<?xml version="1.0"?><!-- generator="bbPress" -->

<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
<title>Giveaway of the Day Forums Tag: Root</title>
<link>http://www.giveawayoftheday.com/forums/</link>
<description>Giveaway of the Day Forums Tag: Root</description>
<language>en</language>
<pubDate>Mon, 06 Oct 2008 14:02:33 +0000</pubDate>

<item>
<title>gracie20 on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/5#post-40577</link>
<pubDate>Fri, 22 Aug 2008 06:30:46 +0000</pubDate>
<dc:creator>gracie20</dc:creator>
<guid isPermaLink="false">40577@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;I am getting a Trojan alert in my system. what should i do? Please reply. &#60;/p&#62;
&#60;p&#62;Gracie Sh&#60;br /&#62;
&#60;a href=&#34;http://hdtvlcdplasma.com&#34; rel=&#34;nofollow&#34;&#62;http://hdtvlcdplasma.com&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>skeptic on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/5#post-40347</link>
<pubDate>Mon, 18 Aug 2008 02:53:16 +0000</pubDate>
<dc:creator>skeptic</dc:creator>
<guid isPermaLink="false">40347@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;Still no word from the GOTD team. it is now over 4 hours since I tried to post on the current giveaway comments section. My comment has not been posted.&#60;br /&#62;
This will not go away!&#60;br /&#62;
If this silence continue, I will notify all tech newsletters and magazines that I subscribed to. They include: PC WORLD, PC Magazine, Windows Secrets and a dozen more.
&#60;/p&#62;</description>
</item>
<item>
<title>crysisevolved on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/5#post-40346</link>
<pubDate>Mon, 18 Aug 2008 02:44:43 +0000</pubDate>
<dc:creator>crysisevolved</dc:creator>
<guid isPermaLink="false">40346@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;Yea I got spyware on this latest download. This is the first time I have ever used GAOTD....and I am disappointed. Since I really liked this site, I recommended it to some friends once I found out about it. I now told them they packed spyware in their downloads, and not to visit the website. I have AVG and it tells me this, along with adaware2008
&#60;/p&#62;</description>
</item>
<item>
<title>JDPower on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/5#post-40345</link>
<pubDate>Mon, 18 Aug 2008 01:39:53 +0000</pubDate>
<dc:creator>JDPower</dc:creator>
<guid isPermaLink="false">40345@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;So no comment from GAOTD on this matter (neither here or on the comments for today's giveaway), very disappointing. Personally I'd have pulled the download straight away which only leaves two explanations for the silence - either GAOTD knew about the spyware in todays download and don't care, or they are getting paid well to add this spyware software in their giveaways. Either way it seems GAOTD are no longer trustworthy (and fully deserve to go back to being a red listed site with McAfee Site Advisor)
&#60;/p&#62;</description>
</item>
<item>
<title>GAOTD lover to hater in 1 day on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/5#post-40337</link>
<pubDate>Sun, 17 Aug 2008 21:12:15 +0000</pubDate>
<dc:creator>GAOTD lover to hater in 1 day</dc:creator>
<guid isPermaLink="false">40337@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;As jstone says: &#34;Today's (8/17/08) giveaway, Plato iPod PSP 3GP Converter (http://www.giveawayoftheday.com/plato-ipod-psp-3gp-converter/) contains spyware called &#34;RelevantKnowledge&#34;.&#60;/p&#62;
&#60;p&#62;There's no need for a detection scan as it actually pops up a screen *telling* you this at the beginning of the install (albeit in tiny print).&#34;&#60;/p&#62;
&#60;p&#62;This has totally destroyed my confidence in GAOTD. Despite their claims, they obviously DO NOT check the software carefully enough. I have recommended this site to several non-technical friends and now I'll have to advise them that it can no longer be trusted.&#60;/p&#62;
&#60;p&#62;As of now GAOTD is gone from my bookmarks. Some may say that it's only one instance but that is one instance too many. A sad day indeed.
