<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>MSBasic Virus Blog</title>
	<atom:link href="http://msbasic.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://msbasic.wordpress.com</link>
	<description>This is my daily journal about malware information</description>
	<pubDate>Wed, 13 Aug 2008 15:55:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Panda AV Command Line 9.5.1</title>
		<link>http://msbasic.wordpress.com/2008/08/13/panda-av-command-line-951/</link>
		<comments>http://msbasic.wordpress.com/2008/08/13/panda-av-command-line-951/#comments</comments>
		<pubDate>Wed, 13 Aug 2008 15:55:35 +0000</pubDate>
		<dc:creator>msbasic</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[msbasic]]></category>

		<category><![CDATA[PANDA]]></category>

		<guid isPermaLink="false">http://msbasic.wordpress.com/?p=76</guid>
		<description><![CDATA[Greetz to Panda AV team that had just made it&#8217;s ninth version of it&#8217;s (their) comand Line AV.
This new engine incorporates interesting features over previous versions specially focused on detecting and deactivating active rootkits and improved heuristic detection of new and unknown malware:
* Engine version 1.5.1 integration.
* Reboot driver. Disinfection during reboot of active rootkits. [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Greetz to Panda AV team that had just made it&#8217;s ninth version of it&#8217;s (their) comand Line AV.</p>
<p>This new engine incorporates interesting features over previous versions specially focused on detecting and deactivating active rootkits and improved heuristic detection of new and unknown malware:</p>
<p>* Engine version 1.5.1 integration.<br />
* Reboot driver. Disinfection during reboot of active rootkits. Needs to run with admin priviledge.<br />
* Integration of Heuristic engine 7.0.7 with improved performance. Defaults to medium sensitivity.<br />
* Suspicious detection counter in both console and logs.<br />
* Digitally signed executables.<br />
* New log in CSV format (pavcl.log).</p>
<p>The new log format is as follows:<br />
[Date];[Complete_path];[File_name_in_compressed];[Malware_name];[Detection_ID];[Action_taken];<br />
[Sub_action];[Additional_information];[Status_ok_or_error];</p>
<p>Be sure to download the <strong><a href="http://research.pandasecurity.com/blogs/images/pav.zip">signature file</a></strong> available from their blog for testing purposes which is NOT updated on a regular basis. For production and critical scanning systems make sure to contact Panda for a regular signature feed.</p>
<p><a href="http://research.pandasecurity.com/blogs/images/pavcl.zip"><strong>Download the new PAVCL 9.5.1.00 here</strong></a>.</p>
<p>Return codes are available for integrations of PAVCL with automated scanning systems. PAVCL returns a numeric value of 4 bytes to indicate the type of program exit, the type of operation performed and the number of malware detected. For more info on this contact me.</p>
<p>This version is compatible with Windows 2000, 2003, XP (32 and 64 bits) and Vista (32 and 64 bits).</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/msbasic.wordpress.com/76/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/msbasic.wordpress.com/76/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/msbasic.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/msbasic.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/msbasic.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/msbasic.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/msbasic.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/msbasic.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/msbasic.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/msbasic.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/msbasic.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/msbasic.wordpress.com/76/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msbasic.wordpress.com&blog=3460623&post=76&subd=msbasic&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://msbasic.wordpress.com/2008/08/13/panda-av-command-line-951/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/msbasic-128.jpg" medium="image">
			<media:title type="html">MSBasic</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Updates for half year&#8230;</title>
		<link>http://msbasic.wordpress.com/2008/08/13/ms-bulletins-per-year/</link>
		<comments>http://msbasic.wordpress.com/2008/08/13/ms-bulletins-per-year/#comments</comments>
		<pubDate>Wed, 13 Aug 2008 15:18:07 +0000</pubDate>
		<dc:creator>msbasic</dc:creator>
		
