<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>im-infected.com</title>
	<atom:link href="http://www.im-infected.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.im-infected.com</link>
	<description></description>
	<lastBuildDate>Tue, 09 Feb 2010 01:54:46 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Trojan-BNK.Win32.Keylogger.gen</title>
		<link>http://www.im-infected.com/popups/trojan-bnk-win32-keylogger-gen.html</link>
		<comments>http://www.im-infected.com/popups/trojan-bnk-win32-keylogger-gen.html#comments</comments>
		<pubDate>Tue, 09 Feb 2010 01:54:46 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Popups]]></category>
		<category><![CDATA[How to remove Trojan-BNK.Win32.Keylogger.gen]]></category>
		<category><![CDATA[Trojan-BNK.Win32.Keylogger.gen Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2346</guid>
		<description><![CDATA[Trojan-BNK.Win32.Keylogger.gen is a threat that comes from a rogue security programs XP Antispyware 2010 and Vista Antispyware 2010. The alert will display:
Xp Antispyware 2010 Firewall Alert
Xp Antispyware 2010 has blocked a program from accessing the Internet.
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
Private data can be stolen by third parties, including credit card details and passwords.
Name: Microsoft [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/popups/trojan-bnk-win32-keylogger-gen.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus.Boot-DOS.V.1526</title>
		<link>http://www.im-infected.com/popups/virus-boot-dos-v-1526.html</link>
		<comments>http://www.im-infected.com/popups/virus-boot-dos-v-1526.html#comments</comments>
		<pubDate>Tue, 09 Feb 2010 01:42:01 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Popups]]></category>
		<category><![CDATA[How to remove Virus.Boot-DOS.V.1526]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2343</guid>
		<description><![CDATA[Virus.Boot-DOS.V.1526 is a threat exhibited by a rogue program XP Antispyware 2010 and Vista Antispyware 2010 to trick computer users. Virus.Boot-DOS.V.1526 detection is untrusted if displayed in the following message:
XP Antispyware 2010 ALERT
System hacked!
Unknown program is scanning your system registry right now! Identity theft detected!
Details
Attack from:  9.37.247.159 port: 9536
Attacked port: 9536
Threat: Virus.Boot-DOS.V.1526



Type
Popup


Sub-Type
FakeAV


Aliases
 


OS Affected
Windows


Detected By
MalwareBytes



What are [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/popups/virus-boot-dos-v-1526.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Paladin Antivirus</title>
		<link>http://www.im-infected.com/rogue/paladin-antivirus.html</link>
		<comments>http://www.im-infected.com/rogue/paladin-antivirus.html#comments</comments>
		<pubDate>Tue, 09 Feb 2010 01:32:25 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Rogue]]></category>
		<category><![CDATA[How to remove Paladin Antivirus]]></category>
		<category><![CDATA[Paladin Antivirus Malware]]></category>
		<category><![CDATA[Paladin Antivirus Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2340</guid>
		<description><![CDATA[Paladin Antivirus is a counterfeit security program that is a successor to Malware Defense. The family where Paladin Antivirus came from was created to generate revenue for its developers that continues to scam computer users by useless program pretending to be an antivirus application. Primary means to spread this malware is via Internet, where a [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/rogue/paladin-antivirus.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GuardWWW</title>
		<link>http://www.im-infected.com/rogue/guardwww.html</link>
		<comments>http://www.im-infected.com/rogue/guardwww.html#comments</comments>
		<pubDate>Sun, 07 Feb 2010 03:35:59 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Rogue]]></category>
		<category><![CDATA[GuardWWW Malware]]></category>
		<category><![CDATA[GuardWWW Virus]]></category>
		<category><![CDATA[How to remove GuardWWW]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2336</guid>
		<description><![CDATA[GuardWWW is another fake anti-malware program that was developed by the same persons who spread enormous security applications. GuardWWW will utilize the Internet by pretending to be an online virus scanner that scans visitors computer. It will generate fake results and advise to download unregistered version of GuardWWW and install it on the computer. Once [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/rogue/guardwww.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SafePcAv</title>
		<link>http://www.im-infected.com/rogue/safepcav.html</link>
		<comments>http://www.im-infected.com/rogue/safepcav.html#comments</comments>
		<pubDate>Sun, 07 Feb 2010 03:25:58 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Rogue]]></category>
		<category><![CDATA[How to remove SafePcAv]]></category>
		<category><![CDATA[SafePcAv Malware]]></category>
		<category><![CDATA[SafePcAv Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2333</guid>
		<description><![CDATA[SafePcAv is another scam antivirus program designed to steal money from its innocent victim using deceiving tactics on the security of the computer. SafePcAv is unsafe and should be removed from computer immediately. Once inside the system, SafePcAv attempts to connect to a remote computer to download additional malware that will enhance its presence on [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/rogue/safepcav.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cutwail.gen.o</title>
		<link>http://www.im-infected.com/trojan/cutwail-gen-o.html</link>
		<comments>http://www.im-infected.com/trojan/cutwail-gen-o.html#comments</comments>
		<pubDate>Thu, 04 Feb 2010 10:25:41 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Remove Cutwail.gen.o]]></category>
		<category><![CDATA[Trojan Cutwail]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2329</guid>
		<description><![CDATA[Cutwail.gen.o is a general detection for a malware that belongs to a family that has the different characteristics depending on the variants. Cutwail.gen.o spreads via IRC, file-sharing networks and spam e-mail messages.



