<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>im-infected.com &#187; Virus</title>
	<atom:link href="http://www.im-infected.com/category/virus/feed" rel="self" type="application/rss+xml" />
	<link>http://www.im-infected.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Sep 2010 09:00:36 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>W32/Pinkslipbot</title>
		<link>http://www.im-infected.com/virus/w32pinkslipbot.html</link>
		<comments>http://www.im-infected.com/virus/w32pinkslipbot.html#comments</comments>
		<pubDate>Fri, 11 Jun 2010 02:39:15 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[Remove W32/Pinkslipbot]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2778</guid>
		<description><![CDATA[W32.Qakbot is a virus that usually propagates through unsecured network shares. W32/Pinkslipbot downloads additional files, steals confidential information, and opens a back door on the affected system. The virus contains rootkit functionality to allow it to hide its presence.



Type
Virus


Sub Type
Malware


Aliases
W32.Qakbot, BKDR_QAKBOT.AF,
Backdoor:Win32/Qakbot.gen!A


OS Affected
Windows


Detected By
McAfee



What are the Symptoms of W32/Pinkslipbot Infection?
It will modify Windows Registry and add the following entries:

HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Windows\CurrentVersion\Run\]
“ctfmon” = &#8220;%Appdata%\microsoft\kxviad\kxviad.exe&#8221;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\]
“[Application Name]” [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/virus/w32pinkslipbot.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/Spybot.worm!dw</title>
		<link>http://www.im-infected.com/virus/w32spybot-wormdw.html</link>
		<comments>http://www.im-infected.com/virus/w32spybot-wormdw.html#comments</comments>
		<pubDate>Tue, 08 Jun 2010 02:19:42 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[W32/Spybot.worm!dw Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2770</guid>
		<description><![CDATA[W32/Spybot.worm!dw is a virus that will inject itself into Winlogon.exe to make itself run each time Windows is started. W32/Spybot.worm!dw also gathers confidential information from an infected computer including user name, passwords and web site visited.



Type
Virus


Sub Type
Malware


Aliases
 


OS Affected
Windows


Detected By
McAfee



]]></description>
		<wfw:commentRss>http://www.im-infected.com/virus/w32spybot-wormdw.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/Expiro.e</title>
		<link>http://www.im-infected.com/virus/w32expiro-e.html</link>
		<comments>http://www.im-infected.com/virus/w32expiro-e.html#comments</comments>
		<pubDate>Tue, 08 Jun 2010 02:13:44 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[W32/Expiro.e Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2766</guid>
		<description><![CDATA[W32/Expiro.e is a file-infector virus that will look for executable files on victims computer. W32/Expiro.e will append all .exe files by attaching its code to the end of the file.



Type
Virus


Sub Type
Win32


Aliases
Virus.Win32.Expiro.r, Virus:Win32/Expiro.N,
Virus.Win32.Expiro


OS Affected
Windows


Detected By
McAfee



]]></description>
		<wfw:commentRss>http://www.im-infected.com/virus/w32expiro-e.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/Sality.gen.e</title>
		<link>http://www.im-infected.com/virus/w32sality-gen-e.html</link>
		<comments>http://www.im-infected.com/virus/w32sality-gen-e.html#comments</comments>
		<pubDate>Fri, 14 May 2010 02:20:30 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[How to remove W32/Sality.gen.e]]></category>
		<category><![CDATA[W32/Sality.gen.e]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2679</guid>
		<description><![CDATA[W32/Sality.gen.e is a generic detection for a parasitic virus that belongs to a W32/Sality family. W32/Sality.gen.e will search local drives, network-shared drives and removable drives for PE executable files for it to infect. It will append the infected file with viral code on the last section of the PE image.



Type
Virus


Sub Type
Win32


Aliases
 


OS Affected
Windows


Detected By
McAfee



]]></description>
		<wfw:commentRss>http://www.im-infected.com/virus/w32sality-gen-e.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/Palevo.gen.a</title>
		<link>http://www.im-infected.com/virus/w32palevo-gen-a.html</link>
		<comments>http://www.im-infected.com/virus/w32palevo-gen-a.html#comments</comments>
		<pubDate>Sun, 28 Mar 2010 03:11:55 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[Palevo.gen.a]]></category>
		<category><![CDATA[W32/Palevo.gen.a]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2540</guid>
		<description><![CDATA[W32/Palevo.gen.a is a worm that will propagate from infected computer to another drive when connected. W32/Palevo.gen.a also steals information such as user name and passwords related to file-sharing networks or P2P programs. A backdoor activity can also performed by W32/Palevo.gen.a that will download and execute more malware on the compromised computer.



