<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ismailsaleh.net &#187; anti-malware</title>
	<atom:link href="http://ismailsaleh.net/tag/anti-malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://ismailsaleh.net</link>
	<description>Truth to tell</description>
	<lastBuildDate>Thu, 03 May 2012 03:45:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>tr/crypt.fkm.gen infection</title>
		<link>http://ismailsaleh.net/2009/11/21/trcrypt-fkm-gen-infection/</link>
		<comments>http://ismailsaleh.net/2009/11/21/trcrypt-fkm-gen-infection/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 16:17:27 +0000</pubDate>
		<dc:creator>Ismail Saleh</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[ad-aware]]></category>
		<category><![CDATA[anti-malware]]></category>
		<category><![CDATA[antivir]]></category>
		<category><![CDATA[avira]]></category>
		<category><![CDATA[fkm]]></category>
		<category><![CDATA[gen]]></category>
		<category><![CDATA[hijack-this]]></category>
		<category><![CDATA[srypt]]></category>
		<category><![CDATA[tr]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://ismailsaleh.net/?p=47</guid>
		<description><![CDATA[My laptop was infected by this trojan name tr/crypt.fkm.gen as detected by avira antivir. Some information taken from Sophos : Troj/Scrods-Gen is a family of Trojans for the Windows platform. Members of Troj/Scrods-Gen usually attempt to download and execute files &#8230; <a href="http://ismailsaleh.net/2009/11/21/trcrypt-fkm-gen-infection/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>My laptop was infected by this trojan name tr/crypt.fkm.gen as detected by avira antivir.</p>
<p>Some information taken from <a href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojscrodsgen.html" target="_blank">Sophos</a> :</p>
<blockquote><p>Troj/Scrods-Gen is a family of Trojans for the Windows platform.</p>
<p>Members of Troj/Scrods-Gen usually attempt to download and execute files from remote locations.</p>
<p>Members of Troj/Scrods-Gen may attempt to copy itself to the Windows folder, often with the filename csrss.scr, and may set the following registry entry:</p>
<p>HKCR\.key<br />
(default)<br />
regfile</p></blockquote>
<p>I did not know from where did it come from. But my suspect is from torrent, where I download a video (a movie, old one) and when launch it Windows Media Player popup a message said that I need to download a free codec. I did download it (silly me!) and actually run it (an exe file). And nothing happen at that time.</p>
<p>But few days later Avira start to popup this message about tr/crypt.fkm.gen trojan and it detect it at file that is in System32 folder. Oh Boy! Nope! Avira unable to delete it. Ad-Aware not able to detect it. Hijack-This able to delete its entry, but it will magically reappear again.</p>
<p>The way I remove it is by running Malwarebytes&#8217; Anti-Malware. That also took several reboot to clear it from the system&#8230;</p>
<p>Scary&#8230;. when you have too much important data inside.</p>
]]></content:encoded>
			<wfw:commentRss>http://ismailsaleh.net/2009/11/21/trcrypt-fkm-gen-infection/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