		<category><![CDATA[Information]]></category>

		<category><![CDATA[Microsoft]]></category>

		<category><![CDATA[msbasic]]></category>

		<category><![CDATA[Rulez!]]></category>

		<guid isPermaLink="false">http://msbasic.wordpress.com/?p=72</guid>
		<description><![CDATA[Here are the half or more of the bulletins updates for MS (Sorry for not posting this ones, I forgot).
February MS Bulletins:
This month Microsoft has released 11 security bulletins (from MS08-03 to MS08-013). Six of them are rated as critical and five are Important. We recommend you to update your systems ASAP, as most of [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Here are the half or more of the bulletins updates for MS (Sorry for not posting this ones, I forgot).</p>
<h1>February MS Bulletins:</h1>
<p>This month Microsoft has released 11 security bulletins (from MS08-03 to MS08-013)<span class="item">.</span> Six of them are rated as critical and five are Important. We recommend you to update your systems ASAP, as most of the vulnerabilities allow remote code execution.</p>
<p>These bulletins updates the following software: LSASS, DirectShow, Internet Explorer, Macrovision Driver, JScript, VBscript, Office Suite, Media File Formats, Message Queuing Service.</p>
<p><img src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/02/13/ms08-feb2.jpg" alt="Microsoft Security Bulletin Summary for February 2008" width="700" height="534" /></p>
<h1>April MS Bulletins</h1>
<p>Five critical and three important updates have been released (from MS08-018 to MS08-025). It&#8217;s time to start updating your system if you haven&#8217;t done it yet.</p>
<p>Critical updates affect these components: Microsoft Project, GDI, VBScript and JScript scripting engines, updated ActiveX Kill Bits and Internet Explorer. On the other hand, DNS Client, Windows Kernel and MIcrosoft Visio are patched with important updates.</p>
<p>Most of them allow remote code execution, so don&#8217;t forget to update your system asap.<br />
<span style="font-family:tahoma,arial,helvetica,sans-serif;">You can find more information about the security bulletins by clicking the following link: <a title="MS08-April" href="http://www.microsoft.com/technet/security/bulletin/ms08-apr.mspx" target="_blank">MS08-April</a></span></p>
<p><img src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/04/09/MS08-April.jpg" alt="Microsoft Security Bulletin Summary for April 2008" width="700" height="384" /></p>
<h1>July MS Bulletins</h1>
<p><span style="font-size:x-small;"> </span></p>
<p>As always, every 2nd Tuesday of the month Microsoft publishes his security bulletins. This month only 4 have been published and all of them rated as important.</p>
<p>Below you can see a description of the bulletins released in July.</p>
<p><strong><a title="Microsoft Security Bulletin MS08-040" href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" target="_blank">Microsoft Security Bulletin MS08-040</a></strong></p>
<p><img style="width:700px;height:213px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/09/40.JPG" alt="" width="700" height="213" /></p>
<p><a title="Microsoft Security Bulletin MS08-038" href="http://www.microsoft.com/technet/security/bulletin/ms08-038.mspx" target="_blank"><strong>Microsoft Security Bulletin MS08-038</strong></a></p>
<p><img style="width:700px;height:230px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/09/38.JPG" alt="" width="700" height="230" /></p>
<p><strong><a title="Microsoft Security Bulletin MS08-037" href="http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx" target="_blank">Microsoft Security Bulletin MS08-037</a></strong></p>
<p><img style="width:700px;height:207px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/09/37.JPG" alt="" width="700" height="207" /></p>
<p><strong><a title="Microsoft Security Bulletin MS08-039" href="http://www.microsoft.com/technet/security/bulletin/ms08-039.mspx" target="_blank">Microsoft Security Bulletin MS08-039</a></strong></p>
<p><img style="width:700px;height:226px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/09/39.JPG" alt="" width="700" height="226" /></p>
<h1>May MS Bulletins</h1>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">Four new security bulletins have been published (from MS08-026 to MS08-029) as part of the usual launch of <a href="http://www.microsoft.com/technet/security/bulletin/ms08-may.mspx" target="_blank">Microsoft updates</a>. </span></p>
<div class="entryviewheading">
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">We recommend you to update your systems as soon as possible, as according to Microsoft’s classification three of the bulletins are rated as “critical”, while the last one is rated as “moderate”.</span></p>
<p><img style="width:716px;height:253px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/05/14/MS08-MAY.JPG" alt="MS08-MAY" width="716" height="253" /></p>
<p> </p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">You can find more information about the security bulletins by clicking the following links: </span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><a href="http://www.microsoft.com/technet/security/bulletin/MS08-026.mspx" target="_blank">MS08-026</a>: An update for Microsoft Word which solves two vulnerabilities that could allow remote code execution if a user opens a specially crafted Word file.</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><a href="http://www.microsoft.com/technet/security/bulletin/MS08-027.mspx" target="_blank">MS08-027</a>: An update for Microsoft Publisher which solves a vulnerability that could be exploited in order to execute arbitrary code if a user opens a malicious Publisher file.</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><a href="http://www.microsoft.com/technet/security/bulletin/MS08-028.mspx" target="_blank">MS08-028</a>: An update to solve a remote code execution vulnerability in Microsoft Jet Database Engine.</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><a href="http://www.microsoft.com/technet/security/bulletin/MS08-029.mspx" target="_blank">MS08-029</a>: A security update in order to match two vulnerabilities in the Microsoft Malware Engine, which could allow a remote attacker to cause a denial of service if a specially crafted is scanned.</span></p>
<h1><span style="font-family:Tahoma;">March MS Bulletins</span></h1>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">As usual, every second Tuesday Microsoft published security updates for its products. On 11th March, Microsoft published </span><a href="http://www.microsoft.com/technet/security/bulletin/ms08-mar.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">four updates</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> (from MS08-014 to MS08-017), all of them rated as critical and affecting Microsoft Office suite.</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">We recommend you to update your systems as soon as possible, as all this flaws could allow remote code execution to be run.</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">You can find more information about the security bulletins by clicking the following links:</span></p>
<p><strong><a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;idvirus=189909" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-014</span></a></strong><span style="font-family:tahoma,arial,helvetica,sans-serif;">: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution.</span></p>
