<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3608062753818595663</id><updated>2012-01-18T13:34:05.293+08:00</updated><category term='Tools'/><category term='Portable AV'/><category term='Security Alerts'/><category term='Security Tips'/><category term='Events'/><category term='Tutorials'/><category term='News'/><category term='Viruses'/><category term='How to ...'/><category term='RCE'/><title type='text'>Portable Antivirus &amp; Security Blog</title><subtitle type='html'>This webblog will tell and story about my software development and anything related to computer security.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>56</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-6168760960612049802</id><published>2010-09-20T08:44:00.000+08:00</published><updated>2010-09-20T08:44:43.565+08:00</updated><title type='text'>Redirect to Data0.Net ...</title><content type='html'>This blog will be automatically redirect to &lt;a href="http://www.data0.net/"&gt;www.data0.net&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-6168760960612049802?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/6168760960612049802/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=6168760960612049802' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6168760960612049802'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6168760960612049802'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2010/09/redirect-to-data0net.html' title='Redirect to Data0.Net ...'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-8132499174903051188</id><published>2010-03-09T18:04:00.000+08:00</published><updated>2010-03-09T18:04:34.930+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='Portable AV'/><title type='text'>Move to Visual Basic 2008</title><content type='html'>Microsoft Visual Basic and C++ 2008 is very powerful IDE for VB fans. After developing a few tools, I decided to change my Portable Antivirus code to VB2008 make it much stable and powerful. 50% of the code has been converted so far. No more VB6, its too old and almost 12 years already.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-8132499174903051188?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/8132499174903051188/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=8132499174903051188' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/8132499174903051188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/8132499174903051188'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2010/03/move-to-visual-basic-2008.html' title='Move to Visual Basic 2008'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-955763323465230053</id><published>2010-01-08T11:30:00.000+08:00</published><updated>2010-01-08T11:30:32.056+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorials'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>Unpacking AutoIt Script</title><content type='html'>&lt;a href="http://www.autoitscript.com/autoit3/"&gt;AutoIt&lt;/a&gt; is a known BASIC-like scripting and self-contained into UPX packed executable file. AutoIt also has been known to be used by virus author to create malicious program and spread it through all over network or media storages.&lt;br /&gt;&lt;br /&gt;Here it is I show a sample that I've got from somebody who sent it to me. Most antivirus is already detected as &lt;a href="http://www.avira.com/en/threats/section/details/id_vir/4344/w32_almanahe.b.html"&gt;W32/Almanahe.B&lt;/a&gt;. It seem this virus is still in the wild on some country. Ok, let focus on the topics. On this tutorial, let assume that you already have a sample of application or malware sample that compiled with AutoIt.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How do we know that it is an AutoIt file?&lt;/b&gt;&lt;br /&gt;Its pretty simple to detect this kind of file. For me, just load up your sample with Notepad.exe. and search for 'AU3!EA' keyword. It will jump to the bottom of the file and there is some 'garbage' thing started with 'AU3!EA' character. And that was and encrypted AutoIt script that we want to decrypt. Lame way but fast to detect it.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_oqd-5f-VZso/S0aO4RmVFTI/AAAAAAAAATw/0ulOd-vgiCw/s1600-h/au3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_oqd-5f-VZso/S0aO4RmVFTI/AAAAAAAAATw/0ulOd-vgiCw/s320/au3.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;The tools that we need for this dynamic analysis/reverse:&lt;br /&gt;1. &lt;a href="http://peid.has.it/"&gt;PEiD&lt;/a&gt;&lt;br /&gt;2. &lt;a href="http://myauttoexe.angelfire.com/"&gt;myAutToExe.exe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;All you need to do, download the tools above. Run PEiD and load-up your AutoIt sample file into it. You will see something similar with the picture below:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_oqd-5f-VZso/S0aNlUzhDLI/AAAAAAAAATo/gU2dUsdjFzs/s1600-h/peid.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_oqd-5f-VZso/S0aNlUzhDLI/AAAAAAAAATo/gU2dUsdjFzs/s320/peid.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;I use the sample malware from the people sent it to me. The PEiD will look show you some basic information and said it was compiled with Microsoft Visual C++ 7.0.&lt;br /&gt;&lt;br /&gt;Next, run your&amp;nbsp;&lt;a href="http://myauttoexe.angelfire.com/"&gt;myAutToExe.exe&lt;/a&gt; and drag and drop your sample AutoIt file into the top textbox. It will automatically start analyzing the file and extracting the script.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_oqd-5f-VZso/S0ajzXxC0QI/AAAAAAAAAT4/mkoiB4Qf0dI/s1600-h/myaut2Exe1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_oqd-5f-VZso/S0ajzXxC0QI/AAAAAAAAAT4/mkoiB4Qf0dI/s320/myaut2Exe1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;After the process it will look like this (picture above). All processing data will be saved as log, source code and resources file.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_oqd-5f-VZso/S0akoP77ytI/AAAAAAAAAUA/Xry2NNgLWz8/s1600-h/myaut2Exe2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_oqd-5f-VZso/S0akoP77ytI/AAAAAAAAAUA/Xry2NNgLWz8/s320/myaut2Exe2.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;There it is, a sort file with the source code of the malware (or program). The source code file will be saved as .au3 extension file and can be viewed with any text editor. Starting from this point we can analize this piece of malware easily without needed to using complicated way (static analysis).&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_oqd-5f-VZso/S0alh9mrVHI/AAAAAAAAAUI/5nHlqrQU3mI/s1600-h/myaut2Exe3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_oqd-5f-VZso/S0alh9mrVHI/AAAAAAAAAUI/5nHlqrQU3mI/s320/myaut2Exe3.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Here it is a screen shot of the source code that we already have. Seem like this people trying to expose itself by inserting their information into the source code. LoL.&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Since this AutoIt script can be readable by any one, there is a few AutoIt script malware that I found that already obfuscated&amp;nbsp; to prevent analyzer from easily trace their code. I'll explain this type on next blogpost...&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-955763323465230053?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/955763323465230053/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=955763323465230053' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/955763323465230053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/955763323465230053'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2010/01/unpacking-autoit-script.html' title='Unpacking AutoIt Script'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_oqd-5f-VZso/S0aO4RmVFTI/AAAAAAAAATw/0ulOd-vgiCw/s72-c/au3.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-4025011540633962171</id><published>2009-11-29T22:34:00.010+08:00</published><updated>2009-12-04T21:51:46.754+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>Malware Playground</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_oqd-5f-VZso/SxKRd9or2sI/AAAAAAAAARw/ifBYn225his/s1600/logo.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SxKRd9or2sI/AAAAAAAAARw/ifBYn225his/s640/logo.PNG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Around 3 month ago, I was starting developing a sandbox tool for easy to analyst any of malware sample that can generate at least basic information from the sample. I just named it Malware Playground as its work to 'play' with almost all Windows programs within it. Sound funny like a kids playing with knife but wearing a shield. The program itself has been developed using Microsoft Visual Basic 6 and working with more than 20 other programs.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_oqd-5f-VZso/SxKO6fu9glI/AAAAAAAAARg/BdY9JCMfoHE/s1600/mp.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SxKO6fu9glI/AAAAAAAAARg/BdY9JCMfoHE/s400/mp.PNG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;At this moment, this program includes all required features for doing malware analyst. Here it is some features:&lt;br /&gt;+ Save report as text and HTML format.&lt;br /&gt;+ Analysis can be started at your own choice such as you can dump process memory instead of analyst all of the function (Registry, Dump, Handle, String, Port, Files and Folders, AV alias and so on).&lt;br /&gt;+ Work with Windows platform (on VMWare or VirPC).&lt;br /&gt;+ Work together with Sandboxie.&lt;br /&gt;+ Drag and drop and warn before start analyzing it. &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_oqd-5f-VZso/SxKPGgVT2zI/AAAAAAAAARo/JQOmARKhGg0/s1600/mp2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_oqd-5f-VZso/SxKPGgVT2zI/AAAAAAAAARo/JQOmARKhGg0/s400/mp2.PNG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Malware Playground is still in development and some advanced features still remains in progress. Here it is list of features that currently in development:&lt;br /&gt;+ Network activities&lt;br /&gt;+ Process activities&lt;br /&gt;+ Smart suggestion and recommendation technologies.&lt;br /&gt;+ Add more AV alias detection&lt;br /&gt;+ Security Risk Level perimeter.&lt;br /&gt;+ Provide an official website for useful information and services.&lt;br /&gt;+ Integrates with web interfaces that allowed user uploading their malware sample.&lt;br /&gt;+ Save all known threat object into database.&lt;br /&gt;+ Mapping all origin location for the malware and visualize on global map.&lt;br /&gt;&lt;br /&gt;While this useful tools is still in progress, I was unable to provide a fully compiled program to give a test but you can leave a comment and suggest for more features.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-4025011540633962171?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/4025011540633962171/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=4025011540633962171' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/4025011540633962171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/4025011540633962171'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/11/malware-playground.html' title='Malware Playground'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_oqd-5f-VZso/SxKRd9or2sI/AAAAAAAAARw/ifBYn225his/s72-c/logo.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-1103997438789557895</id><published>2009-11-11T11:55:00.003+08:00</published><updated>2009-11-12T19:37:07.412+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Alerts'/><title type='text'>iPhone Worm - Ikee</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://1.bp.blogspot.com/_v7Nd6pidYeQ/SrQFy_MLiZI/AAAAAAAABvo/Gc7a6HKst2s/s1600/apple-worm2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="79" src="http://1.bp.blogspot.com/_v7Nd6pidYeQ/SrQFy_MLiZI/AAAAAAAABvo/Gc7a6HKst2s/s200/apple-worm2.jpg" width="81" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;While surfing on the internet at Bayu Beach Resort, Port Dickson, found something interesting on the internet. It is iPhoneOS.Ikee worm. This kind of virus is rarely found especially on Apple iPhone. The worm do some basic function such as spreading via SSH and changing wallpaper as their payload.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;During infection, this little worm will change victim wallpaper to Rick Astley image (80's singer). The worm has been written by Ashley Town a 21 years old unemployed programmer from Wollogong, Australia.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_oqd-5f-VZso/SvvwllXiPTI/AAAAAAAAAQ4/TdvRAWLnY7A/s1600-h/iKee-Rickrolling-iPhone-Worm.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_oqd-5f-VZso/SvvwllXiPTI/AAAAAAAAAQ4/TdvRAWLnY7A/s320/iKee-Rickrolling-iPhone-Worm.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Upon executing the virus code, the worm will scan an IP address using default SSH configurations. IP range may be vary at random pool as well as copying it self to the startup folder and do some payload by changing default wallpaper. The worm source code also has been reveal as the picture below show some function that change the wallpaper and various commented code.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_oqd-5f-VZso/SvvzRvRoO7I/AAAAAAAAARA/vwJrVmW71Ow/s1600-h/ikee_iphone_worm_source_code_wild.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SvvzRvRoO7I/AAAAAAAAARA/vwJrVmW71Ow/s400/ikee_iphone_worm_source_code_wild.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;More detail report can be found &lt;a href="http://www.symantec.com/norton/security_response/writeup.jsp?docid=2009-111015-5423-99&amp;amp;tabid=2"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-1103997438789557895?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/1103997438789557895/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=1103997438789557895' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/1103997438789557895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/1103997438789557895'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/11/iphone-worm-ikee.html' title='iPhone Worm - Ikee'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_v7Nd6pidYeQ/SrQFy_MLiZI/AAAAAAAABvo/Gc7a6HKst2s/s72-c/apple-worm2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-2953613414042455876</id><published>2009-10-15T21:49:00.000+08:00</published><updated>2009-10-15T21:49:44.517+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='Portable AV'/><title type='text'>New Portable Antivirus on few final stage!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_oqd-5f-VZso/StcoU9bk2QI/AAAAAAAAAPw/Q-3iQ6JRMmc/s1600-h/scan.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_oqd-5f-VZso/StcoU9bk2QI/AAAAAAAAAPw/Q-3iQ6JRMmc/s200/scan.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt; This week I was updating new Portable Antivirus code with some user friendly features. This is one of the most advanced anti virus made by my self. Here it is a few change I have made this week for Portable Antivirus project:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;+ New name; now it is Data0.Net Portable Antivirus.&lt;br /&gt;+ Better system tray icon &amp;amp; pop up message.&lt;br /&gt;+ Support multi language including Bahasa Melayu.&lt;br /&gt;+ Speed up database reading for fast scanning.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Those code make me sleepless but its worth it. I'm happy to finish it but still got few more step. I need to finish up my beta sandbox tools called 'Malware Playground'. Sound funny but it could be an advanced sandbox soon.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-2953613414042455876?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/2953613414042455876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=2953613414042455876' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/2953613414042455876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/2953613414042455876'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/10/new-portable-antivirus-on-few-final.html' title='New Portable Antivirus on few final stage!'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_oqd-5f-VZso/StcoU9bk2QI/AAAAAAAAAPw/Q-3iQ6JRMmc/s72-c/scan.JPG' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-7729963015201933970</id><published>2009-10-02T11:20:00.000+08:00</published><updated>2009-10-02T11:20:53.555+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Alerts'/><title type='text'>Cyber-Communalism</title><content type='html'>Since a few years ago, Malaysia, Indonesia and other south east Asian country have make some mistake that generating communalism or in easy word '&lt;i&gt;big misunderstanding&lt;/i&gt;' whether about culture, political, terrorism or religious. In cyber world also get the impact of this misunderstanding. Indonesian could call Malaysia as '&lt;i&gt;Malingsia&lt;/i&gt;' while Malaysian people could call them as '&lt;i&gt;Indonesial&lt;/i&gt;'.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_X7KggPzXX9s/R5wmcpDTvAI/AAAAAAAAAA0/1CKK_dY-FJ8/S150/C+Documents+and+Settings+R+Desktop+New+Folder+-+ind.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_X7KggPzXX9s/R5wmcpDTvAI/AAAAAAAAAA0/1CKK_dY-FJ8/S150/C+Documents+and+Settings+R+Desktop+New+Folder+-+ind.jpg" /&gt;&lt;/a&gt; &lt;a href="http://ard1z.files.wordpress.com/2007/11/malingsia2007.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="70" src="http://ard1z.files.wordpress.com/2007/11/malingsia2007.jpg" width="96" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace; text-align: center;"&gt;&lt;span style="font-size: x-small;"&gt;communalism art &lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Internet alone we can find so many articles, libel, forum, blog and many more about this issue (&lt;a href="http://www.google.com.my/#hl=en&amp;amp;source=hp&amp;amp;q=Malingsia&amp;amp;btnG=Google+Search&amp;amp;meta=&amp;amp;aq=f&amp;amp;oq=Malingsia&amp;amp;fp=5462f493e6756328"&gt;Example 1&lt;/a&gt;). Wikipedia also has been describe details about &lt;a href="http://en.wikipedia.org/wiki/Communalism_%28South_Asia%29"&gt;Communalism&lt;/a&gt;. This will give impact to all Asian country especially between Malaysia and Indonesia. As an example below show you many website from Malaysia has been defaced because of this issue:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://security.org.my/uploads/suhakam-1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="124" src="http://security.org.my/uploads/suhakam-1.png" width="200" /&gt;&lt;/a&gt; &lt;a href="http://van-odin.net/images/0706-defaced.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="150" src="http://van-odin.net/images/0706-defaced.jpg" width="200" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://i113.photobucket.com/albums/n226/agusdwikarna/heritage-gov-my-hacked.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="145" src="http://i113.photobucket.com/albums/n226/agusdwikarna/heritage-gov-my-hacked.png" width="200" /&gt;&lt;/a&gt;&lt;a href="http://asyafaat.files.wordpress.com/2008/11/polri_deface.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="144" src="http://asyafaat.files.wordpress.com/2008/11/polri_deface.jpg" width="200" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Most of this issue produced by local/foreign media making the conflict more complicated and people will think different and negative perception each other by just read or hearing rumors. As I wrote this topic, there was the latest hot issue such as Pendet dance and Island. While the real thing is, there is none of this issue are truth.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-7729963015201933970?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7729963015201933970'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7729963015201933970'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/10/cyber-communalism.html' title='Cyber-Communalism'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_X7KggPzXX9s/R5wmcpDTvAI/AAAAAAAAAA0/1CKK_dY-FJ8/s72-c/C+Documents+and+Settings+R+Desktop+New+Folder+-+ind.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-427323219509017399</id><published>2009-09-09T20:46:00.007+08:00</published><updated>2009-09-09T23:20:03.350+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>Interesting about W32.Virut variant</title><content type='html'>&lt;div style="text-align: justify;"&gt;Within last 2 month, I continuously reading and made some RCE for well known viruses call W32.Virut or other malware analyst named it as W32.Sality.  This is not a new virus. It is already detected around 2006. Since last 2 month I  received more than 20 report from my friend around Malaysian about this virus that already infecting their labs and PCs.&lt;br /&gt;&lt;br /&gt;W32.Virut is a parasitic file infector, polymorphic and backdoor capabilities. Once it has been executed it will inject its code into winlogon.exe process and create a new thread in that process. But its depend on version of the variant. Other variant injecting their code onto smss.exe and csrss.exe process. It infects all EXE and SCR file type by appending to the last section of the host file and set it entry point to point to viral code. So, any execution from the infected file will run the viral code first before passing to host code. W32.Virut prevent its execution from running on Virtual Machine such as VMWare or Virtual PC and make it difficult to trace its presence, thread and processes. Also, its polymorhic making my sandbox generate inaccurate result and need manually analyst.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_oqd-5f-VZso/Sqe3b09GtOI/AAAAAAAAANQ/4JU4RmNwT00/s1600-h/1.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 289px; height: 210px;" src="http://3.bp.blogspot.com/_oqd-5f-VZso/Sqe3b09GtOI/AAAAAAAAANQ/4JU4RmNwT00/s400/1.JPG" alt="PICTURE 1" id="BLOGGER_PHOTO_ID_5379469968616633570" border="0" /&gt;&lt;/a&gt;From Picture 1, it is clearly shown that the string inside the W32.Virut is working its jobs such as adding its process list to the Windows Firewall, Disabling System File Protection, Modify HOSTS file, contacting external server address and as well as Windows API pointing to Windows DLL files.&lt;br /&gt;&lt;br /&gt;W32.Virut has already generate a few hundred variant generated from its polymorphic technique. Making it hard to detect with a simple static Hash detection.&lt;br /&gt;&lt;/div&gt;&lt;i&gt;&lt;/i&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;Solution: Repair &amp;amp; Cleaning&lt;/span&gt;&lt;br /&gt;There is many tools out there for quick repair your infected file. One of the best tools is &lt;a href="http://www.avg.com/filedir/util/avg_rem_sup.dir/rmvirut/rmvirut.exe"&gt;AVG Win32/Virut Removal&lt;/a&gt;. It free to download &amp;amp; use.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-427323219509017399?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/427323219509017399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/427323219509017399'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/09/interesting-about-w32virut-variant.html' title='Interesting about W32.Virut variant'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_oqd-5f-VZso/Sqe3b09GtOI/AAAAAAAAANQ/4JU4RmNwT00/s72-c/1.