<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SpyZooka Blog - Easy Spyware Removal</title>
	<atom:link href="http://bluepenguinsoftware.com/spyzooka/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://bluepenguinsoftware.com/spyzooka/blog</link>
	<description>SpyZooka’s antispyware blog with the latest news, tips and advice about spyware and  protecting yourself online.</description>
	<lastBuildDate>Sat, 13 Mar 2010 03:15:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>SpyZooka Warns Computer Owners of Total PC Defender Scam</title>
		<link>http://bluepenguinsoftware.com/spyzooka/blog/total-pc-defender-scam/</link>
		<comments>http://bluepenguinsoftware.com/spyzooka/blog/total-pc-defender-scam/#comments</comments>
		<pubDate>Sat, 13 Mar 2010 03:15:30 +0000</pubDate>
		<dc:creator>bluepenguin15</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Total PC Defender]]></category>
		<category><![CDATA[totalpcdefender]]></category>
		<category><![CDATA[totalpcdefender.com]]></category>

		<guid isPermaLink="false">http://bluepenguinsoftware.com/spyzooka/blog/?p=9724</guid>
		<description><![CDATA[SUMMARY: SpyZooka warns of rogue software that tricks computer owners into thinking their computer has security problems. Total PC Defender mimics actual spyware and is a fake program that won’t remove viruses from computers.
Sequim, WA – If you have a computer that suddenly shows windows filled with warnings of security problems and the urgent need [...]]]></description>
			<content:encoded><![CDATA[<p>SUMMARY: SpyZooka warns of rogue software that tricks computer owners into thinking their computer has security problems. Total PC Defender mimics actual spyware and is a fake program that won’t remove viruses from computers.</p>
<p>Sequim, WA – If you have a computer that suddenly shows windows filled with warnings of security problems and the urgent need to buy an antispyware program, it may be a scam. Carl Haugen, President of BluePenguin Software says, “<a href="http://bluepenguinsoftware.com/spyzooka/blog/total-pc-defender/">Total PC Defender</a> mimics actual spyware programs showing a computer user fake security warnings that can scare a user into thinking the computer is infected and tricking the user into purchasing a full version of the software program. This program is a fake and does not show real security warnings or real scan results, nor does it remove viruses from computers.”</p>
<p>Rogue software programs like Total PC Defender may accidentally be downloaded through fake URLs that pop up at the top of search engine results, redirecting you to another page. There will most likely be a ‘Click to fix’ button, prompting you to give money, which ends up being an illegitimate company selling a product that is not protecting your computer.</p>
<p>“Once installed, the only way to remove Total PC Defender is to reformat your hard drive or use a legitimate antispyware program like SpyZooka to remove it,” says Haugen. “SpyZooka is a legitimate <a href="http://bluepenguinsoftware.com/spyzooka/">antispyware program</a> that will detect and protect your computer from such infections.”</p>
<p>Contact: Carl D. Haugen III, CdO, HsD<br />
Company: BluePenguin Software, Inc<br />
www.BluePenguinSoftware.com<br />
Phone: 561-459-5393<br />
Email: press@bluepenguinsoftware.com</p>
]]></content:encoded>
			<wfw:commentRss>http://bluepenguinsoftware.com/spyzooka/blog/total-pc-defender-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32.Shark Trojan</title>
		<link>http://bluepenguinsoftware.com/spyzooka/blog/shark-trojan/</link>
		<comments>http://bluepenguinsoftware.com/spyzooka/blog/shark-trojan/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 09:00:11 +0000</pubDate>
		<dc:creator>Carl Haugen</dc:creator>
				<category><![CDATA[Backdoor Trojan]]></category>
		<category><![CDATA[Shark]]></category>
		<category><![CDATA[Win32.Shark]]></category>
		<category><![CDATA[Win32Shark]]></category>

		<guid isPermaLink="false">http://bluepenguinsoftware.com/spyzooka/blog/?p=9314</guid>
		<description><![CDATA[Win32.Shark is a backdoor Trojan horse program.  This nasty program downloads other malware onto your already infected system.  Win32.Shark will spread itself through spam e-mails, pornographic websites and file-sharing programs.  Once it has entered, it will inject malicious files into your registry that will activate annoying pop-up advertisements.  In addition to turning off your security [...]]]></description>
