<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebProNews &#187; worm</title>
	<atom:link href="http://www.webpronews.com/tag/worm/feed" rel="self" type="application/rss+xml" />
	<link>http://www.webpronews.com</link>
	<description>Breaking News in Tech, Search, Social, &#38; Business</description>
	<lastBuildDate>Sun, 12 Feb 2012 22:29:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Scary New Virus Will Make Your Computer Cry</title>
		<link>http://www.webpronews.com/super-virus-2012-01</link>
		<comments>http://www.webpronews.com/super-virus-2012-01#comments</comments>
		<pubDate>Fri, 27 Jan 2012 20:19:09 +0000</pubDate>
		<dc:creator>Zach Walton</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Computer]]></category>
		<category><![CDATA[scary]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=93075</guid>
		<description><![CDATA[It’s natural for viruses to mutate in nature and become stronger over time. The scary thing is that it’s now happening to computer viruses. Mutating viruses are nothing new, they are used to infect machines in a way that can’t &#8230;]]></description>
			<content:encoded><![CDATA[<p>It’s natural for viruses to mutate in nature and become stronger over time. The scary thing is that it’s now happening to computer viruses. </p>
<p>Mutating viruses are nothing new, they are used to infect machines in a way that can’t be stopped by traditional anti-virus software. The problem comes in with a new report from <a href="http://softwin.ro/?pagina=index&#038;&#038;limba=2">Softwin</a>, the Romania based anti-virus software company that makes BitDefender, that says they have found multiple instances of computers being infected by worms that have previously been infected by a virus. They consider it a new “Frankenstein piece of malware” that has the potential to cause a lot of damage. </p>
<p>For those who perhaps don’t know a lot of viruses and worms, a worm is usually an executable file while a virus infects executables. The inevitable problem arises when a virus infects the executable that a worm resides in. </p>
<p>Fortunately, the researchers at BitDefender have no evidence at this point that the new super virus is any worse than a traditional virus. The concern is that worms are better at moving through systems, so a virus attached to a worm will have an easier time moving through a system. </p>
<p>The research team found 40,000 instances of the mutated malware out of a sample of 10 million files. One example was a virus designed to create back doors for hackers infected a worm that steals passwords. Their combination resulted in a mutation that could steal passwords while simultaneously creating a backdoor for the hacker to access the stolen information. </p>
<p><a href="http://www.physorg.com/news/2012-01-bitdefender-evidence-viruses-infecting-worms.html">PhysOrg</a> brings up an interesting point in that a virus&#8217; main goal is to cause destruction. So in theory, a virus should destroy whatever it infects including the worm. The researchers never addressed this, but there’s a possibility that the virus could destroy the worm before it does any damage. </p>
<p>The researchers say that the combination of the two malware types was unintentional. The issue raised now is that hackers know it’s possible to combine the two. If it does occur, it could “pose a very serious threat to computers and networks the world over.” </p>
<p>For more examples of how this new super virus can destroy your computer, check out an expert analysis <a href="http://www.malwarecity.com/blog/virus-infects-worm-by-mistake-1246.html">here.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/super-virus-2012-01/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Facebook Publicly Unmasks Koobface Hackers</title>
		<link>http://www.webpronews.com/facebook-publicly-unmasks-koobface-hackers-2012-01</link>
		<comments>http://www.webpronews.com/facebook-publicly-unmasks-koobface-hackers-2012-01#comments</comments>
		<pubDate>Tue, 17 Jan 2012 18:04:08 +0000</pubDate>
		<dc:creator>Mike Tuttle</dc:creator>
				<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=89919</guid>
		<description><![CDATA[The New York Times reported yesterday on a powerful &#8220;web gang&#8221; that have been pocketing millions of dollars from unsuspecting web surfers using a worm dubbed &#8220;Koobface&#8221; (an anagram of &#8220;Facebook&#8221;). Apparently, it is known who they are. It is &#8230;]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.nytimes.com/2012/01/17/technology/koobface-gang-uses-facebook-to-spread-powerful-worm.html">New York Times reported</a> yesterday on a powerful &#8220;web gang&#8221; that have been pocketing millions of dollars from unsuspecting web surfers using a worm dubbed &#8220;Koobface&#8221; (an anagram of &#8220;Facebook&#8221;). Apparently, it is known who they are. It is known where they are. It is known how they do what they do. But, no one is touching them.</p>
