<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Windows Protection &#187; Worms</title>
	<atom:link href="http://windowsprotection.net/category/worms/feed/" rel="self" type="application/rss+xml" />
	<link>http://windowsprotection.net</link>
	<description>Protect your computer from spyware, adware and other malware</description>
	<lastBuildDate>Fri, 27 Apr 2012 14:08:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Remove Worm.Win32.Passma (Removal Instructions)</title>
		<link>http://windowsprotection.net/remove-worm-win32-passma/</link>
		<comments>http://windowsprotection.net/remove-worm-win32-passma/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 10:42:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://windowsprotection.net/?p=4066</guid>
		<description><![CDATA[Threat Description: Worm.Win32.Passma (alias W32/Passma worm) is privacy-infringing malicious software that is able to do quite a bit of harm to the system it infiltrates. Worm.Win32.Passma propagates in several ways. One of these may be the use of spam Email that are sent by automated machines (bots) and come with contagious attachments. If you click [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline; color: #666666;"><strong>Threat Description:</strong></span></p>
<p style="text-align: justify;"><strong>Worm.Win32.Passma</strong> (alias W32/Passma worm) is privacy-infringing malicious software that is able to do quite a bit of harm to the system it infiltrates. Worm.Win32.Passma propagates in several ways. One of these may be the use of spam Email that are sent by automated machines (bots) and come with contagious attachments. If you click one of those attached files you may unknowingly help hackers promote their nasty cyber offspring. Another method of Worm.Win32.Passma distribution (a more widespread one) is through security backdoors and small leaks in the targeted systems. The worm can easily make its way through such splits and find itself inside your Operating System without you knowing about that. When on board, Worm.Win32.Passma configures your OS to run some bad executables every time you log into Windows. This effect is achieved through some changes made to Windows Registry. These corrupt processes are Passma.exe and Servicemgr.exe, and they will determine the extent to which you can feel protected when using your machine. <span id="more-4066"></span>Worm.Win32.Passma can steal passwords and other private information stored on your workstation. One additional instance of Worm.Win32.Passma’s activity is its establishing a background connection with an outer IRC server thus giving remote attackers the access to your system. All in all, it’s not recommended to ignore the presence of such mendacious and perilous parasite as Worm.Win32.Passma on your computer. Please stick to some of the tips below to secure your PC from the impact of this worm.</p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Determine if your system is infected with Worm.Win32.Passma parasite and related threats:</strong></span></p>
<p class="links" style="text-align: center;"><a href="http://windowsprotection.net/spyware-doctor-antivirus/wormwin32passma/download-worm-win32-passma-free-scanner-with-remover">Download Worm.Win32.Passma Free Scanner with Remover</a></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>How to remove this threat manually:</strong></span></p>
<p style="text-align: justify;">Worm.Win32.Passma manual deletion procedure:</p>
<p><span style="text-decoration: underline; color: #666666;">Get rid of the related corrupt files:<br />
</span></p>
<ul>
<li>passma.exe</li>
<li>servicemgr.exe</li>
<li>fld.dll</li>
<li>fso.dll</li>
<li>idws.dll</li>
<li>keyf.dll</li>
<li>keyn.dll</li>
</ul>
<p><span style="text-decoration: underline; color: #666666;">Delete the associated registry entries:</span></p>
<ul>
<li>HKEY_CURRENT_USER\software\virtual maid</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion guid</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\virtual maidvirtual maid</li>
</ul>
<p style="text-align: justify;">Please note that Worm.Win32.Passma manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:</p>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td width="1" height="33"><a href="http://windowsprotection.net/spyware-doctor-antivirus/wormwin32passma/download-worm-win32-passma-free-scanner-with-remover"><img border="0" src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_l.gif" width="62" height="59" /></a></td>
<td align="center" background="http://windowsprotection.net/wp-content/uploads/bg_btn_bg.jpg" bgcolor="#1d4bc5"><a href="http://windowsprotection.net/spyware-doctor-antivirus/wormwin32passma/download-worm-win32-passma-free-scanner-with-remover" class="links-big-green-button"><strong><span class="style12">Download</span> <span class="style13">Worm.Win32.Passma</span> <span class="style12">Removal Tool</span></strong></a></td>
<td width="1"><img src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_r.jpg" width="40" height="59" /></td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://windowsprotection.net/remove-worm-win32-passma/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Custam worm (Removal Instructions)</title>
		<link>http://windowsprotection.net/remove-w32-custam-worm/</link>
		<comments>http://windowsprotection.net/remove-w32-custam-worm/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 17:36:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://windowsprotection.net/?p=4056</guid>
		<description><![CDATA[Threat Description: The sole fact that W32.Custam is a computer worm implies that it infiltrates computers without being noticed (and intercepted of course) and spreads instantly throughout the contaminated system by means of replicating itself. W32.Custam worm injects Windows Operating System and typically applies backdoor methods for that purpose. It finds and uses software vulnerabilities [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline; color: #666666;"><strong>Threat Description:</strong></span></p>
<p style="text-align: justify;">The sole fact that <strong>W32.Custam</strong> is a computer worm implies that it infiltrates computers without being noticed (and intercepted of course) and spreads instantly throughout the contaminated system by means of replicating itself. W32.Custam worm injects Windows Operating System and typically applies backdoor methods for that purpose. It finds and uses software vulnerabilities when intruding; another way of W32.Custam’s infiltration is removable media such as flash memory. Along with being really hard to detect, W32.Custam is also not simple to remove because, like we have mentioned, it creates copies of itself in different system locations. This means eliminating this worm from one spot will sure not stop the parasite from acting, so it takes a more complex approach to disinfect the computer system. Let’s now analyze the activity of W32.Custam when it’s running on your PC. It’s as simple as ABC for W32.Custam to set up a connection with an external server which is maintained by criminals. With the help of W32.Custam worm, these Internet fraudsters can hack into your system and get hold of the private data stored on your machine. <span id="more-4056"></span>One more function potentially implemented by this threat is downloading other hideous parasites such as spyware, trojan viruses etc. When running on the background of your system, W32.Custam may cause your computer to act up and operate slower than usual. To avoid all these drawbacks of W32.Custam activity and save your confidential information, it’s a must to get it off your system.</p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Determine if your system is infected with W32.Custam worm and related threats:</strong></span></p>