<p><strong><a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;idvirus=189910" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-015</span></a></strong><span style="font-family:tahoma,arial,helvetica,sans-serif;">: Vulnerability in Microsoft Outlook Could Allow Remote Code Execution.</span></p>
<p><strong><a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;idvirus=189911" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-016</span></a></strong><span style="font-family:tahoma,arial,helvetica,sans-serif;">: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution.</span></p>
<p><strong><a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;idvirus=189912" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-017</span></a></strong><span style="font-family:tahoma,arial,helvetica,sans-serif;">: Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution.</span></p>
<p> </p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><img style="width:691px;height:192px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/03/13/MSBulletin03.JPG" alt="MSBulletin" width="691" height="192" /></span></p>
<h1><span style="font-family:Tahoma;">August MS Bulletins</span></h1>
<div class="entryviewheading">
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">Eleven new security bulletins have been published (from MS08-041 to MS08-051) as part of the usual launch of </span><a href="http://www.microsoft.com/technet/security/bulletin/ms08-aug.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">Microsoft updates</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;">.</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">We recommend you to update your system as soon as possible, as according to Microsoft&#8217;s classification six of the bulletins are rated as &#8220;critical&#8221;, while the others are rated as &#8220;important&#8221;.</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">You can find more information about the security bulletins by clicking the following links:</span></p>
<p> </p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-041.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-041</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access.</span></li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-042.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-042</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Vulnerability in Microsoft Word.</span></li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-043.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-043</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Vulnerabilities in Microsoft Excel.</span></li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-044.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-044</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Vulnerabilities in Microsoft Office Filters.</span></li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-045.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-045</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Cumulative Security Update for Internet Explorer.</span></li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-046.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-046</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Vulnerability in Microsoft Windows Image Color Management System.</span></li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-047.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-047</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Vulnerability in IPsec Policy Processing.</span></li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-048.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-048</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Security Update for Outlook Express and Windows Mail.</span></li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-049.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-049</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Vulnerabilities in Event System.</span></li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-050.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-050</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Vulnerability in Windows Messenger.</span></li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-051.mspx" target="_blank"><span style="font-family:tahoma,arial,helvetica,sans-serif;">MS08-051</span></a><span style="font-family:tahoma,arial,helvetica,sans-serif;"> – Vulnerabilities in Microsoft PowerPoint.</span></li>
</ul>
<p> </p>
<p> </p>
<p> </p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><img style="width:704px;height:611px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/08/13/MS08-AUG.JPG" alt="" width="704" height="611" /></span></p>
<p> </p></div>
<div class="entryviewfooter">
<div class="entrylistfooter"></div>
</div>
</div>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/msbasic.wordpress.com/72/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/msbasic.wordpress.com/72/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/msbasic.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/msbasic.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/msbasic.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/msbasic.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/msbasic.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/msbasic.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/msbasic.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/msbasic.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/msbasic.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/msbasic.wordpress.com/72/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msbasic.wordpress.com&blog=3460623&post=72&subd=msbasic&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://msbasic.wordpress.com/2008/08/13/ms-bulletins-per-year/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/msbasic-128.jpg" medium="image">
			<media:title type="html">MSBasic</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/02/13/ms08-feb2.jpg" medium="image">
			<media:title type="html">Microsoft Security Bulletin Summary for February 2008</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/04/09/MS08-April.jpg" medium="image">
			<media:title type="html">Microsoft Security Bulletin Summary for April 2008</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/09/40.JPG" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/09/38.JPG" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/09/37.JPG" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/09/39.JPG" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/05/14/MS08-MAY.JPG" medium="image">
			<media:title type="html">MS08-MAY</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/03/13/MSBulletin03.JPG" medium="image">
			<media:title type="html">MSBulletin</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/08/13/MS08-AUG.JPG" medium="image" />
	</item>
		<item>
		<title></title>
		<link>http://msbasic.wordpress.com/2008/08/12/70/</link>
		<comments>http://msbasic.wordpress.com/2008/08/12/70/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 17:08:47 +0000</pubDate>
		<dc:creator>msbasic</dc:creator>
		
