<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>Remove-Malware.com &#187; rootkits</title> <atom:link href="http://remove-malware.com/category/malware/rootkits/feed/" rel="self" type="application/rss+xml" /><link>http://remove-malware.com</link> <description>Antivirus Reviews For 2011 / 2012, Tools and How To&#039;s</description> <lastBuildDate>Thu, 09 Feb 2012 14:29:19 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>Rootkit Zero Access Removal Notes</title><link>http://remove-malware.com/malware/rootkits/rootkit-zero-access-max-notes/</link> <comments>http://remove-malware.com/malware/rootkits/rootkit-zero-access-max-notes/#comments</comments> <pubDate>Tue, 27 Dec 2011 15:51:05 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[rootkits]]></category> <category><![CDATA[max++ removal]]></category> <category><![CDATA[rootkit zero access]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=3274</guid> <description><![CDATA[<p>This post is split up in a few sections.  It&#8217;s mostly my notes on dealing with rootkit zero access (a.k.a &#8211; rootkit.zeroacess, w32/Sirefef or Max++) Methods of Infection for Rootkit Zero Access (max++) Outdated Java (this seems to be the #1 way) .exe&#8217;s that have random porn type names.  They are made to look like [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/rootkits/rootkit-zero-access-max-notes/">Rootkit Zero Access Removal Notes</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/rootkits/rootkit-zero-access-max-notes/feed/</wfw:commentRss> <slash:comments>30</slash:comments> </item> <item><title>TDL4 Rootkit Video &#8211; Being Used as a Proxy</title><link>http://remove-malware.com/malware/rootkits/tdl4-rootkit-video-being-used-as-a-proxy/</link> <comments>http://remove-malware.com/malware/rootkits/tdl4-rootkit-video-being-used-as-a-proxy/#comments</comments> <pubDate>Tue, 12 Jul 2011 15:44:34 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[rootkits]]></category> <category><![CDATA[tdl4 rootkit]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=2807</guid> <description><![CDATA[<p>In this video you get to see how the TDL4 rootkit uses your PC as a proxy server.  The tools used in this video are Comodo Cleaning Essentials and the Windows Task Manager. &#160;</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/rootkits/tdl4-rootkit-video-being-used-as-a-proxy/">TDL4 Rootkit Video &#8211; Being Used as a Proxy</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/rootkits/tdl4-rootkit-video-being-used-as-a-proxy/feed/</wfw:commentRss> <slash:comments>54</slash:comments> </item> <item><title>Microsoft Security Essentials &#8211; Rootkit Followup Video</title><link>http://remove-malware.com/malware/rootkits/microsoft-security-essentials-rootkit-followup-video/</link> <comments>http://remove-malware.com/malware/rootkits/microsoft-security-essentials-rootkit-followup-video/#comments</comments> <pubDate>Thu, 10 Dec 2009 18:07:16 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[rootkits]]></category> <category><![CDATA[Video Reviews]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[security essentials]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=1953</guid> <description><![CDATA[<p>In this followup video to the Microsoft Security Detection and Removal tests video I show you what rootkit was present on the PC, what apps couldn&#8217;t even detect it and what finally removed it. http://www.youtube.com/watch?v=aRfnBjTCG4I</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/rootkits/microsoft-security-essentials-rootkit-followup-video/">Microsoft Security Essentials &#8211; Rootkit Followup Video</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/rootkits/microsoft-security-essentials-rootkit-followup-video/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Skynet Rootkit – When Malware with Movie Names Attack!</title><link>http://remove-malware.com/malware/rootkits/skynet-rootkit-%e2%80%93-when-malware-with-movie-names-attack/</link> <comments>http://remove-malware.com/malware/rootkits/skynet-rootkit-%e2%80%93-when-malware-with-movie-names-attack/#comments</comments> <pubDate>Thu, 13 Aug 2009 14:39:56 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[rootkits]]></category> <category><![CDATA[antivir 9]]></category> <category><![CDATA[avira antivir]]></category> <category><![CDATA[browser redirection]]></category> <category><![CDATA[free versions]]></category> <category><![CDATA[Internet Security]]></category> <category><![CDATA[killing machines]]></category> <category><![CDATA[quick scan]]></category> <category><![CDATA[syntax error]]></category><guid
isPermaLink="false">http://remove-malware.com/uncategorized/skynet-rootkit-%e2%80%93-when-malware-with-movie-names-attack/</guid> <description><![CDATA[<p
style="float:right; margin:0 0 10px 15px; width:240px;"> <img
