<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>PCBugSquad</title>
	<atom:link href="http://www.pcbugsquad.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcbugsquad.com</link>
	<description>Your daily stop for the latest computer advice.</description>
	<pubDate>Wed, 25 Mar 2009 19:58:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New XP Police Clone – WinPC Defender</title>
		<link>http://www.pcbugsquad.com/2009/03/new-xp-police-clone-winpc-defender/</link>
		<comments>http://www.pcbugsquad.com/2009/03/new-xp-police-clone-winpc-defender/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 22:48:46 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Rogue Anti-Spyware]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[rogue]]></category>

		<category><![CDATA[winpc defender]]></category>

		<category><![CDATA[xp police]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=160</guid>
		<description><![CDATA[Getting slammed in school, but wanted to post about WinPC Defender.  BleepingComputer has a new guide up for a XP Police Antivirus clone called WinPCDefender.  Here is a quote:
WinPC Defender is a new rogue anti-spyware program discovered by security analyst S!Ri and is a clone of the programs named XP Police Antivirus and IE Security. [...]]]></description>
			<content:encoded><![CDATA[<p>Getting slammed in school, but wanted to post about WinPC Defender.  BleepingComputer has a new guide up for a XP Police Antivirus clone called WinPCDefender.  Here is a quote:</p>
<blockquote><p><strong>WinPC Defender</strong> is a new rogue anti-spyware program discovered by security analyst <a href="http://siri-urz.blogspot.com/2009/03/winpc-defender.html">S!Ri</a> and is a clone of the programs named <a href="http://www.bleepingcomputer.com/malware-guides/remove-xp-police-antivirus">XP Police Antivirus</a> and <a href="http://www.bleepingcomputer.com/malware-removal/remove-ie-security">IE Security</a>. Like its predecessors, this program is installed and advertised through the use of Trojans that display fake security alerts on your computer. These security alerts state that your computer is infected and that you should click on them in order to download software that will protect you. Once you click on these alerts, the Trojan will automatically download and install the program on your computer.</p></blockquote>
<p>There guide is linked to below:</p>
<p><a href="http://www.bleepingcomputer.com/virus-removal/remove-winpc-defender">How to remove WinPC Defender</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2009/03/new-xp-police-clone-winpc-defender/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Spyware Fighter guide live at BleepingComputer</title>
		<link>http://www.pcbugsquad.com/2009/03/spyware-fighter-guide-live-bleepingcomputer/</link>
		<comments>http://www.pcbugsquad.com/2009/03/spyware-fighter-guide-live-bleepingcomputer/#comments</comments>
		<pubDate>Fri, 13 Mar 2009 01:07:41 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Rogue Anti-Spyware]]></category>

		<category><![CDATA[bleepingcomputer]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[spyware fighter]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=158</guid>
		<description><![CDATA[Just stumbled on a Spyware Fighter removal guide over at BleepingComputer, so it appears that Spyware Fighter is now live.  We reported about this rogue in Feb, but at the time the malware was not live and installable.  If you become infected with Spyware Fighter be sure to visit BleepingComputer in order to remove this [...]]]></description>
			<content:encoded><![CDATA[<p>Just stumbled on a <a title="Spyware Fighter removal guide" href="http://www.bleepingcomputer.com/virus-removal/spyware-fighter-removal">Spyware Fighter removal guide</a> over at BleepingComputer, so it appears that Spyware Fighter is now live.  We reported about this rogue in Feb, but at the time the malware was not live and installable.  If you become infected with Spyware Fighter be sure to visit BleepingComputer in order to remove this infection.</p>
<p><a title="Spyware Fighter removal guide" href="http://www.bleepingcomputer.com/virus-removal/spyware-fighter-removal"><br />
</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2009/03/spyware-fighter-guide-live-bleepingcomputer/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove the W32.SillyFDC.BAY worm</title>
		<link>http://www.pcbugsquad.com/2009/03/remove-w32sillyfdcbay-worm/</link>
		<comments>http://www.pcbugsquad.com/2009/03/remove-w32sillyfdcbay-worm/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 16:40:45 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Worms]]></category>

		<category><![CDATA[2.SillyFDC.BAY]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[worm]]></category>