		<category><![CDATA[Virus info]]></category>

		<guid isPermaLink="false">http://msbasic.wordpress.com/?p=70</guid>
		<description><![CDATA[It’s pretty clear that Beijing’s Olympic Games are a good chance for cybercrooks to infect users using the Games as a social engineering tool. 
The Games had started some days ago, and we have just seen a new malware, Bck/PcClient.HV, that seems to be a PowerPoint about the Games, but it installs in the infected [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="font-family:tahoma,arial,helvetica,sans-serif;">It’s pretty clear that Beijing’s Olympic Games are a good chance for cybercrooks to infect users using the Games as a social engineering tool. </span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">The Games had started some days ago, and we have just seen a new malware, Bck/PcClient.HV, that seems to be a PowerPoint about the Games, but it installs in the infected computers the files PcCortr.dll and 81.dll, that lower the system security level, enabling the file wuauct.exe copied by the malware in the system folder to remotely connect to a Chinese IP to send information about the infected computer. </span></p>
<p><img style="width:126px;height:127px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/08/08/001.JPG" alt="" width="126" height="127" /></p>
<p><img style="width:306px;height:19px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/08/08/003.JPG" alt="" width="306" height="19" /></p>
<p><span style="font-family:Tahoma;">To avoid any suspect, it shows 12 slides about the real Beijing Olympic Stadium:</span></p>
<p><img style="width:595px;height:448px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/08/08/002.JPG" alt="" width="595" height="448" /></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/msbasic.wordpress.com/70/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/msbasic.wordpress.com/70/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/msbasic.wordpress.com/70/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/msbasic.wordpress.com/70/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/msbasic.wordpress.com/70/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/msbasic.wordpress.com/70/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/msbasic.wordpress.com/70/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/msbasic.wordpress.com/70/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/msbasic.wordpress.com/70/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/msbasic.wordpress.com/70/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/msbasic.wordpress.com/70/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/msbasic.wordpress.com/70/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msbasic.wordpress.com&blog=3460623&post=70&subd=msbasic&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://msbasic.wordpress.com/2008/08/12/70/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/msbasic-128.jpg" medium="image">
			<media:title type="html">MSBasic</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/08/08/001.JPG" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/08/08/003.JPG" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/08/08/002.JPG" medium="image" />
	</item>
		<item>
		<title>Some Fun&#8230;?</title>
		<link>http://msbasic.wordpress.com/2008/08/12/some-fun/</link>
		<comments>http://msbasic.wordpress.com/2008/08/12/some-fun/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 17:06:46 +0000</pubDate>
		<dc:creator>msbasic</dc:creator>
		
		<category><![CDATA[Virus info]]></category>

		<category><![CDATA[.]]></category>

		<guid isPermaLink="false">http://msbasic.wordpress.com/?p=68</guid>
		<description><![CDATA[Angelina naked!!!&#8230;. Angelina Jolie porno Video Free!!!&#8230;. Angelina Jolie And Madonna Compete For Adoption Of Jamie Lynn Spears Baby!!!!! Angelina Jolie And The *** Lover.-.. Angelina.. Angelinaaa&#8230;.. Angelinaaaaaaaaaaaaaaaaaa!!!!!!!

You can also find messages with other fake news about any topic, but mainly about celebrities like Rihana, Pamela, Britney Spears,Obama, Bush but among them the most used is [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Angelina naked!!!&#8230;. Angelina Jolie porno Video Free!!!&#8230;. Angelina Jolie And Madonna Compete For Adoption Of Jamie Lynn Spears Baby!!!!! Angelina Jolie And The *** Lover.-.. Angelina.. Angelinaaa&#8230;.. Angelinaaaaaaaaaaaaaaaaaa!!!!!!!</p>
<p><img style="width:417px;height:585px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/30/angelina_nude.jpg" alt="" width="417" height="585" /></p>
<p>You can also find messages with other fake news about any topic, but mainly about celebrities like Rihana, Pamela, Britney Spears,Obama, Bush but among them the most used is Angelina Jolie.</p>
<p><img style="width:599px;height:704px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/30/outlook.jpg" alt="" width="599" height="704" /></p>
<p>However, we have recently received another kind of spam. But I was surprised not to see Angelina Jolie neither Britney nor obama.. instead, I saw that it was a fake email coming from an airline company which attached had a flight electronic ticket&#8230;</p>
<p><img style="width:700px;height:500px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/30/e-ticket.jpg" alt="" width="700" height="500" /></p>
<p>This eletronic ticket is in fact a Banker Trojan,Trj/Sinowal.VQK, which is designed to steal confidential data&#8230;</p>
<p><img style="width:311px;height:18px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/30/e-ticket_file.jpg" alt="" width="311" height="18" /></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/msbasic.wordpress.com/68/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/msbasic.wordpress.com/68/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/msbasic.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/msbasic.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/msbasic.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/msbasic.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/msbasic.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/msbasic.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/msbasic.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/msbasic.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/msbasic.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/msbasic.wordpress.com/68/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msbasic.wordpress.com&blog=3460623&post=68&subd=msbasic&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://msbasic.wordpress.com/2008/08/12/some-fun/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/msbasic-128.jpg" medium="image">
			<media:title type="html">MSBasic</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/30/angelina_nude.jpg" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/30/outlook.jpg" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/30/e-ticket.jpg" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/30/e-ticket_file.jpg" medium="image" />
	</item>
		<item>
		<title>Independence Day&#8217;s Worm (Since 1 Month)</title>
		<link>http://msbasic.wordpress.com/2008/08/12/independence-days-worm-since-1-month/</link>
		<comments>http://msbasic.wordpress.com/2008/08/12/independence-days-worm-since-1-month/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 17:03:16 +0000</pubDate>
		<dc:creator>msbasic</dc:creator>
		