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-7245848104585788257</id><published>2009-06-06T16:34:00.006+08:00</published><updated>2009-06-06T21:36:22.449+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>RCE - W32/Autorun.82944</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_oqd-5f-VZso/SipwzIGC6yI/AAAAAAAAAME/n8-0PU9t3Uc/s1600-h/3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 435px; height: 209px;" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SipwzIGC6yI/AAAAAAAAAME/n8-0PU9t3Uc/s400/3.jpg" alt="" id="BLOGGER_PHOTO_ID_5344207931476994850" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;A few days ago I have discover a virus that spread using common known media, USB Flash disk. This virus seem to be the same as other malware and it was compressed with PECompact utilities. The worm itself has been written using Microsoft Visual Basic 6.0. This worm is commonly known as &lt;span style="font-style: italic;"&gt;W32/Autorun.worm!n (McAfee), TR/Crypt.PEPM.Gen (Avira), Win32.Worm.VB.NXY (BitDefender)&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);font-size:130%;" &gt;&lt;span style="font-weight: bold;"&gt;File Information&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;File Name:&lt;/span&gt; various&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Size:&lt;/span&gt; 82,944 Bytes&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Type:&lt;/span&gt; Trojan&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Static File:&lt;/span&gt; Yes&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;MD5 Checksum:&lt;/span&gt; 22b52c23e6dd2809733e011a8eedab03&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);font-size:130%;" &gt;&lt;span style="font-weight: bold;"&gt;File Name / Process File Name &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This virus commonly use several file name to spoof it self as a folder. Here it is some sort of file name has been use by this malware:&lt;br /&gt;&lt;br /&gt;1. romantic.exe&lt;br /&gt;2. forever.exe&lt;br /&gt;3. System Volume Information.exe&lt;br /&gt;4. love.exe&lt;br /&gt;5. task.exe&lt;br /&gt;6. userinit.exe&lt;br /&gt;7. system.exe&lt;br /&gt;. autorun.inf&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_oqd-5f-VZso/SipXfMSqW5I/AAAAAAAAAL0/RhcZozzlGQo/s1600-h/1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 289px; height: 312px;" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SipXfMSqW5I/AAAAAAAAAL0/RhcZozzlGQo/s400/1.jpg" alt="" id="BLOGGER_PHOTO_ID_5344180101215574930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;There is 2 common process file name used by this worm:&lt;br /&gt;1. userinit.exe&lt;br /&gt;2. system.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt;Startup&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt; / Registry Alteration&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The worm altering Windows registry as a startup point everytime Windows load.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_oqd-5f-VZso/Sipdz_uuTWI/AAAAAAAAAL8/Kh5ZM7sLO4o/s1600-h/2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 155px;" src="http://2.bp.blogspot.com/_oqd-5f-VZso/Sipdz_uuTWI/AAAAAAAAAL8/Kh5ZM7sLO4o/s400/2.jpg" alt="" id="BLOGGER_PHOTO_ID_5344187055690632546" border="0" /&gt;&lt;/a&gt;Key:&lt;br /&gt;HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&lt;br /&gt;Userinit=c:\windows\userinit.exe&lt;br /&gt;&lt;br /&gt;Other modified registry key is:&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Policies\Explorer&lt;br /&gt;"NoDriveTypeAutoRun"&lt;br /&gt;"NoDriveAutoRun"&lt;br /&gt;&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced&lt;br /&gt;"HideFileExt"&lt;br /&gt;"ShowSuperHidden"&lt;br /&gt;"Hidden"&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);font-size:130%;" &gt;&lt;span style="font-weight: bold;"&gt;Payload&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The worm seem to overwrite a &lt;span style="font-style: italic;"&gt;%systemroot%\system32\drivers\etc\hosts&lt;/span&gt; file and set every unwanted domain name to pointing to localhost (127.0.0.1) IP. Most of the listing are computer security website including antivirus, firewall and download site.&lt;br /&gt;&lt;br /&gt;The worm also contain some DDoS attack code which will send a random packet to the target.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);font-size:130%;" &gt;&lt;span style="font-weight: bold;"&gt;Programming&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This virus has been created by people who was new to the programming especially Visual Basic 6. Take a look some of their codes, it uses many timer to use their malicious function thus, making this worm unstable and taking alot of CPU usages.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;Other Analysis:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Here it is some extracted string from the compiled Executable file.&lt;br /&gt;&lt;a href="http://www.easy-share.com/1905563077/w32.autorun.82944.txt"&gt;Download here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Other analysis:&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/b99b43d357f16ae92dfb00fe3dc141839083307dbb012e9f575f434f340cc37b-1243473333"&gt;Analysis from Virus Total&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;VDEF updates for Portable Antivirus is available to download.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-7245848104585788257?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/7245848104585788257/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=7245848104585788257' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7245848104585788257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7245848104585788257'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/06/rce-w32autorun82944.html' title='RCE - W32/Autorun.82944'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_oqd-5f-VZso/SipwzIGC6yI/AAAAAAAAAME/n8-0PU9t3Uc/s72-c/3.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-5439367796885036600</id><published>2009-05-06T23:57:00.005+08:00</published><updated>2009-05-07T00:51:19.401+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>New Microsoft Windows 7 RC Launch!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://i.zdnet.com/blogs/24-04-2009-13-24-19.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 323px; height: 145px;" src="http://i.zdnet.com/blogs/24-04-2009-13-24-19.jpg" alt="" border="0" /&gt;&lt;/a&gt;Just a few minutes ago, I've read google news that Microsoft is already launch a new Microsoft Windows 7 Release Candidate (RC). Well, I'm still not finish yet exploring Windows 7 Beta Build 7000 but this is the chance to get free and unlimited licenses number from Microsoft product. Gotta get it now.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/windows/windows-7/download.aspx"&gt;To download Microsoft Windows 7 RC click here!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-5439367796885036600?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/5439367796885036600/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=5439367796885036600' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/5439367796885036600'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/5439367796885036600'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/05/new-microsoft-windows-7-rc-launch.html' title='New Microsoft Windows 7 RC Launch!'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-596792907873303092</id><published>2009-05-03T00:33:00.005+08:00</published><updated>2009-05-03T11:57:23.810+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Are you with Windows 7?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://eeepc.net/wp-content/uploads/2009/02/windows-7-desktop.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 507px; height: 318px;" src="http://eeepc.net/wp-content/uploads/2009/02/windows-7-desktop.jpg" alt="Microsoft Windows 7" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;After 4 month of using Microsoft Windows 7 Ultimate, I think there is much more improvement compared with Windows Vista Ultimate. Only a few minor bugs I found on Start Menu and visual effect thing. Well, as I read a news from &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9132464"&gt;ComputerWorld&lt;/a&gt;, Windows 7 could be lunch this August but still no specific date. Hope it much better after the first release.&lt;br /&gt;&lt;br /&gt;Windows 7 taskbar have totally different compare with other Windows version. When many Windows opened, taskbar will appear only an icon with a great stable thumbnail preview. Also, when user try to open many Windows Explorer, all the Windows will be grouped into one icon on the taskbar until user over their mouse cursor on it to choose which Window they want to use.&lt;br /&gt;&lt;br /&gt;Well, here it is a few minor uncomfortable thing/bugs I found my self on Windows 7 Ultimate Beta Build 7000:&lt;br /&gt;&lt;br /&gt;1. Start menu scroll bar some time cannot be scroll or dragged by mouse.&lt;br /&gt;2. In some cases, the wallpaper disappear and leave only plain color.&lt;br /&gt;3. When I lock the Windows and the logged in back, the screen resolution reset to the recommended setting (another rarely situation).&lt;br /&gt;4. Some old application (mine was Macromedia Fireworks 8) still can't totally support Aero/transparent window effect.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-596792907873303092?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/596792907873303092/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=596792907873303092' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/596792907873303092'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/596792907873303092'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/05/are-you-with-windows-7.html' title='Are you with Windows 7?'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-9156751433973668260</id><published>2009-04-18T21:31:00.002+08:00</published><updated>2009-04-18T22:00:05.232+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Data0.Net Temporary down!</title><content type='html'>This week Data0.Net and several website has temporary down due to the change of new server from Germany to Malaysia. This may take a week to transfer all the data. Hopefully, it work better than before.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-9156751433973668260?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/9156751433973668260/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=9156751433973668260' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/9156751433973668260'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/9156751433973668260'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/04/data0net-temporary-down.html' title='Data0.Net Temporary down!'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-524653970752797836</id><published>2009-04-01T22:52:00.002+08:00</published><updated>2009-04-01T23:08:59.935+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>You together with Conflicker!</title><content type='html'>&lt;div style="text-align: justify;"&gt;Mmm... I have already monitoring this worm since it it was first version... I think around the end of last year. This worm have some unique technique to spread itself along with their payload. After I discover this worm hiding itself on '&lt;span class="Apple-style-span" style="font-style: italic; "&gt;recycler&lt;/span&gt;' folder on somebody USB flash drive. On some version this worm cannot be just delete to remove it. It will need special permission in order to remove it completely. But, once its running on your PCs with network. Your network could be clogged because this worm has an abilities to generate about 500 domain name by itself. The worm is not designed by non-professional programming. This 'guy' have a programming skill and the worm was designed to create a huge network clog. Quite interesting to me. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The complete and detailed analysis can be found from the link below:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://mtc.sri.com/Conficker/addendumC/index.html"&gt;http://mtc.sri.com/Conficker/addendumC/index.html&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-524653970752797836?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/524653970752797836/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=524653970752797836' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/524653970752797836'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/524653970752797836'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/04/you-together-with-conflicker.html' title='You together with Conflicker!'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-3587743468980853892</id><published>2009-03-29T18:13:00.005+08:00</published><updated>2009-03-29T19:29:08.729+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Tips'/><title type='text'>What is Heuristic?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.palgrave-journals.com/jors/journal/vaop/ncurrent/images/2602635i1.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 233px; height: 239px;" src="http://www.palgrave-journals.com/jors/journal/vaop/ncurrent/images/2602635i1.gif" alt="" border="0" /&gt;&lt;/a&gt;Many people ever heard about Heuristic detection or in other name some security product called it &lt;a href="http://www.pandasecurity.com/homeusers/solutions/truprevent/"&gt;TruPrevent&lt;/a&gt;, &lt;a href="http://www.avira.com/en/company_news/december_av-comparatives.html"&gt;AHeAD&lt;/a&gt; as well as Portable Antivirus called it Alternator Heuristic Technology (AHT). In simple word, Heuristic technology is a method to determine if the program is similar to the previous detection of common viruses.&lt;br /&gt;&lt;br /&gt;Here it is a good explanation about Heuristic taken from Wikipedia:&lt;br /&gt;&lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;blockquote style="font-style: italic;"&gt;&lt;p&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;Heuristic&lt;/b&gt; (&lt;span title="Representation in the International Phonetic Alphabet (IPA)" class="IPA"&gt;/hjuːˈrɪs.tɪk/&lt;/span&gt;) is an adjective for methods that help in problem solving, in turn leading to learning and discovery. These methods in most cases employ experimentation and trial-and-error techniques. A heuristic method is particularly used to rapidly come to a solution that is reasonably close to the best possible answer, or 'optimal solution'. Heuristics are "&lt;a href="http://en.wikipedia.org/wiki/Rule_of_thumb" title="Rule of thumb"&gt;rules of thumb&lt;/a&gt;", educated guesses, intuitive judgments or simply &lt;a href="http://en.wikipedia.org/wiki/Common_sense" title="Common sense"&gt;common sense&lt;/a&gt;. &lt;b&gt;Heuristics&lt;/b&gt; (hyu-ˈris-tiks) as a noun is another name for heuristic methods.&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-size:85%;"&gt;In more precise terms, heuristics stand for strategies using readily accessible, though loosely applicable, information to control &lt;a href="http://en.wikipedia.org/wiki/Problem_solving" title="Problem solving"&gt;problem solving&lt;/a&gt; in human beings and machines.&lt;sup id="cite_ref-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Heuristic#cite_note-0" title=""&gt;&lt;span&gt;[&lt;/span&gt;1&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt; &lt;a href="http://en.wikipedia.org/wiki/Forensic_engineering" title="Forensic engineering"&gt;Forensic engineering&lt;/a&gt; is an important tool in tracing defects in products and processes. The Heuristic Model or commonly referred to as the (gut-level approach) is a simplified method of decision making that put emphasis on internal personality attributes of the decision maker.&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;There is several way for making Heuristic detection:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Detecting double extension file&lt;/li&gt;&lt;li&gt;Detecting based on PE-Section hash&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Detecting based on Resource Section&lt;/li&gt;&lt;li&gt;Detecting based on Compression method&lt;/li&gt;&lt;li&gt;Detecting based on String&lt;/li&gt;&lt;li&gt;Detecting based on API&lt;/li&gt;&lt;/ol&gt;and many more...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-3587743468980853892?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/3587743468980853892/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=3587743468980853892' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3587743468980853892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3587743468980853892'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/03/what-is-heuristic.html' title='What is Heuristic?'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-9031371980798536158</id><published>2009-03-20T20:59:00.004+08:00</published><updated>2009-03-20T23:22:23.145+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Data0.Net Problem?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_oqd-5f-VZso/ScO0VLbt1II/AAAAAAAAAI4/6TA9MFeA1tQ/s1600-h/data0error.jpg"&gt;&lt;img style="border:none; margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 214px;" src="http://3.bp.blogspot.com/_oqd-5f-VZso/ScO0VLbt1II/AAAAAAAAAI4/6TA9MFeA1tQ/s400/data0error.jpg" alt="" id="BLOGGER_PHOTO_ID_5315290261166609538" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Well, there was almost 2 weeks already that my data0.net domain went down. But this is not affected to all country and area. I was informed that TMNet was trying to do something with undersea cable that connected to the Europe. Data0.Net was currently hosted at Datacenter located in Frankfurt, Germany.&lt;br /&gt;&lt;br /&gt;I was reported that a few major domain also affected such as www.syok.org, www.asiahoster.com, www.lombongit.net and so on.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-9031371980798536158?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/9031371980798536158/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=9031371980798536158' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/9031371980798536158'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/9031371980798536158'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/03/data0net-problem.html' title='Data0.Net Problem?'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_oqd-5f-VZso/ScO0VLbt1II/AAAAAAAAAI4/6TA9MFeA1tQ/s72-c/data0error.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-4353532465252698475</id><published>2009-03-06T09:58:00.003+08:00</published><updated>2009-03-07T10:48:58.314+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Alerts'/><title type='text'>AsiaHoster.com Web Hoster!</title><content type='html'>Well, after a few weeks i'm keep monitoring this web hoster. It seem that this provider should take care very much about their server since there is many domain shared into one server. This because the server always down 3-4 times a weeks and sometime 1 time a day. It may take around 1-3 hours downtime.&lt;br /&gt;&lt;br /&gt;As we can see below, the picture that cause of server down.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_oqd-5f-VZso/SbHZsQ-FteI/AAAAAAAAAGw/IGizCCRjzF0/s1600-h/lowmem.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 238px;" src="http://2.bp.blogspot.com/_oqd-5f-VZso/SbHZsQ-FteI/AAAAAAAAAGw/IGizCCRjzF0/s400/lowmem.png" alt="" id="BLOGGER_PHOTO_ID_5310264790139385314" border="0" /&gt;&lt;/a&gt;It seem someone from the shared hosting use lot of memory that may cause of the server down and all people on the shared domain loose their advantaged with unfair usage. AND, its keep low. I don't know how much domain name parked on this server.&lt;br /&gt;&lt;br /&gt;Little detailed:&lt;br /&gt;&lt;br /&gt;The main datacenter seem located at Frankfurt, Germany.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_oqd-5f-VZso/SbHYnP0sBnI/AAAAAAAAAGo/vJ9XOoa9gKY/s1600-h/maps.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 231px;" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SbHYnP0sBnI/AAAAAAAAAGo/vJ9XOoa9gKY/s400/maps.png" alt="" id="BLOGGER_PHOTO_ID_5310263604420544114" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Here it is a few domain name list known shared with &lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;ns1.asiahoster.com&lt;/span&gt; and &lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;ns2.asiahoster.com&lt;/span&gt;:&lt;br /&gt;&lt;ol&gt;&lt;span style="font-size: 9pt; font-style: normal; font-family: arial; color: rgb(0, 0, 0);"&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/ahmadfaidhi.com"&gt;http://ahmadfaidhi.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/blog.ahmadfaidhi.com"&gt;http://blog.ahmadfaidhi.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/fairuji.nasz.my"&gt;http://fairuji.nasz.my/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/hujan.org"&gt;http://hujan.org/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/image.syok.org"&gt;http://image.syok.org/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/rekreasikota.summitmy.com"&gt;http://rekreasikota.summitmy.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/rocker.smktip.com"&gt;http://rocker.smktip.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/savoc-nru.syok.org"&gt;http://savoc-nru.syok.org/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/syok.org"&gt;http://syok.org/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/torrent.syok.org"&gt;http://torrent.syok.org/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.ahmadfaidhi.com"&gt;http://www.ahmadfaidhi.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.asiahoster.com"&gt;http://www.asiahoster.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.fairuji.nasz.my"&gt;http://www.fairuji.nasz.my/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.hujan.org"&gt;http://www.hujan.org/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.indiefanzine.com"&gt;http://www.indiefanzine.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.jejakpuncak.summitmy.com"&gt;http://www.jejakpuncak.summitmy.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.limemyth.com"&gt;http://www.limemyth.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.mykjkk.com"&gt;http://www.mykjkk.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.nasz.my"&gt;http://www.nasz.my/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.penfluid.com"&gt;http://www.penfluid.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.summitmy.com"&gt;http://www.summitmy.com/&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;   &lt;a href="http://sitedossier.com/site/www.syok.org"&gt;http://www.syok.org/&lt;/a&gt;&lt;/li&gt;&lt;/span&gt;&lt;/ol&gt;Some of the website listed above is already change their server due to the lack of server response.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-4353532465252698475?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/4353532465252698475/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=4353532465252698475' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/4353532465252698475'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/4353532465252698475'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/03/asiahostercom-web-hoster.html' title='AsiaHoster.com Web Hoster!'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_oqd-5f-VZso/SbHZsQ-FteI/AAAAAAAAAGw/IGizCCRjzF0/s72-c/lowmem.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-8211297014556665381</id><published>2009-01-31T22:52:00.010+08:00</published><updated>2009-01-31T23:29:35.508+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Google Problem? Turn all result to "This site may harm your computer"</title><content type='html'>Today and a few minutes ago, i'm trying to search some plugin for my Wordpress pages on Google Search but suddenly all search result turn into "&lt;a href="http://www.google.com.my/support/bin/answer.py?answer=45449&amp;amp;topic=360&amp;amp;hl=en&amp;amp;sa=X&amp;amp;oi=malwarewarninglink&amp;amp;resnum=1&amp;amp;ct=help"&gt;This site may harm your computer&lt;/a&gt;". As you can see below is an images from the result.