			<content:encoded><![CDATA[<p>Win32.Shark is a backdoor Trojan horse program.  This nasty program downloads other malware onto your already infected system.  Win32.Shark will spread itself through spam e-mails, pornographic websites and file-sharing programs.  Once it has entered, it will inject malicious files into your registry that will activate annoying pop-up advertisements.  In addition to turning off your security software, this pest gives control of your computer over to its hacker.  Now, nothing one your system is off limits!</p>
<p><span id="more-9314"></span></p>
<p><strong>AKA:</strong><br />
Net-Worm.Win32.Mytob.f<br />
W32.Mytob.L@mm<br />
W32/Mytob.gen@MM<br />
WORM_MYTOB.J<br />
I-Worm.Mytob.I<br />
W32/Mytob-D<br />
Worm:Win32/Hellim.B<br />
Net-Worm.Mytob!sd5<br />
Backdoor.VB.GEN<br />
Backdoor.Win32.Shark.dxa<br />
Backdoor.Win32.Shark.aoo<br />
Backdoor.Win32.VB<br />
Related Files: shel.exe<br />
my_server.exe<br />
localhoster.exe<br />
okiller.exe<strong> </strong></p>
<p><strong>Category: </strong><br />
Trojan<strong></strong></p>
<p><strong>Recommended Action: </strong><br />
Remove at once.</p>
<p>Attempting manual removal is difficult and must be approached with caution.  You must kill all running processes for Win32.Shark.  You must then search for all remaining files and then delete them.  Leaving any files behind will result in this program returning and causing more harm to your PC.  To safeguard fully against this threat and any others, use a trusted system that doesn’t require manual removal.</p>
<p>SpyZooka is an effective spyware removal program with the ability to automatically clear all spyware from your PC.  With so many choices out there, know that SpyZooka offers the only 100% spyware removal guarantee.  The choice is simple – SpyZooka.</p>
]]></content:encoded>
			<wfw:commentRss>http://bluepenguinsoftware.com/spyzooka/blog/shark-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32.Shang Trojan</title>
		<link>http://bluepenguinsoftware.com/spyzooka/blog/shang-trojan/</link>
		<comments>http://bluepenguinsoftware.com/spyzooka/blog/shang-trojan/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 14:00:25 +0000</pubDate>
		<dc:creator>Carl Haugen</dc:creator>
				<category><![CDATA[Backdoor Trojan]]></category>
		<category><![CDATA[Shang]]></category>
		<category><![CDATA[Win32.Shang]]></category>
		<category><![CDATA[Win32Shang]]></category>

		<guid isPermaLink="false">http://bluepenguinsoftware.com/spyzooka/blog/?p=9311</guid>
		<description><![CDATA[Hackers who usually write viruses will also write backdoor Trojan programs like Win32.Shang.  This program is beloved by hackers because of its relative ease in infiltrating a system.  Hackers will use these programs to harvest confidential data for identify theft or to use your PC to distribute additional malware.  These pests will be able to [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Hackers who usually write viruses will also write backdoor Trojan programs like Win32.Shang.  This program is beloved by hackers because of its relative ease in infiltrating a system.  Hackers will use these programs to harvest confidential data for identify theft or to use your PC to distribute additional malware.  These pests will be able to execute files, run applications and even open and close your disk drive!  Failure to remove this pest quickly and you could lose much more than the use of your disk drive.</p>
<p style="text-align: justify;">For detection, look for the following fingerprints: 0a1dddf9f034c174&#8230;, 822cb1154adf89b0&#8230;, 30512ef325f9002e&#8230;, c4eacb0bacf11935&#8230;, 3a75ab0c4904bb6c&#8230;, d97c48adb95e11ff&#8230;, eb561faf7f74d01a&#8230;</p>
<p style="text-align: justify;">
<p style="text-align: justify;"><span id="more-9311"></span></p>
<p style="text-align: justify;"><strong>AKA: </strong><br />
Backdoor.Win32.Shang.15<br />
Backdoor.Shang.15<br />
BackDoor-UW<br />
Backdoor.Trojan<br />
BackDoor.Shang.15<br />
Troj/Shang-15<br />
Backdoor:Win32/Shang.1_5<br />
BKDR_DEVILICON.A<br />
BDC/Shang.15.Cli<br />
Win32:Trojan-gen.<br />
BackDoor.Shang.D<br />
Backdoor.Shang.1.5.A<br />
Trj/Shangquan.C<br />
Win32/Shang.15.Client<br />
<strong><br />
Related Files: </strong><br />
N/A</p>
<p><strong>Category: </strong><br />
Backdoor Trojan</p>
<p><strong>Recommended Action: </strong><br />
