<?xml version="1.0" encoding="ISO-8859-1"?>

<!DOCTYPE rss PUBLIC "-//Netscape Communications//DTD RSS 0.91//EN"
 "http://my.netscape.com/publish/formats/rss-0.91.dtd">

<rss version="0.91">

<channel>
<title>the Gurus Online</title>
<link>http://www.eznuke.com/gurusonline</link>
<description>GurusOnline</description>
<language>en-us</language>

<item>
<title>Christmas Viruses</title>
<link>http://www.eznuke.com/gurusonline/modules.php?name=News&amp;file=article&amp;sid=12</link>
<description>Panda Software's weekly report on viruses and intruders -<br>&nbsp; &nbsp;Virus Alerts, by 
Panda Software (<a href="http://www.pandasoftware.com/">http://www.pandasoftware.com</a>)<br><br>Madrid, December 23 2005 
- This week's report looks at two Trojans<br>-MerryX.A and Mitglieder.GO-, and 
two worms -Dasher.A and Dasher.B-.<br><br>MerryX.A is a Trojan sent in an email 
with the following characteristics<br>relating to Christmas:<br><br>Subject: 
MERRY CHRISTMAS!<br><br>Message text: Merry Christmas and a Happy New 
Year!<br><br>Attachments: A_LIGHTSMC10.GIF, a picture of colored lights with 
the<br>words &quot;Merry Christmas&quot;; and MERRY CHRISTMAS!.RAR, a 
self-extractable<br>file containing two other files: SQLServer.exe, a copy of 
the Trojan,<br>and MERRY CHRISTMAS!.SWF, a Flash animation showing Father 
Christmas<br>leaving presents by a tree.<br><br>MerryX.A takes a series of 
actions on the computers it infects<br>including:<br><br>- It logs the 
keystrokes typed by the user. This can be used to capture<br>passwords or other 
kind of sensitive information, thus posing a threat<br>to the user's privacy. 
Then, it connects to a remote server, to which it<br>sends the information 
gathered.<br><br>- It attempts to download files from different websites. These 
can be<br>any type of file, including malware.<br><br>The second Tojan we're 
looking at today is Mitglieder.GO, which has been<br>sent massively via email by 
the Bagle.FX worm, in a message containing a<br>ZIP file.<br><br>Mitglieder.GO 
is a Trojan that connects every four hours to a random URL<br>selected from a 
list of websites included in its code in order to<br>download and run a file. 
This file can be of any nature, including<br>malware. When it is run this Trojan 
displays a Windows image.<br><br>We end today's report with Dasher.A and 
Dasher.B, two worms that spread<br>across the Internet. They spread in a 
self-extractable RAR file that<br>
search for IP addresses of computers with Windows 2003/XP/2000 affected<br>by the critical vulnerabilities reported by Microsoft in bulletin<br>MS05-051. The self-extractable RAR file is installed on vulnerable<br>computers in which Dasher.A and Dasher.B manage to exploit these<br>security problems.<br><br>If your computer has Windows 2003/XP/2000, it is advisable to download<br>and install the updates that resolve these vulnerabilities. More<br>information is available in Microsoft bulletin MS05-051.<br><br>More information about these and other threats is available from Panda<br>software's Encyclopedia at:<br><a>http://www.pandasoftware.com/virus_info/encyclopedia/</a><br><br>NOTE: The address above may not show up on your screen as a single line.<br>This would prevent you from using the link to access the web page. If<br>this happens, just use the 'cut' and 'paste' options to join the pieces<br>of the URL.<br><br><br>------------------------------------------------------------<br>To unsubscribe from Virus Alerts, please visit:<br><a>http://www.pandasoftware.com/unsubscribe.asp</a><br><br>To contact with Panda Software, please visit:<br><a>http://www.pandasoftware.com/about/contact/</a><br>------------------------------------------------------------<br>",0]
);