<p class="links" style="text-align: center;"><a href="http://windowsprotection.net/spyware-doctor-antivirus/w32custam/download-w32-custam-free-scanner-with-remover">Download W32.Custam Free Scanner with Remover</a></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>How to remove this threat manually:</strong></span></p>
<p style="text-align: justify;">W32.Custam manual deletion procedure:</p>
<p><span style="text-decoration: underline; color: #666666;">Get rid of the related corrupt files:<br />
</span></p>
<ul>
<li>%SystemDrive%\[random folder name]\[sid]\DeSkToP.ini</li>
<li>%SystemDrive%\[random folder name]\[sid]\[random file name].exe</li>
</ul>
<p><span style="text-decoration: underline; color: #666666;">Delete the associated registry entries:</span></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{63KLC5K0-4OPM-00WE-AAX8-17EF1D187263}</li>
</ul>
<p style="text-align: justify;">Please note that W32.Custam manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:</p>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td width="1" height="33"><a href="http://windowsprotection.net/spyware-doctor-antivirus/w32custam/download-w32-custam-free-scanner-with-remover"><img border="0" src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_l.gif" width="62" height="59" /></a></td>
<td align="center" background="http://windowsprotection.net/wp-content/uploads/bg_btn_bg.jpg" bgcolor="#1d4bc5"><a href="http://windowsprotection.net/spyware-doctor-antivirus/w32custam/download-w32-custam-free-scanner-with-remover" class="links-big-green-button"><strong><span class="style12">Download</span> <span class="style13">W32.Custam</span> <span class="style12">Removal Tool</span></strong></a></td>
<td width="1"><img src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_r.jpg" width="40" height="59" /></td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://windowsprotection.net/remove-w32-custam-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Palevo worm (Removal Instructions)</title>
		<link>http://windowsprotection.net/remove-w32-palevo-worm/</link>
		<comments>http://windowsprotection.net/remove-w32-palevo-worm/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 21:19:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://windowsprotection.net/?p=3913</guid>
		<description><![CDATA[Threat Description: Having W32.Palevo (alias Palevo worm) malware on your computer, you are likely to stumble upon some serious system malfunctions and get your privacy endangered. The bulk of W32.Palevo worm’s impact on a random Operating System is concentrated on your security protection, i.e. the antivirus software you have on board your PC. W32.Palevo tends [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline; color: #666666;"><strong>Threat Description:</strong></span></p>
<p style="text-align: justify;">Having <strong>W32.Palevo</strong> (alias Palevo worm) malware on your computer, you are likely to stumble upon some serious system malfunctions and get your privacy endangered. The bulk of W32.Palevo worm’s impact on a random Operating System is concentrated on your security protection, i.e. the antivirus software you have on board your PC. W32.Palevo tends to disable the usage of actual antivirus tools so that the removal procedure gets much aggravated. W32.Palevo spreads owing to shared networks and infected file attachments. So anyone is potentially exposed to the unannounced intrusion of this nasty infection. Unlike the vast majority of worms, W32.Palevo changes the Registry and therefore makes your system run malicious executables upon each startup. Along with this, W32.Palevo usually helps additional malware enter your computer without any particular obstacles. Another bad part of W32.Palevo nature consists in the fact that it populates the injected system with enormous speed through a sophisticated self-replication procedure. <span id="more-3913"></span>W32.Palevo extermination is not simple and can be hardly effective if you do it manually since it spreads through all system drives (you can try though). Both manual and automatic removal tips are described in detail below.</p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Determine if your system is infected with W32.Palevo worm and related threats:</strong></span></p>
<p class="links" style="text-align: center;"><a href="http://windowsprotection.net/spyware-doctor-antivirus/w32palevo/download-w32-palevo-free-scanner-with-remover">Download W32.Palevo Free Scanner with Remover</a></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>How to remove this threat manually:</strong></span></p>
<p style="text-align: justify;">W32.Palevo manual deletion procedure:</p>
<p><span style="text-decoration: underline; color: #666666;">Get rid of the related corrupt files:<br />
</span></p>
<ul>
<li>%Windir%\msddrv42.exe</li>
</ul>
<p><span style="text-decoration: underline; color: #666666;">Delete the associated registry entries:</span></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;Microsoft Driver Setup&#8221; = &#8220;%Windir%\msddrv42.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\&#8221;Microsoft Driver Setup&#8221; = &#8220;%Windir%\msddrv42.exe&#8221;</li>
</ul>
<p style="text-align: justify;">Please note that W32.Palevo manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:</p>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td width="1" height="33"><a href="http://windowsprotection.net/spyware-doctor-antivirus/w32palevo/download-w32-palevo-free-scanner-with-remover"><img border="0" src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_l.gif" width="62" height="59" /></a></td>
<td align="center" background="http://windowsprotection.net/wp-content/uploads/bg_btn_bg.jpg" bgcolor="#1d4bc5"><a href="http://windowsprotection.net/spyware-doctor-antivirus/w32palevo/download-w32-palevo-free-scanner-with-remover" class="links-big-green-button"><strong><span class="style12">Download</span> <span class="style13">W32.Palevo</span> <span class="style12">Removal Tool</span></strong></a></td>
<td width="1"><img src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_r.jpg" width="40" height="59" /></td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://windowsprotection.net/remove-w32-palevo-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove W32.Scrshotvid worm (Removal Instructions)</title>
		<link>http://windowsprotection.net/remove-w32-scrshotvid-worm/</link>
