<?xml version="1.0"?><rss version="2.0"><channel><title>Software Download, freeware, shareware, demo trail versions</title><link>http://www.applicationindex.com/index.php</link><description></description><generator></generator><item><title>Backdoor.Ryknos Removal Tool </title><description><![CDATA[Backdoor.Ryknos Removal Tool is designed to remove the infections of 
· Backdoor.Ryknos 
· Backdoor.Ryknos.B 
· SecurityRisk.First4DRM

Please disconnect the computer from the network and Internet first, if you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with Read Only access or by using password protection. 

If you are removing an infection from a network, first make sure that all the shares are disabled or set to Read Only. 
This tool is not designed to run on Novell NetWare servers. To remove this threat from a NetWare server, first make sure that you have the current virus definitions, and then run a full system scan with the Symantec antivirus product.

Usage:
· Close all the running programs. 
· If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet.
· Locate the file that you just downloaded. 
· Double-click the FixRyknos.exe file to start the removal tool. 
· Click Start to begin the process, and then allow the tool to run. 
· Restart the computer. 
· Run the removal tool again to ensure that the system is clean. 
· If you are running Windows Me/XP, then reenable System Restore. 
· If you are on a network or if you have a full-time connection to the Internet, reconnect the computer to the network or to the Internet connection. 
· Run LiveUpdate to make sure that you are using the most current virus definitions

What's New in This Release:

· released to add extra support

]]></description><summary><![CDATA[Backdoor.Ryknos Removal Tool is designed to remove the infections of Backdoor.Ryknos, Backdoor.Ryknos.B & SecurityRisk.First4DRM ]]></summary><website>http://www.symantec.com/security_response/writeup.jsp?docid=2005-111016-4134-99</website><download>http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixRyknos.exe</download><platform>Windows </platform><filesize>169 KB </filesize><price>freeware</price><author>Symantec Corporation </author><email>submit@applicationindex.com</email><added>1220703667</added><updated>1220703667</updated><url>backdoor.ryknos-removal-tool</url><keywords>Removal Tool , remove Backdoor.Ryknos , remove infection , Backdoor , Ryknos , Removal</keywords></item><item><title>Trojan.Vundo free Removal Tool </title><description><![CDATA[Trojan.Vundo free Removal Tool was designed to remove the infections of Trojan.Vundo.

If you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem, disconnect the computer from the network and Internet. 

Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. 

Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not re-infect the computer after it has been 
Disable or password-protect file sharing, or set the shared files to Read Only, ection.
]]></description><summary><![CDATA[This tool is designed to run a desinfection of Trojan.Vundo ]]></summary><website>http://www.symantec.com/security_response/writeup.jsp?docid=2004-112210-3747-99</website><download>http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixVundo.exe</download><platform>Windows All </platform><filesize>162 KB</filesize><price>freeware</price><author>Symantec </author><email>submit@applicationindex.com</email><added>1220703115</added><updated>1220703115</updated><url>trojan.vundo-free-removal-tool</url><keywords>Trojan Vundo removal tool , Vundo cleaner , clean trojan Vundo , Trojan , Vundo , removal</keywords></item><item><title>InfoArmor </title><description><![CDATA[InfoArmor is the ONLY software that can authorize a program to visit protected folders or files. Most file-protect software prevent unwanted user to access protected files, but InfoArmor prevents unwanted software or program to access them. 

This make InfoArmor very suitable for website-protecting: You may permit only webserver and ftp software to access your web pages,any other programs,event windows kernel process, can not be utilized by hackers to deface your webpages.InfoArmor is a program which protects webpages and important files against hackers.

InfoArmor works in kernel mode. Unlike most other website protector, it consumes very little of the memory and CPU resource. It works in "Trigger" mode and never check your webfiles periodically. It starts with windows system starts up. There's no need to logon and manually start it.

InfoArmor makes it very simple to defend trojan, virus, spyware, and other unkown malicious program: they can't be planted onto your disk.

When alarm is triggered,InfoArmor provide an option to let you make a decision, InfoArmor can remember this decision and change it's security rule at runtime.

InfoArmor can protect your website in background, and the protection service is invisible.

InfoArmor can protect both folders and files with wild cards. So, you can protect all files in all directories / folders of your choice.

InfoArmor can save all the warning messages to log file, and mail the warning messages to you automaticly, so if something happen, you will be notified at immediately.

Configurable configuration files. With this feature, configuration file can be put somewhere on the network, thus make administration easier.
]]></description><summary><![CDATA[Protect webpages and important files against hacker, defend trojan and virus ]]></summary><website>http://www.qwerks.com/Product/8306.html</website><download>http://www.qwerks.com/download/8306/USMSetup.EXE</download><platform>Windows NT / 2K / XP / 2003 </platform><filesize>2 MB </filesize><price>USD 29.95</price><author>InfoArmor Workgroup </author><email>info@qwerks.com </email><added>1220702660</added><updated>1220702660</updated><url>infoarmor</url><keywords>authorize program , Protect webpage , protect file , authorize , protect , antivirus</keywords></item><item><title>Symantec W32.Sober Removal Tool </title><description><![CDATA[Symantec Security Response has developed a removal tool to clean the infections of the following W32.Sober variants:
· W32.Sober@mm
· W32.Sober.B@mm
· W32.Sober.C@mm
· W32.Sober.D@mm
· W32.Sober@mm.enc
· W32.Sober.gen
· W32.Sober.E@mm
· W32.Sober.F@mm
· W32.Sober.G@mm
· W32.Sober.I@mm
· W32.Sober.L@mm
· W32.Sober.N@mm
· W32.Sober.O@mm
· W32.Sober.Q@mm
· W32.Sober.V@mm
· W32.Sober.W@mm
· W32.Sober.X@mm

W32.Sober.gen is a generic detection that can detect any variants of W32.Sober. If your computer is detected as infected with W32.Sober.gen, download and run the tool. In most cases, the tool will be able to remove the infection.

