<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>My DigitalZone &#187; Malwarebytes</title>
	<atom:link href="http://mydigitalzone.net/tag/malwarebytes/feed/" rel="self" type="application/rss+xml" />
	<link>http://mydigitalzone.net</link>
	<description></description>
	<lastBuildDate>Fri, 15 Jan 2010 04:34:05 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Rootkit: Malware and Trojan</title>
		<link>http://mydigitalzone.net/2009/04/16/rootkit-malware-and-trojan/</link>
		<comments>http://mydigitalzone.net/2009/04/16/rootkit-malware-and-trojan/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 05:58:50 +0000</pubDate>
		<dc:creator>Jenny</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Avast!]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Malwarebytes]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[Rootkit Buster]]></category>
		<category><![CDATA[Trend Micro]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://mydigitalzone.net/?p=138</guid>
		<description><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style>




I spent half a day last weekend to help my friend to battle with a computer infected with trojans.  Lots of them.  They were persistent and difficult to remove.  Malwares like AntiVirus 2008 or AntiVirus 2009 as described in this post were easier to remove compared with the ones I encountered last [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style><p id="top" /><script type="text/javascript"><!--
google_ad_client = "pub-2241621611203959";
/* DZone_posts336x280, created 1/2/09 */
google_ad_slot = "2956728885";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script><br />
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br />
<a href="http://www.amazon.com/gp/product/B001DQFLMC?ie=UTF8&#038;tag=latinballroom-20&#038;linkCode=as2&#038;camp=1789&#038;creative=9325&#038;creativeASIN=B001DQFLMC"><img border="0" src="/images/amazon/61lfqIQbhoL._SL160_.jpg"></a><img src="http://www.assoc-amazon.com/e/ir?t=latinballroom-20&#038;l=as2&#038;o=1&#038;a=B001DQFLMC" width="1" height="1" border="0" alt="" style="border:none !important; margin:0px !important;" /></p>
<p>I spent half a day last weekend to help my friend to battle with a computer infected with trojans.  Lots of them.  They were persistent and difficult to remove.  Malwares like AntiVirus 2008 or AntiVirus 2009 as described in <a href="http://mydigitalzone.net/2008/12/01/malware/">this post</a> were easier to remove compared with the ones I encountered last week.  Basically, AntiVirus 2008 and AntiVirus 2009 are malware that uses scare tactics to make users to buy their own virus removal software.  The ones I encountered at my friend&#8217;s house turned out to be a kind called &#8220;<strong>rootkit</strong>.&#8221;</p>
<p>According to <a href="http://en.wikipedia.org/wiki/Rootkit">wikipedia</a>, &#8220;A rootkit is a software system that consists of a program, or combination of several programs, designed to hide or obscure the fact that a system has been compromised&#8230; An attacker may use a rootkit to replace vital system executables, which may then be used to hide processes and files the attacker has installed, along with the presence of the rootkit. Access to the hardware, e.g., the reset switch, is rarely required, as a rootkit is intended to seize control of the operating system.&#8221;  This is a <strong>serious</strong> threat.  </p>
<p>The computer in question has a good working McAfee Virus scan and its On Access scan window keeps popping up saying that trojan was found and deleted.  That&#8217;s how my friend found about their existence.  The reason he asked my help was that it looks like it was catching the same gourp of files again and again, even though the virus scan said it had deleted them.  Some of the files were in windows\system32\drivers.  They were systemntmi.sys, amd64si.sys, i386si.sys, amd64si.sys, and lots of others.</p>
<p>So, there I was.  Trying various other software.  I tried Malwarebytes&#8217; Anti-Malware.  It found a bunch of infections.  Like over 50.  It said it had removed them.  Reboot.  Scanned again.  Strange.  It found them again.  Removed.  Reboot.  I used Avast!  Reboot.  I used Trend Micro Rootkit Buster.  Reboot.  As I said earlier, the trojans were persistent.  I decided to take a break at that point to do more research on the issue.</p>
<p>What I will do this weekend is to do an <strong>OS reinstal</strong>l this weekend.  As <a href="http://en.wikipedia.org/wiki/Rootkit">the wikipedia article</a> says, &#8220;Even if the nature and composition of a rootkit is known, the time and effort of a system administrator with the necessary skills or experience would be better spent re-installing the operating system from scratch.&#8221;  </p>
<p>Oh well.  I&#8217;m looking at two system restore projects within a week!  </p>
]]></content:encoded>
			<wfw:commentRss>http://mydigitalzone.net/2009/04/16/rootkit-malware-and-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to Remove Antivirus 2008</title>
		<link>http://mydigitalzone.net/2008/12/01/malware/</link>
		<comments>http://mydigitalzone.net/2008/12/01/malware/#comments</comments>
		<pubDate>Mon, 01 Dec 2008 07:00:55 +0000</pubDate>
		<dc:creator>Jenny</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Anti-Malware]]></category>
		<category><![CDATA[Antivirus 2007]]></category>
		<category><![CDATA[Antivirus 2008]]></category>
		<category><![CDATA[Antivirus 2009]]></category>
		<category><![CDATA[Malwarebytes]]></category>

