<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>eGuru &#187; Spyware</title>
	<atom:link href="http://eguru.info/tag/spyware/feed/" rel="self" type="application/rss+xml" />
	<link>http://eguru.info</link>
	<description>Modern business, books, travel, and technology</description>
	<lastBuildDate>Tue, 20 Jul 2010 11:06:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Trojan masquerades as iPhone game</title>
		<link>http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/</link>
		<comments>http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/#comments</comments>
		<pubDate>Fri, 19 Sep 2008 07:49:31 +0000</pubDate>
		<dc:creator>Prithvi Mandava</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[iPhone]]></category>

		<guid isPermaLink="false">http://eguru.info/?p=200</guid>
		<description><![CDATA[Security firm Sophos warned on Thursday that e-mails being circulated on the Web that purport to offer a free iPhone game instead are carrying a Trojan horse that can take control of infected Windows machines. The e-mails have subject lines like &#8220;Virtual iPhone games!&#8221; and &#8220;Apple: The most popular game!&#8221; The attachment is called &#8220;Penguin.Panic.zip,&#8221; [...]]]></description>
			<content:encoded><![CDATA[<div class="postBody">
<p>Security firm Sophos warned on Thursday that e-mails being circulated on the Web that purport to offer a free iPhone game instead are carrying a Trojan horse that can take control of infected Windows machines.<span id="more-200"></span></p>
<p>The e-mails have subject lines like &#8220;Virtual iPhone games!&#8221; and &#8220;Apple: The most popular game!&#8221; The attachment is called &#8220;Penguin.Panic.zip,&#8221; which refers to the iPhone game of the same name.</p>
<p>The Trojan has been identified as <a href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojagenthny.html">Troj/Agent-HNY</a>, Sophos said.</p>
<p>Sophos has not yet seen versions that run on Mac OS X, the Apple iPhone, or other mobile devices.</p>
</div>
<div class="origPosted">Originally posted at <a class="origPostedBlog" href="http://news.cnet.com/8301-1009_3-10045647-83.html">News &#8211; Security</a></div>
<div class="origPosted"><a href="http://www.download.com/8301-2007_4-10045647-12.html?part=rss&amp;tag=feed&amp;subj=TheDailyDownload" target="_blank">Source</a></div>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-shr">
<ul class="socials">
		<li class="shr-comfeed">
			<a href="http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/&amp;title=Trojan+masquerades+as+iPhone+game" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/&amp;title=Trojan+masquerades+as+iPhone+game" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/&amp;title=Trojan+masquerades+as+iPhone+game" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/&amp;title=Trojan+masquerades+as+iPhone+game" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/&amp;title=Trojan+masquerades+as+iPhone+game" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Trojan+masquerades+as+iPhone+game+-+http://b2l.me/aa7n49&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/&amp;title=Trojan+masquerades+as+iPhone+game&amp;desc=%0D%0A%0D%0ASecurity%20firm%20Sophos%20warned%20on%20Thursday%20that%20e-mails%20being%20circulated%20on%20the%20Web%20that%20purport%20to%20offer%20a%20free%20iPhone%20game%20instead%20are%20carrying%20a%20Trojan%20horse%20that%20can%20take%20control%20of%20infected%20Windows%20machines.%0D%0A%0D%0AThe%20e-mails%20have%20subject%20lines%20like%20%22Virtual%20iPhone%20games%21%22%20and%20%22Apple%3A%20The%20most%20po" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/&amp;bm_description=Trojan+masquerades+as+iPhone+game&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/&amp;t=Trojan+masquerades+as+iPhone+game" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://eguru.info/2008/09/trojan-masquerades-as-iphone-game/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove Antivirus XP 2008</title>
		<link>http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/</link>
		<comments>http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/#comments</comments>
		<pubDate>Tue, 16 Sep 2008 18:37:15 +0000</pubDate>
		<dc:creator>Prithvi Mandava</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[XP]]></category>

		<guid isPermaLink="false">http://eguru.info/?p=168</guid>
		<description><![CDATA[Antivirus XP 2008 is back, unfortunately. It&#8217;s not an antivirus app, but a cleverly disguised rogue security application that tries to get you to buy the non-existent &#8220;security&#8221; it&#8217;s selling. Advertised using the common tricks of Trojans and faux security alerts, this nasty piece of malware can take over your desktop settings to mimic safe [...]]]></description>
			<content:encoded><![CDATA[<p>Antivirus XP 2008 is back, unfortunately. It&#8217;s not an antivirus app, but a cleverly disguised rogue security application that tries to get you to buy the non-existent &#8220;security&#8221; it&#8217;s selling. Advertised using the common tricks of Trojans and faux security alerts, this nasty piece of malware can take over your desktop settings to mimic safe mode, display fake virus detections, and opens a faux Internet Explorer window stating that Google has detected a malware infection.<span id="more-168"></span></p>
<div class="cnet-image-div image-large float-none"><img class="cnet-image" src="http://i.i.com.com/cnwk.1d/i/bto/20080915/antivirus_xp_2008_web_site_540x404.jpg" alt="" width="540" height="404" /></p>