		<category><![CDATA[xSafe.exe]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=155</guid>
		<description><![CDATA[

Description:
W32.SillyFDC.BAY is a removable media worm that spreads through infected flash drives, external hard drives, and other USB storage devices.  Once infected, your computer will then infect any other removable devices that become inserted into your computer. When infected, the worm will create the C:\Program Files\Common Files\xSafe.exe file and then add the following registry key [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #0000ff"><br />
</span></p>
<p><span style="color: #0000ff"><strong>Description:</strong></span></p>
<p>W32.SillyFDC.BAY is a removable media worm that spreads through infected flash drives, external hard drives, and other USB storage devices.  Once infected, your computer will then infect any other removable devices that become inserted into your computer. When infected, the worm will create the C:\Program Files\Common Files\xSafe.exe file and then add the following registry key so that it runs automatically when you start Windows:</p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;xSafe&#8221; = &#8220;%ProgramFiles%\Common Files\xSafe.exe&#8221;</p></blockquote>
<p><span style="color: #0000ff"><strong><br />
Manual Removal Instructions for W32.SillyFDC.BAY:</strong></span></p>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">End these processes if they exist:<br />
</span></strong><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>xSafe.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files if they exist:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>C:\Program Files\Common Files\xSafe.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys if they exist:<br />
</span></strong><a href="http://support.microsoft.com/kb/256986" target="_blank">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000">Warning: </span><span style="color: #000000">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.</span></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;xSafe&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2009/03/remove-w32sillyfdcbay-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Delete the Perfume.exe or W32.SillyFDC.BBA worm</title>
		<link>http://www.pcbugsquad.com/2009/03/delete-perfumeexe-w32sillyfdcbba-worm/</link>
		<comments>http://www.pcbugsquad.com/2009/03/delete-perfumeexe-w32sillyfdcbba-worm/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 16:37:20 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Rogue Anti-Spyware]]></category>

		<category><![CDATA[Worms]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[perfume.exe]]></category>

		<category><![CDATA[W32.SillyFDC.BBA]]></category>

		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=151</guid>
		<description><![CDATA[

Description:
W32.SillyFDC.BBA is a worm that spreads through removable media devices such as flash drives, external hard drives, and other USB storage devices.  Once infected, your computer will then infect any other removable devices that become inserted into your computer. When infected, the worm will create the SystemDrive%\SYSTEM\[SID]\Perfume.exe file and then add the following registry key [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #0000ff"><br />
</span></p>
<p><span style="color: #0000ff"><strong>Description:</strong></span></p>
<p>W32.SillyFDC.BBA is a worm that spreads through removable media devices such as flash drives, external hard drives, and other USB storage devices.  Once infected, your computer will then infect any other removable devices that become inserted into your computer. When infected, the worm will create the SystemDrive%\SYSTEM\[SID]\Perfume.exe file and then add the following registry key so that it runs automatically when you start Windows:</p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-22CX3C644241}</p></blockquote>
<p><span style="color: #0000ff"><strong><br />
Manual Removal Instructions for W32.SillyFDC.BBA:</strong></span></p>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">End these processes if they exist:<br />
</span></strong><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>Perfume.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files if they exist:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>%SystemDrive%\SYSTEM\[SID]\Perfume.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys if they exist:<br />
</span></strong><a href="http://support.microsoft.com/kb/256986" target="_blank">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000">Warning: </span><span style="color: #000000">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.</span></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-22CX3C644241}</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2009/03/delete-perfumeexe-w32sillyfdcbba-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove the Troj/Banker-EPN infection and the wmiprevse.exe file</title>
		<link>http://www.pcbugsquad.com/2009/03/remove-trojbanker-epn-wmiprevseexe/</link>
		<comments>http://www.pcbugsquad.com/2009/03/remove-trojbanker-epn-wmiprevseexe/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 18:42:52 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Tutorial]]></category>

		<category><![CDATA[banking]]></category>

		<category><![CDATA[identity theft]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=149</guid>
		<description><![CDATA[