		<category><![CDATA[Virus info]]></category>

		<category><![CDATA[Independence Day]]></category>

		<guid isPermaLink="false">http://msbasic.wordpress.com/?p=66</guid>
		<description><![CDATA[Once again the Stormworm as in many other special dates reaches our mailboxes in order to infect our computers with malware. 
This time it is related to a very special day in the United States:
Independence Day firework broke all records
Amazing Independence Day show
Celebrating the Glory of our Nation
Celebrating 4th of July
Super 4th!
Etc…

This is what we will [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="font-size:10pt;color:navy;font-family:Arial;"><span style="color:#000000;">Once again the Stormworm as in many other special dates reaches our mailboxes in order to infect our computers with malware.</span> </span></p>
<p><span style="font-size:10pt;color:navy;font-family:Arial;"><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><span style="color:#000000;">This time it is related to a very special day in the United States:</span></span></span></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><span style="color:#000000;"><em>Independence Day firework broke all records</em></span></span></span></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><span style="color:#000000;"><em>Amazing Independence Day show</em></span></span></span></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><span style="color:#000000;"><em>Celebrating the Glory of our Nation</em></span></span></span></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><span style="color:#000000;"><em>Celebrating 4th of July</em></span></span></span></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><span style="color:#000000;"><em>Super 4th!</em></span></span></span></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><span style="color:#000000;"><em>Etc…</em></span></span></span></span></p>
<p></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;">This is what we will view in the web after clicking the link included in these emails:<span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"> </span></span></span></span></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><img style="width:552px;height:477px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/04/02.WWW.JPG" alt="WWW" width="552" height="477" /></span></span></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><span style="font-size:10pt;color:black;font-family:Tahoma;"><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;">Evidently, as in many other occasions, it is not an embedded video, so while we are seeing this website, our browser will be trying to install W32/Nurech.BG.worm in our computer.</span></span></span></span></span></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><span style="font-size:10pt;color:black;font-family:Tahoma;"><span style="font-size:10pt;color:black;font-family:Tahoma;"><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;">The cases we have seen up to now follow the same pattern, the links point to different websites whose IPs are located in the United States and a malicious file will be downloaded “http://xxx.xxx.xxx.xxx/fireworks.exe ”.</span></span></span></span></span></span></span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><span style="color:#000000;"><span style="font-size:10pt;color:navy;font-family:Tahoma;"><span style="font-size:10pt;color:black;font-family:Tahoma;"><span style="font-size:10pt;color:black;font-family:Tahoma;"><img style="width:277px;height:398px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/04/03.IPs.JPG" alt="IPs" width="277" height="398" /></span></span></span></span></span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/msbasic.wordpress.com/66/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/msbasic.wordpress.com/66/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/msbasic.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/msbasic.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/msbasic.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/msbasic.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/msbasic.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/msbasic.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/msbasic.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/msbasic.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/msbasic.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/msbasic.wordpress.com/66/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msbasic.wordpress.com&blog=3460623&post=66&subd=msbasic&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://msbasic.wordpress.com/2008/08/12/independence-days-worm-since-1-month/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/msbasic-128.jpg" medium="image">
			<media:title type="html">MSBasic</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/04/02.WWW.JPG" medium="image">
			<media:title type="html">WWW</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/04/03.IPs.JPG" medium="image">
			<media:title type="html">IPs</media:title>
		</media:content>
	</item>
		<item>
		<title>Fake UPS Mail</title>
		<link>http://msbasic.wordpress.com/2008/08/12/fake-ups-mail/</link>
		<comments>http://msbasic.wordpress.com/2008/08/12/fake-ups-mail/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 16:59:57 +0000</pubDate>
		<dc:creator>msbasic</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://msbasic.wordpress.com/?p=64</guid>
		<description><![CDATA[These last days, several false email messages in circulation which seemed to come from the UPS company. However, they are not related to with this company at all.
The aim of these emails is not to inform us of the impossibility to deliver a postal package, but to entice us to open the attached file to [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="font-family:Tahoma;">These last days, several false email messages in circulation which seemed to come from the UPS company. However, they are not related to with this company at all.</span></p>
<p><span style="font-family:Tahoma;">The aim of these emails is not to inform us of the impossibility to deliver a postal package, but to entice us to open the attached file to infect our computers (detected as Trj/Agent.JEN).</span></p>
<p><img style="width:82px;height:65px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/15/Attached.JPG" alt="" width="82" height="65" /></p>
<p><span style="font-family:Tahoma;">This malware is copied in the system, replacing the Windows Userinit.exe (this file is the one which runs explorer.exe, the interface of the system and other important processes), copying the legitimate file as userini.exe, so that the computer can work properly.</span></p>
<p><span style="font-family:Tahoma;">Additionally, it establishes a connection with a Russian domain, which has been used on some occassions by banker Trojans. From this domain it will redirect the request to a German domain in order to download a rootkit and a rogue antivirus, detected as Rootkit/Agent.JEP and Adware/AntivirusXP2008 respectively.</span></p>
<p><span style="font-family:Tahoma;">The following graph represents the evolution of this malware with regard to the samples received during the last days. Before being included in our signature file, it was already detected by our TruPrevent Technologies as a suspicious file.</span></p>
<p><img style="width:700px;height:484px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/15/Evolution.JPG" alt="" width="700" height="484" /></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><em>Trj/Agent.JEN<br />
</em>MD5: 6B4EF50E3E21205685CEA919EBF93476</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><em>Rootkit/Agent.JEP<br />
</em>MD5: C65EBF59203CE3F05861398CC41A976A</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;"><em>Adware/AntivirusXP2008<br />
</em>MD5: EF6FFCC71B81B53328B63985B20C3871</span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/msbasic.wordpress.com/64/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/msbasic.wordpress.com/64/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/msbasic.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/msbasic.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/msbasic.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/msbasic.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/msbasic.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/msbasic.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/msbasic.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/msbasic.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/msbasic.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/msbasic.wordpress.com/64/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msbasic.wordpress.com&blog=3460623&post=64&subd=msbasic&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://msbasic.wordpress.com/2008/08/12/fake-ups-mail/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/msbasic-128.jpg" medium="image">
			<media:title type="html">MSBasic</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/15/Attached.JPG" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/15/Evolution.JPG" medium="image" />
	</item>
		<item>
		<title>The Secret Simpsons Chapter&#8230;</title>
		<link>http://msbasic.wordpress.com/2008/08/12/the-secret-simpsons-chapter/</link>
		<comments>http://msbasic.wordpress.com/2008/08/12/the-secret-simpsons-chapter/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 16:55:33 +0000</pubDate>
		<dc:creator>msbasic</dc:creator>
		