		<guid isPermaLink="false">http://mydigitalzone.net/?p=11</guid>
		<description><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style>



Antivirus 2008 is malware and is becoming rampant.  It is extremely annoying and oftentimes makes a computer unoperable with its pop-ups and fake warnings.  According to Wikipedia, Malware is &#8220;software designed to infiltrate or damage a computer system without the owner&#8217;s informed consent.&#8221;  Most people get infected with Antivirus 2008 by installing [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
<!--
.nmstitle {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 13px;
	text-transform: capitalize;
	color: #003333;
}

.nmsdesc {
	font-family: Verdana, Arial, Helvetica, sans-serif;
	font-size: 12px;

	color: #003333;
}
-->
</style><p id="top" /><script type="text/javascript"><!--
google_ad_client = "pub-2241621611203959";
/* DZone_posts336x280, created 1/2/09 */
google_ad_slot = "2956728885";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script><br />
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br />
Antivirus 2008 is malware and is becoming rampant.  It is extremely annoying and oftentimes makes a computer unoperable with its pop-ups and fake warnings.  According to <a href="http://en.wikipedia.org/wiki/Malware">Wikipedia</a>, Malware is &#8220;software designed to infiltrate or damage a computer system without the owner&#8217;s informed consent.&#8221;  Most people get infected with Antivirus 2008 by installing a fake codec for audio or video files or by installing software that hides malicious software in the package.  <strong>You can remove Antivirus 2008 with free software called &#8220;Anti-Malware&#8221; by Malwarebytes.  So, do not buy software that Antivirus 2008 recommends.</strong></p>
<p><strong>Infections</strong><br />
It has many variants but the main characteristics of this malware is to rely on <strong>scare tactics</strong> (about virus infection on the PC) and to convince the user to <strong>buy Virus removal software</strong> online.  When Antivirus 2008 gets installed on a computer, it will start giving warnings about viruses on the computer.  It will ask the user to scan the computer with Antivirus and will show the results.  All the infections shown in the result window are actually fake, planted by Antivirus 2008 itself.  When the user tries to remove infections, he/she will be notified that the removal capability is disabled with the free version of Antivirus and only the purchased version will be able to remove the infections.  </p>
<p>Here are a few screenshots of the Antivirus warnings.<br />
<img src="http://www.mydigitalzone.net/images/antivirus_2008_1.jpg" alt="Anti-Virus 2008" width = 500 height = 400 /><br />
<img src="http://www.mydigitalzone.net/images/antivirus_2008_2.jpg" alt="Anti-virus 2008" width = 500 height = 400 /></p>
<p><strong>Removal</strong><br />
It is possible to remove Antivirus 2008 manually; however, it is a complicated process and can be intimidating if you are not familiar with computers.  There is excellent software that can take care of Antivirus 2007/2008/2009 infections and other malware problems.  The software is free for basic uses, and you don&#8217;t need to buy an upgraded paid version.  Please go to <a href="http://www.malwarebytes.org/">Malwarebyte&#8217;s home page, </a>download <a href="http://www.malwarebytes.org/mbam.php">Anti Malware</a>, install it, scan your computer, and follow the directions.  I&#8217;ve used this software many times on my and my friend&#8217;s computer.  It is effective and easy to use.</p>
<p><strong>Additional software for precaution and regular maintenance</strong><br />
I also recommend to use <a href="http://www.lavasoft.com/?domain=adaxis.net">Lavasoft&#8217;s Ad-Aware</a>.  One note of caution for this software is that their latest version seems to be a bit buggy, at least on my computer.  This software scans for spyware and other malware that can cause problems.</p>
]]></content:encoded>
			<wfw:commentRss>http://mydigitalzone.net/2008/12/01/malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