<p>The men involved in this enterprise have been the subject of much investigation by Facebook&#8217;s security team, as well as by independent researcher Jan Droemer. But, it&#8217;s not like they are taking pains to hide. They post photos of their vacation trips to Monte Carlo, Spain and casinos in Germany. They check in on FourSquare.</p>
<p>“We’ve had a picture of one of the guys in a scuba mask on our wall since 2008,” said Ryan McGeehan, manager of investigations and incident response at Facebook.</p>
<p>The five men in this &#8220;gang&#8221; are:</p>
<p>   * Anton Korotchenko AKA “KrotReal”<br />
   * Stanislav Avdeyko AKA “leDed”<br />
   * Svyatoslav E. Polichuck AKA “PsViat” and “PsycoMan”<br />
   * Roman P. Koturbach AKA “PoMuc”<br />
   * Alexander Koltysehv AKA “Floppy.” </p>
<p>Yes, they are Russian. And they operate openly in central St. Petersburg. Which explains why the FBI have not nabbed them. In the absence of cooperation with the police in Russia, Facebook decided to out these guys publicly.</p>
<p>“People who engage in this type of stuff need to know that their name and real identity are going to come out eventually and they’re going to get arrested and they’re going to be targeted,” Joe Sullivan, chief security officer at Facebook said. “People are fighting back.” </p>
<p>How Koobface works, and how you can protect yourself from it, was the topic of an <a href="http://nakedsecurity.sophos.com/questions-and-answers-about-koobface/">excellent write-up on Sophos</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/facebook-publicly-unmasks-koobface-hackers-2012-01/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Most Email Was Spam In 2007</title>
		<link>http://www.webpronews.com/most-email-was-spam-in-2007-2008-01</link>
		<comments>http://www.webpronews.com/most-email-was-spam-in-2007-2008-01#comments</comments>
		<pubDate>Fri, 11 Jan 2008 14:31:54 +0000</pubDate>
		<dc:creator>Mike Sachoff</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=43259</guid>
		<description><![CDATA[<p>Spam comprised 95 percent of all email traffic in 2007 according to anti-spam company SpamStopsHere.</p>
<p>Spammers experimented with attaching encoded messages in a variety of file formats including MP3, Zip, Excel, Word and PDF. MP3 spam proved to be short lived. Spammers attached MP3 files named after popular songs and artists. When a recipient opened the attachment an electronic voice delivered a message promoting a stock for a particular company.</p>]]></description>
			<content:encoded><![CDATA[<p>Spam comprised 95 percent of all email traffic in 2007 according to anti-spam company SpamStopsHere.</p>
<p>Spammers experimented with attaching encoded messages in a variety of file formats including MP3, Zip, Excel, Word and PDF. MP3 spam proved to be short lived. Spammers attached MP3 files named after popular songs and artists. When a recipient opened the attachment an electronic voice delivered a message promoting a stock for a particular company.</p>
<p>2007 was also the year of the &quot;Worm&quot;. The storm worm was created to infect PCs for the purpose of sending spam, or as a host computer that is able to infect other PCs. Experts have estimated the number of infected PCs could be as high as 10 million.</p>
<p>Phishing scams were also wide spread. Banking, IRS, <a href="http://search.ebay.com/search/search.dll?from=R40&amp;_trksid=m37&amp;satitle=spam&amp;category0=" title="Spam">eBay</a> and <a href="https://www.paypal.com/" title="Spam Phishing">PayPal</a> phishing attacks increased significantly in 2007.</p>
<p>&quot;2007 was a challenging year for the antispam industry and a phenomenal year for us,&quot; said Ted Green, President of <a href="http://www.spamstopshere.com/" title="Spam 2007">SpamStopsHere</a>. &quot;With spam reaching such critical levels, our customer base has grown substantially due to the simple fact that many of our competitors have difficulty keeping their antispam solutions up to date with the latest spam campaigns.&quot;</p>
<p><center><img border="0" align="center" src="http://images.ientrymail.com/webpronews/article_pics/sm_body/spamstopshere_logo.gif" alt="SpamStopsHere" title="SpamStopsHere" /></center></p>
<p>&quot;SpamStopsHere has a team of technicians that review spam 24 hours, seven days a week. This allows us to update our system every minute and block the latest spam campaigns.&quot;<br />
&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/most-email-was-spam-in-2007-2008-01/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Storm Worm Spreads In YouTube Spam</title>
		<link>http://www.webpronews.com/storm-worm-spreads-in-youtube-spam-2007-08</link>
		<comments>http://www.webpronews.com/storm-worm-spreads-in-youtube-spam-2007-08#comments</comments>
		<pubDate>Mon, 27 Aug 2007 23:53:04 +0000</pubDate>
		<dc:creator>WebProNews Staff</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[Labs]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Storm Worm]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=40060</guid>
		<description><![CDATA[One of the most prolific worms in recent memory has been seen in connection with spam that purports to be from a friend who wants you to see a YouTube video.