&#60;/p&#62;</description>
</item>
<item>
<title>jstone on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/5#post-40321</link>
<pubDate>Sun, 17 Aug 2008 15:41:53 +0000</pubDate>
<dc:creator>jstone</dc:creator>
<guid isPermaLink="false">40321@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;Today's (8/17/08) giveaway, Plato iPod PSP 3GP Converter (http://www.giveawayoftheday.com/plato-ipod-psp-3gp-converter/) contains spyware called &#34;RelevantKnowledge&#34;.&#60;/p&#62;
&#60;p&#62;There's no need for a detection scan as it actually pops up a screen *telling* you this at the beginning of the install (albeit in tiny print).&#60;/p&#62;
&#60;p&#62;You can find more information about this particular spyware at &#60;a href=&#34;http://www.benedelman.org/news/062907-1.html&#34; rel=&#34;nofollow&#34;&#62;http://www.benedelman.org/news/062907-1.html&#60;/a&#62; among other places.&#60;/p&#62;
&#60;p&#62;According to the message at the beginning of this topic, &#34;The GOTD Team do scan the giveaways prior to making them available, using multiple tools, and take every precaution to ensure that giveaways are virus, spyware or malware free.&#34;&#60;/p&#62;
&#60;p&#62;I really find it hard to believe that they're really checking for malware if they missed something *this* blatant.  Simply reading the text on the first install screen would have alerted them.&#60;/p&#62;
&#60;p&#62;Meanwhile, there's been no response from the GAOTD admins despite the multiple warnings of spyware in the comments.&#60;/p&#62;
&#60;p&#62;How many people got infected with this garbage because they downloaded and installed it  before my warning -- it's the second comment -- got out of the &#34;awaiting moderation&#34; stage and became visible?  For that matter, there are probably still people installing it without reading the comments first.
&#60;/p&#62;</description>
</item>
<item>
<title>Violet4714 on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/5#post-39953</link>
<pubDate>Wed, 13 Aug 2008 18:03:40 +0000</pubDate>
<dc:creator>Violet4714</dc:creator>
<guid isPermaLink="false">39953@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;McAfee detected something in Smart Install Maker after installation...scan date was 11/30/2007...&#60;/p&#62;
&#60;p&#62;New Malware.bl&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://us.mcafee.com/virusInfo/default.asp?id=alphar&#38;#38;char=New%20Malware.bl&#34; rel=&#34;nofollow&#34;&#62;http://us.mcafee.com/virusInfo/default.asp?id=alphar&#38;#38;char=New%20Malware.bl&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;in: C:\Program Files\Smart Install Maker\sim.exe&#60;/p&#62;
&#60;p&#62;it was also found in a System Restore point that was created after install...&#60;/p&#62;
&#60;p&#62;A0040785.exe was the restore point description...&#60;/p&#62;
&#60;p&#62;it was detected as Heuristic...&#60;/p&#62;
&#60;p&#62;McAfee Definition of Heuristic: Heuristic analysis is behavior-based analysis of a computer program by anti-virus software to identify a potential virus. Often heuristic scanning produces false alarms when a clean program behaves as a virus might.&#60;/p&#62;
&#60;p&#62;no other reports of infection were posted, but i wasn't comfortable with it on my PC, so i quarantined it...i haven't restored it to see if updated definitions have changed the status of SIM (the developers may have asked McAfee to check it &#38;#38; verify it is ok)...&#60;/p&#62;
&#60;p&#62;this is my main PC, and i've had no problems with online transactions...&#60;/p&#62;
&#60;p&#62;XPSP2 MCE (up to date)
&#60;/p&#62;</description>
</item>
<item>
<title>gonzo on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/5#post-39949</link>
<pubDate>Wed, 13 Aug 2008 16:34:59 +0000</pubDate>
<dc:creator>gonzo</dc:creator>
<guid isPermaLink="false">39949@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;Sure. No hits with up-to-date AVG 8.0 Free Edition, but I don't think that it picks up trojans, does it?&#60;/p&#62;
&#60;p&#62;I'm using DefenseWall as a sandbox isolator. I wish I was confident about exactly how I'd know if DefenseWall was doing any good against a trojan. I regularly get messages from DefenseWall regarding some program I'm using logging keystrokes, but those programs are legit and need keystroke logging to function, or at least their web sites claim so.
&#60;/p&#62;</description>
</item>
<item>
<title>Lee on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-39814</link>
<pubDate>Mon, 11 Aug 2008 18:16:28 +0000</pubDate>
<dc:creator>Lee</dc:creator>
<guid isPermaLink="false">39814@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;Did you both scan with any other AV or SW application?
