<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0"
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>NOD32 and Virus News - Adware, Spyware and Trojans</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/</link>
    <description>Everything you wanted to know about NOD32 and Viruses</description>
    <dc:language>en</dc:language>
    <admin:errorReportsTo rdf:resource="mailto:" />
    <generator>Serendipity 0.8.2 - http://www.s9y.org/</generator>
    
    <image>
        <url>http://www.betterantivirus.com/nod32-and-virus-news/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: NOD32 and Virus News - Adware, Spyware and Trojans - Everything you wanted to know about NOD32 and Viruses</title>
        <link>http://www.betterantivirus.com/nod32-and-virus-news/</link>
        <width>100</width>
        <height>21</height>
    </image>
<item>
    <title>Death of the Nothing Doing Worm</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/950-Death-of-the-Nothing-Doing-Worm.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/950-Death-of-the-Nothing-Doing-Worm.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=950</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=950</wfw:commentRss>
    <author>news@betterantivirus.com (Annette King)</author>
    <content:encoded>
&lt;br /&gt;
We know, it's sad but true. Our last weeks super-star, the worm that does nothing, has slowly declined it's spread.&lt;br /&gt;&lt;br /&gt;We've been following it's evolution, however it seems the last version only has one additional feature: it can update itself to the latest version. It does this by exploiting the adodb.stream vulnerability in Internet Explorer to download a file from several hosts which contain instructions on the location of the new version. Although BitDefender detects this e-threat since January under the name VBS.Worm.Runauto.E it has not changed ever since. Seems like it's development stopped at version 10.0.&lt;br /&gt; &lt;br /&gt;Nevertheless, this weeks malware evolution hasn't stopped with our friendly worm. Next we will look at a worm called &lt;a title=&quot;Win32.Antiman.N&quot; target=&quot;_top&quot; href=&quot;http://www.bitdefender.com/VIRUS-1000331-en--Win32.Antiman.N.html&quot;&gt;Win32.Antiman.N&lt;/a&gt;. If infected with it, the victim will surely be ridden of a certain genre of music called &amp;quot;manele&amp;quot;. It searches the entire hard disk for most &amp;quot;manele&amp;quot; artists and and will delete them. Next it will add a lot of entries to the %windir%system32drivershosts  file to block social networking websites, like hi5 and netlog, and many free download websites that provide this genre of music. It will also send itself to the whole Yahoo Messenger list using a set number of strings in Romanian language that state something like: I found a great new program for winamp (or for pictures). &lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/950-guid.html#extended&quot;&gt;Continue reading &quot;Death of the Nothing Doing Worm&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Tue, 15 Jul 2008 15:06:00 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/950-guid.html</guid>
    </item>
<item>
    <title>E-mail allegedly from UPS delivers a computer virus</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/949-E-mail-allegedly-from-UPS-delivers-a-computer-virus.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/949-E-mail-allegedly-from-UPS-delivers-a-computer-virus.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=949</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=949</wfw:commentRss>
    <author>news@betterantivirus.com (Sean Cannon)</author>
    <content:encoded>
An e-mail informing recipients that they have a package that the United Parcel Service could not deliver is actually a new computer virus, company officials said.&lt;br /&gt;&lt;br /&gt;The e-mail that appears to come from UPS contains an attachment that recipients are told to open in order to make arrangements to pick up their shipment, UPS officials said.&lt;br /&gt;&lt;br /&gt;The attachment is actually a computer virus, the company said.&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/949-guid.html#extended&quot;&gt;Continue reading &quot;E-mail allegedly from UPS delivers a computer virus&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Tue, 15 Jul 2008 11:27:03 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/949-guid.html</guid>
    </item>
<item>
    <title>Virus attacks on 120 brokers' servers force DSE to halt trading</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/944-Virus-attacks-on-120-brokers-servers-force-DSE-to-halt-trading.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/944-Virus-attacks-on-120-brokers-servers-force-DSE-to-halt-trading.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=944</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=944</wfw:commentRss>
    <author>news@betterantivirus.com (Sean Cannon)</author>
    <content:encoded>