src="http://remove-malware.com/wp-content/uploads/2009/08/081309_1439_SkynetRootk1.jpg" width="240" /></p><p>No, the global A.I. network of man killing machines from the Terminator movie is not on your computer, it&#8217;s just a browser redirection rootkit. Figure 1 &#8211; The Skynet Rootkit I went over Tom&#8217;s house last night on the report that he couldn&#8217;t run a quick scan with SuperAntiSpyware (his box blue screened with a [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/rootkits/skynet-rootkit-%e2%80%93-when-malware-with-movie-names-attack/">Skynet Rootkit – When Malware with Movie Names Attack!</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/rootkits/skynet-rootkit-%e2%80%93-when-malware-with-movie-names-attack/feed/</wfw:commentRss> <slash:comments>19</slash:comments> </item> <item><title>Free Rootkit Removal Programs</title><link>http://remove-malware.com/antimalware/anti-malware-howto/free-rootkit-removal-steps/</link> <comments>http://remove-malware.com/antimalware/anti-malware-howto/free-rootkit-removal-steps/#comments</comments> <pubDate>Tue, 07 Jul 2009 14:27:06 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[Anti-Malware HowTo]]></category> <category><![CDATA[rootkits]]></category> <category><![CDATA[bootable antivirus]]></category> <category><![CDATA[free rootkit removal]]></category> <category><![CDATA[rescue cd]]></category> <category><![CDATA[system32 folder]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=1549</guid> <description><![CDATA[<p>This is a quick post on free rootkit removal.  I get 5-10 emails a day on how to remove rootkits,  so I&#8217;m hoping this will answer a few of those. Rootkits can be removed for free with: 1.  A Bootable AntiVirus Disc (like the Avira free rescue cd). Rootkits reside in the system32 folder, so [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/antimalware/anti-malware-howto/free-rootkit-removal-steps/">Free Rootkit Removal Programs</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/antimalware/anti-malware-howto/free-rootkit-removal-steps/feed/</wfw:commentRss> <slash:comments>15</slash:comments> </item> <item><title>New Generation of Rogue Antivirus Prevent Browsing</title><link>http://remove-malware.com/antimalware/rogue-anti-malware/new-generation-of-rogue-antivirus-prevent-browsing/</link> <comments>http://remove-malware.com/antimalware/rogue-anti-malware/new-generation-of-rogue-antivirus-prevent-browsing/#comments</comments> <pubDate>Fri, 13 Feb 2009 21:00:00 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[Anti-Malware HowTo]]></category> <category><![CDATA[Anti-Malware News]]></category> <category><![CDATA[Anti-Malware Tools]]></category> <category><![CDATA[Rogue Anti-Malware]]></category> <category><![CDATA[rootkits]]></category> <category><![CDATA[antivirus program]]></category> <category><![CDATA[new generation]]></category> <category><![CDATA[search engine]]></category> <category><![CDATA[search engine queries]]></category> <category><![CDATA[url navigation]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=1141</guid> <description><![CDATA[<p
style="float:right; margin:0 0 10px 15px; width:240px;"> <img
src="http://remove-malware.com/wp-content/uploads/2009/02/spyware-protect.jpg" width="240" /></p><p>As you can see by the screen shot below, a rogue antivirus program called Spyware Protect 2009 has blocked my attempt to browse the internet either by direct URL navigation or via search engine queries.  Spyware Protect 2009 is just one example, I&#8217;ve seen over a dozen rogues that come bundled with TDSSERV rootkits (the [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/antimalware/rogue-anti-malware/new-generation-of-rogue-antivirus-prevent-browsing/">New Generation of Rogue Antivirus Prevent Browsing</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/antimalware/rogue-anti-malware/new-generation-of-rogue-antivirus-prevent-browsing/feed/</wfw:commentRss> <slash:comments>19</slash:comments> </item> <item><title>Malware Customer Call &#8211; Notes from a real appointment</title><link>http://remove-malware.com/malware/rootkits/malware-customer-call-notes-from-a-real-appointment/</link> <comments>http://remove-malware.com/malware/rootkits/malware-customer-call-notes-from-a-real-appointment/#comments</comments> <pubDate>Wed, 19 Nov 2008 17:58:24 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[rootkits]]></category> <category><![CDATA[blank desktop]]></category> <category><![CDATA[documents and settings]]></category> <category><![CDATA[dozen pieces]]></category> <category><![CDATA[Microsoft Windows]]></category> <category><![CDATA[real time]]></category> <category><![CDATA[security product]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=637</guid> <description><![CDATA[<p>Ms Hager: &#8220;Hi Matt,  my computer is giving me a little fit&#8230;I don&#8217;t know what my husband has been doing&#8221; Matt: &#8220;What&#8217;cha got going on?