<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>security blog &#187; Malware/Malware Removal</title>
	<atom:link href="http://elamb.org/category/malwaremalware-removal/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>don&#039;t be sheeple</description>
	<lastBuildDate>Fri, 03 Sep 2010 03:27:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Star Trek Based Anti-Virus: Klingon Anti-Virus (KAV)</title>
		<link>http://elamb.org/star-trek-based-anti-virus-klingon-anti-virus-kav/</link>
		<comments>http://elamb.org/star-trek-based-anti-virus-klingon-anti-virus-kav/#comments</comments>
		<pubDate>Sat, 23 May 2009 02:43:08 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Trojans]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[security]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1709</guid>
		<description><![CDATA[Sophos put out a Star Trek Based Anti-Virus.  Pure genius.  The downloads for it are off the charts.  Its free.  Its fun and its increbibly smart marketing.  Like many brilliant ideas it was an accident.  Well, it was put out as an accident.  But I for one am [...]]]></description>
			<content:encoded><![CDATA[<p>Sophos put out a <a href="http://www.sophos.com/klingon-anti-virus/">Star Trek Based Anti-Virus</a>.  Pure genius.  The downloads for it are off the charts.  Its free.  Its fun and its increbibly smart marketing.  Like many brilliant ideas it was an accident.  Well, it was put out as an accident.  But I for one am glad it was.    </p>
<p><object width="250" height="250"><param name="movie" value="http://www.youtube.com/v/B6XD2zGtvAM&#038;rel=0&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en&#038;feature=player_embedded&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/B6XD2zGtvAM&#038;rel=0&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en&#038;feature=player_embedded&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="250" height="250"></embed></object></p>
<p>The Star Trek movie was awesome by the way!  Great move for a franchise that deserves a larger commercial audience.  I&#8217;m anxious for more movies and shows.   </p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1709&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/star-trek-based-anti-virus-klingon-anti-virus-kav/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>derad: Malicious &#8220;Security Warning&#8221; Popups</title>
		<link>http://elamb.org/derad-malicious-security-warning-popups/</link>
		<comments>http://elamb.org/derad-malicious-security-warning-popups/#comments</comments>
		<pubDate>Sun, 02 Nov 2008 03:14:37 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[derad]]></category>
		<category><![CDATA[malware removal]]></category>
		<category><![CDATA[scamware]]></category>
		<category><![CDATA[scumware]]></category>
		<category><![CDATA[spyware]]></category>

	<!-- AutoMeta Start -->
	<category>radcliff</category>
	<category>debra</category>
	<category>fellow</category>
	<category>blogger</category>
	<category>advice</category>
	<category>quick</category>
	<category>good</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/derad-malicious-security-warning-popups/</guid>
		<description><![CDATA[Here is some good quick advice from my fellow blogger Debra Radcliff:
Panda Security reports increased spread and success of popup “security warnings.” These warnings popup when people surf the Web and hit a malicious or infected Website, and keep flashing their warnings until the user goes to the link, at which time they get infected. [...]]]></description>
			<content:encoded><![CDATA[<p>Here is some good quick advice from my fellow blogger <a href="http://derad.typepad.com/">Debra Radcliff</a>:</p>
<blockquote><p>Panda Security reports increased spread and success of popup “security warnings.” These warnings popup when people surf the Web and hit a malicious or infected Website, and keep flashing their warnings until the user goes to the link, at which time they get infected. </p>
<p>No legitimate security company would do this to a computer, so don’t click the link. Instead, disconnect from the Internet, clear your browser history and restart your computer.  If your browser is still flashing warnings, the system will need to be disinfected through anti-virus or a computer restoration service. </p></blockquote>
<p>Usually these false security warnings are a symptom of something much worse.  I&#8217;ve had some that will actually not allow you to do much of anything but click on the link in their fake pop-up.  What I did was a <a href="http://elamb.org/hacked/removemalware.htm">system restore</a>, but you can also boot in Safe mode and attempt to clean the system.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1538&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/derad-malicious-security-warning-popups/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Ed Skoudis lists the Top 5 Worst Attacks of 1998 &#8211; 2002</title>
		<link>http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/</link>
		<comments>http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/#comments</comments>
		<pubDate>Wed, 11 Jun 2008 00:04:15 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Trojans]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[code red]]></category>
		<category><![CDATA[ed skoudis]]></category>
		<category><![CDATA[i love you]]></category>
		<category><![CDATA[melissa]]></category>
		<category><![CDATA[nimda]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>skoudis</category>
	<category>nimda</category>
	<category>lessons</category>
	<category>1998</category>
	<category>iis</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/</guid>
		<description><![CDATA[That which does not kill us makes us stronger.