Description:
Troj/Banker-EPN is a Trojan that attempts to steal accounts, passwords, and other online banking related information.  This infection listens to the traffic that you send to online banking web sites, and when it finds certain information, records it and sends it to a remote location.  This information is then used to either perform identify theft [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #0000ff"><br />
</span></p>
<p><span style="color: #0000ff"><strong>Description:</strong></span></p>
<p>Troj/Banker-EPN is a Trojan that attempts to steal accounts, passwords, and other online banking related information.  This infection listens to the traffic that you send to online banking web sites, and when it finds certain information, records it and sends it to a remote location.  This information is then used to either perform identify theft or to sell it to those who will.</p>
<p>Once this infection is installed, it will create the C:\Windows\wmiprevse.exe file and then add the following registry key so that it runs automatically when you start Windows:</p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;wmiprevse&#8221; = “C:\Windows\wmiprevse.exe&#8221;</p></blockquote>
<p><span style="color: #000000;">If this infection is found on your computer, it is strongly suggested that you contact all of your banks and have your account information changed immediately.  Also by explaining the situation they can have your accounts monitored for illicit activity.</span></p>
<p><span style="color: #777777"></p>
<p><span style="color: #0000ff"><strong>Manual Removal Instructions for Troj/Banker-EPN:</strong></span></p>
<p></span></p>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">End these processes if they exist:<br />
</span></strong><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>wmiprevse.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files if they exist:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>C:\Windows\wmiprevse.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys if they exist:<br />
</span></strong><a href="http://support.microsoft.com/kb/256986" target="_blank">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000">Warning: </span><span style="color: #000000">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.</span></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;wmiprevse&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2009/03/remove-trojbanker-epn-wmiprevseexe/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Delete QuickTime_.exe and remove the Troj/MalHost-B infection.</title>
		<link>http://www.pcbugsquad.com/2009/03/delete-quicktimeexe-remove-trojmalhost-b/</link>
		<comments>http://www.pcbugsquad.com/2009/03/delete-quicktimeexe-remove-trojmalhost-b/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 18:19:57 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[QuickTime_.exe]]></category>

		<category><![CDATA[Troj/MalHost-B]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=147</guid>
		<description><![CDATA[

Description:
The Troj/MalHost-Trojan pretends to be a video, but in reality is malware that changes your Windows HOSTS file that will redirect your web browser to further malicious sites. While the infection’s video is being shown on your desktop, the Trojan modifies your Windows HOSTs files to redirect popular web sites to malicious services under the [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #0000ff;"><br />
</span></p>
<p><span style="color: #0000ff;"><strong>Description:</strong></span></p>
<p>The Troj/MalHost-Trojan pretends to be a video, but in reality is malware that changes your Windows HOSTS file that will redirect your web browser to further malicious sites. While the infection’s video is being shown on your desktop, the Trojan modifies your Windows HOSTs files to redirect popular web sites to malicious services under the malware writer’s control.  These web sites will instead attempt to infect you with further malware.</p>
<p>When infected, this Trojan will create the C:\Program Files\QuickTime_.exe file and then create the following registry key to start itself automatically when Windows starts:</p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;Apple Inc.&#8221; = “C:\Program Files\QuickTime_.exe -atboottime&#8221;</p></blockquote>
<p><span style="color: #777777;"><br />
</span><span style="color: #0000ff;">Manual Removal Instructions for Troj/MalHost-B</span></p>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">End these processes if they exist:<br />
</span></strong><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>QuickTime_.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files if they exist:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>C:\Program Files\QuickTime_.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys if they exist:<br />
</span></strong><a href="http://support.microsoft.com/kb/256986" target="_blank">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.</span></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;Apple Inc.&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2009/03/delete-quicktimeexe-remove-trojmalhost-b/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to delete updmngr.exe and remove the Troj/Agent-JBX infection.</title>
		<link>http://www.pcbugsquad.com/2009/03/delete-updmngrexe-remove-trojagent-jbx/</link>
		<comments>http://www.pcbugsquad.com/2009/03/delete-updmngrexe-remove-trojagent-jbx/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 13:52:12 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=145</guid>
		<description><![CDATA[