]]></description>
			<content:encoded><![CDATA[<p>One of the most prolific worms in recent memory has been seen in connection with spam that purports to be from a friend who wants you to see a YouTube video.<br />
<span id="more-40060"></span><br />
The link looks legitimate in the spams, but looks are deceiving in this case. The gang believed to be responsible for the Storm worm have been spamming people over the past weekend with fake YouTube links.</p>
<p>
McAfee researcher Vinoo Thomas said on the <a href=http://www.avertlabs.com/research/blog/index.php/2007/08/27/latest-nuwar-spamming-uses-youtube-lure/>Avert Labs blog</a> that the spammers now use a couple of ways to get the worm onto someone&#8217;s system. In the easiest scenario, a victim on a vulnerable system click the link and triggers an onslaught of browser and application exploits.</p>
<p>
If those don&#8217;t take hold on a system, the person visiting the fake YouTube page is encouraged to download and launch the attack manually. A screenshot of the scam showed dialog typical for download sites, where the viewer is told to click another link if the download does not begin within a short period of time.</p>
<p>
&#8220;We expect these spammers to continue to use these types of tactics,&#8221; said Dave Marcus, security research and communications manager at McAfee.</p>
<p>
<small></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/storm-worm-spreads-in-youtube-spam-2007-08/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MySpace Phishes For The Worm</title>
		<link>http://www.webpronews.com/myspace-phishes-for-the-worm-2006-12</link>
		<comments>http://www.webpronews.com/myspace-phishes-for-the-worm-2006-12#comments</comments>
		<pubDate>Tue, 05 Dec 2006 18:08:42 +0000</pubDate>
		<dc:creator>Autumn Davis</dc:creator>
				<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Delicious]]></category>
		<category><![CDATA[Digg]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[Reddit]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=33404</guid>
		<description><![CDATA[MySpace hooks the phising sites by removing the worm from user profiles.
]]></description>
			<content:encoded><![CDATA[<p>MySpace hooks the phising sites by removing the worm from user profiles.</p>
<table align="right" border="0" width="128">
<tbody>
<tr>
<td height="62" width="122"><a href="http://www.webproworld.com/viewtopic.php?p=334869#334869"><img src="http://images.ientrymail.com/CommentImage-4.gif" border="0" height="60" width="130"></a></td>
</tr>
</tbody>
</table>
<p>GET FREE ABERCROMBIE, HOLLISTER, AE CLOTHING!  Currently I have around fifteen messages of that nature, and some of an explicit nature, in my <a href="http://www.myspace.com/" class="bluelink">MySpace</a> message inbox.  What&#8217;s worse is that they appear to be sent from someone I know personally.</p>
<p>Hundreds of user profiles were inundated with similar content from contacts on their friends&#8217; lists, and many victims were left wondering why they had been removed as a friend.  </p>
<p>A worm that directed users to a phishing site, which MySpace discovered on Friday, caused the solicitation of messages.</p>
<p>Users who were redirected by the worm to one of the phishing sites were asked for their username and password, which was in turn used to gain access to their personal profiles on the site.  </p>
<p>Once access was gained, any number of spam mail could be sent to the contacts on the user&#8217;s profile.</p>
<p>The worm used Javascript to exploit Apple&#8217;s Quick Time player, which can be embedded into MySpace profiles.  </p>
<p>Once a profile was vulnerable, legitimate links on MySpace were replaced with infected links which led to the phishing sites.</p>
<p>MySpace&#8217;s over 70 million registered users could even have their profile infected simply by viewing a profile that had the worm.  </p>
<p>In order to rectify the situation, MySpace shut down all infected user profiles over the weekend, also shutting down five of the six phishing sites used to gain profile access.  The &#8220;place for friends&#8221; assures users that all profiles containing the infection have been deactivated.</p>
