<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>malwarecrawler.com</title>
	<atom:link href="http://malwarecrawler.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://malwarecrawler.com</link>
	<description>Malware Monitoring Blog</description>
	<lastBuildDate>Tue, 23 Feb 2010 19:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>my_virtual_c facebook application. Self propagating spam/worm?</title>
		<link>http://malwarecrawler.com/?p=275</link>
		<comments>http://malwarecrawler.com/?p=275#comments</comments>
		<pubDate>Tue, 23 Feb 2010 16:57:19 +0000</pubDate>
		<dc:creator>Baz</dc:creator>
				<category><![CDATA[Malware Related]]></category>
		<category><![CDATA[bit.ly]]></category>
		<category><![CDATA[delete]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[get rid of]]></category>
		<category><![CDATA[my_virtual_c]]></category>
		<category><![CDATA[notification]]></category>
		<category><![CDATA[remove]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[what is]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://malwarecrawler.com/?p=275</guid>
		<description><![CDATA[Being an avid facebook user myself, I was quite interested today to find that one of my friends had supposedly commented on a photo of me. I logged in, and checked my notifications feed&#8230;and sure enough, there was a notification about a photo comment: Looks legit, doesn&#8217;t it? Checking the address bar revealed something very [...]]]></description>
		<wfw:commentRss>http://malwarecrawler.com/?feed=rss2&amp;p=275</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>How to remove/delete Security Tool virus/malware</title>
		<link>http://malwarecrawler.com/?p=262</link>
		<comments>http://malwarecrawler.com/?p=262#comments</comments>
		<pubDate>Wed, 18 Nov 2009 21:08:44 +0000</pubDate>
		<dc:creator>Baz</dc:creator>
				<category><![CDATA[Malware Related]]></category>
		<category><![CDATA[1e9e29317c18ad84953357e2f5779085]]></category>
		<category><![CDATA[BackDoor.Netbus]]></category>
		<category><![CDATA[delete]]></category>
		<category><![CDATA[get rid of]]></category>
		<category><![CDATA[Harmful software detected]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[paybillusa.com]]></category>
		<category><![CDATA[remove]]></category>
		<category><![CDATA[rogue]]></category>
		<category><![CDATA[Security Tool]]></category>
		<category><![CDATA[Security Tool Warning]]></category>
		<category><![CDATA[SecurityTool]]></category>
		<category><![CDATA[Spyware.IEmonster activity detected]]></category>
		<category><![CDATA[uninstall]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Virus.Dos.Criminal]]></category>

		<guid isPermaLink="false">http://malwarecrawler.com/?p=262</guid>
		<description><![CDATA[Yet another &#8220;fake antivirus&#8221; type threat is currently doing the rounds. This one is called Security Tool. The installer was downloaded from utilitiesdiscounts.com, which operates an &#8220;affiliate tracking&#8221; download server, with the scammers getting paid for every person they infect. When the installer is run, a randomly named folder consisting of numbers is created in [...]]]></description>
		<wfw:commentRss>http://malwarecrawler.com/?feed=rss2&amp;p=262</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to remove/delete Secure Keeper virus/malware</title>
		<link>http://malwarecrawler.com/?p=255</link>
		<comments>http://malwarecrawler.com/?p=255#comments</comments>
		<pubDate>Wed, 18 Nov 2009 20:22:52 +0000</pubDate>
		<dc:creator>Baz</dc:creator>
				<category><![CDATA[Malware Related]]></category>
		<category><![CDATA[08276428e07ef2ddc74cb03f48c4cbf1]]></category>
		<category><![CDATA[3c20e6c5476cd87e961c3005b258247c]]></category>
		<category><![CDATA[a03f23a464c2f798315fe8c8447dfc31]]></category>
		<category><![CDATA[delete]]></category>
		<category><![CDATA[get rid of]]></category>
		<category><![CDATA[remove]]></category>
		<category><![CDATA[SecureKeeper Software]]></category>
		<category><![CDATA[SecureKeeper.exe]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[uninstall]]></category>
		<category><![CDATA[your computer is at risk]]></category>

