<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Remove spyware, adware and malware &#187; Trojans</title>
	<atom:link href="http://www.spywares-remove.com/remove/trojans/feed" rel="self" type="application/rss+xml" />
	<link>http://www.spywares-remove.com</link>
	<description>Spyware removal instructions</description>
	<lastBuildDate>Thu, 09 Feb 2012 09:26:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>NetworkControl</title>
		<link>http://www.spywares-remove.com/remove-networkcontrol-networkcontrol-removal-tutorial</link>
		<comments>http://www.spywares-remove.com/remove-networkcontrol-networkcontrol-removal-tutorial#comments</comments>
		<pubDate>Thu, 05 Aug 2010 08:36:05 +0000</pubDate>
		<dc:creator>Gina</dc:creator>
				<category><![CDATA[Rogue Anti-Spyware]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Network Control]]></category>
		<category><![CDATA[NetworkControl]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=1925</guid>
		<description><![CDATA[NetworkControl is a trojan that starts its activities once installed to your computer. As common for trojan horses NetworkControl also enters the system through its flaws and makes its presence like a rogue anti-spyware. This isn’t so because it only seems you have fake anti-spyware onto your computer.

Trojan spreads in two ways: through rogue online [...]]]></description>
			<content:encoded><![CDATA[<p>NetworkControl is a trojan that starts its activities once installed to your computer. As common for trojan horses NetworkControl also enters the system through its flaws and makes its presence like a rogue anti-spyware. This isn’t so because it only seems you have fake anti-spyware onto your computer.</p>
<p><a href="http://www.spywares-remove.com/remove-networkcontrol-networkcontrol-removal-tutorial"><img class="alignnone size-full wp-image-1928" title="fake-system-restore" src="http://www.spywares-remove.com/wp-content/uploads/2010/08/fake-system-restore1.jpg" alt="" width="550" height="392" /></a></p>
<p>Trojan spreads in two ways: through rogue online anti-malware scanners and through sites that utilize exploits to automatically install the trojan onto your computer without user‘s knowledge or permission. Trojan displays various security alerts:</p>
<p><em><strong>System Restore</strong><br />
Critical System Notification<br />
Remote administrator Adam1 has changed some system files of Windows OS.<br />
Checking will take several minutes.<br />
Please do not turn off the computer &#8211; it can lead to system crash.<br />
</em></p>
<p><em><strong>Remote login request</strong><br />
Don&#8217;t allow access unless you clearly understand what you are doing.<br />
Your computer received a remote login request by user: &#8220;Adam1&#8243; from the IP &lt;ip address&gt;.<br />
<strong>Deny </strong>or <strong>Allow</strong><br />
</em></p>
<p><em><strong>Remote query of terminating application</strong><br />
Don&#8217;t allow access unless you clearly understand what you are doing.<br />
Your computer has received a remote query from IP &lt;ip address&gt; of terminating application.<br />
<strong>Allow access</strong> or <strong>Deny Access</strong><br />
</em></p>
<p><em><strong>Remote software installation</strong><br />
Don&#8217;t allow access unless you clearly understand what you are doing.<br />
Your computer has received a request from the IP &lt;ip address&gt; to install Zeus software.<br />
<strong>Block Installation</strong> or <strong>Allow installation</strong><br />
</em></p>
<p><em><strong>Unable to find installed software</strong><br />
System was unable to find installed firewall software.</em></p>
<p>This is a fraud and none of the information should be trusted. You have to ignore all fake warning messages. Do not click on any links trojan displays on pop-ups because it is a scam and not worth spending your money. Choose decent security software and remove NetworkControl as soon as possible.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/remove-networkcontrol-networkcontrol-removal-tutorial/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Mywebtattoo</title>
		<link>http://www.spywares-remove.com/remove-mywebtattoo-mywebtattoo-removal-help</link>
		<comments>http://www.spywares-remove.com/remove-mywebtattoo-mywebtattoo-removal-help#comments</comments>
		<pubDate>Wed, 30 Jun 2010 14:01:38 +0000</pubDate>
		<dc:creator>Gina</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[My web tattoo]]></category>
		<category><![CDATA[Myweb tattoo]]></category>
