<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; Malware/Virus</title>
	<atom:link href="http://elamb.org/category/malwarevirus/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>what porn sites are virus free</title>
		<link>http://elamb.org/what-porn-sites-are-virus-free/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-porn-sites-are-virus-free</link>
		<comments>http://elamb.org/what-porn-sites-are-virus-free/#comments</comments>
		<pubDate>Sat, 27 Aug 2011 07:10:51 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Trojans]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Super GEEK]]></category>

	<!-- AutoMeta Start -->
	<category>porn</category>
	<category>billions</category>
	<category>virus</category>
	<category>virus</category>
	<category>sites</category>
	<category>xhamster</category>
	<category>uprising</category>
	<category>xvideos</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3489</guid>
		<description><![CDATA[I have been trying to avoid this subject for quite sometime. Porn is given some sort of false taboo label. Its black labeled and looked down upon but somehow the porn industry manages to make billions and billions of dollars &#8230; <a href="http://elamb.org/what-porn-sites-are-virus-free/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I have been trying to avoid this subject for quite sometime.  </p>
<p>Porn is given some sort of false taboo label.  Its black labeled and looked down upon but somehow the porn industry manages to make billions and billions of dollars internationally.  </p>
<p>Moral dilemma aside, porn sites have been given a very bad rap due to the huge amount of virus&#8217; put out by malware sites.  Lately there have been an uprising of really good virus free porn sites.  </p>
<p>And here are just a few:</p>
<blockquote><p>xvideos<br />
xhamster<br />
redtube<br />
youporn<br />
pornhub<br />
youjizz</p>
<p>*all .com</p>
</blockquote>
<p>These are free sites.  No membership necessary.  And, equally important, they are virus free.  These sites make money on the ADs.<br />
My one complaint about them is the pop-under promoting their live cam sites.  I am HATE pop-unders.  But they are harmless on the sites listed.  They have to make money some how.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/what-porn-sites-are-virus-free/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>What is Autorun.inf?</title>
		<link>http://elamb.org/what-is-autorun-inf/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-is-autorun-inf</link>
		<comments>http://elamb.org/what-is-autorun-inf/#comments</comments>
		<pubDate>Wed, 23 Feb 2011 23:00:34 +0000</pubDate>
		<dc:creator>brenz</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Computer Security/Home Computer Security]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[I got hacked]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Trojans]]></category>
		<category><![CDATA[Malware/Virus]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3158</guid>
		<description><![CDATA[What is AutoRun.inf? What exactly is an autorun.inf? Is it a virus or just a file that needed by other application in our computer to run? Have you ever gotten alerted by your system anti-virus application that autorun.inf was detected &#8230; <a href="http://elamb.org/what-is-autorun-inf/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>What is AutoRun.inf?<br />
	What exactly is an autorun.inf? Is it a virus or just a file that needed by other application in our computer to run? Have you ever gotten alerted by your system anti-virus application that autorun.inf was detected as a threat to your computer? </p>
<p>AutoRun.inf is a primary instruction file associated with Autorun function. Autorun.inf is just a simple text-based configuration file that tells the operating system which executable to start or which icon to use. In other words, Autorun.inf simply tells the operating system how to deal on the programs or executable files and how the operating will treat the contents of a CD or any removable disks that is plug to your computer. </p>
<p>Autorun.inf is not a malware, but a virus might use autorun.inf to get access to your computer programs and files. Common virus like bacalid, ravmon.exe and even Trojan virus hides in autorun.inf to easily spread to your computer.  These viruses save themselves in the root directory of the infected hard disks and will run themselves every time you double click the drive. Usually if a USB stick or a CD was infected by a virus, once it was plugged to your computer the device automatically runs itself especially with the device where autorun was enabled. </p>
<p>If autorun.inf was detected by your anti-virus as a threat to your computer but not yet tried to make an action then here are some tips to remove autorun.inf which are infected by virus.</p>