		<category><![CDATA[Virus info]]></category>

		<category><![CDATA[ChunkyLOver Malware]]></category>

		<category><![CDATA[Homer]]></category>

		<guid isPermaLink="false">http://msbasic.wordpress.com/?p=62</guid>
		<description><![CDATA[We have already observed that malware creators use any event, “true or fake” news as a social engineering technique to deceive users and install malware in their systems. One of the latest tricks we have seen is the use of one detail mentioned in one of the Simpsons episode, more specifically in Season 14 / [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="font-family:tahoma,arial,helvetica,sans-serif;">We have already observed that malware creators use any event, “true or fake” news as a social engineering technique to deceive users and install malware in their systems. One of the latest tricks we have seen is the use of one detail mentioned in one of the Simpsons episode, more specifically in Season 14 / 14-8 / EABF03 / The Dad Who Knew Too Little.</span></p>
<p><img style="width:465px;height:295px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/14/Homer_Computer.png" alt="" width="465" height="295" /></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">In this episode, Homer Simpson reveals that his email address is &#8220;chunkylover53@aol.com&#8221;, and just as matter of interest, this address was actually registered by one of its producers, answering users as if he were Homer himself. For this reason, it is no wonder that many fans have added this address as a contact in their email service.</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">However, it seems that there are certain AOL accounts that are passing themselves off as the identity of Chunkylover53, in order to deceive users and make them follow a link to infect their computers with a malicious code which is being distributed with the following message via the instant messaging program AIM:</span></p>
<p><img style="width:545px;height:163px;" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/14/02AIM.JPG" alt="" width="545" height="163" /></p>
<p><span style="font-family:Tahoma;">The malware has been detected as Bck/Turkojan.I, as it is a variant created with the Constructor/Turkojan mentioned previously in this <a href="http://msbasic.wordpress.com/2008/06/09/lolz_trojan/">post</a></span><span style="font-family:Tahoma;">.</span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/msbasic.wordpress.com/62/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/msbasic.wordpress.com/62/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/msbasic.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/msbasic.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/msbasic.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/msbasic.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/msbasic.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/msbasic.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/msbasic.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/msbasic.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/msbasic.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/msbasic.wordpress.com/62/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msbasic.wordpress.com&blog=3460623&post=62&subd=msbasic&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://msbasic.wordpress.com/2008/08/12/the-secret-simpsons-chapter/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/msbasic-128.jpg" medium="image">
			<media:title type="html">MSBasic</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/14/Homer_Computer.png" medium="image" />

