<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Giveaway of the Day Forums &#187; Tag: trojan - Recent Posts</title>
		<link>http://www.giveawayoftheday.com/forums/tags/trojan</link>
		<description>Giveaway of the Day Forums &raquo; Tag: trojan - Recent Posts</description>
		<language>en-US</language>
		<pubDate>Thu, 26 Nov 2009 13:43:37 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.2</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>http://www.giveawayoftheday.com/forums/search.php</link>
		</textInput>
		<atom:link href="http://www.giveawayoftheday.com/forums/rss/tags/trojan" rel="self" type="application/rss+xml" />

		<item>
			<title>nrshapiro on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-68097</link>
			<pubDate>Mon, 23 Nov 2009 18:04:02 +0000</pubDate>
			<dc:creator>nrshapiro</dc:creator>
			<guid isPermaLink="false">68097@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Norton Internet Security 2010 will not allow activate.exe to run.  It won&#38;#39;t allow it to stay either--deleting it.  I could disable NAV of course, but then if activate.exe did contain a virus I&#38;#39;d be screwed, especially since it needs to be run with admin privileges.  So I think GOTD needs to work this out with Norton.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Steve on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-68005</link>
			<pubDate>Sat, 21 Nov 2009 02:56:51 +0000</pubDate>
			<dc:creator>Steve</dc:creator>
			<guid isPermaLink="false">68005@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;&#60;a href=&#34;http://www.giveawayoftheday.com/photo-stamp-remover/&#34; rel=&#34;nofollow&#34;&#62;http://www.giveawayoftheday.com/photo-stamp-remover/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;OS = Windows XP Pro, sp3, IE8, all patches. Stamp Remover has been on this machine since the giveaway, although I don&#38;#39;t think I ever used it after the giveaway.&#60;/p&#62;
&#60;p&#62;SAV 9.0.7.1000, scan engine 91.2.1.10, virus definitions version 11/18/2009 rev. 3. auto-protect scan detected c:\program files\photo stamp remover\StampRemover.exe as a threat called &#38;quot;downloader&#38;quot;. default action = clean (failed). backup action = quarantine (failed). final action taken by SAV = delete. The file was deleted successfully.&#60;/p&#62;
&#60;p&#62;Very suspsicious if you ask me, especially since I wasn&#38;#39;t even using the software. I was starting another software (radioget) at the time.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>rezidue on "IObit Advanced SystemCare malware trojan Conduit toolbar is classed as malware"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/6507#post-67489</link>
			<pubDate>Tue, 10 Nov 2009 02:34:23 +0000</pubDate>
			<dc:creator>rezidue</dc:creator>
			<guid isPermaLink="false">67489@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;thanks for the update HD3!&#60;/p&#62;
&#60;p&#62;something was very fishy about this and I still think they took the code in question...&#60;/p&#62;
&#60;p&#62;BTW - I like your updates on tech issues (even if I have to &#38;quot;decode&#38;quot; some of your posts - :-)   )&#60;/p&#62;
&#60;p&#62;regards - Damian
&#60;/p&#62;</description>
		</item>
		<item>
			<title>hotdoge3 on "IObit Advanced SystemCare malware trojan Conduit toolbar is classed as malware"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/6507#post-67486</link>
			<pubDate>Tue, 10 Nov 2009 02:22:28 +0000</pubDate>
			<dc:creator>hotdoge3</dc:creator>
			<guid isPermaLink="false">67486@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;&#60;a href=&#34;http://forums.iobit.com/showthread.php?t=4801&#38;amp;page=2&#34; rel=&#34;nofollow&#34;&#62;http://forums.iobit.com/showthread.php?t=4801&#38;amp;page=2&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;A legal letter will be released later, which will prove that there is no problem with&#60;br /&#62;
Intellectual Property Rights.&#60;/p&#62;
&#60;p&#62;For the sake of avoiding dispute and possible problems, we have deleted all disputed items in way?&#60;br /&#62;
our database temporarily, and have updated IObit Security 360’s database.&#60;/p&#62;