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_oqd-5f-VZso/SYRnO5Fnh5I/AAAAAAAAAFE/F_RQKe81KCk/s1600-h/googleproblem1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 201px; height: 400px;" src="http://1.bp.blogspot.com/_oqd-5f-VZso/SYRnO5Fnh5I/AAAAAAAAAFE/F_RQKe81KCk/s400/googleproblem1.jpg" alt="" id="BLOGGER_PHOTO_ID_5297472567234758546" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Then, if you click on one of those link it will turn result that says "Warning - Visiting the website may harm your computer!". See the images below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_oqd-5f-VZso/SYRn1eJwTgI/AAAAAAAAAFM/lctS4Q8oxuo/s1600-h/googleproblem2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 395px;" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SYRn1eJwTgI/AAAAAAAAAFM/lctS4Q8oxuo/s400/googleproblem2.jpg" alt="" id="BLOGGER_PHOTO_ID_5297473230019251714" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;If we click to all link came from the result it will give a warning of a fake malware. This also include search on images. All the link will return result from the following URL example.&lt;br /&gt;&lt;br /&gt;http://www.google.com.my/interstitial?url=http://wordpress.org/&lt;br /&gt;&lt;br /&gt;and another error images a few minutes ago...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_oqd-5f-VZso/SYRtQ1xU-LI/AAAAAAAAAFU/LeMCzDEy0bY/s1600-h/googleproblem3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 240px;" src="http://2.bp.blogspot.com/_oqd-5f-VZso/SYRtQ1xU-LI/AAAAAAAAAFU/LeMCzDEy0bY/s400/googleproblem3.jpg" alt="" id="BLOGGER_PHOTO_ID_5297479197773854898" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I guess maybe Google people are trying to test something on the server in real situation...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-8211297014556665381?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/8211297014556665381/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=8211297014556665381' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/8211297014556665381'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/8211297014556665381'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/01/google-problem-turn-all-result-to-this.html' title='Google Problem? Turn all result to &quot;This site may harm your computer&quot;'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_oqd-5f-VZso/SYRnO5Fnh5I/AAAAAAAAAFE/F_RQKe81KCk/s72-c/googleproblem1.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-5294849716227977401</id><published>2009-01-24T22:16:00.000+08:00</published><updated>2009-01-24T23:35:36.357+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>"Downadup" worm infections skyrocket</title><content type='html'>&lt;span id="ArticleBody"&gt;&lt;p&gt;The number of desktops and servers infected by the &lt;a href="http://www.computerweekly.com/Articles/2009/01/15/234236/downadup-worm-targets-corporate-networks.htm"&gt;"downadup" worm&lt;/a&gt; has skyrocketed to nearly nine million, according to security firm F-Secure.&lt;/p&gt;&lt;p&gt;That is an increase of more than six million since Thursday last week, when F-Secure warned that the worm was affecting corporate networks and spreading rapidly.&lt;/p&gt;&lt;p&gt;The worm, also known as "conficker", is a large family of network that causes various problems, including locking network users out of their accounts.&lt;/p&gt;&lt;p&gt;F-Secure said in a blog that the spread of the worm was "amazing" and that the situation was not getting better. &lt;/p&gt;&lt;p&gt;The firm ascribes the rapid infection rate to the fact that there are several different variants of the worm.&lt;/p&gt;&lt;p&gt;The most common variant F-Secure has been tracking is creating 250 possible domains each day, the firm said.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.computerweekly.com/Articles/2009/01/19/234309/downadup-worm-infections-skyrocket.htm"&gt;ComputerWeekly.com&lt;br /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-5294849716227977401?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/5294849716227977401/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=5294849716227977401' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/5294849716227977401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/5294849716227977401'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/01/downadup-worm-infections-skyrocket.html' title='&quot;Downadup&quot; worm infections skyrocket'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-1084376330593952213</id><published>2009-01-05T23:29:00.004+08:00</published><updated>2009-05-02T15:29:17.609+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><title type='text'>What is a computer virus?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_oqd-5f-VZso/SWIoxqim5XI/AAAAAAAAAEU/HAGeBuj2gKQ/s1600-h/ist2_5470117-computer-virus-warning.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 133px;" src="http://1.bp.blogspot.com/_oqd-5f-VZso/SWIoxqim5XI/AAAAAAAAAEU/HAGeBuj2gKQ/s200/ist2_5470117-computer-virus-warning.jpg" alt="" id="BLOGGER_PHOTO_ID_5287833746184529266" border="0" /&gt;&lt;/a&gt;To put it simply, a computer virus is just a small computer program that can replicate itself and place itself on a computer without the computer user knowing it. They typically come attached to other files. These files are typically executable files with a (.exe) file extension. People often use the term virus to mistakenly label other troublesome programs that are really malware or adware. There is a difference. Most malware and adware do not replicate themselves and therefore are not technically considered viruses. However, these days, malware is a far more common type of infection. Other things that can infect a computer but aren't really viruses are things like computer worms and Trojan horses.&lt;br /&gt;Trojan horses are very common these days. As their name implies, they often sneak into a person's computer because they come packaged as a useful program like a screensaver or something. Then, once they are installed on the computer, they open up ports (like a secret door to the internet) on your computer and allow other types of infections to sneak in. These other infections come in totally unannounced. You won't realize they are there until your antivirus program happens to detect them. By then, it is possible that their intended damage has already occurred.&lt;br /&gt;This is why it is important to have a firewall on your computer. The firewall increases the computer's security by closing all of these doors and locking them. The firewall only allows doors to open that are used by common programs like web browsers and email. For another port (door) to be opened, the firewall program usually asks for permission from the computer user. That's why you get the messages popping up in the lower right hand corner of your computer asking if it is okay for something to happen.&lt;br /&gt;Another type of infection is the computer worm. Computer worms are like viruses except they do not come attached to any other files. These worms can move from computer to computer across a network. They move from computer to computer by going through open ports. This is the biggest benefit of having a firewall to keep those ports closed and locked. The internet is one giant network. So, just by being connected to the internet, your computer is exposed to this type of infection.&lt;br /&gt;Adware is another type of program all together. Typically, these program come bundled with other software as well. When downloading some music sharing software, if you read all the fine print you would see that the reason that software is free is because it comes bundled with an adware program. The adware program will make pop ups come up on your computer. It might also modify your internet browser so that your search results are influenced in some way that benefits the author of the program.&lt;br /&gt;I can honestly say from experience that you can guarantee getting an infection by using your Windows based computer to browse the internet regularly if you do not have an adequate firewall on your computer. The firewall is far more important than your antivirus software itself. This is one of the most misunderstood computer security issues among the general public.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-1084376330593952213?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/1084376330593952213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=1084376330593952213' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/1084376330593952213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/1084376330593952213'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/01/what-is-computer-virus.html' title='What is a computer virus?'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_oqd-5f-VZso/SWIoxqim5XI/AAAAAAAAAEU/HAGeBuj2gKQ/s72-c/ist2_5470117-computer-virus-warning.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-8112881060020638789</id><published>2009-01-04T08:44:00.003+08:00</published><updated>2010-09-23T13:41:02.776+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Portable AV'/><title type='text'>Download Portable Antivirus</title><content type='html'>[ Download Section temporary not available ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-8112881060020638789?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/8112881060020638789/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=8112881060020638789' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/8112881060020638789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/8112881060020638789'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/01/download-latest-version-of-portable.html' title='Download Portable Antivirus'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-7420972395176860970</id><published>2008-12-19T15:16:00.007+08:00</published><updated>2009-01-06T18:08:15.187+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Alerts'/><title type='text'>Windefender2009 – not an Antivirus</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_oqd-5f-VZso/SUx_YjVuv0I/AAAAAAAAADk/H7RUm1Dg508/s1600-h/win-defender(2).JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 269px;" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SUx_YjVuv0I/AAAAAAAAADk/H7RUm1Dg508/s400/win-defender(2).JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5281736522778722114" /&gt;&lt;/a&gt;&lt;br /&gt;The WinDefender2009 infection starts any of three ways. You can go to a corrupt porn web page, a corrupt website that promotes gambling, or you can open an attachment in a spam email. Any of those three ways will get you infected with WinDefender2009. On the porn and gambling related sites, WinDefender2009 will pretend to be a video codec or an ActiveX control.&lt;br /&gt;&lt;br /&gt;WinDefender2009 is new on the wild web. It is almost a funny thought that a fake antivirus has upgraded itself, but that is the alarming reality. Once WinDefender2009 has its hooks into your computer you start getting alarming pop-ups tell you that your computer is infected. These pop-ups make the claim that only WinDefender2009 will remove your infection. We have seen WinDefender2009 before. WinDefender2009 is a clone. The names WinDefender2009 has been known as in the past are TotalSecure2009, TotalSecure 2009 and Total Secure 2009.&lt;br /&gt;&lt;br /&gt;Once you click on the pop-ups your computer goes to a website with a fake scan. This fake scan will tell you files, which are really part of your operating system, are your infection. Sometimes the scan can name hundreds of files. This can be alarming for the uninformed computer user. We all want our computer to be healthy and work properly. So when faced with the possibility of such a large infection, the uninformed computer user can fall for the scam and purchase the full version of the software when suggested after the scan.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_oqd-5f-VZso/SUx_3ZOQtcI/AAAAAAAAADs/pwkyUU5SSac/s1600-h/windefender-2008.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 262px;" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SUx_3ZOQtcI/AAAAAAAAADs/pwkyUU5SSac/s400/windefender-2008.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5281737052638983618" /&gt;&lt;/a&gt;&lt;br /&gt;When WinDefender2009 is “purchased” you have traded your credit card information in exchange for a bundle of spyware, malware and adware. So you have paid for an infection. No just an infection though--you have paid for an infection that is difficult to remove. The spyware will monitor your behavior for personal information, log ins and passwords, which it will send to the original programmers. The adware will monitor your browsing behavior and present you with pop-up ads for products and services it deems relative to your interests and browsing habits. Your pop-up blocker will be useless against these pop-ups. In addition, the malware will run in the background and affect your computer’s performance, making it slow to start up or shut down. Your system tray icons, background and screensaver will be changed. Legitimate system files, registry keys, and DLL files will go missing, causing you to get the “Blue Screen of Death.”&lt;br /&gt;&lt;br /&gt;WinDefender2009 is difficult to remove manually. If you miss any file, WinDefender2009 will reinstall itself on system startup. To deal with WinDefender2009 you need an antispyware program, not an antivirus. If you already have one, but you still have WinDefender2009, you should contact the makers of your program. In most cases the software companies will make a fix for any new threats their users have found. If your program claims to have removed WinDefender2009, yet it fails to do so, look for an antispyware program with a 100% removal guarantee. With new threats it can take months for all antispyware companies to come up with effective removal tools.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-7420972395176860970?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/7420972395176860970/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=7420972395176860970' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7420972395176860970'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7420972395176860970'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/12/windefender2009-not-antivirus.html' title='Windefender2009 – not an Antivirus'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_oqd-5f-VZso/SUx_YjVuv0I/AAAAAAAAADk/H7RUm1Dg508/s72-c/win-defender(2).JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-504753015273298146</id><published>2008-12-18T14:38:00.003+08:00</published><updated>2009-01-06T18:08:49.140+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorials'/><title type='text'>7 Steps to Get the Best Online Internet Security</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_oqd-5f-VZso/SUyDCjmCS5I/AAAAAAAAAD8/Ps1yGDLpgKg/s1600-h/web_security1.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 185px;" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SUyDCjmCS5I/AAAAAAAAAD8/Ps1yGDLpgKg/s200/web_security1.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5281740542936501138" /&gt;&lt;/a&gt;The concerns of Internet Security have grown today like never before. Despite the continuous attempts of Internet community, the threats are increasing and getting more and more vicious by each passing day.&lt;br /&gt;&lt;br /&gt;There are many Internet Security tools available in the market. Some of them are outstanding. But still, none of them is perfect. It can't be. The best protection is in your own hands. Follow a disciplined approach while using Internet services.&lt;br /&gt;&lt;br /&gt;1. Be careful about using MS Outlook. Outlook is more susceptible to worms than other e-mail programs, unless you have efficient Anti-Virus programs running. Use Pegasus or Thunderbird (by Mozilla), or a web-based program such as Hotmail or Yahoo.&lt;br /&gt;&lt;br /&gt;2. Take special precaution while dealing with email attachments. Be cautious about attachments with a double extension, such as .txt.vb or .jpg.exe, as the system will only recognize the extension to the extreme right, and run the file as such. Double extensions are often a good indicator that the file is malicious.&lt;br /&gt;&lt;br /&gt;3. Do not use disks that other people gave you, even from work. The disk could be infected with a virus. Of course, you can run a virus scan on it first to check it out, but AV programs are not 100% effective.&lt;br /&gt;&lt;br /&gt;4. Do not download software from just any website. If it is a reputable site that you trust, you are probably safe. The threat is not only from software; even other file types like .txt, .doc, .xml can have infections.&lt;br /&gt;&lt;br /&gt;5. Be careful when surfing. You might get a malicious script from a webpage without even getting a warning. Tweak your Browser settings for maximum safety.&lt;br /&gt;&lt;br /&gt;6. Try to balance paranoia with common sense. Some people get really weird about viruses, spyware, etc. It's just a computer! Back up your data and follow these steps, and it shouldn't be a big problem.&lt;br /&gt;&lt;br /&gt;7. Setup your download manager to scan a download first before you open it. When you click to download a file from Internet, generally browser gives two options. To save it on the Disk or To Open the file with the default program. Always choose the first option, because, it ensures that the download is first scanned with your antivirus, before saving it on the disk.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-504753015273298146?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/504753015273298146/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=504753015273298146' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/504753015273298146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/504753015273298146'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/12/7-steps-to-get-best-online-internet.html' title='7 Steps to Get the Best Online Internet Security'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_oqd-5f-VZso/SUyDCjmCS5I/AAAAAAAAAD8/Ps1yGDLpgKg/s72-c/web_security1.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-7880638038566795108</id><published>2008-12-16T15:09:00.004+08:00</published><updated>2009-01-06T18:10:15.881+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorials'/><title type='text'>10 Tips to Make your Windows Computer Faster</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://makeuseof.com/images/windows-speedup-tips.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 80px; height: 70px;" src="http://makeuseof.com/images/windows-speedup-tips.jpg" border="0" alt="" /&gt;&lt;/a&gt;Your computer running Windows isn’t running in the same speed that it used to run when you first used it. It’s slower, crappy, takes a while to start and tests your patience like anything. There are many reasons for this, let’s try fixing up a few things on your slow Windows PC:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Slow Start Up&lt;/span&gt;&lt;br /&gt;There can be a variety of reasons to Windows loading slow during start up. Go to Run, type msconfig and hit enter. Under the ‘Start Up’ tab, uncheck the unwanted programs and press OK. Things should be a bit fine the next time Windows boots.&lt;br /&gt;&lt;br /&gt;Another program worth mentioning here is &lt;a href="http://www.r2.com.au/software.php?page=2&amp;amp;show=startdelay"&gt;StartUp Delayer&lt;/a&gt; which will help in setting after how much time programs should be loaded after Windows boots. For instance, you could set your instant messenger program to load 50 seconds after Windows starts up.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Slow Loading Start Menu&lt;/span&gt;&lt;br /&gt;If the Start Menu items are loading slowly, you can open the Registry Editor by typing in the Run menu ‘regedit.exe’ and pressing Enter. Go to HKEY_CURRENT_USER\Control Panel\Desktop. Look for MenuShowDelay, and double click to edit the value. The lower the number specified, the faster the Start Menu will load.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Slow Right Click Context Menu&lt;/span&gt;&lt;br /&gt;Probably the Windows Right Click menu on your computer is loading slow because too many programs added unwanted entries there. &lt;a href="http://www.hace.us-inc.com/mmm.shtml"&gt;Just download this program called Mmm&lt;/a&gt;, install it and then modify your context menu to remove unwanted items to speed it up.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://makeuseof.com/images/win-fixes-send-to.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 135px; height: 71px;" src="http://makeuseof.com/images/win-fixes-send-to.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;span style="font-weight:bold;"&gt;'Send To' Menu Slow Send To Menu&lt;/span&gt;&lt;br /&gt;If the Send To menu loads slowly, you can type ’sendto’ in the Run Dialog, and remove unwanted items in the Explorer Window that appears. This should add some speed to it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Slow Defragmentation&lt;/span&gt;&lt;br /&gt;The Windows Defragmenter can’t get any slower. You need to have an alternative to the Windows Defragmenter, and &lt;a href="http://www.defraggler.com/"&gt;Defraggler&lt;/a&gt; is just one of the best ones available in the market. It’s free, and works like a charm and can speed up defragmentation manifold. For some alternatives, see &lt;a href="http://www.makeuseof.com/tag/five-programs-to-defragment-your-pc/"&gt;Five Free Programs to Defragment your PC&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Slow loading My Computer Window&lt;/span&gt;&lt;br /&gt;my-computer.jpg If the My Computer Window loads slowly, in the Explorer Window, go to Tools&gt;&gt; Folder Options&gt;&gt; View and uncheck ‘Automatically search for network folders and printers”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Slow loading Add or Remove Programs Applet&lt;/span&gt;&lt;br /&gt;This is one of the most annoying piece of programs present in Windows, it takes ages to load if you have a considerable number of programs installed on your computer. You can either use the all-in-one &lt;a href="http://www.ccleaner.com/"&gt;CCleaner&lt;/a&gt; for this purpose, or get &lt;a href="http://www.nirsoft.net/utils/myuninst.html"&gt;MyUninstaller&lt;/a&gt; that comes as a speedy replacement for Add or Remove Programs.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Slow Ending of Unresponsive Programs&lt;/span&gt;&lt;br /&gt;If you’ve clicked on ‘End Task’ if any program is running unresponsive, you might have noticed that the program is not terminated immediately. You can alter this by going to Run&gt;&gt; regedit.exe&gt;&gt; HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ and change this value to 1000.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Disable Animations and Appearance Overhauls to maximize performance&lt;/span&gt;&lt;br /&gt;If you’re a serious performance junkie, you probably won’t bother about eyecandy. Go to System Properties in the Control Panel. Click ‘Advanced’, then ‘Performance’ and click ‘Adjust for best performance’. This might boost your PC’s performance up a bit.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://makeuseof.com/images/win-fixes-performance-adj.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 367px; height: 428px;" src="http://makeuseof.com/images/win-fixes-performance-adj.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Additional Tips:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;- Always keep your computer clean. Remove Junk and Unnecessary registry entries. Use &lt;a href="http://www.ccleaner.com/"&gt;CCleaner&lt;/a&gt; for this purpose, one excellent tool that just does what it says.&lt;br /&gt;&lt;br /&gt;- Don’t keep installing software. Install a program only if it really serves you a purpose.&lt;br /&gt;&lt;br /&gt;- Keep as less programs as possible running on the System Tray. This essentially means reducing the number of programs that start during Windows start up.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-7880638038566795108?