Massive virus attacks on over 120 brokerage houses' server systems yesterday forced the Dhaka Stock Exchange (DSE) to suspend stock trading for almost the whole day.&lt;br /&gt;&lt;br /&gt;Till filing of this report at 9 pm yesterday, DSE teams were working to get the systems restored. They were using anti-virus software Kaspersky to clean the infected servers .&lt;br /&gt;&lt;br /&gt;DSE Chief Executive Officer said an investigation will be launched to find out whether the virus attack was an act of any organised crime.&lt;br /&gt;&lt;br /&gt;Trading meanwhile took place on the premier bourse for only one hour at the later part of the day.&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/944-guid.html#extended&quot;&gt;Continue reading &quot;Virus attacks on 120 brokers' servers force DSE to halt trading&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Thu, 10 Jul 2008 09:04:33 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/944-guid.html</guid>
    </item>
<item>
    <title>Watch Out for an IE Zero-Day Attack</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/941-Watch-Out-for-an-IE-Zero-Day-Attack.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/941-Watch-Out-for-an-IE-Zero-Day-Attack.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=941</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=941</wfw:commentRss>
    <author>news@betterantivirus.com (Sean Cannon)</author>
    <content:encoded>
&lt;b&gt;There's no fix yet available for the latest attack against Microsoft's browser.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Microsoft yesterday warned of a new attack underway against a flaw in the ActiveX control for the Snapshot Viewer for Microsoft Access, used by IE. There is not yet any patch available for the zero-day security hole, and the attacks likely focus on business targets.&lt;br /&gt;&lt;br /&gt;In its security advisory, Redmond says the vulnerable control installs with &amp;quot;all supported versions of Microsoft Office Access except for Microsoft Office Access 2007. The ActiveX control is also shipped with the standalone Snapshot Viewer.&amp;quot; A poisoned Web page that exploits the hole could surreptitiously download malware to a victim PC.&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/941-guid.html#extended&quot;&gt;Continue reading &quot;Watch Out for an IE Zero-Day Attack&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Wed, 09 Jul 2008 10:59:00 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/941-guid.html</guid>
    </item>
<item>
    <title>Malware scenario: Third World War has begun</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/940-Malware-scenario-Third-World-War-has-begun.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/940-Malware-scenario-Third-World-War-has-begun.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=940</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=940</wfw:commentRss>
    <author>news@betterantivirus.com (Sean Cannon)</author>
    <content:encoded>
&lt;br /&gt;
Sophos is warning of an attempt by hackers to infect computers using the camouflage of a news report claiming that the USA has invaded Iran. Widely spammed out emails with subject lines including &amp;quot;Third World War has begun&amp;quot;, &amp;quot;20000 US Soldiers in Iran&amp;quot;, and &amp;quot;US Army crossed Iran's borders&amp;quot; have been intercepted by Sophos. &lt;br /&gt;&lt;br /&gt;The emails contain links to a malicious webpage that displays what appears to be a video player showing the mushroom cloud of a nuclear explosion with the following text beneath:&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/940-guid.html#extended&quot;&gt;Continue reading &quot;Malware scenario: Third World War has begun&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Wed, 09 Jul 2008 09:05:53 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/940-guid.html</guid>
    </item>
<item>
    <title>Storm gang uses 4 July fireworks to spread Trojan</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/933-Storm-gang-uses-4-July-fireworks-to-spread-Trojan.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/933-Storm-gang-uses-4-July-fireworks-to-spread-Trojan.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=933</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=933</wfw:commentRss>
    <author>news@betterantivirus.com (Sean Cannon)</author>
    <content:encoded>
&lt;br /&gt;A widespread malicious e-mail spam campaign used the guise of the 4 July American Independence Day celebrations last week.&lt;br /&gt;&lt;br /&gt;Using the promise of an impressive video clip of fireworks, the spam was designed to steal users' private data, including online banking details.&lt;br /&gt;&lt;br /&gt;The attack was the latest from the gang behind the Dorf malware, also known as the Storm worm, reported anti-virus software firm Sophos.&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/933-guid.html#extended&quot;&gt;Continue reading &quot;Storm gang uses 4 July fireworks to spread Trojan&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Tue, 08 Jul 2008 16:31:00 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/933-guid.html</guid>
    </item>
<item>
    <title>E-hijackers make a killing with 'ransomware'</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/937-E-hijackers-make-a-killing-with-ransomware.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/937-E-hijackers-make-a-killing-with-ransomware.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=937</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=937</wfw:commentRss>
    <author>news@betterantivirus.com (Annette King)</author>
    <content:encoded>