		<category><![CDATA[Mywebtattoo]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=1640</guid>
		<description><![CDATA[Mywebtattoo is a spyware trojan which has the only purpose to steal user’s password of online banking. Malicious spyware may also install a toolbar and generate various messages in the form of pop-ups and banners. Mywebtattoo also collects users’ profiles that are in a popular social networks and email addresses. Spyware has to be deleted [...]]]></description>
			<content:encoded><![CDATA[<p>Mywebtattoo is a spyware trojan which has the only purpose to steal user’s password of online banking. Malicious spyware may also install a toolbar and generate various messages in the form of pop-ups and banners. Mywebtattoo also collects users’ profiles that are in a popular social networks and email addresses. Spyware has to be deleted as soon as it is noticed otherwise you may have serious problems. Choose reputable security software and terminate Mywebtattoo upon detection.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/remove-mywebtattoo-mywebtattoo-removal-help/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Adobe Flash Player install</title>
		<link>http://www.spywares-remove.com/remove-fake-adobe-flash-player-install-fake-adobe-flash-player-install-removal-help</link>
		<comments>http://www.spywares-remove.com/remove-fake-adobe-flash-player-install-fake-adobe-flash-player-install-removal-help#comments</comments>
		<pubDate>Mon, 21 Jun 2010 11:09:59 +0000</pubDate>
		<dc:creator>Gina</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Fake Adobe Flash Player install]]></category>
		<category><![CDATA[Fake AdobeFlash Player]]></category>
		<category><![CDATA[FakeAdobe FlashPlayer install]]></category>
		<category><![CDATA[FakeAdobeFlashPlayerinstall]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=1551</guid>
		<description><![CDATA[Trojan.Ransomware is a trojan which covers its traces under the Adobe Flash Player’s name. it presents itself as legitimate installer, however, it is trying to commit an SMS fraud.

Once active, trojan makes a copy of itself in %ALLUSERSPROFILE% and then displays fake pop-up in Russian. Trojan tends to trick user into sending an SMS to [...]]]></description>
			<content:encoded><![CDATA[<p>Trojan.Ransomware is a trojan which covers its traces under the Adobe Flash Player’s name. it presents itself as legitimate installer, however, it is trying to commit an SMS fraud.</p>
<p><a href="http://www.spywares-remove.com/remove-fake-adobe-flash-player-install-fake-adobe-flash-player-install-removal-help"><img class="alignnone size-full wp-image-1550" title="Fake Adobe Flash Player install" src="http://www.spywares-remove.com/wp-content/uploads/2010/06/Fake-Adobe-Flash-Player-install.jpg" alt="" width="398" height="241" /></a></p>
<p>Once active, trojan makes a copy of itself in %ALLUSERSPROFILE% and then displays fake pop-up in Russian. Trojan tends to trick user into sending an SMS to receive a registration key for full installation of Adobe Flash Player application. This is a fraud. Do not believe any information this trojan displays. It only gains to get money from unwary users. You better choose decent security software and terminate the trojan that will help to get rid of annoying pop-ups.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/remove-fake-adobe-flash-player-install-fake-adobe-flash-player-install-removal-help/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lsas.Trojan-Spy.DOS.Keycopy</title>
		<link>http://www.spywares-remove.com/remove-lsas-trojan-spy-dos-keycopy-lsas-trojan-spy-dos-keycopy-removal-help</link>
		<comments>http://www.spywares-remove.com/remove-lsas-trojan-spy-dos-keycopy-lsas-trojan-spy-dos-keycopy-removal-help#comments</comments>
		<pubDate>Mon, 31 May 2010 13:31:02 +0000</pubDate>
		<dc:creator>Gina</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Lsas.Trojan-Spy.DOS.Keycopy]]></category>
		<category><![CDATA[LsasTrojanSpyDOSKeycopy]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=1392</guid>
		<description><![CDATA[Lsas.Trojan-Spy.DOS.Keycopy is a backdoor trojan. It enters the system through its vulnerabilities and makes a perfect background for malwares to sneak in, for example, Cleanup Antivirus malicious program. Lsas.Trojan-Spy.DOS.Keycopy tries to trick user into believing their computer is infected by spreading misleading information. Lsas.Trojan-Spy.DOS.Keycopy is a harmful trojan therefore it should be removed upon detection.