		<comments>http://windowsprotection.net/remove-w32-scrshotvid-worm/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 12:18:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://windowsprotection.net/?p=3674</guid>
		<description><![CDATA[Threat Description: W32.Scrshotvid is a self-replicating computer worm that tends to propagate via removable media, or as a hidden component of downloaded files that seem harmless. The biggest risk arising from W32.Scrshotvid intrusion is that of privacy violation probability. This nefarious parasite is able to open security holes in the compromised system from the inside. [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline; color: #666666;"><strong>Threat Description:</strong></span></p>
<p style="text-align: justify;"><strong>W32.Scrshotvid</strong> is a self-replicating computer worm that tends to propagate via removable media, or as a hidden component of downloaded files that seem harmless. The biggest risk arising from W32.Scrshotvid intrusion is that of privacy violation probability. This nefarious parasite is able to open security holes in the compromised system from the inside. These so-called backdoors will be used to further establish a stealthy connection with an external server which is hackers’ analytic center. Along with this obscure indirect influence, W32.Scrshotvid is as well capable of uploading dangerous files onto the targeted OS thus making the PC exposed to many other infections such as spyware, trojans, rogue antivirus tools etc. W32.Scrshotvid is sensitive to the stuff being typed by the infected PC’s user. It records these data and sends them to cyber criminals for further processing. These can be your credit card details, passwords and other personally identifiable information which is strictly private. <span id="more-3674"></span>Every feature of W32.Scrshotvid is a stimulus to get that worm removed from one’s computer if it happens to have compromised it. W32.Scrshotvid detection is a hard nut to crack so it takes using a professional antivirus solution. You can find more info on this point below.</p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Determine if your system is infected with W32.Scrshotvid worm and related threats:</strong></span></p>
<p class="links" style="text-align: center;"><a href="http://windowsprotection.net/spyware-doctor-antivirus/w32scrshotvid/download-w32-scrshotvid-worm-free-scanner-with-remover">Download W32.Scrshotvid Free Scanner with Remover</a></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>How to remove this threat manually:</strong></span></p>
<p style="text-align: justify;">W32.Scrshotvid manual deletion procedure:</p>
<p><span style="text-decoration: underline; color: #666666;">Get rid of the related corrupt files:<br />
</span></p>
<ul>
<li>%DriveLetter%\imagem.exe</li>
<li>%System%\msnmsg.exe</li>
</ul>
<p><span style="text-decoration: underline; color: #666666;">Delete the associated registry entries:</span></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\&#8221;Msnmsg&#8221; = &#8220;%System%\msnmsg.exe&#8221;</li>
</ul>
<p style="text-align: justify;">Please note that W32.Scrshotvid manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:</p>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td width="1" height="33"><a href="http://windowsprotection.net/spyware-doctor-antivirus/w32scrshotvid/download-w32-scrshotvid-worm-free-scanner-with-remover"><img border="0" src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_l.gif" width="62" height="59" /></a></td>
<td align="center" background="http://windowsprotection.net/wp-content/uploads/bg_btn_bg.jpg" bgcolor="#1d4bc5"><a href="http://windowsprotection.net/spyware-doctor-antivirus/w32scrshotvid/download-w32-scrshotvid-worm-free-scanner-with-remover" class="links-big-green-button"><strong><span class="style12">Download</span> <span class="style13">W32.Scrshotvid</span> <span class="style12">Removal Tool</span></strong></a></td>
<td width="1"><img src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_r.jpg" width="40" height="59" /></td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://windowsprotection.net/remove-w32-scrshotvid-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Rootkit.Win32.Agent.pp &#8211; Rootkit.Win32 Removal Guide</title>
		<link>http://windowsprotection.net/how-to-remove-rootkitwin32agentpp-rootkitwin32-removal-guide/</link>
		<comments>http://windowsprotection.net/how-to-remove-rootkitwin32agentpp-rootkitwin32-removal-guide/#comments</comments>
		<pubDate>Tue, 22 Dec 2009 17:58:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://windowsprotection.net/?p=3283</guid>
		<description><![CDATA[Rootkit.Win32.Agent.pp Description: Rootkit.Win32.Agent.pp is a pseudo-infection being exploited by Malware Defense scareware in order to frighten its victims into buying the registered version of this nasty software product. Actually, Rootkit.Win32.Agent.pp is a real computer parasite that records a PC user’s keystrokes and transmits these data to a remote analytic center run by hackers. But in [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline; color: #666666;"><strong>Rootkit.Win32.Agent.pp Description:</strong></span></p>
<p style="text-align: justify;"> <strong>Rootkit.Win32.Agent.pp</strong> is a pseudo-infection being exploited by <a href=" http://windowsprotection.net/how-to-remove-malware-defense-malware-defense-removal-guide/">Malware Defense</a> scareware in order to frighten its victims into buying the registered version of this nasty software product. Actually, Rootkit.Win32.Agent.pp is a real computer parasite that records a PC user’s keystrokes and transmits these data to a remote analytic center run by hackers. But in the framework of Malware Defense rogueware distribution schemes, Rootkit.Win32.Agent.pp is being exploited as just a scary-sounding puppet infection that is supposed to get people greatly alarmed and inclined to install whatever software is suggested – just to get rid of this virus. Malware Defense fake anti-spyware tends to trigger alerts like the one shown below, saying that Rootkit.Win32.Agent.pp worm has been intercepted on your PC and must be neutralized immediately <span id="more-3283"></span> lest it should play havoc with your Operating System and ruin it in the long run. This warning has one major goal – to have you click the green option in the bottom and thus unknowingly initiated the process of Malware Defense virus installation onto your machine. Please keep in mind that Rootkit.Win32.Agent.pp is not to be afraid of as such – it’s Malware Defense rogue that you should fear. Stick to the following instructions to eliminate the malicious program triggering Rootkit.Win32.Agent.pp misleading ads.  </p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Find out if your PC is infected with Rootkit.Win32.Agent.pp:</strong></span></p>
<p class="links" style="text-align: center;"><a href=" http://windowsprotection.net/spyware-doctor/rootkitwin32agentpp/download-rootkitwin32agentpp-free-scanner-with-remover">Download Rootkit.Win32.Agent.pp Free Scanner with Remover</a></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Rootkit.Win32.Agent.pp Related Alert Screenshot:</strong></span></p>