The W32.Sober Removal Tool does the following: 
· Terminates the W32.Sober viral processes. 
· Deletes the W32.Sober files. 
· Deletes the dropped files. 
· Deletes the registry values that the worm added

What's New in This Release:

· released to add support for W32.Sober.X@mm

 
]]></description><summary><![CDATA[Symantec Security Response has developed a removal tool to clean the infections of the W32.Sober variants ]]></summary><website>http://www.symantec.com/security_response/writeup.jsp?docid=2003-102909-2446-99</website><download>http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixSbr.exe</download><platform>Windows All </platform><filesize>178 KB</filesize><price>freeware</price><author>Symantec Corporation </author><email>submit@applicationindex.com</email><added>1220702286</added><updated>1220702286</updated><url>symantec-w32.sober-removal-tool</url><keywords>remove W32.Sober , Removal Tool , detect W32.Sober , remove , Removal , W32.Sober</keywords></item><item><title>W32.Secefa Removal Tool </title><description><![CDATA[W32.Secefa Removal Tool is designed to remove the infections of the following threats: 
· W32.Secefa.A
· W32.Secefa.B
· W32.Secefa.C
· Trojan.Gamqowi

If you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem, disconnect the computer from the network and Internet. Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. 

To ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with Read Only access or by using password protection, because W32.Secefa spreads by using shared folders on networked computers.

If you are removing an infection from a network, first make sure that all the shares are disabled or set to Read Only. 

This tool is not designed to run on Novell NetWare servers. To remove this threat from a NetWare server, first make sure that you have the current virus definitions, and then run a full system scan with the Symantec antivirus product.

Usage:
· Close all the running programs. 
· If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet. 
· If you are running Windows Me or XP, turn off System Restore
· Click Start to begin the process, and then allow the tool to run
· Restart the computer. 
· Run the removal tool again to ensure that the system is clean. 
· If you are running Windows Me/XP, then reenable System Restore. 
· If you are on a network or if you have a full-time connection to the Internet, reconnect the computer to the network or to the Internet connection. 
· Run LiveUpdate to make sure that you are using the most current virus definitions.

When the tool has finished running, you will see a message indicating whether the threat has infected the computer. The tool displays results similar to the following: 
· Total number of the scanned files 
· Number of deleted files 
· Number of repaired files 
· Number of terminated viral processes 
· Number of fixed registry entries

W32.Secefa Removal Tool does the following: 
· Terminates the associated processes 
· Deletes the associated files 
· Deletes the registry values added by the threat

]]></description><summary><![CDATA[W32.Secefa Removal Tool is designed to remove the infections of W32.Secefa.A, W32.Secefa.B, W32.Secefa.C and Trojan.Gamqowi ]]></summary><website>http://www.symantec.com/security_response/writeup.jsp?docid=2005-120211-0059-99</website><download>http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FxSecefa.exe</download><platform>Windows All </platform><filesize>171 KB </filesize><price>freeware</price><author>Symantec Corporation</author><email>submit@applicationindex.com</email><added>1220701878</added><updated>1220701878</updated><url>w32.secefa-removal-tool</url><keywords>Removal Tool , remove W32.Secefa , Trojan.Gamqowi remover , W32.Secefa , Removal , remove</keywords></item><item><title>AntiVirus Tester </title><description><![CDATA[AntiVirus Tester can test Windows on a level of safety
]]></description><summary><![CDATA[AntiVirus Tester can test Windows on a level of safety ]]></summary><website>http://www.geocities.com/SiliconValley/6190/at.html</website><download>http://www.geocities.com/SiliconValley/6190/DrASMp.zip</download><platform>Windows All </platform><filesize>134 KB </filesize><price>freeware</price><author>Sergey Antonov </author><email>mmist@rambler.ru</email><added>1220701470</added><updated>1220701470</updated><url>antivirus-tester</url><keywords>test safety , safety level , AntiVirus Tester , test , safety , AntiVirus</keywords></item><item><title>ClamMail </title><description><![CDATA[ClamMail is a personal POP3 proxy for Windows which can also filter emails deleting malware.

ClamMail can be used as a POP3 proxy only and (and this was the main reason to create it) to filter incoming emails and delete all unwanted malwares (viruses, trojans, phishings and more).

Here are some key features of "ClamMail":

· POP3 proxy for single computer or small network allow sharing single Internet connection if only e-mail retrieve is needed 
· Delete unwanted malware from e-mails using ClamAV antivirus engine 
· Automatic background antivirus database updates 
· Reporting by e-mail if malware was found 
· Work as Windows NT/XP/2000 service or as Win98 application 
· Under Windows NT/XP/2000 any information,warnings,errors are stored in system event log (available to admins using event log viewer from network also) 
· Localized versions (currently: English,Polish,German) 
· Licensed under GNU General Public License 
· Can be extended (process is started) to full antivirus]]></description><summary><![CDATA[ClamMail is a personal POP3 proxy that can filter emails deleting malware ]]></summary><website>http://www.bransoft.com/clammail/en/clammail.html</website><download>http://sourceforge.net/project/showfiles.php?group_id=125389</download><platform>Windows All </platform><filesize>1.4 MB </filesize><price>freeware</price><author>Bogus?aw Brandys </author><email>submit@applicationindex.com</email><added>1220700918</added><updated>1220700918</updated><url>clammail</url><keywords>mail filter , delete malware , POP3 proxy , ClamMail , mail , filter</keywords></item><item><title>Kaspersky Anti-Virus for Microsoft ISA Server Enterprise Edition </title><description><![CDATA[Kaspersky Anti-Virus for Microsoft ISA Server 2004 Enterprise Edition (hereafter, also Kaspersky Anti-Virus for ISA Servers) is a system of anti-virus protection of files transferred using the HTTP and FTP protocols via the Microsoft Internet Security and Acceleration Server. It ensures reliable protection of corporate networks from penetration of malicious software.