-Friedrich Nietzsche 
In the November 2002, Information Security Magazine article, Infosec’s Worst NightMares, Ed Skoudis lists the Top 5 Worst Attacks of 1998 – 2002.  Mr. Skoudis is the founders of Intelguardians Network Intelligence, LLC and is a handler of the very popular Internet Storm Center.
Mr. [...]]]></description>
			<content:encoded><![CDATA[<p><em>That which does not kill us makes us stronger.</em><br />
-Friedrich Nietzsche </p>
<p>In the November 2002, Information Security Magazine article, Infosec’s Worst NightMares, Ed Skoudis lists the Top 5 Worst Attacks of 1998 – 2002.  Mr. Skoudis is the founders of Intelguardians Network Intelligence, LLC and is a handler of the very popular Internet Storm Center.</p>
<p>Mr. Skoudis mentions that the Top five major destructive attacks of 1998 – 2002 made many industries “battle-tested” and more likely to be proactive rather than reactive.  The 5 year Worst Skoudis list is based on exploits that shook our very faith in the Internet and security of e-commerce. </p>
<p><strong>1.  <a href="http://en.wikipedia.org/wiki/Code_Red_worm">Code Red (2001)</a></strong>.  July 13 2001, the worm attacked Microsoft IIS systems.  By 19 July 2001, the worm had affected over 350,000 systems.  SANS and Honeynet Project set up honey pots to capture the worm.  But E-eye Digital Security Programmers did the most intense research on the worm and also named it.   The worm exploited a vulnerability in the indexing software distributed with IIS, described in Microsoft’s MS01-033 patch.  It was a buffer overflow attack. Some of the lessons learned:  Keep systems patched, use of honey pots to capture malware, coordinated response helps to contain worms.  </p>
<p><strong>2.  Nimda (2001). </strong> Shortly after 9/11, the Nimda worm was unleashed.  It caused more damage financially than Code Red.  There were rumors that it was China that released it to hurt the US further, but this is unlikely due to the nature of Nimda. </p>
<blockquote><p>
While it was bad, it had the appearance of a being written by a determined amateur, not a nation-state that spends $1 Billion annually on cyberwarfare capabilities. – Skoudis.  </p></blockquote>
<p>Nimda affected Windows 95, 98, Me, NT, or 2000 and servers running Windows NT and 2000.  It was so affective because it attacked IIS, e-mail, browsers and network shares.  This multi dimensional attack method could mark a trend in future cyberfare.</p>
<p><em>Lessons Learned: The importance of an incident response capability, disabling arbitrary scripts in e-mail and browsers.</em></p>
<p><strong>3.  Melissa (1999) &#038; LoveLetter (2000). </strong> Both of these exploited malware through e-mail propagation.  Melissa used Microsoft Word Macro virus and LoveLetter (I Love You Virus).   The worm harvested the victims address book to forward itself to more victims which killed a lot of email servers.  Lessons Learned:  Many companies got serious about implementing anti-virus applications throughout the network.<br />
<strong><br />
4.  Distributed Denial-of-Service (DdoS) attacks (2000)</strong>.  After all the panic of pre-Y2K, a completely new and unexpected storm hit major sites: Yahoo!, Amazon, CNN, E*Trade ZDNet and eBay.  All by a single child hacker nicked named Mafiaboy.  He had spread zombie flooding agents to hundreds of machines around the world and used them to attack sites with billions of useless packets.  <em>Lessons Learned: employ anti-spoofing filters.</em><br />
<strong><br />
5.  Remote Control Trojan Horse Backdoors (1998 – 2000)</strong>.  In 1998, the Cult of the Dead Cow hackers group created the Trojan, Back Orifice which initially targeted Windows NT/9x.    The tool allowed unskilled attackers to attack any vulnerable system.  It also marked the rise of the “script kiddies” and produced a bunch of spin offs such as Subseven, Netbus and Hack-a-Tack.  </p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1149&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Malware Alarm</title>
		<link>http://elamb.org/malware-alarm/</link>
		<comments>http://elamb.org/malware-alarm/#comments</comments>
		<pubDate>Sat, 23 Feb 2008 05:28:55 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[I got hacked]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Trojans]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[malware alarm]]></category>
		<category><![CDATA[ps guard]]></category>
		<category><![CDATA[remove malware]]></category>
		<category><![CDATA[spy sheriff]]></category>

	<!-- AutoMeta Start -->
	<category>alarm</category>
	<category>restore</category>
	<category>useless</category>
	<category>malware</category>
	<category>mode”</category>
	<category>“safe</category>
	<category>minimized</category>
	<category>usable</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/malware-alarm/</guid>
		<description><![CDATA[A friend of mine wanted me to do some work on her computer, but when I fired up the computer all I saw was Malware Alarm.
