<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; Worm</title>
	<atom:link href="http://elamb.org/category/worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Riparare File Dnsrslve Da W32 Spybot Worm</title>
		<link>http://elamb.org/riparare-file-dnsrslve-da-w32-spybot-worm/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=riparare-file-dnsrslve-da-w32-spybot-worm</link>
		<comments>http://elamb.org/riparare-file-dnsrslve-da-w32-spybot-worm/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 01:24:04 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>dnsrslve</category>
	<category>riparare</category>
	<category>spybot</category>
	<category>w32</category>
	<category>gen</category>
	<category>rbot</category>
	<category>worm</category>
	<category>apn</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/riparare-file-dnsrslve-da-w32-spybot-worm/</guid>
		<description><![CDATA[more on: Riparare File Dnsrslve Da W32 Spybot Worm Dnsrslve.exe [DNS Resolver] is a virus added by the W32/Rbot-WS worm also know as Backdoor.Win32.Rbot.gen, W32/Sdbot.worm.gen.g, WORM_SDBOT.APN. ref: http://sophos.com Tags: riparare-file-dnsrslve-da-w32-spybot-worm, worm, malware, w32]]></description>
			<content:encoded><![CDATA[<p>more on: <a href="http://elamb.org/hacked/riparare-file-dnsrslve-da-w32-spybot-worm.htm">Riparare File Dnsrslve Da W32 Spybot Worm</a></p>
<p>Dnsrslve.exe [DNS Resolver] is a virus added by the W32/Rbot-WS worm also know as Backdoor.Win32.Rbot.gen, W32/Sdbot.worm.gen.g, WORM_SDBOT.APN. </p>
<p>ref: http://sophos.com</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/riparare-file-dnsrslve-da-w32-spybot-worm" title="See the Technorati tag page for 'riparare-file-dnsrslve-da-w32-spybot-worm'." rel="tag">riparare-file-dnsrslve-da-w32-spybot-worm</a>, <a href="http://technorati.com/tag/worm" title="See the Technorati tag page for 'worm'." rel="tag">worm</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/riparare-file-dnsrslve-da-w32-spybot-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>recuperar informacion malograda por w32 pawur</title>
		<link>http://elamb.org/recuperar-informacion-malograda-por-w32-pawur/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=recuperar-informacion-malograda-por-w32-pawur</link>
		<comments>http://elamb.org/recuperar-informacion-malograda-por-w32-pawur/#comments</comments>
		<pubDate>Sun, 02 Dec 2007 01:15:57 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>pawur</category>
	<category>win32</category>
	<category>anzae</category>
	<category>w32</category>
	<category>tasin</category>
	<category>nombre</category>
	<category>inzae</category>
	<category>worm</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/recuperar-informacion-malograda-por-w32-pawur/</guid>
		<description><![CDATA[information on Riparare file dnsrslve da w32 spybot worm W32@pawur is a worm. More information on pawur Nombre:&#160;W32/Pawur.A Nombre NOD32: Win32/Pawur.A Tipo: Gusano de Internet Alias:&#160;Pawur.A, Tasin.A, Anzae, I-Worm.Pawur.A, I-Worm.Pawur.a, I-Worm.VB.w, I-Worm/Pawur.A, NewHeur_PE, W32.Inzae.A, W32/Anzae.Worm, W32/Tasin.A.worm, Win32/Inzae.A.Dropper, Win32/Pawur.A, WORM_ANZAE.A, W32/Anzae-A, &#8230; <a href="http://elamb.org/recuperar-informacion-malograda-por-w32-pawur/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>information on <a href="http://http://elamb.org/hacked/recuperar-informacion-malograda-por-w32-pawur.htm">Riparare file dnsrslve da w32 spybot worm</a></p>
<p>W32@pawur is a worm. <a href="http://www.vsantivirus.com/pawur-a.htm">More information on pawur</a></p>
<p><strong>Nombre:</strong>&nbsp;W32/Pawur.A<br />
      <strong>Nombre NOD32:</strong> Win32/Pawur.A<br />
      <strong>Tipo:</strong> Gusano de Internet<br />
      <strong>Alias:</strong>&nbsp;Pawur.A,  Tasin.A, Anzae, I-Worm.Pawur.A, I-Worm.Pawur.a, I-Worm.VB.w,  I-Worm/Pawur.A, NewHeur_PE, W32.Inzae.A, W32/Anzae.Worm,  W32/Tasin.A.worm, Win32/Inzae.A.Dropper, Win32/Pawur.A, WORM_ANZAE.A,  W32/Anzae-A, W32/Insae.A@mm, Email-Worm.Win32.Pawur.a, Win32.HLLM.Pawur<br />
      <strong>Fecha:</strong>&nbsp;22/nov/04<br />
      <strong>Plataforma:</strong> Windows 32-bit<br />