<p>You can disable autorun.inf for all drives by configuring the registry of your computer.  First you need to open the registry by typing regedit.exe to the command prompt or you may execute it in run. Then look for this registry: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer<br />
Double-click the NoDriveAutorun DWORD entry and type the value HEX: FF (255 in Decimal). (If the NoDriveAutorun does not exists, you can create it by right-clicking the right side area of the regedit window, then click New-&gt;DWord Value -&gt; type NoDriveAutorun) Close the registry and restart the computer. This procedure will disable all the autorun for all drives of your computer and at least will prevent the autorun function of infected USB drives or CDs and avoid the infection of viruses like the Bacalid and RavMon.exe.</p>
<p>Another procedure to disable or delete autorun.inf that has been infected by virus is by using the command prompt, type cd\ then press enter. You may type the letter of your USB drive or CD drive, for example F: then press enter. Type this attrib –h –r –s autorun.inf then press enter, type del autorun.inf.That’s the easiest way to avoid spreading virus from your computer especially using sutorun.inf. If you have any questions, you can comment on this post, thank you!</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/what-is-autorun-inf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Star Trek Based Anti-Virus: Klingon Anti-Virus (KAV)</title>
		<link>http://elamb.org/star-trek-based-anti-virus-klingon-anti-virus-kav/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=star-trek-based-anti-virus-klingon-anti-virus-kav</link>
		<comments>http://elamb.org/star-trek-based-anti-virus-klingon-anti-virus-kav/#comments</comments>
		<pubDate>Sat, 23 May 2009 02:43:08 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Trojans]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[security]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1709</guid>
		<description><![CDATA[Sophos put out a Star Trek Based Anti-Virus. Pure genius. The downloads for it are off the charts. Its free. Its fun and its increbibly smart marketing. Like many brilliant ideas it was an accident. Well, it was put out &#8230; <a href="http://elamb.org/star-trek-based-anti-virus-klingon-anti-virus-kav/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Sophos put out a <a href="http://www.sophos.com/klingon-anti-virus/">Star Trek Based Anti-Virus</a>.  Pure genius.  The downloads for it are off the charts.  Its free.  Its fun and its increbibly smart marketing.  Like many brilliant ideas it was an accident.  Well, it was put out as an accident.  But I for one am glad it was.    </p>
<p><object width="250" height="250"><param name="movie" value="http://www.youtube.com/v/B6XD2zGtvAM&#038;rel=0&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en&#038;feature=player_embedded&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/B6XD2zGtvAM&#038;rel=0&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en&#038;feature=player_embedded&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="250" height="250"></embed></object></p>
<p>The Star Trek movie was awesome by the way!  Great move for a franchise that deserves a larger commercial audience.  I&#8217;m anxious for more movies and shows.   </p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/star-trek-based-anti-virus-klingon-anti-virus-kav/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Osama Hanged (virus)</title>
		<link>http://elamb.org/osama-hanged-virus/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=osama-hanged-virus</link>
		<comments>http://elamb.org/osama-hanged-virus/#comments</comments>
		<pubDate>Fri, 03 Oct 2008 06:24:22 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Trojans]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[hanged]]></category>
		<category><![CDATA[osama]]></category>
		<category><![CDATA[virus]]></category>

	<!-- AutoMeta Start -->
	<category>osama</category>
	<category>hanged</category>
	<category>hanged</category>
	<category>laden</category>
	<category>invitation</category>
	<category>disc</category>
	<category>contacts</category>
	<category>virus</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/osama-hanged-virus/</guid>
		<description><![CDATA[*verified with snopes.com and about anti-virus* Emails with pictures of Osama Bin-Laden hanged are being sent and the moment that you open these emails your computer will crash and you will not be able to fix it! 1.) If you &#8230; <a href="http://elamb.org/osama-hanged-virus/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>*verified with <a href="http://www.snopes.com/computer/virus/osama.asp">snopes.com</a> and about anti-virus*</p>