<p style="text-align: center;"><img class="aligncenter" title="Rootkit.Win32.Agent.pp Related Alert Screenshot" src="http://windowsprotection.net/wp-content/uploads/2009/12/rootkitwin32agentpp1.jpg" alt="Rootkit.Win32.Agent.pp Related Alert Screenshot" width="520" height="546" /></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>How to remove Rootkit.Win32.Agent.pp manually:</strong></span></p>
<p style="text-align: justify;">To perform manual removal of Rootkit.Win32.Agent.pp, you should do the following:</p>
<p><span style="text-decoration: underline; color: #666666;">Delete Rootkit.Win32.Agent.pp corrupt files:<br />
</span></p>
<ul>
<li>%Program Files%\Malware Defense</li>
<li>%Program Files%\Malware Defense\help.ico</li>
<li>%Program Files%\Malware Defense\md.db</li>
<li>%Program Files%\Malware Defense\mdefense.exe</li>
<li>%Program Files%\Malware Defense\mdext.dll</li>
<li>%Program Files%\Malware Defense\uninstall.exe</li>
<li>%UserProfile%\Desktop\Malware Defense Support.lnk</li>
<li>%UserProfile%\Desktop\Malware Defense.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Malware Defense</li>
<li>%UserProfile%\Start Menu\Programs\Malware Defense\Malware Defense Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Malware Defense\Malware Defense.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Malware Defense\Uninstall Malware Defense.lnk</li>
</ul>
<p><span style="text-decoration: underline; color: #666666;">Remove Rootkit.Win32.Agent.pp associated registry entries:</span></p>
<ul>
<li>HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\SimpleShlExt</li>
<li>HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}</li>
<li>HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#8220;Malware Defense&#8221;</li>
</ul>
<p style="text-align: justify;">Please, note that manual removal of Rootkit.Win32.Agent.pp is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic Rootkit.Win32.Agent.pp removal tool below:</p>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td width="1" height="33"><a href=" http://windowsprotection.net/spyware-doctor/rootkitwin32agentpp/download-rootkitwin32agentpp-free-scanner-with-remover"><img border="0" src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_l.gif" width="62" height="59" /></a></td>
<td align="center" background="http://windowsprotection.net/wp-content/uploads/bg_btn_bg.jpg" bgcolor="#1d4bc5"><a href=" http://windowsprotection.net/spyware-doctor/rootkitwin32agentpp/download-rootkitwin32agentpp-free-scanner-with-remover" class="links-big-green-button"><strong><span class="style12">Download</span> <span class="style13">Rootkit.Win32.Agent.pp</span> <span class="style12">Removal Tool</span></strong></a></td>
<td width="1"><img src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_r.jpg" width="40" height="59" /></td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://windowsprotection.net/how-to-remove-rootkitwin32agentpp-rootkitwin32-removal-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Worm.PoeBot.KY &#8211; Worm.PoeBot.KY Removal Guide</title>
		<link>http://windowsprotection.net/how-to-remove-wormpoebotky-wormpoebotky-removal-guide/</link>
		<comments>http://windowsprotection.net/how-to-remove-wormpoebotky-wormpoebotky-removal-guide/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 14:55:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://windowsprotection.net/?p=3217</guid>
		<description><![CDATA[Worm.PoeBot.KY Description: Worm.PoeBot.KY (also known as Virus/Win32.Virut.av or Backdoor:Win32/Poebot.BD) is a computer worm that spreads across PC networks using host system exploits and security vulnerabilities. Worm.PoeBot.KY establishes a hidden connection with an external server and drops its own executables into a phony Recycle Bin directory so as to disguise and hide inside the compromised Operating [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline; color: #666666;"><strong>Worm.PoeBot.KY Description:</strong></span></p>
<p style="text-align: justify;"><strong>Worm.PoeBot.KY</strong> (also known as Virus/Win32.Virut.av or Backdoor:Win32/Poebot.BD) is a computer worm that spreads across PC networks using host system exploits and security vulnerabilities. Worm.PoeBot.KY establishes a hidden connection with an external server and drops its own executables into a phony Recycle Bin directory so as to disguise and hide inside the compromised Operating System. The above might sound a bit confusing but this precisely exemplifies the intricacy of malware applications nowadays. Sad to know, Worm.PoeBot.KY may perform the function of a keylogger that records the user’s typed symbols in order to send this private information to a remote IP. Worm.PoeBot.KY can also corrupt and distort the system files and vital processes running on the compromised system. Considering the fact that Worm.PoeBot.KY is a privacy hazard, it should be removed once intercepted on your PC. <span id="more-3217"></span>Furthermore, Worm.PoeBot.KY is likely to replicate itself and thus infect other nodes (computers) of the same network. Please beware of Worm.PoeBot.KY infection as it can seriously impact your computer routine and endanger other computers on your network. You can stick to the instructions listed below to remove Worm.PoeBot.KY parasite from your machine.</p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Find out if your PC is infected with Worm.PoeBot.KY malware:</strong></span></p>
<p class="links" style="text-align: center;"><a href="http://windowsprotection.net/spyware-doctor-antivirus/wormpoebotky/download-wormpoebotky-free-scanner-with-remover">Download Worm.PoeBot.KY Free Scanner with Remover</a></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>How to remove Worm.PoeBot.KY manually:</strong></span></p>
<p style="text-align: justify;">To perform manual removal of Worm.PoeBot.KY worm, you should do the following:</p>
<p><span style="text-decoration: underline; color: #666666;">Delete Worm.PoeBot.KY corrupt files:<br />
</span></p>
<ul>
<li>%RECYCLER%\S-1-5-21-0243556031-888888379-781863308-1455\p55bd.exe</li>
<li>%System%\fcyysey.exe</li>
<li>%System%\logon.exe</li>
<li>%System%\trkvxf.exe</li>
<li>%System%\winIogon.exe</li>
</ul>
<p><span style="text-decoration: underline; color: #666666;">Remove Worm.PoeBot.KY registry entries:</span></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon</li>
</ul>
<p style="text-align: justify;">Please, note that manual removal of Worm.PoeBot.KY worm is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic Worm.PoeBot.KY removal tool below:</p>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td width="1" height="33"><a href="http://windowsprotection.net/spyware-doctor-antivirus/wormpoebotky/download-wormpoebotky-free-scanner-with-remover"><img border="0" src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_l.gif" width="62" height="59" /></a></td>
