<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NVDi Support News &#38; Alerts &#187; Waledac</title>
	<atom:link href="http://news.nvdi.net/tag/waledac/feed/" rel="self" type="application/rss+xml" />
	<link>http://news.nvdi.net</link>
	<description>&#160;&#160;Support information and alerts for NVDi customers and friends</description>
	<lastBuildDate>Sun, 04 Apr 2010 20:54:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>Conficker starts serving up malware</title>
		<link>http://news.nvdi.net/2009/04/conficker-starts-serving-up-malware/</link>
		<comments>http://news.nvdi.net/2009/04/conficker-starts-serving-up-malware/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 02:36:34 +0000</pubDate>
		<dc:creator>wkwalker</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Downadup]]></category>
		<category><![CDATA[Spyware Protect 2009]]></category>
		<category><![CDATA[Waledac]]></category>

		<guid isPermaLink="false">http://news.nvdi.net/?p=76</guid>
		<description><![CDATA[As mentioned in the previous post, Conficker is stirring. After applying some code updates, it has started serving up malware. It&#8217;s typical of botnets like Conficker to be rented out in sections to various groups of dirtbags, so not all Conficker victims are getting identical infestations. Some systems are being infected with a fake antivirus [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in the previous post, Conficker is stirring. After applying some code updates, it has started serving up malware. It&#8217;s typical of botnets like Conficker to be rented out in sections to various groups of dirtbags, so not all Conficker victims are getting identical infestations.</p>
<p>Some systems are being infected with a fake antivirus application called &#8220;Spyware Protect 2009.&#8221; Once launched, it buries you in a blizzard of pop-ups claiming you are infected with any number of malware programs and offering to remove them for $49.95. (Looks like the price has gone up. The standard scareware demand used to be $39.95.)</p>
<p>Other Conficker nodes are being infected with &#8220;Waledac,&#8221; which establishes a back door for sending spam. Waledac also acts as a password-stealing Trojan, so victims face a privacy threat, as well.</p>
<p>Further reading . . .</p>
<p>PC World has <a href="http://www.pcworld.com/article/162891/conficker_reveals_its_business_model.html">a good overall write-up</a> and <a href="http://www.viruslist.com/en/weblog?weblogid=208187654">Kaspersky&#8217;s analysis provides additional detail</a>, especially about Spyware Protect 2009.</p>
]]></content:encoded>
			<wfw:commentRss>http://news.nvdi.net/2009/04/conficker-starts-serving-up-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