Name and Fame were once the driving factors for writing viruses, but thats not what drives virus authors of today. Now, its all about money and the present generations of malware authors are finding new ways to indulge in cyber crime.&lt;br /&gt;&lt;br /&gt;From installing adware and spyware programmes, to spam and phishing or extortion of internet websites with denial of service attacks, cyber criminals are now targeting home consumers with Ransomware.&lt;br /&gt;&lt;br /&gt;Just like criminals who kidnap your loved ones and then demand a ransom to return them unharmed , ransomware is an extortion scheme whereby cyber criminals hijack data files on a victims computer and then demand a ransom to get back the files in their original condition.&lt;br /&gt;&lt;br /&gt;Important documents and image files on the victims computer are encrypted and held to ransom until the victim agrees to the attackers demands.&lt;br /&gt;&lt;br /&gt;Ransomware programmes may also try to embarrass or scare their victims to get them to comply quickly, using dirty tactics like displaying pornographic images and threatening to expose them for possession of such material on their computer.&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/937-guid.html#extended&quot;&gt;Continue reading &quot;E-hijackers make a killing with 'ransomware'&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Tue, 08 Jul 2008 14:30:00 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/937-guid.html</guid>
    </item>
<item>
    <title>Microsoft Offers Bug Workaround for ActiveX Exploit</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/934-Microsoft-Offers-Bug-Workaround-for-ActiveX-Exploit.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/934-Microsoft-Offers-Bug-Workaround-for-ActiveX-Exploit.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=934</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=934</wfw:commentRss>
    <author>news@betterantivirus.com (Annette King)</author>
    <content:encoded>
Microsoft Relevant Products/Services on Monday issued a security advisory to warn users about attacks targeting a vulnerability in the ActiveX control for the Snapshot Viewer in the Microsoft Access database management system.&lt;br /&gt;&lt;br /&gt;Microsoft said it is investigating active, targeted attacks. &amp;quot;When a user views the Web page, the vulnerability could allow remote code execution,&amp;quot; Microsoft said in its security advisory. &amp;quot;An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.&amp;quot;&lt;br /&gt;&lt;br /&gt;The ActiveX control for the Snapshot Viewer enables users to view a Microsoft Access report snapshot without having the standard or run-time versions of Access. The vulnerability only affects the ActiveX control for the Snapshot Viewer for Microsoft Office Access 2000, Microsoft Office Access 2002, and Microsoft Office Access 2003.&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/934-guid.html#extended&quot;&gt;Continue reading &quot;Microsoft Offers Bug Workaround for ActiveX Exploit&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Tue, 08 Jul 2008 11:21:14 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/934-guid.html</guid>
    </item>
<item>
    <title>Trojan lurks, waiting to steal admin passwords</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/932-Trojan-lurks,-waiting-to-steal-admin-passwords.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/932-Trojan-lurks,-waiting-to-steal-admin-passwords.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=932</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=932</wfw:commentRss>
    <author>news@betterantivirus.com (Sean Cannon)</author>
    <content:encoded>
&lt;br /&gt;
Coreflood uses Microsoft admin tool to infect corporate networks, security firm says&lt;br /&gt;&lt;br /&gt;Writers of a password-stealing Trojan horse program have found that a little patience can lead to a lot of infections.&lt;br /&gt;&lt;br /&gt;They have managed to infect hundreds of thousands of computers, including more than 14,000 within one unnamed global hotel chain, by waiting for system administrators to log onto infected PCs and then using a Microsoft administration tool to spread their malicious software throughout the network.&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/932-guid.html#extended&quot;&gt;Continue reading &quot;Trojan lurks, waiting to steal admin passwords&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Tue, 08 Jul 2008 09:14:51 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/932-guid.html</guid>
    </item>
<item>
    <title>Trojan lurks, waiting to steal admin passwords</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/931-Trojan-lurks,-waiting-to-steal-admin-passwords.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/931-Trojan-lurks,-waiting-to-steal-admin-passwords.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=931</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=931</wfw:commentRss>
    <author>news@betterantivirus.com (Annette King)</author>
    <content:encoded>
&lt;br /&gt;
Writers of a password-stealing Trojan horse program have found that a little patience can lead to a lot of infections.&lt;br /&gt;&lt;br /&gt;They have managed to infect hundreds of thousands of computers, including more than 14,000 within one unnamed global hotel chain, by waiting for system administrators to log onto infected PCs and then using a Microsoft administration tool to spread their malicious software throughout the network.&lt;br /&gt;&lt;br /&gt;The criminals behind the Coreflood Trojan are using the software to steal banking and brokerage account usernames and passwords. They've amassed a 50GB database of this information from the machines they've infected, according to Joe Stewart, director of malware research at security vendor SecureWorks Inc.&lt;br /&gt;&lt;br /&gt;&amp;quot;They've been able to spread throughout entire enterprises,&amp;quot; he said. &amp;quot;That's something you rarely see these days.&amp;quot;&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/931-guid.html#extended&quot;&gt;Continue reading &quot;Trojan lurks, waiting to steal admin passwords&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Mon, 07 Jul 2008 21:15:00 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/931-guid.html</guid>