&#60;p&#62;ABOUT THE ACCUSATION –DISPUTE THREAD &#38;quot; Closed Thread &#38;quot; ? IObit not like some posts?&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://forums.iobit.com/showthread.php?t=4868&#34; rel=&#34;nofollow&#34;&#62;http://forums.iobit.com/showthread.php?t=4868&#60;/a&#62;  Uninstalling iobit 360 (mostly toolbar related)&#60;br /&#62;
Conduit toolbar is classed as malware by most. (This is in IObit forums well said,&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.siteadvisor.com/sites/iobit.com&#34; rel=&#34;nofollow&#34;&#62;http://www.siteadvisor.com/sites/iobit.com&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.siteadvisor.com/sites/iobit.com/downloads21853516/&#34; rel=&#34;nofollow&#34;&#62;http://www.siteadvisor.com/sites/iobit.com/downloads21853516/&#60;/a&#62;  (9/10)Nuisance Score Red bad&#60;br /&#62;
Exploit-ObscuredHtml trojan &#60;/p&#62;
&#60;p&#62;&#38;quot;C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe&#38;quot; /startup&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.siteadvisor.com/sites/iobit.com/downloads/21889236/&#34; rel=&#34;nofollow&#34;&#62;http://www.siteadvisor.com/sites/iobit.com/downloads/21889236/&#60;/a&#62;  (9/10)Nuisance Score Red bad&#60;br /&#62;
URL of the download: htxxtp://download.iobit.com/asc-setup.exe&#60;/p&#62;
&#60;p&#62;awcsetup.exe installed the following programs on our PC:Exploit-ObscuredHtml trojan&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.siteadvisor.com/sites/iobit.com/downloads/&#34; rel=&#34;nofollow&#34;&#62;http://www.siteadvisor.com/sites/iobit.com/downloads/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;Changes your default search page, Buttons, toolbars or add ons.&#60;br /&#62;
You may also like to see Post IObit 360
&#60;/p&#62;</description>
		</item>
		<item>
			<title>TeXaCo on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-67025</link>
			<pubDate>Sun, 01 Nov 2009 16:55:24 +0000</pubDate>
			<dc:creator>TeXaCo</dc:creator>
			<guid isPermaLink="false">67025@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;After installing IOBIT 360 reported it the dll file as a trojan. Then after scanning my whole system, it came up with 15 other files from regtidy as a virus. As the program was taking me to (I&#38;#39;m assuming the software website). Avira blocked the website from being displayed saying it was known to be a malicious website and WOT also blocked it.&#60;/p&#62;
&#60;p&#62;Now I know there have been false positives in the past but this seems to be too much to be false.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>perz on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-66963</link>
			<pubDate>Sat, 31 Oct 2009 21:46:02 +0000</pubDate>
			<dc:creator>perz</dc:creator>
			<guid isPermaLink="false">66963@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;RegTidy trojan detected and identified by Avira AntiVir Premium:&#60;br /&#62;
Virus or unwanted program &#38;#39;TR/Drop.arte.410624 [trojan]&#38;#39;&#60;br /&#62;
detected in file &#38;#39;C:\Program Files\RegTidy 2009\RegTidy.dll.&#60;br /&#62;
Action performed: Deny access
&#60;/p&#62;</description>
		</item>
		<item>
			<title>leofelix on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-66949</link>
			<pubDate>Sat, 31 Oct 2009 19:27:32 +0000</pubDate>
			<dc:creator>leofelix</dc:creator>
			<guid isPermaLink="false">66949@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;RegTidy is a misleading application, it will brings to false positive detection, more it can mess up you system.&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.emsisoft.com/en/malware/?Adware.Win32.RegTidy&#34; rel=&#34;nofollow&#34;&#62;http://www.emsisoft.com/en/malware/?Adware.Win32.RegTidy&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.mywot.com/en/scorecard/regtidy.com&#34; rel=&#34;nofollow&#34;&#62;http://www.mywot.com/en/scorecard/regtidy.com&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;I wonder GOTD team didn&#38;#39;t check it
&#60;/p&#62;</description>
		</item>
		<item>
			<title>watcher13 on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-65804</link>
