<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>PCBugSquad</title>
	<atom:link href="http://www.pcbugsquad.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcbugsquad.com</link>
	<description>Your daily stop for the latest computer advice.</description>
	<pubDate>Wed, 20 Aug 2008 00:50:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>How to remove Trace Sweeper</title>
		<link>http://www.pcbugsquad.com/2008/08/how-to-remove-trace-sweeper/</link>
		<comments>http://www.pcbugsquad.com/2008/08/how-to-remove-trace-sweeper/#comments</comments>
		<pubDate>Tue, 19 Aug 2008 21:48:01 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Rogue Anti-Spyware]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[rogue]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=95</guid>
		<description><![CDATA[Trace Sweeper is a rogue privacy software that when run on your computer displays fake an exaggerated results that cannot be removed unless you first purchase the software.  The program is also set to run automatically when your computer starts, which will cause your computer to operate slower and create pop-ups about how you [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;">Trace Sweeper is a rogue privacy software that when run on your computer displays fake an exaggerated results that cannot be removed unless you first purchase the software.  The program is also set to run automatically when your computer starts, which will cause your computer to operate slower and create pop-ups about how you should register the software.</span></p>
<div id="attachment_96" class="wp-caption aligncenter" style="width: 510px"><a href="http://www.pcbugsquad.com/wp-content/uploads/2008/08/trace-sweeper.jpg"><img class="size-full wp-image-96" title="trace-sweeper" src="http://www.pcbugsquad.com/wp-content/uploads/2008/08/trace-sweeper.jpg" alt="Trace Sweeper screen shot" width="500" height="374" /></a><p class="wp-caption-text">Trace Sweeper screen shot</p></div>
<h2><span style="color: #0000ff;">Automatic Removal Method</span></h2>
<p>If you are infected with this malware, then we suggest you use Symantec Antivirus to remove this infection. The current definitions for Symantec Antivirus contains methods of removing this virus.</p>
<p><img style="border-top-width: 0pt; border-left-width: 0pt; border-bottom-width: 0pt; vertical-align: middle; border-right-width: 0pt" src="http://www.pcbugsquad.com/images/download.jpg" alt="Download" /><a href="http://send.onenetworkdirect.net/z/45/CD106753/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/send.onenetworkdirect.net');">Download Symantec Antivirus to scan your computer for free</a></p>
<p align="left"><strong></strong></p>
<h2><span style="color: #0000ff;">Manual Removal Instructions for </span></h2>
<p><strong><span style="text-decoration: underline;">End these processes:</span></strong></p>
<p><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<p><span style="text-decoration: underline;"><strong></strong></span></p>
<blockquote><p>tracesweeper.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>c:\Program Files\Trace Sweeper<br />
c:\Program Files\Trace Sweeper\tracesweeper.exe<br />
c:\Program Files\Trace Sweeper\tracesweeper.url<br />
c:\Program Files\Trace Sweeper\unins000.dat<br />
c:\Program Files\Trace Sweeper\unins000.exe<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Trace Sweeper<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Trace Sweeper\Trace Sweeper on the Web.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Trace Sweeper\Trace Sweeper.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Trace Sweeper\Uninstall Trace Sweeper.lnk</p></blockquote>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys: </span></strong></p>
<p><a href="http://support.microsoft.com/kb/256986" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/support.microsoft.com');">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the <a href="#auto" target="_blank">automated</a> removal method above.</span></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\&#8221;tracesweeper&#8221;<br />
=&#8221;C:\Program Files\Trace Sweeper\tracesweeper.exe&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2008/08/how-to-remove-trace-sweeper/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove the WORM_KOOBFACE.D Facebook worm.</title>
		<link>http://www.pcbugsquad.com/2008/08/how-to-remove-the-worm_koobfaced-facebook-worm/</link>
		<comments>http://www.pcbugsquad.com/2008/08/how-to-remove-the-worm_koobfaced-facebook-worm/#comments</comments>
		<pubDate>Tue, 19 Aug 2008 21:27:43 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Backdoor]]></category>

		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[Worms]]></category>

		<category><![CDATA[facebook]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=93</guid>
		<description><![CDATA[The WORM_KOOBFACE.D worm is malware that spreads itself through the online social site called Facebook.  When a user becomes infected with this worm, it will install a copy of itself as C:\Windows\fbtre6.exe and then further download the following files:

C:\5465465465463.BAT
C:\Windows\fmark2.dat

When fbtre6.exe is run it will display the following message in Windows:
Error installing Codec. Please contact support.
It [...]]]></description>
			<content:encoded><![CDATA[<p>The WORM_KOOBFACE.D worm is malware that spreads itself through the online social site called Facebook.  When a user becomes infected with this worm, it will install a copy of itself as C:\Windows\fbtre6.exe and then further download the following files:</p>
<ul>
<li>C:\5465465465463.BAT</li>
<li>C:\Windows\fmark2.dat</li>
</ul>
<p>When fbtre6.exe is run it will display the following message in Windows:</p>
<blockquote><p>Error installing Codec. Please contact support.</p></blockquote>
<p>It is important to note that this infection will delete itself if it detects that you have not used Facebook.com on the infected computer.  If Facebook cookies are found, though, it will add a link to a location where it can be downloaded in the infected user’s Facebook profile.  It is through these links in infected user’s profiles that the infection spreads.</p>
<p><span style="color: #0000ff;">Automatic Removal Method</span></p>
<p>If you are infected with this malware, then we suggest you use Trend Micro antivirus to remove this infection. It is know to be able to remove this malware and it is included in its current virus definitions.</p>
<p><img style="border-top-width: 0pt; border-left-width: 0pt; border-bottom-width: 0pt; vertical-align: middle; border-right-width: 0pt" src="http://www.pcbugsquad.com/images/download.jpg" alt="Download" /><a href="http://send.onenetworkdirect.net/z/320/CD106753/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/send.onenetworkdirect.net');">Download Trend Micro Antivirus to scan your computer</a></p>
<h2><span style="color: #0000ff;">Manual Removal Instructions for </span></h2>
<p><strong><span style="text-decoration: underline;">End these processes:</span></strong></p>
<p><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>fbtre6.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>C:\Windows\fbtre6.exe<br />
C:\5465465465463.BAT<br />
C:\Windows\fmark2.dat</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys: </span></strong></p>
<p><a href="http://support.microsoft.com/kb/256986" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/support.microsoft.com');">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the <a href="#auto" target="_blank">automated</a> removal method above.</span></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<br />
sysftray = “C:\Windows\fbtre6.exe&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2008/08/how-to-remove-the-worm_koobfaced-facebook-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove the WORM_SOHANAD.DR infection</title>
		<link>http://www.pcbugsquad.com/2008/08/how-to-remove-the-worm_sohanaddr-infection/</link>
		<comments>http://www.pcbugsquad.com/2008/08/how-to-remove-the-worm_sohanaddr-infection/#comments</comments>
		<pubDate>Wed, 13 Aug 2008 21:17:48 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=91</guid>
		<description><![CDATA[The WORM_SOHANAD.DR worm is once that propogates as an attachment to email messages that are spammed by other malware or users.  It is also possible, that this worm can be installed via other malware that download and install it on your computer.  When infected the following files will be created on your computer:

C:\Windows\dc.exe
C:\Windows\SVIQ.EXE
C:\Windows\System\Fun.exe

Once running, the [...]]]></description>
			<content:encoded><![CDATA[<p>The WORM_SOHANAD.DR worm is once that propogates as an attachment to email messages that are spammed by other malware or users.  It is also possible, that this worm can be installed via other malware that download and install it on your computer.  When infected the following files will be created on your computer:</p>
<ul>
<li>C:\Windows\dc.exe</li>
<li>C:\Windows\SVIQ.EXE</li>
<li>C:\Windows\System\Fun.exe</li>
</ul>
<p><span style="color: #0000ff;"><span style="color: #000000;">Once running, the worm will read your Outlook address book and spam all of the addresses in your address book with emails containing the attachments:</span></span></p>
<ul>
<li><span style="color: #0000ff;"><span style="color: #000000;">dc.exe</span></span></li>
<li><span style="color: #0000ff;"><span style="color: #000000;">Fun.exe</span></span></li>
</ul>
<p><span style="color: #0000ff;">Automatic Removal Method</span></p>
<p>If you are infected with this malware, then we suggest you use Trend Micro antivirus to remove this infection. It is know to be able to remove this malware and it is included in its current virus definitions.  A big thumbs up for Trend Micro for being able to remove this infection so quickly.</p>
<p><img style="border-top-width: 0pt; border-left-width: 0pt; border-bottom-width: 0pt; vertical-align: middle; border-right-width: 0pt" src="http://www.pcbugsquad.com/images/download.jpg" alt="Download" /><a href="http://send.onenetworkdirect.net/z/320/CD106753/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/send.onenetworkdirect.net');">Download Trend Micro Antivirus to scan your computer</a></p>
<h2><span style="color: #0000ff;">Manual Removal Instructions for </span></h2>
<p><strong><span style="text-decoration: underline;">End these processes:</span></strong></p>
<p><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>dc.exe<br />
sviq.exe<br />
fun.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>C:\Windows\dc.exe<br />
C:\Windows\SVIQ.EXE<br />
C:\Windows\System\Fun.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys: </span></strong></p>
<p><a href="http://support.microsoft.com/kb/256986" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/support.microsoft.com');">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the <a href="#auto" target="_blank">automated</a> removal method above.</span></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\<br />
CurrentVersion\Run<br />
dc = &#8220;C:\Windows\dc.exe&#8221;<br />
dc2k5 = &#8220;C:\Windows\SVIQ.EXE&#8221;<br />
Fun = &#8220;C:\Windows\System\Fun.exe&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2008/08/how-to-remove-the-worm_sohanaddr-infection/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove TROJ_POPHOT.O and the svchosd.exe infection.</title>
		<link>http://www.pcbugsquad.com/2008/07/how-to-remove-troj_pophoto-and-the-svchosdexe-infection/</link>
		<comments>http://www.pcbugsquad.com/2008/07/how-to-remove-troj_pophoto-and-the-svchosdexe-infection/#comments</comments>
		<pubDate>Wed, 30 Jul 2008 17:10:36 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[removal guide]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=86</guid>
		<description><![CDATA[The TROJ_POPHOT.O Trojan is installed form other malware downloaded off of the Internet.  When run, this Trojan will install the following files on your computer:

    * C:\Windows\System32\inf\scsys16_080725.dll
    * C:\Windows\System32\inf\sppdcrs080725.scr
    * C:\Windows\System32\inf\svchosd.exe
    * C:\Windows\dcbdcatys32_080725a.dll
    * C:\Windows\system\sgcxcxxaspf080725.exe
    * C:\Windows\tawisys.ini ]]></description>
			<content:encoded><![CDATA[<p>The TROJ_POPHOT.O Trojan is installed form other malware downloaded off of the Internet.  When run, this Trojan will install the following files on your computer:</p>
<ul>
<li>C:\Windows\System32\inf\scsys16_080725.dll</li>
<li>C:\Windows\System32\inf\sppdcrs080725.scr</li>
<li>C:\Windows\System32\inf\svchosd.exe</li>
<li>C:\Windows\dcbdcatys32_080725a.dll</li>
<li>C:\Windows\system\sgcxcxxaspf080725.exe</li>
<li>C:\Windows\tawisys.ini</li>
<li>C:\Windows\wftadfi16_080725a.dll</li>
</ul>
<p>The Trojan will also add a registry entry to start itself every time you restart this computer. This registry entry will start C:\Windows\System32\inf\svchosd.exe, which is actually a renamed rundll32.exe, which will be used to load the code found in the wftadfi16_080725a.dll DLL file.</p>
<h2><span style="color: #0000ff;">Automatic Removal Method</span></h2>
<p>If you are infected with this malware, then we suggest you use Trend Micro antivirus to remove this infection. It is know to be able to remove this malware and it is included in its current virus definitions.  A big thumbs up for Trend Micro for being able to remove this infection so quickly.</p>
<p><img style="border-top-width: 0pt; border-left-width: 0pt; border-bottom-width: 0pt; vertical-align: middle; border-right-width: 0pt" src="http://www.pcbugsquad.com/images/download.jpg" alt="Download" /><a href="http://send.onenetworkdirect.net/z/320/CD106753/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/send.onenetworkdirect.net');">Download Trend Micro Antivirus to scan your computer</a></p>
<h2><span style="color: #0000ff;">Manual Removal Instructions for </span></h2>
<p><strong><span style="text-decoration: underline;">End these processes:</span></strong></p>
<p><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>svchosd.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>C:\Windows\System32\inf\scsys16_080725.dll<br />
C:\Windows\System32\inf\sppdcrs080725.scr<br />
C:\Windows\System32\inf\svchosd.exe<br />
C:\Windows\dcbdcatys32_080725a.dll<br />
C:\Windows\system\sgcxcxxaspf080725.exe<br />
C:\Windows\tawisys.ini<br />
C:\Windows\wftadfi16_080725a.dll</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys: </span></strong></p>
<p><a href="http://support.microsoft.com/kb/256986" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/support.microsoft.com');">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the <a href="#auto" target="_blank">automated</a> removal method above.</span></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\<br />
CurrentVersion\policies\Explorer\run<br />
initnyuser = &#8220;%System%\inf\svchosd.exe %WINDOWS%\wftadfi16_080725a.dll tanlt88&#8243;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2008/07/how-to-remove-troj_pophoto-and-the-svchosdexe-infection/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove the Trojan.Proscks.C Malware</title>
		<link>http://www.pcbugsquad.com/2008/07/how-to-remove-the-trojanproscksc-malware/</link>
		<comments>http://www.pcbugsquad.com/2008/07/how-to-remove-the-trojanproscksc-malware/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 16:13:03 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[removal guide]]></category>