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/7880638038566795108/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=7880638038566795108' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7880638038566795108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7880638038566795108'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/12/10-tips-to-make-your-windows-computer.html' title='10 Tips to Make your Windows Computer Faster'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-6010720576641398100</id><published>2008-12-14T22:01:00.001+08:00</published><updated>2009-01-06T18:09:03.033+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorials'/><title type='text'>10 Tips: Prevent from Viruses</title><content type='html'>&lt;span style="font-weight:bold;"&gt;1. Regularly install updates for your anti-virus software.&lt;/span&gt;&lt;br /&gt;New viruses are constantly appearing - unless you have updated your software, it may not have the necessary information for handling new virus types and variants. When you install an update, new entries are added to the software's virus definitions database so that suspect files can be recognised and dealt with. F-Secure issues a new anti-virus update daily, and unless you change the settings, will remind you every seven days that you should update.- normally, every couple of weeks should be considered the longest you should leave it. Make a special effort to update when a new virus "hits the headlines".&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;2. Think twice about using Outlook Express for your e-mail.&lt;/span&gt;&lt;br /&gt;Outlook Express is too closely bound up in its workings with Internet Explorer and your access to the World Wide Web to maintain adequate security. Using more self-contained e-mail client* software, it's pretty well impossible for a virus to enter your computer except through your opening an infected attachment. With Outlook Express, simply through an e-mail being displayed in the Preview Pane you can be taken straight to a website from which infected script is loaded up on your computer. A patch has been issued by Microsoft to deal with this glaring security hole, but this has been severely criticised by independent evaluators. For more information, click here. It's much better to use fully-fledged e-mail client software, such as plain Outlook, First Class Conference etc. for handling your e-mail.&lt;br /&gt;&lt;br /&gt;* The client-server relationship is something which you'll keep coming up against when you use Internet services - your computer needs the appropriate client software installed so you can use the services of particular types of server - e-mail, ftp (file transfer protocol), web. A server is just a "dedicated" computer - one which serves a specific purpose in a network.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;3. Don't open e-mail attachments unless you know who's sent them and what they are.&lt;/span&gt; Change your view settings so you can see file extensions.&lt;br /&gt;This is much more important with some types of file than with others - you can recognise different file types by the extensions they have. .EXE, .COM, .PIF, .JS, .VBS, .SHS, .SCR, .DOT are some of the most notably dangerous. Double file extensions - for example "readme.txt.vbs" - should always be treated with suspicion.&lt;br /&gt;Look out also for oddities in the header information of e-mail messages - a sender you've never heard with a subject such as "sorry about yesterday"; a blank subject header.&lt;br /&gt;&lt;br /&gt;On many computers, the default setting means that you see file names without their extensions. So, suspect attachments won't be immediately evident. To set your computer so that you see file extensions:open My Computer or Windows Explorer. From the View menu, select Options, then click the View tab. Make sure that "Hide file extensions for known file types" isn't checked.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;4. Never leave a floppy disk in the drive when you start up or restart your computer.&lt;/span&gt;&lt;br /&gt;This is the standard, old-fashioned pre-Internet way of passing on viruses. By default, your computer looks first for its operating system to the floppy disk drive, and only then to the hard disk. So, if an infected diskette is on the drive, off goes the virus when you boot up. Always reformat old disks before you reuse them. A virus may have been lurking on it for years. If you have the confidence to change your computer's BIOS settings, it's a good idea to alter the boot sequence to C: A: This will set your computer so that it refers first to the hard disk instead of the floppy drive when it boots up.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;5. CDs and Zip disks can carry viruses too.&lt;/span&gt;&lt;br /&gt;Now that Internet-transmitted viruses are far more popular than disk-transmitted ones, this isn't all that common. But it remains a possibility! You can run an anti-virus scan on any kind of diskette - this never does any harm.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;6. If your anti-virus software reports a suspect file, take all possible action before you close down your computer.&lt;/span&gt;&lt;br /&gt;Familiarise yourself in advance with your anti-virus software so that you know what decisions to make in an emergency. It's at the stage of booting up again that a virus file can pass all of its nastinesses into your operating system, and into your system registry.&lt;br /&gt;&lt;br /&gt;Whatever anti-virus software you're using, you're likely to run into situations where a file is recognised as suspect, but contains a new or unusual virus which isn't included in the software's virus definitions database. If this happens you will be told that the suspect file can't be disinfected, and offered the choice to rename or delete it. Delete unless you have very good reasons for thinking it could be a wanted and important file.&lt;br /&gt;&lt;br /&gt;F-Secure users in this situation may find it something other than intuitive that you must press the Back button to return to the screen where, when disinfect has failed, you can choose the delete or rename alternative. Don't press the Finish button!!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;7. Make sure you have a system start-up disk to use in emergencies.&lt;/span&gt;&lt;br /&gt;If a virus does manage to infect your system, it could mean that you can't load Windows. Without a start-up disk, which will be different for different computer models and operating systems, you - or anybody you call on for help - will have a much harder time rescuing your system in the event of failure. This applies whether or not failure is due to a virus infection. If a start-up disk wasn't supplied with your computer, follow the appropriate link (Internet connection required) to Microsoft's instructions for making one: Windows 95/98 ;Windows ME; Windows 2000; Windows XP.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;8. When using Microsoft software, always make sure that you keep macro virus protection enabled.&lt;/span&gt;&lt;br /&gt;Macros are stored sets of instructions which are used within Microsoft Office applications to automate complex or repetitive tasks. Unfortunately macros can also be used to introduce viruses. Macro virus protection is set from within each of the Office software applications:&lt;br /&gt;Office 97: from the Tools menu, select Options, then General. By default protection is enabled - don't switch it off!&lt;br /&gt;Office 2000/XP: go to Tools | Options | Security. With Macro security set to medium, Word warns of macros in a file and prompts whether you want to disable them. High security automatically disables all "unsigned" macros.&lt;br /&gt;&lt;br /&gt;If you receive a macro warning when you open a Microsoft Office file, always select the "disable macros" option unless you expect the file to contain a macro and know that you can trust it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;9. Only download files from trustworthy websites.&lt;/span&gt;&lt;br /&gt;Always avoid downloading files from bulletin boards or public newsgroups - these are particularly likely to be used by virus writers to distribute their new viruses. When downloading software updates (for instance drivers, multimedia players etc.), go to the manufacturer's official website. Be watchful!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;10. Never pass on a virus warning without checking first yourself that it isn't a hoax.&lt;/span&gt;&lt;br /&gt;Hoax virus warnings can be more than just a nuisance - they may be almost as dangerous as viruses themselves. For example, you may be instructed to delete a file from your computer in order to prevent a virus infection, when in fact the file is an essential system file. Before passing on any virus warning message, check on the specific virus you're being warned about at the F-secure website, or the website of any other producer of reputable anti-virus software.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-6010720576641398100?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/6010720576641398100/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=6010720576641398100' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6010720576641398100'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6010720576641398100'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/12/10-tips-prevent-from-viruses.html' title='10 Tips: Prevent from Viruses'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-3471521158358355584</id><published>2008-12-13T17:26:00.005+08:00</published><updated>2009-01-06T18:11:52.531+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Tips'/><title type='text'>U3 - Portable USB Apps Platform; Secure your USB Drive</title><content type='html'>&lt;a href="http://www.everythingusb.com/hardware/resize.php?size=80&amp;amp;filename=u3_smart_logo.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 80px; height: 102px;" src="http://www.everythingusb.com/hardware/resize.php?size=80&amp;amp;filename=u3_smart_logo.jpg" border="0" alt="" /&gt;&lt;/a&gt;It's official, the floppy drive is dead. Indeed, Dell and a plethora of other PC manufacturers have simply stopped including the decades-old drive, thanks in no small part to the smaller, lighter, and faster USB flash drive that can carry over 1,000 times the standard 3.5" floppy. We've watched the evolution of the portable data disk, but now it's time to take that evolution a step further.&lt;br /&gt;&lt;br /&gt;Enter the U3 smart drive. Co-developed by SanDisk and M-Systems, the open-standard U3 platform allows users to take their applications, not just data, with them to any USB-equipped Windows PC and to launch them with as little as two clicks. True, while applications have been tweaked by users to run directly off a flash drive, applications written for U3 smart drives don't require a geek to set up, and are 100% legal to operate.&lt;br /&gt;&lt;br /&gt;Two Letters for the Price of One&lt;br /&gt;The first time we plugged our retail Geek Squad U3 Smart Drive into the computer, Windows automatically recognized the drive and set the Add New Hardware wizard to work, identifying not one but two drives taking up two drive letters.&lt;a href="http://www.everythingusb.com/images/list/u3devicemanager.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 279px; height: 115px;" src="http://www.everythingusb.com/images/list/u3devicemanager.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;A small, 4MB read-only system partition of the U3 drive pretends to be a CD-ROM drive, while the data partition shows up as a regular flash drive. Because Windows is led to believe that the system partition is a CD, U3 takes advantage of the AutoPlay feature in windows to automatically run the U3 LaunchPad and unlock the data partition of the drive. It should be noted that U3 will run on any Windows 2000/XP system, regardless if the user has administrative rights or not.&lt;br /&gt;&lt;br /&gt;After the LaunchPad's animated splash screen disappeared, we were greeted by an Oddcast talking presentation of the U3 platform's features and a quick intro of how to use the LaunchPad and download additional applications. Kudos goes to whoever thought of using the Oddcast system for a quick intro of how to use the drive, as it provides a user-friendly way for new users and computer-illiterate types to quickly jump into using the drive.&lt;br /&gt;&lt;br /&gt;Apps Ahoy!&lt;br /&gt;The LaunchPad is the heart of the U3 smart drive, and bears a striking resemblance to the Windows XP start menu. Accessed from a U3 icon in the system tray, it provides quick access to applications and documents installed on the U3 smart drive, as well as mean to manage them.&lt;br /&gt;&lt;br /&gt;The left side of the LaunchPad lists the installed applications and next to their &lt;a href="http://www.everythingusb.com/hardware/resize.php?size=240&amp;amp;filename=u3launchpad.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 240px; height: 292px;" src="http://www.everythingusb.com/hardware/resize.php?size=240&amp;amp;filename=u3launchpad.jpg" border="0" alt="" /&gt;&lt;/a&gt;icons, with a convenient Download Programs link underneath that links to the U3 software catalog. The right side of the LaunchPad contains links to open the data partition in an explorer window, manage installed apps and the drive itself, and get help.&lt;br /&gt;&lt;br /&gt;Programs can be either downloaded via the built-in web browser (barebones Internet Explorer), or installed from a file on the local computer. In the case of the Geek Squad drive, we are given a third option to download software from the Geek Squad's software catalog (actually hosted by M-Systems, one of the U3 co-founders), which is just the three applications and intro that came preloaded. Not that it matters to most users, but there are two file-types associated with the U3 platform. *.u3i is an XML-based text file that defines the application's version, download path and working parameters, whereas *.u3p is a zip file containing everything needed to run an application.&lt;br /&gt;&lt;a href="http://www.everythingusb.com/hardware/resize.php?size=390&amp;amp;filename=u3softwarecatalog.jpg"&gt;&lt;img style="float:center; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 390px; height: 263px;" src="http://www.everythingusb.com/hardware/resize.php?size=390&amp;amp;filename=u3softwarecatalog.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Most users will find themselves downloading new programs from software.u3.com. While somewhat quirky in design, the site organizes the various applications into 9 different overlapping categories that can then be sorted by name, price, or download availability. Quick links to download freeware or trialware allow users to quickly try software before making a purchase decision. A Top-5 Downloads and Coming Soon section also help to see what new applications everyone's raving about.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;While some of our favorite applications like Dmailer, Thunderbird, Trillian, Winamp and McAfee AV are already out for download, it's quite interesting to see what's headed to the platform. Skype's PC to Phone VoIP service, Firefox's superior web browser, PocketSearch's file content search, and PocketCache's snapshot-based backup system are sure to make a splash when they become available, and there's even a DVD authoring program headed for the drive. What strikes us as odd however is that we couldn't find any word processing applications mentioned yet, so for now we'll just have to fill the gap with Portable OpenOffice.&lt;br /&gt;&lt;a href="http://www.everythingusb.com/hardware/resize.php?size=240&amp;amp;filename=u3manageprograms.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 240px; height: 233px;" src="http://www.everythingusb.com/hardware/resize.php?size=240&amp;amp;filename=u3manageprograms.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Once a U3 application is installed on the drive, you can specify the order in which it appears in the LaunchPad, and tell it to start every time the drive is plugged into a computer. Detailed statistics on the version, footprint of the program, last run time, and vendor are also available.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;For Your Eyes Only&lt;br /&gt;It's possible to lock down the U3 smart drive's data partition with a password so that files will remain secure from prying eyes, complete with password hint. When security is enabled, the CD-ROM partition will load first, and will only enable the data partition after authentication. A password hint can be specified for those with bad memories, and in a worst case scenario the entire data partition can be erased if the password is truly forgotten.&lt;br /&gt;&lt;br /&gt;Enabling security comes at the expense of backwards compatibility however. Because U3 is only compatible with Windows 2000 and XP, any Mac, Linux, or Windows 98/ME users will not be able to authenticate themselves to see the partition. When plugged into a Mac running OS X 10.3, we didn't see the data partition at all until security was disabled. Users working in a cross-platform environment may wish to look into an alternative security application to secure their documents. Also, it is unclear if files stored on the drive are encrypted or not, but most likely they are not because it takes mere seconds to enable security for a near-full 512MB drive.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.everythingusb.com/hardware/resize.php?size=390&amp;amp;filename=u3lastresort.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 390px; height: 336px;" src="http://www.everythingusb.com/hardware/resize.php?size=390&amp;amp;filename=u3lastresort.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;One curious discovery we made was mention of a self-destruct feature in the U3 help files, stating that after a certain amount of invalid password attempts, the drive would lock itself permanently requiring a total reformat. We tested this on the Geek Squad drive, but after 100 invalid password attempts our data was still accessible. Only time can tell how secure the U3 platform really is.&lt;br /&gt;&lt;br /&gt;The Bottom Line&lt;br /&gt;U3 is an important step in the evolution of how we get our work done. User-friendly and well documented, U3 smart drives are something that we could actually give to our grandparents without worrying about how many times they'll be calling us for tech support.&lt;br /&gt;&lt;br /&gt;In the future when office applications are released, parents can send their U3-equipped kids off to college knowing that they can get their work done on any of the school computers without having to buy an expensive laptop. Perhaps most importantly, people with multiple computers will actually be legal and don't have to deal with paying over $300 on products like Office thanks to End User License Agreements (EULAs) being written per flash drive instead of per computer.&lt;br /&gt;&lt;br /&gt;About the only thing we can see wrong with the U3 platform is the lack of cross-platform compatibility, but that might change later on now that Macs are going x86.&lt;br /&gt;&lt;br /&gt;By Scott Clark, Consumer Technology Editor&lt;br /&gt;Edited by Alternator&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-3471521158358355584?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/3471521158358355584/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=3471521158358355584' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3471521158358355584'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3471521158358355584'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/12/u3-portable-usb-apps-platform-secure.html' title='U3 - Portable USB Apps Platform; Secure your USB Drive'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-521164531902446037</id><published>2008-12-12T21:59:00.001+08:00</published><updated>2009-01-06T18:09:44.550+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='How to ...'/><title type='text'>How to Repair a Malfunction USB Flash Drive</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://openclipart.org/people/mystica/mystica_USB_Flash_Drive.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 119px; height: 119px;" src="http://openclipart.org/people/mystica/mystica_USB_Flash_Drive.png" border="0" alt="" /&gt;&lt;/a&gt;Flash memory, flash drive, pen drive and memory drive are just some of the names that are used to refer to USB flash drive. It is a compact device that was developed to be a secure and safe data transfer as well as data storage gadget. While this travel data storage device may seem to be perfect, it is still possible that it might corrupt your data. Just like in any other technology, a USB flash drive is also prone to technical problems that often lead to the corruption or loss of data. Assuming that its hardware is undamaged, doing a re-format can solve USB problems.&lt;br /&gt;&lt;br /&gt;USB formatting is as easy as A-B-C. First, you have to right click on the removable drive corresponding to where the USB was inserted, and then click on the "format" option. Or you can try using the file system drop down, where options "FAT and FAT32" are available. Choose the FAT option, it will reveal format utilities, then click on the "Quick format" option then press on "start" to initiate format operations. This way, all the data that the USB contains will be deleted, but the errors will hopefully be gone. Usually, errors or malfunction occurs during file transfers or data storage. For simple drive errors, scanning and re-formatting can work. In this manner, all the bad sectors of the USB will work like new.&lt;br /&gt;&lt;br /&gt;When formatting does not solve your USB problems, you can make use of an alternate method. For more complicated USB problems, you will need to check the bios first to determine the actual problem. Before doing that, it is advised that you backup all the files from your hard drive to another hard drive, CD or DVD, and then turn off your computer. Insert your problematic USB on the drive port and turn on the computer. When the system bios are prompted, immediately press the F8 key. For some computers, it is the delete key or F2 key that initiate bios checking and take note of the operators that are listed on the screen. Using the cursor keys, navigate the bios and boot the CD drive first, save and then exit. Insert your operating system restore disk, save and restart. Simply follow the cue that initiates installation of your operating system. When the USB disk appears on the list of which drive format comes, then your USB is in the clear.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_oqd-5f-VZso/SUJyd9hAElI/AAAAAAAAACE/x8kYi5XBGeE/s1600-h/00401_kingston_flash_memory.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 200px; height: 159px;" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SUJyd9hAElI/AAAAAAAAACE/x8kYi5XBGeE/s200/00401_kingston_flash_memory.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5278907572286394962" /&gt;&lt;/a&gt;Depending on the options, you must opt out the re-installation of the operating system at this point. If it is still running, simply quit and leave the other drives alone. Try to reset the computer to boot from the disk instead of the CD drive as before. If your USB flash drive is already usable, it must now be detected in windows. If you fail to do this operating system re-installation, then just continue following the installation instructions. However, never try to install the operating system onto the USB disk drive.&lt;br /&gt;&lt;br /&gt;Before going over your USB problems and trying out some troubleshooting tricks, have all your files backed up first, this task is something that must not be taken lightly. Although formatting seems easy, it is a lengthy process that needs to be done by somebody who fully understands the application. If everything else fails, get hold of your USB's warranty so you can get it fixed from customer support.