			<pubDate>Wed, 14 Oct 2009 19:03:20 +0000</pubDate>
			<dc:creator>watcher13</dc:creator>
			<guid isPermaLink="false">65804@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Not sure. It has a small AV module. Maybe it was checking for updates. As you probably saw, it also had links to other bundled software and &#38;quot;recommended&#38;quot; softwares. If you didn&#38;#39;t deselect all that stuff, it might have been trying to contact one of them. Also, I haven&#38;#39;t got around to installing yet, but I read over in the comments section that it still has nag screens to get you to upgrade. It may have been trying to download one of them. I&#38;#39;m thinking it&#38;#39;s one or two of these annoying, but semi-harmless functions.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>prs on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-65801</link>
			<pubDate>Wed, 14 Oct 2009 17:56:29 +0000</pubDate>
			<dc:creator>prs</dc:creator>
			<guid isPermaLink="false">65801@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Today,s offer has rave reviews from the regulars. Would hate to let this go. I posted this in the comments section today and I find that my comment is &#38;quot;moderated&#38;quot; So here goes. Had this evaluated at virustotal and jotti.org. The result is 1/41 and 1/21 detecting Trojan. Kaspersky in those two lists is happy. Zone Alarm on my computer informs me that AnVir is trying to contact two particular destination IP. What does that mean ?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>notblocklox on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-65795</link>
			<pubDate>Wed, 14 Oct 2009 16:28:03 +0000</pubDate>
			<dc:creator>notblocklox</dc:creator>
			<guid isPermaLink="false">65795@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;No, my Kasper is quite happy with AnVir.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>prs on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-65789</link>
			<pubDate>Wed, 14 Oct 2009 14:16:04 +0000</pubDate>
			<dc:creator>prs</dc:creator>
			<guid isPermaLink="false">65789@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Todays offering by AnVir had my Kaspersky Internet Security crying foul. It is detected as a Trojan. I added AnVir to exclusions. Anyone else have this trouble ?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>gtoal on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-65788</link>
			<pubDate>Wed, 14 Oct 2009 13:57:56 +0000</pubDate>
			<dc:creator>gtoal</dc:creator>
			<guid isPermaLink="false">65788@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Today&#38;#39;s signature update to McAfee just flagged the 22 Jan PDFZilla executable as &#38;quot;Generic.dx!fua&#38;quot; (and deleted it).
&#60;/p&#62;</description>
		</item>
		<item>
			<title>rezidue on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-63537</link>
			<pubDate>Sun, 06 Sep 2009 22:48:10 +0000</pubDate>
			<dc:creator>rezidue</dc:creator>
			<guid isPermaLink="false">63537@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;VirusTotal scan of webgalery.exe from &#60;a href=&#34;http://www.giveawayoftheday.com/softorbits-html-web-gallery-creator/&#34;&#62;SoftOrbits HTML Web Gallery Creator given away on September 4, 2009&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;&#60;strong&#62;Trojan-Downloader.Win32.Adload.jot&#60;/strong&#62;&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.virustotal.com/analisis/1d243e423585d8295a62d5d465644c66767c0a7b5454a12ea5cce3cc0e3691cf-1252275170&#34; rel=&#34;nofollow&#34;&#62;http://www.virustotal.com/analisis/1d243e423585d8295a62d5d465644c66767c0a7b5454a12ea5cce3cc0e3691cf-1252275170&#60;/a&#62;
&#60;/p&#62;</description>
		</item>
		<item>
			<title>rezidue on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-63142</link>
			<pubDate>Sun, 30 Aug 2009 00:04:15 +0000</pubDate>
			<dc:creator>rezidue</dc:creator>
			<guid isPermaLink="false">63142@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;&#60;a href=&#34;http://www.giveawayoftheday.com/2009/08/14/&#34;&#62;&#60;strong&#62;Batch Image Resizer given away on August 14, 2009&#60;/strong&#62;&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;&#60;strong&#62;Backdoor.Win32.Hupigon.htas&#60;/strong&#62;&#60;/p&#62;