Remove at once.</p>
<p style="text-align: justify;">For manual removal for Win32.Shang, you must delete all files and folders and any registry entries for the program.  This can be quite difficult not to mention time consuming.  If you want a faster way, SpyZooka is the answer.  SpyZooka will eliminate the need for poring over different file names and such.</p>
<p style="text-align: justify;">SpyZooka does it for you.  With SpyZooka on your side, you have no need to fear spyware again.  Simply set SpyZooka to scan for detection of spyware each time you startup Windows.  It’s that simple.</p>
]]></content:encoded>
			<wfw:commentRss>http://bluepenguinsoftware.com/spyzooka/blog/shang-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32.Shah Trojan</title>
		<link>http://bluepenguinsoftware.com/spyzooka/blog/shah-trojan/</link>
		<comments>http://bluepenguinsoftware.com/spyzooka/blog/shah-trojan/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 11:00:18 +0000</pubDate>
		<dc:creator>Carl Haugen</dc:creator>
				<category><![CDATA[Backdoor Trojan]]></category>
		<category><![CDATA[Shah]]></category>
		<category><![CDATA[ValueWin32.Shah]]></category>
		<category><![CDATA[Win32Shah]]></category>

		<guid isPermaLink="false">http://bluepenguinsoftware.com/spyzooka/blog/?p=9307</guid>
		<description><![CDATA[Backdoor, Win32.Shah, is named after the Persian word for king but it may be aptly named “king of nuisances.”  Backdoors have recently become enormously popular within the hacker community because of their ability to surreptitiously enter a user’s PC and gather data.  Like its many cousins, Win32.Shah will enter unannounced and will embed itself into [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Backdoor, Win32.Shah, is named after the Persian word for king but it may be aptly named “king of nuisances.”  Backdoors have recently become enormously popular within the hacker community because of their ability to surreptitiously enter a user’s PC and gather data.  Like its many cousins, Win32.Shah will enter unannounced and will embed itself into the PC’s directories using random names in order to avoid detection.  It will also open a port that sallows other malware to enter quite easy and accessible.</p>
<p style="text-align: justify;">
<p style="text-align: justify;"><span id="more-9307"></span></p>
<p style="text-align: justify;"><strong>AKA: </strong><br />
Backdoor.Win32.Shah.10.B<br />
Troj/Shah.10-B<br />
Backdoor.Shah.10.B,<br />
BKDR_SHAH.10.B<br />
Win32/Shah.10.B<br />
Shah.10.B Backdoor<br />
Backdoor:Win32/Shah.1_<br />
Backdoor:Win32/Shah.1_0B<br />
Backdoor:Win32/Shah.A<br />
Backdoor:Win32/Shah.B</p>
<p style="text-align: justify;"><strong>Related Files: </strong><br />
N/A<br />
<strong><br />
Category: </strong><br />
Backdoor Trojan</p>
<p><strong>Recommended Action: </strong><br />
Remove at once.</p>
<p style="text-align: justify;">In order to remove Win32.Shah manually, you must kill all running processes, terminate all registry entries and delete all remaining files.  If even one file is left behind, Win32.Shah will resurface and all your effort will be for naught.  To be sure this pest is gone you can use an automatic remover like SpyZooka.  SpyZooka is a trusted anti-spyware application that promises around the clock protection against spyware.  SpyZooka can easily eliminate this threat and will keep you secure from new threats.  With SpyZooka on your side, you’re always protected.</p>
]]></content:encoded>
			<wfw:commentRss>http://bluepenguinsoftware.com/spyzooka/blog/shah-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SpyZooka Gets New Spyware Directory</title>
		<link>http://bluepenguinsoftware.com/spyzooka/blog/spyzooka-gets-new-spyware-directory/</link>
		<comments>http://bluepenguinsoftware.com/spyzooka/blog/spyzooka-gets-new-spyware-directory/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 03:26:26 +0000</pubDate>
		<dc:creator>bluepenguin15</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[spyware database]]></category>
		<category><![CDATA[SPYWARE DIRECTORY]]></category>

		<guid isPermaLink="false">http://bluepenguinsoftware.com/spyzooka/blog/?p=9722</guid>
		<description><![CDATA[SUMMARY: BluePenguin Software announces new spyware directory for SpyZooka. SpyZooka’s new spyware directory integrates knowledge, assessments and solutions providing superior spyware protection.