<p>Add to <a class="printMailTop" href="http://del.icio.us/post" onclick="window.open('http://del.icio.us/post?v=4&amp;partner=wpn&amp;noui&amp;jump=close&amp;url='+encodeURIComponent(location.href)+'&amp;title='+encodeURIComponent(document.title),'delicious','toolbar=no,width=700,height=400'); return false;"><img border="0" src="http://images1.ientrymail.com/webpronews/delicious-pic.png" /> Del.icio.us</a> | <a href="javascript:void window.open('http://digg.com/submit?phase=2&amp;url='+encodeURIComponent(window.location.href)+'&amp;ei=UTF-8','popup','width=520px,height=420px,status=0,location=0,resizable=1,scrollbars=1,left=100,top=50',0)"><img border="0" src="http://images1.ientrymail.com/webpronews/digg-pic.png" /> Digg</a>  | <a href="javascript:location.href='http://reddit.com/submit?url='+encodeURIComponent(location.href)+'&amp;title='+encodeURIComponent(document.title)"><img border="0" src="http://images.ientrymail.com/webpronews/reddit.png" />Reddit</a> | <a href="javascript:location.href='http://www.furl.net/storeIt.jsp?u='+encodeURIComponent(document.location.href)+'&amp;t='+encodeURIComponent(document.title)+' '"><img border="0" src="http://images1.ientrymail.com/webpronews/furl-pic.png" /> Furl</a></p>
<p>Autmn Davis is a staff writer for WebProNews covering ebusiness and technology.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/myspace-phishes-for-the-worm-2006-12/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flash Worm Leads to No MySpace Widget Love</title>
		<link>http://www.webpronews.com/flash-worm-leads-to-no-myspace-widget-love-2006-07</link>
		<comments>http://www.webpronews.com/flash-worm-leads-to-no-myspace-widget-love-2006-07#comments</comments>
		<pubDate>Fri, 21 Jul 2006 19:43:20 +0000</pubDate>
		<dc:creator>Ken Yarmosh</dc:creator>
				<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Craigslist]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[leads]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[TechCrunch]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[widget]]></category>
		<category><![CDATA[widgets]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=30493</guid>
		<description><![CDATA[<a href="http://www.techcrunch.com/2006/07/20/myspace-security-measure-disables-viral-spread-of-widgets/" class="bluelink">TechCrunch is reporting</a> that third-party MySpace widgets such as those by the ever popular YouTube are no longer allowed to have link throughs.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.techcrunch.com/2006/07/20/myspace-security-measure-disables-viral-spread-of-widgets/" class="bluelink">TechCrunch is reporting</a> that third-party MySpace widgets such as those by the ever popular YouTube are no longer allowed to have link throughs.</p>
<p>This move is due to recent past security issues, including a flash based worm &#8220;that had spread far and wide through the site and sent users to an off site page claiming that the U.S. government was behind the 9/11 terrorist attacks&#8221;:<br />
<blockquote>Just as javascript has been unusable in MySpace, most flash objects are also now unable to link out to third party sites when viewed with Flash player 9. MySpace users are now being encouraged to download a beta version of Flash 9 in order to view MySpace hosted video. When they do so, almost all other widgets (YouTube, etc) no longer link out to third party sites because of code inserted by MySpace after a security breach last weekend. Some flash widgets appear unaffected but there is no clear reason why. Being displayed in a music section profile is the only thing that I and several friends could see as different between the few widgets that still link out and those that don&#8217;t.</p></blockquote>
<p>What&#8217;s happening with MySpace is not dissimilar from what we saw occur with Oodle, <a href="http://www.technosight.com/blog/another-mash-up-mess-up/" class="bluelink">when craigslist pulled their data</a>. This change holds some pretty huge implications, including that <b>so many new web services have been betting on the MySpace strategy to spur adoption and grow their userbase.</b> Herein lies the problem of what we perceive is the &#8220;new web&#8221;. It&#8217;s not always as open and social, as we make it out to be. People are still concerned about dollar $igns.</p>
<p>Indeed, MySpace is showing more and more that they are very concerned about maintaining and protecting their little world from others monopolizing on and monteizing their investment (think SingleStat.us, DatingAnyone, and other services they shutdown). In other words, if you want to take advantage of MySpace, then fork over the cash for advertising.</p>