		<guid isPermaLink="false">http://malwarecrawler.com/?p=255</guid>
		<description><![CDATA[Another new rogue to hit the internet is called Secure Keeper. SecureKeeper is downloaded in a similar way to the other rogues I have blogged about previously. The installer was downloded from pinggost.com/download/ and promptly proceeded to take over the computer. A randomly named file, such as KXRC7FOZ.exe is dropped into C:\DOCUMENTS AND SETTINGS\USERNAME\LOCAL SETTINGS\TEMP\, [...]]]></description>
		<wfw:commentRss>http://malwarecrawler.com/?feed=rss2&amp;p=255</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IOBit accused of stealing proprietary Malwarebytes database</title>
		<link>http://malwarecrawler.com/?p=249</link>
		<comments>http://malwarecrawler.com/?p=249#comments</comments>
		<pubDate>Tue, 03 Nov 2009 00:50:13 +0000</pubDate>
		<dc:creator>Baz</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[360]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[chinese]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[illegal]]></category>
		<category><![CDATA[IOBit]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[mbam]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[signatures]]></category>
		<category><![CDATA[stealing]]></category>
		<category><![CDATA[truth]]></category>
		<category><![CDATA[vendor]]></category>

		<guid isPermaLink="false">http://malwarecrawler.com/?p=249</guid>
		<description><![CDATA[Marcin Kleczynski, CEO of Malwarebytes, has posted a detailed accusation, presenting evidence that IOBit (A Chinese security vendor) is stealing the Malwarebytes database of threats. IOBit, based in Chengdu, provide a product called IOBit Security 360. Kleczynski, CEO of Malwarebytes Corporation, had this to say on the company blog: &#8220;We came across a post on [...]]]></description>
		<wfw:commentRss>http://malwarecrawler.com/?feed=rss2&amp;p=249</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Blog currently dormant</title>
		<link>http://malwarecrawler.com/?p=246</link>
		<comments>http://malwarecrawler.com/?p=246#comments</comments>
		<pubDate>Mon, 26 Oct 2009 10:20:58 +0000</pubDate>
		<dc:creator>Baz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://malwarecrawler.com/?p=246</guid>
		<description><![CDATA[Just thought I&#8217;d add, that I haven&#8217;t abandoned this blog completely, just taking some time out to pursue other stuff. Will be back pretty soon Oh, and siteadvisor finally did sort themselves out about a month and a half later, with the help of a number of my security friends. Thanks a million guys! ~Baz.]]></description>
		<wfw:commentRss>http://malwarecrawler.com/?feed=rss2&amp;p=246</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Siteadvisor false alarm on my website</title>
		<link>http://malwarecrawler.com/?p=239</link>
		<comments>http://malwarecrawler.com/?p=239#comments</comments>
		<pubDate>Thu, 13 Aug 2009 15:14:57 +0000</pubDate>
		<dc:creator>Baz</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[red]]></category>
		<category><![CDATA[siteadvisor]]></category>