		<category><![CDATA[trojans]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/2008/07/how-to-remove-the-trojanproscksc-malware/</guid>
		<description><![CDATA[The Proscks Trojan modifies files on the compromised computer and connects to a remote server. Once infected you will be shown pop-up advertisements on your computer.]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;">The Proscks Trojan modifies files on the compromised computer and connects to a remote server. Once infected you will be shown pop-up advertisements on your computer.</span></p>
<p><span style="font-size: small;">When infected the Trojan.Proscks.C malware will create the following files:</span></p>
<ul>
<li>%Temp%\RarSFX0\IPHOST.DLL</li>
<li>%Temp%\RarSFX0\iphy.dll</li>
<li>%Temp%\RarSFX0\xExe.dll</li>
<li>%Temp%\RarSFX0\loaderSvc.exe</li>
<li>%System%\IPHOST.DLL</li>
<li>%System%\_proxy.dll</li>
<li>%System%\iphy.dll</li>
<li>%System%\fhpatch.dll</li>
<li>%System%\fiplock.dll</li>
<li>%System%\IpSvchostF.dll</li>
<li></li>
</ul>
<p>Next, the Trojan copies the file %System%\svchost.exe to the following location:</p>
<blockquote><p>%System%\[EIGHT RANDOM CHARACTERS]</p></blockquote>
<p>It then modifies %System%\svchost.exe so that the following file is executed every time Windows starts:</p>
<blockquote><p>%System%\IPHOST.DLL</p></blockquote>
<p>The Trojan then downloads a .dll file from a remote location and saves it as %System%\IPHACTION.dll.</p>
<p><span style="color: #0000ff;">Automatic Removal Method</span></p>
<p>If you are infected with this malware, then we suggest you use Symantec Antivirus to remove this infection. The current definitions for Symantec Antivirus contains methods of removing this virus.</p>
<p><img style="border-top-width: 0pt; border-left-width: 0pt; border-bottom-width: 0pt; vertical-align: middle; border-right-width: 0pt" src="http://www.pcbugsquad.com/images/download.jpg" alt="Download" /><a href="http://send.onenetworkdirect.net/z/45/CD106753/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/send.onenetworkdirect.net');">Download Symantec Antivirus to scan your computer for free</a></p>
<p align="left"><strong></strong></p>
<h2><span style="color: #0000ff;">Manual Removal Instructions for </span></h2>
<p><strong><span style="text-decoration: underline;">End these processes:</span></strong></p>
<p><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<p><span style="text-decoration: underline;"><strong></strong></span></p>
<blockquote><p>loaderSvc.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;">Delete these files:</p>
<p></span><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></strong></p>
<blockquote><p>%Temp%\RarSFX0\IPHOST.DLL<br />
%Temp%\RarSFX0\iphy.dll<br />
%Temp%\RarSFX0\xExe.dll<br />
%Temp%\RarSFX0\loaderSvc.exe<br />
%System%\IPHOST.DLL<br />
%System%\_proxy.dll<br />
%System%\iphy.dll<br />
%System%\fhpatch.dll<br />
%System%\fiplock.dll<br />
%System%\IpSvchostF.dll</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2008/07/how-to-remove-the-trojanproscksc-malware/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove Secure Expert Cleaner</title>
		<link>http://www.pcbugsquad.com/2008/07/how-to-remove-secure-expert-cleaner/</link>
		<comments>http://www.pcbugsquad.com/2008/07/how-to-remove-secure-expert-cleaner/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 16:02:44 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Rogue Anti-Spyware]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[removal guide]]></category>

