Archive for August, 2007

SpyHunter Threat Database Update 6.16

SpyHunter defs version 6.16 (08/30/2007)
Latest Program version: 2.9.5018

The following new parasites have been added:

Worm.Gibe, Email-Worm.Swenm, AntiVirusPro, Worm.Kelvir.A, Worm.Bropia, Worm.Spybot.PEN, Trojan.Rbot-AHI, Worm.Zhelatin.HS, ErrorDoctor, Worm.Feebs, Trojan.Agent-ECU

Read more on SpyHunter Threat Database Update 6.16 »

Worm.Gibe Removal Guide

Worm.Gibe Description

Gibe is a worm virus that is written in Visual Basic. This threat propagates through mall-mailing, open network shares, IRC, and peer-to-peer file sharing networks. Once executed on your PC, Gibe will send itself as an email attachment to all addresses that it can gather from your Microsoft Outlook Address Book. It will masquerade as a Microsoft Security Update and uses its own SMTP engine to transmit the messages.

Read more on Worm.Gibe Removal Guide »

Email-Worm.Swen Removal Guide

Email-Worm.Swen Description

Swen is a worm virus. This threat propagates through mall-mailing, open network shares, IRC, and peer-to-peer file sharing networks. Once executed on your PC, Swen will send itself as an email attachment to all addresses that it can gather from your Outlook Address Book.

Read more on Email-Worm.Swen Removal Guide »

AntiVirusPro Removal Guide

AntiVirusPro Description

Spyware Image

AntiVirusPro is a rogue anti-spyware application. AntiVirusPro is often downloaded and installed by a Trojan, through browser security holes, or via other unconventional and unethical mechanisms. Once installed, AntiVirusPro will also display notifications of imaginary security and privacy risks in its attempts to get the user to purchase the full version and may generate system instability. This threat may also change your Windows desktop wallpaper. AntiVirusPro is related to 1stAntivirus.

Read more on AntiVirusPro Removal Guide »

Worm.Kelvir.A Removal Guide

Worm.Kelvir.A Description

Kelvir is a worm virus that spreads through Windows Messenger. Once installed on your PC, Kelvir will send a message with the text “omg this is funny!” to all of your Windows Messenger contacts, along with a link to download the worm. This file will also download a Spybot worm variant. This worm will disable DCOM and will add itself to the Windows run key so that it auto-starts when Windows starts.

Read more on Worm.Kelvir.A Removal Guide »

Worm.Bropia Removal Guide

Worm.Bropia Description

Bropia is a worm virus that spreads through MSN Messenger. Once it is executed, the worm will send messages to all of your Messenger clients with a copy of itself as the payload. It will also set itself up to automatically run at Windows startup. The worm will disable regedit.exe, mstask.exe, and msconfig.exe in an attempt to thwart its removal. It will also download and display a counter image from a web address.

Read more on Worm.Bropia Removal Guide »

Worm.Spybot.PEN Removal Guide

Worm.Spybot.PEN Description

This variant of the Spybot worm spreads itself across network shares that are open, or have weak passwords. It may also exploit a variety of Windows vulnerabilities, and may come bundled with other malware. Once executed, it will automatically start with Windows and can be used by a hacker to launch Denial of Service attacks on other computers and networks. Additionally, this worm has backdoor capabilities and keystroke logging features, making this worm a severe threat to the security of your personal and financial data.

Read more on Worm.Spybot.PEN Removal Guide »

Trojan.Rbot-AHI Removal Guide

Trojan.Rbot-AHI Description

Rbot-AHI is a Trojan application that downloads and installs additional malware. This program is malicious and extremely dangerous. Rbot installs secretly on your computer, often through browser security exploits, exploitation of network shares, or un-patched buffer overflow vulnerabilities and firmly embeds itself into your system. This malware will silently download and install updates and additional parasites. It also opens up numerous backdoor security holes, allowing remote attackers to control your computer, execute programs, download additional malware, and steal confidential personal data and credit card information.

Read more on Trojan.Rbot-AHI Removal Guide »

Worm.Zhelatin.HS Removal Guide

Worm.Zhelatin.HS Description

Zhelatin is an email worm that propagates as a spam email attachment. Once installed on your system, the worm will employ rootkit techniques in an attempt to prevent detection. It will attempt to add your PC to an IRC Botnet, and will then use your PC to send spam emails. Infected email messages will be sent to all email addresses that the worm is able to find on your computer.

Read more on Worm.Zhelatin.HS Removal Guide »

ErrorDoctor Removal Guide

ErrorDoctor Description

Spyware Image

ErrorDoctor is a rogue computer cleanup application. ErrorDoctor, also known as Error Doctor 2007, is ostensibly designed to detect and repair registry errors, but is often downloaded and installed by a Trojan, through browser security holes, or via other unconventional and unethical mechanisms. Once installed, Error Doctor launches on Windows startup. It will display notifications of imaginary registry errors in its attempts to get the user to purchase the full version.

Read more on ErrorDoctor Removal Guide »