<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>411 on Spyware &#187; Worms</title>
	<atom:link href="http://www.411-spyware.com/remove/worms/feed" rel="self" type="application/rss+xml" />
	<link>http://www.411-spyware.com</link>
	<description>411-Spyware.com</description>
	<lastBuildDate>Fri, 20 Nov 2009 02:05:11 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Sdbot.add</title>
		<link>http://www.411-spyware.com/remove-sdbot-add</link>
		<comments>http://www.411-spyware.com/remove-sdbot-add#comments</comments>
		<pubDate>Mon, 03 Aug 2009 01:55:41 +0000</pubDate>
		<dc:creator>Kristopher</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://www.411-spyware.com/?p=5072</guid>
		<description><![CDATA[<strong>Sdbot.add</strong> -- dubbed "W32/Sdbot-ADD" by Sophos -- is a worm more painful than watching the KardashSimpHiltonSonian sisters. Instead of ruining reality TVfa, Sdbot.add runs wild through unprotected local networks.  Once Sdbot.add is launched, it drops a rootkit that lets a hacker sneak into a backdoor of your computer. The Sdbot.add-enabled hacker then can control your computer remotely, through an IRC network. 

Sound worse than reading about KimJessParissica talking about their weight?

It is.  So close PerezHilton.com, and let me show you how to get rid of Sdbot.add.]]></description>
		<wfw:commentRss>http://www.411-spyware.com/remove-sdbot-add/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Invitation Card.zip</title>
		<link>http://www.411-spyware.com/remove-invitation-card-zip</link>
		<comments>http://www.411-spyware.com/remove-invitation-card-zip#comments</comments>
		<pubDate>Fri, 26 Jun 2009 19:44:02 +0000</pubDate>
		<dc:creator>Kristopher</dc:creator>
				<category><![CDATA[Worms]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://www.411-spyware.com/?p=4898</guid>
		<description><![CDATA[<a href="http://www.411-spyware.com/images/Twitter-invitation-card-zip.gif" title="Invitation Card.zip screenshot" rel="lightbox"><img src="http://www.411-spyware.com/images/Twitter-invitation-card-zip.gif" class="alignleft" alt="Invitation Card.zip screenshot" /></a> <strong>Invitation Card.zip</strong> is a worm attached to a scam email that pretends to be an invite to social networking site Twitter.com.
This Invitation Card.zip email reads:
<blockquote><strong>From:</strong> invitations@twitter.com
    <strong>Subject: Your friend invited you to twitter!</strong></blockquote>

If you open this Invitation Card.zip attachment, you'll launch W32.Ackantta.B@mm, a worm that will copy itself to your removable drives and shared folders, then spam your other friends. W32.Ackantta.B@mm then may download  a Trojan onto your machine, such as <a title="Invitation Card.zip is related to Trojan Vundo" href="http://www.411-spyware.com/remove-trojan-vundo">Trojan Vundo</a>.

I'm sure being part of a hacker's botnet sounds like a hot weekend, but if you'd rather spend your Sunday otherwise -- church? Family? Strip club? -- I can show you how to get rid of Invitation Card.zip and W32.Ackantta.B@mm, for free.]]></description>
		<wfw:commentRss>http://www.411-spyware.com/remove-invitation-card-zip/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif</title>
		<link>http://www.411-spyware.com/remove-your-dad-naked-hahahaha-pif</link>
		<comments>http://www.411-spyware.com/remove-your-dad-naked-hahahaha-pif#comments</comments>
		<pubDate>Sat, 06 Jun 2009 03:29:30 +0000</pubDate>
		<dc:creator>Kristopher</dc:creator>
				<category><![CDATA[Worms]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Skype worm]]></category>

		<guid isPermaLink="false">http://www.411-spyware.com/?p=4732</guid>
		<description><![CDATA[<a href="http://www.411-spyware.com/images/YOUR-MOTHER-NAKED-hahahaha.pif.gif" title="YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif screenshot" rel="lightbox"><img src="http://www.411-spyware.com/images/YOUR-MOTHER-NAKED-hahahaha.pif.gif" class="alignleft" alt="YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif screenshot" /></a> <strong>YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif</strong> is a Skype worm that spreads via messages from buddies on your contact list.  You'll get a message from a contact, asking you if you want to download an MS-DOS .pif extension file, titled YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif, YOUR-MOTHER-NAKED-hahahaha.pif, hahaa-lesbians-cats.PIF, OMG-GAY-DOGS.com, or OMG-lesbian_dogs.PIF.