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-521164531902446037?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/521164531902446037/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=521164531902446037' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/521164531902446037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/521164531902446037'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/12/how-to-repair-malfunction-usb-flash.html' title='How to Repair a Malfunction USB Flash Drive'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_oqd-5f-VZso/SUJyd9hAElI/AAAAAAAAACE/x8kYi5XBGeE/s72-c/00401_kingston_flash_memory.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-5783711354478595985</id><published>2008-12-10T22:30:00.001+08:00</published><updated>2009-01-06T18:12:06.753+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Tips'/><title type='text'>Get Latest Exploit, Shellcode on the Net!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.e-xplo.it/exploit.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 300px; height: 150px;" src="http://www.e-xplo.it/exploit.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Since a few years ago, i'm very interest and study about software exploit, shellcode, metasploit and so on. Here it is a few list of website contain information and exploit code that can be found:&lt;br /&gt;&lt;br /&gt;1. &lt;a href="http://www.milw0rm.com/"&gt;http://www.milw0rm.com/&lt;/a&gt;&lt;br /&gt;2. &lt;a href="http://www.securiteam.com/"&gt;http://www.securiteam.com/&lt;/a&gt;&lt;br /&gt;3. &lt;a href="http://neworder.box.sk/"&gt;http://neworder.box.sk&lt;/a&gt;&lt;br /&gt;4. &lt;a href="http://www.governmentsecurity.org/exploits.php"&gt;http://www.governmentsecurity.org/&lt;/a&gt;&lt;br /&gt;5. &lt;a href="http://www.metasploit.com/"&gt;http://www.metasploit.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you have any other good website that related to this topic. Feel free to share with me... ;D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-5783711354478595985?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/5783711354478595985/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=5783711354478595985' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/5783711354478595985'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/5783711354478595985'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/12/get-latest-exploit-shellcode-on-net.html' title='Get Latest Exploit, Shellcode on the Net!'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-7267348354153740346</id><published>2008-12-09T16:26:00.001+08:00</published><updated>2009-01-06T18:10:02.852+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Portable Antivirus Website Down?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_oqd-5f-VZso/ST4tAQOXxRI/AAAAAAAAABc/M-Ww6rNjQmU/s1600-h/pav_abnner.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 50px;" src="http://1.bp.blogspot.com/_oqd-5f-VZso/ST4tAQOXxRI/AAAAAAAAABc/M-Ww6rNjQmU/s400/pav_abnner.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5277705295703295250" /&gt;&lt;/a&gt;&lt;div&gt;After a few week of my website at Data0.Net domain are several times down due to the poor web hoster server. It seem I have to change to a new and powerful server. I'm getting tired when I open my Data0.Net domain and its keep return a girl picture. Complaint is already been made several times. I'm losing lot of money if this keep happening.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;script type="text/javascript"&gt;&lt;!-- google_ad_client = "pub-3826932552632626"; /* Banner Panjang 468x15, created 09/12/08 */ google_ad_slot = "9015907976"; google_ad_width = 468; google_ad_height = 15; //--&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;&lt;br /&gt;&lt;/script&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-7267348354153740346?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/7267348354153740346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=7267348354153740346' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7267348354153740346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7267348354153740346'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/12/portable-antivirus-website-down.html' title='Portable Antivirus Website Down?'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_oqd-5f-VZso/ST4tAQOXxRI/AAAAAAAAABc/M-Ww6rNjQmU/s72-c/pav_abnner.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-7747305367438604273</id><published>2008-11-20T18:10:00.001+08:00</published><updated>2009-01-06T18:09:33.487+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='How to ...'/><title type='text'>How To run Multiple Versions of the Same Program on your PC</title><content type='html'>&lt;p&gt;I was asked in the comments of &lt;a href="http://www.makeuseof.com/tag/how-to-power-up-your-skype-application/"&gt;a previous post&lt;/a&gt; how I managed to run multiple versions of Skype at the same time and while answering him, I thought it was worth turning my answer into a post. It isn’t just Skype that this can be used for. You can also use this method to run multiple versions of your favourite instant messaging program (if you have more than one ID) or multiple versions of your internet browser if you have more than one email account with the same provider. For instance, using this tip you can access multiple gmail accounts at the same time.&lt;/p&gt; &lt;p&gt;With the Windows operating system, everything runs under a user account which you log into when you boot up the computer. Say for the purposes of this discussion, my main default user account on my PC is &lt;strong&gt;MARK_1&lt;/strong&gt;.   Well when I boot up the PC in the morning, MARK_1 will load and all programs I subsequently use will run under &lt;strong&gt;MARK_1&lt;/strong&gt;.&lt;/p&gt; &lt;p&gt;But I sometimes help out a friend who runs a &lt;a href="http://www.varrasconsultancy.com/"&gt;virtual telephone answering service&lt;/a&gt; through Skype. So obviously only one Skype line isn’t going to cut it. To open more Skype lines (without having to log in and out of Windows all the time), here’s what you do :&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;img src="http://www.makeuseof.com/wp-content/uploads/2007/09/newwindowsaccount.gif" alt="newwindowsaccount.gif" /&gt;&lt;/p&gt;&lt;p&gt;First, you need to set up more Windows user accounts.    To make this simple, I’ll name them &lt;strong&gt;MARK_2, MARK_3&lt;/strong&gt; and so on. Since I have a German language computer, I can’t really post too many screenshots and I am unsure of the terminology on an English language computer so I will describe it to you in general terms and perhaps you can tell me the exact wording. In the Windows start menu, you have a “System Setup” option and in there is an option called “User Accounts”. This is where you maintain your Windows accounts, including the main administrator account.&lt;/p&gt; &lt;p&gt;Just open that option up, choose the new account option and set up as many new accounts as you need. YOU DON’T HAVE TO LOG OUT OF YOUR CURRENT USER ACCOUNT TO DO THIS! Plus you need to have administrator privileges to set up new accounts. So trying this at work is probably not a good idea as your IT department will probably not appreciate it.&lt;/p&gt; &lt;p&gt;&lt;img src="http://www.makeuseof.com/wp-content/uploads/2007/09/runas.gif" alt="runas.gif" align="left" /&gt;Once the accounts are set up, go to the desktop icon (or the start menu link) of the program you want to start again and choose “run as”. This will open up a sign-in box with a drop-down list of your user accounts (which by now should contain the new ones you have just created). Just choose another account, enter the password (if you set one up during the account creation process) and the program will instantly open again under that new windows user account.&lt;/p&gt; &lt;p&gt;Using this method, I have run up to five Skype lines simultaneously and the ICQ chat program three times (although I am sure more is possible if you have the CPU capacity to support them all). As I said before, you can also use this method to run more than one Firefox browser to check email accounts or perhaps you want to be logged in as two different users in a social network? The possibilities for running more than one Windows user account is endless.&lt;/p&gt; &lt;p&gt;Can you think of other scenarios where running more than one user account would be beneficial?    Let’s hear it in the comments!&lt;/p&gt; &lt;p&gt;&lt;em&gt;By: Mark O’Neill is a freelance writer, proofreader and blogger. Visit his blog at &lt;a href="http://www.betterthantherapy.net/"&gt;BetterThanTherapy.net&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-7747305367438604273?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/7747305367438604273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=7747305367438604273' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7747305367438604273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7747305367438604273'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/11/how-to-run-multiple-versions-of-same.html' title='How To run Multiple Versions of the Same Program on your PC'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-3493919038967974015</id><published>2008-11-15T00:00:00.001+08:00</published><updated>2009-01-06T18:05:54.638+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Events'/><title type='text'>SKILLS Competition</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_oqd-5f-VZso/SR7W6V26gvI/AAAAAAAAAA0/cU1F4wqQcs0/s1600-h/14112008497.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 150px;" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SR7W6V26gvI/AAAAAAAAAA0/cU1F4wqQcs0/s200/14112008497.jpg" alt="" id="BLOGGER_PHOTO_ID_5268884911858287346" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_oqd-5f-VZso/SR7W5hHN9GI/AAAAAAAAAAs/uLZdu84VRJE/s1600-h/14112008495.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 150px;" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SR7W5hHN9GI/AAAAAAAAAAs/uLZdu84VRJE/s200/14112008495.jpg" alt="" id="BLOGGER_PHOTO_ID_5268884897699591266" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_oqd-5f-VZso/SR7W5T28O5I/AAAAAAAAAAk/7cQVFGw75es/s1600-h/14112008491.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 150px;" src="http://2.bp.blogspot.com/_oqd-5f-VZso/SR7W5T28O5I/AAAAAAAAAAk/7cQVFGw75es/s200/14112008491.jpg" alt="" id="BLOGGER_PHOTO_ID_5268884894141660050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_oqd-5f-VZso/SR7W5OgybxI/AAAAAAAAAAc/mbCDn5fKd1E/s1600-h/14112008487.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 150px;" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SR7W5OgybxI/AAAAAAAAAAc/mbCDn5fKd1E/s200/14112008487.jpg" alt="" id="BLOGGER_PHOTO_ID_5268884892706565906" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_oqd-5f-VZso/SR7U_A0Jv8I/AAAAAAAAAAM/P4IcrNp2GAY/s1600-h/14112008484.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 240px;" src="http://2.bp.blogspot.com/_oqd-5f-VZso/SR7U_A0Jv8I/AAAAAAAAAAM/P4IcrNp2GAY/s320/14112008484.jpg" alt="" id="BLOGGER_PHOTO_ID_5268882793085648834" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This morning I wake up as early 6am to prepare to goto Cheras to watch SKILLS Competition sponsorship by Malaysia CIDB. The competition is taking several categories including IT/Software and Application, Web Design, Graphic Design, Industrial Electronic, CADD, Therapy and many more. I'm just interest about IT/Software and Application section which is seem to be easy if I could join. The question is simple. Every participant need to complete a Microsoft Access application including database and forms. Very simple. But thats take a days to complete it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_oqd-5f-VZso/SR7VU4kbCCI/AAAAAAAAAAU/W9MZv2DBaH0/s1600-h/14112008485.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px; height: 150px;" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SR7VU4kbCCI/AAAAAAAAAAU/W9MZv2DBaH0/s200/14112008485.jpg" alt="" id="BLOGGER_PHOTO_ID_5268883168829311010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I came back to ADTEC Batu Pahat and arrive at 10:30pm having dinner at Parit Karjo.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-3493919038967974015?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/3493919038967974015/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=3493919038967974015' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3493919038967974015'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3493919038967974015'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/11/skills-competition.html' title='SKILLS Competition'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_oqd-5f-VZso/SR7W6V26gvI/AAAAAAAAAA0/cU1F4wqQcs0/s72-c/14112008497.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-1749851688832341310</id><published>2008-09-25T20:00:00.005+08:00</published><updated>2009-11-13T10:31:47.527+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Tips'/><title type='text'>Web Link</title><content type='html'>There is many great website around the world. This is only less than 0.01% of total best website but its worth it. This page will show you most of Malaysian security related website.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Malaysian Security Related Website:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.malaysia-best.com/vbuster/index.htm"&gt;www.malaysia-best.com/vbuster/index.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.hmsecurity.org/"&gt;www.hmsecurity.org&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geekzlife.net/"&gt;www.geekzlife.net&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.malaysiav.com/"&gt;www.malaysiav.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.neologylab.com/"&gt;www.neologylab.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Malaysian Official Cyber Security Agencies:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mycert.org.my/"&gt;www.mycert.org.my&lt;/a&gt; / &lt;a href="http://www.cybersecurity.org.my/"&gt;www.cybersecurity.org.my&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Malaysia IT Forum&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.putera.com/"&gt;www.putera.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.lowyat.net/"&gt;www.lowyat.net&lt;/a&gt; &lt;br /&gt;&lt;span id="main" style="visibility: visible;"&gt;&lt;span id="search" style="visibility: visible;"&gt;&lt;cite&gt;&lt;/cite&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.ittutor.net/"&gt;www.ittutor.net&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-1749851688832341310?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/1749851688832341310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/1749851688832341310'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/09/web-link.html' title='Web Link'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-6881763698767517884</id><published>2008-09-25T19:06:00.026+08:00</published><updated>2009-11-29T22:59:19.400+08:00</updated><title type='text'>Software</title><content type='html'>This page show you the software that has been developed by the author. Leave your comment for your feedback.&lt;br /&gt;&lt;br /&gt;1. Data0 Portable Antivirus&lt;br /&gt;2. Data0 Process Viewer&lt;br /&gt;3. Data0 Classic Explorer&lt;br /&gt;4. Data0 Force Wipe File&lt;br /&gt;5. Data0 Virus Database Generator&lt;br /&gt;5. Data0 Quick Virus Remover&lt;br /&gt;6. Windows Firewall Fixer&lt;br /&gt;7. Shutdown Timer&lt;br /&gt;8. Malware Manager&lt;br /&gt;9. 3Firewall&lt;br /&gt;10. &lt;a href="http://portableantivirus.blogspot.com/2009/11/malware-playground.html"&gt;Malware Playground&lt;/a&gt; (Advanced Sandbox)&lt;br /&gt;11. OpenKamus&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-6881763698767517884?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6881763698767517884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6881763698767517884'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/09/software.html' title='Software'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-6396847193044884905</id><published>2008-09-25T11:04:00.004+08:00</published><updated>2010-01-08T11:37:48.826+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorials'/><title type='text'>Tutorial</title><content type='html'>Here it is some sort of my own tutorial. More tutorial will be listed here as I manage to make some updates on it. If you need me to write a tutorial just leave a comment.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2008/09/extract-autoit-script.html"&gt;Extract AutoIt Script from EXE file&lt;/a&gt; (Video).&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2010/01/unpacking-autoit-script.html"&gt;Unpacking AutoIt Script&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-6396847193044884905?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/6396847193044884905/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=6396847193044884905' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6396847193044884905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6396847193044884905'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/09/tutorial.html' title='Tutorial'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-932596713828586037</id><published>2008-09-25T10:58:00.006+08:00</published><updated>2009-09-25T11:03:53.793+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Tutorials'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>Extract AutoIt Script</title><content type='html'>&lt;div style="text-align: left;"&gt;This is quite old technique to extract an AutoIt script from the compiled EXE files espeacially malware. You can refer this tutorial from my video uploaded to YouTube.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=LkSsbOeJiLc"&gt;Extract AutoIt Script Video Tutorial&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/LkSsbOeJiLc&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/LkSsbOeJiLc&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Actually this kind of extracting method is depending on AutoIt version. Currently this tutorial show you how to extract AutoIt EXE version 3.2.2.0. Other version will be available soon.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-932596713828586037?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/932596713828586037/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=932596713828586037' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/932596713828586037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/932596713828586037'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2008/09/extract-autoit-script.html' title='Extract AutoIt Script'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-7057771117126760189</id><published>2007-10-08T14:39:00.000+08:00</published><updated>2009-03-24T14:43:43.070+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Tips'/><title type='text'>Virus Glossary</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Adware&lt;/span&gt;&lt;br /&gt;Adware is software that presents banner ads or in pop-up windows through a bar that appears on a computer screen. Those advertising spots usually can't be removed and are consequently always visible. The connection data allow many conclusions on the usage behavior and are problematic in terms of data security.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Backdoors&lt;/span&gt;&lt;br /&gt;A backdoor can gain access to a computer by going around the computer access security mechanisms.&lt;br /&gt;&lt;br /&gt;A program that is being executed in the background generally enables the attacker almost unlimited rights. User's personal data can be spied with the backdoor's help, but are mainly used to install further computer viruses or worms on the relevant system.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Boot viruses&lt;/span&gt;&lt;br /&gt;The boot or master boot sector of hard drives is mainly infected by boot sector viruses. They overwrite important information necessary for the system execution. One of the awkward consequences: the computer system cannot be loaded any more…&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Bot-Net&lt;/span&gt;&lt;br /&gt;A Bot-Net is collection of softwarre bots, which run autonomously. A Bot-Net can comprise a collection of cracked machines running programs (usually referred to as worms, Trojans) under a common command and control infrastructure. Boot-Nets server various purposes, including Denial-of-service attacks, etc., partly without the affected PC user's knowledge. The main potential of Bot-Nets is that the networks can achieve dimensions on thousands of computers and its bandwidth sum bursts most conventional Internet accesses.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Dialer &lt;/span&gt;&lt;br /&gt;A dialer is a computer programm that establishes a connection to the Internet or to another computer network through the telephone line or the digital ISDN network. Fraudsters use dialers to charge users high rates when dialing up to the Internet without their knowledge.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;EICAR test file&lt;/span&gt;&lt;br /&gt;The EICAR test file is a test pattern that was developed at the European Institute for Computer Antivirus Research for the purpose to test the functions of anti-virus programs. It is a text file which is 68 characters long and its file extension is “.COM” all virus scanners should recognize as virus. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Exploit&lt;/span&gt;&lt;br /&gt;An exploit (security gap) is a computer program or script that takes advantage of a bug, glitch or vulnerability leading to privilege escalation or denial of service on a computer system. A form of an exploit for example are attacks from the Internet with the help of manipulated data packages. Programs can be infiltrated in order to obtain higher access.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Grayware&lt;/span&gt;&lt;br /&gt;Grayware operates in a way similar to malware, but it is not spread to harm the users directly. It does not affect the system functionality as such. Mostly, information on the patterns of use is collected in order to either sell these data or to place advertisements systematically.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Hoaxes&lt;/span&gt;&lt;br /&gt;The users have obtained virus alerts from the Internet for a few years and alerts against viruses in other networks that are supposed to spread via email. These alerts are spread per email with the request that they should be sent to the highest possible number of colleagues and to other users, in order to warn everyone against the "danger".&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Honeypot&lt;/span&gt;&lt;br /&gt;A honeypot is a service (program or server), which is installed in a network.&lt;br /&gt;&lt;br /&gt;It has the function to monitor a network and to protocol attacks. This service is unknown to the legitime user - because of this reason he is never addressed. If an attacker examines a network for the weak points and uses the services which are offered by a Honeypot, it is protocolled and an alert sets off.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Keystroke logging&lt;/span&gt;&lt;br /&gt;Keystroke logging is a diagnostic tool used in software development that captures the user's keystrokes. It can be useful to determine sources of error in computer systems and is sometimes used to measure employee productivity on certain clerical tasks. Like this, confidential and personal data, such as passwords or PINs, can be spied and sent to other computers via the Internet. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Macro viruses&lt;/span&gt;&lt;br /&gt;Macro viruses are small programs that are written in the macro language of an application (e.g. WordBasic under WinWord 6.0) and that can normally only spread within documents of this application. Because of this, they are also called document viruses. In order to be active, they need that the corresponding applications are activated and that one of the infected macros has been executed. Unlike "normal" viruses, macro viruses do consequently not attack executable files but they do attack the documents of the corresponding host-application.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Polymorph viruses&lt;/span&gt;&lt;br /&gt;Polymorph viruses are the real masters of disguise. They change their own programming codes - and are therefore very hard to detect.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Program viruses&lt;/span&gt;&lt;br /&gt;A computer virus is a program that is capable to attach itself to other programs after being executed and cause an infection. Viruses multiply themselves unlike logic bombs and Trojans. In contrast to a worm, a virus always requires a program as host, where the virus deposits his virulent code. The program execution of the host itself is not changed as a rule.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Script viruses and worms&lt;/span&gt;&lt;br /&gt;Such viruses are extremely easy to program and they can spread - if the required technology is on hand - within a few hours via email round the globe.&lt;br /&gt;&lt;br /&gt;Script viruses and worms use a script language such as Javascript, VBScript etc. to infiltrate in other new scripts or to spread by activation of operating system functions. This frequently happens via email or through the exchange of files (documents).&lt;br /&gt;&lt;br /&gt;A worm is a program that multiplies itself but that does not infect the host. Worms can consequently not form part of other program sequences. Worms are often the only possibility to infiltrate any kind of damaging programs on systems with restrictive security measures.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Spyware&lt;/span&gt;&lt;br /&gt;Spyware are so called spy programs that intercept or take partial control of a computer's operation without the user's informed consent. Spyware is designed to expolit infected computers for commerical gain. Typical tactics furthering this goal include delivery of unsolicited pop-up advertisements. AntiVir is able to detect this kind of software with the category "ADSPY" or "adware-spyware".&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Trojan horses (short Trojans)&lt;/span&gt;&lt;br /&gt;Trojans are pretty common nowadays. We are talking about programs that pretend to have a particular function, but that show their real image after execution and carry out a different function that, in most cases, is destructive. Trojan horses cannot multiply themselves, which differenciates them from viruses and worms. Most of them have an interesting name (SEX.EXE or STARTME.EXE) with the intention to induce the user to start the Trojan. Immediately after execution they become active and can, for example, format the hard drive. A dropper is a special form of Trojan that 'drops' viruses, i.e. embeds viruses on the computer system.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Zombie&lt;/span&gt;&lt;br /&gt;A Zombie-PC is a computer that is infected with malware programs and that enables hackers to abuse computers via remote control for criminal purposes. The affected PC, for example, can start Denial-of-Service- (DoS) attacks at command or send spam and phishing emails.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-7057771117126760189?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/7057771117126760189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=7057771117126760189' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7057771117126760189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7057771117126760189'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2007/10/virus-glossary.html' title='Virus Glossary'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-2744944285940679883</id><published>2006-07-25T18:07:00.002+08:00</published><updated>2009-05-02T15:29:30.501+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><title type='text'>World First Computer Viruses!</title><content type='html'>&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The &lt;a href="http://en.wikipedia.org/wiki/Creeper_virus" title="Creeper virus"&gt;Creeper virus&lt;/a&gt; was first detected on &lt;a href="http://en.wikipedia.org/wiki/ARPANET" title="ARPANET"&gt;ARPANET&lt;/a&gt;, the forerunner of the &lt;a href="http://en.wikipedia.org/wiki/Internet" title="Internet"&gt;Internet&lt;/a&gt; in the early 1970s.&lt;sup id="cite_ref-viruslist_2-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus#cite_note-viruslist-2" title=""&gt;&lt;span&gt;[&lt;/span&gt;3&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt; Creeper was an experimental &lt;a href="http://en.wikipedia.org/w/index.php?title=Self-replicating_program&amp;amp;action=edit&amp;amp;redlink=1" class="new" title="Self-replicating program (page does not exist)"&gt;self-replicating program&lt;/a&gt; written by &lt;a href="http://en.wikipedia.org/wiki/Bob_Thomas" title="Bob Thomas" class="mw-redirect"&gt;Bob Thomas&lt;/a&gt; at &lt;a href="http://en.wikipedia.org/wiki/BBN" title="BBN"&gt;BBN&lt;/a&gt; in 1971.&lt;sup id="cite_ref-3" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus#cite_note-3" title=""&gt;&lt;span&gt;[&lt;/span&gt;4&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt; Creeper used the ARPANET to infect DEC &lt;a href="http://en.wikipedia.org/wiki/PDP-10" title="PDP-10"&gt;PDP-10&lt;/a&gt; computers running the &lt;a href="http://en.wikipedia.org/wiki/TOPS-20" title="TOPS-20"&gt;TENEX operating system&lt;/a&gt;. Creeper gained access via the ARPANET and copied itself to the remote system where the message, "I'm the creeper, catch me if you can!" was displayed. The &lt;i&gt;Reaper&lt;/i&gt; program was created to delete Creeper.&lt;sup id="cite_ref-4" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus#cite_note-4" title=""&gt;&lt;span&gt;[&lt;/span&gt;5&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt; &lt;p&gt;A program called "&lt;a href="http://en.wikipedia.org/w/index.php?title=Rother_J&amp;amp;action=edit&amp;amp;redlink=1" class="new" title="Rother J (page does not exist)"&gt;Rother J&lt;/a&gt;" was the first computer virus to appear "in the wild" — that is, outside the single computer or lab where it was created.&lt;sup class="noprint Template-Fact"&gt;&lt;span title="This claim needs references to reliable sources since March 2009" style="white-space: nowrap;"&gt;[&lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Wikipedia:Citation_needed" title="Wikipedia:Citation needed"&gt;citation needed&lt;/a&gt;&lt;/i&gt;]&lt;/span&gt;&lt;/sup&gt; Written in 1981 by &lt;a href="http://en.wikipedia.org/wiki/Richard_Skrenta" title="Richard Skrenta" class="mw-redirect"&gt;Richard Skrenta&lt;/a&gt;, it attached itself to the &lt;a href="http://en.wikipedia.org/wiki/Apple_DOS" title="Apple DOS"&gt;Apple DOS&lt;/a&gt; 3.3 operating system and spread via &lt;a href="http://en.wikipedia.org/wiki/Floppy_disk" title="Floppy disk"&gt;floppy disk&lt;/a&gt;.&lt;sup id="cite_ref-5" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus#cite_note-5" title=""&gt;&lt;span&gt;[&lt;/span&gt;6&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt; This virus was created as a practical joke when Richard Skrenta was still in high school. It was injected in a game on a floppy disk. On its 50th use the &lt;a href="http://en.wikipedia.org/wiki/Elk_Cloner" title="Elk Cloner"&gt;Elk Cloner&lt;/a&gt; virus would be activated, infecting the computer and displaying a short poem beginning "Elk Cloner: The program with a personality."&lt;/p&gt; &lt;p&gt;The first PC virus in the wild was a boot sector virus dubbed &lt;a href="http://en.wikipedia.org/wiki/%28c%29Brain" title="(c)Brain" class="mw-redirect"&gt;(c)Brain&lt;/a&gt;&lt;sup id="cite_ref-6" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus#cite_note-6" title=""&gt;&lt;span&gt;[&lt;/span&gt;7&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;, created in 1986 by the &lt;a href="http://en.wikipedia.org/wiki/Farooq_Alvi_Brothers" title="Farooq Alvi Brothers"&gt;Farooq Alvi Brothers&lt;/a&gt;, operating out of &lt;a href="http://en.wikipedia.org/wiki/Lahore,_Pakistan" title="Lahore, Pakistan" class="mw-redirect"&gt;Lahore, Pakistan&lt;/a&gt;. The brothers reportedly created the virus to deter pirated copies of software they had written&lt;sup class="noprint Template-Fact"&gt;&lt;span title="This claim needs references to reliable sources since March 2009" style="white-space: nowrap;"&gt;[&lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Wikipedia:Citation_needed" title="Wikipedia:Citation needed"&gt;citation needed&lt;/a&gt;&lt;/i&gt;]&lt;/span&gt;&lt;/sup&gt;. However, analysts have claimed that the Ashar virus, a variant of Brain, possibly predated it based on code within the virus.&lt;sup class="noprint Inline-Template"&gt;&lt;span title="The material in the vicinity of this tag may be based upon unreliable original research since January 2008" style="white-space: nowrap;"&gt;[&lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Wikipedia:No_original_research" title="Wikipedia:No original research"&gt;original research?&lt;/a&gt;&lt;/i&gt;]&lt;/span&gt;&lt;/sup&gt;&lt;/p&gt; &lt;p&gt;Before computer networks became widespread, most viruses spread on &lt;a href="http://en.wikipedia.org/wiki/Removable_media" title="Removable media"&gt;removable media&lt;/a&gt;, particularly &lt;a href="http://en.wikipedia.org/wiki/Floppy_disk" title="Floppy disk"&gt;floppy disks&lt;/a&gt;. In the early days of the &lt;a href="http://en.wikipedia.org/wiki/Personal_computer" title="Personal computer"&gt;personal computer&lt;/a&gt;, many users regularly exchanged information and programs on floppies. Some viruses spread by infecting programs stored on these disks, while others installed themselves into the disk &lt;a href="http://en.wikipedia.org/wiki/Boot_sector" title="Boot sector"&gt;boot sector&lt;/a&gt;, ensuring that they would be run when the user booted the computer from the disk, usually inadvertently. PCs of the era would attempt to boot first from a floppy if one had been left in the drive. Until floppy disks fell out of use, this was the most successful infection strategy and boot sector viruses were the most common in the wild for many years.&lt;sup id="cite_ref-7" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus#cite_note-7" title=""&gt;&lt;span&gt;[&lt;/span&gt;8&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt; &lt;p&gt;Traditional computer viruses emerged in the 1980s, driven by the spread of personal computers and the resultant increase in &lt;a href="http://en.wikipedia.org/wiki/Bulletin_board_system" title="Bulletin board system"&gt;BBS&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Modem" title="Modem"&gt;modem&lt;/a&gt; use, and software sharing. &lt;a href="http://en.wikipedia.org/wiki/Bulletin_board" title="Bulletin board"&gt;Bulletin board&lt;/a&gt; driven software sharing contributed directly to the spread of Trojan horse programs, and viruses were written to infect popularly traded software. &lt;a href="http://en.wikipedia.org/wiki/Shareware" title="Shareware"&gt;Shareware&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Copyright_violation" title="Copyright violation" class="mw-redirect"&gt;bootleg&lt;/a&gt; software were equally common &lt;a href="http://en.wikipedia.org/wiki/Vector_%28malware%29" title="Vector (malware)"&gt;vectors&lt;/a&gt; for viruses on BBS's.&lt;sup class="noprint Template-Fact"&gt;&lt;span title="This claim needs references to reliable sources since January 2008" style="white-space: nowrap;"&gt;[&lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Wikipedia:Citation_needed" title="Wikipedia:Citation needed"&gt;citation needed&lt;/a&gt;&lt;/i&gt;]&lt;/span&gt;&lt;/sup&gt; Within the "pirate scene" of hobbyists trading illicit copies of &lt;a href="http://en.wikipedia.org/wiki/Retail_software" title="Retail software" class="mw-redirect"&gt;retail software&lt;/a&gt;, traders in a hurry to obtain the latest applications were easy targets for viruses.&lt;sup class="noprint Inline-Template"&gt;&lt;span title="The material in the vicinity of this tag may be based upon unreliable original research since January 2008" style="white-space: nowrap;"&gt;[&lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Wikipedia:No_original_research" title="Wikipedia:No original research"&gt;original research?&lt;/a&gt;&lt;/i&gt;]&lt;/span&gt;&lt;/sup&gt;&lt;/p&gt; &lt;p&gt;Since the mid-1990s, &lt;a href="http://en.wikipedia.org/wiki/Macro_virus_%28computing%29" title="Macro virus (computing)"&gt;macro viruses&lt;/a&gt; have become common. Most of these viruses are written in the scripting languages for Microsoft programs such as &lt;a href="http://en.wikipedia.org/wiki/Microsoft_Word" title="Microsoft Word"&gt;Word&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Microsoft_Excel" title="Microsoft Excel"&gt;Excel&lt;/a&gt; and spread throughout &lt;a href="http://en.wikipedia.org/wiki/Microsoft_Office" title="Microsoft Office"&gt;Microsoft Office&lt;/a&gt; by infecting documents and spreadsheets. Since Word and Excel were also available for &lt;a href="http://en.wikipedia.org/wiki/Mac_OS" title="Mac OS"&gt;Mac OS&lt;/a&gt;, most could also spread onto &lt;a href="http://en.wikipedia.org/wiki/Macintosh" title="Macintosh"&gt;Macintosh computers&lt;/a&gt; as well. Although the majority of these viruses did not have the ability to send infected &lt;a href="http://en.wikipedia.org/wiki/Electronic_mail" title="Electronic mail" class="mw-redirect"&gt;e-mail&lt;/a&gt;, those viruses which did took advantage of the &lt;a href="http://en.wikipedia.org/wiki/Microsoft_Outlook" title="Microsoft Outlook"&gt;Microsoft Outlook&lt;/a&gt; &lt;a href="http://en.wikipedia.org/wiki/Component_Object_Model" title="Component Object Model"&gt;COM&lt;/a&gt; interface.&lt;sup class="noprint Template-Fact"&gt;&lt;span title="This claim needs references to reliable sources since January 2008" style="white-space: nowrap;"&gt;[&lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Wikipedia:Citation_needed" title="Wikipedia:Citation needed"&gt;citation needed&lt;/a&gt;&lt;/i&gt;]&lt;/span&gt;&lt;/sup&gt;&lt;/p&gt; &lt;p&gt;Some old versions of Microsoft Word allow macros to replicate themselves with additional blank lines. If two macro viruses simultaneously infect a document, the combination of the two, if also self-replicating, can appear as a "mating" of the two and would likely be detected as a virus unique from the "parents."&lt;sup id="cite_ref-8" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus#cite_note-8" title=""&gt;&lt;span&gt;[&lt;/span&gt;9&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt; &lt;p&gt;A virus may also send a &lt;a href="http://en.wikipedia.org/wiki/Uniform_Resource_Locator" title="Uniform Resource Locator"&gt;web address&lt;/a&gt; link as an &lt;a href="http://en.wikipedia.org/wiki/Instant_message" title="Instant message" class="mw-redirect"&gt;instant message&lt;/a&gt; to all the contacts on an infected machine. If the recipient, thinking the link is from a friend (a trusted source) follows the link to the website, the virus hosted at the site may be able to infect this new computer and continue propagating.&lt;/p&gt; &lt;p&gt;Cross-site scripting viruses emerged recently, and were academically demonstrated in 2005.&lt;sup id="cite_ref-9" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus#cite_note-9" title=""&gt;&lt;span&gt;[&lt;/span&gt;10&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt; Since 2005 there have been multiple instances of the cross-site scripting viruses in the wild, exploiting websites such as &lt;a href="http://en.wikipedia.org/wiki/Samy_%28XSS%29" title="Samy (XSS)"&gt;MySpace&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Yahoo" title="Yahoo" class="mw-redirect"&gt;Yahoo&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-2744944285940679883?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/2744944285940679883/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=2744944285940679883' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/2744944285940679883'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/2744944285940679883'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2006/07/world-first-computer-viruses.html' title='World First Computer Viruses!'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-1978637810970461007</id><published>2005-10-03T08:59:00.004+08:00</published><updated>2009-10-03T09:45:03.186+08:00</updated><title type='text'>Advertisement</title><content type='html'>Data0You may put this advertisement banner into your website to support local product. More banner size will be available soon.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img526.imageshack.us/img526/7492/iklan2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://img526.imageshack.us/img526/7492/iklan2.gif" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;480px × 30px&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;span style="font-size: x-small;"&gt;&lt;textarea 20%;="" cols="35" font-size:="" name="code" onclick="this.select();trackSelection()" onfocus="this.select()" readonly="readonly" rows="5"&gt;&amp;lt;a href='http://www.data0.net/' target='_blank'&amp;gt;&amp;lt;img width='158' height='40' alt='Data0.Net Portable Antivirus' src='http://img526.imageshack.us/img526/7492/iklan2.gif' border='0'&amp;gt;&amp;lt;/a&amp;gt;&lt;/textarea&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-1978637810970461007?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/1978637810970461007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/1978637810970461007'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2005/10/advertisement.html' title='Advertisement'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-3670046564567963273</id><published>2005-09-22T09:16:00.001+08:00</published><updated>2009-09-22T09:31:18.133+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>AT4RE FastScanner</title><content type='html'>&lt;a href="http://www.at4re.com/download.php?view.5" title="AT4RE FastScanner"&gt;AT4RE FastScanner&lt;/a&gt; is one of packer, PE info, compiler, cryptor detector&amp;nbsp; with plug-in capabilities. This tools works same like other packed detector to give alternative usage for user.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_oqd-5f-VZso/Srgm11FU9gI/AAAAAAAAAPI/zhThx6sYlrk/s1600-h/1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_oqd-5f-VZso/Srgm11FU9gI/AAAAAAAAAPI/zhThx6sYlrk/s400/1.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;An example show you PE file is being analyzed with all basic information shown.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_oqd-5f-VZso/SrgnBFw_NDI/AAAAAAAAAPQ/7UyNqOp3iCs/s1600-h/2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_oqd-5f-VZso/SrgnBFw_NDI/AAAAAAAAAPQ/7UyNqOp3iCs/s400/2.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Show you PE section with all available offset.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_oqd-5f-VZso/SrgoIFvCNbI/AAAAAAAAAPg/bd9rXvM2SyE/s1600-h/3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_oqd-5f-VZso/SrgoIFvCNbI/AAAAAAAAAPg/bd9rXvM2SyE/s400/3.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Disassembler is another advantage giving user to analyze and finding useful instruction.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;AT4RE FastScanner can be downloaded from:&lt;br /&gt;&lt;a href="http://www.at4re.com/request.php?5"&gt;Here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-3670046564567963273?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/3670046564567963273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=3670046564567963273' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3670046564567963273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3670046564567963273'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2005/09/at4re-fastscanner.html' title='AT4RE FastScanner'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_oqd-5f-VZso/Srgm11FU9gI/AAAAAAAAAPI/zhThx6sYlrk/s72-c/1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-2984554336088328610</id><published>2005-09-21T21:37:00.003+08:00</published><updated>2009-09-21T22:06:23.060+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>PROTECTiON iD</title><content type='html'>Another small tools with great features. As I downloaded the latest one, there interfaces was changed and little bit confuse if some user new to it but again this great tools comes with special features.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img27.imageshack.us/img27/5720/66203898.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://img27.imageshack.us/img27/5720/66203898.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 11pt;"&gt;Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;&lt;br /&gt;&lt;br /&gt;- detection of every major PC ISO Game / App protection&lt;br /&gt;&lt;span style="color: black;"&gt;- sector scanning CDs / DVDs for Copy Protections&lt;br /&gt;&lt;/span&gt;- covers more than &lt;b&gt;430 (different!)&lt;/b&gt; protections including exe protectors, .net protectors, packers, dongles, licenses &amp;amp; installers&lt;br /&gt;- files / folders can simply be drag &amp;amp; droped into pid (link files will re resolved too)&lt;br /&gt;&lt;span style="color: black;"&gt;- strong scanning routines allowing it to detect multiple protections in one file&lt;br /&gt;- easy scanning via shell context menu&lt;br /&gt;&lt;/span&gt;- usefully misc tools included&lt;br /&gt;- coded 100% in Win32 assembly language&lt;br /&gt;- fully 32bit &amp;amp; 64bit compliant&lt;br /&gt;- working on every Windows OS from Win9x to windows Vista&lt;br /&gt;&lt;span style="color: black;"&gt;- no additional files are required (like VB Runtimes, MSVC dlls or ASPI drivers)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;PROTECTION ID can be downloaded from:&lt;br /&gt;&lt;a href="http://pid.gamecopyworld.com/ProtectionID_v6.2.3.rar"&gt;Here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-2984554336088328610?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/2984554336088328610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=2984554336088328610' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/2984554336088328610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/2984554336088328610'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2005/09/protection-id.html' title='PROTECTiON iD'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-269217303209447957</id><published>2005-09-14T14:35:00.005+08:00</published><updated>2009-10-03T21:52:53.071+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Tips'/><title type='text'>Mal-ware Analyst Tools</title><content type='html'>&lt;div style="text-align: justify;"&gt;Most of anti virus developer has their own technique and skill to get rid of mal-ware content. Making analyst for the captured mal-ware is very important before deciding whether it is harmful or not. Anti virus or security company with Malware Analyst job has their own &amp;amp; useful tools to trace malware like behaviour. Well, here it is some basic tools for Reverse Code Engineering. Click on each list for detail:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;PE Editor/Memory Dump:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2004/09/lordpe-deluxe.html"&gt;LordPE Deluxe&lt;/a&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2004/09/ollydump-for-ollydebugger.html"&gt;OllyDump&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2004/09/explorer-suite.html" title="Explorer Suite"&gt;Explorer Suite&lt;/a&gt; (Combine with all the tools we need).