]]></description>
			<content:encoded><![CDATA[<p>Lsas.Trojan-Spy.DOS.Keycopy is a backdoor trojan. It enters the system through its vulnerabilities and makes a perfect background for malwares to sneak in, for example, <a href="http://www.spywares-remove.com/remove-cleanup-antivirus-cleanup-antivirus-removal-guide">Cleanup Antivirus </a>malicious program. Lsas.Trojan-Spy.DOS.Keycopy tries to trick user into believing their computer is infected by spreading misleading information. Lsas.Trojan-Spy.DOS.Keycopy is a harmful trojan therefore it should be removed upon detection.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/remove-lsas-trojan-spy-dos-keycopy-lsas-trojan-spy-dos-keycopy-removal-help/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Microsoft Windows Activation alert</title>
		<link>http://www.spywares-remove.com/remove-fake-microsoft-windows-activation-fake-microsoft-windows-activation-removal-tutorial</link>
		<comments>http://www.spywares-remove.com/remove-fake-microsoft-windows-activation-fake-microsoft-windows-activation-removal-tutorial#comments</comments>
		<pubDate>Mon, 24 May 2010 09:40:29 +0000</pubDate>
		<dc:creator>Gina</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Fake Microsoft Windows Activation]]></category>
		<category><![CDATA[Fake MicrosoftWindows Activation]]></category>
		<category><![CDATA[FakeMicrosoft WindowsActivation]]></category>
		<category><![CDATA[FakeMicrosoftWindowsActivation]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=1351</guid>
		<description><![CDATA[Fake Microsoft Windows Activation is a pop-up claiming that Windows needs to be re-activated. For this you have to enter credit card information then you are most likely infected with a ransomware infection.

The Fake Microsoft Windows Activation screen reads:
Microsoft Windows Activation
Microsoft Piracy Control
Your copy of Windows was activated by another user. To help reduce software [...]]]></description>
			<content:encoded><![CDATA[<p>Fake Microsoft Windows Activation is a pop-up claiming that Windows needs to be re-activated. For this you have to enter credit card information then you are most likely infected with a ransomware infection.</p>
<p><a href="http://www.spywares-remove.com/remove-fake-microsoft-windows-activation-fake-microsoft-windows-activation-removal-tutorial"><img class="alignnone size-full wp-image-1352" title="fake_windows_activation_alert" src="http://www.spywares-remove.com/wp-content/uploads/2010/05/fake_windows_activation_alert.jpg" alt="" width="577" height="455" /></a></p>
<p>The Fake Microsoft Windows Activation screen reads:</p>
<p><em>Microsoft Windows Activation<br />
Microsoft Piracy Control</em></p>
<p><em>Your copy of Windows was activated by another user. To help reduce software piracy, please re-activate your copy of Windows now. We will ask for your billing details, but your credit card will NOT be charged. You must activate Windows before you can continue to use it. Microsoft is committed to your privacy. For more information, www.microsoft.com/privacy.</em></p>
<p><em>Do you want to activate Windows now? </em></p>
<p>Fake Windows Activation trojan locks up your computer, disables Task Manager and provides only two options &#8220;activate windows&#8221; or &#8220;do it later&#8221;. If you click on &#8220;do it later&#8221; your computer will simply be rebooted. For terminating this ransomware choose decent security tool or follow a removal tutorial.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/remove-fake-microsoft-windows-activation-fake-microsoft-windows-activation-removal-tutorial/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flooder.Skypflood</title>
		<link>http://www.spywares-remove.com/remove-flooder-skypflood-flooder-skypflood-removal-guide</link>
		<comments>http://www.spywares-remove.com/remove-flooder-skypflood-flooder-skypflood-removal-guide#comments</comments>
		<pubDate>Tue, 27 Apr 2010 09:22:28 +0000</pubDate>
		<dc:creator>Gina</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Flooder.Skypflood]]></category>
		<category><![CDATA[FlooderSkypflood]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=1268</guid>
		<description><![CDATA[Flooder.Skypflood  is a trojan horse which enables computer users to send harmful messages and emoticons to any Skype contacts via the hotkeys. This malicious application can be found in a different names as Generic.dx!lfy (McAfee), Mal/Generic-A (Sophos), Virus.Win32.Skypflood (Ikarus), Win-Trojan/Xema.variant (AhnLab). If you want your computer stayed secure make sure you installed reputable security software [...]]]></description>