&#60;/p&#62;</description>
</item>
<item>
<title>Mercurius on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-39523</link>
<pubDate>Wed, 06 Aug 2008 22:51:20 +0000</pubDate>
<dc:creator>Mercurius</dc:creator>
<guid isPermaLink="false">39523@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;At least 1 reply. Thanks, Gonzo, for your confirmation. It feels strange to report a trojan banker in a GOTD product and nothing happens almost 1 day.&#60;/p&#62;
&#60;p&#62;But I do wonder why GOTD remains silent. Bad sign for what's going on behind the stage,&#60;br /&#62;
or just due to their vacation? We'll see...&#60;/p&#62;
&#60;p&#62;Meanwhile I've moved the two suspicious files onto a USB stick, and as a consequence the a² scan of the SIM directory is clean now. Nevertheless, such a state of &#34;security&#34; seems to me nothing but self-deceptive - not at all to my liking. How can we tell whether the two baddies haven't generated &#34;remote server files&#34; (cf. the given link above) hidden deeply inside the registry?&#60;/p&#62;
&#60;p&#62;So, what has to be done till somebody &#34;official&#34; is going to take over responsibility?!&#60;/p&#62;
&#60;p&#62;Well, to play safe you've got primarily one solution - all downloaders of Smart Install Maker must QUARANTINE the pc where SIM has been installed on in that they stop doing online banking on that same pc! If you are lucky having a notebook at your disposal, use IT for online banking as long as the coast isn't clear yet.&#60;/p&#62;
&#60;p&#62;Other than that I don't see an alternative to a reformat of your internet pc ...&#60;br /&#62;
Do you, GOTD team???
&#60;/p&#62;</description>
</item>
<item>
<title>gonzo on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-39505</link>
<pubDate>Wed, 06 Aug 2008 16:39:53 +0000</pubDate>
<dc:creator>gonzo</dc:creator>
<guid isPermaLink="false">39505@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;Ditto here. Identical experience on my Vista Home Premium Presario laptop while recently trying out Emsi Anti-Malware 3.5.&#60;/p&#62;
&#60;p&#62;The files are identified further by Emsi as coming from Smart Install Maker -&#60;/p&#62;
&#60;p&#62;C:\Program Files\Smart Install Maker\Data\Install.exe&#60;/p&#62;
&#60;p&#62;I downloaded and installed Smart Install Maker from GAOTD on November 15, 2007.&#60;/p&#62;
&#60;p&#62;Question: If you delete the Smart Install Maker setup.exe file as well as the Install.exe file as I have done, are you then completely free of the Banker Trojan/Spy problem? In other words, can you safely use the Smart Install Maker program?
&#60;/p&#62;</description>
</item>
<item>
<title>Mercurius on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-39449</link>
<pubDate>Tue, 05 Aug 2008 19:22:00 +0000</pubDate>
<dc:creator>Mercurius</dc:creator>
<guid isPermaLink="false">39449@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;Smart Install Maker (GOTD from 11/27/2007) malware ALERT&#60;/p&#62;
&#60;p&#62;Emsi a² Anti-Malware 3.5 (very recent giveaway) has found a TROJAN-SPY.Win32.Banker.khi which is “capable of stealing private information such as account numbers, passwords and banking credentials” (cf. &#60;a href=&#34;http://www.avast.com/eng/win32-banker.html&#34; rel=&#34;nofollow&#34;&#62;http://www.avast.com/eng/win32-banker.html&#60;/a&#62;).&#60;br /&#62;
Infected appear to be two files named “install.exe” (in “Data” folder) and &#34;setup.exe” (if you haven’t deleted this file immediately after installation).&#60;/p&#62;
&#60;p&#62;GOTD team, you definitively ought to investigate that issue! It surely isn’t a minor one!&#60;br /&#62;
To be honest, although there have been a few false positives in the a² results, this time I don’t believe in a f.p. for multiple reasons.&#60;br /&#62;
Something which is considerably questioning the credibility of the author, I.B.C., as well as in every case alike we had on GOTD, is that on their website they give no hint whatsoever as to their location, not even the country they come from.&#60;br /&#62;
The point is, would a serious, customer-related company not be trying to build trust by letting the customer know where, at least in which country, the company’s working that he’s gonna pay and rely his pc on?