Sequim, WA – BluePenguin Software announces new spyware directory for SpyZooka. SpyZooka’s new spyware directory integrates knowledge, assessments and solutions providing superior spyware protection. “Spyware can infiltrate computers to garner personal information, track activities [...]]]></description>
			<content:encoded><![CDATA[<p>SUMMARY: BluePenguin Software announces new spyware directory for SpyZooka. SpyZooka’s new spyware directory integrates knowledge, assessments and solutions providing superior spyware protection.</p>
<p>Sequim, WA – BluePenguin Software announces new spyware directory for SpyZooka. SpyZooka’s new spyware directory integrates knowledge, assessments and solutions providing superior spyware protection. “Spyware can infiltrate computers to garner personal information, track activities and rack up charges,” says Carl Haugen, president and founder of BluePenguin Software. “SpyZooka’s new spyware directory identifies types of spyware and offers a solution to rid a computer of that spyware.”</p>
<p>Spyware enters computers without a visual trace and can take information stored on the computer, track internet visits and even hijack dial-up systems causing them to rack up hundreds of dollars in calls to 900 numbers. Hackers can take control of computers through spyware.</p>
<p>SpyZooka’s spyware directory was created for ease of use. Set up alphabetically by spyware, each category then provides a list of manufacturers. Histories are given including dates the spyware were developed, if they are still active or if they are defunct. A rating on a scale of 1-100 advises of the severity of the virus.</p>
<p>Spyware can enter a computer through email, shared printers and computers and faulty URLs. SpyZooka’s spyware directory identifies existing problems through a free computer scan and has ready solutions on hand if a computer has been infected.</p>
<p>A few of the viruses discussed in the spyware directory are Adware, Backdoor, Trojan, Dialer, Keylogger, Rogue and more. The results of these viruses can be destructive and disastrous.</p>
<p>“SpyZooka’s spyware directory was developed in order to put control back with computer owners,” says Carl Haugen of BluePenguin. “We wanted to create something that was intuitive to use and that wasn’t filled with computer jargon. Our directory is easy to navigate and speaks in layman’s terms so anyone can understand it.”</p>
<p>Contact: Carl D. Haugen III, CdO, HsD<br />
Company: BluePenguin Software, Inc<br />
www.BluePenguinSoftware.com<br />
Phone: 561-459-5393<br />
Email: press@bluepenguinsoftware.com</p>
]]></content:encoded>
			<wfw:commentRss>http://bluepenguinsoftware.com/spyzooka/blog/spyzooka-gets-new-spyware-directory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32.ShadowPhyre RAT</title>
		<link>http://bluepenguinsoftware.com/spyzooka/blog/shadowphyre-rat/</link>
		<comments>http://bluepenguinsoftware.com/spyzooka/blog/shadowphyre-rat/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 09:00:26 +0000</pubDate>
		<dc:creator>Carl Haugen</dc:creator>
				<category><![CDATA[Backdoor Trojan]]></category>
		<category><![CDATA[ShadowPhyre]]></category>
		<category><![CDATA[Win32.ShadowPhyre]]></category>
		<category><![CDATA[Win32ShadowPhyre]]></category>

		<guid isPermaLink="false">http://bluepenguinsoftware.com/spyzooka/blog/?p=9304</guid>
