<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>From the Mind of Marc... &#187; conficker</title>
	<atom:link href="http://mdpblog.mdpsystems.com/tag/conficker/feed/" rel="self" type="application/rss+xml" />
	<link>http://mdpblog.mdpsystems.com</link>
	<description>Advice and insights from a computer authority</description>
	<pubDate>Wed, 21 Apr 2010 18:47:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>One of Conficker&#8217;s purposes revealed&#8230;.</title>
		<link>http://mdpblog.mdpsystems.com/2009/04/10/one-of-confickers-purposes-revealed/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/04/10/one-of-confickers-purposes-revealed/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 21:21:56 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Virus Protection]]></category>

		<category><![CDATA[conficker]]></category>

		<category><![CDATA[security software]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=98</guid>
		<description><![CDATA[It looks like all that updating Conficker did on April 1st and in the past few days had a reason: to push rogue anti-spyware software. According to several security software vendors, Conficker is dropping a program called SpywareProtect2009 on infected machines. The purpose of rogue anti-spyware programs is to scare users into paying for the [...]]]></description>
			<content:encoded><![CDATA[<p>It looks like all that updating Conficker did on April 1st and in the past few days had a reason: to push rogue anti-spyware software. <a href="http://blogs.pcmag.com/securitywatch/2009/04/conficker_awakens_mutates_hust.php" target="_blank">According to several security software vendors</a>, Conficker is dropping a program called SpywareProtect2009 on infected machines. The purpose of rogue anti-spyware programs is to scare users into paying for the software to clean up infections that the software itself has downloaded to the machine. Typically these programs will besiege the user with large pop-up windows proclaiming, in big red letters, that the computer is infected with hundreds of pieces of malware. If you receive any of these so-called warnings, don&#8217;t click on any of them. Run your security software (Norton, McAfee, Trend Micro, etc) to remove the threat. You can also go to any of the security vendors&#8217; websites to get free removal tools for Conficker or any of the rogue anti-spyware programs. Check out our previous blog posts <a href="http://mdpblog.mdpsystems.com/tag/conficker/" target="_blank">here</a> for more information on Conficker and how to check for and remove it.</p>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/04/10/one-of-confickers-purposes-revealed/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Conficker is alive.</title>
		<link>http://mdpblog.mdpsystems.com/2009/04/09/conficker-is-alive/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/04/09/conficker-is-alive/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 13:13:46 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Virus Protection]]></category>