		<category><![CDATA[rogue]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=79</guid>
		<description><![CDATA[Secure Expert Cleaner is a program that states it can make your computer secure by cleaning it of security risks.  Unfortunately, this program does not live up to its name.  Secure Expert Cleaner will scan your computer and list legitimate programs as risks and state that they are dangerous.  Then, in order to remove them, you need to first purchase the software.]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;">Secure Expert Cleaner is a program that states it can make your computer secure by cleaning it of security risks.  Unfortunately, this program does not live up to its name.  Secure Expert Cleaner will scan your computer and list legitimate programs as risks and state that they are dangerous.  Then, in order to remove them, you need to first purchase the software.</span></p>
<p><span style="font-size: small;">This software is a scam and should be avoided as you will only be wasting your money and not actually cleaning your computer.</span></p>
<div id="attachment_80" class="wp-caption aligncenter" style="width: 510px"><a href="http://www.pcbugsquad.com/wp-content/uploads/2008/07/secure-expert-cleaner.jpg"><img class="size-full wp-image-80" title="secure-expert-cleaner" src="http://www.pcbugsquad.com/wp-content/uploads/2008/07/secure-expert-cleaner.jpg" alt="Secure Expert Cleaner" width="500" height="373" /></a><p class="wp-caption-text">Secure Expert Cleaner</p></div>
<p><a name="auto"></a></p>
<h2><span style="color: #0000ff;">Automatic Removal Method</span></h2>
<p>We recommend that you install <a href="http://send.onenetworkdirect.net/z/11953/CD106753/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/send.onenetworkdirect.net');">Spyware Doctor</a> from PCTools in order to remove Secure Expert Cleaner from your computer. Spyware Doctor has an incredible track record for removing and detecting the latest malware.</p>
<p align="left"><img style="border-top-width: 0pt; border-left-width: 0pt; border-bottom-width: 0pt; vertical-align: middle; border-right-width: 0pt" src="http://www.pcbugsquad.com/images/download.jpg" alt="Download" /><a href="http://send.onenetworkdirect.net/z/11953/CD106753/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/send.onenetworkdirect.net');">Download Spyware Doctor to scan your computer for free</a></p>
<p align="left"><strong></strong></p>
<h2><span style="color: #0000ff;">Manual Removal Instructions</span></h2>
<p><strong><span style="text-decoration: underline;">End these processes:</span></strong></p>
<p><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<p><span style="text-decoration: underline;"><strong></strong></span></p>
<blockquote><p>SEC.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>c:\Documents and Settings\All Users\Application Data\SEC<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecureExpertCleaner<br />
&lt;userprofile&gt;\Local Settings\Temp\is-ROV72.tmp<br />
c:\Program Files\SecureExpertCleaner<br />
c:\Program Files\SecureExpertCleaner\Microsoft.VC80.CRT<br />
c:\Documents and Settings\All Users\Desktop\Launch SecureExpertCleaner.lnk<br />
c:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecureExpertCleaner\Launch SecureExpertCleaner.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecureExpertCleaner\Uninstall SecureExpertCleaner.lnk<br />
&lt;userprofile&gt;\Application Data\Microsoft\Internet Explorer\Quick Launch\SecureExpertCleaner.lnk<br />
c:\Program Files\SecureExpertCleaner\mfc80.dll<br />
c:\Program Files\SecureExpertCleaner\Microsoft.VC80.MFC.manifest<br />
c:\Program Files\SecureExpertCleaner\Reminder.exe<br />
c:\Program Files\SecureExpertCleaner\SEC.exe<br />
c:\Program Files\SecureExpertCleaner\SEC.ico<br />
c:\Program Files\SecureExpertCleaner\SEC.xml<br />
c:\Program Files\SecureExpertCleaner\unins.ico<br />
c:\Program Files\SecureExpertCleaner\unins000.dat<br />
c:\Program Files\SecureExpertCleaner\unins000.exe<br />
c:\Program Files\SecureExpertCleaner\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest<br />
c:\Program Files\SecureExpertCleaner\Microsoft.VC80.CRT\msvcp80.dll<br />
c:\Program Files\SecureExpertCleaner\Microsoft.VC80.CRT\msvcr80.dll</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys: </span></strong></p>
<p><a href="http://support.microsoft.com/kb/256986" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/support.microsoft.com');">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the <a href="#auto" target="_blank">automated</a> removal method above.</span><span style="color: #000000;"><br />
</span></p>
<blockquote><p>HKEY_CURRENT_USER\Software\SEC<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\3P_USEC_is1<br />
HKEY_LOCAL_MACHINE\SOFTWARE\SEC</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2008/07/how-to-remove-secure-expert-cleaner/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove the desktop.sysm or W32.Azero.A infection</title>
		<link>http://www.pcbugsquad.com/2008/07/how-to-remove-the-desktopsysm-or-w32azeroa-infection/</link>
		<comments>http://www.pcbugsquad.com/2008/07/how-to-remove-the-desktopsysm-or-w32azeroa-infection/#comments</comments>
		<pubDate>Fri, 25 Jul 2008 19:56:25 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[removal guide]]></category>