If you accepted YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif, don't open it. If you launch YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif, you'll start spreading YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif to buds on your Skype contact list. YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif may also download more badware onto your system.  Check your Skype's download history, and see if you accidentally downloaded YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif. If you did, avoid restarting your computer -- if you reboot your system, the worm may execute.

Don't worry too much if you already opened YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif -- I'll show you how to get rid of YOUR &#8211; DAD &#8211; NAKED &#8211; hahahaha . pif for free.
]]></description>
		<wfw:commentRss>http://www.411-spyware.com/remove-your-dad-naked-hahahaha-pif/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Batzback.B</title>
		<link>http://www.411-spyware.com/remove-batzback-b</link>
		<comments>http://www.411-spyware.com/remove-batzback-b#comments</comments>
		<pubDate>Thu, 21 May 2009 23:32:04 +0000</pubDate>
		<dc:creator>Kristopher</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://www.411-spyware.com/?p=4613</guid>
		<description><![CDATA[Batzback.B -- dubbed "W32/Batzback-B" by Sophos -- is a worm more annoying and ultimately useless than the KardashSimpHiltonSonian sisters. Batzback.B's gig?  Not random product endorsements and claiming it's not fat -- Batzback.B just disables some of your computer's software, including system tools such as Folder Options, Task Manager, and Registry Editor. 

Batzback.B spreads via network and local drives, dropping a copy of itself on every drive it can access.

Batzback.B  sounds like a hot date, but I'd rather delete Batzback.B . You ready?]]></description>
		<wfw:commentRss>http://www.411-spyware.com/remove-batzback-b/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Worm.Fontra.F</title>
		<link>http://www.411-spyware.com/remove-worm-fontra-f</link>
		<comments>http://www.411-spyware.com/remove-worm-fontra-f#comments</comments>
		<pubDate>Tue, 19 May 2009 18:23:07 +0000</pubDate>
		<dc:creator>Kristopher</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://www.411-spyware.com/?p=4586</guid>
		<description><![CDATA[<img alt="Worm.Fontra.F" title="Worm.Fontra.F Screen Shot" src="http://www.411-spyware.com/images/Worm.Fontra.F.gif" style="border: 1px; float: left; margin: 0 10px 10px 0;" /> <strong>Worm.Fontra.F</strong> -- dubbed "W32/Fontra-F" by Sophos, "Virus.Win32.Fontra.c" by Kaspersky and F-Secure,  "W32/Vbbot" by Mcafee, and "Worm/Delf.ATB" by Grisoft  -- is a worm that spreads through folders connected with file-sharing apps, like BearShare or Limewire. The worm sneaks into these shared folders by replacing the folders' media files with its own zip archive -- without changing these media files' names. 

The only way to tell if you're infected with Worm.Fontra.F may be the inability to play Beyonce's latest single.

In which case, you may want to thank Worm.Fontra.F.]]></description>
		<wfw:commentRss>http://www.411-spyware.com/remove-worm-fontra-f/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Warezov</title>
		<link>http://www.411-spyware.com/remove-warezov</link>
		<comments>http://www.411-spyware.com/remove-warezov#comments</comments>
		<pubDate>Sat, 16 May 2009 18:43:30 +0000</pubDate>
		<dc:creator>Kristopher</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://www.411-spyware.com/?p=4588</guid>
		<description><![CDATA[<strong>Warezov</strong> is a family of worms that infect computers through spam. Emails carrying Warezov are usually styled like an undelivered message or software update, with Warezov attached. After Warezov sneaks into your system, it spams your contacts with a similar message, and attempts to download updated versions of itself from sites. The worm may also block your access to some sites by changing your computer's HOSTS file, and stop your security software by killing their related processes.