		<description><![CDATA[RAT or Remote Administration Tool, Win32.ShadowPhyre, is brought to us by hacker, Dark-Mentor.  This pest also falls under the category of a backdoor Trojan.  Hackers will send these backdoor Trojans on a bit of a reconnaissance mission that will only make it easier for the hacker to enter when it sees fit.  The hacker and [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">RAT or Remote Administration Tool, Win32.ShadowPhyre, is brought to us by hacker, Dark-Mentor.  This pest also falls under the category of a backdoor Trojan.  Hackers will send these backdoor Trojans on a bit of a reconnaissance mission that will only make it easier for the hacker to enter when it sees fit.  The hacker and the backdoor will communicate and instructions will be given.  Eventually, the hacker will assume full control of your PC if not removed promptly.</p>
<p style="text-align: justify;">
<p style="text-align: justify;"><span id="more-9304"></span></p>
<p style="text-align: justify;"><strong>AKA: </strong><br />
Troj/ShadowPhyre-A<br />
Backdoor.ShadowPhyre.A<br />
BKDR_SHADOWPHYRE.A<br />
Win32/ShadowPhyre.A<br />
ShadowPhyre.A Backdoor<br />
Backdoor.Win32.ShadowPhyre.b<br />
Backdoor.ShadowPhyre.b<br />
BackDoor-GE<br />
BackDoor.ShPhyre<br />
Troj/ShadowP-B<br />
Backdoor:Win32/ShadowPhyre.B<br />
BKDR_SHADOW.A<br />
TR/ShadowPhyreB.Cli<br />
Win32:Trojan-gen.<br />
BackDoor.ShadowPhyre<br />
Backdoor.ShadowPhyre.B<br />
Trojan.ShadowPhyre.B<br />
Trj/ShadowPhyre2.Cl<br />
Win32/Shadow<strong> </strong></p>
<p style="text-align: justify;"><strong>Related Files: </strong><br />
readme.doc<br />
shadow.exe<br />
trance.exe<strong></strong></p>
<p style="text-align: justify;"><strong>Category: </strong><br />
RAT<br />
Backdoor<strong></strong></p>
<p style="text-align: justify;"><strong>Recommended Action: </strong><br />
Remove at once.</p>
<p style="text-align: justify;">Win32.ShadowPhyre can be removed but not without difficulty.  To do so, you must kill the following processes:<br />
shadow.exe, trance.exe</p>
<p style="text-align: justify;">Then, remove the following files<br />
readme.doc, shadow.exe, trance.exe.</p>
<p style="text-align: justify;">If this does not work, you may need a stronger solution.  That can be found in none other than SpyZooka.  SpyZooka is an automatic spyware remover that changes hours of tedious manual removal into minutes with the simple click of your mouse.  You can save yourself countless hours by investing in SpyZooka’s proprietary system.  To be certain, to be sure, use SpyZooka.</p>
]]></content:encoded>
			<wfw:commentRss>http://bluepenguinsoftware.com/spyzooka/blog/shadowphyre-rat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32.Shadow Trojan</title>
		<link>http://bluepenguinsoftware.com/spyzooka/blog/shadow-trojan/</link>
		<comments>http://bluepenguinsoftware.com/spyzooka/blog/shadow-trojan/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 14:00:14 +0000</pubDate>
		<dc:creator>Carl Haugen</dc:creator>
				<category><![CDATA[Backdoor Trojan]]></category>
		<category><![CDATA[Shadow]]></category>
		<category><![CDATA[Win32.Shadow]]></category>
		<category><![CDATA[Win32Shadow]]></category>

		<guid isPermaLink="false">http://bluepenguinsoftware.com/spyzooka/blog/?p=9301</guid>
		<description><![CDATA[This dangerous program, Win32.Shadow, has a variety of functions depending on the needs of the attacker.  It can be an e-mail flooder, which means it will clog a network or your PC by sending out massive quantities of e-mails.