		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=77</guid>
		<description><![CDATA[The W32.Azero.A infection is virus that infects .exe files so that when they are run they further infect other .exe files. When a .exe file is run the virus will create the following files:]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;">The W32.Azero.A infection is virus that infects .exe files so that when they are run they further infect other .exe files. When a .exe file is run the virus will create the following files:</span></p>
<ul>
<li>%System%\Windows 3d.scr</li>
<li>%System%\commandprompt.sysm</li>
<li>%System%\desktop.sysm</li>
<li>%UserProfile%\application data\Microsoft\[4 RANDOM LETTERS].exe</li>
</ul>
<p>It will then create the following folders:</p>
<p>It also creates the following folders:</p>
<ul>
<li>%UserProfile%\applications data\excel</li>
<li>%UserProfile%\applications data\media player</li>
<li>%UserProfile%\applications data\Microsoft</li>
<li>%UserProfile%\applications data\office</li>
<li>%UserProfile%\applications data\Windows</li>
<li>%UserProfile%\applications data\word</li>
</ul>
<p>It then creates the following Windows Registry entry so that it starts automatically when the computer boots up:</p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;VisualStyle&#8221; = &#8220;%System%\desktop.sysm&#8221;</p></blockquote>
<p>When a computer is infected with this virus they will find that their computer runs slower than normal and tends to crash.</p>
<h2><span style="color: #0000ff;">Automatic Removal Method</span></h2>
<p>If you are infected with this malware, then we suggest you use Symantec Antivirus to remove this infection. The current definitions for Symantec Antivirus contains methods of removing this virus.</p>
<p><img style="border-top-width: 0pt; border-left-width: 0pt; border-bottom-width: 0pt; vertical-align: middle; border-right-width: 0pt" src="http://www.pcbugsquad.com/images/download.jpg" alt="Download" /><a href="http://send.onenetworkdirect.net/z/45/CD106753/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/send.onenetworkdirect.net');">Download Symantec Antivirus to scan your computer for free</a></p>
<p align="left"><strong></strong></p>
<h2><span style="color: #0000ff;">Manual Removal Instructions for </span></h2>
<p><strong><span style="text-decoration: underline;">End these processes:</span></strong></p>
<p><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<p><span style="text-decoration: underline;"><strong></strong></span></p>
<blockquote><p>desktop.sysm</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote>
<ul>
<li>%System%\Windows 3d.scr</li>
<li>%System%\commandprompt.sysm</li>
<li>%System%\desktop.sysm</li>
<li>%UserProfile%\application data\Microsoft\[4 RANDOM LETTERS].exe</li>
</ul>
</blockquote>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys: </span></strong></p>
<p><a href="http://support.microsoft.com/kb/256986" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/support.microsoft.com');">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the <a href="#auto" target="_blank">automated</a> removal method above.</span></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;VisualStyle&#8221; = &#8220;%System%\desktop.sysm&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2008/07/how-to-remove-the-desktopsysm-or-w32azeroa-infection/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove the Troj_Renos.ACO or lphc3pgj0e3ct.exe infection.</title>
		<link>http://www.pcbugsquad.com/2008/07/how-to-remove-the-troj_renosaco-or-lphc3pgj0e3ctexe-infection/</link>
		<comments>http://www.pcbugsquad.com/2008/07/how-to-remove-the-troj_renosaco-or-lphc3pgj0e3ctexe-infection/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 19:44:14 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[lphc3pgj0e3ct.exe]]></category>