<p class="image-caption">Antivirus XP 2008&#8242;s Web site looks legit, but caveat emptor.</p>
</div>
<p>Yeah, Google.</p>
<p>Apparently, though, the virus is now being spread in more insidious ways, and numerous people who claim safe browsing habits and up-to-date security definitions are being infected&#8211;including two of my friends.</p>
<p>In helping them remove it, I discovered an excellent post on the <a href="http://forums.cnet.com/5208-6122_102-0.html?forumID=44&amp;threadID=288404&amp;messageID=2798150#2798150">CNET Forums</a> that explained a detailed and accurate method of removal. I&#8217;ve retyped it below with more detail in case you&#8217;re not able to get to the forums. It&#8217;s not particularly complicated, but if you&#8217;re not comfortable with advanced settings, I&#8217;d recommend proceeding cautiously or get a friend to help.</p>
<div class="cnet-image-div image-medium float-right"><img class="cnet-image" src="http://i.i.com.com/cnwk.1d/i/bto/20080915/antivirus_xp_2008_scan_270x206.jpg" alt="" width="270" height="206" /></p>
<p class="image-caption">The scan window from Antivirus XP 2008 also looks legit. It&#8217;s also not.</p>
</div>
<p>A warning before we begin: do not boot your computer into safe mode. Leave it running as you normally would. I tried restarting into safe mode, and the malware was prepared for that&#8211;its folders and files became undetectable.</p>
<p>First, in the Start menu, click on Run. If you can&#8217;t find the Run option, hit WIN+R. (That&#8217;s the key with the Windows icon on it.)</p>
<p>Type in <strong>msconfig</strong>, and go to the Startup tab. You&#8217;re looking for two files. One begins with the string of letters &#8220;lph,&#8221; and the second begins with &#8220;rhc&#8221;. The examples provided are longer strings, &#8220;lphc35dj0e1an&#8221; and &#8220;rhc75dj0e1an&#8221;, but after the first three letters, the strings are known to change on different computers. Uncheck the boxes next to both of them, then click on Apply and OK or Close at the bottom of the window.</p>
<div class="cnet-image-div image-medium float-left"><img class="cnet-image" src="http://i.i.com.com/cnwk.1d/i/bto/20080915/antivirus_xp_2008_old_scan_270x206.jpg" alt="" width="270" height="206" /></p>
<p class="image-caption">The scan window from an older version of Antivirus XP 2008.</p>
</div>
<p>Restart your computer normally. You&#8217;ll notice that the background hasn&#8217;t changed. To restore your desktop settings, you&#8217;ll need to go to Start &gt; Run again, or Win+R. This time, type in <strong>Gpedit.msc</strong>. On the left nav, look for User Configuration near the middle. Navigate through Administrative Templates, then Control Panel, and finally Display. When you click on display, you&#8217;ll see a list of options open in the central pane. Right click on &#8220;Remove Display in Control Panel,&#8221; and click &#8220;Properties.&#8221; Then choose &#8220;Disabled.&#8221;</p>
<p>Repeat those same steps for the following attributes: Hide Desktop, Prevent changing wallpaper, Hide Appearance and Themes, Hide Settings, and Hide Screen Saver. Change all to &#8220;Disabled,&#8221; then hit Apply, OK, and restart your computer.</p>
<p>You will still see the Antivirus XP 2008 desktop &#8220;theme&#8221;, but now you can change it. Anywhere on your desktop, right-click and select properties. The first tab that opens should allow you to change your theme. If you also suffer from massive icons, use the last tab on the right, Settings. In the middle of that tab&#8217;s window you&#8217;ll see a Screen Resolution option, most likely set to 800&#215;600. Move the slider to the left to choose a more aesthetically appealing resolution.</p>
<p><a href="http://www.download.com/8301-2007_4-10041667-12.html" target="_blank">Source</a></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-shr">
<ul class="socials">
		<li class="shr-comfeed">
			<a href="http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/&amp;title=How+to+remove+Antivirus+XP+2008" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/&amp;title=How+to+remove+Antivirus+XP+2008" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/&amp;title=How+to+remove+Antivirus+XP+2008" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/&amp;title=How+to+remove+Antivirus+XP+2008" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/&amp;title=How+to+remove+Antivirus+XP+2008" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=How+to+remove+Antivirus+XP+2008+-+http://b2l.me/aa49n2&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/&amp;title=How+to+remove+Antivirus+XP+2008&amp;desc=Antivirus%20XP%202008%20is%20back%2C%20unfortunately.%20It%27s%20not%20an%20antivirus%20app%2C%20but%20a%20cleverly%20disguised%20rogue%20security%20application%20that%20tries%20to%20get%20you%20to%20buy%20the%20non-existent%20%22security%22%20it%27s%20selling.%20Advertised%20using%20the%20common%20tricks%20of%20Trojans%20and%20faux%20security%20alerts%2C%20this%20nasty%20piece%20of%20malware%20can%20take" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/&amp;bm_description=How+to+remove+Antivirus+XP+2008&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/&amp;t=How+to+remove+Antivirus+XP+2008" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://eguru.info/2008/09/how-to-remove-antivirus-xp-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