&#60;/p&#62;</description>
</item>
<item>
<title>gtoal on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-38454</link>
<pubDate>Sat, 19 Jul 2008 06:45:18 +0000</pubDate>
<dc:creator>gtoal</dc:creator>
<guid isPermaLink="false">38454@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;I tried to watch a video this evening with VLC and got an error &#34;&#60;code&#62;C:\Windows\system32\OPENGL32.DLL is either&#60;br /&#62;
not designed to run on Windows or it contains an error.&#60;br /&#62;
Try installing the program again using the original installation&#60;br /&#62;
media or contact your system administrator or the software vendor for support&#60;/code&#62;&#34;&#60;/p&#62;
&#60;p&#62;Remembering what someone posted yesterday about wondershare having updated some DLLs, I pulled out my last complete backup - fortunately from last weekend - and compared the size and date stamps of all the files in system32, thinking it was just&#60;br /&#62;
an older version of something that had been badly updated'.  Apart from 5 files which&#60;br /&#62;
appeared to be related to microsoft update, there was nothing visibly different.&#60;/p&#62;
&#60;p&#62;However obviously something *had* changed, so I did a hex dump of opengl32.dll from before and after the last backup.&#60;/p&#62;
&#60;p&#62;It turns out that the most recent one has had its code compressed and some new code added to it, and written back on top of the file so that the length is preserved.  Some of the original contents are still present at the end of the file since the compressed code + virus are shorter than the original.&#60;/p&#62;
&#60;p&#62;The insertion of the virus was also careful to update the date stamps so that they don't appear to have been changed.&#60;/p&#62;
&#60;p&#62;The only software that I've installed since the last backup (with the exception of one program which I installed under returnil and then removed) is from GAOTD - the Gridinsoft editor, and Wondershare.&#60;/p&#62;
&#60;p&#62;Here is the start of opengl32.dll from the old safe version:&#60;/p&#62;
&#60;blockquote&#62;&#60;p&#62;
00000000: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00  : MZ..............&#60;br /&#62;
00000010: b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00  : &#60;a href=&#34;mailto:........@.......&#34;&#62;........@.......&#60;/a&#62;&#60;br /&#62;
00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  : ................&#60;br /&#62;
00000030: 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00  : ................&#60;br /&#62;
00000040: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68  : ........!..L.!Th&#60;br /&#62;
00000050: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f  : is program canno&#60;br /&#62;
00000060: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20  : t be run in DOS&#60;br /&#62;
00000070: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00  : mode....$.......&#60;br /&#62;
00000080: a8 e1 0e 74 ec 80 60 27 ec 80 60 27 ec 80 60 27  : ...t..&#60;code&#62;&#38;#39;..&#60;/code&#62;'..`'&#60;br /&#62;
00000090: ec 80 61 27 41 80 60 27 cb 46 1b 27 fd 80 60 27  : ..a'A.&#60;code&#62;&#38;#39;.F.&#38;#39;..&#60;/code&#62;'
&#60;/p&#62;&#60;/blockquote&#62;
&#60;p&#62;and here is the start of the code from the infected version:&#60;/p&#62;
&#60;blockquote&#62;&#60;p&#62;
00000000: 3d 22 97 cb 91 cb e6 f1 7d 9f 8c 9f 92 81 9f f1  : =&#34;......}.......&#60;br /&#62;
00000010: c9 7a 39 06 06 47 d8 b0 71 5b 6f 14 d6 c7 1a 8d  : .z9..G..q[o.....&#60;br /&#62;
00000020: 5a bd d9 6c 9d e3 42 2a ee d2 88 3b 43 db 0e 41  : Z..l..B*...;C..A&#60;br /&#62;
00000030: 08 49 22 05 5a 08 91 58 48 aa 81 6e 9e 2e 47 d3  : .I&#34;.Z..XH..n..G.&#60;br /&#62;
00000040: f5 40 4f b6 9a ba 3e 51 0c e2 81 6e df f1 5d a5  : &#60;a href=&#34;mailto:.@O...&#38;gt;Q...n..].&#34;&#62;.@O...&#38;gt;Q...n..].&#60;/a&#62;&#60;br /&#62;
00000050: 5c 47 2a e5 48 a5 1c 21 85 e7 08 db 9a 26 29 1e  : \G*.H..!.....&#38;#38;).&#60;br /&#62;
00000060: c4 db 74 1b 4e ff 16 a2 c9 c7 52 67 80 a0 13 eb  : ..t.N.....Rg....&#60;br /&#62;
00000070: b5 a9 5b d5 1a 24 16 db d6 8c f4 7b b9 28 32 eb  : ..[..$.....{.(2.&#60;br /&#62;
00000080: bb b2 4e ed c0 f9 c6 0c 17 88 69 29 4b 70 95 04  : ..N.......i)Kp..&#60;br /&#62;
00000090: 5e 40 5c 0c 02 58 0a df b9 d9 7c d7 29 2f 53 f8  : ^@\..X....&#124;.)/S.
