<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Unix Sysadmin &#187; Virus and Microsoft</title>
	<atom:link href="http://www.sysadmindayph.com/blog/category/virus-and-microsoft/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sysadmindayph.com/blog</link>
	<description>SysAdmin Blog, TechTips and Reviews</description>
	<lastBuildDate>Fri, 27 Jan 2012 04:36:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PWS-Gamania Trojan</title>
		<link>http://www.sysadmindayph.com/blog/pws-gamania-trojan/</link>
		<comments>http://www.sysadmindayph.com/blog/pws-gamania-trojan/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 02:35:53 +0000</pubDate>
		<dc:creator>elizar</dc:creator>
				<category><![CDATA[Virus and Microsoft]]></category>
		<category><![CDATA[pws-gamania]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.sysadmindayph.com/blog/?p=168</guid>
		<description><![CDATA[PWS-Gamania or PWS-Gamania.gen.a is a computer trojan discovered July 22, 2008. PWS-Gamania is a password stealing trojan which attempts to steal user information for certain online games. The characteristics of this password stealer with regards to passwords stolen, sites accessed, files downloaded etc will differ, depending on the way in which the attacker had configured &#8230; <a href="http://www.sysadmindayph.com/blog/pws-gamania-trojan/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><strong>PWS-Gamania or PWS-Gamania.gen.a</strong> is a computer trojan discovered July 22, 2008. PWS-Gamania is a password stealing trojan which attempts to steal user information for certain online games.</p>
<p>The characteristics of this password stealer with regards to passwords stolen, sites accessed, files downloaded etc will differ, depending on the way in which the attacker had configured it. Hence, this is a general description.</p>
<p>PWS-Gamania is also knows as</p>
<ul>
<li>Trj/Lineage.BZE [Panda]</li>
<li>Trojan.Win32.Vaklik.bkh [Kaspersky]</li>
<li>Trojan:Win32/Meredrop [Microsoft]</li>
<li>W32.Gammima.AG [Symantec]</li>
<li>W32/Autorun-CL [Sophos]</li>
</ul>
<p>My Dell D630 laptop is probably infected by this one. Good thing I am no gamer nor is there any important password this trojan can steal.</p>
<p>More information about PWS-Gamania can be found here: http://vil.nai.com/vil/content/v_147533.htm</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sysadmindayph.com/blog/pws-gamania-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>wpv991242765100 &#8211; viruses, spyware, adware, trojans, rootkits, worms?</title>
		<link>http://www.sysadmindayph.com/blog/wpv991242765100-viruses-spyware-adware-trojans-rootkits-worms/</link>
		<comments>http://www.sysadmindayph.com/blog/wpv991242765100-viruses-spyware-adware-trojans-rootkits-worms/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 08:49:09 +0000</pubDate>
		<dc:creator>elizar</dc:creator>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Virus and Microsoft]]></category>
		<category><![CDATA[adware]]></category>
		<category><![CDATA[rootkits]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[worms?]]></category>
		<category><![CDATA[wpv991242765100]]></category>

		<guid isPermaLink="false">http://www.sysadmindayph.com/blog/?p=153</guid>
		<description><![CDATA[wpv991242765100.exe &#8211; What is it? You may be wondering what this filename or process is when you try and searching for any malicious application running in you Windows XP/VIsta machine.. (via Task manager). wpv991242765100.exe&#8217;s  could be viruses, spyware, adware, trojans, rootkits, worms, information stealers, keyloggers, bots&#8230; I for one is not sure, but I also &#8230; <a href="http://www.sysadmindayph.com/blog/wpv991242765100-viruses-spyware-adware-trojans-rootkits-worms/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><strong>wpv991242765100.exe</strong> &#8211; What is it? You may be wondering what this filename or process is when you try and searching for any malicious application running in you Windows XP/VIsta machine.. (via Task manager).</p>
<p><strong>wpv991242765100.exe&#8217;s</strong>  could be viruses, spyware, adware, trojans, rootkits, worms, information stealers, keyloggers, bots&#8230; I for one is not sure, but I also have this process running in my windows machine and I just discovered that this is the culprit on some of my computer problems.</p>