			<content:encoded><![CDATA[<p>Flooder.Skypflood  is a trojan horse which enables computer users to send harmful messages and emoticons to any Skype contacts via the hotkeys. This malicious application can be found in a different names as Generic.dx!lfy (McAfee), Mal/Generic-A (Sophos), Virus.Win32.Skypflood (Ikarus), Win-Trojan/Xema.variant (AhnLab). If you want your computer stayed secure make sure you installed reputable security software to delete this trojan.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/remove-flooder-skypflood-flooder-skypflood-removal-guide/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rustock Spambot</title>
		<link>http://www.spywares-remove.com/rustock-spambotremove-rustock-spambot-rustock-spambot-removal-help</link>
		<comments>http://www.spywares-remove.com/rustock-spambotremove-rustock-spambot-rustock-spambot-removal-help#comments</comments>
		<pubDate>Mon, 29 Mar 2010 11:21:21 +0000</pubDate>
		<dc:creator>Gina</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Rustock Spambot]]></category>
		<category><![CDATA[RustockSpambot]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=1091</guid>
		<description><![CDATA[Rustock Spambot is a trojan which is very powerful and surely unwanted. Rustock Spambot generates spam from your IP and sends them out through emails. Rustock Spambot is capable of infecting your friends’ computers through sending its malcode to people who are included on your address book You should remove Rustock Spambot trojan from your [...]]]></description>
			<content:encoded><![CDATA[<p>Rustock Spambot is a trojan which is very powerful and surely unwanted. Rustock Spambot generates spam from your IP and sends them out through emails. Rustock Spambot is capable of infecting your friends’ computers through sending its malcode to people who are included on your address book You should remove Rustock Spambot trojan from your machine in the shortest time frame possible.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/rustock-spambotremove-rustock-spambot-rustock-spambot-removal-help/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan-Dropper.Nemqe</title>
		<link>http://www.spywares-remove.com/trojan-dropper-nemqe</link>
		<comments>http://www.spywares-remove.com/trojan-dropper-nemqe#comments</comments>
		<pubDate>Fri, 22 Jan 2010 13:44:59 +0000</pubDate>
		<dc:creator>Bryan Michael</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Nemqe]]></category>
		<category><![CDATA[Trojan-Dropper.Nemqe]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=931</guid>
		<description><![CDATA[Trojan-Dropper.Nemqe is a trojan which on execution drops and installs additional malware onto the users computer.
Trojan-Dropper.Nemqe behaviour:

Sets the drive to autoplay by creating autorun.inf file in its root directory. If the drive is shared across the network then other remote computers can be infected any time they try to access this share.
Hosts file modification that [...]]]></description>
			<content:encoded><![CDATA[<p>Trojan-Dropper.Nemqe is a trojan which on execution drops and installs additional malware onto the users computer.</p>
<p>Trojan-Dropper.Nemqe behaviour:</p>
<ul>
<li>Sets the drive to autoplay by creating autorun.inf file in its root directory. If the drive is shared across the network then other remote computers can be infected any time they try to access this share.</li>
<li>Hosts file modification that may block access to the security web sites.</li>
<li>Produces outbound traffic.</li>
<li>Downloads/requests other files from Internet.</li>
<li>Registers a Browser Helper Object.</li>
<li>Contains characteristics of an identified security risk.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/trojan-dropper-nemqe/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan.FakeSmoke</title>
		<link>http://www.spywares-remove.com/trojan-fakesmoke</link>
		<comments>http://www.spywares-remove.com/trojan-fakesmoke#comments</comments>
		<pubDate>Wed, 13 Jan 2010 15:16:07 +0000</pubDate>
		<dc:creator>Bryan Michael</dc:creator>
				<category><![CDATA[Rogue Anti-Spyware]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Trojan.FakeSmoke]]></category>
		<category><![CDATA[WinBlueSoft]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=881</guid>
		<description><![CDATA[Trojan.FakeSmoke is a rogue anti-spyware product developed by WinBlueSoft. Once installed on a computer it will periodically warn the user that they get infected by some malwares, which are some non-harmful text files that dropped by itself and could only be detected by this program. It will only stop when the user buys a copy [...]]]></description>
			<content:encoded><![CDATA[<p>Trojan.FakeSmoke is a rogue anti-spyware product developed by WinBlueSoft. Once installed on a computer it will periodically warn the user that they get infected by some malwares, which are some non-harmful text files that dropped by itself and could only be detected by this program. It will only stop when the user buys a copy of the software.</p>