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/14/02AIM.JPG" medium="image" />
	</item>
		<item>
		<title>Windows Registry Deleting =)</title>
		<link>http://msbasic.wordpress.com/2008/08/12/windows-registry-deleting/</link>
		<comments>http://msbasic.wordpress.com/2008/08/12/windows-registry-deleting/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 16:41:46 +0000</pubDate>
		<dc:creator>msbasic</dc:creator>
		
		<category><![CDATA[Broadcast &amp; Videos]]></category>

		<category><![CDATA[Alex]]></category>

		<category><![CDATA[Delete]]></category>

		<category><![CDATA[Dusaster]]></category>

		<category><![CDATA[Mark]]></category>

		<category><![CDATA[msbasic]]></category>

		<category><![CDATA[Registry]]></category>

		<category><![CDATA[UnixrAnge]]></category>

		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://msbasic.wordpress.com/?p=60</guid>
		<description><![CDATA[Sorry for long time no posting and approving your comments but I were in other things&#8230; This post is about a vgideo I made in another account of youtube, the video was called &#8220;Registry Deleting&#8221; about deleting all the registry entries I could in Windows Microsoft (C). I were afraid that the thing that happened [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Sorry for long time no posting and approving your comments but I were in other things&#8230; This post is about a vgideo I made in another account of youtube, the video was called &#8220;Registry Deleting&#8221; about deleting all the registry entries I could in Windows Microsoft (C). I were afraid that the thing that happened to the virtual PC &#8220;Test PC&#8221; happened to my, Mark&#8217;s computer&#8230; So When I just deleted the half of the registry entries you could see some lags in the video just that I was cutting the video for checking the registry of Mark&#8217;s Computer (An old friend). You can check the video on <a href="http://www.youtube.com/watch?v=x9nWxsJTv8w">http://www.youtube.com/watch?v=x9nWxsJTv8w</a>. Don&#8217;t try that at your home computer thatv was released on a test pc&#8230; After that I deleted other registry entries I could and&#8230; I Deleted AUTOEXEC.bat and I Turned off the computer with The Virtual PC Option, not the Windows, because I also Deketed Rundll32.dll and .exe and I could press the start button nor volume&#8230; Well When I just Started it again this happened:</p>
<p><img class="aligncenter" src="http://i37.tinypic.com/2qt946x.png" alt="" width="642" height="401" /></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/msbasic.wordpress.com/60/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/msbasic.wordpress.com/60/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/msbasic.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/msbasic.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/msbasic.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/msbasic.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/msbasic.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/msbasic.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/msbasic.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/msbasic.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/msbasic.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/msbasic.wordpress.com/60/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msbasic.wordpress.com&blog=3460623&post=60&subd=msbasic&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://msbasic.wordpress.com/2008/08/12/windows-registry-deleting/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/msbasic-128.jpg" medium="image">
			<media:title type="html">MSBasic</media:title>
		</media:content>

		<media:content url="http://i37.tinypic.com/2qt946x.png" medium="image" />
	</item>
		<item>
		<title>Akihabara distributing malware too?</title>
		<link>http://msbasic.wordpress.com/2008/06/12/akihabara-distributing-malware-too/</link>
		<comments>http://msbasic.wordpress.com/2008/06/12/akihabara-distributing-malware-too/#comments</comments>
		<pubDate>Thu, 12 Jun 2008 22:59:54 +0000</pubDate>
		<dc:creator>msbasic</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Akihabara]]></category>

		<category><![CDATA[HI]]></category>

		<category><![CDATA[Japan]]></category>

		<category><![CDATA[QIHost]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://msbasic.wordpress.com/?p=58</guid>
		<description><![CDATA[It is surprising how fast the cyber-crooks take advantage of any eye-catching news to distribute malware. Less than two days after the tragic event that took place in Tokyo “Tomohiro Kato - Akihabara Killer”, we detected an email that used this news as a bait to deceive users.
The email seemed to come from an address [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="font-family:Tahoma;">It is surprising how fast the cyber-crooks take advantage of any eye-catching news to distribute malware. Less than two days after the tragic event that took place in Tokyo “Tomohiro Kato - Akihabara Killer”, we detected an email that used this news as a bait to deceive users.</span></p>
<p><span style="font-family:Tahoma;">The email seemed to come from an address belonging to the RPP news (Radio Programas del Perú) in order to pass itself as a trustworthy source. However, you can check in the following </span><a href="http://www.rpp.com.pe/2008/06/08/siete_muertos_y_diez_heridos_apuñalados_por_un_hombre_en_el_centro_de_tokio/nid_127227.html" target="_blank"><span style="font-family:Tahoma;">URL</span></a><span style="font-family:Tahoma;">, which makes reference to the official news published by RPP, that it is totally different to the news included in the malicious email message, where after a brief description of the event, users are enticed to download and see a video regarding this news. However, what they actually download and install in the system is the Trojan QHost.IH.</span></p>
<p><img src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/11/01.JPG" alt="KIller!" width="581" height="458" /></p>
<p><span style="font-family:Tahoma;">This malware is designed to modify the hosts file by adding four fake websites of a certain banking entity. This way, if users visit any of the websites included in the hosts file, they will not be redirected to the original one but to another imitating the original website.</span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/msbasic.wordpress.com/58/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/msbasic.wordpress.com/58/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/msbasic.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/msbasic.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/msbasic.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/msbasic.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/msbasic.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/msbasic.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/msbasic.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/msbasic.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/msbasic.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/msbasic.wordpress.com/58/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msbasic.wordpress.com&blog=3460623&post=58&subd=msbasic&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://msbasic.wordpress.com/2008/06/12/akihabara-distributing-malware-too/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/msbasic-128.jpg" medium="image">
			<media:title type="html">MSBasic</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/11/01.JPG" medium="image">
			<media:title type="html">KIller!</media:title>
		</media:content>
	</item>
		<item>
		<title>TurkOjan</title>
		<link>http://msbasic.wordpress.com/2008/06/09/lolz_trojan/</link>
		<comments>http://msbasic.wordpress.com/2008/06/09/lolz_trojan/#comments</comments>
		<pubDate>Mon, 09 Jun 2008 23:02:46 +0000</pubDate>
		<dc:creator>msbasic</dc:creator>
		