&#60;p&#62;Please note the wrapper was removed for this scan to verify that it had nothing to do with the bundled Software Informer application.&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.virustotal.com/analisis/f2fb709f74ecf276846fffb5e0da1edc784bcf124b48b124958bda6892cbbe7d-1251589760&#34; rel=&#34;nofollow&#34;&#62;http://www.virustotal.com/analisis/f2fb709f74ecf276846fffb5e0da1edc784bcf124b48b124958bda6892cbbe7d-1251589760&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;&#60;strong&#62;In fact out of the 9 offerings from SoftOrbits.com only 4 applications scanned 100% clean at VirusTotal,&#60;/strong&#62; the rest scan as containing a trojan or adware.&#60;/p&#62;
&#60;p&#62;Sorry I didn't see this sooner,&#60;/p&#62;
&#60;p&#62;Regards,&#60;br /&#62;
Damian
&#60;/p&#62;</description>
		</item>
		<item>
			<title>ants on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-62712</link>
			<pubDate>Sat, 22 Aug 2009 06:43:16 +0000</pubDate>
			<dc:creator>ants</dc:creator>
			<guid isPermaLink="false">62712@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Update!&#60;br /&#62;
After the Gold Audio Suite build has been updated no infection is detected.&#60;br /&#62;
The demo version at vendors site is not changed.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>ants on "Review Trojan/Virus Reports"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/719/page/6#post-62710</link>
			<pubDate>Sat, 22 Aug 2009 05:51:07 +0000</pubDate>
			<dc:creator>ants</dc:creator>
			<guid isPermaLink="false">62710@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Hello!&#60;br /&#62;
Posting this here, because comments are not moderated.&#60;br /&#62;
This is about the Gold Audio Suite, August 21, 2009&#60;/p&#62;
&#60;p&#62;Hello, giveawayfans!&#60;/p&#62;
&#60;p&#62;What do we get today? A virus or a false positive?&#60;/p&#62;
&#60;p&#62;Someone here advised to disable security - not wise;&#60;br /&#62;
I have uploaded erdmpg4.dll to some sites doing a file scan.&#60;br /&#62;
ca 50% of scanners find it infected with something named 'induc'&#60;/p&#62;
&#60;p&#62;clean, say: ArcaVir, A-Squared,AntiVir, CPSecure, Ikarus, NOD32, Panda,Quick Heal, VBA32, Comodo, eSafe, Jiangmin, K7AntiVirus, McAfee-GW, PCTools&#60;/p&#62;
&#60;p&#62;infected, say: avast!, AVG, bitdefender, ClamAV, Dr.Web, F-Prot, F-Secure, GDATA, Kaspersky, Sophos, VirusBuster, Authentium, Microsoft, Norman, Prevx, Symantec, Trend micro, McAfee5715, Fortinet, Sunbelt&#60;/p&#62;
&#60;p&#62;Went to Sophos site, they say:&#60;br /&#62;
&#34; W32/Induc-A&#60;br /&#62;
Aliases	Virus.Win32.Induc.a&#60;br /&#62;
Category	Viruses and Spyware&#60;br /&#62;
Type	Virus&#60;br /&#62;
................&#60;br /&#62;
W32/Induc-A is a virus that infects Delphi files at compile-time. As such, these files cannot be disinfected and need to be recompiled cleanly.&#60;br /&#62;
................&#60;br /&#62;
Because infected executables are produced at compile time by infected Delphi development environments,&#60;br /&#62;
we are seeing many cases of infected files coming from genuine software vendors.&#60;br /&#62;
These are not false positives.&#60;br /&#62;
Clients and software developers seeking to understand why their software is being detected as W32/Induc-A should&#60;br /&#62;
see this [http://www.sophos.com/blogs/sophoslabs/v/post/6195] blog article.&#60;br /&#62;
................&#60;br /&#62;
How it spreads  	&#60;/p&#62;
&#60;p&#62;    * Infected files&#60;/p&#62;
&#60;p&#62;Affected operating systems 	Windows&#60;br /&#62;
Protection available since 	18 August 2009 15:14:59 (GMT)&#60;br /&#62;
Last updated 	20 August 2009 05:28:01 (GMT)&#60;br /&#62;
Detected by 	All Sophos products&#60;br /&#62;
...............&#34;&#60;/p&#62;
&#60;p&#62;Some information from eset - NOD32 site:&#60;br /&#62;
Thanks to ESET’s early warning system - ThreatSense.Net ,&#60;br /&#62;
the first 24 hours from the virus’s release, ESET has received over 30,000 unique infected samples,&#60;br /&#62;