<p>The fake antivirus program may be known by several names: <span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl01_lblAlias">SystemCop</span>, <span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl03_lblAlias">QuickHealCleaner</span>, <span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl05_lblAlias">TrustWarrior, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl07_lblAlias">SaveArmor, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl09_lblAlias">SecureVeteran, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl11_lblAlias">SecuritySoldier, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl13_lblAlias">SafeFighter</span>, <span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl15_lblAlias">TrustSoldier</span>,<span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl17_lblAlias"> TrustFighter</span>, <span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl19_lblAlias">SoftCop, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl21_lblAlias">TRE AntiVirus, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl23_lblAlias">SoftBarrier, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl25_lblAlias">BlockKeeper, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl27_lblAlias">BlockScanner, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl29_lblAlias">BlockProtector, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl31_lblAlias">SystemFighter, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl33_lblAlias">SystemVeteran, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl35_lblAlias">SystemWarrior, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl37_lblAlias">AntiAID, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl43_lblAlias">WinBlueSoft, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl45_lblAlias">WiniBlueSoft, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl47_lblAlias">Winishield</span>, <span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl49_lblAlias">SaveKeep, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl51_lblAlias">WiniFighter, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl53_lblAlias">TrustNinja, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl55_lblAlias">SaveDefense, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl57_lblAlias">BlockDefense, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl59_lblAlias">SaveSoldier, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl61_lblAlias">WiniShield, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl63_lblAlias">SafetyKeeper, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl65_lblAlias">SoftSafeness, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl67_lblAlias">SafeDefender, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl69_lblAlias">Trustcop, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl71_lblAlias">SecureWarrior, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl73_lblAlias">SecureFighter</span>, <span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl75_lblAlias">SoftSoldier, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl77_lblAlias">SoftVeteran, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl79_lblAlias">SoftStronghold, </span><span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl81_lblAlias">ShieldSafeness, Antiadd, AntiKeep, AntiTroy, SiteAdware, IguardPC, GuardPCs, TheDefend, SysDefence, ProtectPCs, APCProtect, GreatDefender, PCsProtector, PCProtectar, InSysSecure, SysDefenders.</span></p>
<p>Aliases: Trojan.Win32.FakeSmoke [Ikarus], Trojan:Win32/FakeSmoke [Microsoft], FakeAlert-IT [McAfee], <span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl39_lblAlias">Win32/WinBlueSoft.A</span> [<span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl39_lblVendor">CA</span>], <span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl41_lblAlias">Trojan-Downloader.Win32.FraudLoad.vtgpk</span> [<span id="ctl00_ctl00_pageContent_contentTop_ctl00_contenttop_repAliases_ctl41_lblVendor">Kaspersky</span>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/trojan-fakesmoke/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zbot</title>
		<link>http://www.spywares-remove.com/trojan-zbot-infostealer-banker</link>
		<comments>http://www.spywares-remove.com/trojan-zbot-infostealer-banker#comments</comments>
		<pubDate>Tue, 12 Jan 2010 10:44:54 +0000</pubDate>
		<dc:creator>Bryan Michael</dc:creator>
				<category><![CDATA[Keyloggers]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Infostealer.Banker.C]]></category>
		<category><![CDATA[Trojan.Zbot]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=873</guid>
		<description><![CDATA[Trojan.Zbot is a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system. Zbot produces outbound traffic and downloads other files from Internet.