<p><strong>Problems Caused by wpv991242765100.exe</strong></p>
<p>To list a few of the nuances that this process is doing on my <a href="http://www.sysadmindayph.com/blog/best-sony-viao-notebooks-and-laptops/">Viao laptop</a> *grin*:</p>
<ul>
<li>Prevented me from connecting to company&#8217;s VPN</li>
<li>Prevents firefox to launch (and IE for that matter)</li>
<li>No internet on firefox, but fine with IE</li>
<li>and probably others.</li>
</ul>
<p><span id="more-153"></span></p>
<p>As of this writing, there&#8217;s only 1 page/site on the entire internet for this word.. now there two.. mine included&#8230; Here&#8217;s some info on that rich content page:</p>
<h2>File Behavior</h2>
<p>WPV151242765100.EXE has been seen to perform the following behavior:</p>
<ul>
<li>The Process is packed and/or encrypted using a software packing process</li>
</ul>
<p>WPV151242765100.EXE has been the subject of the following behavior:</p>
<ul>
<li>Added as a Registry auto start to load Program on Boot up</li>
</ul>
<h2>Country Of Origin</h2>
<p>The filename WPV151242765100.EXE was first seen on May 20 2009 in the following geographical regions of the Prevx community:</p>
<ul>
<li style="background: url(http://www.sysadmindayph.com/images2/flags/EG.gif) no-repeat left center;">EGYPT on May 20 2009</li>
<li style="background: url(http://www.sysadmindayph.com/images2/flags/US.gif) no-repeat left center;">The UNITED STATES on May 20 2009</li>
</ul>
<h2>File Name Aliases</h2>
<p>WPV151242765100.EXE can also use the following file names:</p>
<ul>
<li>95545953.OUT</li>
<li>46109827.EXE</li>
<li>73433163.EXE</li>
<li>WPV951242765100.EXE</li>
<li>WPV991242765100.EXE</li>
<li>WPV181242765100.EXE</li>
<li>WPV041242765100.EXE</li>
<li>WPV131242765100.EXE</li>
<li>WPV651242765100.EXE</li>
<li>WPV231242765100.EXE</li>
<li>WPV701242765100.EXE</li>
<li>WPV431242765100.EXE</li>
</ul>
<h2>Filesizes</h2>
<p>This file has been seen with the following file size:</p>
<ul>
<li>428,032 bytes</li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.sysadmindayph.com/blog/wpv991242765100-viruses-spyware-adware-trojans-rootkits-worms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Mikkey Worm &#8211; This worm is getting out of hand Twitter</title>
		<link>http://www.sysadmindayph.com/blog/the-mikkey-worm-this-worm-is-getting-out-of-hand-twitter/</link>
		<comments>http://www.sysadmindayph.com/blog/the-mikkey-worm-this-worm-is-getting-out-of-hand-twitter/#comments</comments>
		<pubDate>Mon, 13 Apr 2009 13:41:12 +0000</pubDate>
		<dc:creator>elizar</dc:creator>
				<category><![CDATA[IT News]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[twiter]]></category>
		<category><![CDATA[Virus and Microsoft]]></category>
		<category><![CDATA[mikkey worm]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.sysadmindayph.com/blog/?p=137</guid>
		<description><![CDATA[&#8220;This worm is getting out of hand Twitter&#8221; &#8211; Mikkey. There was a swarm of messages flooding the twittersphere in the past couple of days. This twitter worm apparently hasn&#8217;t been controlled yet by twitter as the flood of messages that apparently coming from Mikkey, continues. I, myself, lucky for me haven&#8217;t been pested by &#8230; <a href="http://www.sysadmindayph.com/blog/the-mikkey-worm-this-worm-is-getting-out-of-hand-twitter/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p>&#8220;This worm is getting out of hand <a href="http://www.sysadmindayph.com/blog/twiter-twitter-everyone-twits/">Twitter</a>&#8221; &#8211; <strong>Mikkey</strong>. There was a swarm of messages flooding the twittersphere in the past couple of days. This twitter worm apparently hasn&#8217;t been controlled yet by twitter as the flood of messages that apparently coming from <strong>Mikkey</strong>, continues.</p>
<p>I, myself, lucky for me haven&#8217;t been pested by this Mikkey work as it only affects those who uses the web application of twitter (apparently). I use a third party web apps for firefox (twitterfox).</p>
<p>Here&#8217;s another way of protecting your self from this <strong>Mikkey worm</strong> from startupmeme.com:</p>
