<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>Remove-Malware.com &#187; Malware</title> <atom:link href="http://remove-malware.com/category/malware/feed/" rel="self" type="application/rss+xml" /><link>http://remove-malware.com</link> <description>Antivirus Reviews For 2011 / 2012, Tools and How To&#039;s</description> <lastBuildDate>Thu, 09 Feb 2012 14:29:19 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>Rootkit Zero Access Removal Notes</title><link>http://remove-malware.com/malware/rootkits/rootkit-zero-access-max-notes/</link> <comments>http://remove-malware.com/malware/rootkits/rootkit-zero-access-max-notes/#comments</comments> <pubDate>Tue, 27 Dec 2011 15:51:05 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[rootkits]]></category> <category><![CDATA[max++ removal]]></category> <category><![CDATA[rootkit zero access]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=3274</guid> <description><![CDATA[<p>This post is split up in a few sections.  It&#8217;s mostly my notes on dealing with rootkit zero access (a.k.a &#8211; rootkit.zeroacess, w32/Sirefef or Max++) Methods of Infection for Rootkit Zero Access (max++) Outdated Java (this seems to be the #1 way) .exe&#8217;s that have random porn type names.  They are made to look like [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/rootkits/rootkit-zero-access-max-notes/">Rootkit Zero Access Removal Notes</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/rootkits/rootkit-zero-access-max-notes/feed/</wfw:commentRss> <slash:comments>30</slash:comments> </item> <item><title>TDL4 Rootkit Video &#8211; Being Used as a Proxy</title><link>http://remove-malware.com/malware/rootkits/tdl4-rootkit-video-being-used-as-a-proxy/</link> <comments>http://remove-malware.com/malware/rootkits/tdl4-rootkit-video-being-used-as-a-proxy/#comments</comments> <pubDate>Tue, 12 Jul 2011 15:44:34 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[rootkits]]></category> <category><![CDATA[tdl4 rootkit]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=2807</guid> <description><![CDATA[<p>In this video you get to see how the TDL4 rootkit uses your PC as a proxy server.  The tools used in this video are Comodo Cleaning Essentials and the Windows Task Manager. &#160;</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/rootkits/tdl4-rootkit-video-being-used-as-a-proxy/">TDL4 Rootkit Video &#8211; Being Used as a Proxy</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/rootkits/tdl4-rootkit-video-being-used-as-a-proxy/feed/</wfw:commentRss> <slash:comments>54</slash:comments> </item> <item><title>Searching Online Whitepages Often Leads To Rogue Antivirus&#8230;or Worse</title><link>http://remove-malware.com/malware/malware-warnings/searching-online-whitepages-often-leads-to-rogue-antivirus-or-worse/</link> <comments>http://remove-malware.com/malware/malware-warnings/searching-online-whitepages-often-leads-to-rogue-antivirus-or-worse/#comments</comments> <pubDate>Tue, 07 Dec 2010 20:02:27 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[Malware Warnings]]></category> <category><![CDATA[fake anti-virus]]></category> <category><![CDATA[malware]]></category> <category><![CDATA[rogue anti-virus]]></category> <category><![CDATA[white pages]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=2461</guid> <description><![CDATA[<p
style="float:right; margin:0 0 10px 15px; width:240px;"> <img
src="http://remove-malware.com/wp-content/uploads/2010/12/whitepages_111110.jpg" width="240" /></p><p>I&#8217;m often curious on how my clients become infected.  What websites they visited, what they were searching for and of course what kind of protection they had on their computer.   After taking notes for a month it seams that 75% of the clients infected with rogue (fake) anti-virus first observed the rogues infecting their [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/malware-warnings/searching-online-whitepages-often-leads-to-rogue-antivirus-or-worse/">Searching Online Whitepages Often Leads To Rogue Antivirus&#8230;or Worse</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/malware-warnings/searching-online-whitepages-often-leads-to-rogue-antivirus-or-worse/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>How the TLD4 Rootkit Bypasses Driver Signing on Windows 