<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0.7" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Prevent Online Threats</title>
	<link>http://www.preventonlinethreats.com</link>
	<description>Educate yourself on what you can do to prevent online threats</description>
	<pubDate>Sat, 05 Jul 2008 15:50:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.7</generator>
	<language>en</language>
			<item>
		<title>Win32.Evol</title>
		<link>http://www.preventonlinethreats.com/virus-threats/win32-evol/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/win32-evol/#comments</comments>
		<pubDate>Sat, 05 Jul 2008 15:50:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category>Virus Threats</category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=4755</guid>
		<description><![CDATA[Details
Win32.Evol.a
This is a family of parasitic polymorphic per-process memory resident Win32 viruses. When an infected file is executed, the viruses run an infection routine as a separate thread that searches and infects files in the background up to the moment the host program exits.
The viruses infect Win32 PE executable files with .EXE and .SCR extensions. [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/win32-evol/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Win32.Ev</title>
		<link>http://www.preventonlinethreats.com/virus-threats/win32-ev/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/win32-ev/#comments</comments>
		<pubDate>Sat, 05 Jul 2008 11:50:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category>Virus Threats</category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=4754</guid>
		<description><![CDATA[Details
Win32.Eva
This is a direct action (non-memory resident) parasitic Win32 infector. It searches for PE EXE files in the Windows, Windows system and current directories, then writes itself to the end of the file.
While infecting, the virus does not modify the PE header at all. The infection process is based only on a DOS Stub header: [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/win32-ev/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Win32.Eta</title>
		<link>http://www.preventonlinethreats.com/virus-threats/win32-eta/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/win32-eta/#comments</comments>
		<pubDate>Sat, 05 Jul 2008 07:50:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category>Virus Threats</category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=4753</guid>
		<description><![CDATA[Details
Win32.Etap
Etap is a very complex parasitic {high-polymorphic:Poly} Win32 virus that uses the entry-point obscuring technique. The virus infects Windows executable files (Win32 PE EXE). When run the virus searches for these files and infects them.
Replication
The virus searches for Win32 PE executable files in the current directory and in the directories located in the three levels [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/win32-eta/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Win32.Enumiacs.665</title>
		<link>http://www.preventonlinethreats.com/virus-threats/win32-enumiacs-665/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/win32-enumiacs-665/#comments</comments>
		<pubDate>Sat, 05 Jul 2008 03:50:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category>Virus Threats</category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=4752</guid>
		<description><![CDATA[Details
Win32.Enumiacs.6656
It is not a dangerous memory resident parasitic Windows virus. It replicates under Win32: stays in the system memory and infects PE EXE files that are run. The virus has anti-anti-virus ability: it searches for AVP Monitor window and terminates it. The virus does not manifest itself in any other way. It contains the text [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/win32-enumiacs-665/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Win32.Ennumi.276</title>
		<link>http://www.preventonlinethreats.com/virus-threats/win32-ennumi-276/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/win32-ennumi-276/#comments</comments>
		<pubDate>Fri, 04 Jul 2008 23:50:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category>Virus Threats</category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=4751</guid>
		<description><![CDATA[Details
Win32.Ennumi.2761
This is a dangerous non memory-resident Win32 virus.
It searches all hard drives for PE files to infect.
It searches the Windows directory for a file named immune. If this file exists, the virus will not infect anything.
When infecting, the virus writes itself to the end of files.
Infection depends on the time shown by the local system [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/win32-ennumi-276/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Win32.Emotion</title>
		<link>http://www.preventonlinethreats.com/virus-threats/win32-emotion/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/win32-emotion/#comments</comments>
		<pubDate>Fri, 04 Jul 2008 19:50:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category>Virus Threats</category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=4750</guid>
		<description><![CDATA[Details
Win32.Emotion.a
This is a companion virus. While infecting it searches for .EXE files in the current and Windows directory, renames .EXE file with BIN extension and writes its code with the original name of infected file. The virus is the Windows32 PE executable program, but it is able to infect EXE files of any format (DOS, [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/win32-emotion/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Win32.Elkern</title>
		<link>http://www.preventonlinethreats.com/virus-threats/win32-elkern/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/win32-elkern/#comments</comments>
		<pubDate>Fri, 04 Jul 2008 11:50:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category>Virus Threats</category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=4748</guid>
		<description><![CDATA[Details
Win32.Elkern.c
This is a harmless encoded resident Win32 virus.
It repeatedly searches the current directory, hard and network disks, and all accessible network resources for Win32 (PE exe files) with the extensions .exe and .scr.
The virus infects files in a similar way to Win95.CIH, by writing itself to the file in sections.
After launching itself, the virus remains [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/win32-elkern/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Win32.Drol.5337</title>
		<link>http://www.preventonlinethreats.com/virus-threats/win32-drol-5337/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/win32-drol-5337/#comments</comments>
		<pubDate>Fri, 04 Jul 2008 07:50:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category>Virus Threats</category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=4747</guid>
		<description><![CDATA[Details
Win32.Drol.5337.c
Win32.Drol.5337.c is a dangerous Win32 virus.
It searches the current directory, the Windows directory and the Windows system directory for PE EXE files, and infects them.
The virus is 5337 bytes in size.
When infecting files it writes itself to the end of the file and changes the name of the file section at random.
It does not infect [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/win32-drol-5337/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Win32.Drol.5337</title>
		<link>http://www.preventonlinethreats.com/virus-threats/win32-drol-5337/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/win32-drol-5337/#comments</comments>
		<pubDate>Fri, 04 Jul 2008 03:50:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category>Virus Threats</category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=4746</guid>
		<description><![CDATA[Details
Win32.Drol.5337.a
This is a harmful, non-resident, non-encoded Windows virus, which is related to the viruses Hatred and Undertaker. When an infected file is launched, the virus gains control; it then searches for executable Win32 (PE EXE files) in the current directory, the Windows root and system directories and infects the files found. The infection procedure contains [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/win32-drol-5337/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Win32.Drol.5337</title>
		<link>http://www.preventonlinethreats.com/virus-threats/win32-drol-5337/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/win32-drol-5337/#comments</comments>
		<pubDate>Thu, 03 Jul 2008 23:50:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category>Virus Threats</category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=4745</guid>
		<description><![CDATA[Details
Win32.Drol.5337.a
It is a dangerous nonmemory resident not encrypted parasitic Windows virus related to already known Win32 viruses &#8220;Hatred&#8221; and &#8220;Undertaker&#8221;.
When an infected EXE files is executed, the virus gets control, searches for PE EXE files (Windows32 executable) in current, Windows and Windows system directories, then writes itself into the middle of the file between last [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/win32-drol-5337/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