&#60;/p&#62;&#60;/blockquote&#62;
&#60;p&#62;Maybe that'll be enough for other users here to check their own systems and&#60;br /&#62;
see if anyone else has picked up this same virus.&#60;/p&#62;
&#60;p&#62;After getting two viruses in two weeks, with a high likelihood of them coming from here, this is just getting way too risky.  As much&#60;br /&#62;
as I've enjoyed the petty bickering, I am sad to say I'm outta here.  So long guys, it's been nice knowing you.&#60;/p&#62;
&#60;p&#62;(Although I may drop in to this forum again after I've uploaded the virus to some of the AV sites to see if they can identify it)&#60;/p&#62;
&#60;p&#62;Graham
&#60;/p&#62;</description>
</item>
<item>
<title>gtoal on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-38043</link>
<pubDate>Sun, 13 Jul 2008 22:57:47 +0000</pubDate>
<dc:creator>gtoal</dc:creator>
<guid isPermaLink="false">38043@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;I replaced the hard drive in my portable today with a larger one, and copied over the partitions intact from the old drive.  On reboot windows did a repair (probably noticed the changed drive size) and at the end of that, rebooted.  When I logged on after the reboot, Anvir immediately detected a trojan in the Solveig WMP Trimmer's *Uninstaller* program.  Not sure why it didn't find it earlier, but this isn't something I picked up today - this machine hasn't been online for two or three days.  It's very likely that the trojan has been there from the outset and it was only due to the repair that anvir had a chance to look at all the files on the machine.  It may have been there since it was first installed.&#60;/p&#62;
&#60;p&#62;There's nothing on the original download web page ( &#60;a href=&#34;http://www.giveawayoftheday.com/plugin-solveigmm-wmp-trimmer/&#34; rel=&#34;nofollow&#34;&#62;http://www.giveawayoftheday.com/plugin-solveigmm-wmp-trimmer/&#60;/a&#62; ) about having seen trojans or viruses at the time of release (not even of false positives) so my guess is that this was caught by an antivirus update that came out after the software was installed.&#60;/p&#62;
&#60;p&#62;There are only three possibilities.  I picked up a virus and this file is the only one on my system that's been infected; or the uninstaller had a trojan from the start; or this is a false positive.  My money is on #2.
&#60;/p&#62;</description>
</item>
<item>
<title>my_name_is_brad on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-35844</link>
<pubDate>Sat, 21 Jun 2008 07:41:35 +0000</pubDate>
<dc:creator>my_name_is_brad</dc:creator>
<guid isPermaLink="false">35844@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;nah i never got the activation for that I believe.  I may be thinking of the initial download for that, so I could be mistaken.  I was thinking there was another one that was that way.  Could just be the old memory crapping out again.
&#60;/p&#62;</description>
</item>
<item>
<title>mikerb on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-35724</link>
<pubDate>Fri, 20 Jun 2008 15:36:26 +0000</pubDate>
<dc:creator>mikerb</dc:creator>
<guid isPermaLink="false">35724@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;ah, that would be the infamous &#60;a href=&#34;http://www.giveawayoftheday.com/flex-gif-animator/&#34;&#62;Flex GIF Animator&#60;/a&#62; that only about 2 people managed to get. were you one of them brad?
&#60;/p&#62;</description>
</item>
<item>
<title>my_name_is_brad on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-35527</link>
<pubDate>Thu, 19 Jun 2008 06:44:14 +0000</pubDate>
<dc:creator>my_name_is_brad</dc:creator>
<guid isPermaLink="false">35527@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;i have seen a couple of offers lately that have required a validation from the developer site, and that is not such a bad thing really as it helps the developers keep up with stats on how well this site works for them.&#60;/p&#62;
&#60;p&#62;there was one that troubled me though, and I can't recall the name off hand. It required a second download from their site. To me this poses a huge security risk, and I hope you guys avoid this in the future because you have no way to validate what they decide to change it to.&#60;/p&#62;
&#60;p&#62;Even if I could remember the developer/software I wouldn't name them since their offer did pass the spyware/virus scanners on my computer even at the late time that I typically download. it's just a thought
&#60;/p&#62;</description>
</item>
<item>
<title>You Wont See Me on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-34951</link>
<pubDate>Mon, 16 Jun 2008 02:09:16 +0000</pubDate>
<dc:creator>You Wont See Me</dc:creator>
<guid isPermaLink="false">34951@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;PC Tools' &#34;Threatfire reports that SAGA.exe is logging keystrokes&#34;. I'm not sure if this is something normal for games that the game is supposed to do but having a keylogger built into the game surely made me uninstall it. I posted this in the comments but it was Modded out so I figure I'll throw it up here. &#60;/p&#62;
&#60;p&#62;False Positive? Threatfire uses behavioral based detection so I was just wondering if this is something that is common for games to function and should be allowed to continue or not.
