir Personal</title><content type='html'>&lt;strong&gt;Avira AntiVir Personal is a free antivirus (Basic protection&lt;/strong&gt;).&lt;br /&gt;Protects your computer against dangerous viruses, worms, Trojans and costly dialers. New: Basic Anti-Spyware. &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.free-av.com/en//1/avira_antivir_personal__free_antivirus.html"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 175px; height: 152px;" src="http://2.bp.blogspot.com/_wMVRF_LnaR0/SdN1NZk31gI/AAAAAAAAAAk/1Ri69kLfMEU/s400/free_AV9_EN.gif" alt="" id="BLOGGER_PHOTO_ID_5319724457918977538" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;em&gt;Note: Avira AntiVir Personal - FREE Antivirus is only &lt;span style="color: rgb(204, 0, 0);"&gt;available for single computer&lt;/span&gt; use for home and non commercial use.&lt;/em&gt;&lt;br /&gt;&lt;a href="http://www.free-av.com"&gt;Avira AntiVir Personal&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-8551873809315678931?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/8551873809315678931/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/avira-antivir-personal.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/8551873809315678931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/8551873809315678931'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/avira-antivir-personal.html' title='FREE ANTI VIRUS: Avira AntiVir Personal'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_wMVRF_LnaR0/SdN1NZk31gI/AAAAAAAAAAk/1Ri69kLfMEU/s72-c/free_AV9_EN.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-7189169264157372510</id><published>2009-04-01T21:40:00.001+08:00</published><updated>2009-04-04T12:42:36.630+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Antivirus'/><title type='text'>FREE ANTI VIRUS: Avast! Home Edition Antivirus.</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;  Avast Home Edition is one of the FREE anti virus. This edition is truly free of charge antivirus with spyware protection for non-commercial use.  Try and look if you like it.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.avast.com/eng/download-avast-home.html"&gt;&lt;img style="cursor: pointer; width: 133px; height: 126px;" src="http://3.bp.blogspot.com/_wMVRF_LnaR0/SdNxhhX7hOI/AAAAAAAAAAc/4wK-uv3zQZs/s400/resident.gif" alt="" id="BLOGGER_PHOTO_ID_5319720405563049186" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.avast.com/eng/avast_4_home.html"&gt;&lt;span style="display: block;" id="formatbar_Buttons"&gt;&lt;span class="" style="display: block;" id="formatbar_Add_Image" title="-" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="addImage();" onmousedown="CheckFormatting(event);;ButtonMouseDown(this);"&gt;&lt;img src="http://www.blogger.com/img/blank.gif" alt="Add Image" class="gl_photo" border="0" /&gt;&lt;/span&gt;&lt;/span&gt;Avast Home Edition&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Following version 4.8 of avast!&lt;a href="http://www.avast.com/eng/avast_4_home.html"&gt; Home Edition &lt;/a&gt;and&lt;a href="http://www.avast.com/eng/avast_4_professional.html"&gt; Professional Edition&lt;/a&gt; earlier this year, ALWIL Software has now released version 4.8 of avast! &lt;a href="http://www.avast.com/eng/avast_4_server.html"&gt; Server Edition&lt;/a&gt; and &lt;a href="http://www.avast.com/eng/avast_4_small_business.html"&gt;Small Business Server Edition&lt;/a&gt;. &lt;/div&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-7189169264157372510?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/7189169264157372510/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/04/avast-home-edition-antivirus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/7189169264157372510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/7189169264157372510'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/04/avast-home-edition-antivirus.html' title='FREE ANTI VIRUS: Avast! Home Edition Antivirus.'/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wMVRF_LnaR0/SdNxhhX7hOI/AAAAAAAAAAc/4wK-uv3zQZs/s72-c/resident.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6331323378504528188.post-6389960603800277173</id><published>2009-03-31T22:54:00.000+08:00</published><updated>2009-03-31T22:57:38.212+08:00</updated><title type='text'></title><content type='html'>Welcome to the collection of Free Antivirus. I'll try to introduce about all of Free Antivirus in the world. Hope you enjoy this.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6331323378504528188-6389960603800277173?l=ahotolus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ahotolus.blogspot.com/feeds/6389960603800277173/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ahotolus.blogspot.com/2009/03/welcome-to-collection-of-free-antivirus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/6389960603800277173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6331323378504528188/posts/default/6389960603800277173'/><link rel='alternate' type='text/html' href='http://ahotolus.blogspot.com/2009/03/welcome-to-collection-of-free-antivirus.html' title=''/><author><name>nurnurnur</name><uri>http://www.blogger.com/profile/07504207852615445523</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
