<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; w32</title>
	<atom:link href="http://elamb.org/category/w32/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>What is W32 Myzor?</title>
		<link>http://elamb.org/what-is-w32-myzor/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-is-w32-myzor</link>
		<comments>http://elamb.org/what-is-w32-myzor/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 07:10:40 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[w32]]></category>

	<!-- AutoMeta Start -->
	<category>myzor</category>
	<category>w32</category>
	<category>infected</category>
	<category>infected</category>
	<category>shitty</category>
	<category>balloon</category>
	<category>appliations</category>
	<category>emailers</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/what-is-w32-myzor/</guid>
		<description><![CDATA[W32 Myzor is a part of a family of &#8220;Scamware&#8221;. These are trojans that pose as anti-virus/anti-spyware appliations that actually install malware on to your computer (viruses, worms, mass emailers). They attempt to gather your personal information and scare you &#8230; <a href="http://elamb.org/what-is-w32-myzor/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://elamb.org/hacked/images/biohaz.jpg" alt="malware" />W32 Myzor is a part of a family of &#8220;Scamware&#8221;. These are trojans that pose as anti-virus/anti-spyware appliations that actually install malware on to your computer (viruses, worms, mass emailers). They attempt to gather your personal information and scare you into purchasing some shitty malicious software (no offense to adds running on this site). </p>
<p>W32.Myzor.FK@yf virus. The warning are fake. Your system probably is infected but it is infected because a myzor variant put it there. The balloon about &#8220;You computer is infected&#8221;, is not real.</p>
<p>go to the following for more:</p>
<blockquote><p>
<a href="http://elamb.org/hacked/w32-myzor.html">w32 myzor</a><br />
<a href="http://elamb.org/hacked/w32-myzor-fk.html">w32 myzor fk</a><br />
<a href="http://elamb.org/hacked/w32-myzor-fk-yf.html">w32 myzor fk yf</a></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/what-is-w32-myzor/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>w32 flash almod</title>
		<link>http://elamb.org/w32-flash-almod/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=w32-flash-almod</link>
		<comments>http://elamb.org/w32-flash-almod/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 03:39:52 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[w32]]></category>

	<!-- AutoMeta Start -->
	<category>almod</category>
	<category>alemod</category>
	<category>w32</category>
	<category>flash</category>
	<category>pcgeeks</category>
	<category>commentcomarche</category>
	<category>hijackthis</category>
	<category>potential</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/w32-flash-almod/</guid>
		<description><![CDATA[&#8220;w32 flash almod&#8221; If you are looking for W32/Alemod here are some links to remove this potential virus: - PCGeeks &#8211; W32/Alemod - CommentComarche &#8211; Hijackthis files Tags: w32, alemod, virus]]></description>
			<content:encoded><![CDATA[<p>&#8220;<a href="http://elamb.org/hacked/w32-flash-almod.htm">w32 flash almod</a>&#8221; If you are looking for W32/Alemod here are some links to remove this potential virus:</p>
<p>- PCGeeks &#8211; W32/Alemod </p>
<p>- CommentComarche &#8211; Hijackthis files</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/alemod" title="See the Technorati tag page for 'alemod'." rel="tag">alemod</a>, <a href="http://technorati.com/tag/virus" title="See the Technorati tag page for 'virus'." rel="tag">virus</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/w32-flash-almod/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>w32 serflike a</title>
		<link>http://elamb.org/w32-serflike-a/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=w32-serflike-a</link>
		<comments>http://elamb.org/w32-serflike-a/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 03:33:40 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[w32]]></category>

	<!-- AutoMeta Start -->
	<category>serflike</category>
	<category>autoruns</category>
	<category>w32</category>
	<category>startup</category>
	<category>locations</category>
	<category>auto</category>
	<category>quot</category>
	<category>notifications</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/w32-serflike-a/</guid>
		<description><![CDATA[I have never heard of any virus called &#34;w32 serflike a&#34;, however if you believe you have this or any other malware a good place to start investigating this is to use Autoruns Autoruns is the most comprehensive knowledge of &#8230; <a href="http://elamb.org/w32-serflike-a/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I have never heard of any virus called &quot;w32 serflike a&quot;, however if you believe you have this or any other malware a good place to start investigating this is to use <a href="http://www.microsoft.com/technet/sysinternals/Utilities/AutoRuns.mspx">Autoruns</a></p>
<p>Autoruns is the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them. These programs include ones in your startup folder, Run, RunOnce, and other Registry keys. You can configure Autoruns to show other locations, including Explorer shell extensions, toolbars, browser helper objects, Winlogon notifications, auto-start services, and much more. Autoruns goes way beyond the MSConfig utility bundled with Windows Me and XP.</p>
<p>More on <a href="http://elamb.org/hacked/w32-serflike-a.htm">w32 serflike a</a></p>
<p class="tags">Tags: <a href="http://technorati.com/tag/w32-serflike-a.htm" title="See the Technorati tag page for 'w32-serflike-a.htm'." rel="tag">w32-serflike-a.htm</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/serflike" title="See the Technorati tag page for 'serflike'." rel="tag">serflike</a>, <a href="http://technorati.com/tag/autoruns" title="See the Technorati tag page for 'autoruns'." rel="tag">autoruns</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a>, <a href="http://technorati.com/tag/" title="See the Technorati tag page for ''." rel="tag"></a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/w32-serflike-a/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>virus w32 2fsober.k 40mm</title>
		<link>http://elamb.org/virus-w32-2fsoberk-40mm/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=virus-w32-2fsoberk-40mm</link>
		<comments>http://elamb.org/virus-w32-2fsoberk-40mm/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 03:25:44 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[w32]]></category>