&#60;/p&#62;</description>
</item>
<item>
<title>chuck11 on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-34020</link>
<pubDate>Mon, 09 Jun 2008 14:33:24 +0000</pubDate>
<dc:creator>chuck11</dc:creator>
<guid isPermaLink="false">34020@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;Following-up on the BurnAware issue, AVG also quarantined most of the files as being infected with Klone P.  I contacted the software supplier and got a few cryptic notes back that they no longer support the Home Edition and that I should upgrade to their v.2. However, contrary to what is shown in my / GAOTD registration summary - 'eligible for upgrades for 1 year' - I was informed that only paying customers are eligible for this free upgrade. Not liking this 'bait &#38;#38; switch' approach - when a promised is made...it should be kept.  If someone from GAOTD could check into this, I sure everyone who d/l'd this software would appreciate it. Also, if you want, I can forward their e-mail responses.&#60;/p&#62;
&#60;p&#62;chuck11
&#60;/p&#62;</description>
</item>
<item>
<title>Paulga on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-30099</link>
<pubDate>Wed, 21 May 2008 00:04:30 +0000</pubDate>
<dc:creator>Paulga</dc:creator>
<guid isPermaLink="false">30099@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;iBizCard-Stud.......i just clicked to your link &#60;a href=&#34;http://www.download3k.com/Antivirus-Report-iBizCard.html&#34; rel=&#34;nofollow&#34;&#62;http://www.download3k.com/Antivirus-Report-iBizCard.html&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;and it sure started alarms going on my computer, dangerous....and so forth, where as the second link had no problem and gave a 100% free of virus ++, did you download from the first link??&#60;/p&#62;
&#60;p&#62;Paulga
&#60;/p&#62;</description>
</item>
<item>
<title>TK_M on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-30049</link>
<pubDate>Tue, 20 May 2008 18:03:14 +0000</pubDate>
<dc:creator>TK_M</dc:creator>
<guid isPermaLink="false">30049@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;I updated my AVG Free to version 8.0 from the 7.5 last week and as soon as I did, BurnAware has been thowing up virus reports. This explains why it is suddenly giving reports, it seems to be due to the update.&#60;/p&#62;
&#60;p&#62;If you go to History/Virus Vault in AVG, you can highlight the quarrentined items and send them to Grisoft to be re-analysed if you feel they are false positives. I have just done that, only to find BurnAware have notified them as well.&#60;/p&#62;
&#60;p&#62;While in the virus vault, you can restorew the quarrentined files and BurnAware should then work normally.&#60;/p&#62;
&#60;p&#62;You can also click on &#34;ignore&#34; these files during a scan leave them in place until Grisoft gets them sorted out.&#60;/p&#62;
&#60;p&#62;I tried Avira as it has better detection rates than AVG, but had to go back to AVG as I got far too many false positives from Avira. Not only that, but it was hard to submit reports of false positives to Avira and even when I persevered, they said one false positive was real. Now it looks like AVG have increased their detection rate, but at the cost of more false positives. I will stick with them (at least temporarily) as at least they have made it easy to report suspected false positives.
&#60;/p&#62;</description>
</item>
<item>
<title>hotdoge3 on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-29999</link>
<pubDate>Tue, 20 May 2008 09:14:09 +0000</pubDate>
<dc:creator>hotdoge3</dc:creator>
<guid isPermaLink="false">29999@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;BurnAware Home Edition is suddenly getting virus alerts from Antivirus. The developers are aware of the problem and have reported it to AVG. They say it is a false positie.&#60;br /&#62;
It be fix with a update I had this with Nero 7 wen it fist come out update fix it be a false positie as it new,so keep it be fix be for long.