You can also find it spamming from your PC.  It is able to do this by gaining [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">This dangerous program, Win32.Shadow, has a variety of functions depending on the needs of the attacker.  It can be an e-mail flooder, which means it will clog a network or your PC by sending out massive quantities of e-mails.</p>
<p style="text-align: justify;">You can also find it spamming from your PC.  It is able to do this by gaining secret access and then will use your account to send out spam e-mails to countless unsuspecting users.  It is also a backdoor so if entry is gained, it will open up a port on your PC and leave you vulnerable to other malicious attacks.</p>
<p style="text-align: justify;">
<p style="text-align: justify;"><span id="more-9301"></span></p>
<p style="text-align: justify;"><strong>AKA: </strong><br />
Spammer:Win32.Shadow<br />
Email-Flooder.Win32.Shadow<br />
Backdoor.Win32.Shadow.d<br />
BDS/Shadow.D.1<br />
Win32.Shadow.aa<br />
Win32/Shadow.G<br />
Troj/Shadow-D<br />
Backdoor.Shadow.D<br />
BKDR_SHADOW.D<br />
Win32/Shadow.D<br />
Shadow.D Backdoor<strong> </strong></p>
<p style="text-align: justify;"><strong>Threat type: </strong><br />
Backdoor Trojan</p>
<p><strong>Related Files: </strong><br />
N/A<strong></strong></p>
<p style="text-align: justify;"><strong>Category: </strong><br />
Trojan<strong></strong></p>
<p style="text-align: justify;"><strong>Recommended Action: </strong><br />
Remove at once.</p>
<p style="text-align: justify;">Manually remove this scourge of a program by terminating all processes, files, folders and registry entries.  If this process is confusing to you, you are not alone.  Manual removal is difficult.  For a fast and automatic solution, you have SpyZooka.  SpyZooka can easily rid you of Win32.Shadow and ALL spyware in one fell swoop.  SpyZooka scans, detects and eliminates spyware in an all-in-one system.  An easy-to-use application, you will be protected with SpyZooka.</p>
]]></content:encoded>
			<wfw:commentRss>http://bluepenguinsoftware.com/spyzooka/blog/shadow-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32.ServU-based Trojan</title>
		<link>http://bluepenguinsoftware.com/spyzooka/blog/servu-based-trojan/</link>
		<comments>http://bluepenguinsoftware.com/spyzooka/blog/servu-based-trojan/#comments</comments>
		<pubDate>Sun, 07 Mar 2010 11:00:55 +0000</pubDate>
		<dc:creator>Carl Haugen</dc:creator>
				<category><![CDATA[Backdoor Trojan]]></category>
		<category><![CDATA[ServU-based]]></category>
		<category><![CDATA[Win32.ServU-based]]></category>
		<category><![CDATA[Win32ServU-based]]></category>

		<guid isPermaLink="false">http://bluepenguinsoftware.com/spyzooka/blog/?p=9289</guid>
		<description><![CDATA[Win32.ServU-based is known to be a backdoor Trojan program.  It uses such mediums as e-mail, shareware and freeware sites, Internet Relay Chat and Peer-to-Peer programs to find its way onto your computer.  If you have the misfortune of being infected with this malware, you will encounter such things as an extremely slow computer, possible disabling [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Win32.ServU-based is known to be a backdoor Trojan program.  It uses such mediums as e-mail, shareware and freeware sites, Internet Relay Chat and Peer-to-Peer programs to find its way onto your computer.  If you have the misfortune of being infected with this malware, you will encounter such things as an extremely slow computer, possible disabling of security software and even a complete loss of control of your PC.  Win32.ServU-based gains entry and will open a random port to communicate with its author.  This pest came onto the scene in March of 2005.</p>
<p style="text-align: justify;">
<p style="text-align: justify;"><span id="more-9289"></span></p>
<p style="text-align: justify;"><strong>AKA:</strong><br />
Backdoor.Win32.ServU-based<br />
Backdoor:Win32/ServUbased.AH<br />
Win32.ServU-based.ap<br />