	<!-- AutoMeta Start -->
	<category>2fsober</category>
	<category>40mm</category>
	<category>w32</category>
	<category>sober</category>
	<category>mailing</category>
	<category>mass</category>
	<category>bat</category>
	<category>varies</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/virus-w32-2fsoberk-40mm/</guid>
		<description><![CDATA[You typed in w32/sober.@mm You are looking for information on the W32.Sober@mm. W32 indicates that this malware affects Windows 32 systems. Sober is the family of malware it belongs to and â€œmmâ€ stands for mass-mailing. The W32.Sober@mm virus is actually &#8230; <a href="http://elamb.org/virus-w32-2fsoberk-40mm/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>You typed in w32/sober.@mm</p>
<p>You are looking for information on the W32.Sober@mm. W32 indicates that this malware affects Windows 32 systems. Sober is the family of malware it belongs to and â€œmmâ€ stands for mass-mailing. The W32.Sober@mm virus is actually a mass-mailing worm. It uses a SMTP engine to spread itself. The subject of the email is in English or German. The name of the email attachment varies, and it will have a .bat, .com, .exe, .pif, or .scr file extension. It is written in the Visual Basic programming language and is compressed with UPX. W32.Sober@mm may display the fake error message &#8220;File not complete!&#8221; </p>
<p>More on <a href="http://elamb.org/hacked/virus-w32-2fsober-k-40mm.htm">virus w32 2fsober.k 40mm</a></p>
<p class="tags">Tags: <a href="http://technorati.com/tag/virus" title="See the Technorati tag page for 'virus'." rel="tag">virus</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/2fsober.k" title="See the Technorati tag page for '2fsober.k'." rel="tag">2fsober.k</a>, <a href="http://technorati.com/tag/40mm" title="See the Technorati tag page for '40mm'." rel="tag">40mm</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a>, <a href="http://technorati.com/tag/sober" title="See the Technorati tag page for 'sober'." rel="tag">sober</a>, <a href="http://technorati.com/tag/remove" title="See the Technorati tag page for 'remove'." rel="tag">remove</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/virus-w32-2fsoberk-40mm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Riparare File Dnsrslve Da W32 Spybot Worm</title>
		<link>http://elamb.org/riparare-file-dnsrslve-da-w32-spybot-worm/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=riparare-file-dnsrslve-da-w32-spybot-worm</link>
		<comments>http://elamb.org/riparare-file-dnsrslve-da-w32-spybot-worm/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 01:24:04 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>dnsrslve</category>
	<category>riparare</category>
	<category>spybot</category>
	<category>w32</category>
	<category>gen</category>
	<category>rbot</category>
	<category>worm</category>
	<category>apn</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/riparare-file-dnsrslve-da-w32-spybot-worm/</guid>
		<description><![CDATA[more on: Riparare File Dnsrslve Da W32 Spybot Worm Dnsrslve.exe [DNS Resolver] is a virus added by the W32/Rbot-WS worm also know as Backdoor.Win32.Rbot.gen, W32/Sdbot.worm.gen.g, WORM_SDBOT.APN. ref: http://sophos.com Tags: riparare-file-dnsrslve-da-w32-spybot-worm, worm, malware, w32]]></description>
			<content:encoded><![CDATA[<p>more on: <a href="http://elamb.org/hacked/riparare-file-dnsrslve-da-w32-spybot-worm.htm">Riparare File Dnsrslve Da W32 Spybot Worm</a></p>
<p>Dnsrslve.exe [DNS Resolver] is a virus added by the W32/Rbot-WS worm also know as Backdoor.Win32.Rbot.gen, W32/Sdbot.worm.gen.g, WORM_SDBOT.APN. </p>
<p>ref: http://sophos.com</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/riparare-file-dnsrslve-da-w32-spybot-worm" title="See the Technorati tag page for 'riparare-file-dnsrslve-da-w32-spybot-worm'." rel="tag">riparare-file-dnsrslve-da-w32-spybot-worm</a>, <a href="http://technorati.com/tag/worm" title="See the Technorati tag page for 'worm'." rel="tag">worm</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/riparare-file-dnsrslve-da-w32-spybot-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