Kaspersky Anti-Virus for Microsoft ISA Server acts as a filter that intercepts packets transferred via the HTTP and FTP protocols, isolates controlled objects from this data, analyzes them for the presence of viruses and prevents infected files and Web documents from penetrating a corporate network. 

Kaspersky Anti-Virus for Microsoft ISA Server Enterprise Edition includes data stream filters and the anti-virus kernel. The filters are integrated into Microsoft ISA Server as plug-ins, and the anti-virus kernel is installed into the system as a service.

The anti-virus protection is managed through a special interface built into the ISA administration snap-in for Microsoft Management Console (MMC) as an extension. 

Kaspersky Anti-Virus for Microsoft ISA Server Enterprise Edition will perform the following functions:
· Anti-virus protection and processing of data streams received from the Internet.
· Generation of data streams from disinfected files and the delivery of these streams to the client upon request.
· Scheduled and manual updating of the anti-virus database via the Internet, a local folder, or a shared folder.
· Logging of statistics about program performance and displaying the results using standard Windows tools.
· Management of license keys.

In addition, Kaspersky Anti-Virus for Microsoft ISA Server allows the administrator to:
· Set parameters for anti-virus protection and for notifications about dangerous events.
· Create groups of users in accordance with the adopted network policy.
For example, you can use the existing administration division to define anti-virus policy settings for each of the groups created. This can significantly speed up the scanning process.
· Create a list of trusted servers for one or several groups of users; the traffic from these servers will be excluded from scanning for viruses.
· Create a list of types of object excluded from anti-virus protection.

Kaspersky Anti-Virus supports the following data transfer protocols:
· HTTP 1.0 and 1.1 (RFC 2616);
· FTP (RFC 959, 2389, Extensions to FTP);
· FTP over HTTP.

Requirements:

· Microsoft Windows 2003 Server operating system
· Microsoft ISA Server 2004 Enterprise Edition installed on the computer.

Kaspersky Anti-Virus can be installed only on array servers that belong to a Microsoft Windows 2003 domain. All array members must authenticate on the configuration server (ISA Configuration Storage Server) using their domain accounts. Kaspersky Anti-Virus cannot work on array servers connected to the configuration server via SSL.

To install Kaspersky Anti-Virus, the user must have local administrator and domain administrator rights. The user also should have rights to administer the server array on which the application is installed.
]]></description><summary><![CDATA[Anti-virus protection of files transferred using the HTTP and FTP protocols via the MS Internet Security and Acceleration Server ]]></summary><website>http://www.kaspersky.com/index.html</website><download>http://www.kaspersky.com/downloads</download><platform>Windows 2003 </platform><filesize>14 MB </filesize><price>freeware</price><author>Kaspersky Labs </author><email>Kaspersky-Global@arvato-systems.de</email><added>1220700137</added><updated>1220700137</updated><url>kaspersky-anti-virus-for-microsoft-isa-server-enterprise-edition</url><keywords>anti-virus protection , secure transfer , prevent infection , Kaspersky , Anti-Virus , ISA</keywords></item><item><title>DefencePlus </title><description><![CDATA[Antivirus software and firewalls play valuable roles in protecting your system. However they cannot protect your computer from hackers and worms that use buffer overflow security holes in Windows to infiltrate into the system. Once your computer is under hackers' control, they will turn your day into a nightmare. In a few seconds they can stealthily copy your documents, passwords, credit card numbers or run a malicious application.

DefencePlus is a software that provides you an anti-hacking protection.

DefencePlus offers what traditional antiviruses and firewalls miss - a real-time anti-hacking protection. It is specifically designed to eliminate stack- and heap-based buffer overflow vulnerabilities, traditionally exploited by hackers. The program silently runs in the background, watching for hacker and worm assaults and blocks any intrusion-like process from the outset before it compromises the integrity of your system.

As distinct from its competitors, DefencePlus protects your entire system, including the operating system, its components and all software installed on your computer. Four security levels are available - low, medium, high and ultra. By specifying the security level for each application individually, you can achieve a full compatibility of DefencePlus with your system and minimize the number of misoperations.

With DefencePlus you will no longer fear that any unscrupulous parasite can read your emails, modify your system settings, or infect your computer with a virus. Thanks to the minimal resource utilization, the program doesn't hinder computer performance. And by using DefencePlus with a good antivirus product and a firewall, you get the unyielding three-layer protection system against all kinds of security threats.

]]></description><summary><![CDATA[DefencePlus is an invisible anti-hacking armor for Windows ]]></summary><website>http://www.softsphere.com/</website><download>http://www.softsphere.com/downloads/</download><platform>Windows NT / 2K / XP / 2003 </platform><filesize>425 KB </filesize><price>USD 39.00 </price><author>SoftSphere Technologies </author><email>info@softsphere.com </email><added>1220699711</added><updated>1220699711</updated><url>defenceplus</url><keywords>anti-hacking armor , anti-hacking protection , block intrusion , DefencePlus , anti-hacking , anti-hacker</keywords></item><item><title>MalWhere </title><description><![CDATA[What is MalWhere? 
Does your computer run slow or crash from time to time? If so then there might be a malicious process running on your system without you knowing about it.

A process is a single executable module that runs concurrently with other executable modules, most of the processes that run on your computer are valid software that you installed, but many times its not.