<td align="center" background="http://windowsprotection.net/wp-content/uploads/bg_btn_bg.jpg" bgcolor="#1d4bc5"><a href="http://windowsprotection.net/spyware-doctor-antivirus/wormpoebotky/download-wormpoebotky-free-scanner-with-remover" class="links-big-green-button"><strong><span class="style12">Download</span> <span class="style13">Worm.PoeBot.KY</span> <span class="style12">Removal Tool</span></strong></a></td>
<td width="1"><img src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_r.jpg" width="40" height="59" /></td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://windowsprotection.net/how-to-remove-wormpoebotky-wormpoebotky-removal-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Worm.Win32.NetSky &#8211; Worm.Win32.NetSky Removal Guide</title>
		<link>http://windowsprotection.net/how-to-remove-wormwin32netsky-wormwin32netsky-removal-guide/</link>
		<comments>http://windowsprotection.net/how-to-remove-wormwin32netsky-wormwin32netsky-removal-guide/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 22:46:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://windowsprotection.net/?p=3170</guid>
		<description><![CDATA[Worm.Win32.NetSky Description: If you happen to receive alerts about the detection of Worm.Win32.NetSky virus on your computer, you should realize that there’s something malicious going on inside your computer system. Trickily enough, the actual malware problem you are facing is not Worm.Win32.NetSky itself – it’s the counterfeit antivirus program that is to worry about. The [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline; color: #666666;"><strong>Worm.Win32.NetSky Description:</strong></span></p>
<p style="text-align: justify;"> If you happen to receive alerts about the detection of <strong>Worm.Win32.NetSky</strong> virus on your computer, you should realize that there’s something malicious going on inside your computer system. Trickily enough, the actual malware problem you are facing is not Worm.Win32.NetSky itself – it’s the counterfeit antivirus program that is to worry about. The spyware alerts allegedly reporting Worm.Win32.NetSky are being triggered by the dangerous rogue anti-spyware tool called <a href="http://windowsprotection.net/how-to-remove-internet-security-2010-internetsecurity-2010-removal-guide/">Internet Security 2010</a> which has been in rotation for around 6 months now. When Internet Security 2010 secretly finds itself inside your computer, it tends to display fake spyware interception alerts like the one whose snapshot we’ve provided below. Please abstain from clicking any buttons on such fake warning messages or else you will unknowingly trigger an almost irrevocable procedure of scareware invasion of your machine.<span id="more-3170"></span>Internet Security 2010 is a nasty PC bug hungry for your money which it wants in exchange for some services that don’t exist. Worm.Win32.NetSky is just bait yet quite an annoying one. Please get rid of the actual virus that has been messing with your computer. Below is a guide that should help you. </p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Find out if your PC is infected with Worm.Win32.NetSky:</strong></span></p>
<p class="links" style="text-align: center;"><a href="http://windowsprotection.net/spyware-doctor/wormwin32netsky/download-wormwin32netsky-free-scanner-with-remover">Download Worm.Win32.NetSky Free Scanner with Remover</a></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Worm.Win32.NetSky Fake Alert Screenshot:</strong></span></p>
<p style="text-align: center;"><img class="aligncenter" title="Worm.Win32.NetSky Screenshot" src="http://windowsprotection.net/wp-content/uploads/2009/12/wormwin32netsky.jpg" alt="Worm.Win32.NetSky Fake Alert Screenshot" width="400" height="335" /></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>How to remove Worm.Win32.NetSky manually:</strong></span></p>
<p style="text-align: justify;">To perform manual removal of Worm.Win32.NetSky, you should do the following:</p>
<p><span style="text-decoration: underline; color: #666666;">Delete Worm.Win32.NetSky corrupt files:<br />
</span></p>
<ul>
<li>%Program Files%\InternetSecurity2010</li>
<li>%Program Files%\InternetSecurity2010\IS2010.exe</li>
<li>%Documents and Settings%\[USER]\Cookies\user@buy[1].txt</li>
<li>%Documents and Settings%\[USER]\Desktop\Internet Security 2010.lnk</li>
<li>%Documents and Settings%\[USER]\Desktop\SetupIS2010.exe</li>
<li>%Documents and Settings%\[USER]\Start Menu\Internet Security 2010.lnk</li>
<li>%Documents and Settings%\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk</li>
</ul>
<p><span style="text-decoration: underline; color: #666666;">Remove Worm.Win32.NetSky associated registry entries:</span></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Internet Security 2010</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Internet Security 2010</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#8220;IS2010.exe&#8221;</li>
</ul>
<p style="text-align: justify;">Please, note that manual removal of Worm.Win32.NetSky is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic Worm.Win32.NetSky removal tool below:</p>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td width="1" height="33"><a href="http://windowsprotection.net/spyware-doctor/wormwin32netsky/download-wormwin32netsky-free-scanner-with-remover"><img border="0" src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_l.gif" width="62" height="59" /></a></td>
<td align="center" background="http://windowsprotection.net/wp-content/uploads/bg_btn_bg.jpg" bgcolor="#1d4bc5"><a href="http://windowsprotection.net/spyware-doctor/wormwin32netsky/download-wormwin32netsky-free-scanner-with-remover" class="links-big-green-button"><strong><span class="style12">Download</span> <span class="style13">Worm.Win32.NetSky</span> <span class="style12">Removal Tool</span></strong></a></td>
<td width="1"><img src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_r.jpg" width="40" height="59" /></td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://windowsprotection.net/how-to-remove-wormwin32netsky-wormwin32netsky-removal-guide/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How to Remove Virus.Win32.Hala.a &#8211; Virus.Win32.Hala.a Removal Guide</title>
		<link>http://windowsprotection.net/how-to-remove-viruswin32halaa-viruswin32halaa-removal-guide/</link>
		<comments>http://windowsprotection.net/how-to-remove-viruswin32halaa-viruswin32halaa-removal-guide/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 09:10:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://windowsprotection.net/?p=2806</guid>
		<description><![CDATA[Virus.Win32.Hala.a Description: Virus.Win32.Hala.a is a PC parasite whose belonging to a particular malware category is being argued over, most IT experts being inclined to consider it a computer worm because it self-replicates and possesses some more corresponding characteristic features. However, Virus.Win32.Hala.a seems to have found itself a new application sphere lately – it’s being exploited [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline; color: #666666;"><strong>Virus.Win32.Hala.a Description:</strong></span></p>