		<guid isPermaLink="false">http://malwarecrawler.com/?p=239</guid>
		<description><![CDATA[Some users of the siteadvisor tool have reported to me that siteadvisor is incorrectly identifying this website as &#8220;red&#8221; (dangerous). I would like to reassure all visitors that this website is completely safe and there is no dangerous content hosted here. They have mistakenly identified a virus removal tool I am hosting as malicious, and [...]]]></description>
		<wfw:commentRss>http://malwarecrawler.com/?feed=rss2&amp;p=239</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove/get rid of Windows Security Suite malware/spyware</title>
		<link>http://malwarecrawler.com/?p=215</link>
		<comments>http://malwarecrawler.com/?p=215#comments</comments>
		<pubDate>Mon, 06 Jul 2009 22:19:38 +0000</pubDate>
		<dc:creator>Baz</dc:creator>
				<category><![CDATA[Custom descriptions of malware]]></category>
		<category><![CDATA[Malware Related]]></category>
		<category><![CDATA[activex]]></category>
		<category><![CDATA[alert]]></category>
		<category><![CDATA[fake]]></category>
		<category><![CDATA[get rid of]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[infected]]></category>
		<category><![CDATA[infection]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[remove]]></category>
		<category><![CDATA[Rogue.WindowsSecuritySuite]]></category>
		<category><![CDATA[search-gala.com]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[spyware.IEmonster.d]]></category>
		<category><![CDATA[Suite]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Windows Security Suite]]></category>
		<category><![CDATA[windowssecuritysuite.com]]></category>
		<category><![CDATA[winss.cfg]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://malwarecrawler.com/?p=215</guid>
		<description><![CDATA[A new variant of fake antivirus software has just gone live on the internet. It goes by the name of Windows Security Suite. Their website (windowssecuritysuite.com) may look quite polished but none of their claims are true and all &#8220;awards&#8221; and statistics have been stolen from other websites. If you have come to my website [...]]]></description>
		<wfw:commentRss>http://malwarecrawler.com/?feed=rss2&amp;p=215</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>MalwareCleaner 2009 &#8211; How to remove/delete/get rid of this nasty fake software</title>
		<link>http://malwarecrawler.com/?p=176</link>
		<comments>http://malwarecrawler.com/?p=176#comments</comments>
		<pubDate>Wed, 22 Apr 2009 00:07:11 +0000</pubDate>
		<dc:creator>Baz</dc:creator>
				<category><![CDATA[Custom descriptions of malware]]></category>
		<category><![CDATA[Malware Related]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[571613]]></category>
		<category><![CDATA[571613.exe]]></category>
		<category><![CDATA[bcaumiqw.exe]]></category>
		<category><![CDATA[C:\grubxp\]]></category>
		<category><![CDATA[c:\grubxp\571613.exe]]></category>
		<category><![CDATA[delete]]></category>
		<category><![CDATA[fake]]></category>
		<category><![CDATA[gappbmks.com]]></category>
		<category><![CDATA[get rid of]]></category>
		<category><![CDATA[grubxp]]></category>
		<category><![CDATA[gybdxtog.dll]]></category>
		<category><![CDATA[heqsjbv.exe]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[how to delete malware cleaner]]></category>
		<category><![CDATA[killkr.exe]]></category>
		<category><![CDATA[lised.dll]]></category>
		<category><![CDATA[lujogyl.scr]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Malware Cleaner]]></category>
		<category><![CDATA[Malware Cleaner 2009]]></category>
		<category><![CDATA[MalwareCleaner Technologies]]></category>
		<category><![CDATA[malwarecleaner2009.com]]></category>
		<category><![CDATA[mc_home.exe]]></category>
		<category><![CDATA[mwhbmksa.com]]></category>
		<category><![CDATA[mysfoxc.exe]]></category>
		<category><![CDATA[ojvceq.scr]]></category>
		<category><![CDATA[pdfdlcox.scr]]></category>
		<category><![CDATA[peimbj.exe]]></category>
		<category><![CDATA[pidekwim.com]]></category>
		<category><![CDATA[pqsgeijl.scr]]></category>
		<category><![CDATA[qornq.com]]></category>
		<category><![CDATA[qrpsv.scr]]></category>
		<category><![CDATA[remove]]></category>
		<category><![CDATA[rkmvnwtq.dll]]></category>
		<category><![CDATA[rkvxcdcn.com]]></category>
		<category><![CDATA[rndwvgl.com]]></category>
		<category><![CDATA[rogue]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[seedp.exe]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[toiqqpd.scr]]></category>
		<category><![CDATA[upxbei.exe]]></category>
		<category><![CDATA[usjkeulr.com]]></category>
		<category><![CDATA[uysfwa.exe]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[wtadnnyj.scr]]></category>
		<category><![CDATA[wtgfuvbd.dll]]></category>