&#8221; Ms Hager: &#8220;Well, when I turn the computer on I either get a blank desktop or a big alert saying my antivirus is not registered&#8221; I&#8217;m thinking it&#8217;s malware or [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/rootkits/malware-customer-call-notes-from-a-real-appointment/">Malware Customer Call &#8211; Notes from a real appointment</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/rootkits/malware-customer-call-notes-from-a-real-appointment/feed/</wfw:commentRss> <slash:comments>19</slash:comments> </item> <item><title>GMER Anti-RootKit:  I don’t leave home without it!</title><link>http://remove-malware.com/antimalware/my-tools/gmer-anti-rootkit-i-don%e2%80%99t-leave-home-without-it/</link> <comments>http://remove-malware.com/antimalware/my-tools/gmer-anti-rootkit-i-don%e2%80%99t-leave-home-without-it/#comments</comments> <pubDate>Wed, 29 Oct 2008 15:04:19 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[My Tools]]></category> <category><![CDATA[rootkits]]></category> <category><![CDATA[anti rootkit]]></category><guid
isPermaLink="false">http://remove-malware.com/uncategorized/gmer-anti-rootkit-i-don%e2%80%99t-leave-home-without-it/</guid> <description><![CDATA[<p
style="float:right; margin:0 0 10px 15px; width:240px;"> <img
src="http://remove-malware.com/wp-content/uploads/2008/10/102908-1504-gmerantiroo1.png" width="240" /></p><p>I&#8217;ve had about a dozen calls this week involving some nasty rootkits (TDSSERVE, TDSsycte, WinIK.sys). GMER Anti-Rootkit has quickly and effectively deleted or disabled any rootkit that it finds (usually in under 5 minutes). GMER AntiRootkit is FREE btw! Download it today and run a scan if you have been recently infected. Anything that comes [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/antimalware/my-tools/gmer-anti-rootkit-i-don%e2%80%99t-leave-home-without-it/">GMER Anti-RootKit:  I don’t leave home without it!</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/antimalware/my-tools/gmer-anti-rootkit-i-don%e2%80%99t-leave-home-without-it/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>rootkit.tdsserv/fake &#8211; A Very Annoying RootKit</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/</link> <comments>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comments</comments> <pubDate>Fri, 03 Oct 2008 15:39:47 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[rootkits]]></category> <category><![CDATA[nasty experience]]></category> <category><![CDATA[search engine]]></category> <category><![CDATA[search engine query]]></category> <category><![CDATA[search engine query redirection]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=386</guid> <description><![CDATA[<p>I had a really nasty experience last night with a rootkit only because I forgot my bootable antimalware disc. Root.TDSSERV/FAKE (as identified by SuperAntiSpyware) performs 100% search engine query redirection to go.google which then serves up malvertised websites (like info.com). Once I used my bootable SAS (i had too run home and get my disc) [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/">rootkit.tdsserv/fake &#8211; A Very Annoying RootKit</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/feed/</wfw:commentRss> <slash:comments>16</slash:comments> </item> <item><title>A Weekend Of RootKits:  Figaro.sys Rootkit</title><link>http://remove-malware.com/malware/malware-warnings/a-weekend-of-rootkits-figarosys-rootkit/</link> <comments>http://remove-malware.com/malware/malware-warnings/a-weekend-of-rootkits-figarosys-rootkit/#comments</comments> <pubDate>Sat, 23 Aug 2008 22:04:23 +0000</pubDate> <dc:creator>malwarekilla</dc:creator> <category><![CDATA[Malware Warnings]]></category> <category><![CDATA[rootkits]]></category> <category><![CDATA[removal utility]]></category><guid
isPermaLink="false">http://remove-malware.com/?p=236</guid> <description><![CDATA[<p>I took a few appointments this weekend and witnessed the same infection over and over again&#8230;Figaro.sys. The Figaro.sys rootkit is dropped in c:\windows\system32\drivers (on vista) and on XP i&#8217;ve seen it in the DLLCACHE folder. I don&#8217;t know exactly what it does but I can give you the symptoms: Random reboots Virtumonde drops Very slow [...]</p><p>Thanks for reading the feed for <a
href="http://remove-malware.com">Remove-Malware.com</a> !!!  This post was originally published here: <a
href="http://remove-malware.com/malware/malware-warnings/a-weekend-of-rootkits-figarosys-rootkit/">A Weekend Of RootKits:  Figaro.sys Rootkit</a></p>]]></description> <wfw:commentRss>http://remove-malware.com/malware/malware-warnings/a-weekend-of-rootkits-figarosys-rootkit/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)
Database Caching 26/84 queries in 0.057 seconds using disk: basic
Object Caching 1848/1948 objects using disk: basic

Served from: remove-malware.com @ 2012-02-09 22:51:52 -->