<p style="text-align: justify;"><strong>Virus.Win32.Hala.a</strong> is a PC parasite whose belonging to a particular malware category is being argued over, most IT experts being inclined to consider it a computer worm because it self-replicates and possesses some more corresponding characteristic features. However, Virus.Win32.Hala.a seems to have found itself a new application sphere lately – it’s being exploited as a scare application in the framework of distributing <a href="http://windowsprotection.net/how-to-remove-additional-guard-additionalguard-removal-guide/">Additional Guard</a> and other rogue anti-spyware programs belonging to the same family. Please, take a look at the screenshot below – it’s a Security Center Alert that mentions Virus.Win32.Hala.a as a virus that potentially threatens your PC security and must be blocked. You should bear in mind that such alert is a fake one which tries to make you install Windows Police Pro scareware. Hence, you don’t literally need to delete Virus.Win32.Hala.a infection; you should uninstall the malicious program that triggers fake ads like that. <span id="more-2806"></span>Another thing you should know in this context is the fact that Additional Guard virus infiltrates one’s computer system without the user’s knowledge and authorization because it uses backdoor trojan viruses to intrude in such stealthy manner. So don’t get too surprised to suddenly learn you have that rogueware application on board. Please, follow the guide below to get rid of Virus.Win32.Hala.a problem and the sponsoring rogueware.</p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Find out if your PC is infected with Virus.Win32.Hala.a and related rogue:</strong></span></p>
<p class="links" style="text-align: center;"><a href="http://windowsprotection.net/spyware-doctor-antivirus/viruswin32halaa/download-viruswin32halaa-free-scanner-with-remover">Download Virus.Win32.Hala.a Free Scanner with Remover</a></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Screenshot of Virus.Win32.Hala.a Associated Alert:</strong></span></p>
<p style="text-align: center;"><img class="aligncenter" title="Screenshot of Virus.Win32.Hala.a Associated Alert" src="http://windowsprotection.net/wp-content/uploads/2009/09/virus_halaa.jpg" alt="Virus.Win32.Hala.a Associated Alert" width="520" height="405" border="1" /></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>How to remove Virus.Win32.Hala.a and associated malware manually:</strong></span></p>
<p style="text-align: justify;">To perform manual removal of Virus.Win32.Hala.a and Additional Guard rogue, you should do the following:</p>
<p><span style="text-decoration: underline; color: #666666;">Delete Virus.Win32.Hala.a corrupt files:<br />
</span></p>
<ul>
<li>%Documents and Settings%\All Users\Application Data\2565da61\AG345d.exe</li>
<li>%Documents and Settings%\All Users\Application Data\2565da61\278.mof</li>
<li>%Documents and Settings%\All Users\Application Data\2565da61\mozcrt19.dll</li>
<li>%Documents and Settings%\All Users\Application Data\2565da61\sqlite3.dll</li>
<li>%Documents and Settings%\All Users\Application Data\2565da61\AG.ico</li>
<li>%Documents and Settings%\All Users\Application Data\2565da61\AGSys</li>
<li>%Documents and Settings%\All Users\Application Data\2565da61\AGSys\vd952342.bd</li>
<li>%Documents and Settings%\All Users\Application Data\2565da61\AGSys</li>
<li>%Documents and Settings%\All Users\Application Data\2565da61\ag.cfg</li>
<li>%Documents and Settings%\All Users\Application Data\Microsoft\Internet Explorer\Quick Launch\Additional Guard.lnk</li>
<li>%Documents and Settings%\All Users\Application Data\Additional Guard\cookies.sqlite</li>
<li>%UserProfile%\Desktop\Additional Guard.lnk</li>
<li>%UserProfile%\Recent\ANTIGEN.tmp</li>
<li>%UserProfile%\Recent\cb.exe</li>
<li>%UserProfile%\Recent\CLSV.tmp</li>
<li>%UserProfile%\Recent\ddv.dll</li>
<li>%UserProfile%\Recent\dudl.drv</li>
<li>%UserProfile%\Recent\energy.dll</li>
<li>%UserProfile%\Recent\energy.sys</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\fan.drv</li>
<li>%UserProfile%\Recent\FS.dll</li>
<li>%UserProfile%\Recent\PE.drv</li>
<li>%UserProfile%\Recent\ppal.exe</li>
<li>%UserProfile%\Recent\SICKBOY.tmp</li>
<li>%UserProfile%\Recent\tjd.sys</li>
</ul>
<p><span style="text-decoration: underline; color: #666666;">Remove Virus.Win32.Hala.a associated registry entries:</span></p>
<ul>
<li>HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#8220;Additional Guard&#8221;</li>
</ul>
<p style="text-align: justify;">Please, note that manual removal of Virus.Win32.Hala.a problem is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic Virus.Win32.Hala.a removal tool below:</p>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td width="1" height="33"><a href="http://windowsprotection.net/spyware-doctor-antivirus/viruswin32halaa/download-viruswin32halaa-free-scanner-with-remover"><img border="0" src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_l.gif" width="62" height="59" /></a></td>
<td align="center" background="http://windowsprotection.net/wp-content/uploads/bg_btn_bg.jpg" bgcolor="#1d4bc5"><a href="http://windowsprotection.net/spyware-doctor-antivirus/viruswin32halaa/download-viruswin32halaa-free-scanner-with-remover" class="links-big-green-button"><strong><span class="style12">Download</span> <span class="style13">Virus.Win32.Hala.a</span> <span class="style12">Removal Tool</span></strong></a></td>
<td width="1"><img src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_r.jpg" width="40" height="59" /></td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://windowsprotection.net/how-to-remove-viruswin32halaa-viruswin32halaa-removal-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Net-Worm.Win32.Mytob.t &#8211; Net-Worm.Win32.Mytob.t Removal Guide</title>
		<link>http://windowsprotection.net/how-to-remove-net-wormwin32mytobt-net-wormwin32mytobt-removal-guide/</link>
		<comments>http://windowsprotection.net/how-to-remove-net-wormwin32mytobt-net-wormwin32mytobt-removal-guide/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 11:28:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://windowsprotection.net/?p=2791</guid>
		<description><![CDATA[Net-Worm.Win32.Mytob.t Description: Net-Worm.Win32.Mytob.t is being actively used for paving the distribution paths of rogue anti-spyware. The snapshot below shows a fake warning message triggered by Windows Police Pro scareware application. As you can see, Net-Worm.Win32.Mytob.t is claimed to be a piece of suspicious software that contaminates computers running Windows OS; and it’s stated to have [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline; color: #666666;"><strong>Net-Worm.Win32.Mytob.t Description:</strong></span></p>
