<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
	<title>dotTech - Topic: Trojan has been downloaded from an unknown GOATD Software</title>
	<link>http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/</link>
	<description><![CDATA[Professional Technologians]]></description>
	<generator>Simple:Press Version 5.2.6</generator>
	<atom:link href="http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/rss/" rel="self" type="application/rss+xml" />
        <item>
        	<title>Steelers6 on Trojan has been downloaded from an unknown GOATD Software</title>
        	<link>http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p836</link>
        	<category>Tech Support</category>
        	<guid isPermaLink="true">http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p836</guid>
        	        	<description><![CDATA[<p><img src="http://dottech.org/wp-content/forum-smileys/sf-surprised.gif" title="Surprised" alt="Surprised" /></p>
<p>Sorry to hear of your malware.  I too have had instances of malware/viruses after downloading from sites.  I've never been able to pinpoint that it was GOTD and I don't use peer to peer sites.  I have taken the good advice from DotTech and use GesWall, and some great anitivirus software and anitmalware products.  </p>
<p>I think if you read Ashraf's Security suggestions and those of the posters and use them you will be ok.  I can confirm that I got a trojan after a Google toolbar update.  Luckily it was found with Malwarebyte and IObits, and contained with GesWall so I was able to successfully remove it and no harm was done.  </p>
<p>I also make sure to create a restore point before installing any software including Microsofts often distructive updates.</p>
<p>I hope that helps! Check out Asharfs suggestions about the best security.  I'd use SandBoxie but it doesn't support 64 bit OS's.  GesWall does.</p>
<p>Good luck to you and let us know how it turn out.</p>
<p>Vidimo Se!</p>
]]></description>
        	        	<pubDate>Thu, 05 Nov 2009 06:46:34 -0800</pubDate>
        </item>
        <item>
        	<title>JessRabbit on Trojan has been downloaded from an unknown GOATD Software</title>
        	<link>http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p835</link>
        	<category>Tech Support</category>
        	<guid isPermaLink="true">http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p835</guid>
        	        	<description><![CDATA[<p>I just came across this posting, I know its a couple of months old. About a week or two ago, I too experienced my first trojan attack and to my surprise, it came to me through a software downloaded from GAOTD. And I did find out what software it was, "AnVir Task Manager". So not only did my AV catch it, I also went and Uninstalled it immediately. I've been following GAOTD and Dot Tech for about 2 months now..and they do have some good software at times but just remember that some  developer's get there jollies at spreading viruses and then again, I believe I read at GAOTD site,<img src="http://dottech.org/wp-content/forum-smileys/sf-surprised.gif" title="Surprised" alt="Surprised" /> that at one time within the past month or so, that their wrapper was found to have had did a trojan or some malware in it. So that may be possibly where you and I got this at?? But just keep in mind for future reference, that before you do you an install of ANY software, ALWAYS perform an AntiVirus and Malware Scan just to be safe!! Because on the internet, no one is safe from viruses, trojans and the like.</p>
]]></description>
        	        	<pubDate>Thu, 05 Nov 2009 06:04:17 -0800</pubDate>
        </item>
        <item>
        	<title>PTLdom on Trojan has been downloaded from an unknown GOATD Software</title>
        	<link>http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p832</link>
        	<category>Tech Support</category>
        	<guid isPermaLink="true">http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p832</guid>
        	        	<description><![CDATA[<p>Neither Sandboxie or Geswall allow you to test the installation of software that requires rebooting to run. Only a virtualization solution.</p>
]]></description>
        	        	<pubDate>Wed, 04 Nov 2009 15:41:03 -0800</pubDate>
        </item>
        <item>
        	<title>Ozzie on Trojan has been downloaded from an unknown GOATD Software</title>
        	<link>http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p681</link>
        	<category>Tech Support</category>
        	<guid isPermaLink="true">http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p681</guid>
        	        	<description><![CDATA[<p>I definitely agree with ruchir9897 on the value of sandboxing your browser. I used to use Sandboxie, but about a year ago shifted to Geswall, which I really like. Basically, anything you download is automatically sandboxed, so you can check it without it having to worry about your comp becoming affected (of course, no program guarantees 100 percent safety, but combined with a good AV - I use A2 pro -  you should be right).</p>
]]></description>
        	        	<pubDate>Thu, 15 Oct 2009 08:15:22 -0700</pubDate>
        </item>
        <item>
        	<title>ruchir9897 on Trojan has been downloaded from an unknown GOATD Software</title>
        	<link>http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p680</link>
        	<category>Tech Support</category>
        	<guid isPermaLink="true">http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p680</guid>