		<category><![CDATA[conficker]]></category>

		<category><![CDATA[PC Magazine]]></category>

		<category><![CDATA[rootkit]]></category>

		<category><![CDATA[spyware]]></category>

		<category><![CDATA[Trend Micro]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=94</guid>
		<description><![CDATA[It&#8217;s been in the news recently, and we&#8217;ve talked about it here in previous posts and newsletters. The Conficker worm came to life yesterday according to TrendLabs, Trend Micro&#8217;s blog. It apparently downloads a file from other infected machines via P2P, similar to how file and music sharing services like Limewire work. From the TrendLabs [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been in the news recently, and we&#8217;ve talked about it here in previous posts and newsletters. The Conficker worm came to life yesterday <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/" target="_blank">according to TrendLabs</a>, Trend Micro&#8217;s blog. It apparently downloads a file from other infected machines via P2P, similar to how file and music sharing services like Limewire work. From the <a href="Trend now detects this new Conficker variant as WORM_DOWNAD.E. Some interesting things (well at least in our perspective) found are:     1. (Un)Trigger Date – May 3, 2009, it will stop running    2. Runs in random file name and random service name    3. Deletes this dropped component afterwards    4. Propagates via MS08-067 to external IPs if Internet is available, if no connections, uses local IPs    5. Opens port 5114 and serve as HTTP server, by broadcasting via SSDP request    6. Connects to the following sites:           * Myspace.com           * msn.com           * ebay.com           * cnn.com           * aol.com  It also does not leave a trace of itself in the host machine. It runs and deletes all traces, no files, no registries etc.  Read more: DOWNAD/Conficker Watch: New Variant in The Mix? - http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CBXDoaOb" target="_blank">TrendLabs blog</a>:</p>
<p><span style="color: #0000ff;">Trend now detects this new Conficker variant as <a onclick="javascript:pageTracker._trackPageview('/outgoing/threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EE&amp;VSect=P');" href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EE&amp;VSect=P">WORM_DOWNAD.E</a>. Some interesting things (well at least in our perspective) found are:</span></p>
<ol>
<li><span style="color: #0000ff;">(Un)Trigger Date – May 3, 2009, it will stop running</span></li>
<li><span style="color: #0000ff;">Runs in random file name and random service name</span></li>
<li><span style="color: #0000ff;">Deletes this dropped component afterwards</span></li>
<li><span style="color: #0000ff;">Propagates via MS08-067 to external IPs if Internet is available, if no connections, uses local IPs</span></li>
<li><span style="color: #0000ff;">Opens port 5114 and serve as HTTP server, by broadcasting via SSDP request</span></li>
<li><span style="color: #0000ff;">Connects to the following sites: </span>
<ul>
<li><span style="color: #0000ff;">Myspace.com</span></li>
<li><span style="color: #0000ff;">msn.com</span></li>
<li><span style="color: #0000ff;">ebay.com</span></li>
<li><span style="color: #0000ff;">cnn.com</span></li>
<li><span style="color: #0000ff;">aol.com</span></li>
</ul>
</li>
</ol>
<p><span style="color: #0000ff;">It also does not leave a trace of itself in the host machine. It runs and deletes all traces, no files, no registries etc.</span></p>
<div id="TixyyLink" style="overflow: hidden;"><span style="color: #0000ff;"><br />
Read more: DOWNAD/Conficker Watch: New Variant in The Mix? - <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CBXDoaOb">http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CBXDoaOb</a></span></div>
<div style="overflow: hidden;"></div>
<div style="overflow: hidden;">If you think you might be infected, use the <a href="http://www.joestewart.org/cfeyechart.html" target="_blank">Conficker eye chart</a> to confirm, and follow the <a href="http://blogs.pcmag.com/securitywatch/2009/04/infected_with_conficker_heres.php" target="_blank">PC Mag Security Blog steps</a> to help remove it; or give us a call.</div>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/04/09/conficker-is-alive/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Conficker Worm</title>
		<link>http://mdpblog.mdpsystems.com/2009/04/09/the-conficker-worm/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/04/09/the-conficker-worm/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 12:00:34 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[Computer Fixers]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Virus Protection]]></category>