64-bit</title><link>http://remove-malware.com/malware/malware-news/how-the-tld4-rootkit-bypass-driver-signing-on-windows-64-bit/</link> <comments>http://remove-malware.com/malware/malware-news/how-the-tld4-rootkit-bypass-driver-signing-on-windows-64-bit/#comments</comments> <pubDate>Mon, 15 Nov 2010 18:41:58 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[Malware News]]></category> <category><![CDATA[64-bit]]></category> <category><![CDATA[rootkit]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=2436</guid> <description><![CDATA[<p>Per the Sunbelt Blog: Microsoft’s Windows operating system, running on a 64-bit machine provides enhanced security with driver signing of system and low level drivers. This policy, called the kernel mode code signing policy, disallows any unauthorized or malicious driver to be loaded [1]. The TDL4 rootkit bypasses driver signing policy on 64-bit machines by [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/malware-news/how-the-tld4-rootkit-bypass-driver-signing-on-windows-64-bit/">How the TLD4 Rootkit Bypasses Driver Signing on Windows 64-bit</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/malware-news/how-the-tld4-rootkit-bypass-driver-signing-on-windows-64-bit/feed/</wfw:commentRss> <slash:comments>14</slash:comments> </item> <item><title>Kaspersky Website Serves Up Malware</title><link>http://remove-malware.com/malware/malware-news/kaspersky-website-serves-up-malware/</link> <comments>http://remove-malware.com/malware/malware-news/kaspersky-website-serves-up-malware/#comments</comments> <pubDate>Wed, 20 Oct 2010 17:32:41 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[Malware News]]></category> <category><![CDATA[first reaction]]></category> <category><![CDATA[national security]]></category> <category><![CDATA[security firm]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=2412</guid> <description><![CDATA[<p>My first reaction to this was&#8230;.&#8221;oooooo&#8230;.that&#8217;s bad&#8221;.  Anyway, check out the article. http://www.examiner.com/technology-in-national/security-firm-kaspersky-serves-up-malware-from-its-site</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/malware-news/kaspersky-website-serves-up-malware/">Kaspersky Website Serves Up Malware</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/malware-news/kaspersky-website-serves-up-malware/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Combofix Not As Effective As It Once Was</title><link>http://remove-malware.com/malware/malware-notes/combofix-not-as-effective-as-it-once-was/</link> <comments>http://remove-malware.com/malware/malware-notes/combofix-not-as-effective-as-it-once-was/#comments</comments> <pubDate>Sat, 06 Feb 2010 22:51:12 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[Malware Notes]]></category> <category><![CDATA[same time period]]></category> <category><![CDATA[waste of time]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=1990</guid> <description><![CDATA[<p>I don&#8217;t know if anyone else has noticed but for the last 2-3 weeks Combofix has been more or less&#8230;.a waste of time, in fact I just had to resort to my UBCD4Win on every malware appointment.  The latest round of rootkits seem to be evading it rather well. Also, I&#8217;ve really had to rely [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/malware-notes/combofix-not-as-effective-as-it-once-was/">Combofix Not As Effective As It Once Was</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/malware-notes/combofix-not-as-effective-as-it-once-was/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Microsoft Security Essentials &#8211; Rootkit Followup Video</title><link>http://remove-malware.com/malware/rootkits/microsoft-security-essentials-rootkit-followup-video/</link> <comments>http://remove-malware.com/malware/rootkits/microsoft-security-essentials-rootkit-followup-video/#comments</comments> <pubDate>Thu, 10 Dec 2009 18:07:16 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[rootkits]]></category> <category><![CDATA[Video Reviews]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[security essentials]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=1953</guid> <description><![CDATA[<p>In this followup video to the Microsoft Security Detection and Removal tests video I show you what rootkit was present on the PC, what apps couldn&#8217;t even detect it and what finally removed it. http://www.youtube.com/watch?v=aRfnBjTCG4I</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/rootkits/microsoft-security-essentials-rootkit-followup-video/">Microsoft Security Essentials &#8211; Rootkit Followup Video</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/rootkits/microsoft-security-essentials-rootkit-followup-video/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Atapi.sys Rootkit is EVERYWHERE!