//-->
contains and installs other files that open port 1025. These files<br>search for 
IP addresses of computers with Windows 2003/XP/2000 affected<br>by the critical 
vulnerabilities reported by Microsoft in bulletin<br>MS05-051. The 
self-extractable RAR file is installed on vulnerable<br>computers in which 
Dasher.A and Dasher.B manage to exploit these<br>security problems.<br><br>If 
your computer has Windows 2003/XP/2000, it is advisable to download<br>and 
install the updates that resolve these vulnerabilities. More<br>information is 
available in Microsoft bulletin MS05-051.<br><br>More information about these 
and other threats is available from Panda<br>software's Encyclopedia at:<br><a href="http://www.pandasoftware.com/virus_info/encyclopedia/">http://www.pandasoftware.com/virus_info/encyclopedia/</a><br><br>NOTE: 
The address above may not show up on your screen as a single line.<br>This would 
prevent you from using the link to access the web page. If<br>this happens, just 
use the 'cut' and 'paste' options to join the pieces<br>of the URL.<br></description>
</item>

<item>
<title>New Virus steals Spanish bank info</title>
<link>http://www.eznuke.com/gurusonline/modules.php?name=News&amp;file=article&amp;sid=11</link>
<description>Orange Alert:Panda Software reports new Trojan that could steal<br>&nbsp; &nbsp; &nbsp; &nbsp;online 
banking passwords of thousands of Spanish-speaking users<br><br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 
&nbsp;Virus Alerts, by Panda Software<br>(<a href="http://www.pandasoftware.com/">http://www.pandasoftware.com</a>)<br><br>A new Trojan, Nabload.U, 
which is distributing itself through Messenger,<br>has appeared a few hours ago. 
This Trojan downloads another Trojan,<br>called Banker.bsx, which is currently 
the number one detected piece of<br>malware from Panda's ActiveScan. Its 
objective is to obtain the<br>passwords of certain banks that it has stored in 
its code primarily from<br>Spanish-speaking users.<br><br>The most unusual 
aspect of this Trojan is its ability to capture &nbsp;the<br>information without the 
use of a traditional key logger. The user will<br>be unaware that this is 
occurring. Banks that use virtual keyboards to<br>avoid keyloggers won't be 
protected from this Trojan.<br><br>Once the author has the keys, he can commit 
banking fraud with the<br>accounts.<br><br>According to Luis Corrons, PandaLabs 
director: &quot;This Trojan is an<br>example of a hybrid virus that mixes different 
techniques. Once the user<br>clicks on the URL, it is able to download a Trojan 
and use techniques<br>similar to some spyware and phishing attacks. It is, 
without a doubt, a<br>Trojan designed to steal data quickly, and &nbsp;without 
leaving any tracks.&quot;<br><br><br>Nabload.U uses social engineering techniques to 
get the user to click on<br>the URL provided. The sentence is in Spanish: &quot;ve 
esa vaina<br><a href="http://hometown.%eliminado%.au/miralafoto/foto.exe.">http://hometown.%eliminado%.au/miralafoto/foto.exe.</a>&quot; It 
is disguised as<br>a personal contact. When the user clicks on this URL, another 
Trojan,<br>
<a>http://hometown.%eliminado%.au/arqarq/coco2006.jpg</a> and<br><a>http://hometown.%eliminado%.au/modnatal/coco2006.jpg</a> that downloads a<br>configuration file. In this file, you can find - as well as other<br>information- the e-mail address where the stolen data will be sent.<br><br><br>This Trojan opens up port 1106 on the computer and stays active. So,<br>when the user tries to access &nbsp;one of the online bank addresses shown<br>bellow, the Trojan will be able to capture what the user is doing on the<br>screen, including the login and password typed by virtual keyboards to<br>access the bank account. This Trojan only captures the information from<br>the addresses below:<br><br><a>https://secure2.venezolano.com/</a><br><a>https://e-bdvcp.banvenez.com</a><br><a>https://www.ibprovivienda.com.ve/personas/</a><br><a>https://banco.micasaeap.com/individualmc/</a><br><a>https://olb.todo1.com/servlet/msfv/</a><br><a>https://www.banesco.com",1]
);