		<category><![CDATA[Downloads]]></category>

		<category><![CDATA[Virus info]]></category>

		<guid isPermaLink="false">http://msbasic.wordpress.com/?p=56</guid>
		<description><![CDATA[Yeah it sounds familiar doesn&#8217;t it? Trojan, the answer is trojan. Read the information below&#8230;
Everybody knows that nowadays it is very easy to create malicious programs or new variants of malware generally with the help of programs like virus constructors, which are publicly released by real experts in creating malware.
As Panda mentioned in a previously [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Yeah it sounds familiar doesn&#8217;t it? Trojan, the answer is trojan. Read the information below&#8230;</p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">Everybody knows that nowadays it is very easy to create malicious programs or new variants of malware generally with the help of programs like virus constructors, which are publicly released by real experts in creating malware.</span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">As Panda mentioned in a previously published </span><span style="font-family:tahoma,arial,helvetica,sans-serif;">post</span><span style="font-family:tahoma,arial,helvetica,sans-serif;">, these “beginners” in creating malware use different antivirus scanners with which they test their creations until they are undetectable. </span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">In this case, one of these tools is Constructor/Turkojan, which offers new different functionalities with each version, currently the v4.0. </span><span style="font-family:tahoma,arial,helvetica,sans-serif;">Among the options offered, the following are included: </span></p>
<p><span style="font-family:tahoma,arial,helvetica,sans-serif;">Remote Desktop / Webcam Streaming / Audio Streaming / Remote passwords / MSN Sniffer / Remote Shell / Advanced File Manager / Online &amp; Offline keylogger / Information about remote computer / Etc</span></p>
<p><img src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/09/01.JPG" alt="TurkOjan" width="551" height="624" /></p>
<p><span style="font-family:Tahoma;">You may be wondering which benefits the author gains with this tool.  Obviously, there is a financial reason behind this. Almost all users who design this type of tools offer versions with different services, which include customized support depending on the sum of money paid.</span></p>
<p><img src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/09/02.JPG" alt="Pay for TurkOjan" width="595" height="677" /></p>
<p><span style="font-family:Tahoma;">This is a clear example that shows that cybercrooks are more are more professional and that there is a real organized business which looks for the profitability of their creations.</span></p>
<p><span style="font-family:Tahoma;">-Information by ma friends of Panda and obiously me =).</span></p>
<p><span style="font-family:Tahoma;">Well yeah, I have the trojan in my Test PC Currently running and I&#8217;m writting this in my Test PC. It seems very good unless the 4.0 free version seems to be in turkish only and it sucks, I&#8217;m currently putting the link for trojan in the MOD page only for Admins &amp; Mods, when I get full version I&#8217;m gonna update post putting the link of trojan free version and full version in MOD Page. If I don&#8217;t find full version I&#8217;m gonna still put the free version trojan here so don&#8217;t fuck off xD.</span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/msbasic.wordpress.com/56/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/msbasic.wordpress.com/56/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/msbasic.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/msbasic.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/msbasic.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/msbasic.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/msbasic.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/msbasic.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/msbasic.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/msbasic.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/msbasic.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/msbasic.wordpress.com/56/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=msbasic.wordpress.com&blog=3460623&post=56&subd=msbasic&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://msbasic.wordpress.com/2008/06/09/lolz_trojan/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/msbasic-128.jpg" medium="image">
			<media:title type="html">MSBasic</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/09/01.JPG" medium="image">
			<media:title type="html">TurkOjan</media:title>
		</media:content>

		<media:content url="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/09/02.JPG" medium="image">
			<media:title type="html">Pay for TurkOjan</media:title>
		</media:content>
	</item>
	</channel>
</rss>