		<guid isPermaLink="false">http://malwarecrawler.com/?p=176</guid>
		<description><![CDATA[Late this evening I got news that a new rogue threat from the same branch of &#8220;Fake anti-virus&#8221; malware such as Personal AntiVirus and Antivirus 360 had just been seen in the wild. I decided to take a close look at the software touting itself as &#8220;MalwareCleaner 2009&#8243;. Straight away upon visiting their website, malwarecleaner2009.com, [...]]]></description>
		<wfw:commentRss>http://malwarecrawler.com/?feed=rss2&amp;p=176</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>securityhelpcenter.com &#8211; Hijacking search results and making the good guys look bad</title>
		<link>http://malwarecrawler.com/?p=166</link>
		<comments>http://malwarecrawler.com/?p=166#comments</comments>
		<pubDate>Sat, 18 Apr 2009 17:31:16 +0000</pubDate>
		<dc:creator>Baz</dc:creator>
				<category><![CDATA[Malware Related]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[alert]]></category>
		<category><![CDATA[block.php]]></category>
		<category><![CDATA[fake warning]]></category>
		<category><![CDATA[internetsoftwarepayments.com]]></category>
		<category><![CDATA[networksecurityadvice.com]]></category>
		<category><![CDATA[securityhelpcenter.com]]></category>
		<category><![CDATA[unprotected]]></category>

		<guid isPermaLink="false">http://malwarecrawler.com/?p=166</guid>
		<description><![CDATA[After posting my recent article on Personal Antivirus, I noticed something strange- A number of people were coming to my site from the link http://securityhelpcenter.com/block.php?id=2006-60&#038;url=http://malwarecrawler.com/?p=146 The website seemed to have a strange name and the block.php part of the url got me slightly suspicious. I decided to investigate futher and saw something which was both [...]]]></description>
		<wfw:commentRss>http://malwarecrawler.com/?feed=rss2&amp;p=166</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>PAV- Personal AntiVirus, another rogue software, how to remove/delete/get rid of it</title>
		<link>http://malwarecrawler.com/?p=146</link>
		<comments>http://malwarecrawler.com/?p=146#comments</comments>
		<pubDate>Sat, 18 Apr 2009 14:09:11 +0000</pubDate>
		<dc:creator>Baz</dc:creator>
				<category><![CDATA[Malware Related]]></category>
		<category><![CDATA[6cleanspyware.com]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[antispywarepcscanner.com]]></category>
		<category><![CDATA[block.php]]></category>
		<category><![CDATA[C:\$Recycle.Bin\]]></category>
		<category><![CDATA[C:\program files\pav\pav.exe]]></category>
		<category><![CDATA[C:\Program Files\PersonalAV\Security Software.exe]]></category>
		<category><![CDATA[C:\windows\system32\wincontrol.dll]]></category>
		<category><![CDATA[delete]]></category>
		<category><![CDATA[delete pav]]></category>
		<category><![CDATA[get rid of]]></category>
		<category><![CDATA[how to remove pav.exe]]></category>
		<category><![CDATA[infected]]></category>
		<category><![CDATA[internetsafebrowsing.com]]></category>
		<category><![CDATA[internetsafebrowsinghelp.com]]></category>
		<category><![CDATA[internetsoftwarepayments.com]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[msxmlm.dll]]></category>
		<category><![CDATA[Net-worm.win32.kido]]></category>
		<category><![CDATA[NetFilter.exe]]></category>
		<category><![CDATA[networksecurityadvice.com]]></category>
		<category><![CDATA[pav]]></category>
		<category><![CDATA[pav.exe]]></category>
		<category><![CDATA[personal]]></category>
		<category><![CDATA[personal antivirus]]></category>
		<category><![CDATA[remove]]></category>
		<category><![CDATA[remove pav]]></category>
		<category><![CDATA[rogue]]></category>
		<category><![CDATA[Security Software.exe]]></category>
		<category><![CDATA[securityhelpcenter.com]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[wincontrol.dll]]></category>
		<category><![CDATA[wincontrol[1].dll]]></category>
		<category><![CDATA[winexplorer.dll]]></category>

		<guid isPermaLink="false">http://malwarecrawler.com/?p=146</guid>
		<description><![CDATA[Update: To all of the readers getting a warning like this one from your browsers, stating my site is dangerous- Do not believe it- it is a trick by the personal antivirus infection to scare you away from getting information on how to remove this infection. It is designed to be a convincing mock up [...]]]></description>
		<wfw:commentRss>http://malwarecrawler.com/?feed=rss2&amp;p=146</wfw:commentRss>
		<slash:comments>156</slash:comments>
		</item>
	</channel>
</rss>