<p>Other <a href="http://www.techcrunch.com/2009/04/13/twitter-worm-woes-continue-fourth-round-of-attacks-by-mickeyy/" target="_blank">steps</a> that you can take to ensure safety is to reset your password, disable Javascript and clear cache. You can also keep a check via <a href="http://status.twitter.com/" target="_blank">Twitter Status Blog</a> or follow <a href="http://twitter.com/spam" target="_blank">@spam</a> for further updates. This is very bad for Twitter’s reputation especially when <a href="http://startupmeme.com/friendfeed-our-with-new-updates-real-time-is-just-what-we-needed/" target="_blank">FriendFeed is getting better by the day</a>. I would simply hate unwanted messages in bulk bothering me or my followers.</p>
<p>Steps to fix it:<br />
1. Change your hex color/reset it<br />
2. Change your bio and change the URL<br />
3. DONT click on any profile that is suspicious and use another twitter client like TweetDeck instead of the Twitter website</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sysadmindayph.com/blog/the-mikkey-worm-this-worm-is-getting-out-of-hand-twitter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Kido / Conficker / Downadup / Downup Worm</title>
		<link>http://www.sysadmindayph.com/blog/remove-kido-conficker-downadup-downup-wor/</link>
		<comments>http://www.sysadmindayph.com/blog/remove-kido-conficker-downadup-downup-wor/#comments</comments>
		<pubDate>Tue, 07 Apr 2009 01:44:06 +0000</pubDate>
		<dc:creator>elizar</dc:creator>
				<category><![CDATA[Virus and Microsoft]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[detect]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[downup]]></category>
		<category><![CDATA[how to remove]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[remove]]></category>
		<category><![CDATA[server]]></category>

		<guid isPermaLink="false">http://www.sysadmindayph.com/blog/?p=135</guid>
		<description><![CDATA[Kido, also known as Downup, Downadup and Conficker, is a computer worm targeting the Microsoft Windows operating system that was first detected in October 2008 but, after a couple of months later, it is still being discussed in antivirus forums and message boards. Topics usually discussed is how to detect and remove if you&#8217;re computer &#8230; <a href="http://www.sysadmindayph.com/blog/remove-kido-conficker-downadup-downup-wor/">Continue reading</a>]]></description>
			<content:encoded><![CDATA[<p><strong>Kido</strong>, also known as Downup, Downadup and Conficker, is a computer worm targeting the <strong>Microsoft Windows operating system</strong> that was first detected in October 2008 but, after a couple of months later, it is still being discussed in antivirus forums and message boards.</p>
<p>Topics usually discussed is how to detect and remove if you&#8217;re computer is infected by this Kido (aka Conficker/Downup/Downadup) worm.</p>
<p>It was reported by Panda Security, also a well known antivirus company, that more than 9 million PC’s have been infected. Special mention at the report was China (the probable country of origin). It is said that China is the country most infected by Kido.</p>
<p><span id="more-135"></span></p>
<h1><a title="Permanent Link to Remove Kido / Conficker / Downadup / Downup" rel="bookmark" href="../remove-kido-conficker-downadup-downup/">Remove Kido / Conficker / Downadup / Downup</a></h1>
<p><strong>Kido </strong>although it already has many names (<strong>Downadup, Downup, Conficker</strong> etc.) various antivirus vendors use various naming conventions for worms.</p>
<p><strong>How to Protect Your Computer with Kido/Conficker/Downadup/Downup</strong></p>
<blockquote><p>There is a fix for this worm, the details are on our security site at <a title="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx</a></p>
<p>Please read the above bulletin for the full details, the patches to prevent this worm are on that page.</p></blockquote>
<p><strong>How to Detect if You&#8217;re Infected with Kido</strong></p>
<p>Found this chart while browsing and looking for ways to detect if you are already infected with this Downadup/Conficker/Kido worm</p>
<p>Check it out here: http://www.joestewart.org/cfeyechart.html</p>
<p><strong>How to Remove Kido / Downadup / Conficker / Downup</strong></p>
<p><span><span>If you are already infected and if your Antivirus software can’t eliminate the </span><span class="IL_SPAN"></p>