&#60;/p&#62;</description>
</item>
<item>
<title>Dragonlair on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-29911</link>
<pubDate>Mon, 19 May 2008 12:29:42 +0000</pubDate>
<dc:creator>Dragonlair</dc:creator>
<guid isPermaLink="false">29911@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;BurnAware Home Edition is suddenly getting virus alerts from AVG.  The developers are aware of the problem and have reported it to AVG.  They say it is a false positie. Their site shows it is both the home and free edition affected. The odd part is I have a friend who started getting the messages Saturday night.  I didn't start getting it until this morning's boot. It showed up during the boot, not by trying to use the product.&#60;/p&#62;
&#60;p&#62;We have the same version of BurnAware (we both got it here) and we have the same version and level of AVG Free (8.0) having downloaded/installed it the same day.  We also have almost the same OS (She has Vista Home Premium SP1 and I have Vista Ultimate SP1).  Why did she start getting the messages about 36 hours before I did?&#60;/p&#62;
&#60;p&#62;As the product was not essential to me (I have Roxio Creation 9 from my original PC purchase), I have uninstalled it to be safe.
&#60;/p&#62;</description>
</item>
<item>
<title>zubterfuge on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-29369</link>
<pubDate>Tue, 13 May 2008 21:13:54 +0000</pubDate>
<dc:creator>zubterfuge</dc:creator>
<guid isPermaLink="false">29369@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;The Myspace Editor had a &#34;trojen.adclick&#34; and I was using NAV. The virus isn't found until after the product is installed. How disappointing.
&#60;/p&#62;</description>
</item>
<item>
<title>OiMack on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-27781</link>
<pubDate>Tue, 29 Apr 2008 14:48:50 +0000</pubDate>
<dc:creator>OiMack</dc:creator>
<guid isPermaLink="false">27781@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;Same problem here. After installing iBizCard Bitdefender found two infected files in the E_4 directory. Both infected with Trojan.Peed.Gen.&#60;br /&#62;
The files are&#60;br /&#62;
- EXMLParser.fne&#60;br /&#62;
- shell.fne
&#60;/p&#62;</description>
</item>
<item>
<title>iBizCard_Studio on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-27759</link>
<pubDate>Tue, 29 Apr 2008 10:19:52 +0000</pubDate>
<dc:creator>iBizCard_Studio</dc:creator>
<guid isPermaLink="false">27759@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;Thebeo:Thank you for your report. we will contact Avira and deal with this problem as soon as possible.Please set assured,our produc is 100% Clean&#60;/p&#62;
&#60;p&#62;download3k.com Antivirus Report: &#60;a href=&#34;http://www.download3k.com/Antivirus-Report-iBizCard.html&#34; rel=&#34;nofollow&#34;&#62;http://www.download3k.com/Antivirus-Report-iBizCard.html&#60;/a&#62;&#60;br /&#62;
softpedia.com Antivirus Report: &#60;a href=&#34;http://www.softpedia.com/progClean/iBizCard-Clean-98324.html&#34; rel=&#34;nofollow&#34;&#62;http://www.softpedia.com/progClean/iBizCard-Clean-98324.html&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>Thebeo on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-27754</link>
<pubDate>Tue, 29 Apr 2008 10:03:39 +0000</pubDate>
<dc:creator>Thebeo</dc:creator>
<guid isPermaLink="false">27754@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;to iBizCard_Studio, for your information.&#60;br /&#62;
The program Bizcard.exe creates a Temp directory &#34;E_4&#34;. In this directory it creates al kind of files. One of them is identified as the Trojan. Maybe this narrows the search to the problem.
&#60;/p&#62;</description>
</item>
<item>
<title>iBizCard_Studio on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-27750</link>
<pubDate>Tue, 29 Apr 2008 08:50:42 +0000</pubDate>
<dc:creator>iBizCard_Studio</dc:creator>
<guid isPermaLink="false">27750@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;our product &#34;ibizcard&#34; have not any virus, it's 100% Clean&#60;br /&#62;
download3k.com Antivirus Report: &#60;a href=&#34;http://www.download3k.com/Antivirus-Report-iBizCard.html&#34; rel=&#34;nofollow&#34;&#62;http://www.download3k.com/Antivirus-Report-iBizCard.html&#60;/a&#62;&#60;br /&#62;
softpedia.com Antivirus Report: &#60;a href=&#34;http://www.softpedia.com/progClean/iBizCard-Clean-98324.html&#34; rel=&#34;nofollow&#34;&#62;http://www.softpedia.com/progClean/iBizCard-Clean-98324.html&#60;/a&#62;&#60;br /&#62;
to Thebeo:I will contact Avira to Correct this wrong virus report.