<p>Emails with pictures of Osama Bin-Laden hanged are being sent and the<br />
moment   that you open these emails your computer will crash and you<br />
will not be able   to fix it!</p>
<p>1.)   If you get an e-mail along the lines of &#8216;Osama Bin Laden Captured&#8217;<br />
or &#8216;Osama Hanged&#8217; , don&#8217;t open the Attachment!!!!</p>
<p>This e-mail is   being distributed through countries around the globe,<br />
but mainly in the US and  Israel.</p>
<p>Be considerate &#038;   send this warning to whomever you know..</p>
<p>PLEASE FORWARD   THIS WARNING AMONG FRIENDS, FAMILY AND CONTACTS.</p>
<p>2.)   You should be alert during the next few days:</p>
<p>Do not open any message with an attached file called &#8216;Invitation&#8217;<br />
regardless of who sent   it.</p>
<p>It is a virus that opens an Olympic Torch which &#8216;burns&#8217; the whole hard<br />
disc C of your computer!!!!</p>
<p>This virus will be received from someone who has your e-mail address<br />
in his/her contact list, that is why you should send this E-Mail to all<br />
your   contacts.</p>
<p>It is better to receive this message 25 times than to receive the virus<br />
and open it.</p>
<p>If you receive e-mail called &#8216;invitation&#8217;, though sent by a friend. Do<br />
not open it!!! Shut down your computer immediately!!!!</p>
<p>This is the worst virus announced by CNN, it has been classified by<br />
Microsoft as the most destructive virus ever.</p>
<p>This virus was discovered by McAfee yesterday, and there is no repair<br />
yet for   this kind of virus.</p>
<p>This virus simply  destroys the Zero Sector of the Hard Disc, where the<br />
vital information is   kept.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/osama-hanged-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ed Skoudis lists the Top 5 Worst Attacks of 1998 &#8211; 2002</title>
		<link>http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002</link>
		<comments>http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/#comments</comments>
		<pubDate>Wed, 11 Jun 2008 00:04:15 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Trojans]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[code red]]></category>
		<category><![CDATA[ed skoudis]]></category>
		<category><![CDATA[i love you]]></category>
		<category><![CDATA[melissa]]></category>
		<category><![CDATA[nimda]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>skoudis</category>
	<category>nimda</category>
	<category>lessons</category>
	<category>1998</category>
	<category>iis</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/</guid>
		<description><![CDATA[That which does not kill us makes us stronger. -Friedrich Nietzsche In the November 2002, Information Security Magazine article, Infosecâ€™s Worst NightMares, Ed Skoudis lists the Top 5 Worst Attacks of 1998 â€“ 2002. Mr. Skoudis is the founders of &#8230; <a href="http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><em>That which does not kill us makes us stronger.</em><br />
-Friedrich Nietzsche </p>
<p>In the November 2002, Information Security Magazine article, Infosecâ€™s Worst NightMares, Ed Skoudis lists the Top 5 Worst Attacks of 1998 â€“ 2002.  Mr. Skoudis is the founders of Intelguardians Network Intelligence, LLC and is a handler of the very popular Internet Storm Center.</p>
<p>Mr. Skoudis mentions that the Top five major destructive attacks of 1998 â€“ 2002 made many industries â€œbattle-testedâ€ and more likely to be proactive rather than reactive.  The 5 year Worst Skoudis list is based on exploits that shook our very faith in the Internet and security of e-commerce. </p>
<p><strong>1.  <a href="http://en.wikipedia.org/wiki/Code_Red_worm">Code Red (2001)</a></strong>.  July 13 2001, the worm attacked Microsoft IIS systems.  By 19 July 2001, the worm had affected over 350,000 systems.  SANS and Honeynet Project set up honey pots to capture the worm.  But E-eye Digital Security Programmers did the most intense research on the worm and also named it.   The worm exploited a vulnerability in the indexing software distributed with IIS, described in Microsoftâ€™s MS01-033 patch.  It was a buffer overflow attack. Some of the lessons learned:  Keep systems patched, use of honey pots to capture malware, coordinated response helps to contain worms.  </p>
<p><strong>2.  Nimda (2001). </strong> Shortly after 9/11, the Nimda worm was unleashed.  It caused more damage financially than Code Red.  There were rumors that it was China that released it to hurt the US further, but this is unlikely due to the nature of Nimda. </p>
<blockquote><p>
While it was bad, it had the appearance of a being written by a determined amateur, not a nation-state that spends $1 Billion annually on cyberwarfare capabilities. â€“ Skoudis.  </p></blockquote>