The computer was really slow and essentially un-usable.  Malware alarm, I noticed, looks a lot like the scamware PS Guard and SpySheriff.  These are applications that pretend to [...]]]></description>
			<content:encoded><![CDATA[<p>A friend of mine wanted me to do some work on her computer, but when I fired up the computer all I saw was Malware Alarm.</p>
<p>The computer was really slow and essentially un-usable.  Malware alarm, I noticed, looks a lot like the scamware PS Guard and SpySheriff.  These are applications that pretend to be anti-virus, anti-spam software that actually infect your system with spyware, mass-mailers, and backdoors into your system.  This type of the malware is known as a trojan.  As usual any attempts to shut this application down or minimized it are useless because even if you do manage to get anything else up, it will eat up so much system resources (CPU, memory, bandwidth) that the computer itself is close to useless.  It you delete it in normal mode and miss a part of it, it will regenerate itself like a hydra.</p>
<p>After looking at the Task Manager (which took 20 minutes or so), I decided to reboot in “safe mode”.  Unless your system has something like a Rootkit (malware that replaces the main component of your operating system) Safe Mode only turns what is needed and nothing else.  I used system restore to remove Malware Alarm.  And Spybot Search and destroy/Adaware to remove everything else.</p>
<p>System Restore should be used first because it is easiest and does require any additional software.  </p>
<p>1)  Reboot in Safe mode: Restart system, hit F8, select “Safe Mode”</p>
<p>2)  Proceed in Safemode: When prompted (as in the picture above) Select “NO”</p>
<p>3)  Restore Wizard: Select a date prior to when you recieved the malware (system restore does not delete newly downloaded files, only new changes in the registry)</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1057&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/malware-alarm/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>What is W32 Myzor?</title>
		<link>http://elamb.org/what-is-w32-myzor/</link>
		<comments>http://elamb.org/what-is-w32-myzor/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 07:10:40 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[w32]]></category>

	<!-- AutoMeta Start -->
	<category>myzor</category>
	<category>w32</category>
	<category>infected</category>
	<category>infected</category>
	<category>shitty</category>
	<category>balloon</category>
	<category>appliations</category>
	<category>emailers</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/what-is-w32-myzor/</guid>
		<description><![CDATA[W32 Myzor is a part of a family of &#8220;Scamware&#8221;. These are trojans that pose as anti-virus/anti-spyware appliations that actually install malware on to your computer (viruses, worms, mass emailers). They attempt to gather your personal information and scare you into purchasing some shitty malicious software (no offense to adds running on this site). 