</title><link>http://remove-malware.com/malware/malware-news/atapi-sys-rootkit-is-everywhere/</link> <comments>http://remove-malware.com/malware/malware-news/atapi-sys-rootkit-is-everywhere/#comments</comments> <pubDate>Tue, 08 Dec 2009 03:09:48 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[Malware News]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[Microsoft Windows]]></category> <category><![CDATA[operating systems]]></category> <category><![CDATA[windows xp]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=1950</guid> <description><![CDATA[<p>Man&#8230;every client I&#8217;ve seen for the past 2 weeks who was infected with malware also had this Atapi.sys rootkit.  I know I&#8217;ve written about this about 2 weeks ago, but I wanted to keep this fresh.  If you&#8217;re searches are getting redirected and you&#8217;ve scanned with just about every thing you can think of then [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/malware-news/atapi-sys-rootkit-is-everywhere/">Atapi.sys Rootkit is EVERYWHERE!</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/malware-news/atapi-sys-rootkit-is-everywhere/feed/</wfw:commentRss> <slash:comments>22</slash:comments> </item> <item><title>Black Screen Of Death Caused By Trojan:Win32/Daonol</title><link>http://remove-malware.com/malware/malware-news/black-screen-of-death-caused-by-trojanwin32daonol/</link> <comments>http://remove-malware.com/malware/malware-news/black-screen-of-death-caused-by-trojanwin32daonol/#comments</comments> <pubDate>Wed, 02 Dec 2009 15:01:35 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[Malware News]]></category> <category><![CDATA[anti malware]]></category> <category><![CDATA[latest versions]]></category> <category><![CDATA[trojan win32]]></category> <category><![CDATA[windows updates]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=1947</guid> <description><![CDATA[<p>I&#8217;ve seen a lot of reports that users are experiencing a black screen of death when some Windows updates are applied. Windows updates do NOT cause the black screen of death, however malware already present on the PC does, specifically Trojan:Win32/Daonol (which is an info stealer/redirector). The latest versions of Trojan:Win32/Daonol are very buggy and [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/malware-news/black-screen-of-death-caused-by-trojanwin32daonol/">Black Screen Of Death Caused By Trojan:Win32/Daonol</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/malware-news/black-screen-of-death-caused-by-trojanwin32daonol/feed/</wfw:commentRss> <slash:comments>13</slash:comments> </item> <item><title>Nasty New Rootkit Patches Atapi.sys</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/</link> <comments>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comments</comments> <pubDate>Mon, 16 Nov 2009 18:55:16 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[Malware Warnings]]></category> <category><![CDATA[anti malware]]></category> <category><![CDATA[atapi.sys driver]]></category> <category><![CDATA[new rootkit]]></category> <category><![CDATA[spyware doctor]]></category> <category><![CDATA[system32 directory]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=1930</guid> <description><![CDATA[<p
style="float:right; margin:0 0 10px 15px; width:240px;"> <img
src="http://remove-malware.com/wp-content/uploads/2009/11/combofix-rootkit2.png" width="240" /></p><p>For the past 7 days I&#8217;ve been seeing a new rootkit (not sure of the name) that patches the atapi.sys driver.  This rootkit was NOT detected by any of the applications I use in my bootable anti-malware toolkit. Full scans with: Avira SAS MBAM Spyware Doctor GMER revealed nothing.  I was still getting all searches [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/">Nasty New Rootkit Patches Atapi.sys</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/feed/</wfw:commentRss> <slash:comments>35</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)
Database Caching 26/85 queries in 0.046 seconds using disk: basic
Object Caching 1805/1933 objects using disk: basic

Served from: remove-malware.com @ 2012-02-09 22:36:11 -->