Win32.ServU-based.bj</p>
<p><strong>Related Files: </strong><br />
svchost1.exe</p>
<p><strong>Category: </strong><br />
Backdoor Trojan</p>
<p><strong>Recommended Action: </strong><br />
Remove at once.<br />
To remove Win32.ServU-based manually, you must kill this process:<br />
svchost1.exe</p>
<p style="text-align: justify;">Delete these registry entries:<br />
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ssdpcl<br />
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ssdpcl\0000<br />
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ssdpcl\0000\control<br />
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ssdpcl<br />
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ssdpcl\enum<br />
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ssdpcl\security</p>
<p>Finally, delete this file:<br />
svchost1.exe</p>
<p style="text-align: justify;">If you are interested in protecting your PC from further damage, then you might want to invest in an anti-spyware system that is designed to eliminate spyware but also keep you immunized from further infection.  You need not look further than SpyZooka.   SpyZooka has been eradicating spyware for many years with great success.  Garnering numerous awards and receiving rave reviews from customers, you can’t go wrong with SpyZooka.</p>
]]></content:encoded>
			<wfw:commentRss>http://bluepenguinsoftware.com/spyzooka/blog/servu-based-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32.SevenSphere Trojan</title>
		<link>http://bluepenguinsoftware.com/spyzooka/blog/sevensphere-trojan/</link>
		<comments>http://bluepenguinsoftware.com/spyzooka/blog/sevensphere-trojan/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 11:00:18 +0000</pubDate>
		<dc:creator>Carl Haugen</dc:creator>
				<category><![CDATA[Backdoor Trojan]]></category>
		<category><![CDATA[SevenSphere]]></category>
		<category><![CDATA[Win32.SevenSphere]]></category>
		<category><![CDATA[Win32SevenSphere]]></category>

		<guid isPermaLink="false">http://bluepenguinsoftware.com/spyzooka/blog/?p=9298</guid>
		<description><![CDATA[Author, Precursor, came up with the harmful and malicious program entitled Win32.SevenSphere.  It will enter unannounced and will leave the following fingerprints behind: 7db6c667b9c7595a&#8230;, 96047fd93adee176&#8230;, 36072adc1489e7d7&#8230;, a7a671fe14c57064&#8230;, 7da8ce114a805d3d&#8230;, e984cb69bde4271d.
Thankfully, there are some traces but otherwise these backdoor Trojan programs are very difficult to detect.  Win32.SevenSphere will hide its processes and will often give random names [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Author, Precursor, came up with the harmful and malicious program entitled Win32.SevenSphere.  It will enter unannounced and will leave the following fingerprints behind: 7db6c667b9c7595a&#8230;, 96047fd93adee176&#8230;, 36072adc1489e7d7&#8230;, a7a671fe14c57064&#8230;, 7da8ce114a805d3d&#8230;, e984cb69bde4271d.</p>
<p style="text-align: justify;">Thankfully, there are some traces but otherwise these backdoor Trojan programs are very difficult to detect.  Win32.SevenSphere will hide its processes and will often give random names to files so you are not sure which ones are which.</p>
<p style="text-align: justify;">
<p style="text-align: justify;"><span id="more-9298"></span></p>
<p style="text-align: justify;"><strong>AKA: </strong><br />
Backdoor.SevenSphere.10<br />
Backdoor/SevenSphere.10<br />
BackDoor-ALP.gen<br />
SennaSpy2001,<br />
Win32/SevenSphere.10<br />
Troj/SevenSphere-10<br />
Backdoor.SevenSphere.10<br />
BKDR_SEVENSPHERE.10<br />
Win32/SevenSphere.10<br />
SevenSphere.10 Backdoor</p>
<p><strong>Related Files: </strong><br />
backdoor.sevensphere.10.exe<br />
lh.nfo, sphere 1.0 server.exe.</p>
<p><strong>Category: </strong><br />
Trojan</p>
<p><strong>Recommended Action: </strong><br />
Remove at once.</p>
<p style="text-align: justify;">While manual removal is difficult, it can be done by following the proceeding directions:<br />