Type
Trojan


Sub-Type
Downloader


Aliases
Backdoor.Win32.HareBot.anq, Mal/Harebot-A
Trojan.Pandex, Trojan:Win32/Malagent


OS Affected
Windows


Detected By
McAfee



What are the Symptoms of Cutwail.gen.o Infection?
It will modify Windows Registry and add the following entries:

HKEY_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Run
imPlayok = &#8220;%System%\imPlayok.exe&#8221;
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
imPlayok = &#8220;%UserProfile%\imPlayok.exe&#8221;

The threat [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/trojan/cutwail-gen-o.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FakeAlert-IS2010.dldr</title>
		<link>http://www.im-infected.com/trojan/fakealert-is2010-dldr.html</link>
		<comments>http://www.im-infected.com/trojan/fakealert-is2010-dldr.html#comments</comments>
		<pubDate>Thu, 04 Feb 2010 10:07:30 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2325</guid>
		<description><![CDATA[FakeAlert-IS2010.dldr is a Trojan that is using  spam e-mail messages, malicious websites and file-sharing networks as its distribution channels to infect a computer. FakeAlert-IS2010.dldr will download a potentially unwanted program on target computer.



Type
Trojan


Sub-Type
Downloader


Aliases
Trojan-Downloader.Win32.FraudLoad.wxvs, W32/Smalltroj.WIRF,
Win32/TrojanDownloader.FakeAlert.AED, Trojan:Win32/Malagent


OS Affected
Windows


Detected By
McAfee



What are the Symptoms of FakeAlert-IS2010.dldr Infection?
It will modify Windows Registry and add the following entries:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-internet-security10.com]
[HKEY_USERS\S-1-(varies)\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-internet-security10.com]
[HKEY_USERS\S-1-(varies)\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\is-soft-download.com]
[HKEY_USERS\S-1-(varies)\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\is-software-download25.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\]
&#8220;NoSetActiveDesktop:&#8221; [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/trojan/fakealert-is2010-dldr.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Your PC Protector</title>
		<link>http://www.im-infected.com/rogue/your-pc-protector.html</link>
		<comments>http://www.im-infected.com/rogue/your-pc-protector.html#comments</comments>
		<pubDate>Wed, 03 Feb 2010 08:56:11 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Rogue]]></category>
		<category><![CDATA[How to remove Your PC Protector]]></category>
		<category><![CDATA[Your PC Protector Malware]]></category>
		<category><![CDATA[Your PC Protector Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2318</guid>
		<description><![CDATA[Your PC Protector is a virus and rogue security program that comes from the family as the harmful Windows Police Pro. Using a Trojan and fake security website, Your PC Protector can easily spread over the Internet by deceiving people when it tries to pretend as a legit anti-virus application. Your PC Protector rogue was also [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/rogue/your-pc-protector.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirus Soft</title>
		<link>http://www.im-infected.com/rogue/antivirus-soft.html</link>
		<comments>http://www.im-infected.com/rogue/antivirus-soft.html#comments</comments>
		<pubDate>Sun, 31 Jan 2010 08:45:36 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Antivirus Soft Malware]]></category>
		<category><![CDATA[How to remove Antivirus Soft]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2308</guid>
		<description><![CDATA[Antivirus Soft is a new bogus computer security tool that can alter system settings and Internet browser configuration such as default home page, proxy and LAN settings configuration. Antivirus Soft causes this changes to make Internet browser redirects to scam security websites and avoid its victims from visiting security related websites. Its presence will also [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/rogue/antivirus-soft.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win 7 Antispyware 2010</title>
		<link>http://www.im-infected.com/rogue/win-7-antispyware-2010.html</link>
		<comments>http://www.im-infected.com/rogue/win-7-antispyware-2010.html#comments</comments>
		<pubDate>Fri, 29 Jan 2010 13:06:26 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Rogue]]></category>
		<category><![CDATA[How to remove Win 7 Antispyware 2010]]></category>
		<category><![CDATA[Win 7 Antispyware 2010 Malware]]></category>
		<category><![CDATA[Win 7 Antispyware 2010 Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2306</guid>
		<description><![CDATA[Win 7 Antispyware 2010 is a deceiving security application that may come uninvited and started to act as a legitimate program scanning the computer. Win 7 Antispyware 2010 scan will produce fabricated results intentionally created to misinform its victims. This preliminary activity was intended to let users download the unregistered copy of Win 7 Antispyware [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/rogue/win-7-antispyware-2010.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