<p style="text-align: justify;"><strong>Net-Worm.Win32.Mytob.t</strong> is being actively used for paving the distribution paths of rogue anti-spyware. The snapshot below shows a fake warning message triggered by <a href="http://windowsprotection.net/remove-windows-police-pro-windowspolicepro-removal-guide/">Windows Police Pro</a> scareware application. As you can see, Net-Worm.Win32.Mytob.t is claimed to be a piece of suspicious software that contaminates computers running Windows OS; and it’s stated to have been detected on your computer. Actually, that’s just a trick applied by Windows Police Pro to scare you and make you believe you really have this odd PC worm on your machine. Having intimidated you this way, Windows Police Pro rogueware creators are hoping to win your trust and get you installing and buying the full commercial version of their scamware. Consequently, you should bear in mind that Net-Worm.Win32.Mytob.t alerts are misleading; that Security Center Alerts like the one below are not to be trusted; and last but not least – the messages about Net-Worm.Win32.Mytob.t being detected are a sign of Windows Police Pro fake anti-spyware invasion. <span id="more-2791"></span>Therefore, it’s most reasonable to locate and eliminate Windows Police Pro rogue, doing which is sure to cease the Net-Worm.Win32.Mytob.t uncontrolled alerting activity.</p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Find out if your PC is infected with Net-Worm.Win32.Mytob.t and related rogue:</strong></span></p>
<p class="links" style="text-align: center;"><a href="http://windowsprotection.net/spyware-doctor-antivirus/networmwin32mytobt/download-net-wormwin32mytobt-free-scanner-with-remover">Download Net-Worm.Win32.Mytob.t Free Scanner with Remover</a></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Screenshot of Net-Worm.Win32.Mytob.t Associated Alert:</strong></span></p>
<p style="text-align: center;"><img class="aligncenter" title="Screenshot of Net-Worm.Win32.Mytob.t Associated Alert" src="http://windowsprotection.net/wp-content/uploads/2009/09/networm_mytobt.jpg" alt="Net-Worm.Win32.Mytob.t Associated Alert" width="520" height="403" border="1" /></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>How to remove Net-Worm.Win32.Mytob.t and associated malware manually:</strong></span></p>
<p style="text-align: justify;">To perform manual removal of Net-Worm.Win32.Mytob.t and Windows Police Pro rogue, you should do the following:</p>
<p><span style="text-decoration: underline; color: #666666;">Delete Net-Worm.Win32.Mytob.t corrupt files:<br />
</span></p>
<ul>
<li>%WINDOWS%\system32\dddesot.dll</li>
<li>%WINDOWS%\system32\desote.exe</li>
<li>%Program Files%\windows police pro\msvcm80.dll</li>
<li>%Program Files%\windows police pro\msvcp80.dll</li>
<li>%Program Files%\windows police pro\msvcr80.dll</li>
<li>%Program Files%\windows police pro\Windows Police Pro.exe</li>
<li>%Program Files%\windows police pro\tmp\dbsinit.exe</li>
<li>%Program Files%\windows police pro\tmp\wispex.html</li>
<li>%Program Files%\windows police pro\tmp\images\i1.gif</li>
<li>%Program Files%\windows police pro\tmp\images\i2.gif</li>
<li>%Program Files%\windows police pro\tmp\images\i3.gif</li>
<li>%Program Files%\windows police pro\tmp\images\j1.gif</li>
<li>%Program Files%\windows police pro\tmp\images\j2.gif</li>
<li>%Program Files%\windows police pro\tmp\images\j3.gif</li>
<li>%Program Files%\windows police pro\tmp\images\jj1.gif</li>
<li>%Program Files%\windows police pro\tmp\images\jj2.gif</li>
<li>%Program Files%\windows police pro\tmp\images\jj3.gif</li>
<li>%Program Files%\windows police pro\tmp\images\l1.gif</li>
<li>%Program Files%\windows police pro\tmp\images\l2.gif</li>
<li>%Program Files%\windows police pro\tmp\images\l3.gif</li>
<li>%Program Files%\windows police pro\tmp\images\pix.gif</li>
<li>%Program Files%\windows police pro\tmp\images\t1.gif</li>
<li>%Program Files%\windows police pro\tmp\images\t2.gif</li>
<li>%Program Files%\windows police pro\tmp\images\up1.gif</li>
<li>%Program Files%\windows police pro\tmp\images\up2.gif</li>
<li>%Program Files%\windows police pro\tmp\images\w1.gif</li>
<li>%Program Files%\windows police pro\tmp\images\w11.gif</li>
<li>%Program Files%\windows police pro\tmp\images\w2.gif</li>
<li>%Program Files%\windows police pro\tmp\images\w3.gif</li>
<li>%Program Files%\windows police pro\tmp\images\w3.jpg</li>
<li>%Program Files%\windows police pro\tmp\images\wt1.gif</li>
<li>%Program Files%\windows police pro\tmp\images\wt2.gif</li>
<li>%Program Files%\windows police pro\tmp\images\wt3.gif</li>
<li>%UserProfile%\start menu\Programs\windows police pro\Windows Police Pro.lnk</li>
<li>%UserProfile%\Desktop\Windows Police Pro.lnk</li>
<li>%UserProfile%\start menu\Programs\windows police pro\Windows Police Pro.lnk</li>
<li>%UserProfile%\Desktop\Windows Police Pro.lnk</li>
<li>%WINDOWS%\svchasts.exe</li>
</ul>
<p><span style="text-decoration: underline; color: #666666;">Remove Net-Worm.Win32.Mytob.t associated registry entries:</span></p>
<ul>
<li>HKEY_CURRENT_USER\SOFTWARE\Windows Police Pro</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Win Police Pro</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\antippro2009_100</li>
</ul>
<p style="text-align: justify;">Please, note that manual removal of Net-Worm.Win32.Mytob.t is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic Net-Worm.Win32.Mytob.t removal tool below:</p>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td width="1" height="33"><a href="http://windowsprotection.net/spyware-doctor-antivirus/networmwin32mytobt/download-net-wormwin32mytobt-free-scanner-with-remover"><img border="0" src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_l.gif" width="62" height="59" /></a></td>
<td align="center" background="http://windowsprotection.net/wp-content/uploads/bg_btn_bg.jpg" bgcolor="#1d4bc5"><a href="http://windowsprotection.net/spyware-doctor-antivirus/networmwin32mytobt/download-net-wormwin32mytobt-free-scanner-with-remover" class="links-big-green-button"><strong><span class="style12">Download</span> <span class="style13">Net-Worm.Win32.Mytob.t</span> <span class="style12">Removal Tool</span></strong></a></td>
<td width="1"><img src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_r.jpg" width="40" height="59" /></td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://windowsprotection.net/how-to-remove-net-wormwin32mytobt-net-wormwin32mytobt-removal-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Backdoor.Win32.Hupigon Worm &#8211; Backdoor.Win32.Hupigon.fixn Removal Guide</title>
		<link>http://windowsprotection.net/how-to-remove-backdoorwin32hupigon-worm-backdoorwin32hupigonfixn-removal-guide/</link>
		<comments>http://windowsprotection.net/how-to-remove-backdoorwin32hupigon-worm-backdoorwin32hupigonfixn-removal-guide/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 09:15:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://windowsprotection.net/?p=2479</guid>
		<description><![CDATA[Backdoor.Win32.Hupigon Worm Description: Backdoor.Win32.Hupigon (aka Backdoor.Win32.Hupigon.fixn or Hupigon.fixn) is a computer worm that infects one’s OS secretly and challenges the user’s privacy by stealing confidential information. That’s the encyclopaedic knowledge. However, Backdoor.Win32.Hupigon worm is known to have been lately exploited in the scareware campaign meant for pushing the rogue antivirus product called Windows Antivirus Pro. [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline; color: #666666;"><strong>Backdoor.Win32.Hupigon Worm Description:</strong></span></p>