<p>Nimda affected Windows 95, 98, Me, NT, or 2000 and servers running Windows NT and 2000.  It was so affective because it attacked IIS, e-mail, browsers and network shares.  This multi dimensional attack method could mark a trend in future cyberfare.</p>
<p><em>Lessons Learned: The importance of an incident response capability, disabling arbitrary scripts in e-mail and browsers.</em></p>
<p><strong>3.  Melissa (1999) &#038; LoveLetter (2000). </strong> Both of these exploited malware through e-mail propagation.  Melissa used Microsoft Word Macro virus and LoveLetter (I Love You Virus).   The worm harvested the victims address book to forward itself to more victims which killed a lot of email servers.  Lessons Learned:  Many companies got serious about implementing anti-virus applications throughout the network.<br />
<strong><br />
4.  Distributed Denial-of-Service (DdoS) attacks (2000)</strong>.  After all the panic of pre-Y2K, a completely new and unexpected storm hit major sites: Yahoo!, Amazon, CNN, E*Trade ZDNet and eBay.  All by a single child hacker nicked named Mafiaboy.  He had spread zombie flooding agents to hundreds of machines around the world and used them to attack sites with billions of useless packets.  <em>Lessons Learned: employ anti-spoofing filters.</em><br />
<strong><br />
5.  Remote Control Trojan Horse Backdoors (1998 â€“ 2000)</strong>.  In 1998, the Cult of the Dead Cow hackers group created the Trojan, Back Orifice which initially targeted Windows NT/9x.    The tool allowed unskilled attackers to attack any vulnerable system.  It also marked the rise of the â€œscript kiddiesâ€ and produced a bunch of spin offs such as Subseven, Netbus and Hack-a-Tack.  </p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>w32 serflike a</title>
		<link>http://elamb.org/w32-serflike-a/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=w32-serflike-a</link>
		<comments>http://elamb.org/w32-serflike-a/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 03:33:40 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[w32]]></category>

	<!-- AutoMeta Start -->
	<category>serflike</category>
	<category>autoruns</category>
	<category>w32</category>
	<category>startup</category>
	<category>locations</category>
	<category>auto</category>
	<category>quot</category>
	<category>notifications</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/w32-serflike-a/</guid>
		<description><![CDATA[I have never heard of any virus called &#34;w32 serflike a&#34;, however if you believe you have this or any other malware a good place to start investigating this is to use Autoruns Autoruns is the most comprehensive knowledge of &#8230; <a href="http://elamb.org/w32-serflike-a/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I have never heard of any virus called &quot;w32 serflike a&quot;, however if you believe you have this or any other malware a good place to start investigating this is to use <a href="http://www.microsoft.com/technet/sysinternals/Utilities/AutoRuns.mspx">Autoruns</a></p>
<p>Autoruns is the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them. These programs include ones in your startup folder, Run, RunOnce, and other Registry keys. You can configure Autoruns to show other locations, including Explorer shell extensions, toolbars, browser helper objects, Winlogon notifications, auto-start services, and much more. Autoruns goes way beyond the MSConfig utility bundled with Windows Me and XP.</p>
<p>More on <a href="http://elamb.org/hacked/w32-serflike-a.htm">w32 serflike a</a></p>
<p class="tags">Tags: <a href="http://technorati.com/tag/w32-serflike-a.htm" title="See the Technorati tag page for 'w32-serflike-a.htm'." rel="tag">w32-serflike-a.htm</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/serflike" title="See the Technorati tag page for 'serflike'." rel="tag">serflike</a>, <a href="http://technorati.com/tag/autoruns" title="See the Technorati tag page for 'autoruns'." rel="tag">autoruns</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a>, <a href="http://technorati.com/tag/" title="See the Technorati tag page for ''." rel="tag"></a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/w32-serflike-a/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netdrvr Ext W32 Spybot Worm</title>
		<link>http://elamb.org/netdrvr-ext-w32-spybot-worm/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=netdrvr-ext-w32-spybot-worm</link>
		<comments>http://elamb.org/netdrvr-ext-w32-spybot-worm/#comments</comments>
		<pubDate>Mon, 26 Nov 2007 06:38:11 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>netdrvr</category>
	<category>ext</category>
	<category>ext</category>
	<category>spybot</category>