A Process can be a virus, Trojan or a spyware. 
MalWhere offers you information about the processes currently running on you computer.
MalWhere provides you with the tools to terminate and eliminate any program that may disrupt, damage, slowdown or crash your system.

Even if the process is fairly new and MalWhere DB isn't updated yet, its AI (Artificial Intelligent) algorithm will query search engines and analyze it for you.

Be the first to know when a malicious process is running on your computer!!!
]]></description><summary><![CDATA[MalWhere provides you with information about the processes currently running on you system. ]]></summary><website>http://www.malwhere.com/</website><download>http://www.malwhere.com/download.html</download><platform>Windows All </platform><filesize>1.1 MB </filesize><price>freeware</price><author>Ran Geva </author><email>ran@rangeva.com</email><added>1220698690</added><updated>1220698690</updated><url>malwhere-6099</url><keywords>malwhere detector , malwhere process , process malwhere , process , malwhere , detect</keywords></item><item><title>W32.Blackmal@mm Removal Tool </title><description><![CDATA[W32.Blackmal@mm Removal Tool is designed to remove the infections of W32.Blackmal.E@mm. 

If you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem, disconnect the computer from the network and Internet. Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. 

Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with Read Only access or by using password protection. 

If you are removing an infection from a network, first make sure that all the shares are disabled or set to Read Only. 

W32.Blackmal@mm Removal Tool was not designed to run on a Novell NetWare server. To remove this threat from a NetWare server, first make sure that you have the current virus definitions, and then run a full system scan with the Symantec antivirus product.

Usage:
Important: You must have administrative rights to run this tool on Windows NT 4.0, Windows 2000, or Windows XP.

Note for network administrators: If you are running MS Exchange 2000 Server, we recommend that you exclude the M drive from the scan by running the tool from a command line, with the Exclude switch. For more information, read the Microsoft knowledge base article: XADM: Do Not Back Up or Scan Exchange 2000 Drive M (Article 298924).

· Download the FixBmalE.exe file from: http://securityresponse.symantec.com/avcenter/FixBmalE.exe. 
· Save the file to a convenient location, such as your Windows desktop
· Close all the running programs. 
· If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet
· Locate the file that you just downloaded. 
· Double-click the FixBmalE.exe file to start the removal tool. 
· Click Start to begin the process, and then allow the tool to run
· Restart the computer. 
· Run the removal tool again to ensure that the system is clean. 
· If you are running Windows Me/XP, then reenable System Restore. 
· If you are on a network or if you have a full-time connection to the Internet, reconnect the computer to the network or to the Internet connection. 
· Run LiveUpdate to make sure that you are using the most current virus definitions

When the tool has finished running, you will see a message indicating whether the threat has infected the computer. The tool displays results similar to the following: 
· Total number of the scanned files 
· Number of deleted files 
· Number of repaired files 
· Number of terminated viral processes 
· Number of fixed registry entries

The Removal Tool does the following: 
· Terminates the associated processes 
· Deletes the associated files 
· Deletes the registry values added by the threat
]]></description><summary><![CDATA[W32.Blackmal@mm Removal Tool is designed to remove the infections of W32.Blackmal.E@mm ]]></summary><website>http://www.symantec.com/security_response/writeup.jsp?docid=2006-011712-3235-99</website><download>http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixBmalE.exe</download><platform>Windows All </platform><filesize>168 KB </filesize><price>freeware</price><author>Symantec Corporation</author><email>submit@applicationindex.com</email><added>1220698072</added><updated>1220698072</updated><url>w32.blackmal-mm-removal-tool-6097</url><keywords>Removal Tool , remove infection,  remove W32.Blackmal.E@mm , Removal , remove , infection</keywords></item><item><title>F-Force Malware Disinfection </title><description><![CDATA[F-Force Malware Disinfection is a useful program that will disinfects computers who are infected with known variants of the following malware:

Agobot (Backdoor.Win32.Agobot)
Aimbot (Backdoor.Win32.Aimbot)
Bagle (Email-Worm.Win32.Bagle, except .N, .O, .P, .Q, .R variants)
Bozori (Net-Worm.Win32.Bozori)
Codbot (Backdoor.Win32.Codbot)
Dumaru (Email-Worm.Win32.Dumaru)
Fanbot (Backdoor.Win32.Fanbot)
Forbot (Backdoor.Win32.Forbot)
IRCBot (Backdoor.Win32.IRCBot)
Mitglieder (Trojan-Proxy.Win32.Mitglieder or Trojan-Spy.Win32.Mitglieder)
Mydoom (Email-Worm.Win32.Mydoom)
Mytob (Net-Worm.Win32.Mytob)
Netsky (Email-Worm.Win32.NetSky)
Padobot (Net-Worm.Win32.Padobot)
Poebot (Backdoor.Win32.Poebot)
Rbot (Backdoor.Win32.Rbot)
SDBot (Backdoor.Win32.SdBot)
Spybot (P2P-Worm.Win32.SpyBot)
Wootbot (Backdoor.Win32.Wootbot)
Zafi (Email-Worm.Win32.Zafi)

In addition the F-Force utility detects EICAR test file.

The F-Force utility might be able to disinfect computers that are infected
with new variants of these backdoors and worms, however disinfection will
only work if these variants are detected generically by AVP engine.

The F-Force utility disinfects Windows HOSTS file by removing entries that
were added by malware. In addition the utility automatically restores the
default EXE file startup string in case it was modified by malware.

The F-Force utility creates a log file named F-FORCE.LOG in the root
Windows directory (usually C:WINDOWS). The log file is appended every
time the F-Force utility is run.