		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=75</guid>
		<description><![CDATA[A new variant of the Troj_Renos.ACO infection was discovered that installs a file called lphc3pgj0e3ct.exe into your C:WindowsSystem32folder. This infection is installed on your computer by one of the following three methods:]]></description>
			<content:encoded><![CDATA[<p>A new variant of the Troj_Renos.ACO infection was discovered that installs a file called lphc3pgj0e3ct.exe into your C:WindowsSystem32folder. This infection is installed on your computer by one of the following three methods:</p>
<ul>
<li>This Trojan may be downloaded from remote site(s) by other malware.</li>
<li>It may be dropped by other malware.</li>
<li>It may be downloaded unknowingly by a user when visiting malicious Web site(s).</li>
</ul>
<p>When started, the infection will connect to a remote web site to download and run another file that is also detected as Troj_Renos.ACO.  It then copies itself to C:WindowsSystem32lphc3pgj0e3ct.exe and adds a entry into the Windows Registry to start the file everytime you boot your computer.</p>
<p>This infection will also change your Windows desktop wallpaper to look like:</p>
<div id="attachment_72" class="wp-caption aligncenter" style="width: 480px"><a href="http://www.pcbugsquad.com/wp-content/uploads/2008/07/renos.gif"><img class="size-full wp-image-72" title="renos" src="http://www.pcbugsquad.com/wp-content/uploads/2008/07/renos.gif" alt="Trojan Renos Wallpaper" width="470" height="390" /></a><p class="wp-caption-text">Trojan Renos Wallpaper</p></div>
<p align="center">
<h2><span style="color: #0000ff;">Automatic Removal Method</span></h2>
<p>If you are infected with this malware, then we suggest you use Trend Micro antivirus to remove this infection. It is know to be able to remove this malware and it is included in its current virus definitions.  A big thumbs up for Trend Micro for being able to remove this infection so quickly.</p>
<p><img style="border-top-width: 0pt; border-left-width: 0pt; border-bottom-width: 0pt; vertical-align: middle; border-right-width: 0pt" src="http://www.pcbugsquad.com/images/download.jpg" alt="Download" /><a href="http://send.onenetworkdirect.net/z/320/CD106753/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/send.onenetworkdirect.net');">Download Trend Micro Antivirus to scan your computer</a></p>
<h2><span style="color: #0000ff;">Manual Removal Instructions for </span></h2>
<p><strong><span style="text-decoration: underline;">End these processes:</span></strong></p>
<p><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>lphc3pgj0e3ct.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>C:WindowsSystem32lphc3pgj0e3ct.exe<br />
C:WindowsSystem32phc3pgj0e3ct.bmp<br />
C:WindowsSystem32blphc3pgj0e3ct.scr</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys: </span></strong></p>
<p><a href="http://support.microsoft.com/kb/256986" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/support.microsoft.com');">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the <a href="#auto" target="_blank">automated</a> removal method above.</span></p>
<blockquote><p>HKEY_LOCAL_MACHINESOFTWAREMicrosoft<br />
WindowsCurrentVersionRun<br />
lphc3pgj0e3ct = &#8220;%System%lphc3pgj0e3ct.exe&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2008/07/how-to-remove-the-troj_renosaco-or-lphc3pgj0e3ctexe-infection/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove XLGuarder or XLG Security Center</title>
		<link>http://www.pcbugsquad.com/2008/07/how-to-remove-xlguarder-or-xlg-security-center/</link>
		<comments>http://www.pcbugsquad.com/2008/07/how-to-remove-xlguarder-or-xlg-security-center/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 19:10:49 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Rogue Anti-Spyware]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[removal guide]]></category>