	<category>w32</category>
	<category>worm</category>
	<category>exe</category>
	<category>exe</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/netdrvr-ext-w32-spybot-worm/</guid>
		<description><![CDATA[Those looking for &#8220;Netdrvr Ext W32 Spybot Worm&#8221; You typed &#8220;Netdrvr Ext&#8221; Did you mean &#8220;netdrvr.exe&#8221;? If you meant &#8220;netdrvr.exe&#8221; then you definitely have malware. More than likely you have a virus running in a critical system folder of Windows: &#8230; <a href="http://elamb.org/netdrvr-ext-w32-spybot-worm/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Those looking for &#8220;<a href="http://elamb.org/hacked/netdrvr-ext-w32-spybot-worm.htm">Netdrvr Ext W32 Spybot Worm</a>&#8221;</p>
<p>You typed &#8220;Netdrvr Ext&#8221; Did you mean &#8220;netdrvr.exe&#8221;? </p>
<p>If you meant &#8220;<a href="http://elamb.org/hacked/netdrvr-ext-w32-spybot-worm.htm">netdrvr.exe</a>&#8221; then you definitely have malware. More than likely you have a virus running in a critical system folder of Windows: C:\Windows\System32\netdrvr.exe. This virus looks like it might be a device driver (Network DRV) but it is like a cancer to your system resources and privacy.</p>
<p>This virus can be removed with free tools such as Adaware, HijackThis or Microsoft&#8217;s <a href="http://elamb.org/hacked/netdrvr-ext-w32-spybot-worm.htm">Autoruns</a> (recommended).</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/netdrvr" title="See the Technorati tag page for 'netdrvr'." rel="tag">netdrvr</a>, <a href="http://technorati.com/tag/ext" title="See the Technorati tag page for 'ext'." rel="tag">ext</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/spybot" title="See the Technorati tag page for 'spybot'." rel="tag">spybot</a>, <a href="http://technorati.com/tag/worm" title="See the Technorati tag page for 'worm'." rel="tag">worm</a>, <a href="http://technorati.com/tag/virus" title="See the Technorati tag page for 'virus'." rel="tag">virus</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/netdrvr-ext-w32-spybot-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Storm Worm Erupts Into Worst Virus Sustained Attack In the Last 2 Years</title>
		<link>http://elamb.org/storm-worm-erupts-into-worst-virus-sustained-attack-in-the-last-2-years/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=storm-worm-erupts-into-worst-virus-sustained-attack-in-the-last-2-years</link>
		<comments>http://elamb.org/storm-worm-erupts-into-worst-virus-sustained-attack-in-the-last-2-years/#comments</comments>
		<pubDate>Thu, 26 Jul 2007 04:21:20 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware/Virus]]></category>

	<!-- AutoMeta Start -->
	<category>postini</category>
	<category>storm</category>
	<category>informationweek</category>
	<category>swidler</category>
	<category>sustained</category>
	<category>mails</category>
	<category>attack</category>
	<category>million</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/storm-worm-erupts-into-worst-virus-sustained-attack-in-the-last-2-years/</guid>
		<description><![CDATA[The Storm worm authors are waging a multi-pronged attack and generating the largest virus attack some researchers say they&#8217;ve seen in two years.&#8221;We are basically in the midst of an incredibly large attack,&#8221; said Adam Swidler, a senior manager with &#8230; <a href="http://elamb.org/storm-worm-erupts-into-worst-virus-sustained-attack-in-the-last-2-years/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><span id="articleBody"> The Storm worm authors are waging a multi-pronged attack and generating the largest virus attack some researchers say they&#8217;ve seen in two years.&#8221;We are basically in the midst of an incredibly large attack,&#8221; said Adam Swidler, a senior manager with <a class="iAs" style="border-bottom: medium none; font-weight: bold; text-decoration: none; padding-bottom: 0px; color: darkblue; background-color: transparent; cursor: pointer" target="_blank" href="http://informationweek.com/news/showArticle.jhtml?articleID=201200849#">security company<img style="border: medium none ; float: none" src="http://images.intellitxt.com/ast/adTypes/mag-glass_10x10.gif" /></a> Postini. &#8220;It&#8217;s the most sustained attack that we&#8217;ve seen. There&#8217;s been nine to 10 days straight days of attack at this level.&#8221;</p>