HOW TO MAKE IT WORK:

1. Unpack the F-Force utility from the provided ZIP archive either with
WinZip or PkUnzip utilities. A trial version of WinZip archiver can be
downloaded from the following website:

http://www.winzip.com/ddchomea.htm

2. Download the archive called LATEST.ZIP from F-Secure web or ftp sites.
This archive contains the latest anti-virus database files. It can be
downloaded from these URLs:

http://www.f-secure.com/download-purchase/latest.zip
ftp://ftp.f-secure.com/anti-virus/updates/latest/latest.zip

3. Place the downloaded LATEST.ZIP archive in the same folder where the
F-Force utility is located.

4. Run the unpacked F-Force.exe file from a hard disk to eliminate malware
infection. You can run the utility by either double-clicking on its file
from Windows Explorer or you can start it from a command prompt (to open a
command prompt click 'Start' button, select 'Run' menu and type CMD.EXE
(if you have Windows NT, 2000 or XP) or type COMMAND.COM (if you have
Windows 98 or ME). Then press 'Enter' to run the command interpreter. In
the opened command prompt window you have to type CD command followed by
a folder name where the F-Force utility is located, for example:

CD C:TEMP

Press 'Enter' to run that command. To run the F-Force utility from that
folder type F-FORCE and press 'Enter'.

First the F-Force utility will kill all detected malware processes in
memory. Then the utility will remove all startup Registry key values
created by the malware and finally it will scan all available hard disks
and delete all infected files. If needed, the utility disinfects Windows
HOSTS file and restores the default value of EXE file startup key in the
Registry.

5. Reboot the system. After restart your system should be clean from the
above mentioned malware.

If you have F-Secure Anti-Virus installed, the utility will temporarily
disable the on-access scanner (OAS) to be able to disinfect your system.
After the utility completes disinfection it enables the on-access scanner.

You can get a trial version of F-Secure Anti-Virus and the latest updates
for it from our website:

http://www.f-secure.com/download-purchase/list.shtml
http://www.f-secure.com/download-purchase/updates.shtml
]]></description><summary><![CDATA[F-Force is a free malware disinfection utility created by F-Secure ]]></summary><website>http://www.f-secure.com/</website><download>http://www.f-secure.com/downloads/</download><platform>Windows All </platform><filesize>228 KB </filesize><price>freeware</price><author>F-Secure Corporation </author><email>helsinki@f-secure.com</email><added>1220697627</added><updated>1220697627</updated><url>f-force-malware-disinfection-6095</url><keywords>malware disinfecter , virus scanner , virus protector , antivirus , virus , scan</keywords></item><item><title>W32.Kiman Removal Tool </title><description><![CDATA[This tool is designed to remove the infections of W32.Kiman.A.

If you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem, disconnect the computer from the network and Internet. Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with Read Only access or by using password protection. 

If you are removing an infection from a network, first make sure that all the shares are disabled or set to Read Only. 

This tool is not designed to run on Novell NetWare servers. To remove this threat from a NetWare server, first make sure that you have the current virus definitions, and then run a full system scan with the Symantec antivirus product

You must have administrative rights to run this tool on Windows NT 4.0, Windows 2000, or Windows XP.

Note for network administrators: If you are running MS Exchange 2000 Server, we recommend that you exclude the M drive from the scan by running the tool from a command line, with the Exclude switch

Usage:
· Close all the running programs. 
· If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet. 
· If you are running Windows Me or XP, turn off System Restore
· Double-click the FxKiman.exe file to start the removal tool. 
· Click Start to begin the process, and then allow the tool to run
NOTE: If you have any problems when you run the tool, or it does nor appear to remove the threat, restart the computer in Safe mode and run the tool again
· Restart the computer. 
· Run the removal tool again to ensure that the system is clean. 
· If you are running Windows Me/XP, then reenable System Restore. 
· If you are on a network or if you have a full-time connection to the Internet, reconnect the computer to the network or to the Internet connection. 
· Run LiveUpdate to make sure that you are using the most current virus definitions

When the tool has finished running, you will see a message indicating whether the threat has infected the computer. W32.Kiman Removal Tool will display results similar to the following:
· Total number of the scanned files 
· Number of deleted files 
· Number of repaired files 
· Number of terminated viral processes 
· Number of fixed registry entries

The Removal Tool does the following: 
· Terminates the associated processes 
· Deletes the associated files 
· Deletes the registry values added by the threat
]]></description><summary><![CDATA[This tool is designed to remove the infections of W32.Kiman.A ]]></summary><website>http://www.symantec.com/security_response/writeup.jsp?docid=2006-020215-2339-99</website><download>http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixKiman.exe</download><platform>Windows All </platform><filesize>159 KB </filesize><price>freeware</price><author>Symantec Corporation </author><email>submit@applicationindex.com</email><added>1220697252</added><updated>1220697252</updated><url>w32.kiman-removal-tool-6094</url><keywords>Removal Tool , remove infection , remove W32.Kiman , W32.Kiman , Removal , remove</keywords></item><item><title>PC Security Suite </title><description><![CDATA[PC Security Suite includes Spyware and Virus Protection from Computer Associates eliminates unauthorized access to your PC, at home, the office, or on the road. PC Security Suite is easy to install/use and provides reliable and high-performance protection instantly when installed. 

PC Security Suite has an intuitive interface that allows users to easily adjust default settings to create custom configurations. 

Features include: Packet Filtering , Port Scanning, IP/Website Protection, Email Anomaly Detection, and Advanced Application Protection. 