where in many cases the original software was a legitimate application prior to infection.&#60;/p&#62;
&#60;p&#62;According to Juraj Malcho, the Head of ESET Virus Lab,&#60;br /&#62;
“the concern is over the period during which the virus went undetected and was able to infect a large number of PCs,&#60;br /&#62;
resulting in the infiltrated software being distributed to users directly by their vendor.&#60;br /&#62;
To our dismay, often the reaction of the software vendor has been that the detection of a virus is a false-positive.&#60;br /&#62;
”It is likely that the first samples of the virus date back to April 2009.&#60;br /&#62;
The reason why the virus was left unnoticed for such a long time period is that Delphi code tends to be quite voluminous&#60;br /&#62;
and the virus body itself quite small. &#60;/p&#62;
&#60;p&#62;......................&#60;/p&#62;
&#60;p&#62;......................&#60;/p&#62;
&#60;p&#62;This was written before post #11 in comments
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Robert on "Warning: Today&#039;s Streaming Video recorder contains Trojan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5991#post-62460</link>
			<pubDate>Tue, 18 Aug 2009 22:31:45 +0000</pubDate>
			<dc:creator>Robert</dc:creator>
			<guid isPermaLink="false">62460@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Hi Sue,dr mabuse,GM...&#60;/p&#62;
&#60;p&#62;No problems over here either.&#60;br /&#62;
If in doubt you can always look for a second opinion and upload files to &#60;a href=&#34;http://www.virustotal.com&#34; rel=&#34;nofollow&#34;&#62;http://www.virustotal.com&#60;/a&#62;&#60;br /&#62;
(the file will be scanned with 41 different antivirus engines and the result will give you a pretty good idea if it's false positive or not)
&#60;/p&#62;</description>
		</item>
		<item>
			<title>watcher13 on "Warning: Today&#039;s Streaming Video recorder contains Trojan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5991#post-62456</link>
			<pubDate>Tue, 18 Aug 2009 22:11:17 +0000</pubDate>
			<dc:creator>watcher13</dc:creator>
			<guid isPermaLink="false">62456@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;That particular hit is often a false positive caused by Avira's heuristic detection routine. I've seen it more than once. If you're not familiar, heuristics are designed to try and identify new, never before identified viruses, but often hit on normal, built in behaviors of the software. Still, no problem with being cautious if you'd rather just uninstall to be safe.&#60;/p&#62;
&#60;p&#62;From Avira's site, you can see it's just a generic heuristic hit. However, someone would have to submit the file for Avira to verify it's a false positive:&#60;/p&#62;
&#60;p&#62;TR/Dropper.Gen - Trojan&#60;br /&#62;
Summary  Full description  &#60;/p&#62;
&#60;p&#62;Virus: TR/Dropper.Gen&#60;br /&#62;
Date discovered: 19/06/2007&#60;br /&#62;
Type: Trojan&#60;br /&#62;
Subtype: Dropper&#60;br /&#62;
In the wild: Yes&#60;br /&#62;
Reported Infections: Low&#60;br /&#62;
Distribution Potential: Low&#60;br /&#62;
Damage Potential: Low&#60;br /&#62;
Static file: No&#60;br /&#62;
Engine version: 7.04.00.34 &#60;/p&#62;
&#60;p&#62; General Side effects:&#60;br /&#62;
   • Drops malicious files&#60;/p&#62;
&#60;p&#62; Special detection TR/Dropper.Gen &#60;/p&#62;
&#60;p&#62;Description:&#60;br /&#62;
A generic detection routine designed to detect common family characteristics shared in several variants.&#60;/p&#62;
&#60;p&#62;This special detection routine was developed in order to detect unknown variants and will be enhanced continuously.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>RosnSC on "Warning: Today&#039;s Streaming Video recorder contains Trojan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5991#post-62450</link>
			<pubDate>Tue, 18 Aug 2009 20:11:53 +0000</pubDate>
			<dc:creator>RosnSC</dc:creator>
			<guid isPermaLink="false">62450@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;I downloaded the updated one to my laptop. Didn't get any warnings of any type, so it must be okay. A little later on this evening I plan to download it to my desktop computer. I would have done that one last night, too, but it was 'down'.&#60;/p&#62;