Description:
Troj/Agent-JBX is a Trojan that attempts to connect to the Internet in order to transmit and receive information.  This Trojan is typically bundled with other malware.
Once infected, this Trojan will create the C:\Windows\System32\updmngr.exe file and then create the following registry key to start itself automatically:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows “load” = “C:\Windows\System32\updmngr.exe”
Manual Removal Instructions for Troj/Agent-JBX

End these processes [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #0000ff;"><br />
</span></p>
<p><span style="color: #0000ff;"><strong>Description:</strong></span></p>
<p>Troj/Agent-JBX is a Trojan that attempts to connect to the Internet in order to transmit and receive information.  This Trojan is typically bundled with other malware.</p>
<p>Once infected, this Trojan will create the C:\Windows\System32\updmngr.exe file and then create the following registry key to start itself automatically:</p>
<blockquote><p>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows “load” = “C:\Windows\System32\updmngr.exe”</p></blockquote>
<p><span style="color: #0000ff;">Manual Removal Instructions for Troj/Agent-JBX</span></p>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">End these processes if they exist:<br />
</span></strong><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>updmngr.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files if they exist:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>C:\Windows\System32\updmngr.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys if they exist:<br />
</span></strong><a href="http://support.microsoft.com/kb/256986" target="_blank">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.</span></p>
<blockquote><p>HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows “load” = “C:\Windows\System32\updmngr.exe”</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2009/03/delete-updmngrexe-remove-trojagent-jbx/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Remove the W32/AutoRun-ZX worm and the Ogard.exe infection</title>
		<link>http://www.pcbugsquad.com/2009/03/remove-w32autorun-zx-worm-ogardexe-infection/</link>
		<comments>http://www.pcbugsquad.com/2009/03/remove-w32autorun-zx-worm-ogardexe-infection/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 13:21:43 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Rogue Anti-Spyware]]></category>

		<category><![CDATA[Worms]]></category>

		<category><![CDATA[autoplay]]></category>

		<category><![CDATA[autorun]]></category>

		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/2009/03/remove-the-w32autorun-zx-worm-and-the-ogardexe-infection/</guid>
		<description><![CDATA[

Description:
W32/AutoRun-ZX is a removable media worm that spreads by infecting devices such as flash drives, external hard drives, and other removable media.  Once an infected media is inserted into a clean machine, the clean computer will autplay the media and infect itself.
Once infected, the worm will create the file C:\RESTORE\k-1-3542-4232123213-7676767-8888886\Ogard.exe.  It will then create the [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #0000ff;"><br />
</span></p>
<p><span style="color: #0000ff;"><strong>Description:</strong></span></p>
<p>W32/AutoRun-ZX is a removable media worm that spreads by infecting devices such as flash drives, external hard drives, and other removable media.  Once an infected media is inserted into a clean machine, the clean computer will autplay the media and infect itself.</p>
<p>Once infected, the worm will create the file C:\RESTORE\k-1-3542-4232123213-7676767-8888886\Ogard.exe.  It will then create the follow registry key to start itself automatically:</p>
<blockquote><p>HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-00WE-AAX5-77EF1D187322}</p></blockquote>
<p><span style="color: #0000ff;">Manual Removal Instructions for W32/AutoRun-ZX</span></p>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">End these processes if they exist:<br />
</span></strong><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>Ogard.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files if they exist:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>C:\RESTORE\k-1-3542-4232123213-7676767-8888886\Ogard.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys if they exist:<br />
</span></strong><a href="http://support.microsoft.com/kb/256986" target="_blank">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.</span></p>
<blockquote><p>HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-00WE-AAX5-77EF1D187322}</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2009/03/remove-w32autorun-zx-worm-ogardexe-infection/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove winbows.exe or the W32/Autorun-AAI worm</title>
		<link>http://www.pcbugsquad.com/2009/03/remove-winbowsexe-w32autorun-aai-worm/</link>
		<comments>http://www.pcbugsquad.com/2009/03/remove-winbowsexe-w32autorun-aai-worm/#comments</comments>
		<pubDate>Sat, 07 Mar 2009 20:31:44 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Worms]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=141</guid>
		<description><![CDATA[