<p>MySpace was clever with this move though &#8211; they didn&#8217;t stop those widgets from being on the site. That would have caused a huge backlash from the MySpace crowd. Instead, they put an additional step between the widget and the user. Now, they have to do a search for the widget, instead of just clicking it. With the pathetic attention span of most MySpacers, that&#8217;s actually pretty significant (and at the same time, quite sad).</p>
<p><a href=" http://del.icio.us/post"onclick="window.open('   http://del.icio.us/post?v=4&#038;partner=xxx&#038;noui&#038;jump=close&#038;url='+encodeURIComponent(location.href)+'&#038;title='+encodeURIComponent(  document.title),  'delicious','toolbar=no,width=700,height=400'); return false;" CLASS="printMailTop"><span   CLASS="printMailTopAquo">&raquo;</span>&nbsp;Del.icio.us</a> | <a href="javascript:void     window.open('http://digg.com/submit?phase=2&#038;url='+encodeURIComponent(window.     location.href)+'&#038;ei=UTF-8','popup','width=520px,height=420px,status=0,locati     on=0,resizable=1,scrollbars=1,left=100,top=50',0)">DiggThis</a>  | <a href="javascript:void     window.open('http://myweb2.search.yahoo.com/myresults/bookmarklet?t='+encode     URIComponent(document.title)+'&#038;u='+encodeURIComponent(window.location.href)+     '&#038;tag=','popup','width=520px,height=420px,status=0,location=0,resizable=1,sc rollbars=1,left=100,top=50',0)">Yahoo! My     Web</a> | <a href="javascript:location.href='http://www.furl.net/storeIt.jsp?u='+encodeUR     IComponent(document.location.href)+'&#038;t='+encodeURIComponent(document.title)+ ' '">Furl</a></p>
<p><a href="http://www.technosight.com/">Ken Yarmosh</a> is a consultant who helps organizations get the most out of their technology investments. He works with technology users and creators across various industries, focusing on technology education and strategy. With over 7 years IT experience, Ken has worked with small businesses, non-profits, federal agencies, and multi-million dollar companies. </p>
<p>His online efforts include acting as the Editor for the Corante Technology Hub and authoring the <a href="http://www.technosight.com/blog/">TECHNOSIGHT</a> blog.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/flash-worm-leads-to-no-myspace-widget-love-2006-07/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ho Ho No! Santa Worm On IM</title>
		<link>http://www.webpronews.com/ho-ho-no-santa-worm-on-im-2005-12</link>
		<comments>http://www.webpronews.com/ho-ho-no-santa-worm-on-im-2005-12#comments</comments>
		<pubDate>Tue, 20 Dec 2005 18:29:36 +0000</pubDate>
		<dc:creator>WebProNews Staff</dc:creator>
				<category><![CDATA[Search]]></category>
		<category><![CDATA[Santa]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=25284</guid>
		<description><![CDATA[Users of instant messaging systems MSN, AIM, ICQ, and Yahoo could get smacked with a worm that entices people to click on a link to Santa Claus.
]]></description>
			<content:encoded><![CDATA[<p>Users of instant messaging systems MSN, AIM, ICQ, and Yahoo could get smacked with a worm that entices people to click on a link to Santa Claus.</p>
<p>This gift is one you&#8217;ll wish you&#8217;d never opened. The IM.GiftCom.All worm arriving by those IM systems or over Windows Messenger appears to be a URL linked to a picture of Santa Claus. IMLogic, which discovered the worm, <a href=http://tc.imlogic.com/threatcenterportal/pubThreatDetail.aspx?ThreatID=3399 class=bluelink>posted</a> that clicking the URL launches an executable file.</p>
<p>Once that file gets started, it embeds itself into the PC as a rootkit, and scans the registry, file system, and Internet cache. IMLogic also said the process hides from antivirus and other system tools that might detect it. The worm also logs keystrokes and may also try to spread itself to other users over IM to usernames it grabs from those services on the infected PC.</p>
<p>While its method of distribution doesn&#8217;t make it a big threat, the amount of damage it can do to a system caused IMLogic to rate it as a Medium threat, a company executive <a href=http://news.com.com/Santa+IM+worm+hits+AOL%2C+MSN+and+Yahoo/2100-7349_3-6002790.html class=bluelink>told</a> CNet News.</p>
<p>Users and administrators should ensure they are running the most current versions of their antivirus engines and that signature files have been updated to help repel the threat. Also, people will want to be careful about clicking on links in messages that arrive unexpectedly, even if they appear to be from a legitimate messaging buddy.</p>
<p>&#8212;<br />