//-->
Banker.BSX, is downloaded. It also offers two others URLs_<br><a href="http://hometown.%eliminado%.au/arqarq/coco2006.jpg">http://hometown.%eliminado%.au/arqarq/coco2006.jpg</a> 
and<br><a href="http://hometown.%eliminado%.au/modnatal/coco2006.jpg">http://hometown.%eliminado%.au/modnatal/coco2006.jpg</a> that 
downloads a<br>configuration file. In this file, you can find - as well as 
other<br>information- the e-mail address where the stolen data will be 
sent.<br><br><br>This Trojan opens up port 1106 on the computer and stays 
active. So,<br>when the user tries to access &nbsp;one of the online bank addresses 
shown<br>bellow, the Trojan will be able to capture what the user is doing on 
the<br>screen, including the login and password typed by virtual keyboards 
to<br>access the bank account. This Trojan only captures the information 
from<br>the addresses below:<br><br><a href="https://secure2.venezolano.com/">https://secure2.venezolano.com/</a><br><a href="https://e-bdvcp.banvenez.com/">https://e-bdvcp.banvenez.com</a><br><a href="https://www.ibprovivienda.com.ve/personas/">https://www.ibprovivienda.com.ve/personas/</a><br><a href="https://banco.micasaeap.com/individualmc/">https://banco.micasaeap.com/individualmc/</a><br><a href="https://olb.todo1.com/servlet/msfv/">https://olb.todo1.com/servlet/msfv/</a><br><a href="https://www.banesco.com/servicios_electronicos_pag.htm">https://www.banesco.com
.htm</a><br><a>https://www.banesconline.com</a><br><a>https://www.provinet.net/shtml/</a><br><a>https://bod.bodmillenium.com</a><br><a>https://www.corp-line.com.ve/personas/</a><br><br>Once the Trojan has captured the information, it sends this data to an<br>e-mail address. The author can change this e-mail address as desired.<br><br>To help as many users as possible scan and disinfect their systems,<br>Panda Software offers its free, online anti-malware solution, Panda<br>ActiveScan, which now also detects spyware, at<br><a>http://www.activescan.com</a>. Webmasters who would like to include<br>ActiveScan on their websites can get the HTML code, free from<br><a>http://www.pandasoftware.com/partners/webmasters</a>.<br><br>TruPreventTM detection technologies detect and eliminate Banker.BSX with<br>no need for previous updates, so computers with these technologies have<br>been protected from the moment the Trojan Horse appeared.<br><br>For further information about Nabload.U and Banker.BSX, visit Panda<br>Software's Encyclopedia:<br><a>http://www.pandasoftware.com/virus_info/encyclopedia/</a><br><br>------------------------------",1]
);

//-->
/servicios_electronicos_pag.htm</a><br><a href="https://www.banesconline.com/">https://www.banesconline.com</a><br><a href="https://www.provinet.net/shtml/">https://www.provinet.net/shtml/</a><br><a href="https://bod.bodmillenium.com/">https://bod.bodmillenium.com</a><br><a href="https://www.corp-line.com.ve/personas/">https://www.corp-line.com.ve/personas/</a><br><br>Once the 
Trojan has captured the information, it sends this data to an<br>e-mail address. 
The author can change this e-mail address as desired.<br><br>To help as many 
users as possible scan and disinfect their systems,<br>Panda Software offers its 
free, online anti-malware solution, Panda<br>ActiveScan, which now also detects 
spyware, at<br><a href="http://www.activescan.com/">http://www.activescan.com</a>. 
Webmasters who would like to include<br>ActiveScan on their websites can get the 
HTML code, free from<br><a href="http://www.pandasoftware.com/partners/webmasters">http://www.pandasoftware.com/partners/webmasters</a>.<br><br>TruPreventTM 
detection technologies detect and eliminate Banker.BSX with<br>no need for 
previous updates, so computers with these technologies have<br>been protected 
from the moment the Trojan Horse appeared.<br><br>For further information about 
Nabload.U and Banker.BSX, visit Panda<br>Software's Encyclopedia:<br><a href="http://www.pandasoftware.com/virus_info/encyclopedia/">http://www.pandasoftware.com/virus_info/encyclopedia/</a><br><br></description>
</item>