&#60;/p&#62;</description>
</item>
<item>
<title>Thebeo on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-27745</link>
<pubDate>Tue, 29 Apr 2008 08:26:49 +0000</pubDate>
<dc:creator>Thebeo</dc:creator>
<guid isPermaLink="false">27745@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;After installing iBizCard, Avira Antivir detects trojan &#34;TR/Crypt.XPACK.Gen&#34;.&#60;br /&#62;
Please look in to this.
&#60;/p&#62;</description>
</item>
<item>
<title>turkishvan007 on "Review Trojan/Virus Reports"</title>
<link>http://www.giveawayoftheday.com/forums/topic/719/page/4#post-23513</link>
<pubDate>Mon, 24 Mar 2008 16:02:33 +0000</pubDate>
<dc:creator>turkishvan007</dc:creator>
<guid isPermaLink="false">23513@http://www.giveawayoftheday.com/forums/</guid>
<description>&#60;p&#62;I use Norton online protection and antivirus tool, I have AnVir Task Manager and Mamutu.  My Norton is updated daily and is current.  I'm running Windows XP SP2.&#60;/p&#62;
&#60;p&#62;My system found the trojan Hacktool.Rootkit in Robotask  idlehook.dll yesterday/today and in my easttec backup files under the Robotask product backup.  I downloaded Robotask and haven't used it since I downloaded it on September 28, 2007 and east tec backup was used October 12, 2007.  Norton Antivirus did not find this trojan until this mornings scan so the trojan ended up in this file somehow but I don't know how.&#60;/p&#62;
&#60;p&#62;I'm not saying this virus was downloaded in Robotask or EastTec Backup's original download from GAOTD because I routinely do full system Virus Scans (once a week) and quick scans whenever I restart my computer and they haven't been found until now.  What I'm saying is to please do a full system scan on your computer to make sure you catch this trojan if your computer has somehow received it.  The trojan has been removed from my computer as of this morning.  &#60;/p&#62;
&#60;p&#62;Symatec provided this information on the Trojan.&#60;/p&#62;
&#60;p&#62;Hacktool.RootkitRisk Level 1: Very LowPrinter Friendly Page&#60;br /&#62;
SUMMARY TECHNICAL DETAILS REMOVAL Discovered: September 27, 2001&#60;br /&#62;
Updated: February 13, 2007 11:38:00 AM&#60;br /&#62;
Type: Trojan Horse&#60;br /&#62;
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP&#60;/p&#62;
&#60;p&#62;Hacktool.Rootkit comprises a set of programs and scripts that work together to allow attackers to break into a system. If Hacktool.Rootkit is detected on a system, it is very likely that an attacker has gained complete control of that system. All files that are detected as Hacktool.Rootkit should be deleted. Infected systems may need to be restored from backups or patched to restore security.&#60;/p&#62;
&#60;p&#62;Rootkits first appeared on the UNIX operating system. Administrator/Superuser accounts on UNIX systems are called root. Rootkits are kits of programs that are designed to gain root access on a system. The term rootkit now refers to any set of tools that can be used to gain unauthorized access to a system.&#60;br /&#62;
ProtectionInitial Rapid Release version September 27, 2001&#60;br /&#62;
Latest Rapid Release version March 24, 2008 revision 004&#60;br /&#62;
Initial Daily Certified version September 27, 2001 revision 007&#60;br /&#62;
Latest Daily Certified version March 24, 2008 revision 005&#60;br /&#62;
Initial Weekly Certified release date September 27, 2001&#60;br /&#62;
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.&#60;/p&#62;
&#60;p&#62;Threat AssessmentWildWild Level: Medium&#60;br /&#62;
Number of Infections: More than 1000&#60;br /&#62;
Number of Sites: More than 10&#60;br /&#62;
Geographical Distribution: Low&#60;br /&#62;
Threat Containment: Easy&#60;br /&#62;
Removal: Moderate&#60;br /&#62;
DamageDamage Level: Medium&#60;br /&#62;
DistributionDistribution Level: Low &#60;/p&#62;
&#60;p&#62;Writeup By: Jimmy Shah&#60;/p&#62;
&#60;p&#62;Hope this helps someone else out.
&#60;/p&#62;</description>
</item>

</channel>
</rss>