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Packer/ID Detector:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2004/09/trid-file-identifier.html"&gt;TrID&lt;/a&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2004/09/peid-pe-identifier.html" title="PEiD"&gt;PEiD&lt;/a&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2004/09/exeinfo-pe.html" title="ExeInfo PE"&gt;ExeInfo PE&lt;/a&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2005/09/protection-id.html" title="Protection ID"&gt;Protection ID&lt;/a&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2005/09/at4re-fastscanner.html" title="AT4RE FastScanner"&gt;AT4RE FastScanner&lt;/a&gt;&lt;br /&gt;DiE (Detect it Easy)&lt;br /&gt;RDG Packer Detector&lt;br /&gt;Jim Clausing's Malware Packer Signatures&lt;br /&gt;Neil's Collection of Packer Signatures&lt;br /&gt;packerid.py (Python)&lt;br /&gt;&lt;br /&gt;Sometime, one packed detector is not enough. Not all detector can detect all packer.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Disassembly/Debugger Tools:&lt;/span&gt;&lt;br /&gt;OllyDebugger, OllyScript&lt;br /&gt;Interactive Disassembler (IDA)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Resource Viewer:&lt;/span&gt;&lt;br /&gt;PE Explorer&lt;br /&gt;ResHacker&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Process Monitor:&lt;/span&gt;&lt;br /&gt;Sysinternals Process Explorer&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;File &amp;amp; Folder Watcher:&lt;/span&gt;&lt;br /&gt;SpyMe Tools&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Registry Snapshot:&lt;/span&gt;&lt;br /&gt;RegShot&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Network Tools:&lt;/span&gt;&lt;br /&gt;WireShark&lt;br /&gt;NMap&lt;br /&gt;Snort&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Honeypot:&lt;/span&gt;&lt;br /&gt;HiHAT (&lt;a href="http://hihat.sourceforge.net/"&gt;Website&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Sandbox&lt;/span&gt;:&lt;br /&gt;Sandboxie&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Other Miscellanous tools:&lt;/span&gt;&lt;br /&gt;Sandboxie&lt;br /&gt;VMWare&lt;br /&gt;Microsoft Virtual PC&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Online tools:&lt;/span&gt;&lt;br /&gt;VirusTotal&lt;br /&gt;ThreatExpert&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-269217303209447957?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/269217303209447957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/269217303209447957'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2005/09/mal-ware-analyst-tools.html' title='Mal-ware Analyst Tools'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-3101644513541010643</id><published>2004-09-21T20:53:00.001+08:00</published><updated>2009-09-21T21:22:44.444+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>ExeInfo PE</title><content type='html'>ExeInfo PE have some same features with &lt;a href="http://portableantivirus.blogspot.com/2004/09/peid-pe-identifier.html"&gt;PEiD&lt;/a&gt; but with some extra function to make it more easier and faster to access such as&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img6.imageshack.us/img6/1475/44108526.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://img6.imageshack.us/img6/1475/44108526.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Main interfaces is very similar to PEiD but with some great functionalities.&amp;nbsp; &lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img15.imageshack.us/img15/3346/82930331.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://img15.imageshack.us/img15/3346/82930331.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt; With &lt;b&gt;Rip &lt;/b&gt;button all resources can be extracted at once and saved into current directory.&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img12.imageshack.us/img12/3417/21366127.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://img12.imageshack.us/img12/3417/21366127.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt; With tools menu user can get a lot of information inside PE files such as registry key, OEP, save resource section, XoR permutator (easy to reverse any reversed string such as ROT13) and many more.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img12.imageshack.us/img12/783/33072659.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://img12.imageshack.us/img12/783/33072659.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt; File Menu offer to you multiple options about taking action to your analyzed file. WYSIWYG.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;EXEInfo PE can be downloaded from:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://www.exeinfo.xwp.pl/"&gt;http://www.exeinfo.xwp.pl&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-3101644513541010643?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/3101644513541010643/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=3101644513541010643' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3101644513541010643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3101644513541010643'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/09/exeinfo-pe.html' title='ExeInfo PE'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-4712316257425025140</id><published>2004-09-21T20:21:00.000+08:00</published><updated>2009-09-21T20:32:55.985+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>PEiD - PE Identifier</title><content type='html'>This small tools have a big features for those who want to extract information from PE files.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img225.imageshack.us/img225/7545/22784508.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://img225.imageshack.us/img225/7545/22784508.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;PEiD have its own special features:&lt;/b&gt;&lt;br /&gt;1. It has a superb GUI and the interface is really intuitive and simple.&lt;br /&gt;2. Detection rates are amongst the best given by any other identifier.&lt;br /&gt;3. Special scanning modes for *advanced* detections of modified and unknown files.&lt;br /&gt;4. Shell integration, Command line support, Always on top and Drag'n'Drop capabilities.&lt;br /&gt;5. Multiple file and directory scanning with recursion.&lt;br /&gt;6. Task viewer and controller.&lt;br /&gt;7. Plugin Interface with plugins like Generic OEP Finder and Krypto ANALyzer.&lt;br /&gt;8. Extra scanning techniques used for even better detections.&lt;br /&gt;9. Heuristic Scanning options.&lt;br /&gt;10. New PE details, Imports, Exports and TLS viewers&lt;br /&gt;11. New built in quick disassembler.&lt;br /&gt;12. New built in hex viewer.&lt;br /&gt;13. External signature interface which can be updated by the user.&lt;br /&gt;&lt;br /&gt;Well, I use it for long time and this is the great and fast tools for getting PE information without need to install anything.&lt;br /&gt;&lt;br /&gt;PEiD can be downloaded from here:&lt;br /&gt;&lt;a href="http://www.peid.info/"&gt;http://www.peid.info&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-4712316257425025140?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/4712316257425025140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=4712316257425025140' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/4712316257425025140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/4712316257425025140'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/09/peid-pe-identifier.html' title='PEiD - PE Identifier'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-8076585559439436162</id><published>2004-09-19T23:31:00.001+08:00</published><updated>2009-09-20T22:56:48.231+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>Explorer Suite</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;This one of most advanced freeware tools for Reverse Code Engineer. Created by Daniel Pistelli, a freeware suite of tools including a PE editor called CFF Explorer and a process viewer. The PE editor has full support for PE32/64. Special fields description and modification (.NET supported), utilities, rebuilder, hex editor, import adder, signature scanner, signature manager, extension support, scripting, disassembler, dependency walker etc. First PE editor with support for .NET internal structures. Resource Editor (Windows Vista icons supported) capable of handling .NET manifest resources. The suite is available for x86, x64 and Itanium. &lt;/span&gt;  &lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt; &lt;a class="shorttitle" href="http://www.ntcore.com/files/ExplorerSuite.exe"&gt;- Explorer Suite (Multi-Platform Version, Recommended)&lt;/a&gt; &lt;br /&gt;&lt;a class="shorttitle" href="http://www.ntcore.com/files/ExplorerSuite-x86.exe"&gt;- Explorer Suite (x86 Version)&lt;/a&gt; &lt;br /&gt;&lt;a class="shorttitle" href="http://www.ntcore.com/files/CFF_Explorer.zip"&gt;- CFF Explorer (x86 Version, stand-alone, Zip Archive)&lt;/a&gt;  &lt;br /&gt;&lt;br /&gt;&lt;a class="shorttitle" href="http://www.woodmann.com/collaborative/tools/index.php/Category:CFF_Explorer_Extensions"&gt;- CFF Explorer Extensions Repository&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_oqd-5f-VZso/SrT5kViRh_I/AAAAAAAAAOo/5o1-iq7ip1A/s1600-h/1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_oqd-5f-VZso/SrT5kViRh_I/AAAAAAAAAOo/5o1-iq7ip1A/s400/1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;The CFF Explorer was designed to make PE editing as easy as possible, but without losing sight on the portable executable's internal structure. This application includes a series of tools which might help not only reverse engineers but also programmers. It offers a multi-file environment and a switchable interface.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_oqd-5f-VZso/SrT5sixSi9I/AAAAAAAAAOw/uYGiMg-4OFE/s1600-h/2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SrT5sixSi9I/AAAAAAAAAOw/uYGiMg-4OFE/s400/2.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Arial; font-size: medium;"&gt;Features:&lt;/span&gt;&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;&lt;ul style="font-family: Arial,Verdana; font-size: 13px; list-style-type: square;"&gt;&lt;li&gt;Process Viewer&lt;/li&gt;&lt;li&gt;Windows Viewer&lt;/li&gt;&lt;li&gt;PE and Memory Dumper&lt;/li&gt;&lt;li&gt;Full support for PE32/64&lt;/li&gt;&lt;li&gt;Special fields description and modification (.NET supported)&lt;/li&gt;&lt;li&gt;PE Utilities&lt;/li&gt;&lt;li&gt;PE Rebuilder (with Realigner, IT Binder, Reloc Remover, Strong Name    Signature Remover, Image Base Changer)&lt;/li&gt;&lt;li&gt;View and modification of .NET internal structures&lt;/li&gt;&lt;li&gt;Resource Editor (full support for Windows Vista icons)&lt;/li&gt;&lt;li&gt;Support in the Resource Editor for .NET resources (dumpable as well)&lt;/li&gt;&lt;li&gt;Hex Editor&lt;/li&gt;&lt;li&gt;Import Adder&lt;/li&gt;&lt;li&gt;PE integrity checks&lt;/li&gt;&lt;li&gt;Extension support&lt;/li&gt;&lt;li&gt;Visual Studio Extensions Wizard&lt;/li&gt;&lt;li&gt;Powerful scripting language&lt;/li&gt;&lt;li&gt;Dependency Walker&lt;/li&gt;&lt;li&gt;Quick Disassembler (x86, x64, MSIL)&lt;/li&gt;&lt;li&gt;Name Unmangler&lt;/li&gt;&lt;li&gt;Extension support&lt;/li&gt;&lt;li&gt;File Scanner&lt;/li&gt;&lt;li&gt;Directory Scanner&lt;/li&gt;&lt;li&gt;Deep Scan method&lt;/li&gt;&lt;li&gt;Recursive Scan method&lt;/li&gt;&lt;li&gt;Multiple results&lt;/li&gt;&lt;li&gt;Report generation&lt;/li&gt;&lt;li&gt;Signatures Manager&lt;/li&gt;&lt;li&gt;Signatures Updater&lt;/li&gt;&lt;li&gt;Signatures Collisions Checker&lt;/li&gt;&lt;li&gt;Signatures Retriever&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-8076585559439436162?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/8076585559439436162/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=8076585559439436162' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/8076585559439436162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/8076585559439436162'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/09/explorer-suite.html' title='Explorer Suite'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_oqd-5f-VZso/SrT5kViRh_I/AAAAAAAAAOo/5o1-iq7ip1A/s72-c/1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-7956460723160004115</id><published>2004-09-19T23:22:00.007+08:00</published><updated>2009-09-20T22:57:43.593+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>TrID - File Identifier</title><content type='html'>&lt;div style="text-align: justify;"&gt;TrID is an utility designed to identify file types from their binary signatures. While there are similar utilities with hard coded rules, TriID has no such rules. Instead, it is extensible and can be trained to recognize new formats in a fast and automatic way. &lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;TrID has many uses: identify what kind of file was sent to you via e-mail, aid in forensic analysis,  support in file recovery, etc. &lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;TrID uses a database of definitions which describe recurring patterns for supported file types. As this is subject to  very frequent update, it's made available as a separate package. Just download both TrID and this archive and unpack in the same folder.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The database of definitions is constantly expanding; the more that are available, the more accurate an analysis of an unknown file can be. You can help! Use the program to both recognize unknown file types and develop new definitions that can be added to the library. See the &lt;a href="http://mark0.net/soft-tridscan-e.html"&gt;TrIDScan&lt;/a&gt; page for information about how you can help. Just run the TrIDScan module against a number of files of a given type. The program will do the rest. &lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Because TrID uses an expandable database it will never be out of date. As new file types become available you can run the scan module against them and help keep the program up to date. Other people around the world will be doing the same thing making the database a dynamic and living thing.  If you have special file formats that only you use, you can also add them to your local database, making their identification easier. &lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;To get you started, the &lt;a href="http://mark0.net/soft-trid-deflist.html"&gt;current library&lt;/a&gt; of definitions is up to 3833 file types and growing fast. &lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;TrID is simple to use. Just run TrID and point it to the file to be analyzed. The file will be read and compared with the definitions in the database. Results are presented in order of highest probability.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img33.imageshack.us/img33/8708/50984906.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="350" src="http://img33.imageshack.us/img33/8708/50984906.jpg" width="420" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;For more information and download &lt;a href="http://mark0.net/soft-trid-e.html"&gt;click here&lt;/a&gt;.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-7956460723160004115?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/7956460723160004115/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=7956460723160004115' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7956460723160004115'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/7956460723160004115'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/09/trid-file-identifier.html' title='TrID - File Identifier'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-4844853152373414500</id><published>2004-09-19T22:48:00.002+08:00</published><updated>2009-09-20T22:58:42.232+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>OllyDump for OllyDebugger</title><content type='html'>&lt;div style="text-align: justify;"&gt;OllyDump is one of advanced memory dumping tools. It is easy to use with OllyDbg as a plugin. Once the process is being debugged at runtime, it will be automatically search for PE section. But this tools does not give you automatically an OEP for any compressed PE file. You still have to find their OEP offset manually and write down the offset to the OllyDump window. The picture below show you how the OllyDump plugin works for dumping UPX packed file.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img185.imageshack.us/img185/412/48671602.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="310" src="http://img185.imageshack.us/img185/412/48671602.jpg" width="420" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Just simply add your founded OEP to the &lt;i&gt;Modify &lt;/i&gt;box and hit &lt;i&gt;Dump &lt;/i&gt;button to save as a dumped file. You can edit the listed section for your own usages. You can easily dumping PE file without need to highlight all the debugged code and choose '&lt;i&gt;Follow in Dump &amp;gt; Selection&lt;/i&gt;'. This way sometime does not produce an accurate result.&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;You can find OllyDump &lt;a href="http://rapidshare.com/files/282238065/g_ollydump221b.zip"&gt;here&lt;/a&gt; or &lt;a href="http://www.google.com.my/#hl=en&amp;amp;source=hp&amp;amp;q=ollydump&amp;amp;btnG=Google+Search&amp;amp;meta=&amp;amp;fp=a518f93177784ce8"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-4844853152373414500?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/4844853152373414500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=4844853152373414500' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/4844853152373414500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/4844853152373414500'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/09/ollydump-for-ollydebugger.html' title='OllyDump for OllyDebugger'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-6113914123369873822</id><published>2004-09-19T17:31:00.003+08:00</published><updated>2009-09-20T22:59:48.270+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='RCE'/><title type='text'>LordPE Deluxe</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_oqd-5f-VZso/SrSlANbMggI/AAAAAAAAAOY/7ahigtrjRq8/s1600-h/1.JPG" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5383108877636895234" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SrSlANbMggI/AAAAAAAAAOY/7ahigtrjRq8/s400/1.JPG" style="cursor: pointer; height: 366px; margin: 0pt 10px 10px 0pt; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;LordPE Deluxe is one of the greatest tools for making process dump on memory for along time. It was developed by yoda. Here it is what this tools can do:&lt;br /&gt;&lt;br /&gt;+ Dump process from memory and save as file.&lt;br /&gt;+ Dump process module&lt;br /&gt;+ Get Basic information about PE header.&lt;br /&gt;+ Rebuild any PE file (realign, wipe relocation, rebuild import table, etc)&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_oqd-5f-VZso/SrSnIVErGKI/AAAAAAAAAOg/QPFVPw08afA/s1600-h/2.JPG" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5383111216152123554" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SrSnIVErGKI/AAAAAAAAAOg/QPFVPw08afA/s400/2.JPG" style="cursor: pointer; display: block; height: 260px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;img alt="" src="file:///C:/DOCUME%7E1/MOHDAL%7E1/LOCALS%7E1/Temp/moz-screenshot.jpg" /&gt;&lt;br /&gt;Author website can be reach at &lt;a href="http://y0da.cjb.net/"&gt;http://y0da.cjb.net&lt;/a&gt; but it no longer exist I guess. You can try get it from &lt;a href="http://www.google.com.my/#hl=en&amp;amp;safe=off&amp;amp;q=lordpe&amp;amp;meta=&amp;amp;fp=17e9af6b4992e7e2"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-6113914123369873822?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/6113914123369873822/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=6113914123369873822' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6113914123369873822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6113914123369873822'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/09/lordpe-deluxe.html' title='LordPE Deluxe'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_oqd-5f-VZso/SrSlANbMggI/AAAAAAAAAOY/7ahigtrjRq8/s72-c/1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-6701356281092173331</id><published>2004-09-19T11:35:00.006+08:00</published><updated>2010-01-19T18:00:12.903+08:00</updated><title type='text'>Donate</title><content type='html'>&lt;div style="text-align: justify;"&gt;Your donation will help improving our website, software and the quality of product. Every donation will be much appreciated. If you want to make donation with PayPal please use the following form to start donate:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" style="border: 1px solid rgb(0, 0, 0); height: 187px; padding: 5px; width: 171px;"&gt;&lt;tbody&gt;&lt;tr&gt; &lt;td width="145"&gt;&lt;form action="https://www.paypal.com/row/cgi-bin/webscr" method="post" name="_xclick"&gt;&lt;b&gt;Amount&lt;/b&gt;&lt;br /&gt;&lt;div style="margin-bottom: 0pt; margin-top: 0pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0pt; margin-top: 0pt;"&gt;&lt;select name="Amount" size="1"&gt;&lt;option selected="selected" value="1.00"&gt;1.00&lt;/option&gt;&lt;option value="2.00"&gt;2.00&lt;/option&gt;&lt;option value="3.00"&gt;3.00&lt;/option&gt;&lt;option value="4.00"&gt;4.00&lt;/option&gt;&lt;option value="5.00"&gt;5.00&lt;/option&gt;&lt;option value="10.00"&gt;10.00&lt;/option&gt;&lt;option value="15.00"&gt;15.00&lt;/option&gt;&lt;option value="20.00"&gt;20.00&lt;/option&gt;&lt;option value="25.00"&gt;25.00&lt;/option&gt;&lt;option value="30.00"&gt;30.00&lt;/option&gt;&lt;option value="35.00"&gt;35.00&lt;/option&gt;&lt;option value="40.00"&gt;40.00&lt;/option&gt;&lt;option value="45.00"&gt;45.00&lt;/option&gt;&lt;option value="50.00"&gt;50.00&lt;/option&gt;&lt;option value="100.00"&gt;100.00&lt;/option&gt;&lt;option value="200.00"&gt;200.00&lt;/option&gt;&lt;option value="300.00"&gt;300.00&lt;/option&gt;&lt;option value="400.00"&gt;400.00&lt;/option&gt;&lt;option value="500.00"&gt;500.00&lt;/option&gt;&lt;option value="1000.00"&gt;1000.00&lt;/option&gt;&lt;/select&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0pt; margin-top: 0pt;"&gt;&lt;b&gt;Currency&lt;/b&gt; &lt;select name="currency_code" size="1"&gt;&lt;option value="AUD"&gt;Australian Dollar&lt;/option&gt;&lt;option selected="selected" value="USD"&gt;USD&lt;/option&gt;&lt;option value="GBP"&gt;British Pound&lt;/option&gt;&lt;option value="CAD"&gt;Canadian Dollars&lt;/option&gt;&lt;option value="CZK"&gt;Czech Koruna&lt;/option&gt;&lt;option value="DKK"&gt;Danish Kroner&lt;/option&gt;&lt;option value="EUR"&gt;EUR&lt;/option&gt;&lt;option value="HKD"&gt;Hong Kong Dollars&lt;/option&gt;&lt;option value="HUF"&gt;Hungarian Forint&lt;/option&gt;&lt;option value="JPY"&gt;Japanese YEN&lt;/option&gt;&lt;option value="NZD"&gt;New Zealand Dollars&lt;/option&gt;&lt;option value="NOK"&gt;Norwegian Kroner&lt;/option&gt;&lt;option value="PLN"&gt;Polisg Zlotych&lt;/option&gt;&lt;option value="SGD"&gt;Singapore Dollars&lt;/option&gt;&lt;option value="SEK"&gt;Swedish Kronor&lt;/option&gt;&lt;option value="CHF"&gt;Swiss Francs&lt;/option&gt;&lt;/select&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;input alt="Make payments with PayPal - it's fast, free and secure!" border="0" name="submit" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SrRV8GFh3QI/AAAAAAAAANg/mWivfDG9DJI/s400/PayPal.96171224.jpg" type="image" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;/center&gt;If you wish to donate via online banking, sending check or cash deposit, you can bank-in your donation to the following bank account:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_oqd-5f-VZso/SrRdIEJu1eI/AAAAAAAAANo/MaxoqYWoiDw/s1600-h/publicbank.