W32.Myzor.FK@yf [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://elamb.org/hacked/images/biohaz.jpg" alt="malware" />W32 Myzor is a part of a family of &#8220;Scamware&#8221;. These are trojans that pose as anti-virus/anti-spyware appliations that actually install malware on to your computer (viruses, worms, mass emailers). They attempt to gather your personal information and scare you into purchasing some shitty malicious software (no offense to adds running on this site). </p>
<p>W32.Myzor.FK@yf virus. The warning are fake. Your system probably is infected but it is infected because a myzor variant put it there. The balloon about &#8220;You computer is infected&#8221;, is not real.</p>
<p>go to the following for more:</p>
<blockquote><p>
<a href="http://elamb.org/hacked/w32-myzor.html">w32 myzor</a><br />
<a href="http://elamb.org/hacked/w32-myzor-fk.html">w32 myzor fk</a><br />
<a href="http://elamb.org/hacked/w32-myzor-fk-yf.html">w32 myzor fk yf</a></p></blockquote>
<img src="http://elamb.org/?ak_action=api_record_view&id=1000&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/what-is-w32-myzor/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>w32 flash almod</title>
		<link>http://elamb.org/w32-flash-almod/</link>
		<comments>http://elamb.org/w32-flash-almod/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 03:39:52 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[w32]]></category>

	<!-- AutoMeta Start -->
	<category>almod</category>
	<category>alemod</category>
	<category>w32</category>
	<category>flash</category>
	<category>pcgeeks</category>
	<category>commentcomarche</category>
	<category>hijackthis</category>
	<category>potential</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/w32-flash-almod/</guid>
		<description><![CDATA[&#8220;w32 flash almod&#8221; If you are looking for W32/Alemod here are some links to remove this potential virus:
- PCGeeks &#8211; W32/Alemod 
- CommentComarche &#8211; Hijackthis files
Tags: w32, alemod, virus]]></description>
			<content:encoded><![CDATA[<p>&#8220;<a href="http://elamb.org/hacked/w32-flash-almod.htm">w32 flash almod</a>&#8221; If you are looking for W32/Alemod here are some links to remove this potential virus:</p>
<p>- PCGeeks &#8211; W32/Alemod </p>
<p>- CommentComarche &#8211; Hijackthis files</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/alemod" title="See the Technorati tag page for 'alemod'." rel="tag">alemod</a>, <a href="http://technorati.com/tag/virus" title="See the Technorati tag page for 'virus'." rel="tag">virus</a></p><img src="http://elamb.org/?ak_action=api_record_view&id=998&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/w32-flash-almod/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>w32 serflike a</title>
		<link>http://elamb.org/w32-serflike-a/</link>
		<comments>http://elamb.org/w32-serflike-a/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 03:33:40 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[w32]]></category>

	<!-- AutoMeta Start -->
	<category>serflike</category>
	<category>autoruns</category>
	<category>w32</category>
	<category>startup</category>
	<category>locations</category>
	<category>auto</category>
	<category>quot</category>
	<category>notifications</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/w32-serflike-a/</guid>
		<description><![CDATA[I have never heard of any virus called &#34;w32 serflike a&#34;, however if you believe you have this or any other malware a good place to start investigating this is to use Autoruns
Autoruns is the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system [...]]]></description>
			<content:encoded><![CDATA[<p>I have never heard of any virus called &quot;w32 serflike a&quot;, however if you believe you have this or any other malware a good place to start investigating this is to use <a href="http://www.microsoft.com/technet/sysinternals/Utilities/AutoRuns.mspx">Autoruns</a></p>
<p>Autoruns is the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them. These programs include ones in your startup folder, Run, RunOnce, and other Registry keys. You can configure Autoruns to show other locations, including Explorer shell extensions, toolbars, browser helper objects, Winlogon notifications, auto-start services, and much more. Autoruns goes way beyond the MSConfig utility bundled with Windows Me and XP.</p>
<p>More on <a href="http://elamb.org/hacked/w32-serflike-a.htm">w32 serflike a</a></p>