Type
Virus


Sub Type
Worm


Aliases
Win32/Peerfrag.GJ, W32.Pilleuz!gen1,
TR/Crypt.XPACK.Gen2


OS Affected
Windows


Detected By
McAfee



What [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/virus/w32palevo-gen-a.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/Rimecud</title>
		<link>http://www.im-infected.com/virus/w32rimecud.html</link>
		<comments>http://www.im-infected.com/virus/w32rimecud.html#comments</comments>
		<pubDate>Sun, 07 Mar 2010 09:16:22 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[How to remove W32/Rimecud]]></category>
		<category><![CDATA[W32/Rimecud Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2460</guid>
		<description><![CDATA[W32/Rimecud is the worm that can propagate via removal USB drives, Yahoo and MSN Messenger, file-sharing network and network shared resources. W32/Rimecud will inject a malicious code on explorer.exe to run itself on the infected computer.



Type
Virus


Sub Type
Win32


Aliases
 


OS Affected
Windows


Detected By
McAfee



What are the Symptoms of W32/Rimecud Infection?
It will modify Windows Registry and add the following entry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current Version\Winlogon\Taskman: &#8220;%RootDir%\RECYLCER\[ID]\sysdate.exe&#8221;

The threat will [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/virus/w32rimecud.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Xpiro.B</title>
		<link>http://www.im-infected.com/virus/w32-xpiro-b.html</link>
		<comments>http://www.im-infected.com/virus/w32-xpiro-b.html#comments</comments>
		<pubDate>Thu, 25 Feb 2010 03:05:41 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[Remove W32.Xpiro.B]]></category>
		<category><![CDATA[W32.Xpiro.B Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2425</guid>
		<description><![CDATA[W32.Xpiro.B is a virus that infects all .exe files on the affected computer. W32.Xpiro.B can monitor Internet connections and gathers sensitive information. It also scans the registry, gathering user names and passwords stored within it.




Type
Virus


Sub Type
PWS


Aliases
 


OS Affected
Windows


Detected By
Symantec



What are the Symptoms of W32.Xpiro.B Infection?
The threat will drop the following malicious files:

%CurrentFolder%\7z.exe

How to Remove W32.Xpiro.B Manually
1. Restart your computer in SafeMode
- After Power-On the [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/virus/w32-xpiro-b.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Gammima.AG!gen1</title>
		<link>http://www.im-infected.com/virus/w32-gammima-aggen1.html</link>
		<comments>http://www.im-infected.com/virus/w32-gammima-aggen1.html#comments</comments>
		<pubDate>Sat, 19 Dec 2009 09:53:08 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2135</guid>
		<description><![CDATA[W32.Gammima.AG!gen1 is a heuristic detection used to identify computer security threats that were related to the W32.Gammima.AG family.



Type
Virus


Sub Type
Malware


Aliases
 


OS Affected
Windows


Detected By
Symantec



]]></description>
		<wfw:commentRss>http://www.im-infected.com/virus/w32-gammima-aggen1.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32/Sdbot.worm!fn</title>
		<link>http://www.im-infected.com/virus/w32sdbot-wormfn.html</link>
		<comments>http://www.im-infected.com/virus/w32sdbot-wormfn.html#comments</comments>
		<pubDate>Tue, 15 Dec 2009 02:04:31 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2119</guid>
		<description><![CDATA[W32/Sdbot.worm!fn is a virus that can provide a remote attacker full access on the victims computer via an IRC (Internet Relay Chat) protocol. W32/Sdbot.worm!fn can spread via spam email messages, network shared drives or downloaded by another threat.



Type
Virus


Sub Type
Worm


Aliases
Worm/SdBot.26112.1, Backdoor.Win32.SdBot.lnk,
Backdoor:Win32/IRCbot, Worm.SdBot.AGYM


OS Affected
Windows


Detected By
McAfee



What are the Symptoms of W32/Sdbot.worm!fn Infection?
It will modify Windows Registry and add the following [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/virus/w32sdbot-wormfn.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32/Cryptor</title>
		<link>http://www.im-infected.com/virus/win32cryptor.html</link>
		<comments>http://www.im-infected.com/virus/win32cryptor.html#comments</comments>
		<pubDate>Sat, 21 Nov 2009 01:26:52 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[Remove Win32.Cryptor]]></category>
		<category><![CDATA[Win32/Cryptor]]></category>
		<category><![CDATA[Win32/Cryptor Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=1957</guid>
		<description><![CDATA[Win32/Cryptor is a detection for a malicious file that was encrypted in to be able to conceal itself from target computer and antivirus programs. Win32/Cryptor will attempt to communicate to a remote server to download additional malware. Blocking Internet access, disabling security programs and modifying registry entries are just some of Win32/Cryptor payload to harm [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/virus/win32cryptor.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