		<category><![CDATA[xlg security center]]></category>

		<category><![CDATA[xlguarder]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=64</guid>
		<description><![CDATA[XLGuarder, or XLG Security Center, is a rogue anti-spyware program that displays deliberate false information about infections found on your computer.  Overall, this software is a scam and should be avoided at all cost.  Please use the automated or manual removal instructions below to remove this infection.]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;">XLGuarder, or XLG Security Center, is a rogue anti-spyware program that displays deliberate false information about infections found on your computer.  This malware is typical for its type:</span></p>
<ul>
<li>Shows false results</li>
<li>Won&#8217;t let you remove any supposed infections unless you first purchase the software.</li>
<li>Hijacks the Internet Explorer Start page.</li>
<li>Makes your computer slower.</li>
<li>Provides no way of contacting the developers of the software.</li>
</ul>
<p>Overall, this software is a scam and should be avoided at all cost.  Please use the automated or manual removal instructions below to remove this infection.</p>
<div id="attachment_65" class="wp-caption aligncenter" style="width: 510px"><a href="http://www.pcbugsquad.com/wp-content/uploads/2008/07/xlguarder.jpg"><img class="size-full wp-image-65" title="xlguarder" src="http://www.pcbugsquad.com/wp-content/uploads/2008/07/xlguarder.jpg" alt="XLGuarder or XLG Security Center image" width="500" height="363" /></a><p class="wp-caption-text">XLGuarder or XLG Security Center image</p></div>
<h2><span style="color: #0000ff;">Automatic Removal Method</span></h2>
<p>If you are infected with this malware, then we suggest you use Symantec Antivirus to remove this infection. It is know to be able to remove this malware and XLG Security Center is included in its current virus definitions.  A big thumbs up for Symantec adding this to removal definitions so quickly!</p>
<p><img style="border-top-width: 0pt; border-left-width: 0pt; border-bottom-width: 0pt; vertical-align: middle; border-right-width: 0pt" src="http://www.pcbugsquad.com/images/download.jpg" alt="Download" /><a href="http://send.onenetworkdirect.net/z/45/CD106753/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/send.onenetworkdirect.net');">Download Symantec Antivirus to scan your computer for free</a></p>
<p align="left"><strong></strong></p>
<h2><span style="color: #0000ff;">Manual Removal Instructions for </span></h2>
<p><strong><span style="text-decoration: underline;">End these processes:</span></strong></p>
<p><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<p><span style="text-decoration: underline;"><strong></strong></span></p>
<blockquote><p>sysutil.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>&lt;userprofile&gt;Start MenuProgramsProtection<br />
c:windowssysutils<br />
c:windowssysutilswarning<br />
c:windowssysutilssounds<br />
c:windowssysutilssettings.ini<br />
c:windowssysutilssysutil.exe<br />
c:windowssysutilssysutil_s.exe<br />
c:windowssysutilsuninstall.exe<br />
c:windowssysutilswinsystip.exe<br />
c:windowssysutilssounds�1.wav<br />
c:windowssysutilssounds�2.wav<br />
c:windowssysutilssounds�3.wav<br />
c:windowssysutilswarningalertpage.jpg<br />
c:windowssysutilswarningspacer.gif<br />
c:windowssysutilswarningwarningpage.html<br />
&lt;userprofile&gt;Start MenuProgramsProtectionUninstall XLG.lnk<br />
c:windowsiebho.dll</p></blockquote>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys: </span></strong></p>
<p><a href="http://support.microsoft.com/kb/256986" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/support.microsoft.com');">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the <a href="#auto" target="_blank">automated</a> removal method above.</span></p>
<blockquote><p>HKEY_CLASSES_ROOTCLSID{D032570A-5F63-4812-A094-87D007C23012}<br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{D032570A-5F63-4812-A094-87D007C23012}<br />
HKEY_CURRENT_USERSoftwaresysutils<br />
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallsysutils</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2008/07/how-to-remove-xlguarder-or-xlg-security-center/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Secret DNS flaw possibly revealed</title>
		<link>http://www.pcbugsquad.com/2008/07/secret-dns-flaw-possibly-revealed/</link>
		<comments>http://www.pcbugsquad.com/2008/07/secret-dns-flaw-possibly-revealed/#comments</comments>
		<pubDate>Tue, 22 Jul 2008 18:59:20 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Vulnerabilities]]></category>

		<category><![CDATA[dns]]></category>

		<category><![CDATA[exploit]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=61</guid>
		<description><![CDATA[Two weeks ago a security research named Dan Kaminksy found a very dangerous  flaw in DNS that could allow an attacker to manipulate the information  given back by a DNS server.  This attack would allow an attacker to  poison a DNS servers cache, so any future requests for the IP address  of a [...]]]></description>
			<content:encoded><![CDATA[<p>Two weeks ago a security research named Dan Kaminksy found a very dangerous  flaw in <a href="http://en.wikipedia.org/wiki/Domain_Name_System" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">DNS</a> that could allow an attacker to manipulate the information  given back by a DNS server.  This attack would allow an attacker to  <em>poison</em> a DNS servers cache, so any future requests for the IP address  of a host name would instead reply with the attackers chosen IP address rather  than the legitimate one.</p>
<p>As <a href="http://www.doxpara.com/?p=1162" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.doxpara.com');">part of this  announcement</a>, Dan asked that no other security researchers publicly  speculate as to the vulnerability in order to not give any black hats, or  hackers, the ability to figure the flaw out and use it.  He asked this in order  to provide all of the ISPs and companies in the world to update their DNS  servers to versions that do not have this flaw.  It turns out, though that  another researcher named Halvar Flake may have <a href="http://addxorrol.blogspot.com/2008/07/on-dans-request-for-no-speculation.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/addxorrol.blogspot.com');">figured it out</a>.</p>
<p>I wont try to explain it, but you may want to read the blog post i linked  above.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2008/07/secret-dns-flaw-possibly-revealed/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