<p class="tags">Tags: <a href="http://technorati.com/tag/w32-serflike-a.htm" title="See the Technorati tag page for 'w32-serflike-a.htm'." rel="tag">w32-serflike-a.htm</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/serflike" title="See the Technorati tag page for 'serflike'." rel="tag">serflike</a>, <a href="http://technorati.com/tag/autoruns" title="See the Technorati tag page for 'autoruns'." rel="tag">autoruns</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a>, <a href="http://technorati.com/tag/" title="See the Technorati tag page for ''." rel="tag"></a></p><img src="http://elamb.org/?ak_action=api_record_view&id=997&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/w32-serflike-a/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>virus w32 2fsober.k 40mm</title>
		<link>http://elamb.org/virus-w32-2fsoberk-40mm/</link>
		<comments>http://elamb.org/virus-w32-2fsoberk-40mm/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 03:25:44 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[w32]]></category>

	<!-- AutoMeta Start -->
	<category>2fsober</category>
	<category>40mm</category>
	<category>w32</category>
	<category>sober</category>
	<category>mailing</category>
	<category>mass</category>
	<category>bat</category>
	<category>varies</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/virus-w32-2fsoberk-40mm/</guid>
		<description><![CDATA[You typed in w32/sober.@mm
You are looking for information on the W32.Sober@mm. W32 indicates that this malware affects Windows 32 systems. Sober is the family of malware it belongs to and “mm” stands for mass-mailing. The W32.Sober@mm virus is actually a mass-mailing worm. It uses a SMTP engine to spread itself. The subject of the email [...]]]></description>
			<content:encoded><![CDATA[<p>You typed in w32/sober.@mm</p>
<p>You are looking for information on the W32.Sober@mm. W32 indicates that this malware affects Windows 32 systems. Sober is the family of malware it belongs to and “mm” stands for mass-mailing. The W32.Sober@mm virus is actually a mass-mailing worm. It uses a SMTP engine to spread itself. The subject of the email is in English or German. The name of the email attachment varies, and it will have a .bat, .com, .exe, .pif, or .scr file extension. It is written in the Visual Basic programming language and is compressed with UPX. W32.Sober@mm may display the fake error message &#8220;File not complete!&#8221; </p>
<p>More on <a href="http://elamb.org/hacked/virus-w32-2fsober-k-40mm.htm">virus w32 2fsober.k 40mm</a></p>
<p class="tags">Tags: <a href="http://technorati.com/tag/virus" title="See the Technorati tag page for 'virus'." rel="tag">virus</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/2fsober.k" title="See the Technorati tag page for '2fsober.k'." rel="tag">2fsober.k</a>, <a href="http://technorati.com/tag/40mm" title="See the Technorati tag page for '40mm'." rel="tag">40mm</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a>, <a href="http://technorati.com/tag/sober" title="See the Technorati tag page for 'sober'." rel="tag">sober</a>, <a href="http://technorati.com/tag/remove" title="See the Technorati tag page for 'remove'." rel="tag">remove</a></p><img src="http://elamb.org/?ak_action=api_record_view&id=996&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/virus-w32-2fsoberk-40mm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>recuperar informacion malograda por w32 pawur</title>
		<link>http://elamb.org/recuperar-informacion-malograda-por-w32-pawur/</link>
		<comments>http://elamb.org/recuperar-informacion-malograda-por-w32-pawur/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 01:15:57 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>pawur</category>
	<category>win32</category>
	<category>anzae</category>
	<category>w32</category>
	<category>tasin</category>
	<category>nombre</category>
	<category>inzae</category>
	<category>worm</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/recuperar-informacion-malograda-por-w32-pawur/</guid>
		<description><![CDATA[information on Riparare file dnsrslve da w32 spybot worm
W32@pawur is a worm. More information on pawur
Nombre:&#160;W32/Pawur.A
      Nombre NOD32: Win32/Pawur.A
      Tipo: Gusano de Internet
      Alias:&#160;Pawur.A,  Tasin.A, Anzae, I-Worm.Pawur.A, I-Worm.Pawur.a, I-Worm.VB.w,  I-Worm/Pawur.A, NewHeur_PE, W32.Inzae.A, W32/Anzae.Worm,  W32/Tasin.A.worm, Win32/Inzae.A.Dropper, Win32/Pawur.A, WORM_ANZAE.A, [...]]]></description>
			<content:encoded><![CDATA[<p>information on <a href="http://http://elamb.org/hacked/recuperar-informacion-malograda-por-w32-pawur.htm">Riparare file dnsrslve da w32 spybot worm</a></p>