<p style="text-align: justify;"><strong>Backdoor.Win32.Hupigon</strong> (aka Backdoor.Win32.Hupigon.fixn or Hupigon.fixn) is a computer worm that infects one’s OS secretly and challenges the user’s privacy by stealing confidential information. That’s the encyclopaedic knowledge. However, Backdoor.Win32.Hupigon worm is known to have been lately exploited in the scareware campaign meant for pushing the rogue antivirus product called <a href="http://windowsprotection.net/how-to-remove-windows-antivirus-pro-windowsantivirus-pro-removal-guide/">Windows Antivirus Pro</a>. In this particular role, Backdoor.Win32.Hupigon is mentioned on deceptive alerts triggered by vundo trojans related to Windows Antivirus Pro malware. It’s the trojans that are responsible for triggering the false ads reading “Windows Antivirus Pro has denied internet access of the program”. Those bogus alerts blame Backdoor.Win32.Hupigon.fixn for compromising the user’s privacy through personal data theft and transmission to remote attackers. The two options available on Backdoor.Win32.Hupigon alerts are as follows: “Yes, Activated Windows Antivirus Pro” and “No, Activate later”.<span id="more-2479"></span> As you can see, the malware is entrapping you by suggesting a way too poor choice. In other words, by using the scary denomination of Backdoor.Win32.Hupigon worm, Windows Antivirus Pro tries to intimidate people into buying the license for this rogue program. Please, do not fall victim of this tricky scheme; remove Windows Antivirus Pro and the associated trojans instead of fighting the imaginary worm.</p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Find out if your PC is infected with Backdoor.Win32.Hupigon Worm:</strong></span></p>
<p class="links" style="text-align: center;"><a href="http://windowsprotection.net/spyware-doctor-antivirus/backdoorwin32hupigon/download-backdoorwin32hupigon-free-scanner-with-remover">Download Backdoor.Win32.Hupigon Worm Free Scanner with Remover</a></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>Screenshot of Backdoor.Win32.Hupigon Worm Associated Alert:</strong></span></p>
<p style="text-align: center;"><img class="aligncenter" title="Screenshot of Backdoor.Win32.Hupigon Worm Associated Alert" src="http://windowsprotection.net/wp-content/uploads/backdoorwin32hupigon.jpg" alt="Backdoor.Win32.Hupigon Worm Associated Alert" width="520" height="457" border="1" /></p>
<p><span style="text-decoration: underline; color: #666666;"><strong>How to remove Backdoor.Win32.Hupigon Worm manually:</strong></span></p>
<p style="text-align: justify;">To perform manual removal of Backdoor.Win32.Hupigon, you should do the following:</p>
<p><span style="text-decoration: underline; color: #666666;">Delete Backdoor.Win32.Hupigon Worm corrupt files:<br />
</span></p>
<ul>
<li>%UserProfile%\Desktop\Windows Antivirus Pro.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Windows Antivirus Pro</li>
<li>%UserProfile%\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk</li>
<li>%Program Files%\Windows Antivirus Pro\</li>
<li>%Program Files%\Windows Antivirus Pro\ANTI_files.exe</li>
<li>%Program Files%\Windows Antivirus Pro\msvcm80.dll</li>
<li>%Program Files%\Windows Antivirus Pro\msvcp80.dll</li>
<li>%Program Files%\Windows Antivirus Pro\msvcr80.dll</li>
<li>%Program Files%\Windows Antivirus Pro\Windows Antivirus Pro.exe</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\dbsinit.exe</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\wispex.html</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\i1.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\i2.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\i3.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\j1.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\j2.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\j3.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\jj1.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\jj2.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\jj3.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\l1.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\l2.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\l3.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\pix.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\t1.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\t2.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\up1.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\up2.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\w1.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\w11.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\w2.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\w3.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\w3.jpg</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\wt1.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\wt2.gif</li>
<li>%Program Files%\Windows Antivirus Pro\tmp\images\wt3.gif</li>
<li>%WINDOWS%\ppp3.dat</li>
<li>%WINDOWS%\ppp4.dat</li>
<li>%WINDOWS%\svchast.exe</li>
<li>%WINDOWS%\system32\bennuar.old</li>
<li>%WINDOWS%\system32\dddesot.dll</li>
<li>%WINDOWS%\system32\desot.exe</li>
<li>%WINDOWS%\system32\sysnet.dat</li>
</ul>
<p><span style="text-decoration: underline; color: #666666;">Remove Backdoor.Win32.Hupigon Worm associated registry entries:</span></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Softimer</li>
<li>HKEY_CURRENT_USER\Software\Windows Antivirus Pro</li>
<li>HKEY_CLASSES_ROOT\CLSID\{425882B0-B0BF-11CE-B59F-00AA006CB37D}</li>
<li>HKEY_CLASSES_ROOT\CLSID\{F54AF7DE-6038-4026-8433-CC30E3F17212}</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F54AF7DE-6038-4026-8433-CC30E3F17212}</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Win Antivirus Pro</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AntipPro2009_12</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AntipPro2009_12</li>
</ul>
<p style="text-align: justify;">Please, note that manual removal of Backdoor.Win32.Hupigon Worm is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic Backdoor.Win32.Hupigon Worm removal tool below:</p>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td width="1" height="33"><a href="http://windowsprotection.net/spyware-doctor-antivirus/backdoorwin32hupigon/download-backdoorwin32hupigon-free-scanner-with-remover"><img border="0" src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_l.gif" width="62" height="59" /></a></td>
<td align="center" background="http://windowsprotection.net/wp-content/uploads/bg_btn_bg.jpg" bgcolor="#1d4bc5"><a href="http://windowsprotection.net/spyware-doctor-antivirus/backdoorwin32hupigon/download-backdoorwin32hupigon-free-scanner-with-remover" class="links-big-green-button"><strong><span class="style12">Download</span> <span class="style13">Backdoor.Win32.Hupigon Worm</span> <span class="style12">Removal Tool</span></strong></a></td>
<td width="1"><img src="http://windowsprotection.net/wp-content/uploads/cr_btn_bg_r.jpg" width="40" height="59" /></td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://windowsprotection.net/how-to-remove-backdoorwin32hupigon-worm-backdoorwin32hupigonfixn-removal-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