PC Security Suite is high-performance desktop security that is affordable, feature-rich and simple to use. PC Security Suite includes eTrust Pestpatrol Anti-Spyware and eTrust Anti-Virus from Computer Associates, which detects and removes spyware, adware, viruses, worms, and other web-based threats to protect your PC from information theft and diminished system performance. 

eTrust PestPatrol and Anti-Virus complements PC Security Suite’s personal firewall protection to provide comprehensive security for safe Internet connectivity. For continuous security protection, real-time logs are created to help you isolate problems and perform spyware and virus scans when needed.
]]></description><summary><![CDATA[Personal Firewall with Spyware and Virus Protection - Total Desktop Security]]></summary><website>http://www.privacyware.com/</website><platform>Windows All</platform><filesize>16.6 MB</filesize><price>49.95$</price><author>Privacyware.com </author><email>service@privacyware.com </email><added>1219494485</added><updated>1219494485</updated><url>pc-security-suite-5685</url><keywords>PC Security, personal firewall, Virus Protection, PC, Security, personal, firewall</keywords></item><item><title>Trojan.Lodear Removal Tool </title><description><![CDATA[Trojan.Lodear Removal Tool is designed to remove the infections of: 
· Trojan.Lodear.B
· Trojan.Lodav.A

If you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem, disconnect the computer from the network and Internet. Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with Read Only access or by using password protection. 

If you are removing an infection from a network, first make sure that all the shares are disabled or set to Read Only. 

This tool is not designed to run on Novell NetWare servers. To remove this threat from a NetWare server, first make sure that you have the current virus definitions, and then run a full system scan with the Symantec antivirus product

You must have administrative rights to run this tool on Windows NT 4.0, Windows 2000, or Windows XP

Usage:
· Close all the running programs. 
· If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet. 
· Locate the file that you just downloaded. 
· Double-click the FxLodear.exe file to start the removal tool. 
· Click Start to begin the process, and then allow the tool to run. 
· Restart the computer. 
· Run the removal tool again to ensure that the system is clean. 
· If you are running Windows Me/XP, then reenable System Restore. 
· If you are on a network or if you have a full-time connection to the Internet, reconnect the computer to the network or to the Internet connection. 
· Run LiveUpdate to make sure that you are using the most current virus definitions.  




]]></description><summary><![CDATA[Trojan.Lodear Removal Tool is designed to remove the infections of Trojan.Lodear.B and Trojan.Lodav.A]]></summary><website>http://www.symantec.com/security_response/writeup.jsp?docid=2005-110313-3626-99</website><download>http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FxLodear.exe</download><platform>Windows All</platform><filesize>174 KB</filesize><price>freeware</price><author>Symantec Corporation</author><email>genevieve_haldeman@symantec.com</email><added>1219493633</added><updated>1219493633</updated><url>trojan.lodear-removal-tool-5684</url><keywords> Trojan.Lodear Removal, remove Trojan.Lodear, Removal Tool, Trojan.Lodear, Trojan.Lodear.B, Trojan.Lodav.A, Removal</keywords></item><item><title>ADSTools </title><description><![CDATA[Alternate Data Stream files are potentially harmful and cannot be detected by most antivirus and spyware programs.

ADSTools is a program which was developed to find, make and use alternate data stream files on computers with NTFS file systems.

Here are some key features of "ADSTools":

· Find all ADS files on your system
· Edit ADS files
· View ADS files
· Copy or move an existing visible file and make it an ADS file
· Copy or move an ADS file to a visible file location
· Rename ADS files
· Delete ADS files
· Run ADS files 


No other software program has the ability to work with Alternate Data Streams in the way that ADSTools can.
 




]]></description><summary><![CDATA[ADSTools allows users to find, make and use NTFS Alternate Data Stream files]]></summary><website>http://www.adstools.net/</website><platform>Windows NT/2K/XP/2003</platform><filesize>2.06 MB</filesize><price>25$</price><author>ADSTools </author><email>submit@applicationindex.com</email><added>1219493244</added><updated>1219493244</updated><url>adstools</url><keywords>Alternate Data Stream, find dts, Edit ADS, edit, find, ads, files</keywords></item><item><title>Protector Plus for Exchange </title><description><![CDATA[Protector Plus for Exchange is an anti-virus tool designed for Microsoft Exchange server.

Protector Plus scans all the emails received by the mail server and it blocks all the infected emails. Protector Plus ensures that the network will be free of viruses that spread through email. Protector Plus detects emails infected by all types of viruses, trojans and worms before they reach the user's inbox. 

Protector Plus for Exchange is packed with many useful features like remote management, email alerts, InstaUpdate, quarantine, compressed files scanning and many more. 

Protector Plus antivirus software can be remotely managed from anywhere in the network. The remote management software can be used to monitor the activities on the email server and to configure Protector Plus. 

Protector Plus can be configured to send email alerts to the sender of the infected email, to the intended recipient and to the administrator when it detects a virus. 

It maintains informative log files which can be used to analyze the virus incidents and to implement security policies. The InstaUpdate feature of Protector Plus will automatically download the virus database updates from the developer's web site free of cost. 

The updates are released every week and in case of emergencies. Protector Plus for Exchange is easy to install and use. This software works on Exchange 2000 server. This software is a 30 day evaluation copy. Download Protector Plus for Exchange and try free of cost.

Here are some key features of "Protector Plus for Exchange":