		<category><![CDATA[conficker]]></category>

		<category><![CDATA[Norton]]></category>

		<category><![CDATA[security software]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=83</guid>
		<description><![CDATA[A particularly nefarious piece of malware has been in the news a lot lately: Conficker. Also known as Downadup and the April Fools worm, it is very sneaky and difficult to detect. Fortunately, because of its popularity, there has been a lot of research done to figure out ways to stop it from spreading and [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: x-small; font-family: Trebuchet MS,Verdana,Helvetica,sans-serif; color: #0066cc;"><span style="font-size: 12pt; font-family: Times New Roman,Times,Serif;">A particularly nefarious piece of malware has been in the news a lot lately: Conficker. Also known as Downadup and the April Fools worm, it is very sneaky and difficult to detect. Fortunately, because of its popularity, there has been a lot of research done to figure out ways to stop it from spreading and to remove it from machines that have been infected. The easiest way to determine if you have been infected with Conficker is to use the Conficker eye chart (available <a href="http://www.joestewart.org/cfeyechart.html" target="_blank">here</a>). Part of Conficker&#8217;s programming is to block access to well-known security software vendors&#8217; websites, such as Symantec and Trend Micro. The &#8220;eye chart&#8221; has a legend that explains what you should see if you don&#8217;t have Conficker, and also what you see if you do have Conficker. If the chart appears normal, then you most likely haven&#8217;t been infected; if there are some images missing, then you probably have Conficker. Don&#8217;t panic though, it can be fixed. You can access a list of steps to remove Conficker <a href="http://blogs.pcmag.com/securitywatch/2009/04/infected_with_conficker_heres.php" target="_blank">here</a>, or you can give us a call. Even if you don&#8217;t have Conficker, make sure you have the latest version of your preferred security software and that it&#8217;s up-to-date. We recommend Norton Internet Security 2009 (available <a href="http://shop.symantecstore.com/store/symnahho/en_US/ContentTheme/ThemeID.1795800/pbPage.NIS09wide?ipd=InterstitialChall&amp;ipln=true" target="_blank">here</a>).</span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/04/09/the-conficker-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Happy April Fool&#8217;s Day</title>
		<link>http://mdpblog.mdpsystems.com/2009/04/01/happy-april-fools-day/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/04/01/happy-april-fools-day/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 20:51:52 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[conficker]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=77</guid>
		<description><![CDATA[So April 1st is here, and the end of the world has not been brought about by the Conficker worm&#8230; as far as we know. However, Conficker is still around, and if you are not sure whether or not you have it, it&#8217;s better to be safe. PC Magazine has put together a checklist of [...]]]></description>
			<content:encoded><![CDATA[<p>So April 1st is here, and the end of the world has not been brought about by the Conficker worm&#8230; as far as we know. However, Conficker is still around, and if you are not sure whether or not you have it, it&#8217;s better to be safe. PC Magazine has put together a checklist of steps to make sure your machine is not infected; it&#8217;s available <a href="http://www.pcmag.com/article2/0,2817,2344170,00.asp" target="_blank">here</a>. If you just want to download the scanning and removal tools, you can get them from the Conficker Working Group site <a href="http://www.confickerworkinggroup.org/wiki/pmwiki.php?n=ANY.RepairTools" target="_blank">here</a>. And make sure you have installed the latest Windows updates and any updates for your security software (you DO have security software right?!?!?).</p>
<p>PS- This is NOT an April Fool&#8217;s joke.</p>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/04/01/happy-april-fools-day/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Downadup = 4/1 (or: Conficker set to do something on April 1)</title>
		<link>http://mdpblog.mdpsystems.com/2009/03/30/downadup-41-or-conficker-set-to-do-something-on-april-1/</link>
		<comments>http://mdpblog.mdpsystems.com/2009/03/30/downadup-41-or-conficker-set-to-do-something-on-april-1/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 18:45:29 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Virus Protection]]></category>

		<category><![CDATA[conficker]]></category>

		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://mdpblog.mdpsystems.com/?p=73</guid>
		<description><![CDATA[Conficker (also known as Downadup) is a pretty nasty worm that has three known variations (A, B, and most recently C). It gets onto your machine through a Windows security flaw that was patched in October of 2008, and is programmed to call a sequence of control servers for updates and presumably other nasty activities. [...]]]></description>
			<content:encoded><![CDATA[<p>Conficker (also known as Downadup) is a pretty nasty worm that has three known variations (A, B, and most recently C). It gets onto your machine through a Windows security flaw that was patched in October of 2008, and is programmed to call a sequence of control servers for updates and presumably other nasty activities. Recently, Kaspersky Labs, a security software and research company, was able to figure out the list of names the worm would check for updates and teamed with <a href="http://www.opendns.com" target="_self">OpenDNS</a> to block these attempts. Now researchers are saying that the worm is programmed to do something on April 1. What that is, they don&#8217;t know; they only know that it is set to &#8220;call home&#8221; on that day. Fortunately, there are many <a href="http://blogs.pcmag.com/securitywatch/2009/03/the_most_important_things_to_k.php#more" target="_blank">ways to remove the worm</a> if you&#8217;ve been infected. And as always, keeping your antivirus and antispyware software up-to-date and installing Windows updates will help protect your machine.</p>
]]></content:encoded>
			<wfw:commentRss>http://mdpblog.mdpsystems.com/2009/03/30/downadup-41-or-conficker-set-to-do-something-on-april-1/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