<p>Swidler said in an interview with <em>InformationWeek</em> that the attack started a little more than a week ago, and Postini since then has recorded 200 million <a class="iAs" style="border-bottom: medium none; font-weight: bold; text-decoration: none; padding-bottom: 0px; color: darkblue; background-color: transparent; cursor: pointer" target="_blank" href="http://informationweek.com/news/showArticle.jhtml?articleID=201200849#">spam<img style="border: medium none ; float: none" src="http://images.intellitxt.com/ast/adTypes/mag-glass_10x10.gif" /></a> e-mails luring users to malicious Web sites. Before this attack, an average day sees about 1 million virus-laden e-mails, according to Postini. Last Thursday, however, the company tracked 42 million Storm-related messages in that day alone. As of Tuesday afternoon, Postini researchers were predicting they would see that day between 4 million and 6 million virus e-mails &#8212; 99% of them associated with the Storm worm.</p>
<p>more on the complete ad heavy <a href="http://informationweek.com/news/showArticle.jhtml?articleID=201200849">Infoweek siteÂ </a></p>
<p></span></p>
<p class="tags">Tags: <a href="http://technorati.com/tag/postini" title="See the Technorati tag page for 'postini'." rel="tag">postini</a>, <a href="http://technorati.com/tag/spam" title="See the Technorati tag page for 'spam'." rel="tag">spam</a>, <a href="http://technorati.com/tag/virus" title="See the Technorati tag page for 'virus'." rel="tag">virus</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/storm-worm-erupts-into-worst-virus-sustained-attack-in-the-last-2-years/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>myspace virus (simple thing you can do to avoid it)</title>
		<link>http://elamb.org/myspace-virus-simple-thing-you-can-do-to-avoid-it/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=myspace-virus-simple-thing-you-can-do-to-avoid-it</link>
		<comments>http://elamb.org/myspace-virus-simple-thing-you-can-do-to-avoid-it/#comments</comments>
		<pubDate>Wed, 24 Jan 2007 15:43:44 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[myspace]]></category>

	<!-- AutoMeta Start -->
	<category>myspace</category>
	<category>sneaky</category>
	<category>slightest</category>
	<category>redirects</category>
	<category>viruses</category>
	<category>actions</category>
	<category>attempts</category>
	<category>flash</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/myspace-virus-simple-thing-you-can-do-to-avoid-it/</guid>
		<description><![CDATA[There have been some very sneaky viruses on myspace such as flash based redirects. But some are a little less sneaky and only take the slightest change in user actions. Phishing attempts will do something like this. They will ask &#8230; <a href="http://elamb.org/myspace-virus-simple-thing-you-can-do-to-avoid-it/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>There have been some very sneaky viruses on myspace such as <a href="http://chaseandsam.com/2006/07/myspace-hack-spreading-like-wildfire.html">flash based redirects.</a></p>
<p>But some are a little less sneaky and only take the slightest change in user actions.</p>
<p align="center"><img height="243" src="http://elamb.org/hacked/images/myspace-virus1.jpg" width="350" /></p>
<p align="left">Phishing attempts will do something like this. They will ask you to put in your myspace e-mail and password.Â  More on <a title="Myspace malware" href="http://elamb.org/hacked/myspace-virus.htm">Myspace viruses</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/myspace-virus-simple-thing-you-can-do-to-avoid-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Myspace gets Hacked</title>
		<link>http://elamb.org/myspace-gets-hacked/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=myspace-gets-hacked</link>
		<comments>http://elamb.org/myspace-gets-hacked/#comments</comments>
		<pubDate>Wed, 24 Jan 2007 15:34:32 +0000</pubDate>
		<dc:creator>elamb</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[myspace]]></category>

	<!-- AutoMeta Start -->
	<category></category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/myspace-gets-hacked/</guid>
		<description><![CDATA[Myspace doesn&#8217;t seem safe, if someone can change everyone&#8217;s about me. This happened a few weeks ago. Changed everyone&#8217;s about me to &#8220;but most of all nathan is my hero&#8221; read moreÂ &#124;Â digg story Tags: myspace, malware]]></description>
			<content:encoded><![CDATA[<p>Myspace doesn&#8217;t seem safe, if someone can change everyone&#8217;s about me. This happened a few weeks ago. Changed everyone&#8217;s about me to &#8220;but most of all nathan is my hero&#8221;</p>
<p><a href="http://search.yahoo.com/search?p=site%3Amyspace.com+%22but+most+of+all+Nathan+is+my+hero%22&#038;fr=yfp-t-501&#038;toggle=1&#038;cop=mss&#038;ei=UTF-8">read more</a>Â |Â <a href="http://digg.com/tech_deals/Myspace_gets_Hacked">digg story</a></p>
<p class="tags">Tags: <a href="http://technorati.com/tag/myspace" title="See the Technorati tag page for 'myspace'." rel="tag">myspace</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/myspace-gets-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