· Protector Plus for Exchange scans all the incoming mails, including attachments, before they arrive at the users' mailboxes. Only those emails that do not contain any malware are allowed to pass through the scanning program. Infected emails are blocked. This ensures that no user will get an infected email and the entire network is protected from malware like viruses, trojans, worms, etc., that arrive through email. Protector Plus can be configured to disinfect, delete or quarantine the infected emails. 
· Protector Plus for Exchange comes with a configuration program that can be run from any workstation connected to the Exchange server. This program can be used to view the scanning activity on the server, configure the scan options and virus alerts, view reports, etc.. 
· Protector Plus for Exchange can send virus alerts when it detects a virus in the email. These alerts can be sent to the sender of the infected email, recipients of the infected email, the Administrator or to a list of pre-configured users. The message format to each one of these can also be configured. The alerts sent to the Administrator and to the list of users can be in a digest form as well.
· The remote management program of Protector Plus for Exchange can be used to monitor all the activity done by Protector Plus on the Exchange server. Activity details like the sender of infected emails, the recipients, the attachment details, the action taken by Protector Plus, the total number of emails received, number of infected emails, etc. can be monitored on-line. 
· Protector Plus for Exchange connects automatically to Protector Plus Console or configured website and checks for the availability of upgrades. If it finds either a product update or new virus database files, it picks the update and automatically upgrades the V-Trap. 
· The virus database updates are released every week. Emergency updates are released whenever there is an outbreak of a virus in the wild. The frequency to connect to our site to check for the updates can be configured. 
· Protector Plus for Exchange has the quarantine facility to safely keep the infected files for further analysis. Infected files will be moved to the quarantine folder. The quarantined files will be encrypted and they cannot infect the system. These quarantined files can be restored for further scanning or deleted.
· Protector Plus for Exchange can generate reports that will help the Administrator to understand the virus detection activity done on the server, the origin of the infected emails and their intended recipients. Reports can be viewed for a combination of date range, recipient mailboxes and viruses detected. These reports are useful in implementing user policies and to take corrective actions.
]]></description><summary><![CDATA[Protector Plus antivirus software for Exchange Server]]></summary><website>http://www.pspl.com/</website><download>http://www.pspl.com/download/wntec.htm</download><platform>Windows 2K/XP</platform><filesize>3.74 MB</filesize><price>249.95$</price><author>Proland Software </author><email>webmaster@pspl.com </email><added>1219492751</added><updated>1219492751</updated><url>protector-plus-for-exchange-5681</url><keywords>Exchange server, server antivirus, scan email, Exchange server, antivirus, scan, manage</keywords></item><item><title>EmailSupervisor </title><description><![CDATA[EmailSupervisor will monitor all outgoing emails from your PC and prevents resending your personal data to third persons. 

It also prevents an attempt to use your computer as a platform for spreading malicious code and infecting your colleagues and your family. 

It works on system level regardless of your email client type and its settings. ]]></description><summary><![CDATA[EmailSupervisor - Prevents resending your personal data to third persons.]]></summary><website>http://www.securitysupervisor.com/ </website><download>http://www.securitysupervisor.com/download-es.html</download><platform>Windows 2K/XP</platform><filesize>171 KB</filesize><price>39.95$</price><author>SecuritySupervisor Company</author><email>ss1@securitysupervisor.com</email><added>1219492297</added><updated>1219492297</updated><url>emailsupervisor-5680</url><keywords>monitor e-mail, resend e-mail, personal data, data, personal, resend, e-mail</keywords></item><item><title>Panda TruPrevent Personal 2006 </title><description><![CDATA[TruPrevent Personal is the first product to provide truly effective protection against unknown viruses and intrusions.

TruPrevent Personal protects against the growing risk of infection from new viruses capable of spreading globally in a matter of hours and infecting your computer before you can update your antivirus.

It adds a second layer of defense to complement your antivirus protection and is specifically designed to neutralize unknown attacks. 

It is also extremely effective at combating Internet viruses with the capacity to spread without needing to hide in e-mail messages or attachments.

]]></description><summary><![CDATA[TruPrevent Personal is the first product to provide truly effective protection against unknown viruses and intrusions]]></summary><website>http://www.pandasecurity.com/default</website><download>http://www.pandasecurity.com/enterprise/downloads/</download><platform>Windows All</platform><filesize>16.8 MB</filesize><price>29.95$</price><author>Panda Software International S</author><email>info@pandasecurity.com</email><added>1219491679</added><updated>1219491679</updated><url>panda-truprevent-personal-2006-5679</url><keywords>protect pc, block fraud, combat virus, protect, scan, virus, spyware</keywords></item><item><title>MailScan for MDaemon </title><description><![CDATA[MailScan for MDaemon is a proven antivirus solution made to protect against email viruses and block spam. Situated directly on the MDaemon® email server, rather than dispersed on each client computer, MailScan proactively secures the network by banning harmful email messages at the server.

MailScan for MDaemon scans and cleans all viruses and worms on every component (e.g. HTML attachments, HTML scripts, S/Mime) in an email message. It also provides the utility to delete known malicious attachments like HAPPY99.EXE and EXPLOREZIP right at the Gateway/MDaemon® server level. Once detained, infected email is deleted, quarantined for further review, or forwarded to an administrator. 

MailScan for MDaemon users have the option to receive live antivirus updates from the Internet, via FTP. This antivirus solution automatically upgrades and reconfigures antivirus definitions. Updates can be accomplished with any proxy server and MailScan for MDaemon completely automates all relevant updating tasks, requiring zero administrative efforts.

Here are some key features of "MailScan for MDaemon":

· Virus Scanning 
VisNetic MailScan scans all incoming and outgoing emails for viruses. 

Virus infected attachments are disinfected and sent to their destination. Non-removable virus infected attachments, are either deleted or quarantined. If MailScan detects a Word or Excel attachment that contains an infected macro, it removes the virus from the attachment. Clean Macros are not removed from the document. 

In case of any virus infection, appropriate warning messages, with the Virus Name, Action taken and e-mail details, are sent to the email Sender, the Recipient and the Mail-Server Administrator. 

· AntiVirus Updates
VisNetic MailScan users have the option to receive live updates from the Internet, via FTP. Additionally, broken downloads may be easily resumed whenever necessary. Updates can be accomplished with any proxy server, such as WinRoute Firewall by Deerfield.com. MailScan completely automates all relevant updating tasks, and requires zero administrative efforts. 

Antivirus definitions are available on multiple FTP sites and update requests from MailScan are automatically routed to the first available FTP site, increasing the speed at which new antivirus protection updates are downloaded to the server. 