<item>
<title>Post-holiday posting</title>
<link>http://www.eznuke.com/gurusonline/modules.php?name=News&amp;file=article&amp;sid=10</link>
<description>Now that the holidays are pretty much over, the Gurus will be online more often. Just like you, we have families, and have enjoyed some time with them, but now it's time for us to get back to work!</description>
</item>

<item>
<title>Internet Safety Guidelines for Kids</title>
<link>http://www.eznuke.com/gurusonline/modules.php?name=News&amp;file=article&amp;sid=9</link>
<description>From SafeKids.com - <br>
<br>
<div align="left">
<div align="center">
<br>

<strong>Kids' Rules for Online 
Safety</strong><br>
</div>
<strong><br>
<strong>

</strong></strong></div>
<strong><strong>           1.

I will not give out 
personal information such as my address, telephone number, parents&rsquo; work 
address/telephone number, or the name and location of my school without my 
parents&rsquo; permission.<br>
<br>
         2.

I will tell my parents 
right away if I come across any information that makes me feel 
uncomfortable. <br>
<br>
        3.

I will never agree to 
get together with someone I &quot;meet&quot; online without first checking with my 
parents. If my parents agree to the meeting, I will be sure that it is in a 
public place and bring my mother or father along.<br>
<br>
 4.

I will never send a 
person my picture or anything else without first checking with my 
parents. 


<br>
<br>
5.

I will not respond to 
any messages that are mean or in any way make me feel uncomfortable. It is not 
my fault if I get a message like that. If I do I will tell my parents right away 
so that they can contact the service provider. 


<br>
<br>
6.

I will talk with my 
parents so that we can set up rules for going online. We will decide upon the 
time of day that I can be online, the length of time I can be online and 
appropriate areas for me to visit. I will not access other areas or break these 
rules without their permission.<br>
<br>
 7.

I will not give out my 
Internet password to anyone (even my best friends) other than my 
parents.<br>
<br>
 8.

I will check with my 
parents before downloading or installing software or doing anything that could 
possibly hurt our computer or jeopardize my family&rsquo;s 
privacy<br>
<br>
 9.

I will be a good online 
citizen and not do anything that hurts other people or is against the 
law.<br>
<br>
 10.

I will help my parents 
understand how to have fun and learn things online and teach them things about 
the Internet, computers and other 
technology.<br>
<br>
<br>
</strong></strong><div align="center">

<strong><strong><font>Rules one through 
six are  adapted from the brochure <a href="http://gurusonline.eznuke.comchild_safety.htm">Child Safety on 
the Information Highway</a> by SafeKids.Com founder Larry Magid. (<font>&copy;</font> 2004 National Center for Missing and Exploited 
Children). Rules 7 through 10 are copyrighted by Larry Magid (<font>&copy; </font>2005)</font>
<br>
</strong></strong></div></description>
</item>

<item>
<title>Sober.AH world&#039;s most detected virus</title>
<link>http://www.eznuke.com/gurusonline/modules.php?name=News&amp;file=article&amp;sid=8</link>
<description>From Panda Software:<br>
<br>
Madrid, November 22 2005 - The Sober.AH worm, detected just a few hours
ago by PandaLabs, is now the most frequently detected virus worldwide,
according to data collected by the Panda ActiveScan online antivirus
solution.<br>
<br>
As was expected, and given the fact that this worm
sends itself in email messages in English or German depending on the
recipient's address, the United States and Germany have been, until
now, the countries most affected by Sober.AH. However, according to
data from PandaLabs, incidents have been recorded all around the world.<br>
</description>
</item>

<item>
<title>FBI reports E-Mail Scam, Worm</title>
<link>http://www.eznuke.com/gurusonline/modules.php?name=News&amp;file=article&amp;sid=7</link>
<description>From Techtree.com:<br>
<br>
The Federal Bureau of Investigation (FBI) has issued a 
press note warning the public to avoid falling victim to an on-going mass e-mail 
scheme, wherein computer users received unsolicited e-mails supposedly sent by 
the FBI. <br><br>These scam e-mails tell the recipients that their Internet use 
has been monitored by the agency, and that they have accessed illegal web sites. 
The e-mails then direct recipients to open an attachment and answer questions. 
<br><br>
</description>
</item>