<input name="IL_MARKER" type="hidden" />worm</span> you would need to download a removal tool offered by various security product vendors.</span></p>
<p><a onclick="javascript:pageTracker._trackPageview('/outgoing/technet.microsoft.com/en-us/security/dd452420.aspx');" href="http://technet.microsoft.com/en-us/security/dd452420.aspx"><strong>Microsoft</strong></a> : <a onclick="javascript:pageTracker._trackPageview('/outgoing/support.kaspersky.com/faq/?qid=208279973');" href="http://support.kaspersky.com/faq/?qid=208279973">Windows Malicious Software Removal Tool<strong><br />
Kaspersky</strong></a> : KidoKiller<br />
<a onclick="javascript:pageTracker._trackPageview('/outgoing/193.110.109.53/anti-virus/tools/beta/f-downadup.txt');" href="ftp://193.110.109.53/anti-virus/tools/beta/f-downadup.txt"><strong>F-Secure</strong></a> : <a onclick="javascript:pageTracker._trackPageview('/outgoing/ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip');" href="ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip">F-downadup</a> (<a onclick="javascript:pageTracker._trackPageview('/outgoing/193.110.109.53/anti-virus/tools/beta/f-downadup.zip');" href="ftp://193.110.109.53/anti-virus/tools/beta/f-downadup.zip">alternate link</a>)<br />
<a onclick="javascript:pageTracker._trackPageview('/outgoing/www.bitdefender.com/VIRUS-1000462-en--Win32.Worm.Downadup.Gen.html');" href="http://www.bitdefender.com/VIRUS-1000462-en--Win32.Worm.Downadup.Gen.html"><strong>BitDefender</strong></a> : <a onclick="javascript:pageTracker._trackPageview('/outgoing/www.bitdefender.com/site/Downloads/downloadFile/1584/FreeRemovalTool');" href="http://www.bitdefender.com/site/Downloads/downloadFile/1584/FreeRemovalTool">Win32.Worm.Downadup.Gen Remover</a><br />
<a onclick="javascript:pageTracker._trackPageview('/outgoing/www.spywarevoid.com/remove-conficker-worm-downadup-removal.html');" href="http://www.spywarevoid.com/remove-conficker-worm-downadup-removal.html"><strong>Spywarevoid</strong></a> : <a onclick="javascript:pageTracker._trackPageview('/outgoing/www.spywarevoid.com/download/sdsetup.exe');" href="http://www.spywarevoid.com/download/sdsetup.exe">W32.downadup.c removal tool</a><br />
<a onclick="javascript:pageTracker._trackPageview('/outgoing/www.symantec.com/security_response/writeup.jsp?docid=2008-112203-2408-99&amp;tabid=3');" href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-112203-2408-99&amp;tabid=3"><strong>Symantec</strong></a> : <a onclick="javascript:pageTracker._trackPageview('/outgoing/www.symantec.com/security_response/writeup.jsp?docid=2009-011316-0247-99');" href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-011316-0247-99">W32.Downadup Remover</a><br />
<a onclick="javascript:pageTracker._trackPageview('/outgoing/www.eset.eu/press-conficker-continues');" href="http://www.eset.eu/press-conficker-continues"><strong>ESET</strong></a> : <a onclick="javascript:pageTracker._trackPageview('/outgoing/download.eset.com/special/EConfickerRemover.exe');" href="http://download.eset.com/special/EConfickerRemover.exe">Conficker Remover</a><br />
<a onclick="javascript:pageTracker._trackPageview('/outgoing/www.sophos.com/support/knowledgebase/article/51416.html');" href="http://www.sophos.com/support/knowledgebase/article/51416.html"><strong>Sophos</strong></a> : <a onclick="javascript:pageTracker._trackPageview('/outgoing/secure.sophos.com/support/updates/dp/full/sconftool_10_sfx.exe');" href="https://secure.sophos.com/support/updates/dp/full/sconftool_10_sfx.exe">Conficker Cleanup Tool</a></p>
<p>Here are some aliases provided by opular antivirus vendors :</p>
<ul>
<li> <strong>Symantec : W32.Downadup</strong></li>
<li><strong>F-Secure : W32/Downadup.A, W32/Downadup.B etc</strong></li>
<li><strong>Panda : Conficker.A, Conficker.B etc</strong></li>
<li><strong>Kaspersky : Net-Worm.Win32.Kido.bt, Net-Worm.Win32.Kido.ip, Net-Worm.Win32.Kido.iq etc</strong></li>
<li><strong><span>McAffe : W32/Conficker.<span class="IL_SPAN"><br />
<input name="IL_MARKER" type="hidden" />worm</span></span></strong></li>
<li><strong><span>Bitdefender : Win32.<span class="IL_SPAN"><br />
<input name="IL_MARKER" type="hidden" />Worm</span>.Downadup.Gen</span></strong></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.sysadmindayph.com/blog/remove-kido-conficker-downadup-downup-wor/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