· Content Scanning 
All incoming and outgoing messages are scanned for abusive words and/or phrases, which are pre-defined by the Security Policy Administrator of MailScan. If such words occur, customizable warning messages can optionally be sent to the Administrator, the sender and the recipient. 

· Pre-defined Security Policies
VisNetic MailScan provides a very easy and convenient way of administrating Rule-Sets and Security Policies. Users can install MailScan and use the default settings. All threats, updates, security policies and rule-sets are "automatically updated" from the Internet, without any user-intervention. 

· Policy based Rule-Sets 
MailScan works on policy-based Rule-Sets. Rule-Sets have been categorized as Universal and Company-specific. A Universal Rule-Set is defined within MailScan and is applicable to all customers. Company-specific Rule-Sets are configured by the Network Administrator and are specific to a company. 

· Powerful Virus Scanning
VisNetic MailScan scans HTML emails and attachments for scripts, also termed IE vulnerabilities. Scripts that contain IFRAME and OBJECT are identified and automatically quarantined by MailScan. To allow for emails with scripts from legitimate sources, pre-approved email addresses may be entered into the MailScan Administrator. 

VisNetic MailScan effectively scans multipart/partial messages for viruses. These messages may be sent through email clients that support multipart/partial messages like Outlook Express. This feature allows Internet and Intranet users to split one sent message into smaller, multiple emails that the receiving client will automatically reassemble as a single message. 

This fragmentation allows users to bypass most security restrictions imposed by mail servers, as emails that are spliced into smaller segments may not be detected by virus scanners or other content filtering mechanisms. MailScan quarantines these message segments and notifies the sender that the message will not be delivered. 

MailScan is one of the first antivirus programs with the ability to detect and disinfect viruses traveling via TNEF (Transport Neutral Encapsulation Format) attachments. Microsoft Outlook uses Rich Text Format (RTF) and TNEF as a standard delivery method. 

· Powerful Content Filtering
VisNetic MailScan's spam email blocker capabilities include the ability to create filters for specific words or phrases, DNS lookup to verify sender's "MX" or "A" record and SMTP server authentication to validate sender's account on sending mail server. 

· Flexible Scanning 
VisNetic MailScan features the option to not scan the content of emails received from or sent to certain domains. This allows administrators to identify an approved or verified safe domain and reduce the amount of scanning required by MailScan. 

· Attachment Reservation 
Administrators can restrict certain attachments from being sent or received from the Internet. For example, a rule can be defined so that any e-mail received by a user having *.EXE or *.COM file attachments, should be auto-forwarded to the administrator. Unknown viruses can be very effectively tackled using such rule-sets. 

· 'Zipped files' Uncompress Facility 
All incoming compressed attachments can be uncompressed, scanned for viruses and passed to the mail server for distribution to the end users. 

· S/MIME Check of Messages
VisNetic MailScan has the capability to check if an e-mail is digitally signed (S/MIME) and warn the user if the content gets changed. 

· Malicious Attachments Deletion 
VisNetic MailScan provides an option to forcibly delete known malicious attachments (Trojans and worms) at the gateway level itself. This list is dynamically updated from the Internet at regular intervals, along with normal AntiVirus Protection and Policy updates. 

· Flexible Notification 
Administrators now have the option to eliminate warning emails to local recipients. This will reduce the volume of email your staff receives notifying them of content violations or virus activity. 

· Urgent Update Overwrite
When subscribed to this FREE service, the postmaster will be sent an email if an urgent antivirus update is made available. When VisNetic MailScan receives this specially coded email, it will trigger the auto update feature causing the urgent update to be downloaded. With "Urgent Updates," MailScan users are protected from fast spreading viruses. 

· Passive Mode FTP Transfers
MailScan supports passive mode, FTP-transfers. MailScan can now receive automatic antivirus updates, safely behind a network's firewall. 

· Runs as a Service
MailScan installs and runs as a service on Windows 95, 98, NT, 2000, and XP. MailScan runs in the background, and is virtually invisible. 

· Virus Warnings
Administrators of VisNetic MailScan can customize virus-warning messages sent to the email sender when an infection is found; virus warnings can be optionally sent to mail recipients, as well. 

· Log Files
All scanning results by MailScan are logged, and administrators have the option to specify maximum size of the log file. The log file allows an administrator to see by whom, when and where viruses are being detected. 

· Background Scanning
With the latest release of MailScan, an administrator can use a supplemental scanner to provide .exe, .doc and .com file scanning. An administrator can use a familiar antivirus protection software package to provide .exe, .doc and .com file scanning, reducing MailScan's workload and speeding up mail processing. MailScan will continue to use the default scanner for scanning archive files, VBS scripts, Applets and other file types. 

· EICAR Test
The European Institute for Computer Anti-Virus Research (EICAR) has developed a test virus. MailScan has added a "Send EICAR Option" that, when tested, shows how MailScan reacts when a virus is detected. This feature can also be used to ensure MailScan is working properly. 

· Virus Information
MailScan provides informative Internet links for live updates on virus information, via the Administrator Help File. 

]]></description><summary><![CDATA[MailScan for MDaemon - a proven antivirus solution designed to protect against email viruses and block spam]]></summary><website>http://www.deerfield.com/products/mailscan/mdaemon/</website><download>http://www.deerfield.com/download/</download><platform>Windows All</platform><filesize>10.3 MB</filesize><price>99.95$</price><author>Deerfield.com </author><email>info@deerfield.com</email><added>1219490080</added><updated>1219490080</updated><url>mailscan-for-mdaemon-5674</url><keywords>mail scaner, Background Scanning, Virus Information, scan, protect, antivirus, email</keywords></item></channel></rss>