        	        	<description><![CDATA[<p>True,I have downloaded GOTD soft and two or three are infected by worms/trojans.Best method is to first scan the installer with excellent AV,plus run the installer in virtual environment like Safe run through Kasperskt Internet Sec 2010,power shadow,sandboxie etc. so that even if it contains viruses,it will destroy your computer till restart since these softwares emulates installation and not installs on hard disk.You are safe.....................................</p>
]]></description>
        	        	<pubDate>Thu, 15 Oct 2009 07:47:51 -0700</pubDate>
        </item>
        <item>
        	<title>yourpalal on Trojan has been downloaded from an unknown GOATD Software</title>
        	<link>http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p444</link>
        	<category>Tech Support</category>
        	<guid isPermaLink="true">http://dottech.org/forums/tech-support/trojan-has-been-downloaded-from-an-unknown-goatd-software/#p444</guid>
        	        	<description><![CDATA[<p>Good day All. First of all I&#39;d like to thank Ashraf &#38; others from dottech.org for trying their best to keep us informed &#38; give us support, &#38; for giving us all the detailed step by step instructions so consistently &#38; generously.&#160;It was by following one of Ashraf&#39;s links to a Full Review from GOATD that I 1st saw that someone cared enough to explain technicalities&#160;&#38; help resolve issues &#38; answer questions. GOATD is great &#38; can&#39;t blame them directly. But there, you don&#39;t get the interaction &#38; timely responses from their &#39;team&#39; or moderators&#160;like are done here at dottech. Many people then, are left with damaged computers for lack of help &#38; support, &#38; every&#160;day at least some are left without anyone answering their pleas for help within that 24 hours. So I want to recognize the value of GOATD, but believe that there is a growing path of "wreckage &#38; ruin" ("Bad Moon on the Rise") as a result. I&#39;ve been trying out GOATD software for about 3 months by reading comments from there (&#38; here) &#38; then downloading, installing, uninstalling, etc. Also, like others I&#39;ve been facing all the problems associated with poorly coded or careless work by developers that may or may not have been knowingly&#160;allowing malware or security issues to be transmitted to us as unpaid "testers." That said (finally!), I now have my 1st&#160;possible malware/Trojan, but I can&#39;t tell from what specific download as there have been so many, otherwise I could warn you all of the exact &#39;culprit.&#39; I have sent what I can to VirusTotal, but not sure I did it correctly until I get a response.</p>
<p>[[[ Hello. Since this is my 1st known malware &#38; I&#39;m using virustotal.com&#160; for the 1st time, would you please let me know what &#38; how I&#39;m to send you what has been detected. For now, here is what I have:</p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">Emco Malware Destroyer Scan Results 8/22/09 2:27 AM</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Times New Roman;">Select Action<span style="mso-spacerun: yes;">&#160; </span>Machine<span style="mso-spacerun: yes;">&#160; </span>Name<span style="mso-spacerun: yes;">&#160; </span>Type<span style="mso-spacerun: yes;">&#160; </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Times New Roman;">Quarantine<span style="mso-spacerun: yes;">&#160; </span>AL-PC<span style="mso-spacerun: yes;">&#160; </span>NMC.KOOBFACE.ADW<span style="mso-spacerun: yes;">&#160; </span>TROJAN<span style="mso-spacerun: yes;">&#160; </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">&#160;</span><span style="font-family: Times New Roman; font-size: small;">[EXISTS_REGKEY_HKLM]=\\SYSTEM\\ControlSet001\\Services\\glok+1b6c-49b1</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">[EXISTS_FILE]=%win%\\glok+1b6c-49b1.sys</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;">&#160;</p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">&#160;</span><span style="font-family: Times New Roman; font-size: small;">REMOVAL</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">HKLM_KEY]=\\SYSTEM\\ControlSet001\\Services\\glok+1b6c-49b1</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">[HKLM_KEY]=\\ControlSet001\\Enum\\Root\\LEGACY_GLOK+1B6C-49B1</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">[HKLM_KEY]=\\SYSTEM\\ControlSet\\Services\\glok+1b6c-49b1</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">[FILE_DEL]=%win%\\glok+1b6c-49b1.sys</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">[FILE_DEL]=%win%\\glok+serv.config</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">&#160;</span><span style="font-family: Times New Roman; font-size: small;">"Normally received as an email attachment; may consist of a rootkit, a peer-to-peer client, and a mass-mailing worm component. Its code may be injected and run from the legitimate services.exe process in order to bypass firewalls."</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;">&#160;<span style="font-family: Times New Roman; font-size: small;">For now I have quarantined it. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: Times New Roman; font-size: small;">Thanks for your help. Al ]]]</span></p>
<p>So I wanted to caution everyone &#38; know if others have had this,&#160; as well as ask for help. Thanks. Al</p>
]]></description>
        	        	<pubDate>Sat, 22 Aug 2009 01:32:15 -0700</pubDate>
        </item>
</channel>
</rss>