<p>W32@pawur is a worm. <a href="http://www.vsantivirus.com/pawur-a.htm">More information on pawur</a></p>
<p><strong>Nombre:</strong>&nbsp;W32/Pawur.A<br />
      <strong>Nombre NOD32:</strong> Win32/Pawur.A<br />
      <strong>Tipo:</strong> Gusano de Internet<br />
      <strong>Alias:</strong>&nbsp;Pawur.A,  Tasin.A, Anzae, I-Worm.Pawur.A, I-Worm.Pawur.a, I-Worm.VB.w,  I-Worm/Pawur.A, NewHeur_PE, W32.Inzae.A, W32/Anzae.Worm,  W32/Tasin.A.worm, Win32/Inzae.A.Dropper, Win32/Pawur.A, WORM_ANZAE.A,  W32/Anzae-A, W32/Insae.A@mm, Email-Worm.Win32.Pawur.a, Win32.HLLM.Pawur<br />
      <strong>Fecha:</strong>&nbsp;22/nov/04<br />
      <strong>Plataforma:</strong> Windows 32-bit<br />
      <strong>Tama&ntilde;o:</strong>&nbsp;49,331 bytes</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/recuperar" title="See the Technorati tag page for 'recuperar'." rel="tag">recuperar</a>, <a href="http://technorati.com/tag/informacion" title="See the Technorati tag page for 'informacion'." rel="tag">informacion</a>, <a href="http://technorati.com/tag/malograda" title="See the Technorati tag page for 'malograda'." rel="tag">malograda</a>, <a href="http://technorati.com/tag/por" title="See the Technorati tag page for 'por'." rel="tag">por</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/pawur" title="See the Technorati tag page for 'pawur'." rel="tag">pawur</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a>, <a href="http://technorati.com/tag/worm" title="See the Technorati tag page for 'worm'." rel="tag">worm</a>, <a href="http://technorati.com/tag/malograda" title="See the Technorati tag page for 'malograda'." rel="tag">malograda</a>, <a href="http://technorati.com/tag/" title="See the Technorati tag page for ''." rel="tag"></a></p><img src="http://elamb.org/?ak_action=api_record_view&id=994&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/recuperar-informacion-malograda-por-w32-pawur/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netdrvr Ext W32 Spybot Worm</title>
		<link>http://elamb.org/netdrvr-ext-w32-spybot-worm/</link>
		<comments>http://elamb.org/netdrvr-ext-w32-spybot-worm/#comments</comments>
		<pubDate>Mon, 26 Nov 2007 06:38:11 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>netdrvr</category>
	<category>ext</category>
	<category>ext</category>
	<category>spybot</category>
	<category>w32</category>
	<category>worm</category>
	<category>exe</category>
	<category>exe</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/netdrvr-ext-w32-spybot-worm/</guid>
		<description><![CDATA[Those looking for &#8220;Netdrvr Ext W32 Spybot Worm&#8221;
You typed &#8220;Netdrvr Ext&#8221; Did you mean &#8220;netdrvr.exe&#8221;? 
If you meant &#8220;netdrvr.exe&#8221; then you definitely have malware. More than likely you have a virus running in a critical system folder of Windows: C:\Windows\System32\netdrvr.exe. This virus looks like it might be a device driver (Network DRV) but it is [...]]]></description>
			<content:encoded><![CDATA[<p>Those looking for &#8220;<a href="http://elamb.org/hacked/netdrvr-ext-w32-spybot-worm.htm">Netdrvr Ext W32 Spybot Worm</a>&#8221;</p>
<p>You typed &#8220;Netdrvr Ext&#8221; Did you mean &#8220;netdrvr.exe&#8221;? </p>
<p>If you meant &#8220;<a href="http://elamb.org/hacked/netdrvr-ext-w32-spybot-worm.htm">netdrvr.exe</a>&#8221; then you definitely have malware. More than likely you have a virus running in a critical system folder of Windows: C:\Windows\System32\netdrvr.exe. This virus looks like it might be a device driver (Network DRV) but it is like a cancer to your system resources and privacy.</p>
<p>This virus can be removed with free tools such as Adaware, HijackThis or Microsoft&#8217;s <a href="http://elamb.org/hacked/netdrvr-ext-w32-spybot-worm.htm">Autoruns</a> (recommended).</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/netdrvr" title="See the Technorati tag page for 'netdrvr'." rel="tag">netdrvr</a>, <a href="http://technorati.com/tag/ext" title="See the Technorati tag page for 'ext'." rel="tag">ext</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/spybot" title="See the Technorati tag page for 'spybot'." rel="tag">spybot</a>, <a href="http://technorati.com/tag/worm" title="See the Technorati tag page for 'worm'." rel="tag">worm</a>, <a href="http://technorati.com/tag/virus" title="See the Technorati tag page for 'virus'." rel="tag">virus</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a></p><img src="http://elamb.org/?ak_action=api_record_view&id=991&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/netdrvr-ext-w32-spybot-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