Description:
W32/Autorun-AAI is a worm that targets removable media.  This worm typically spreads to your computer when you insert removable media such as flash drives, external hard drives, etc that have this infection on them.  Once these devices are inserted, your computer will autoplay the autorun.inf and the worm will run, infecting your computer.  Then if [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #0000ff;"><br />
</span></p>
<p><span style="color: #0000ff;"><strong>Description:</strong></span></p>
<p>W32/Autorun-AAI is a worm that targets removable media.  This worm typically spreads to your computer when you insert removable media such as flash drives, external hard drives, etc that have this infection on them.  Once these devices are inserted, your computer will autoplay the autorun.inf and the worm will run, infecting your computer.  Then if you insert any clean flash drives into your computer, the worm will infect those as well.</p>
<p>Once infected, the worm will create the file C:\Windows\Winbows.exe.  It will then create the follow registry key to start itself automatically:</p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;windows&#8221; = “winbows.exe&#8221;<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;windows&#8221; = “imege.exe&#8221;<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;windows&#8221; = “picture.exe&#8221;</p></blockquote>
<p><span style="color: #0000ff;">Manual Removal Instructions for W32/Autorun-AAI</span></p>
<p><strong></strong></p>
<p><strong><span style="text-decoration: underline;">End these processes if they exist:<br />
</span></strong><a href="http://www.pcbugsquad.com/2008/07/how-to-stop-a-program-in-windows/" target="_blank">Learn how to end processes</a></p>
<blockquote><p>winbows.exe<br />
picture.exe<br />
imege.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;"><br />
Delete these files if they exist:</span></strong><br />
<a href="http://www.pcbugsquad.com/2008/07/how-to-delete-a-file-in-windows/" target="_blank">Lean how to remove files</a></p>
<blockquote><p>C:\Windows\winbows.exe<br />
C:\Windows\imege.exe<br />
C:\Windows\picture.exe</p></blockquote>
<p><strong><span style="text-decoration: underline;">Remove these Registry keys if they exist:<br />
</span></strong><a href="http://support.microsoft.com/kb/256986" target="_blank">Learn how to remove Windows Registry entries</a></p>
<p><span style="color: #ff0000;">Warning: </span><span style="color: #000000;">Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.</span></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&#8221;windows&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2009/03/remove-winbowsexe-w32autorun-aai-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Malware Defender 2009 Removal Guide</title>
		<link>http://www.pcbugsquad.com/2009/03/malware-defender-2009-removal-guide/</link>
		<comments>http://www.pcbugsquad.com/2009/03/malware-defender-2009-removal-guide/#comments</comments>
		<pubDate>Fri, 06 Mar 2009 22:59:53 +0000</pubDate>
		<dc:creator>PCBugSquad</dc:creator>
		
		<category><![CDATA[Malware Removal Guide]]></category>

		<category><![CDATA[Rogue Anti-Spyware]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[bleepingcomputer.com]]></category>

		<category><![CDATA[malware defender 2009]]></category>

		<category><![CDATA[rogue]]></category>

		<category><![CDATA[vundo]]></category>

		<guid isPermaLink="false">http://www.pcbugsquad.com/?p=139</guid>
		<description><![CDATA[

I am running out, but I just read that BleepingComputer.com is reporting that a new rogue has been released that is advertised by the Vundo Trojan.  The Vundo Trojan is a wide spread Trojan that can be quite difficult to remove.  It is also know for causing large-scale installations of various rogues such as Antivirus [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #0000ff;"><br />
</span></p>
<p>I am running out, but I just read that <a href="http://www.bleepingcomputer.com/" target="_blank">BleepingComputer.com</a> is reporting that a new rogue has been released that is advertised by the Vundo Trojan.  The Vundo Trojan is a wide spread Trojan that can be quite difficult to remove.  It is also know for causing large-scale installations of various rogues such as Antivirus 360.</p>
<p>BleepingComputer.com’s removal guide uses Malwarebytes’ Anti-malware to remove it.  The guide can be found below:</p>
<p><a href="http://www.bleepingcomputer.com/forums/topic208905.html">Learn how to remove Malware Defender 2009 (Removal Guide)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcbugsquad.com/2009/03/malware-defender-2009-removal-guide/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