<item>
<title>Latest Gurus Members</title>
<link>http://www.eznuke.com/gurusonline/modules.php?name=News&amp;file=article&amp;sid=6</link>
<description>Please welcome Gurus Online Alkazar and Gurus Online Dave to the ranks of the Gurus Online!</description>
</item>

<item>
<title>New Downloads</title>
<link>http://www.eznuke.com/gurusonline/modules.php?name=News&amp;file=article&amp;sid=5</link>
<description>We have added a number of new programs to our downloads section. Our
featured program is All In One Secretmaker, an awesome program that
provides all kinds of internet utilities, such as popup and spam
blocker, email scanner, intruder protection and more.<br>
</description>
</item>

<item>
<title>Guidelines of the Gurus Online</title>
<link>http://www.eznuke.com/gurusonline/modules.php?name=News&amp;file=article&amp;sid=4</link>
<description><div align="justify">As a member of the Gurus Online, there are certain
guidelines and standards we ask you to keep in mind in order to uphold
and maintain our reputation in the rooms.<br>
<br>
1. Remember that we function as helpers and chat ambassadors. As such,
we are not to allow ourselves to be drawn into room drama.<br>
<br>
2. Always be courteous and helpful. Offer assistance wherever possible.<br>
<br>
3. No member of the Gurus Online is to engage in booting or hacking, or
to assist others in doing so by providing information, tools or
programs.<br>
<br>
4. While on your Gurus Online name, you are to remain <strong>AVAILABLE</strong> status at all times.<br>
<br>
5. It is fine to advertise the Gurus Online, but do so sparingly.
Unless requested by a chatter, limit posting of the website to twice
per hour in any room.<br>
<br>
6. Recruiting is fine as well, as long as guideline #5 is adhered to.<br>
</div>
</description>
</item>

<item>
<title>How Do I Become a Guru?</title>
<link>http://www.eznuke.com/gurusonline/modules.php?name=News&amp;file=article&amp;sid=3</link>
<description><div align="center">So you have seen us in action, and have decided you
want to become a member. But how do you get started? This article
discusses the screening process and qualifications required to become a
member of the Gurus Online.<br>
<br>
<u><strong>SCREENING PROCESS<br>
<br>
</strong></u>We are extremely selective of our members. Not everyone is cut
out to be a Guru. So we have established a screening process to ensure
we get the cream of the crop.<br>
<br>
In most cases, we will not consider a candidate until they have been in
Yahoo chat for at least 6 months. Occasionally we may make an
exception, if we find someone with a great deal of knowledge that has
less than 6 months in chat.<br>
<br>
Candidates will have at least one specific area of expertise;i.e.:
Chat, Web Design, Software, Hardware Troubleshooting and the like.<br>
<br>
Candidates must be referred by a member in good standing.<br>
<br>
For the first two weeks, a probationary member may be observed by a
member of the Gurus Online to offer support and to ensure guidelines
are followed.<br>
<br>
<u><strong>GROUP GUIDELINES</strong></u><br>
<br>
You must be willing to spend at least 4 hours per week online in your
Gurus Online name. While in your Gurus name, you will be on AVAILABLE
status. An invisible Guru cannot help.<br>
<br>
Gurus Online members will uphold the spirit of the group, and avoid
confrontation at all costs. We act as peacekeepers and helpers, we do
not add to the problem by escalating it.<br>
<br>
At all times, members must be alert and aware of the room, and be
willing to offer assistance. If a question or problem is outside your
area of expertise, contact another member. If there are no members
online, get as much info as you can, refer the person with the problem
to our forums, and follow up with them once an answer is found.<br>
<br>
At no time is it appropriate for a member of the Gurus Online to engage
in booting or hacking. This is grounds for immediate dismissal from the
group.<br>
<br>
If you have an issue with a person or group in chat, ignore them and report the problem to Gurus Online Leader.<br>
<br>
</div>
</description>
</item>

</channel>
</rss>