      <strong>Tama&ntilde;o:</strong>&nbsp;49,331 bytes</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/recuperar" title="See the Technorati tag page for 'recuperar'." rel="tag">recuperar</a>, <a href="http://technorati.com/tag/informacion" title="See the Technorati tag page for 'informacion'." rel="tag">informacion</a>, <a href="http://technorati.com/tag/malograda" title="See the Technorati tag page for 'malograda'." rel="tag">malograda</a>, <a href="http://technorati.com/tag/por" title="See the Technorati tag page for 'por'." rel="tag">por</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/pawur" title="See the Technorati tag page for 'pawur'." rel="tag">pawur</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a>, <a href="http://technorati.com/tag/worm" title="See the Technorati tag page for 'worm'." rel="tag">worm</a>, <a href="http://technorati.com/tag/malograda" title="See the Technorati tag page for 'malograda'." rel="tag">malograda</a>, <a href="http://technorati.com/tag/" title="See the Technorati tag page for ''." rel="tag"></a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/recuperar-informacion-malograda-por-w32-pawur/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netdrvr Ext W32 Spybot Worm</title>
		<link>http://elamb.org/netdrvr-ext-w32-spybot-worm/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=netdrvr-ext-w32-spybot-worm</link>
		<comments>http://elamb.org/netdrvr-ext-w32-spybot-worm/#comments</comments>
		<pubDate>Mon, 26 Nov 2007 06:38:11 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>netdrvr</category>
	<category>ext</category>
	<category>ext</category>
	<category>spybot</category>
	<category>w32</category>
	<category>worm</category>
	<category>exe</category>
	<category>exe</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/netdrvr-ext-w32-spybot-worm/</guid>
		<description><![CDATA[Those looking for &#8220;Netdrvr Ext W32 Spybot Worm&#8221; You typed &#8220;Netdrvr Ext&#8221; Did you mean &#8220;netdrvr.exe&#8221;? If you meant &#8220;netdrvr.exe&#8221; then you definitely have malware. More than likely you have a virus running in a critical system folder of Windows: &#8230; <a href="http://elamb.org/netdrvr-ext-w32-spybot-worm/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Those looking for &#8220;<a href="http://elamb.org/hacked/netdrvr-ext-w32-spybot-worm.htm">Netdrvr Ext W32 Spybot Worm</a>&#8221;</p>
<p>You typed &#8220;Netdrvr Ext&#8221; Did you mean &#8220;netdrvr.exe&#8221;? </p>
<p>If you meant &#8220;<a href="http://elamb.org/hacked/netdrvr-ext-w32-spybot-worm.htm">netdrvr.exe</a>&#8221; then you definitely have malware. More than likely you have a virus running in a critical system folder of Windows: C:\Windows\System32\netdrvr.exe. This virus looks like it might be a device driver (Network DRV) but it is like a cancer to your system resources and privacy.</p>
<p>This virus can be removed with free tools such as Adaware, HijackThis or Microsoft&#8217;s <a href="http://elamb.org/hacked/netdrvr-ext-w32-spybot-worm.htm">Autoruns</a> (recommended).</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/netdrvr" title="See the Technorati tag page for 'netdrvr'." rel="tag">netdrvr</a>, <a href="http://technorati.com/tag/ext" title="See the Technorati tag page for 'ext'." rel="tag">ext</a>, <a href="http://technorati.com/tag/w32" title="See the Technorati tag page for 'w32'." rel="tag">w32</a>, <a href="http://technorati.com/tag/spybot" title="See the Technorati tag page for 'spybot'." rel="tag">spybot</a>, <a href="http://technorati.com/tag/worm" title="See the Technorati tag page for 'worm'." rel="tag">worm</a>, <a href="http://technorati.com/tag/virus" title="See the Technorati tag page for 'virus'." rel="tag">virus</a>, <a href="http://technorati.com/tag/malware" title="See the Technorati tag page for 'malware'." rel="tag">malware</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/netdrvr-ext-w32-spybot-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gathering &#8216;Storm&#8217; Superworm Poses Grave Threat to PC Nets</title>
		<link>http://elamb.org/gathering-storm-superworm-poses-grave-threat-to-pc-nets/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=gathering-storm-superworm-poses-grave-threat-to-pc-nets</link>