Terminate the following processes:<br />
backdoor.sevensphere.10.exe, sphere 1.0 server.exe</p>
<p style="text-align: justify;">Secondly, remove the following files:<br />
backdoor.sevensphere.10.exe, lh.nfo, sphere 1.0 server.exe.</p>
<p style="text-align: justify;">For full and complete protection, however, you can try SpyZooka.  SpyZooka is an anti-spyware application like no other.  All the features are automated which eliminates hours of tedious manual removal.  Not only will it remove Win32.SevenSphere, it will eradicate any other spyware programs you might have.  Spyware removal was never so easy.  You can try SpyZooka without any risk.  With its unprecedented 100% spyware removal guarantee, you can feel totally secure in knowing you are getting the best product out there.</p>
]]></content:encoded>
			<wfw:commentRss>http://bluepenguinsoftware.com/spyzooka/blog/sevensphere-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32.Servudoor Trojan</title>
		<link>http://bluepenguinsoftware.com/spyzooka/blog/servudoor-trojan/</link>
		<comments>http://bluepenguinsoftware.com/spyzooka/blog/servudoor-trojan/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 09:00:17 +0000</pubDate>
		<dc:creator>Carl Haugen</dc:creator>
				<category><![CDATA[Backdoor Trojan]]></category>
		<category><![CDATA[Servudoor]]></category>
		<category><![CDATA[Win32.Servudoor]]></category>
		<category><![CDATA[Win32Servudoor]]></category>

		<guid isPermaLink="false">http://bluepenguinsoftware.com/spyzooka/blog/?p=9295</guid>
		<description><![CDATA[Unintentionally installing Win32.Servudoor is the typical mode of circulation for this backdoor pest.  Win32.Servudoor is found bundled with that is downloaded via shareware or freeware sites.  Once this nuisance has gained entry it will open a port (hence its name “backdoor”) and allow a third party to enter.  It will also have the capability of [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Unintentionally installing Win32.Servudoor is the typical mode of circulation for this backdoor pest.  Win32.Servudoor is found bundled with that is downloaded via shareware or freeware sites.  Once this nuisance has gained entry it will open a port (hence its name “backdoor”) and allow a third party to enter.  It will also have the capability of sending and receiving e-mails, changing or deleting files, launching applications and so on.  Having the run of your PC is precisely what this malware is looking for.</p>
<p style="text-align: justify;">
<p style="text-align: justify;"><span id="more-9295"></span></p>
<p style="text-align: justify;"><strong>AKA: </strong><br />
Win32.Servudoor.C,<br />
Backdoor:Win32/Servudoor.I<br />
Backdoor:Win32/Servudoor.AR<br />
Backdoor.Win32.Servudoor.ba<br />
Backdoor:Win32/Servudoor.X<br />
Backdoor:Win32/Servudoor.H<br />
Win32/Servudoor.si</p>
<p><strong>Related Files: </strong><br />
N/A</p>
<p><strong>Category: </strong><br />
Trojan<br />
<strong><br />
Recommended Action: </strong><br />
Remove at once.</p>
<p style="text-align: justify;">Removing Win32.Servudoor manually takes a certain amount of tech savvy.  If you are comfortable and knowledgeable about how this program works then do the following:</p>
<p style="text-align: justify;">Kill this process:<br />
info.exe</p>
<p style="text-align: justify;">Then remove this file:<br />
info.exe, lol.bat.</p>
<p style="text-align: justify;">Many people are unfamiliar with manual removal.  It does have inherent risk.  One false move can render your PC useless.  To save your time and sanity, you can try SpyZooka.  SpyZooka is not only an award-winning anti-spyware application; it is the only program in the business that offers a 100% guarantee on spyware removal. Now, THAT is something you can count on.</p>
]]></content:encoded>
			<wfw:commentRss>http://bluepenguinsoftware.com/spyzooka/blog/servudoor-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