    </item>
<item>
    <title>Trojans stop play for web gamers</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/930-Trojans-stop-play-for-web-gamers.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/930-Trojans-stop-play-for-web-gamers.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=930</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=930</wfw:commentRss>
    <author>news@betterantivirus.com (Annette King)</author>
    <content:encoded>
&lt;br /&gt;
Malware aimed at online gamers posed the most serious online security threat in June, a security firm reported today.&lt;br /&gt;&lt;br /&gt;ESET found that 13.29 per cent of malware detections from a sample of over 10 million systems worldwide were classified as 'Win32/PSW.OnLineGames'.&lt;br /&gt;&lt;br /&gt;Although this figure is significantly down from last month's 18 per cent, ESET warned that this &amp;quot;does not necessarily&amp;quot; mean a drop in the number of infections.&lt;br /&gt;&lt;br /&gt;Win32/PSW.OnLineGames is a family of Trojans with key-logging and rootkit capabilities that gathers information relating to online gaming.&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/930-guid.html#extended&quot;&gt;Continue reading &quot;Trojans stop play for web gamers&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Fri, 04 Jul 2008 14:30:00 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/930-guid.html</guid>
    </item>
<item>
    <title>A Worm That Does Nothing</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/928-A-Worm-That-Does-Nothing.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/928-A-Worm-That-Does-Nothing.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=928</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=928</wfw:commentRss>
    <author>news@betterantivirus.com (Annette King)</author>
    <content:encoded>
&lt;br /&gt;
A Worm That Does Nothing&lt;br /&gt;&lt;br /&gt;This weeks e-threats activity was pretty odd. We have proxy servers, trojans, patchers and the one that beats them all, a worm that does nothing but spread.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Trojan.Asprox.F&lt;/u&gt;&lt;br /&gt;Upon execution this trojan installs itself in the Windows directory and executes at startup as a system process. It's function is that of a proxy server. It listens for connections on TCP ports 80 and 82. It is spreading through compromised websites which make use of the ADODB Javascript exploit that downloads the Trojan on your computer without any interaction. The websites themselves are cracked using SQL Injection exploits. The ugly thing about this is that whenever you visit a website like this you get infected simply by browsing it, if you are using Internet Explorer that is. The Javascript exploit is harmless on other browsers, it will just increase the loading time of the page.&lt;br /&gt;&lt;br /&gt;It seems that a lot of effort is being put into spreading this proxy, so the intentions behind it are probably serious cracking and spamming attempts.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.bitdefender.com/VIRUS-1000321-en--VBS.Worm.Runauto.A.html&quot;&gt;&lt;u&gt;VBS.Worm.Runauto.A&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;It's the strangest thing nowadays. This worm seems not to have any destructive intention. It is only spreading. We say it's strange because usually no more malware is out there without having a negative effect on the victims PC, be it downloading other applications, infecting or deleting files, running backdoors and rootkits, you name it. It uses the most basic hiding methods, merely setting hidden and read only attributes on its own file(s). It also copies itself into your windows and windowssystem32 directories and adds some registry entries to run on system startup. It is spreading through removable drives and uses autorun.inf files to execute itself.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;NOTE: We at Computer Security Solutions are leary of this worm. If your NOD32 detectes it, click to remove, report or repair. If NOD32 is unable to do so, boot into safe mode and run a full scan. We suspect the author of this worm may be setting the groundwork for a future attack or to plant infections on your computer.&lt;/b&gt;&lt;br /&gt; &lt;br /&gt;&lt;u&gt;&lt;a title=&quot;Fix Trojan.Qhost.AKR&quot;&gt;Trojan.Qhost.AKR&lt;/a&gt;&lt;/u&gt; &lt;br /&gt;This threat patches the BitDefender products (Internet Security 2008, Total Security 2008 and Antivirus Plus 2008). It has a nicely built user interface and detailed instructions on how to use it. At some point you are requested to push a button that will add an entry to your system32driversetchosts file. It will set the BitDefender update server (update.bitdefender.com) to localhost (127.0.01). It seems this Trojans purpose is to render the BitDefender products update service unusable so it will not detect new threats anymore.&lt;u&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.malwarecity.com/blog/a-worm-that-does-nothing-97.html&quot; target=&quot;_top&quot; title=&quot;Original Story&quot;&gt;Original Story&lt;/a&gt;&lt;/u&gt;    </content:encoded>