		<comments>http://elamb.org/gathering-storm-superworm-poses-grave-threat-to-pc-nets/#comments</comments>
		<pubDate>Fri, 05 Oct 2007 15:38:08 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>storm</category>
	<category>worm</category>
	<category>infected</category>
	<category>rolled</category>
	<category>estimates</category>
	<category>batters</category>
	<category>attachment</category>
	<category>attachments</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/gathering-storm-superworm-poses-grave-threat-to-pc-nets/</guid>
		<description><![CDATA[The Storm worm first appeared at the beginning of the year, hiding in e-mail attachments with the subject line: &#8220;230 dead as storm batters Europe.&#8221; Those who opened the attachment became infected, their computers joining an ever-growing botnet. Although it&#8217;s &#8230; <a href="http://elamb.org/gathering-storm-superworm-poses-grave-threat-to-pc-nets/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The <a title="storm worm" href="http://www.wired.com/politics/security/commentary/securitymatters/2007/10/securitymatters_1004">Storm worm</a> first appeared at the beginning of the year, hiding in e-mail attachments with the subject line: &#8220;230 dead as storm batters Europe.&#8221; Those who opened the attachment became infected, their computers joining an ever-growing botnet.</p>
<p>Although it&#8217;s most commonly called a worm, Storm is really more: a worm, a Trojan horse and a bot all rolled into one. It&#8217;s also the most successful example we have of a new breed of worm, and I&#8217;ve seen estimates that <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=201804528">between 1 million and 50 million computers</a> have been infected worldwide.</p>
<p>Â </p>
<p>More <a href="http://www.wired.com/politics/security/commentary/securitymatters/2007/10/securitymatters_1004">here</a>.</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/worm" title="See the Technorati tag page for 'worm'." rel="tag">worm</a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/gathering-storm-superworm-poses-grave-threat-to-pc-nets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New IM worm chats with its intended victims</title>
		<link>http://elamb.org/new-im-worm-chats-with-its-intended-victims/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-im-worm-chats-with-its-intended-victims</link>
		<comments>http://elamb.org/new-im-worm-chats-with-its-intended-victims/#comments</comments>
		<pubDate>Thu, 08 Dec 2005 11:57:57 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=359</guid>
		<description><![CDATA[A new worm that targets users of America Online&#39;s AOL Instant Messenger is believed to be the first that actually chats with the intended victim to dupe the target into activating a malicious payload, IM security vendor IMlogic warned Tuesday. &#8230; <a href="http://elamb.org/new-im-worm-chats-with-its-intended-victims/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>A new worm that targets users of America Online&#39;s AOL Instant Messenger<br />
is believed to be the first that actually chats with the intended<br />
victim to dupe the target into activating a malicious payload, IM<br />
security vendor IMlogic warned Tuesday.</p>
<p><a href="http://news.com.com/New+IM+worm+chats+with+its+intended+victims/2100-7349_3-5984845.html?tag=cd.top">read more</a>&nbsp;|&nbsp;<a href="http://digg.com/security/New_IM_worm_chats_with_its_intended_victims">digg story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/new-im-worm-chats-with-its-intended-victims/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are you getting email from the FBI or CIA? (new malicious code)</title>
		<link>http://elamb.org/are-you-getting-email-from-the-fbi-or-cia-new-malicious-code/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=are-you-getting-email-from-the-fbi-or-cia-new-malicious-code</link>
		<comments>http://elamb.org/are-you-getting-email-from-the-fbi-or-cia-new-malicious-code/#comments</comments>
		<pubDate>Mon, 28 Nov 2005 22:36:07 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=342</guid>