&#60;p&#62;Sue
&#60;/p&#62;</description>
		</item>
		<item>
			<title>GMMan on "Warning: Today&#039;s Streaming Video recorder contains Trojan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5991#post-62439</link>
			<pubDate>Tue, 18 Aug 2009 18:36:02 +0000</pubDate>
			<dc:creator>GMMan</dc:creator>
			<guid isPermaLink="false">62439@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Have you gotten the newer download? I heard that there were reports of this earlier, but GAOTD has uploaded a newer, fixed version of the program. I didn't receive any warnings from my avast!.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>dr_mabuse on "Warning: Today&#039;s Streaming Video recorder contains Trojan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5991#post-62437</link>
			<pubDate>Tue, 18 Aug 2009 18:22:12 +0000</pubDate>
			<dc:creator>dr_mabuse</dc:creator>
			<guid isPermaLink="false">62437@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;I donloaded today the files and unzipped them.&#60;br /&#62;
after execution of the setup file i got the warning by my Avira Personal&#60;br /&#62;
that the file Streaming Video Recorder.exe vontains a trojan, namely:&#60;br /&#62;
TR/Dropper.Gen - Trojan&#60;br /&#62;
which will drop malicious files on the system.&#60;br /&#62;
So is this to take serious ?&#60;br /&#62;
Please inform me urgently.&#60;br /&#62;
YS&#60;br /&#62;
Dr.Mabuse
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Lee on "Jotti&#039;s Malware Scan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5787#post-60695</link>
			<pubDate>Fri, 24 Jul 2009 07:18:40 +0000</pubDate>
			<dc:creator>Lee</dc:creator>
			<guid isPermaLink="false">60695@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Found another one: &#60;a href=&#34;http://scanner.novirusthanks.org/&#34; rel=&#34;nofollow&#34;&#62;http://scanner.novirusthanks.org/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;As it says it's called no virus thanks.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>notblocklox on "Jotti&#039;s Malware Scan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5787#post-60604</link>
			<pubDate>Thu, 23 Jul 2009 12:57:58 +0000</pubDate>
			<dc:creator>notblocklox</dc:creator>
			<guid isPermaLink="false">60604@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Thanks for reminding of this two very useful sites.&#60;br /&#62;
Yes both links have been mentioned several times, but there are always new users who didn't read it and as we can see, even old hands get some benefit from re-runs.&#60;br /&#62;
So I used both services since a long time, I never found that download link for use in the context menu. Thanks, wizz.&#60;br /&#62;
Perhaps there is somebody who can explain this: &#60;a href=&#34;http://virusscan.jotti.org/hashsearch.php&#34;&#62;Hash search&#60;/a&#62; ?&#60;/p&#62;
&#60;p&#62;graylox
&#60;/p&#62;</description>
		</item>
		<item>
			<title>wizzard_of_ozz2004 on "Jotti&#039;s Malware Scan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5787#post-60599</link>
			<pubDate>Thu, 23 Jul 2009 12:27:21 +0000</pubDate>
			<dc:creator>wizzard_of_ozz2004</dc:creator>
			<guid isPermaLink="false">60599@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;lmao oops guess i forgot to include the link Lee. Thanks for clearing that up. I'm just a little tired, you have no idea how many times I actually edited that first post before I was happy with it.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Lee on "Jotti&#039;s Malware Scan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5787#post-60597</link>
			<pubDate>Thu, 23 Jul 2009 12:08:10 +0000</pubDate>
			<dc:creator>Lee</dc:creator>
			<guid isPermaLink="false">60597@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;wizzard advertised that already.&#60;/p&#62;
&#60;p&#62;I like them both.&#60;/p&#62;