Email the author <A HREF="&#109;&#97;&#105;&#108;&#116;&#111;&#58;&#100;&#117;&#116;&#116;&#101;&#114;&#64;&#105;&#101;&#110;&#116;&#114;&#121;&#46;&#99;&#111;&#109;">here</A>.</p>
<p>Add to <script language='javascript'> document.write("<a href='http://del.icio.us/post?url="+encodeURIComponent(document.location.href)+"&#038;title="+encodeURIComponent(document.title)+"'>Del.icio.us</a>") </script> | <a href="javascript:void window.open('http://myweb2.search.yahoo.com/myresults/bookmarklet?t='+encodeURIComponent(document.title)+'&#038;u='+encodeURIComponent(window.location.href)+'&#038;ei=UTF-8','popup','width=520px,height=420px,status=0,location=0,resizable=1,scrollbars=1,left=100,top=50',0)">Yahoo My Web</a></p>
<p><script language=JavaScript src="http://aj.600z.com/aj/1095/0/vj?z=1&#038;dim=1088&#038;pos=15"></script></p>
<p>David Utter is a staff writer for WebProNews covering technology and business. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/ho-ho-no-santa-worm-on-im-2005-12/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sober Worm Algorithms Finnished</title>
		<link>http://www.webpronews.com/sober-worm-algorithms-finnished-2005-12</link>
		<comments>http://www.webpronews.com/sober-worm-algorithms-finnished-2005-12#comments</comments>
		<pubDate>Fri, 09 Dec 2005 13:31:02 +0000</pubDate>
		<dc:creator>WebProNews Staff</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=25075</guid>
		<description><![CDATA[The scheme used by the virus writer behind the Sober worms to determine where it will connect on the Internet has been cracked by the Finnish security firm.
]]></description>
			<content:encoded><![CDATA[<p>The scheme used by the virus writer behind the Sober worms to determine where it will connect on the Internet has been cracked by the Finnish security firm.</p>
<p>Another huge outbreak of the Sober worm has been scheduled to happen on January 6th, 2006. However, thanks to Mikko Hyppnen and <a href=http://www.f-secure.com/weblog/archives/archive-122005.html#00000729 class=bluelink>Finnish security firm F-Secure</a>, admins everywhere now have the information to take steps and block infected machines from hitting a URL where a new version of Sober can be obtained and installed.</p>
<p>F-Secure has had the information since May 2005. &#8220;(W)e informed the local police in Germany as well as the affected ISPs (in May). But we didn&#8217;t want to talk about it publicly then &#8211; we didn&#8217;t want to fill in the virus writer on this. But he must know this by now,&#8221; Hyppnen wrote.</p>
<p>An algorithm in Sober generates pseudorandom URLs based on the date. 99 percent of the URLs created don&#8217;t exist. The URLs, which point to free hosting servers in Germany and Austria, can be determined by Sober&#8217;s creator ahead of time. </p>
<p>Then he can create the URL at the free hosting site at the right date to get the latest version of the worm onto any infected machine that can connect to the URL.</p>
<p>That list changes every 14 days, and a change has already been scheduled in existing versions of Sober on January 6th. Admins who block connections at the firewall to freenet.de, pages.at, and arcor.de should thwart any undetected Sober-infected machines on their networks, according to the report.</p>
<p>Previous outbreaks of Sober have delivered millions of Nazi propaganda messages to inboxes worldwide. Putting that to an end would be a tremendous benefit to users everywhere.</p>
<p><script language=JavaScript src="http://aj.600z.com/aj/1095/0/vj?z=1&#038;dim=1088&#038;pos=15"></script></p>
<p>David Utter is a staff writer for WebProNews covering technology and business. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/sober-worm-algorithms-finnished-2005-12/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Worm Sobers Up FBI, CIA</title>
		<link>http://www.webpronews.com/worm-sobers-up-fbi-cia-2005-11</link>
		<comments>http://www.webpronews.com/worm-sobers-up-fbi-cia-2005-11#comments</comments>
		<pubDate>Wed, 23 Nov 2005 18:14:45 +0000</pubDate>
		<dc:creator>John Stith</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[CIA]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=24772</guid>
		<description><![CDATA[The ever-popular Sober worm is making the rounds again in a new and exciting format. The ugly little worm is circulating through email and it looks all nice and official because someone is receiving email from either the FBI or the CIA. Many may ask what they've done wrong to warrant attention from the FBI or CIA. Nothing much really you just happen to have an email account.