		<description><![CDATA[Dear Sir/Madam, We have logged your IP-address on more than 30 illegal Websites. Sober worm pretends to be an email from the FBI or CIA.&#160; read more&#160;&#124;&#160;digg story]]></description>
			<content:encoded><![CDATA[<p>Dear Sir/Madam, We have logged your IP-address on more than 30 illegal Websites.</p>
<p>Sober worm pretends to be an email from the FBI or CIA.&nbsp; </p>
<p><a href="http://www.securitypark.co.uk/article.asp?articleid=24602&amp;Categoryid=1">read more</a>&nbsp;|&nbsp;<a href="http://digg.com/security/Are_you_getting_email_from_the_FBI_or_CIA_">digg story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/are-you-getting-email-from-the-fbi-or-cia-new-malicious-code/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>w32 Zotob</title>
		<link>http://elamb.org/w32-zotob/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=w32-zotob</link>
		<comments>http://elamb.org/w32-zotob/#comments</comments>
		<pubDate>Mon, 22 Aug 2005 13:16:01 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[security]]></category>
		<category><![CDATA[w32 Zotob]]></category>
		<category><![CDATA[Worm]]></category>
		<category><![CDATA[Zotob]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=164</guid>
		<description><![CDATA[Here is more info on the Zotob.&#160; This page covers: How to remove Zotob? Automated &#8220;FixZotob.exe&#8221; type tools from Symantec &#38; Microsoft What is the Zotob and what kind of damage can it do? Not much.. unless it connects with &#8230; <a href="http://elamb.org/w32-zotob/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Here is more info on the Zotob.&nbsp; </p>
<p><a href="http://elamb.blogharbor.com/hacked/zotob.htm">This page covers</a>:</p>
<div>How to remove Zotob?</p>
<div>Automated &#8220;FixZotob.exe&#8221; type tools from Symantec &amp; Microsoft</p>
<div>What is the Zotob and what kind of damage can it do?</p>
<div>Not much.. unless it connects with the outside IRC.</p>
<div>Who created the Zotob? </p>
<div>Diabl0 (Turkey)</div>
<p></p>
<div>Why was Zotob created? bot wars?</p>
<h2><a href="http://elamb.blogharbor.com/hacked/zotob.htm">http://elamb.blogharbor.com/hacked/zotob.htm</a></h2>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/w32-zotob/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zotob.A Worm pandemic</title>
		<link>http://elamb.org/zotoba-worm-pandemic/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=zotoba-worm-pandemic</link>
		<comments>http://elamb.org/zotoba-worm-pandemic/#comments</comments>
		<pubDate>Thu, 18 Aug 2005 22:32:26 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Worm]]></category>
		<category><![CDATA[Zotob]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=162</guid>
		<description><![CDATA[The Zotob Worm has spread across three continents and has brought down systems at CNN, ABC and other networks.&#160; It is a decendant of Mytob.&#160; Zotob exploits the &#8220;plug and play&#8221; features of unpatched Win 2000 systems and earlier versions &#8230; <a href="http://elamb.org/zotoba-worm-pandemic/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The Zotob Worm has spread across three continents and has brought down systems at CNN, ABC and other networks.&nbsp; It is a decendant of <a href="http://www.lurhq.com/pnpworms.html">Mytob</a>.&nbsp; Zotob exploits the &#8220;plug and play&#8221; features of unpatched Win 2000 systems and earlier versions of Windows XP.&nbsp; </p>
<p>&nbsp;</p>
<p>The Zotob Worm, like most worms, slows down network connectivity, can shut down/reboot a system, attempts to spread to other systems on the network and ultimately will connect with a remote server to allow downloads of more destructive malware such as virus&#8217; and Trojans.</p>
<p>&nbsp;</p>
<p><strong>Zotob Worm Variants:</strong></p>
<p>http://securityresponse.symantec.com/avcenter/vinfodb.html</p>
<p>&nbsp;</p>
<p><strong>Summary:</strong></p>
<p><a href="http://singe.rucus.net/blog/archives/510-MS05-039-and-the-Zotob-summary.html">http://singe.rucus.net/blog/archives/510-MS05-039-and-the-Zotob-summary.html</a></p>
<p>&nbsp;</p>
<p>http://singe.rucus.net/blog/archives/510-MS05-039-and-the-Zotob-summary.html</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/zotoba-worm-pandemic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