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5383029847749481954" src="http://1.bp.blogspot.com/_oqd-5f-VZso/SrRdIEJu1eI/AAAAAAAAANo/MaxoqYWoiDw/s400/publicbank.jpg" style="cursor: pointer; float: left; height: 44px; margin: 0pt 10px 10px 0pt; width: 200px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Bank Name:&lt;/span&gt; Public Bank Berhad&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Account Holder:&lt;/span&gt; Nur Mohammad Kamil Bin Mohammad Alta&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Account No. :&lt;/span&gt; &lt;span id="main" style="visibility: visible;"&gt;&lt;span id="search" style="visibility: visible;"&gt;4-9575680-16&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_oqd-5f-VZso/SrReZIYlruI/AAAAAAAAANw/TCqSFz8_UM4/s1600-h/CIMB_Bank.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5383031240454942434" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SrReZIYlruI/AAAAAAAAANw/TCqSFz8_UM4/s400/CIMB_Bank.jpg" style="cursor: pointer; float: left; height: 51px; margin: 0pt 10px 10px 0pt; width: 200px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Bank Name:&lt;/span&gt; CIMB Bank&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Account Holder: &lt;/span&gt;Nur Mohammad Kamil Bin Mohammad Alta&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Account No. :&lt;/span&gt; 05100027843526&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_oqd-5f-VZso/SrRe-Y00YKI/AAAAAAAAAN4/NxA6kwCxdDo/s1600-h/BSN.gif" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5383031880523473058" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SrRe-Y00YKI/AAAAAAAAAN4/NxA6kwCxdDo/s400/BSN.gif" style="cursor: pointer; float: left; height: 124px; margin: 0pt 10px 10px 0pt; width: 124px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Bank Name:&lt;/span&gt; Bank Simpanan Nasional (BSN)&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Account Holder:&lt;/span&gt; Nur Mohammad Kamil Bin Mohammad Alta&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Account No. :&lt;/span&gt; 11100-29-84372834-8&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_oqd-5f-VZso/S1WCnJC5D3I/AAAAAAAAAUQ/vJK06P25PgY/s1600-h/maybank_.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_oqd-5f-VZso/S1WCnJC5D3I/AAAAAAAAAUQ/vJK06P25PgY/s320/maybank_.gif" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Bank Name:&lt;/span&gt; Maybank&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Account Holder:&lt;/span&gt; Nur Mohammad Kamil Bin Mohammad Alta&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Account No. :&lt;/span&gt; 164418076737&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Every donation will be much appreciated. Thank you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-6701356281092173331?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6701356281092173331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6701356281092173331'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/09/donate.html' title='Donate'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_oqd-5f-VZso/SrRdIEJu1eI/AAAAAAAAANo/MaxoqYWoiDw/s72-c/publicbank.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-3804062196723836144</id><published>2004-05-29T10:33:00.009+08:00</published><updated>2010-02-10T12:23:13.244+08:00</updated><title type='text'>Submit Sample</title><content type='html'>&lt;div style="text-align: justify;"&gt;Please upload any malware samples which are not yet detected by Portable Antivirus products along with suspicious and other miscellaneous files using the upload form above. If you having problem uploading a files, then try to use a different web browser (Internet Explorer, Opera, etc.).&lt;br /&gt;&lt;br /&gt;&lt;form action="http://gvom.net/data0/uploader.php" enctype="multipart/form-data" method="POST"&gt;&lt;input name="MAX_FILE_SIZE" type="hidden" value="1000000" /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Choose a file to upload: &lt;input name="uploadedfile" type="file" /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;input type="submit" value="Upload File" /&gt;&lt;/div&gt;&lt;/form&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;If you think our scanner has detected a clean file by mistake please select "False positive suspicion" from the drop down menu above. Note that suspicious files and false positives need to be uploaded separately. Please make sure you verified that the latest version will still detect the file and it is not a solved false alarm at this point in time.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Spam Emails:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Please do not submit spam emails to our analysis system. Spam is advertisement which does not contain any malicious content.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-weight: bold;"&gt;Several files at once:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: 100%;"&gt; In case you want to upload several suspicious files at the same time we suggest to use a common archiving software such as WinZIP, WinRAR, PKZip or Arj.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-weight: bold;"&gt;Submit via email:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: 100%;"&gt;Alternatively you can send suspicious files via email to &lt;a href="mailto:alternator99@gmail.com"&gt;&lt;span style="text-decoration: underline;"&gt;alternator99@gmail.com&lt;/span&gt;&lt;/a&gt;. Please make sure that you compress the files using a packer such as WinZIP, WinRAR, PKZip or Arj. Since some email gateways are equipped with antivirus software, you should also give the file(s) a password to prevent them from being unpacked inadvertently. Please make sure that you're using the password "&lt;u&gt;infected&lt;/u&gt;". Please note that false positives have to be uploaded via web interface and marked as such.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Result:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;If the suspicious file contains a new malware which is unknown to us at this point in time we will update our signature database. After that we'll be able to detect and - if technically possible - remove it.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-3804062196723836144?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3804062196723836144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3804062196723836144'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/05/submit-sample.html' title='Submit Sample'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-8445620221315072592</id><published>2004-05-06T20:37:00.004+08:00</published><updated>2009-05-29T15:18:10.066+08:00</updated><title type='text'>Portable Antivirus 1.7 (Coming Soon)</title><content type='html'>Portable Antivirus 1.7 is the next generation of antivirus software and currently in development and will be available and almost finish developing and testing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-8445620221315072592?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/8445620221315072592'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/8445620221315072592'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/05/portable-antivirus-17-coming-soon.html' title='Portable Antivirus 1.7 (Coming Soon)'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-5574077726329128693</id><published>2004-05-06T20:20:00.006+08:00</published><updated>2009-05-11T21:31:56.788+08:00</updated><title type='text'>Portable Antivirus 1.6</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_oqd-5f-VZso/SgGBnyDFrfI/AAAAAAAAALA/8QEua8RNHQs/s1600-h/1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 307px; height: 256px;" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SgGBnyDFrfI/AAAAAAAAALA/8QEua8RNHQs/s400/1.png" alt="" id="BLOGGER_PHOTO_ID_5332685954232987122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;Portable Antivirus 1.6 is another upgraded new version from the previous one 1.5. A small, fast and advanced scanning engine making this antivirus the most people choice from around Asia.&lt;br /&gt;&lt;br /&gt;The new version have many features such as repairing registry with advanced features, heuristics technologies, real-time scanning, can be updated from internet, come with few useful tools, more advanced configurations and the most important is keep it portable and easy to run anywhere when your PCs having problems.&lt;br /&gt;&lt;br /&gt;Portable Antivirus 1.6 is currently in Beta version before releasing it into the new full version that compatible with all Windows platform. Currently, its work almost all Windows NT version including Windows 2000, XP and Vista.&lt;br /&gt;&lt;br /&gt;You can download this version of Portable Antivirus by &lt;a href="http://www.ziddu.com/download/4572996/pavsetup.exe.html"&gt;clicking here&lt;/a&gt;.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-5574077726329128693?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/5574077726329128693'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/5574077726329128693'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/05/portable-antivirus-16.html' title='Portable Antivirus 1.6'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_oqd-5f-VZso/SgGBnyDFrfI/AAAAAAAAALA/8QEua8RNHQs/s72-c/1.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-6878268192432037686</id><published>2004-05-06T20:08:00.007+08:00</published><updated>2009-09-19T18:05:26.971+08:00</updated><title type='text'>Portable Antivirus 1.5</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_oqd-5f-VZso/SgF-gNkvabI/AAAAAAAAAKw/7qOTXEatKq4/s1600-h/pav15.jpg"&gt;&lt;img style="border: medium none ; margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 212px;" src="http://3.bp.blogspot.com/_oqd-5f-VZso/SgF-gNkvabI/AAAAAAAAAKw/7qOTXEatKq4/s400/pav15.jpg" alt="Portable Antivirus 1.5" id="BLOGGER_PHOTO_ID_5332682525648054706" border="0" /&gt;&lt;/a&gt;Portable Antivirus 1.5 is the most popular single executable antivirus that has been downloaded by more than 400,000 copies. This tiny antivirus can scan and remove up to 200 viruses that has been recorded as in-the-wild by most of commercial antivirus. User still can download this software by &lt;a href="http://www.ziddu.com/download/4573039/portableav.exe.html"&gt;clicking here&lt;/a&gt;. Portable Antivirus 1.5 also have a unique function that can repair your registry that has been modified by viruses such as missing Folder Options, Task Manager, Start Menu item an many more. Also, this tiny antivirus only have 290KB of it's size and suitable to fit into your USB Drive even your floppy disk can fit it.&lt;br /&gt;&lt;br /&gt;Portable Antivirus 1.5 does not required to installed on to your PCs. Simply, just download and run the file and start scanning your PC. Small and really portable. For those who still want to use this little antivirus, you &lt;a href="http://www.ziddu.com/download/4573039/portableav.exe.html"&gt;download it here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;NOTE: Some antivirus program detect this tools as a virus or spyware. This is false detection because this small tools has been compressed with UPX utilities. Please disable other antivirus first before using it.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-6878268192432037686?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://portableantivirus.blogspot.com/feeds/6878268192432037686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3608062753818595663&amp;postID=6878268192432037686' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6878268192432037686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/6878268192432037686'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/05/portable-antivirus-15.html' title='Portable Antivirus 1.5'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_oqd-5f-VZso/SgF-gNkvabI/AAAAAAAAAKw/7qOTXEatKq4/s72-c/pav15.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-217184074775973982</id><published>2004-05-03T00:16:00.001+08:00</published><updated>2009-05-11T21:32:22.590+08:00</updated><title type='text'>Manual Update your Portable Antivirus</title><content type='html'>To update your Portable Antivirus virus definition you can do this with a few simple step. Follow this instruction:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. &lt;a href="http://portableantivirus.blogspot.com/2004/05/download.html"&gt;Download the latest updates&lt;/a&gt; of VDEF file and then extract the ZIPped content. The file name should be appeared as 'vdef1.vdef'.&lt;br /&gt;&lt;br /&gt;2. Simply, goto your  Portable Antivirus system tray icon (near the clock). &lt;span style="font-weight: bold;"&gt;Right click&lt;/span&gt; on it and choose &lt;span style="font-weight: bold;"&gt;Updates... &lt;/span&gt;and click on &lt;span style="font-weight: bold;"&gt;Manual Update&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;3. Choose where your VDEF file has been extracted and click &lt;span style="font-weight: bold;"&gt;Open &lt;/span&gt;button and wait until finish message appear.&lt;br /&gt;&lt;br /&gt;4. And you're done updating your Portable Antivirus. You can see the date was change after the update.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-217184074775973982?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/217184074775973982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/217184074775973982'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/05/manual-update-your-portable-antivirus.html' title='Manual Update your Portable Antivirus'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-5338519854615680855</id><published>2004-05-02T22:09:00.032+08:00</published><updated>2009-09-20T22:54:26.647+08:00</updated><title type='text'>Download</title><content type='html'>Here you can download Portable Antivirus software for free. You can choose whether to download the latest version or an old version.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;Portable Antivirus 1.6 Build 421&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img border="0" src="http://img24.imageshack.us/img24/5599/paviconb.gif" /&gt;&amp;nbsp;&lt;a href="http://www.ziddu.com/download/5106328/pavsetup.exe.html"&gt;Download Here from Ziddu.com&lt;/a&gt;&lt;br /&gt;&lt;img border="0" src="http://img24.imageshack.us/img24/5599/paviconb.gif" /&gt;&amp;nbsp;&lt;a href="http://www.easy-share.com/1905597818/pavsetup.exe"&gt;Download Here from EasyShare&lt;/a&gt;&lt;br /&gt;&lt;img border="0" src="http://img24.imageshack.us/img24/5599/paviconb.gif" /&gt;&amp;nbsp;&lt;a href="http://www.mediafire.com/?mmim5zmyz52"&gt;Download Here from MediaFire&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Portable Antivirus 1.6 also available in standalone version which you can download it from &lt;a href="http://www.easy-share.com/1905888544/portableav16b.exe"&gt;here&lt;/a&gt; or &lt;a href="http://www.mediafire.com/file/mmim5zmyz52/portableav16b.exe"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;VDEF Updates (10 August 2009)&lt;/span&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5344218822563299314" src="http://4.bp.blogspot.com/_oqd-5f-VZso/Sip6tEjXf_I/AAAAAAAAAMU/UcxdosWqYsE/s400/new.gif" style="cursor: pointer; height: 10px; width: 27px;" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img border="0" src="http://cimg.sourceforge.net/greycstoration/img/zip.gif" /&gt;&amp;nbsp;&lt;a href="http://www.ziddu.com/download/5995015/vdef1.zip.html"&gt;Download VDEF Updates here! from Ziddu.com&lt;/a&gt;&lt;br /&gt;&lt;img border="0" src="http://cimg.sourceforge.net/greycstoration/img/zip.gif" /&gt;&amp;nbsp;&lt;a href="http://www.easy-share.com/1907289975/vdef1.zip"&gt;Download VDEF Updates here! from EasyShare&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-size: 85%; font-style: italic;"&gt;Note: To update your Portable Antivirus, first extract the VDEF1.zip file and then choose the extracted file to update. To learn more &lt;a href="http://portableantivirus.blogspot.com/2004/05/manual-update-your-portable-antivirus.html"&gt;&lt;span style="font-weight: bold;"&gt;click here&lt;/span&gt;&lt;/a&gt;. Please make sure turn off any Download Manager to make sure the download to &lt;/span&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: verdana; font-style: italic;"&gt;be successful.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;____________________________________________________________&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Portable Antivirus 1.5 (Old version)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;img border="0" src="http://img24.imageshack.us/img24/5599/paviconb.gif" /&gt;&amp;nbsp;&lt;a href="http://www.ziddu.com/download/4573039/portableav.exe.html"&gt;Download Here from Ziddu.com&lt;/a&gt;&lt;br /&gt;&lt;img border="0" src="http://img24.imageshack.us/img24/5599/paviconb.gif" /&gt;&amp;nbsp;&lt;a href="http://www.easy-share.com/1905253882/portableav.exe"&gt;Download Here from EasyShare&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-family: verdana; font-style: italic;"&gt;Note: Portable Antivirus 1.5 has been discontinue their support however you still can use it to remove certain malware.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;____________________________________________________________&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" src="http://img43.imageshack.us/img43/1229/pdf16x16.gif" /&gt;&amp;nbsp;&lt;a href="http://www.ziddu.com/download/4573577/pavdoc.pdf.html"&gt;Download Portable Antivirus 1.6 Help Document&lt;/a&gt; or &lt;a href="http://www.easy-share.com/1905253793/pavdoc.pdf"&gt;Here&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-5338519854615680855?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/5338519854615680855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/5338519854615680855'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/05/download.html' title='Download'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_oqd-5f-VZso/Sip6tEjXf_I/AAAAAAAAAMU/UcxdosWqYsE/s72-c/new.gif' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-3693600457492194808</id><published>2004-05-02T21:52:00.005+08:00</published><updated>2009-09-19T13:06:01.529+08:00</updated><title type='text'>Awards</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;div style="text-align: left;"&gt;Here it is Portable Antivirus has been awarded by a few downloaded host website:&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://www.softpedia.com/progClean/Windows-Portable-Applications-Portable-Antivirus-Clean-69121.html" title="100% CLEAN Certified by Softpedia"&gt;&lt;img src="http://www.softpedia.com/base_img/softpedia_clean_award_f.gif" border="0" height="116" width="170" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;Softpedia guarantees that &lt;b&gt;Portable Antivirus 1.6 Beta&lt;/b&gt; is &lt;b style="color: rgb(0, 88, 187);"&gt;100% CLEAN&lt;/b&gt;, which means it does not contain any form of malware, including spyware, viruses, trojans and backdoors.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-3693600457492194808?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3693600457492194808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/3693600457492194808'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/05/sponsor.html' title='Awards'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-2227475190795945963</id><published>2004-05-02T21:49:00.005+08:00</published><updated>2009-06-06T21:59:01.213+08:00</updated><title type='text'>About</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_oqd-5f-VZso/Sip2FqD-_2I/AAAAAAAAAMM/R6qjU5puXEk/s1600-h/abt.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 212px; height: 176px;" src="http://1.bp.blogspot.com/_oqd-5f-VZso/Sip2FqD-_2I/AAAAAAAAAMM/R6qjU5puXEk/s400/abt.jpg" alt="" id="BLOGGER_PHOTO_ID_5344213747390938978" border="0" /&gt;&lt;/a&gt;Portable Antivirus is software to help people maintaining their Windows system from and after being infected by malware in one click of button. Portable Antivirus was built to remove viruses without need to restart their Windows after scan and repairing is done. With a Portable concept, this antivirus software can be easily distribute to any of removable drive such as Flash Drive, Memory stick, Portable Hard drive and so on.&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Portable Antivirus can detect several of viruses including worm, Trojan, spy ware, ad ware and many more. Portable Antivirus cannot detect such as old 80’s viruses. Thus, the virus is almost impossible to run on NT-based system such as Windows XP and Vista. Portable Antivirus also has its own technology to detect future viruses. Like other commercial antivirus software, Heuristic technology is a must on every antivirus industry.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Information About Portable Antivirus Generation&lt;/span&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2004/05/portable-antivirus-17-coming-soon.html"&gt;&lt;br /&gt;Portable Antivirus 1.7&lt;/a&gt; (Coming Soon)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2004/05/portable-antivirus-16.html"&gt;Portable Antivirus 1.6&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://portableantivirus.blogspot.com/2004/05/portable-antivirus-15.html"&gt;Portable Antivirus 1.5&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-2227475190795945963?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/2227475190795945963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/2227475190795945963'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2004/05/about.html' title='About'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_oqd-5f-VZso/Sip2FqD-_2I/AAAAAAAAAMM/R6qjU5puXEk/s72-c/abt.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-3608062753818595663.post-547641339698453151</id><published>2004-05-02T21:12:00.008+08:00</published><updated>2009-11-13T10:35:18.081+08:00</updated><title type='text'>Contact</title><content type='html'>&lt;img alt="" border="0" src="http://3.bp.blogspot.com/_oqd-5f-VZso/ScM6jJ6BtLI/AAAAAAAAAH8/-ZG6SK0cQsg/s400/contact.jpg" style="cursor: pointer; float: left; height: 55px; margin: 0pt 10px 10px 0pt; width: 44px;" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You can contact the author directly at:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_oqd-5f-VZso/SrRiyjzDNPI/AAAAAAAAAOQ/IRKQTNFTzBg/s1600-h/GMail-SmallIcon.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5383036075356927218" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SrRiyjzDNPI/AAAAAAAAAOQ/IRKQTNFTzBg/s400/GMail-SmallIcon.png" style="cursor: pointer; float: left; height: 24px; margin: 0pt 10px 10px 0pt; width: 24px;" /&gt;&lt;/a&gt;&lt;a href="mailto:alternator99@gmail.com"&gt;alternator99@gmail.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you want to reach the author via Yahoo! Messenger add the following name:&lt;br /&gt;&lt;br /&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5383034870134763778" src="http://4.bp.blogspot.com/_oqd-5f-VZso/SrRhsZ_scQI/AAAAAAAAAOA/uAILThgSrsk/s400/yim_v6_icon.gif" style="cursor: pointer; float: left; height: 24px; margin: 0pt 10px 10px 0pt; width: 24px;" /&gt; ID: &lt;a href="ymsgr:sendIM?alternat0r"&gt;alternat0r&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;or just leave a message at the shoutbox.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3608062753818595663-547641339698453151?l=portableantivirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/547641339698453151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3608062753818595663/posts/default/547641339698453151'/><link rel='alternate' type='text/html' href='http://portableantivirus.blogspot.com/2009/05/contact.html' title='Contact'/><author><name>Kamil</name><uri>http://www.blogger.com/profile/09128514808603887073</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://2.bp.blogspot.com/_oqd-5f-VZso/SUOEPzzVf0I/AAAAAAAAACs/0oNv6zQRw4g/S220/alternator.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_oqd-5f-VZso/ScM6jJ6BtLI/AAAAAAAAAH8/-ZG6SK0cQsg/s72-c/contact.jpg' height='72' width='72'/></entry></feed>