Aliases:Trojan.Zbot [Ikarus], Infostealer.Banker.C [Symantec], PWS:Win32/Zbot.gen [Microsoft]
]]></description>
			<content:encoded><![CDATA[<p>Trojan.Zbot is a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system. Zbot produces outbound traffic and downloads other files from Internet.</p>
<p>Aliases:Trojan.Zbot [Ikarus], Infostealer.Banker.C [Symantec], PWS:Win32/Zbot.gen [Microsoft]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/trojan-zbot-infostealer-banker/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan-PWS.Dytka</title>
		<link>http://www.spywares-remove.com/trojan-pws-dytka-infostealer-gampass</link>
		<comments>http://www.spywares-remove.com/trojan-pws-dytka-infostealer-gampass#comments</comments>
		<pubDate>Mon, 11 Jan 2010 14:52:06 +0000</pubDate>
		<dc:creator>Bryan Michael</dc:creator>
				<category><![CDATA[Keyloggers]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Infostealer.Gampass]]></category>
		<category><![CDATA[Trojan-PSW.Win32.Dytka.ax]]></category>
		<category><![CDATA[Trojan-PWS.Dytka]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=866</guid>
		<description><![CDATA[Trojan-PWS.Dytka is a threat that tries to terminate anti-virus applications and monitor user activities in hopes to obtain valuable information from the affected user. It&#8217;s a  malicious backdoor trojan that runs in the background and allows remote access to the compromised system. Trojan-PWS.Dytka is a password stealer.
Aliases:Trojan-PSW.Gampass [PCTools], Infostealer.Gampass [Symantec], Backdoor.Win32.Inject.bus [Kaspersky Lab], Trojan-PSW.Win32.Dytka.ax [...]]]></description>
			<content:encoded><![CDATA[<p>Trojan-PWS.Dytka is a threat that tries to terminate anti-virus applications and monitor user activities in hopes to obtain valuable information from the affected user. It&#8217;s a  malicious backdoor trojan that runs in the background and allows remote access to the compromised system. Trojan-PWS.Dytka is a password stealer.</p>
<p>Aliases:Trojan-PSW.Gampass [PCTools], Infostealer.Gampass [Symantec], Backdoor.Win32.Inject.bus [Kaspersky Lab], Trojan-PSW.Win32.Dytka.ax [Kaspersky Lab</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/trojan-pws-dytka-infostealer-gampass/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lsas.Trojan-Spy.DOS.Keycopy</title>
		<link>http://www.spywares-remove.com/remove-lsastrojan-spydoskeycopy</link>
		<comments>http://www.spywares-remove.com/remove-lsastrojan-spydoskeycopy#comments</comments>
		<pubDate>Tue, 23 Jun 2009 08:38:15 +0000</pubDate>
		<dc:creator>Jason J</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Lsas.Trojan-Spy.DOS.Keycopy]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/?p=624</guid>
		<description><![CDATA[Lsas.Trojan-Spy.DOS.Keycopy is a false security warning that appears in order to scare the user into purchasing a rogue-antispyware application Malware Destructor 2009. Lsas.Trojan-Spy.DOS.Keycopy produces this message:
WINDOWS SECURITY ALERT!
Lsas.Trojan-Spy.DOS.Keycopy is suspected to have infected your PC.
This type of virus intercepts entered data and transmits it to a remote server.
Windows Internet Explorer 8
“C:\WINDOWS\ie8\spuninst
Data interception was detected while [...]]]></description>
			<content:encoded><![CDATA[<p>Lsas.Trojan-Spy.DOS.Keycopy is a false security warning that appears in order to scare the user into purchasing a rogue-antispyware application <a title="Remove Malware Destructor 2009" href="http://www.spywares-remove.com/remove-malware-destructor-2009-malware-destructor-2009-removal">Malware Destructor 2009</a>. Lsas.Trojan-Spy.DOS.Keycopy produces this message:</p>
<p><strong>WINDOWS SECURITY ALERT!</strong><br />
<em>Lsas.Trojan-Spy.DOS.Keycopy is suspected to have infected your PC.<br />
This type of virus intercepts entered data and transmits it to a remote server.<br />
Windows Internet Explorer 8<br />
“C:\WINDOWS\ie8\spuninst<br />
Data interception was detected while visiting a website: http://</em></p>
<p>This is a fake security warning that should be taken only as a sign that your computer is infected with Malware Destructor 2009 which is an actual system virus. In order to remove  Malware Destructor 2009 from your computer please follow the instructions bellow.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/remove-lsastrojan-spydoskeycopy/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Admess.Trojan</title>
		<link>http://www.spywares-remove.com/remove-admesstrojan</link>
		<comments>http://www.spywares-remove.com/remove-admesstrojan#comments</comments>
		<pubDate>Tue, 20 Jan 2009 09:08:52 +0000</pubDate>
		<dc:creator>luciana</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Admess]]></category>
		<category><![CDATA[Admess.Trojan]]></category>
		<category><![CDATA[System Security]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/remove-admesstrojan</guid>
		<description><![CDATA[Pop-ups related to Admess.Trojan don’t indicate a trojan, they are symptom of System Security infection. SystemSecurity is not a real anti-spyware. It’s only capable of loading fake alerts warning people about nonexistent threats like Admess.Trojan and Zserv.Transponder.Trojan.