]]></description>
			<content:encoded><![CDATA[<p>The ever-popular Sober worm is making the rounds again in a new and exciting format. The ugly little worm is circulating through email and it looks all nice and official because someone is receiving email from either the FBI or the CIA. Many may ask what they&#8217;ve done wrong to warrant attention from the FBI or CIA. Nothing much really you just happen to have an email account.</p>
<p>The message on the CIA&#8217;s website reads:</p>
<p><b>Some members of the public have in the past few days received a bogus e-mail falsely attributed to CIA&#8217;s Office of Public Affairs. CIA did not send that message. In fact, it does not send unsolicited e-mail to the general public, period. If you have gotten such a message, we strongly encourage you not to open the attachment, which contains a destructive virus.</b></p>
<p>	<a href="http://www.securitypronews.com/news/securitynews/spn-45-20051122FBIVictimofEmailFraud.html" class="bluelink">SecurityProNews</a> did a story on the FBI email yesterday. It seems some individuals felt particularly testosterone laden and elected to choose not only the FBI, but also the CIA for their malicious endeavors. </p>
<p>	Like the FBI emails, the CIA emails look official, coming from addresses tagged with cia.gov. They will tell users to fill out the form attached. When users open the attachment, it turns out to be the virus. The email says the user has been visiting illegal websites and the CIA/FBI knows about it (not entirely implausible) and that the user should answer the attached questions. </p>
<p>	One might question the sanity of those spreading such maliciousness using the name of the FBI or the CIA. They might think they really won&#8217;t get caught. Chances are though, this is just an odd form of job application.  </p>
<p><script language=JavaScript src="http://aj.600z.com/aj/1095/0/vj?z=1&#038;dim=1088&#038;pos=15"></script></p>
<p>John Stith is a staff writer for WebProNews covering technology and business. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/worm-sobers-up-fbi-cia-2005-11/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AIM Worm Installs Rootkit</title>
		<link>http://www.webpronews.com/aim-worm-installs-rootkit-2005-10</link>
		<comments>http://www.webpronews.com/aim-worm-installs-rootkit-2005-10#comments</comments>
		<pubDate>Fri, 28 Oct 2005 14:35:52 +0000</pubDate>
		<dc:creator>WebProNews Staff</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[AIM]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=24178</guid>
		<description><![CDATA[FaceTime Security Labs reported that a variant of the Sdbot worm has been making the rounds on AIM via chats and instant messaging.
]]></description>
			<content:encoded><![CDATA[<p>FaceTime Security Labs reported that a variant of the Sdbot worm has been making the rounds on AIM via chats and instant messaging.</p>
<p>You&#8217;ve got rootkit, and spyware, and a host of problems if your antivirus software isn&#8217;t up to date. A worm circulating through the AIM network can be a serious problem for PCs, FaceTime <a href=http://www.facetime.com/pr/pr051028.aspx class="bluelink">said in a release</a>.</p>
<p>A machine victimized by the worm will experience a whole bunch of problems:</p>
<p><i>
<div style=margin-left:10px; margin-right:10px;>&nbsp;&bull; Adds a lockx.exe rootkit that connects to an IRC server, awaiting remote commands from an attacker.<br />
&nbsp;&bull; Rootkits may be used by an intruder after cracking a computer system and often hides logins, processes, files, and logs. It may include software to intercept data from terminals, network connections, and the keyboard<br />
&nbsp;&bull; Acts as a vector for additional adware, worms and viruses<br />
&nbsp;&bull; Changes a viewer&#8217;s original search page to http://www.eza1netsearch.com/sp2.php<br />
&nbsp;&bull; Often increases the CPU usage to 100 percent after the malware is installed<br />
&nbsp;&bull; Downloads other applications, including 180Solutions, Zango, the Freepod Toolbar, MaxSearch, Media Gateway, and SearchMiracle</div>
<p></i><br />
AIM PC users should verify with their antivirus companies that their virus signatures and scanning engines have been updated, as always.</p>
<p>David Utter is a staff writer for WebProNews covering technology and business. Email him <A HREF="mailto:news@ientry.com">here</A>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/aim-worm-installs-rootkit-2005-10/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 1/49 queries in 0.027 seconds using memcached
Object Caching 630/750 objects using memcached

Served from: webpronews.com @ 2012-02-12 17:50:00 -->