&#60;p&#62;Virustotal software is a bum to find, it's direct link is: &#60;a href=&#34;http://www.virustotal.com/vtsetup.exe&#34; rel=&#34;nofollow&#34;&#62;http://www.virustotal.com/vtsetup.exe&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;Once installed all you do is right click a file and hit send to then virustotal.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>ido99 on "Jotti&#039;s Malware Scan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5787#post-60595</link>
			<pubDate>Thu, 23 Jul 2009 11:44:47 +0000</pubDate>
			<dc:creator>ido99</dc:creator>
			<guid isPermaLink="false">60595@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Thanks, but &#60;a href=&#34;http://www.VIRUSTOTAL.com/&#34; rel=&#34;nofollow&#34;&#62;http://www.VIRUSTOTAL.com/&#60;/a&#62; is better.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Lee on "Jotti&#039;s Malware Scan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5787#post-60593</link>
			<pubDate>Thu, 23 Jul 2009 11:11:52 +0000</pubDate>
			<dc:creator>Lee</dc:creator>
			<guid isPermaLink="false">60593@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Thanks, I tried it, yet to try the software, be good as a shortcut from the desktop.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>wizzard_of_ozz2004 on "Jotti&#039;s Malware Scan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5787#post-60591</link>
			<pubDate>Thu, 23 Jul 2009 10:45:31 +0000</pubDate>
			<dc:creator>wizzard_of_ozz2004</dc:creator>
			<guid isPermaLink="false">60591@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;&#60;a href=&#34;http://www.virustotal.com&#34; rel=&#34;nofollow&#34;&#62;http://www.virustotal.com&#60;/a&#62; is another such site Lee. VirusTotal has 39 scanners backing it and it is an award winner from PCWorld Thanks for the recommendation of Jotti. I don't know where I got it from, but I downloaded software from them and now I just right click on a file and in the send to option is VirusTotal. It will automatically send my file to the site to scan rather than going to the site first and uploading it. I'll look around for a download page and update later.&#60;/p&#62;
&#60;p&#62;&#60;strong&#62;Edit&#60;/strong&#62;&#60;/p&#62;
&#60;p&#62;I found the download page. Click on the Download button at the bottom of the page =)
&#60;/p&#62;</description>
		</item>
		<item>
			<title>LeKanaw on "Jotti&#039;s Malware Scan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5787#post-60580</link>
			<pubDate>Thu, 23 Jul 2009 07:30:09 +0000</pubDate>
			<dc:creator>LeKanaw</dc:creator>
			<guid isPermaLink="false">60580@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Thank You Lee&#60;/p&#62;
&#60;p&#62;I've heard good things about Jotti, but had forgotten. Must be in a BM somewhere 'round here ...&#60;br /&#62;
Thank you for reminding us&#60;/p&#62;
&#60;p&#62;Ciao
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Lee on "Jotti&#039;s Malware Scan"</title>
			<link>http://www.giveawayoftheday.com/forums/topic/5787#post-60578</link>
			<pubDate>Thu, 23 Jul 2009 07:07:49 +0000</pubDate>
			<dc:creator>Lee</dc:creator>
			<guid isPermaLink="false">60578@http://www.giveawayoftheday.com/forums/</guid>
			<description>&#60;p&#62;Was trying out a-squared this morning and watching all the malware it was reporting&#60;/p&#62;
&#60;p&#62;even though NIS2009, Windows Defender and Spy-Bot Search &#38;#38; Destroy reported nothing.&#60;/p&#62;
&#60;p&#62;It was bothering me and I am doing a deep scan it's at 3% and that is after 40 minutes.&#60;/p&#62;
&#60;p&#62;It has found so far, 8 suspicious files.&#60;/p&#62;
&#60;p&#62;I expected a couple were a bit spurious, though never detected by the fore-mentioned scanners.&#60;/p&#62;
&#60;p&#62;I found a site, where you can upload your file which is seen as suspicious and 21 scanners will simultaneously scan the file and report what has been found.&#60;/p&#62;
&#60;p&#62;If this has been posted before then stand-on-me, I thought it would help people stop worrying about files being reported by a lone-scanner as a problem.&#60;/p&#62;
&#60;p&#62;Link:  &#60;a href=&#34;http://virusscan.jotti.org/en&#34; rel=&#34;nofollow&#34;&#62;http://virusscan.jotti.org/en&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;Contains many different languages, English is default.
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