Don’t trust SystemSecurity and don’t pay for deleting a trojan which doesn’t even exist.
Click here to remove System Security [...]]]></description>
			<content:encoded><![CDATA[<p>Pop-ups related to Admess.Trojan don’t indicate a trojan, they are symptom of System Security infection. SystemSecurity is not a real anti-spyware. It’s only capable of loading fake alerts warning people about nonexistent threats like Admess.Trojan and <a href="http://www.spywares-remove.com/remove-zservtranspondertrojan">Zserv.Transponder.Trojan</a>.</p>
<p>Don’t trust SystemSecurity and don’t pay for deleting a trojan which doesn’t even exist.</p>
<p><a href="http://www.spywares-remove.com/remove-system-security">Click here to remove System Security scam</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/remove-admesstrojan/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zserv.Transponder.Trojan</title>
		<link>http://www.spywares-remove.com/remove-zservtranspondertrojan</link>
		<comments>http://www.spywares-remove.com/remove-zservtranspondertrojan#comments</comments>
		<pubDate>Tue, 20 Jan 2009 08:22:54 +0000</pubDate>
		<dc:creator>luciana</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[System Security]]></category>
		<category><![CDATA[Zserv.Transponder]]></category>
		<category><![CDATA[Zserv.Transponder.Trojan]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/remove-zservtranspondertrojan</guid>
		<description><![CDATA[There is no need to worry about Zserv.Transponder.Trojan because a trojan like that doesn’t exist. Zserv.Transponder is only detected by System Security program and other corrupt security tools.
SystemSecurity is a fake anti-spyware; it reports fake infections in order to make people interested in buying a license of the program. If you see pop-ups about Zserv.Transponder.Trojan [...]]]></description>
			<content:encoded><![CDATA[<p>There is no need to worry about Zserv.Transponder.Trojan because a trojan like that doesn’t exist. Zserv.Transponder is only detected by System Security program and other corrupt security tools.</p>
<p>SystemSecurity is a fake anti-spyware; it reports fake infections in order to make people interested in buying a license of the program. If you see pop-ups about Zserv.Transponder.Trojan on your screen, it’s a sign of malware infection. Remove System security to get rid of the pop-ups.</p>
<p><a href="http://www.spywares-remove.com/remove-system-security">Follow this link to remove System Security scam</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/remove-zservtranspondertrojan/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sheur.hsf</title>
		<link>http://www.spywares-remove.com/sheurhsf</link>
		<comments>http://www.spywares-remove.com/sheurhsf#comments</comments>
		<pubDate>Fri, 16 Jan 2009 13:34:27 +0000</pubDate>
		<dc:creator>luciana</dc:creator>
				<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Sheur.hsf]]></category>

		<guid isPermaLink="false">http://www.spywares-remove.com/sheurhsf</guid>
		<description><![CDATA[Sheur.hsf trojan is dangerous for privacy and security of user. Sheur trojan may cause identity theft as it collects sensitive information and delivers it to a remote server. The infection is also able to download other malwares. Sheur.hsf usually downloads corrupt security programs that urge to pay for using them.
Run antispyware scan if you notice [...]]]></description>
			<content:encoded><![CDATA[<p>Sheur.hsf trojan is dangerous for privacy and security of user. Sheur trojan may cause identity theft as it collects sensitive information and delivers it to a remote server. The infection is also able to download other malwares. Sheur.hsf usually downloads corrupt security programs that urge to pay for using them.</p>
<p>Run antispyware scan if you notice new applications installed without your permission.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywares-remove.com/sheurhsf/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