Warezov is a little bundle of joy, hmm?

Let me show you how to delete this badware.]]></description>
		<wfw:commentRss>http://www.411-spyware.com/remove-warezov/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Qakbot</title>
		<link>http://www.411-spyware.com/remove-w32-qakbot</link>
		<comments>http://www.411-spyware.com/remove-w32-qakbot#comments</comments>
		<pubDate>Fri, 15 May 2009 03:49:35 +0000</pubDate>
		<dc:creator>Kristopher</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://www.411-spyware.com/?p=4576</guid>
		<description><![CDATA[<strong>W32.Qakbot</strong> is a worm that spreads through resources shared on a network. Once W32.Qakbot nestles into your computer, the worm may steal personal information (think Outlook, FTP logins, keystrokes typed, sites visited, etc.), download more badware onto your PC, and allow a hacker to access your system.

Unless spending a weekend with a zombie computer sounds hot, let me show you how to remove W32.Qakbot.]]></description>
		<wfw:commentRss>http://www.411-spyware.com/remove-w32-qakbot/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Fiala.A</title>
		<link>http://www.411-spyware.com/remove-w32-fiala-a</link>
		<comments>http://www.411-spyware.com/remove-w32-fiala-a#comments</comments>
		<pubDate>Thu, 14 May 2009 14:56:59 +0000</pubDate>
		<dc:creator>Kristopher</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://www.411-spyware.com/?p=4565</guid>
		<description><![CDATA[<strong>W32.Fiala.A</strong>  is a worm that spreads itself through your removable drives. W32.Fiala.A blocks certain applications from launching, and, as an early birthday gift, W32.Fiala.A may drop Trojans on your PC (think Trojan Horse, Hacktool.Rootkit or Trojan.KillAV).

Thanks, W32.Fiala.A. 

Unless ID theft and zombie computers botnets sound like a hot weekend, let me show you how to get rid of W32.Fiala.A.]]></description>
		<wfw:commentRss>http://www.411-spyware.com/remove-w32-fiala-a/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Mocon</title>
		<link>http://www.411-spyware.com/remove-w32-mocon</link>
		<comments>http://www.411-spyware.com/remove-w32-mocon#comments</comments>
		<pubDate>Thu, 14 May 2009 08:22:40 +0000</pubDate>
		<dc:creator>Kristopher</dc:creator>
				<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://www.411-spyware.com/?p=4556</guid>
		<description><![CDATA[<strong>W32.Mocon</strong>  is a worm that spies on you by tracking your every keystroke.  This worm spreads itself through your removable drives.

Unless identity theft and botnets of zombie computers sound like a hot weekend, let me show you how to remove W32.Mocon.]]></description>
		<wfw:commentRss>http://www.411-spyware.com/remove-w32-mocon/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>INF/Conficker</title>
		<link>http://www.411-spyware.com/remove-inf-conficker</link>
		<comments>http://www.411-spyware.com/remove-inf-conficker#comments</comments>
		<pubDate>Tue, 12 May 2009 17:56:02 +0000</pubDate>
		<dc:creator>Kristopher</dc:creator>
				<category><![CDATA[Worms]]></category>
		<category><![CDATA[Conficker]]></category>

		<guid isPermaLink="false">http://www.411-spyware.com/?p=4528</guid>
		<description><![CDATA[<strong>INF/Conficker</strong> is the latest version of the headline-making Conficker worm. As usual, INF/Conficker blocks your access to security sites (such as McAfee.com, Microsoft.com, and Symantec.com) and anti-badware software (Windows Defender Service, Windows Security Center Service, and more). INF/Conficker has also been linked to pimping <a href="http://www.411-spyware.com/spyware-protect-2009-removal" title="INF/Conficker is related to Spyware Protect 2009">scareware Spyware Protect 2009</a>. So what's new with INF/Conficker? 

INF/Conficker gets its name as it spreads via an "autorun.inf." By doing this, Conficker can automatically infect every mapped and removable drive.  

Let's get rid of INF/Conficker before even more machines are infected.]]></description>
		<wfw:commentRss>http://www.411-spyware.com/remove-inf-conficker/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