    <pubDate>Thu, 03 Jul 2008 13:27:55 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/928-guid.html</guid>
    </item>
<item>
    <title>Web threats hit 12-month high</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/921-Web-threats-hit-12-month-high.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/921-Web-threats-hit-12-month-high.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=921</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=921</wfw:commentRss>
    <author>news@betterantivirus.com (Annette King)</author>
    <content:encoded>
The number of new malicious websites rose by 58 per cent in June to its highest level since April 2007, security experts warned today.&lt;br /&gt;&lt;br /&gt;The latest MessageLabs Intelligence Report attributed the rise to a jump in the number of spyware and adware sites being blocked.&lt;br /&gt;&lt;br /&gt;&amp;quot;Web-based malware has become a dangerous tool in the arsenal of cyber-criminals,&amp;quot; said Mark Sunner, chief security analyst at MessageLabs.&lt;br /&gt;&lt;br /&gt;&amp;quot;The bad guys know that web-borne attacks are uncharted territory for many computer users and are taking advantage of this in addition to vulnerabilities and weak security in web applications.&amp;quot;&lt;br /&gt;&lt;br /&gt;Sunner added that businesses that allow employee access to any website, and sites with webmail accounts that have not been scanned by corporate security systems, are at particular risk.&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/921-guid.html#extended&quot;&gt;Continue reading &quot;Web threats hit 12-month high&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Wed, 02 Jul 2008 14:28:00 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/921-guid.html</guid>
    </item>
<item>
    <title>Author of peer-to-peer computer virus captured</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/923-Author-of-peer-to-peer-computer-virus-captured.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/923-Author-of-peer-to-peer-computer-virus-captured.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=923</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=923</wfw:commentRss>
    <author>news@betterantivirus.com (Annette King)</author>
    <content:encoded>
Milmont said in an e-mail exchange tonight that he has suffered from a brain tumor from an early age that was discovered when he was 16, around when he began work on the virus.&lt;br /&gt;&lt;br /&gt;&amp;quot;It is obvious to me and my family that this greatly affected my mental, physical and emotional state,&amp;quot; Milmont wrote. &amp;quot;Most of the illegal activity took place before I was 18, and I wouldn't do it today.&amp;quot;&lt;br /&gt;&lt;br /&gt;Federal authorities say they have captured the author of an innovative computer virus that infected as many as 15,000 PCs last year.&lt;br /&gt;&lt;br /&gt;Jason Michael Milmont, 19, agreed to plead guilty (you can download a PDF of the plea agreement here) in his hometown of Cheyenne, Wyo., to a federal felony charge of unauthorized access to a computer to further a fraud, according to court documents. He reached the deal with prosecutors in Los Angeles and could face as many as five years in prison.&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/923-guid.html#extended&quot;&gt;Continue reading &quot;Author of peer-to-peer computer virus captured&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Tue, 01 Jul 2008 15:42:00 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/923-guid.html</guid>
    </item>
<item>
    <title>Google among top malware offenders</title>
    <link>http://www.betterantivirus.com/nod32-and-virus-news/archives/920-Google-among-top-malware-offenders.html</link>
<category>Adware, Spyware and Trojans</category>    <comments>http://www.betterantivirus.com/nod32-and-virus-news/archives/920-Google-among-top-malware-offenders.html#comments</comments>
    <wfw:comment>http://www.betterantivirus.com/nod32-and-virus-news/wfwcomment.php?cid=920</wfw:comment>
    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.betterantivirus.com/nod32-and-virus-news/rss.php?version=2.0&amp;type=comments&amp;cid=920</wfw:commentRss>
    <author>news@betterantivirus.com (Sean Cannon)</author>
    <content:encoded>
NEW DELHI: This is one ranking Google could have done without. According to a recent report by Internet consumer advocacy group Stopbadware.org, Google is one of the top five networks responsible for hosting dangerous websites.&lt;br /&gt;&lt;br /&gt;The study describes &amp;quot;badware&amp;quot; as &amp;quot;spyware, malware and deceptive adware.&amp;quot;&lt;br /&gt;&lt;br /&gt;Google recorded some 213,575 individual websites, till May this year, which StopBadware then mapped to IP addresses.&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://www.betterantivirus.com/nod32-and-virus-news/archives/920-guid.html#extended&quot;&gt;Continue reading &quot;Google among top malware offenders&quot;&lt;/a&gt;    </content:encoded>
    <pubDate>Tue, 01 Jul 2008 09:45:19 -0600</pubDate>
    <guid isPermaLink="false">http://www.betterantivirus.com/nod32-and-virus-news/archives/920-guid.html</guid>
    </item>
</channel>
</rss>
